Skip to content

Merge into Agents API - #27

Open
cm2435-hcomp wants to merge 27 commits into
mainfrom
charlie/placement-cli-sdk
Open

cm2435-hcomp wants to merge 27 commits into
mainfrom
charlie/placement-cli-sdk

Conversation

@cm2435-hcomp

@cm2435-hcomp cm2435-hcomp commented Sep 30, 2026 •

Copy link
Copy Markdown
Collaborator

What

Route HoloDesktop CLI runtime and session ownership through the shared Python Agent API SDK. Retain CLI/MCP/ACP/A2A entry points, inference/source settings, authenticated attachment and emergency Stop; close SDK-owned device bridges before closing HTTP transport.

Why

HoloDesktop already uses the local Agents API pattern. Moving lifecycle and sessions to the shared SDK removes duplicate ownership and gives products the same placement interface.

How

Delegate launcher, client and session lifecycle to the SDK; preserve request options and protocol entry points, and close device bridges before their HTTP transport.

Validation and dependencies

P6, depends on hcompai/hai-agents-python#222 and the reviewed runtime/driver/contract releases. MUST NOT merge or publish with the current permissive hai-agents>=1.0.12 floor: update to the actual compatible released SDK and lock before landing. No future version is fabricated here. Legacy CLI artifact ownership remains until this migration ships.

Validation: 453 non-E2E CLI tests pass, 16 skipped, against review SDK sources. Prior isolated CLI/MCP/ACP/A2A live probes exercised files, follow-ups and owned-command Stop. Full installed-product visual/packaged parity remains unverified. Local-agent/local-environment and local-agent/cloud-environment QA covers the new runtime path; candidate hosted combinations were not demonstrated. HoloWork migration is deferred.

Stack navigation: P1 contract → P2 runtime; P3 generation + P4 SDK; P5 checks: runtime, generation, SDK pins; P6 CLI. P7 duplicate pin cleanup follows only after P6 ships. HoloWork integration is subsequent work.

Review guide: intent, architecture, service tradeoffs and merge order.

CI dependency constraint: released SDK/contract packages lack local-runtime modules and Desktop.host, so current installer/unit/type checks require the compatible dependency releases. Ruff lint and format steps pass on the current CI head; mypy and message/session tests pass with candidate SDK/contract sources.

@cm2435-hcomp

Copy link
Copy Markdown
Collaborator Author

bugbot run

@cm2435-hcomp

Copy link
Copy Markdown
Collaborator Author

bugbot run

@cm2435-hcomp

Copy link
Copy Markdown
Collaborator Author

cursor review

- Launch and attach through the SDK's hai_agents_local.runtime.LocalRuntime,
  sharing its state dir (~/.hai/agent-runtime) so CLI and SDK clients on the
  same port see the same token and pid files.
- Build clients with AsyncClient.local(runtime=...); the desktop-recipe
  latency preset uses the runtime's proving HTTP client without bridges.
- Drop the unproven /health probe: doctor attaches through the SDK, and the
  launcher only checks whether anything answers before deciding to spawn.
- holo stop --force also finds runtimes started by released CLIs.
- Test stubs answer the runtime identity challenge.
@abonneth

abonneth commented Oct 1, 2026

Copy link
Copy Markdown
Collaborator

Pushed directly (as agreed), aligning with the SDK changes on hai-agents-python#222:

  • 415ee0c: launch and attach go through the SDK's LocalRuntime and AsyncClient.local(runtime=...), sharing ~/.hai/agent-runtime. Removed the CLI's own launcher and its unproven health probe. Why: the CLI and the SDK used different state dirs on the same port and broke each other, and an unproven probe hands the bearer to whatever holds the port.
  • fc1bb0f: holo agent-api starts on the shared recipe, so other clients can attach.
  • ba8bda7, 1f742f8: README/SECURITY updated for the new state paths, identity proofs and the stop --force pid check.

Tests: 370 passed (e2e 84). Smoke against a real runtime:

  • run --fake spawns and answers;
  • doctor verifies the token;
  • a squatter on the port is rejected and never receives the bearer;
  • stop --force works;
  • 3 concurrent attaches all succeed.

Before merge:

  • Released runtimes don't send proofs yet, so this fails closed against them. Needs a runtime release plus a pin bump.
  • Daemons started by released CLIs keep their token in ~/.holo. The new CLI can't attach to them, but holo stop --force still finds them.
  • The CLI pins runtime 0.1.12 and the SDK pins 0.1.8, which triggers a version-skew warning. Unify them at release time.

…ed SDK

Desktop.host first ships in hai-agent-api 0.1.113; older versions drop
host="user_device" silently.

TEMPORARY: hai-agents is pinned to an unreleased hai-agents-python commit
(a42b972) via tool.uv.sources so CI exercises the local runtime API. Swap
it for a hai-agents release floor before merging.
…ver's identity

The expense-report demo still built AgentApiClient from a base URL and
token. Its fake agent-API now answers runtime identity challenges, reports
the shared recipe, returns a full Session on create, and disables local
desktop bridges since it drives no device.
@abonneth

abonneth commented Oct 1, 2026

Copy link
Copy Markdown
Collaborator

Pushed 42fc682 + b593a60: Windows ARM64 installer.

Why: hai-agents[desktop] pulls pyautogui + 5 deps that ship only sdists. --no-build made ARM64 installs unresolvable.

Change: --no-build → --no-build-package <name> for each manifest wheel (cryptography). Hosted wheels stay binary-only; pure-Python sdists build without a compiler. CI/release smokes drop UV_NO_BUILD so they test the installer's real policy.

Status: ARM64 install now resolves (89 packages). Remaining failures (ARM64 bootstrap No module named hai_agents_local.runtime, calculator did not prove…) are release ordering: they clear once the runtime and SDK with local runtime ship and the floor bumps.

@abonneth

abonneth commented Oct 2, 2026

Copy link
Copy Markdown
Collaborator

Simplification pass (no behavior change), edeb018:

  • Removed RuntimeSpawnSettings.api_token: no readers left (the SDK reads the env var).
  • Removed AUTH_TOKEN_ENV/PORT_ENV re-exports from the launcher; callers import from settings.
  • run_turn catches ApiError only: the SDK client raises it for every HTTP error; the httpx.HTTPStatusError branch was only hit by the test fake.
  • Test stub imports the identity header names from the SDK.
  • Dropped "removed text stays removed" asserts in the static workflow tests.

Tests: 454 passed, 16 skipped; ruff clean.

@abonneth

abonneth commented Oct 3, 2026 •

Copy link
Copy Markdown
Collaborator
Commit Fix
df91e36 SDK source tracks the current local-runtime head
51793dc Shared recipe: missing macOS grants point at the app running holo (clean error, no futile runtime restart); doctor checks this process directly. --fast walkthrough unchanged
80bc951 holo serve fails the A2A task with the same grant guidance

Tests: 455 passed, 16 skipped. ruff + mypy clean. Live holo doctor: green.

@abonneth abonneth changed the title refactor(cli): use shared Agent API runtime and sessions Merge into Agents API Oct 7, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants