Skip to content

Declare the MiniMax Code agent-host view - #356

Merged
SaladDay merged 3 commits into
feature/agent-outside-sandboxfrom
aos/view-mcode
Oct 1, 2026
Merged

SaladDay merged 3 commits into
feature/agent-outside-sandboxfrom
aos/view-mcode

Conversation

@SaladDay

@SaladDay SaladDay commented Oct 1, 2026 •

Copy link
Copy Markdown
Collaborator

The MiniMax Code adapter (mcode) declares its agent-host view: lane L5-mcode, on the Runtime–Harness View declaration (#350) and the shared viewloader (#355). Nothing launches a view yet. The agent-host library (L5a) and the end-to-end qualification (L7) follow.

View declaration

Discovery declares a view when mcode is available and SupportsExecution, and checks it with View.Validate. If the declaration or the loader fails, discovery prints the reason and declares no view.

  • Closure:
    • node: Node's resolved directory;
    • mcode-harness: the bridge directory, which must contain native/cli.js;
    • the viewloader fragment, for a dynamic node.
  • Masks:
    • /assets and /opt/assets (directories);
    • /install.json and /opt/install.json (files);
    • /node_modules, so Node never falls back to the world's modules;
    • the loader masks from viewloader.
  • LocalExec: node.
  • Shims: git and rg.
  • ShimPaths: /bin/bash.
  • ForwardEnv: empty.
  • Proxy: ViewProxyNone.

Executor in a view

  • Launch: node runs [cli.js, acp] through ViewSession.Launch, in the world workspace.
  • Environment: closed.
    • PATH is the shim directory.
    • HOME and MINIMAX_DATA_DIR are home/data.
    • PI_CODING_AGENT_DIR is home/pi-agent.
    • TMPDIR is home/tmp.
    • The MAVIS_BUILTIN_*_DIR variables point at the closure assets.
    • LD_LIBRARY_PATH comes from the loader fragment, and the tool-policy variables are kept.
  • Model: config.yaml holds the gateway URL with no path, and the placeholder key.
  • Workspace profile: there is no toolEnvFile and no local readiness check. The worker stays local.
  • MCP: taken only from ViewSession.MCP. A stdio binding returns ErrUnsupportedOperation.
  • Project .mcp.json: under protected-mcp-v1, patch-native.mjs makes the CLI ignore the workspace's project .mcp.json, so the Session's MCP comes only from the daemon.
  • Session home: every create, write and read in the Session home goes through one os.Root. A link planted at data/config.yaml that points outside the home makes preparation fail.
  • Rejected in a view, each with ErrUnsupportedOperation: Skills, read-only workspaces, restricted network, and enabled Subagents. The Subagent history reader has to run beside the CLI in the live view, and the protocol cannot start a second process in a live view yet. That protocol change is scheduled separately.

Checks

  • View test: resolves the view through the registry. It checks the launch, the closed environment, the gateway config, the planted-link refusal and the Subagents rejection.
  • Go:
    • go test ./apps/daemon/internal/agent/...;
    • -race on mcode and viewloader;
    • go vet ./apps/daemon/...;
    • gofmt;
    • the darwin and windows builds.
  • Harness package: node --test packages/mcode-harness/*.test.mjs gives 7 passed and 4 skipped; the skipped tests need the packaged artifact.

View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

@SaladDay
SaladDay merged commit a2a0328 into feature/agent-outside-sandbox Oct 1, 2026
1 check passed
Discover fills View from the installed node, CLI and workspace bridge: the
closure holds node's directory, the harness directory and node's library
directories, with the ELF interpreter as an Exec overlay. The view Executor
writes the native configuration into the Session home through os.Root, runs
node cli.js acp through ViewSession.Launch with a closed environment, takes
MCP only from ViewSession.MCP and keeps the workspace worker local. The
Subagent history reader runs on the host as the Session user.

The native patch ignores the workspace's project .mcp.json under
protected-mcp-v1.
The reader ran on the agent host as the Session user, outside the view's
containment. A Session has one live view, which runs only the CLI, so a view
Executor rejects enabled Subagents with ErrUnsupportedOperation and starts no
reader.
Discovery asks viewloader.For for node's interpreter overlay, lib closure,
loader masks and LD_LIBRARY_PATH, and declares no view when node's libraries
are not all in the interpreter's directory. The adapter's own ld.so --list
loader is removed.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant