Remove the unserved daemon pairing path and the dormant Parsar upload hook - #363
Open
RyanLee-Dev wants to merge 3 commits into
Open
RyanLee-Dev wants to merge 3 commits into
RyanLee-Dev wants to merge 3 commits into
Conversation
`oac-daemon connect --url --token` posted to /api/v1/runtimes/pair, which Core does not serve and no contract documents, so the path always failed. Its envelope encryption was never wired: Core never stored or used runner_public_key, and SealForRuntime had no caller outside its fixture generator. Daemon credentials come from a Provider bootstrap file, self-hosted Environment enrollment or the oac-core-device profile, all unchanged. - Delete pair.go, the inline pairing flags, their environment handoff and their tests. - Delete internal/runtimecrypto; golang.org/x/crypto is no longer required. - auth: drop the pairing-only Profile fields and Save, which no longer has a production caller; the not-found error points to oac-core-device. - daemonize: drop ReExecOptions.ExtraEnv, which only carried the pairing token to the background child. - paths: drop EnsureProfileDir, whose only caller was auth.Save. - Reword comments and docs that described pairing.
The daemon wrapped every Session and Executor factory to look for PARSAR_CAPABILITY_UPLOAD_TOKEN in AgentOptions env, inject PARSAR_SERVER_URL and prepend its own directory to PATH when a `parsar` executable sat beside it. This is a product-specific path selected by name, which the protocol rules forbid, and it is unreachable: Core never writes AgentOptions env, nothing ships a `parsar` executable next to the daemon, and Core serves no upload route. Applications upload Skills through the public /v1 API. - Delete skill_upload.go and its tests, and the authoring PATH prepend. - Drop the now-unused name-guard exceptions; the capability download fixture keeps a narrow exception for its example host.
This comment has been minimized.
This comment has been minimized.
|
Preview deployment for your docs. Learn more about Mintlify Previews.
💡 Tip: Enable Automations to automatically generate PRs for you. |
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Removes two daemon paths that cannot run today, plus everything that becomes dead with them. Two commits, so the second can be reviewed or reverted on its own.
What changes
1. Unserved pairing path and
runtimecryptooac-daemon connect --url --tokenposted to/api/v1/runtimes/pair. Core does not serve that route and no contract documents it (machine API), so the path always failed.runner_public_key, andSealForRuntimehad no caller outside its fixture generator.pair.go, the--url/--token/--device-nameflags, theOAC_RUNTIME_DAEMON_CONNECT_*handoff to the background child,internal/runtimecrypto(and thegolang.org/x/cryptorequirement), the pairing-onlyauth.Profilefields,auth.Save,paths.EnsureProfileDiranddaemonize.ReExecOptions.ExtraEnv, whose only callers were the pairing path.2. Dormant Parsar capability upload hook
PARSAR_CAPABILITY_UPLOAD_TOKENinAgentOptionsenv, injectPARSAR_SERVER_URLand prepend its own directory toPATHwhen aparsarexecutable sat beside it. That is a product-specific path selected by name, which the protocol rules forbid.AgentOptionsenv (execution/request.go), nothing ships aparsarexecutable next to the daemon, and Core serves no upload route. Applications upload Skills through the public/v1API.skill_upload.goand its tests, the authoring-bridgePATHprepend, and the name-guard exceptions that only covered them. The capability download fixture keeps a narrowed exception for its example host.Behavior
--bootstrap-file, self-hosted Environment enrollment, nativeinstall/start, and theauth.jsonprofile written byoac-core-device.auth.jsonwith the oldhostname,paired_ator runner key fields still loads; the extra fields are ignored.statusno longer printshostname/paired_at, which only the removed pairing path wrote.-bbackground mode and capability download URL rewriting are unchanged.Checks
go build ./...,go vet ./apps/daemon/... ./internal/...,go mod tidy(no further diff),make check-names,make check-docs.go testover./apps/daemon/... ./internal/... ./contracts/agents-api/... ./scripts/openapi-split ./services/core/internal/runtimegateway/...: everything passes exceptapps/daemon/internal/agent/mcode, whose two failures (TestExecutorCancellationRetiresOwnerAndLateCancelCannotRetarget,TestSubagentSettlementIncludesActiveRootTurn) reproduce identically onorigin/mainon the macOS host used.cli,auth,paths,daemonize) pass on their own.check-corewith a test database and live Harness acceptance; no Core behavior or Harness adapter changed.Independent review ran three times. The first two found orphaned helpers left by the removal (
ExtraEnv,EnsureProfileDir) and one stale comment, all fixed. The third approved, including an unreachable-function comparison againstorigin/mainthat shows onlyruntimecryptofunctions removed and none added.Need help on this PR? Tag
@codesmith-botwith what you need. Autofix is disabled.