Project-2 baseline

This commit is contained in:
2026-10-04 21:19:23 -04:00
parent 0f04889edf
commit 213eb3c403
861 changed files with 1710 additions and 3363322 deletions

View File

@@ -30,11 +30,11 @@ from pathlib import Path
import atif_session
import browser_note
try:
from dnsjail import apply_dns_jail
from dnsjail import jailed
except ImportError: # no helper shipped -> no jail, rather than no trials
async def apply_dns_jail(agent, environment) -> None: # type: ignore[misc]
return None
def jailed(run): # type: ignore[misc]
return run
from harbor.agents.installed.codex import Codex
@@ -117,10 +117,10 @@ class SystemNodeCodex(Codex):
_has_browser = False
# Non-snapshot codex tasks run this class directly; the native-snapshot resume path
# overrides run() and applies the jail itself.
# overrides run() and carries its own @jailed.
@jailed
async def run(self, instruction, environment, context): # type: ignore[override]
self._refuse_shell_hostile_key()
await apply_dns_jail(self, environment)
await super().run(instruction, environment, context)
def _auth_json_setup(self, remote_auth_path: str) -> tuple[dict[str, str], str]:
@@ -343,11 +343,10 @@ class InlineSnapshotCodex(SystemNodeCodex):
# A real recorded codex session_meta line (with codex's base_instructions) is the
# most reliable seed for `resume`. The fixture lives in-repo (mounted into the
# devcontainer where this agent code runs); a captured host copy is a secondary
# source, and a synthesized minimal record is the final fallback.
# devcontainer where this agent code runs); a synthesized minimal record is the
# fallback.
_ROLLOUT_TEMPLATE_CANDIDATES = (
os.path.join(os.path.dirname(os.path.abspath(__file__)), "codex-rollout-template.jsonl"),
"/Users/nickheiner/.claude/jobs/e8fade29/tmp/codex-rollout-template.jsonl",
)
@@ -463,6 +462,7 @@ class NativeSnapshotCodex(SystemNodeCodex):
self.logger.warning("NativeSnapshotCodex: could not read session: %s", exc)
return ""
@jailed
async def run(self, instruction, environment, context): # type: ignore[override]
# NOTE: codex unconditionally declares its `tool_search` (MCP apps tool-
# discovery) tool, which the OpenAI API REJECTS for nano models with HTTP
@@ -471,7 +471,6 @@ class NativeSnapshotCodex(SystemNodeCodex):
# disabled_tools) suppress it as of codex 0.135, so nano models are NOT
# runnable under this harness. Use a mini (e.g. gpt-5.4-mini) for the small
# end instead. Non-nano models are unaffected.
await apply_dns_jail(self, environment)
session_text = await self._read_staged_session(environment)
if not session_text:
self.logger.info(