Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
4 changes: 1 addition & 3 deletions .github/workflows/agents-executor.yml
Original file line number Diff line number Diff line change
Expand Up @@ -43,9 +43,7 @@ jobs:
~/.parsar/cache/executor-cargo
~/.parsar/cache/executor-target
key: agents-executor-${{ runner.os }}-1.95.0-${{ hashFiles('packages/codex-executor/Cargo.lock') }}
- name: Check native launcher and independent release build
- name: Check shared workspace helpers and independent release build
run: |
make check-agents-executor
make build-agents-executor
~/.parsar/build/agents-executor/agents-api-codex-executor --version
~/.parsar/build/agents-executor/agents-api-codex-executor --help
79 changes: 0 additions & 79 deletions .github/workflows/agents-harness.yml

This file was deleted.

624 changes: 146 additions & 478 deletions CONTRIBUTING.md

Large diffs are not rendered by default.

15 changes: 3 additions & 12 deletions Makefile
Original file line number Diff line number Diff line change
Expand Up @@ -3,12 +3,12 @@ SQLC_VERSION ?= v1.29.0
SQLC ?= go run github.com/sqlc-dev/sqlc/cmd/sqlc@$(SQLC_VERSION)
SWAG_VERSION ?= v1.16.4

.PHONY: help check check-database check-go check-sqlc sqlc-generate node-deps check-claude-sdk check-mcode-harness build-daemon build-agents-api build-agents-api-release check-agents-api docker-build-agents-api check-agents-api-container build-agents-executor check-agents-executor build-agents-harness check-agents-harness check-agents-harness-native build-agents-runtime build-claude-runtime build-claude-sdk-runtime build-mcode-harness build-mcode-runtime
.PHONY: help check check-database check-go check-sqlc sqlc-generate node-deps check-claude-sdk check-mcode-harness build-daemon build-agents-api build-agents-api-release check-agents-api docker-build-agents-api check-agents-api-container build-agents-executor check-agents-executor build-agents-runtime build-claude-runtime build-claude-sdk-runtime build-mcode-harness build-mcode-runtime

help:
@printf '%s\n' 'make build-agents-api Build standalone Core commands' 'make build-daemon Build the execution daemon' 'make check Run Core, persistence and runtime checks' 'See README.md for runtime prerequisites and deployment.'

check: check-database check-sqlc check-go check-agents-api check-claude-sdk check-mcode-harness check-agents-executor check-agents-harness
check: check-database check-sqlc check-go check-agents-api check-claude-sdk check-mcode-harness check-agents-executor
@printf 'Parsar Core checks passed.\n'

check-database:
Expand All @@ -23,7 +23,7 @@ openapi:
output=$$(mktemp -d "$$root/core-openapi.XXXXXX"); trap 'rm -rf "$$output"' EXIT; \
go run github.com/swaggo/swag/cmd/swag@$(SWAG_VERSION) init \
-g cmd/server/main.go --dir ./services/agents-api,./contracts/agents-api/v1 \
--exclude ./services/agents-api/internal/executor --output "$$output" \
--output "$$output" \
--outputTypes yaml --parseInternal; \
mv "$$output/swagger.yaml" contracts/agents-api/openapi.yaml

Expand Down Expand Up @@ -76,15 +76,6 @@ build-agents-executor:
check-agents-executor:
./scripts/check-agents-executor.sh

build-agents-harness:
./scripts/build-agents-harness.sh

check-agents-harness:
./scripts/check-agents-harness.sh

check-agents-harness-native:
./scripts/build-agents-harness.sh check

build-agents-runtime:
./scripts/build-agents-runtime.sh

Expand Down
14 changes: 12 additions & 2 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -6,11 +6,19 @@ Standalone Agent API Core and its execution runtimes, copied from
The source repository retains both its product and its existing Core copy.

This repository contains the API service, PostgreSQL migrations, pinned public
protocol, execution daemon, Docker/E2B providers, native Harness adapters,
protocol, execution daemon, the Docker provider, native Harness adapters,
runtime image builders, client library, tests and operator documentation.
It does not contain the Parsar web application, product backend, product database,
business CLI or product deployment stack.

V1 user-managed deployments colocate our daemon, selected harness, tools and
`/workspace`. Core manages Docker only; users provision, renew and destroy E2B
through the official SDK. The returned `remote_url` uses our private daemon
transport, not stock `exec-server`. See the
[Runtime enrollment guide](services/agents-api/README.md#user-managed-runtime-enrollment)
for harness enablement and the [qualification record](contracts/agents-api/user-managed-runtime-v1.md)
for tested deployments and remaining limits.

