Skip to content

Remove the unserved daemon pairing path and the dormant Parsar upload hook - #363

Open
RyanLee-Dev wants to merge 3 commits into
mainfrom
remove-dead-pairing-and-parsar-upload
Open

RyanLee-Dev wants to merge 3 commits into
mainfrom
remove-dead-pairing-and-parsar-upload

Conversation

@RyanLee-Dev

@RyanLee-Dev RyanLee-Dev commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Removes two daemon paths that cannot run today, plus everything that becomes dead with them. Two commits, so the second can be reviewed or reverted on its own.

What changes

1. Unserved pairing path and runtimecrypto

  • oac-daemon connect --url --token posted to /api/v1/runtimes/pair. Core does not serve that route and no contract documents it (machine API), so the path always failed.
  • Its envelope encryption was never wired: Core never stores or reads runner_public_key, and SealForRuntime had no caller outside its fixture generator.
  • Removed: pair.go, the --url / --token / --device-name flags, the OAC_RUNTIME_DAEMON_CONNECT_* handoff to the background child, internal/runtimecrypto (and the golang.org/x/crypto requirement), the pairing-only auth.Profile fields, auth.Save, paths.EnsureProfileDir and daemonize.ReExecOptions.ExtraEnv, whose only callers were the pairing path.
  • Comments and docs that described pairing are reworded.

2. Dormant Parsar capability upload hook

  • The daemon wrapped every Session and Executor factory to look for PARSAR_CAPABILITY_UPLOAD_TOKEN in AgentOptions env, inject PARSAR_SERVER_URL and prepend its own directory to PATH when a parsar executable sat beside it. That is a product-specific path selected by name, which the protocol rules forbid.
  • It is unreachable: Core never writes AgentOptions env (execution/request.go), nothing ships a parsar executable next to the daemon, and Core serves no upload route. Applications upload Skills through the public /v1 API.
  • Removed: skill_upload.go and its tests, the authoring-bridge PATH prepend, and the name-guard exceptions that only covered them. The capability download fixture keeps a narrowed exception for its example host.
  • The removed allowlist entries described this integration as "explicitly retained"; that wording came from the branding change (Finish OpenAgentCore naming and enforce retired-name checks #173), which kept it rather than renaming it. Reviewers who know of an external dependency on it should say so here.

Behavior

  • Supported credential sources are unchanged: --bootstrap-file, self-hosted Environment enrollment, native install / start, and the auth.json profile written by oac-core-device.
  • An existing auth.json with the old hostname, paired_at or runner key fields still loads; the extra fields are ignored. status no longer prints hostname / paired_at, which only the removed pairing path wrote.
  • The removed flags are now rejected as undefined flags, without echoing their values.
  • Bootstrap/enrollment mutual exclusion, -b background mode and capability download URL rewriting are unchanged.

Checks

  • go build ./..., go vet ./apps/daemon/... ./internal/..., go mod tidy (no further diff), make check-names, make check-docs.
  • go test over ./apps/daemon/... ./internal/... ./contracts/agents-api/... ./scripts/openapi-split ./services/core/internal/runtimegateway/...: everything passes except apps/daemon/internal/agent/mcode, whose two failures (TestExecutorCancellationRetiresOwnerAndLateCancelCannotRetarget, TestSubagentSettlementIncludesActiveRootTurn) reproduce identically on origin/main on the macOS host used.
  • The first commit builds and its affected packages (cli, auth, paths, daemonize) pass on their own.
  • Not run: check-core with a test database and live Harness acceptance; no Core behavior or Harness adapter changed.

Independent review ran three times. The first two found orphaned helpers left by the removal (ExtraEnv, EnsureProfileDir) and one stale comment, all fixed. The third approved, including an unreachable-function comparison against origin/main that shows only runtimecrypto functions removed and none added.


View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

`oac-daemon connect --url --token` posted to /api/v1/runtimes/pair, which
Core does not serve and no contract documents, so the path always failed.
Its envelope encryption was never wired: Core never stored or used
runner_public_key, and SealForRuntime had no caller outside its fixture
generator.

Daemon credentials come from a Provider bootstrap file, self-hosted
Environment enrollment or the oac-core-device profile, all unchanged.

- Delete pair.go, the inline pairing flags, their environment handoff and
  their tests.
- Delete internal/runtimecrypto; golang.org/x/crypto is no longer required.
- auth: drop the pairing-only Profile fields and Save, which no longer has
  a production caller; the not-found error points to oac-core-device.
- daemonize: drop ReExecOptions.ExtraEnv, which only carried the pairing
  token to the background child.
- paths: drop EnsureProfileDir, whose only caller was auth.Save.
- Reword comments and docs that described pairing.
The daemon wrapped every Session and Executor factory to look for
PARSAR_CAPABILITY_UPLOAD_TOKEN in AgentOptions env, inject
PARSAR_SERVER_URL and prepend its own directory to PATH when a `parsar`
executable sat beside it. This is a product-specific path selected by
name, which the protocol rules forbid, and it is unreachable: Core never
writes AgentOptions env, nothing ships a `parsar` executable next to the
daemon, and Core serves no upload route. Applications upload Skills
through the public /v1 API.

- Delete skill_upload.go and its tests, and the authoring PATH prepend.
- Drop the now-unused name-guard exceptions; the capability download
  fixture keeps a narrow exception for its example host.
@blacksmith-sh

This comment has been minimized.

@mintlify

mintlify Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

Preview deployment for your docs. Learn more about Mintlify Previews.

Project Status Preview Updated
openagentcore 🟢 Ready View Preview Oct 1, 2026, 5:34 AM

💡 Tip: Enable Automations to automatically generate PRs for you.

This branch was successfully deployed

1 active deployment
staging — faedd67c Deployed Oct 1, 2026 by mintlify[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant