Promote agents to dev (agents-to-dev-2026-10-03) - #725
Merged
Merged
Conversation
…ndbox jobs A stateless GARM external provider (v0.1.1 ABI) whose Create/Delete/Get/List speak to agent-harbor's REST direct-sandbox-launch endpoints (agent-harbor specs/REST-Service/Direct-Sandbox-Launch.md, PR #590 head 26d8684a). One GARM instance = one ephemeral sandbox job: instance name = job name, provider_id = job id, garm-controller-id/garm-pool-id labels as owner tags. GARM's DB is the source of truth; the provider keeps no state. - Create hands the JIT runner-install script to the launch as stdin (new rootless `sandbox` template for local-sandbox; GARM's upstream template for vm substrates), always sends ttlSeconds, uses a deterministic Idempotency-Key and adopts its own job on 409 name-conflict, and refuses a job without a cleanupToken. - Get/List map ah job states onto GARM statuses (destroyed = not found). - Delete is idempotent (404 = success) and falls back to the cleanupToken. - The spec's Problem+JSON error model maps onto GARM error kinds/exit codes. - With a pinned key, every launch verifies the host's Ed25519 capability manifest (key, expiry, substrate, ah-* labels). Lives in devops-modules as a second command of the garm-provider-vmharness Go module, reusing its JIT templates, runner-version guard and vendored garm-provider-common; the vmharness package filters the new files out so its store path (and every existing check) is byte-identical. services.garm gains `backend = "agentharbor"` (package default, API key via LoadCredential, store-safe config). Gates: t_garm_provider_agentharbor (behaviour matrix, end-to-end runner lifecycle executing the real install script against a mock ah endpoint, 4 mutation negative controls) and t_garm_provider_agentharbor_module (eval-only example). Nothing deployed.
Add forbidden-branches.nix, which renders the branch-protection policy's `forbiddenBranches` field as one `forbidden-branches` repository ruleset per repository in scope, in the engine's `repositoryRulesets` schema. Repositories on a policy mainline are derived from the `mainlines` output of mainline-protection.nix; product-adapted forks are listed explicitly with their product branch, which must be their default branch. Each ruleset restricts creation, update and non-fast-forward of the forbidden refs, never deletion, so a stray branch can still be removed. It is active with no bypass unless a documented exception is given. The helper refuses a forbidden entry that would block a policy mainline, the repository's own mainline or product branch, or a branch class of the same repository class, as well as malformed fork entries and undocumented bypass or enforcement exceptions. A policy without the field renders nothing. tests/test-forbidden-branches.sh covers the rendered shape, the engine round trip and one named mutation per refusal, each with a positive control.
…positories The flake module's `mcl.gitHooks.installationScript` already refuses to install into a repository other than the flake's own, but upstream git-hooks.nix also publishes its installer unwrapped, as `pre-commit.devShell`, `pre-commit.installationScript` and `pre-commit.shellHook`. `inputsFrom = [ config.pre-commit.devShell ]` is the form consumers copy, and entering such a shell from another checkout planted this flake's `.pre-commit-config.yaml` and hooks there. Those options are read-only upstream and cannot be redefined. All of them ask `settings.gitPackage` whether they stand in a repository (`git rev-parse --git-dir`) before writing anything. The module now sets `gitPackage` (mkDefault) to a git that answers no outside this flake's repository, using the same flake.nix identity as the repo guard, and is the real git for everything else. checks.git-hooks-same-repo-git runs upstream's real installation script in a repository with a different flake.nix, one without, and a subdirectory of the first, and requires them untouched; and from a subdirectory of the flake's own repository requires the hooks to install. With upstream's default git it fails on the first case. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
The busy-runner-reap patch ended with an empty line after the format-patch signature, which the lint job's end-of-file-fixer rewrites, failing lint on every pull request. The garm package still applies it and builds.
Contributor
|
Thanks for your Pull Request! Below you will find a summary of the cachix status of each package, for each supported platform.
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Stabilisation of
agentscut at cb139f8.Brings to
dev:services.garmbackend = "agentharbor". Nothing deployed.Verified locally on x86_64-linux:
t_garm_provider_agentharbor(behaviour matrix, end-to-end lifecycle, 4/4 negative controls) andt_garm_provider_agentharbor_module;git-hooks-reprobuild-handoff;terraform/github/tests/test-forbidden-branches.sh;prek run --all-files; the garm package builds with the edited patch.Not verified: aarch64-darwin (the darwin batches and setup-nix darwin verification are red on recent PRs independently of this change). Certificates: none (repo not certificate-enabled).