Project-2 baseline
This commit is contained in:
@@ -30,11 +30,11 @@ from pathlib import Path
|
||||
import atif_session
|
||||
import browser_note
|
||||
try:
|
||||
from dnsjail import apply_dns_jail
|
||||
from dnsjail import jailed
|
||||
except ImportError: # no helper shipped -> no jail, rather than no trials
|
||||
|
||||
async def apply_dns_jail(agent, environment) -> None: # type: ignore[misc]
|
||||
return None
|
||||
def jailed(run): # type: ignore[misc]
|
||||
return run
|
||||
|
||||
|
||||
from harbor.agents.installed.codex import Codex
|
||||
@@ -117,10 +117,10 @@ class SystemNodeCodex(Codex):
|
||||
_has_browser = False
|
||||
|
||||
# Non-snapshot codex tasks run this class directly; the native-snapshot resume path
|
||||
# overrides run() and applies the jail itself.
|
||||
# overrides run() and carries its own @jailed.
|
||||
@jailed
|
||||
async def run(self, instruction, environment, context): # type: ignore[override]
|
||||
self._refuse_shell_hostile_key()
|
||||
await apply_dns_jail(self, environment)
|
||||
await super().run(instruction, environment, context)
|
||||
|
||||
def _auth_json_setup(self, remote_auth_path: str) -> tuple[dict[str, str], str]:
|
||||
@@ -343,11 +343,10 @@ class InlineSnapshotCodex(SystemNodeCodex):
|
||||
|
||||
# A real recorded codex session_meta line (with codex's base_instructions) is the
|
||||
# most reliable seed for `resume`. The fixture lives in-repo (mounted into the
|
||||
# devcontainer where this agent code runs); a captured host copy is a secondary
|
||||
# source, and a synthesized minimal record is the final fallback.
|
||||
# devcontainer where this agent code runs); a synthesized minimal record is the
|
||||
# fallback.
|
||||
_ROLLOUT_TEMPLATE_CANDIDATES = (
|
||||
os.path.join(os.path.dirname(os.path.abspath(__file__)), "codex-rollout-template.jsonl"),
|
||||
"/Users/nickheiner/.claude/jobs/e8fade29/tmp/codex-rollout-template.jsonl",
|
||||
)
|
||||
|
||||
|
||||
@@ -463,6 +462,7 @@ class NativeSnapshotCodex(SystemNodeCodex):
|
||||
self.logger.warning("NativeSnapshotCodex: could not read session: %s", exc)
|
||||
return ""
|
||||
|
||||
@jailed
|
||||
async def run(self, instruction, environment, context): # type: ignore[override]
|
||||
# NOTE: codex unconditionally declares its `tool_search` (MCP apps tool-
|
||||
# discovery) tool, which the OpenAI API REJECTS for nano models with HTTP
|
||||
@@ -471,7 +471,6 @@ class NativeSnapshotCodex(SystemNodeCodex):
|
||||
# disabled_tools) suppress it as of codex 0.135, so nano models are NOT
|
||||
# runnable under this harness. Use a mini (e.g. gpt-5.4-mini) for the small
|
||||
# end instead. Non-nano models are unaffected.
|
||||
await apply_dns_jail(self, environment)
|
||||
session_text = await self._read_staged_session(environment)
|
||||
if not session_text:
|
||||
self.logger.info(
|
||||
|
||||
Reference in New Issue
Block a user