## Start here

- [API setup, authentication and execution](services/agents-api/README.md)
Expand Down Expand Up @@ -50,5 +58,7 @@ make check

The full gate requires the test database rather than silently skipping persistence
tests. Native model/provider fixtures remain explicit, credential-dependent
acceptance checks; see the [native tests](services/agents-api/tests/native/README.md).
acceptance checks; see the [coverage ledger](contracts/agents-api/README.md).
The Rust gate covers only the retained directory/write/export helpers; the former
separate Codex harness gate and remote probe suite are retired.
Importing existing implementations does not establish additional protocol coverage.
2 changes: 1 addition & 1 deletion apps/parsar-daemon/internal/agent/claudesdk/mcp.go
Original file line number Diff line number Diff line change
Expand Up @@ -21,7 +21,7 @@ func validateMCP(req proto.PromptRequestPayload) error {
if req.MCPHTTPServers == nil {
return nil
}
if !req.DisableExecutionEnvironment || req.RemoteEnvironment != nil {
if !req.DisableExecutionEnvironment {
return fmt.Errorf("claudesdk: HTTP MCP requires environment:none")
}
return validateMCPServers(*req.MCPHTTPServers)
Expand Down
2 changes: 1 addition & 1 deletion apps/parsar-daemon/internal/agent/claudesdk/workspace.go
Original file line number Diff line number Diff line change
Expand Up @@ -45,7 +45,7 @@ type workspaceProfile struct {
}

func prepareWorkspace(config Config, req proto.PromptRequestPayload) (*workspaceProfile, []string, error) {
if req.DisableExecutionEnvironment || req.RemoteEnvironment != nil || req.MCPHTTPServers != nil {
if req.DisableExecutionEnvironment || req.MCPHTTPServers != nil {
return nil, nil, fmt.Errorf("claudesdk: workspace profile does not support the requested execution combination")
}
if req.WorkDir != "" && req.WorkDir != config.Workspace.Directory {
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -76,15 +76,13 @@ func TestWorkspaceTrustedBindingAndEnvironment(t *testing.T) {
}

func TestWorkspaceRejectsConflictsBeforeSideEffects(t *testing.T) {
for _, name := range []string{"none", "remote", "work-dir", "mcp", "caller-policy", "relative", "missing", "overlap", "symlink", "rule-pattern", "ambient-setting", "duplicate-env", "bad-env", "path-empty-component", "path-workspace", "code-in-workspace"} {
for _, name := range []string{"none", "work-dir", "mcp", "caller-policy", "relative", "missing", "overlap", "symlink", "rule-pattern", "ambient-setting", "duplicate-env", "bad-env", "path-empty-component", "path-workspace", "code-in-workspace"} {
t.Run(name, func(t *testing.T) {
config := workspaceFixture(t)
req := workspaceRequest()
switch name {
case "none":
req.DisableExecutionEnvironment = true
case "remote":
req.RemoteEnvironment = &proto.RemoteEnvironment{}
case "work-dir":
req.WorkDir = config.Workspace.ScratchDir
case "mcp":
Expand Down
33 changes: 33 additions & 0 deletions apps/parsar-daemon/internal/agent/codex/environment.go
Original file line number Diff line number Diff line change
Expand Up @@ -3,7 +3,12 @@ package codex
import (
"context"
"encoding/json"
"errors"
"fmt"
"os"
"strings"

"github.com/MiniMax-AI-Dev/parsar/internal/agentdaemon/proto"
)

// Check the native provider instead of assuming an older binary honors the flag.
Expand Down Expand Up @@ -33,3 +38,31 @@ func nativeEnvironmentStatus(ctx context.Context, rpc *JSONRPCClient, id string)
}
return result.Status, nil
}

func configureRestrictedShellEnvironment(plan *SessionPlan) {
plan.ExtraConfig = append(plan.ExtraConfig,
[2]string{"shell_environment_policy.inherit", `"core"`},
[2]string{"shell_environment_policy.ignore_default_excludes", "false"})
}

// Native still recognizes the retired transport variables. Reject them before
// setup so inherited or operator options cannot select a separate executor.
// The explicit none selector remains part of native execution isolation.
func validateNativeTransportEnvironment(req proto.PromptRequestPayload) error {
options, err := buildSessionEnv(req.AgentOptions)
if err != nil {
return err
}
for _, environment := range [][]string{os.Environ(), options} {
for _, entry := range environment {
key, value, _ := strings.Cut(entry, "=")
if value == "" {
continue
}
if (key == "CODEX_EXEC_SERVER_URL" && value != "none") || strings.HasPrefix(key, "CODEX_EXEC_SERVER_NOISE_") {
return errors.New("codex: retired executor transport configuration is not supported")
}
}
}
return nil
}
Original file line number Diff line number Diff line change
Expand Up @@ -9,7 +9,7 @@ import (

// SupportsLocalEnvironment checks deployment prerequisites, not public admission.
func SupportsLocalEnvironment(version string) bool {
if runtime.GOOS != "linux" || runtime.GOARCH != "amd64" || !SupportsRemoteEnvironment(version) || os.Getenv("PARSAR_CODEX_PERMISSION_PROFILE") == "" || os.Getenv("PARSAR_CODEX_HARNESS_BIN") != "" {
if runtime.GOOS != "linux" || runtime.GOARCH != "amd64" || !SupportsNativeSessionRecovery(version) || os.Getenv("PARSAR_CODEX_PERMISSION_PROFILE") == "" || os.Getenv("PARSAR_CODEX_HARNESS_BIN") != "" {
return false
}
binding, err := localworkspace.Load()
Expand Down
71 changes: 0 additions & 71 deletions apps/parsar-daemon/internal/agent/codex/environment_remote.go

This file was deleted.

Loading
Loading