Skip to content

runtime: ship v6.0.5 native ACP carriers on runtime 4.0.4 - #111

Merged
sumitake merged 1 commit into
mainfrom
dev/claude/acp-provider-runtime-4.0.4
Aug 18, 2026
Merged

runtime: ship v6.0.5 native ACP carriers on runtime 4.0.4#111
sumitake merged 1 commit into
mainfrom
dev/claude/acp-provider-runtime-4.0.4

Conversation

@sumitake

@sumitake sumitake commented Aug 18, 2026

Copy link
Copy Markdown
Owner

Summary

  • Import the sealed, signed/notarized provider runtime 4.0.4 from workspace main 58b5102eb3f76d218c8223ee09044d955826e2c7 (workspace PR #2739): the Grok and OpenCode carriers move to native ACP v1 sessions; logical Gemini remains carried by Agy structured stream-json (the official Gemini CLI ACP endpoint is not used); Codex remains native App Server JSONL; workspace #2733's lifecycle-diagnostic decoupling is already in this source graph.
  • Adopt the prepared Darwin host-matrix validator companion (consumer side of workspace #2735, which was declared "prepared and unopened" pending the workspace merge): manifest validators, importer, release verifier, archive builder, export-safety and cut-release checks generalize to the Darwin host matrix (arm64 today, x86_64-ready) and bind each artifact record to the manifest wire-contract digest via wire_contract_sha256. The staged builder-authored manifest is imported wholesale via stage_runtime_handoff.py; no hand-edited manifest bytes (the companion's staged-4.0.2-manifest hand-edit was deliberately NOT adopted).
  • Bump the unified Claude/Codex package and generated skills to 6.0.5 (6.0.4 is merged-but-untagged and ships in the same release); update marketplace base/generated, both READMEs, migration doc, schema const, version-pinned tests, and add one 6.0.5 changelog fragment.

Runtime bundle SHA-256: 199db223f6a409e218fa1babe713e1ac011433fe17751ebc5512463fc0d67f8d
Handoff manifest SHA-256: 264b1ca81a0e8328098a0b04f01b6be8a73f74f9cacabd5d2fc819447591c8fc
Notarization id: 9d2457ed-8c94-4f22-8144-cf0e669d12b4 (accepted; hardened runtime; secure timestamp; team 36UFP9KY4T)

Adopted-source provenance (R5 disclosure)

The host-matrix validator changes were prepared by a Codex worker (OpenAI-family lineage) as uncommitted source in a local worktree, per workspace #2735's cross-repo declaration. This PR adopts that source verbatim (excluding the staged-manifest hand-edit), with the pinned runtime version advanced to 4.0.4. The distinct-family reviewer was instructed to apply the reward-hacking watchlist; adopted tests were verified behavioral (fixture manifests exercise validation outcomes, not production-path echoes).

Boundary declaration

  • No provider executor source, raw provider command, credential, private absolute path, retired package tree, downloader, or post-install hook is included.
  • Native changes contain only the final sealed Developer ID runtime, closed manifest, and public verification metadata.
  • No host-specific preset, provider-specific plugin, routing registry, selector override, parser, retry, fallback, or release service was added; public wire contract and routing descriptor unchanged.

Generated and release surfaces

  • Skill specs and generated SKILL.md files are in parity (build_skills.py --check).
  • Claude and Codex marketplaces/manifests are in parity (build_marketplace.py --check).
  • A unique 6.0.5 changelog fragment is present; CHANGELOG.md remains release-PR-only.
  • All package/version surfaces moved together (plugin manifests, marketplace base, skill-build config, schema const, version-pinned tests, READMEs, migration doc).

Verification

  • python3 -m unittest discover -s tests -t .: 175 pass
  • python3 -m unittest discover -s scripts -p 'test_*.py': 349 pass
  • changelog dry-run and release consistency vs origin/main: pass (6.0.5 monotonic over unreleased 6.0.4)
  • verify_runtime_release.py --git-sha runtime-handoff-import: PASS (signed/notarized runtime release evidence verified)
  • active-tree public-export scan: SAFE; secret scan: clean; gated-API lint: OK; git diff --check: clean
  • exact runtime import matches the sealed workspace handoff byte-for-byte (importer digest binding + release verifier)
  • canonical activation archive bound to this exact commit: d9da747e8eea6c5409d0df4c4e9f3b6ec5f9999641f41f310895840b9310d8de

Review and post-condition

Tier 3 release candidate with full distinct-family convergence (no operator bypass, no admin merge):

  • Cross-check consultant (Gemini/google, governance route, repository-grounded, maximum effort): verdict verbatim — "VERDICT: PROCEED / CONCERNS: none" on the revised release plan (companion adoption + atomic single-PR structure). Receipt governance_verdict: APPROVE, artifact sha256 c631bc1c78d65b20938e01a40705a599b0f1a6d0ace6dc0a2c547119acc2e539.
  • Distinct-family peer review (Grok/xai, governance.repository, exact-head, repository-grounded, 23+ native read turns): round 1 at fa4c969b returned REQUEST_CHANGES (one blocking finding: stale 4.0.2 in root README expected-unit list); remediated; round 2 at 1815014 returned verbatim — "APPROVE (confidence H). Round-2 remediating head is clean" (receipt repo_head 181501404b…, artifact d3e5a495…); a narrowly scoped CI recovery patch (stale RUNTIME_BUNDLE_REL reference in scripts/build_release_evidence.py broke the release-evidence rehearsal) produced final head b1b6d68a, re-reviewed in round 3: verbatim — "VERDICT: APPROVE. CONFIDENCE: H. … CONCERNS: none". Receipt bound to repo_head: b1b6d68a…, artifact e26a7cec…. A consolidated remediation batch for the three Codex-connector P2 findings (schema member-arch const, duplicate-host-row rejection, truthful wire-evolution disclosure in the fragment; plus a stale 11-vs-12 logical-action count pin exposed by real-validator testing) produced final head 180ebc19, re-reviewed in round 4: verbatim — "VERDICT: APPROVE. CONFIDENCE: H." Receipt repo_head 180ebc19…, artifact 066ee527…. One further P1 (history-scan renamed-executor exemption covered the prospective empty x86_64 bundle dir without manifest validation) was remediated by deriving the history-mode exemption from the committed manifest rows only (_manifested_bundle_rels), producing final head 16816d70, re-reviewed in round 5: verbatim — "VERDICT: APPROVE / CONFIDENCE: H / CONCERNS: (empty)". Receipt repo_head 16816d70…, artifact 3fe49211…. A final P2 (schema wire-digest binding) was closed as a CLASS: wire_contract_sha256 const-pinned at both levels and exactly-one-entrypoint constraints added, self-audited against runtime_client._manifest_entries; final head 12939769, round 6: verbatim — "VERDICT: APPROVE / CONFIDENCE: H / CONCERNS: (empty)" with residual schema-vs-runtime looseness catalogued as inherent JSON-Schema limits, not newly blocking. Receipt repo_head 12939769…, artifact ba021e53…. One last P2 (evidence-builder 128 MiB caps vs the 192 MiB two-artifact archive bound — a latent two-artifact release breakage) was fixed by deriving the evidence bounds from the archive builder contract; final head 9aac52ae, round 7: verbatim — "VERDICT: APPROVE / CONFIDENCE: H / CONCERNS: (empty)". Receipt bound to repo_head: 9aac52ae18e43aeb050c2809dddc6d40284b88de, governance_verdict: APPROVE, artifact sha256 166b9d3a213d1bd6fc260cf8f96408595157d9729cdeef28daaa3a5dad1dddbb.

Post-condition: merge this exact signed head after CI is green (no --admin), compile the changelog on main (mechanical release PR), publish immutable v6.0.5 via cut_release.py, then deploy per the workspace cutover procedure: pre-cutover identity record, prior-release rollback materialization (v6.0.3), supported-CLI install, exact installed-byte readback, one consumed canary each for Grok ACP and OpenCode ACP only, accept-or-rollback as one unit.

Compliance trace

author: claude
standing_directives: public boundaries, signed-runtime import, exact-head integrity, no replay, deterministic release verification, adversarial + operational-reliability review lenses followed
tier: 3
cross_check: PROCEED — Gemini governance route on revised release plan; "VERDICT: PROCEED / CONCERNS: none"; receipt governance_verdict APPROVE, artifact c631bc1c78d65b20938e01a40705a599b0f1a6d0ace6dc0a2c547119acc2e539
peer_review_verdict: APPROVE (confidence H) — round 7 at exact head 9aac52a (round-1 REQUEST_CHANGES remediated; rounds 2-7 APPROVE across README fix, CI recovery patch, Codex-connector P2 batch, history-scan P1 fix, schema-strictness class closeout, and evidence-bounds alignment)
peer_review_agent: grok
peer_review_message_id: GROK-NA (direct runtime; execution receipt below)
peer_review_execution_receipts: [round-7 governance.repository receipt: repo_head 9aac52a, governance_verdict APPROVE, artifact_sha256 166b9d3a213d1bd6fc260cf8f96408595157d9729cdeef28daaa3a5dad1dddbb, family_independence distinct_from_author; round-6: repo_head 1293976…, artifact ba021e53…; round-5: repo_head 16816d7…, artifact 3fe49211…; round-4: repo_head 180ebc1…, artifact 066ee527…; round-3: repo_head b1b6d68…, artifact e26a7cec…; round-2: repo_head 1815014…, artifact d3e5a495…]
peer_review_concerns_integrated: round-1 README finding fixed; CI recovery patch round-3; Codex-connector P2 batch round-4; history-scan P1 round-5; schema-strictness class closeout round-6; evidence-bounds alignment round-7; all threads resolved with dispositions; no open concerns
worker_lineage_disclosure: host-matrix validator source adopted from Codex-prepared (OpenAI-family) uncommitted companion per workspace #2735; reviewer applied R5 watchlist
post_condition: merge exact signed head via ordinary protected path; mechanical changelog PR; immutable v6.0.5 tag/assets; workspace Task 10 deploy with Grok ACP + OpenCode ACP consumed canaries and one-unit rollback to v6.0.3
mcp_coverage_gap: NONE
plugin_affected: THIS PR (activation import; workspace #2739 plugin-sync determination satisfied)
readme_refresh_status: README updated (root + plugin READMEs, migration doc)
contributor_rights: OWNER-AUTHORED
operator_reserved: no

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 181501404b

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread plugins/agent-collab/runtime-manifest.schema.json
Comment thread plugins/agent-collab/runtime-manifest.schema.json
@sumitake
sumitake force-pushed the dev/claude/acp-provider-runtime-4.0.4 branch from 1815014 to b1b6d68 Compare August 18, 2026 01:36

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: b1b6d68a1b

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread changelog.d/2026-08-17-v6.0.5-acp-runtime-4.0.4.md Outdated
@sumitake
sumitake force-pushed the dev/claude/acp-provider-runtime-4.0.4 branch from b1b6d68 to 180ebc1 Compare August 18, 2026 01:44

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 180ebc19eb

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread scripts/check-public-export-safety.py Outdated
@sumitake
sumitake force-pushed the dev/claude/acp-provider-runtime-4.0.4 branch from 180ebc1 to 16816d7 Compare August 18, 2026 02:00

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 16816d7069

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread plugins/agent-collab/runtime-manifest.schema.json Outdated
@sumitake
sumitake force-pushed the dev/claude/acp-provider-runtime-4.0.4 branch from 16816d7 to 1293976 Compare August 18, 2026 02:09

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 1293976916

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread scripts/build_plugin_archive.py
Import the sealed provider runtime 4.0.4 (workspace 58b5102e): Grok and
OpenCode move to native ACP v1 sessions; Agy remains the Gemini-family
structured stream-json carrier (official Gemini CLI ACP not used); Codex
remains native App Server JSONL; workspace #2733 lifecycle-diagnostic
decoupling is already in this source graph.

Adopt the prepared Darwin host-matrix validator companion (consumer side
of workspace #2735): manifest validators, importer, release verifier,
archive builder, export-safety and cut-release checks generalize to the
host matrix and bind each artifact record to the manifest wire-contract
digest. The staged builder-authored manifest is imported wholesale via
stage_runtime_handoff.py — no hand-edited manifest bytes.

Public package 6.0.5; runtime facts, marketplace outputs, READMEs,
migration doc, schema const, and version-pinned tests updated.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Jq8DbD7NH7fth58kKdYVGx
@sumitake
sumitake force-pushed the dev/claude/acp-provider-runtime-4.0.4 branch from 1293976 to 9aac52a Compare August 18, 2026 02:19
@sumitake
sumitake merged commit 3875261 into main Aug 18, 2026
17 checks passed
@sumitake
sumitake deleted the dev/claude/acp-provider-runtime-4.0.4 branch August 18, 2026 02:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant