Skip to content

Define the view capability contract - #472

Merged
SaladDay merged 2 commits into
feature/agent-outside-sandboxfrom
aos/view-capability-contract
Oct 7, 2026
Merged

SaladDay merged 2 commits into
feature/agent-outside-sandboxfrom
aos/view-capability-contract

Conversation

@SaladDay

@SaladDay SaladDay commented Oct 7, 2026 •

Copy link
Copy Markdown
Collaborator

Defines the agent-host view capability contract, so that the next lanes (the host's preparation and each adapter) can turn on capabilities one by one through declarations instead of hard-coded rejections.

What changes

  • Declarations. agent.View.Capabilities (ViewCapabilities) declares environment none, Skills, function tools, function-result images, tool search and stdio MCP. View.Validate requires each field to be set explicitly. Agent-host admission follows the declarations, with no second mask. Every adapter keeps today's behavior: whatever its view rejected before stays declared unsupported.
  • Environment none. An empty-root view (read-only noexec root, cwd ViewPrivateRoot/home/work, no world, shims, Link or sandbox network). A request with neither a workspace nor DisableExecutionEnvironment is an incomplete binding.
  • Stdio MCP. The binding at index i runs under the shim alias agent.ViewAlias(i), which the process broker maps to the frozen command, args and cwd. A credentialed stdio binding is a typed ErrViewHandoff rejection, whatever the view declares.
  • Skills are gated separately from installed MCP. Installed Capabilities that no preparation resolved are rejected.
  • Environment and credentials. The Harness env is exactly the adapter's Launch env. The request carries no environment values, and model and MCP credentials stay in the gateway's protected configuration.
  • harness-onboarding.md (en + zh) documents the contract.

Not in this PR

The producers of empty-root views, stdio aliases and prepared Skills come with the host lane, and each adapter flips its declarations as its lane qualifies them.

Checks

  • Focused go test for agent, codex, mcode, claudesdk, viewloader, agenthost, gateway and dispatch.
  • -race -count=50 on the changed agenthost and agent tests.
  • gofmt and go vet, plus the darwin and windows builds of apps/daemon.
  • make check-names check-docs check-ci, and the website translation test.

View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

View.Capabilities declares what each agent-host view runs, and admission
follows it with no second mask: environment none, resolved Skills,
function tools and results, tool search and stdio MCP. Every adapter
declares them unsupported until the agent host builds and qualifies them.
Whatever a view declares, the agent host rejects a Session without strict
resume, with a restricted network, with a credentialed stdio binding, with
installed Capabilities that no preparation resolved, or with neither a
workspace nor environment none. The contract fixes the stdio alias, the
empty-root view and the environment rule.
@SaladDay
SaladDay merged commit cc8fd6a into feature/agent-outside-sandbox Oct 7, 2026
20 checks passed
@SaladDay
SaladDay deleted the aos/view-capability-contract branch October 7, 2026 08:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant