ren worker folder adding orig, mv new one into root

This commit is contained in:
2026-09-25 10:34:29 -04:00
parent 10f0668e32
commit 5b010039d7
1308 changed files with 44597 additions and 1511 deletions

View File

@@ -16,6 +16,9 @@
# token rate): the trial agent (claude-code only) and the grader the verifier launches.
# Serving speed and cost change; the grade itself is not steered.
#
# GRADER_SAMPLES=N (a prefix, or a line in .env) sets how many times the grader scores the
# run and averages. A task's own tests/test.sh supplies the default when it is unset.
#
# Needs python 3.11+ on PATH (tomllib, to read the harness registry). Containers have it;
# a macOS host running HARBOR_ENV=docker may not — set RACCOON_PYTHON if so.
@@ -29,6 +32,11 @@ REPO_ROOT="$(cd "$SCRIPT_DIR/.." && pwd)"
_RJ_SET="${RACCOON_DNS_JAIL+set}"; _RJ_VAL="${RACCOON_DNS_JAIL:-}"
_RJA_SET="${RACCOON_DNS_JAIL_ALLOW+set}"; _RJA_VAL="${RACCOON_DNS_JAIL_ALLOW:-}"
# Same for the grader sample count, under either name (HARBOR_GRADER_SAMPLES is what
# harbor-regrade calls it; GRADER_SAMPLES is what the task's tests/test.sh reads).
# Captured as one value so a caller's spelling beats .env's, whichever each used.
_CALLER_SAMPLES="${GRADER_SAMPLES:-${HARBOR_GRADER_SAMPLES:-}}"
# Source API key
if [ -f "$REPO_ROOT/.env" ]; then
set -a
@@ -156,7 +164,10 @@ if [ -f "$TASK_DIR/task.toml" ] &&
BROWSER_OPTIN=1
fi
if [ -d "$TASK_DIR/environment" ]; then
printf '%s\n' "$BROWSER_OPTIN" > "$TASK_DIR/environment/browser-optin"
# Rename into place: a concurrent run against this task dir must never read the
# instant between truncate and write.
printf '%s\n' "$BROWSER_OPTIN" > "$TASK_DIR/environment/browser-optin.tmp.$$" &&
mv -f "$TASK_DIR/environment/browser-optin.tmp.$$" "$TASK_DIR/environment/browser-optin"
fi
# Preflight: restage the DNS jail script, for the same reason as the marker above.
@@ -171,7 +182,8 @@ if [ -d "$TASK_DIR/environment" ]; then
for DNSJAIL_SRC in "$REPO_ROOT/scripts/lib/dns-jail-container.sh" \
"$REPO_ROOT/task-shared/dns-jail-container.sh"; do
if [ -f "$DNSJAIL_SRC" ]; then
cp "$DNSJAIL_SRC" "$TASK_DIR/environment/dns-jail/dns-jail-container.sh"
_dnsjail_dst="$TASK_DIR/environment/dns-jail/dns-jail-container.sh"
cp "$DNSJAIL_SRC" "$_dnsjail_dst.tmp.$$" && mv -f "$_dnsjail_dst.tmp.$$" "$_dnsjail_dst"
break
fi
done
@@ -255,6 +267,35 @@ FAST_FLAGS=""
GRADER_FAST_FLAGS=""
[ -n "$FAST_REQUESTED" ] && GRADER_FAST_FLAGS="--verifier-env GRADER_FAST_MODE=true"
# A task's tests/test.sh is frozen at creation and defaults its own sample count, so
# forwarding the var is the only way to change one that already exists.
GRADER_SAMPLES_FLAGS=""
_SAMPLES="${_CALLER_SAMPLES:-${GRADER_SAMPLES:-${HARBOR_GRADER_SAMPLES:-}}}"
if [ -n "$_SAMPLES" ]; then
if ! [ "$_SAMPLES" -ge 1 ] 2>/dev/null; then
echo "harbor-run: ERROR — GRADER_SAMPLES must be a positive integer (got '$_SAMPLES')." >&2
exit 1
fi
GRADER_SAMPLES_FLAGS="--verifier-env GRADER_SAMPLES=$_SAMPLES"
fi
# The verifier launches its own grader claude, so it names its own call origin
# rather than inheriting the surface that launched harbor. An array because the
# header value contains a space.
GRADER_ORIGIN_FLAGS=()
if [ -f "$REPO_ROOT/scripts/lib/call-origin.sh" ]; then
. "$REPO_ROOT/scripts/lib/call-origin.sh"
_GRADER_METADATA="$(LLM_CALL_ORIGIN=harbor-grading call_origin_metadata)"
# `if`, not `[ ... ] && ...`: an AND-list is this block's last statement, so under
# `set -e` an empty value would abort the run rather than just skip the header.
if [ -n "$_GRADER_METADATA" ]; then
GRADER_ORIGIN_FLAGS=(
--verifier-env
"ANTHROPIC_CUSTOM_HEADERS=$CALL_ORIGIN_HEADER: $_GRADER_METADATA"
)
fi
fi
# Environment backend. An explicit HARBOR_ENV always wins (either direction).
# Otherwise the default is context-dependent:
# - daytona for the internal repo: runs the trial in a cloud sandbox over
@@ -429,6 +470,8 @@ harbor run \
$EFFORT_FLAGS \
$FAST_FLAGS \
$GRADER_FAST_FLAGS \
$GRADER_SAMPLES_FLAGS \
${GRADER_ORIGIN_FLAGS[@]+"${GRADER_ORIGIN_FLAGS[@]}"} \
"$@" &
HARBOR_PID=$!
trap 'HARBOR_SIGNALLED=1; kill -TERM "$HARBOR_PID" 2>/dev/null || true' TERM