Skip to content

feat: implement the coding-agent execution gateway #487

Description

@christso

Objective

Implement remote Codex and Pi execution through UHP 2026-09-12 and a pinned HarnessRouter Community Edition fork. Authenticated UHP callers select a configured harness and an AllAgents Git workspace or immutable OCI workspace snapshot, continue the same conversation and writable workspace with previous_response_id, and receive output, usage, artifacts, and verified source provenance.

Authoritative inputs

The ADR owns architecture. The plan owns requirements R1-R15, flows, schemas, failure codes, acceptance examples, U0-U6, verification, and Definition of Done. Do not use the superseded A2A gateway/worker design.

Handoff status

Runtime implementation has not started. Begin with U0 only. U1-U6 remain blocked until both required native targets pass the recorded U0 gate on the exact pinned inputs.

Implementation order

  1. U0 — Harness-native auth feasibility. Build the minimal pinned image and prove real Codex and Pi login, first turn, continuation, restart, binding enforcement, profile isolation, atomic idempotency/session/profile admission, runner-owned lock fencing and crash recovery, refresh-fault repair, and passive credential exclusion without a provider-route API key.
  2. U1 — HarnessRouter hook feasibility. Add the generic first-turn materializer boundary, generated workspace-manifest schema and frozen fixture, durable materialization state, delegated cgroup v2 containment, staged publication, checkpoint integration, nested cwd, and stock-UHP compatibility.
  3. U2 — AllAgents Git materializer. Add the versioned descriptor/configuration contracts, complete Git catalog acquisition, exact commit resolution, credentials, canonical manifest generation, provenance, and acquisition limits.
  4. U3 — Session, failures, and credentials. Close crash/restart transitions, the exact public error catalog, response metadata, source-secret isolation, cgroup failure handshake, native-profile projection, and the explicit proxy broker.
  5. U4 — OCI workspace materialization. Verify direct image manifests, the same canonical workspace-manifest schema/blob, layers, whiteouts, repository and archive limits, registry policy, and final staged-tree equality.
  6. U5 — Full-image consumer E2E. Prove native OAuth, explicit proxy isolation, Promptfoo Git/OCI one-shot and continuation, cancellation, restart, and exact coded failure mappings.
  7. U6 — Release and operations. Publish the attested linux/amd64 GHCR image by digest, document operation and rollback, rehearse the maintained fork, and prepare the generic upstream patches.

Settled architecture

  • UHP is the only northbound execution protocol. AllAgents does not add another task/session control plane.
  • HarnessRouter authenticates callers, owns UHP lifecycle and sessions, runs Codex or Pi, and returns output, usage, files, and artifacts.
  • A narrow HarnessRouter fork invokes one generic subprocess materializer after session allocation and before provider selection or fallback.
  • The AllAgents materializer exposes no listening service. It reads server-owned project configuration, acquires Git or OCI sources into staging, emits a private canonical workspace manifest, and returns path-free provenance.
  • Git, OCI, and the runner share one generated normative manifest schema and frozen canonical fixture. Repository names and destinations are unique, each destination names a directory entry, and the runner reconstructs the manifest before publication.
  • Every materializer is born atomically inside a runner-owned, child-inaccessible cgroup v2 leaf. The cgroup must report populated 0 before any terminal result, manifest read, publication, secret release, or cleanup. An unquiescent boundary enters internal containment_pending, exits/restarts the runner, withholds terminal GET/stream visibility and readiness, and exposes failed/cancelled/incomplete only after the old boundary is proven empty.
  • Native OAuth is an explicit owner-trust boundary. The gateway atomically claims each Idempotency-Key; simultaneous duplicates share one admission/result, same-session overlap returns session_busy, and only a genuinely new cross-session turn tries the zero-waiter profile lock. The runner supervisor owns and durably fences that lock through terminal-state acknowledgement and refresh commit. Cross-session collision returns cataloged harness_unavailable before allocation.
  • proxyApiKey is an explicit last-resort deployment mode. It is optional to configure but required version-one implementation and verification scope. OAuth failure never activates it.
  • Source credentials are resolved server-side and injected only into the selected materializer child environment.
  • One materialization is limited to 128 repositories, 500,000 filesystem entries, 32 GiB staged content, and the request deadline.
  • Workspace and auth failures use the plan's exact UHP placement, vendor-prefixed codes, retryability, and Promptfoo mapping. No non-success becomes empty output or an automatic retry.
  • Releases use ghcr.io/allagentsdev/harnessrouter, a public linux/amd64 manifest, digest-pinned deployment, and verified GitHub/Sigstore provenance and SBOM attestations.

Version-one boundaries

  • No A2A execution contract, separate AllAgents gateway, custom agent backend, direct provider adapter, or client-side workspace expansion.
  • No E2B dependency, guest daemon, sandbox-provider abstraction, execution-provider seam, or E2B-specific telemetry or policy layer.
  • No public hostile multi-tenancy, caller-provided origins or credentials, arbitrary materializer commands, mutable OCI tags, automatic source fallback, automatic OAuth-to-proxy fallback, or concurrent refresh-capable turns sharing one profile.
  • Promptfoo owns evaluation datasets, assertions, scoring, repetitions, and retry policy. AllAgents supplies the execution provider contract only.

Delivery evidence

Each unit must satisfy its plan verification before the next dependent unit starts. Final delivery requires stock UHP conformance, generated-schema and frozen-fixture agreement, exact Git/OCI fixtures, cgroup escape and delayed-descendant probes, native Codex/Pi and explicit proxy E2E, fail-fast profile saturation, the complete failure-code matrix through Promptfoo, digest-published image verification, and resolved review findings in both repositories.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions