Skip to content

feat(flows): harness drivers for the new flow API - #77

Merged
futrime merged 3 commits into
feat/new-flow-apifrom
flow-api/u3-harnesses
Sep 25, 2026
Merged

futrime merged 3 commits into
feat/new-flow-apifrom
flow-api/u3-harnesses

Conversation

@futrime

@futrime futrime commented Sep 25, 2026 •

Copy link
Copy Markdown
Member

Unit 3 (Wave 1): open_agent(spec) and open_outworlder(...) in hmz.runtime.flowing.harnesses. Every HarnessKind gets an AgentDriver over coganchor that serves exactly HARNESS_CAPABILITIES. The permission mapping and translation tables live in harnessing.py.

Capability table changes

  • grok: PermissionRequest dropped. At every rung the flow API uses, it runs --always-approve and never asks.
  • codex: AskUser kept. It needs the default_mode_request_user_input feature, verified with the real codex 0.153.4.

Permission mapping

  • local<=READ uses the harness's read-only rung. local=ALL uses bypass everywhere, so user and system scopes are not fenced.
  • Reason: codex's workspace-write sandbox (bwrap) cannot start on this machine, and the spec calls codex BYPASS "danger-full-access + never".
  • dsh and acp are always bypass.
  • While a PERMISSION_REQUEST hook is hung:
    • codex switches to untrusted approvals over its rung's sandbox;
    • kimi and zcode run at coganchor auto (also while an ASK_USER hook is hung).
  • Claude never uses coganchor auto.

coganchor changes

  • SessionBase.fork(into=, cwd=) with forks_elsewhere; Claude copies the transcript into the new workdir.
  • SessionBase.cut() with cuts_transport.
  • codex: strict() output schemas, an approvals override, goal usage is now reported, and a thread resumed on a new server is counted from last.

Tests

  • Unit: tests/unit/flows/test_harness_mapping.py.
  • Integration: check_agent_driver against stand-in claude, codex and opencode, plus hooks, steer, forks, limits and faults, in tests/integration/flows/test_harness_drivers.py.
  • System: tests/system/agents/test_harness_drivers.py.
    • Passed: claude, codex, grok, agy, opencode.
    • Skipped as not signed in here: kimi, zcode, pi, cursor, qwen, mimo, dsh.

🤖 Generated with Claude Code

futrime and others added 3 commits September 25, 2026 10:52
Grok Build's coganchor driver runs every rung the flow API may use at
`--always-approve`, where the CLI approves for itself and never asks a
client, so a PERMISSION_REQUEST hook on it would never fire. The
coordinator authorised dropping the mixin from `GrokBuildAgent`, which
`HARNESS_CAPABILITIES` is read from.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
- `SessionBase.fork(into=, cwd=)` carries a conversation on as a
  conversation of another agent of the same backend and account, and
  into another directory where `forks_elsewhere` says the CLI can:
  Codex, Kimi Code and ZCode are told the child's directory, and Claude
  Code has its transcript copied to where `--resume` looks for it.
- `SessionBase.cut(why=)` interrupts a turn and, on a backend whose
  transport is shared or whose runtime nothing reaches into
  (`cuts_transport`: Codex, Kimi Code, ZCode, dsh), puts that down, so
  that a turn or goal actually stops spending.
- Codex: output schemas are held to what its structured outputs take
  (`strict`); an `approvals` override asks about every command while
  the rung's sandbox stays; a goal reports what it spends; and a thread
  first heard of on a server is counted from `last` rather than from
  its whole restored total.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
`open_agent(spec)` builds an `AgentDriver` over coganchor for every
`HarnessKind`, serving exactly `HARNESS_CAPABILITIES`. A session is a
coganchor agent of its own, so that its rung, web access, skills,
machine, hooks and questions are its own; turns run on threads of their
own, with SESSION_START, USER_PROMPT_SUBMIT, STOP and SESSION_END fired
on the loop and the CLI's own moments bridged through `HookBridge`.

- Permission: local<=READ is the CLI's read-only rung, local=ALL is
  bypass everywhere; never a model-reviewed mode. Codex asks about every
  command (`untrusted`) while a PERMISSION_REQUEST hook is hung, Kimi
  Code and ZCode run at their asking rung while one is hung, and Codex's
  asking feature is switched on for an ASK_USER hook.
- `/goal` goes to the harness's goal, steer maps to interject or to a cut
  and a new turn, forks carry on in another workdir where the CLI can,
  limits are held by the driver and usage is priced with `prices.cost`.
- Failed turns come to the `HarnessError` leaf for their fault.
- `open_outworlder(ask=, away=)` answers for whoever is outside the run.

Tested against stand-in Claude Code, Codex and opencode CLIs through
`check_agent_driver`, and against the real CLIs signed in here.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@futrime
futrime merged commit 83d431f into feat/new-flow-api Sep 25, 2026
2 checks passed
@futrime
futrime deleted the flow-api/u3-harnesses branch September 25, 2026 10:53
futrime pushed a commit that referenced this pull request Sep 25, 2026
feat(flows): harness drivers for the new flow API
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant