Three load-bearing fixes for the airouter dogfood pipeline, derived from
the 2026-05-08 batch-3 dogfood postmortem (gotchas-airouter.md items 27-30):
1. agent-repo/v1/init.sh — seed fresh task branches from
/workspace/reference/main/ (the upstream clone) rather than the agent
repo's stale main. This was THE killer for batch 3: the
agent-runtimes-agents fork has been frozen at 2026-05-04 since the
"Fork cleanup" PR, so every agent started from old state, missing
recent test files and the M16/M22 scripts to delete. The fork remains
the push remote (so finalize.sh works); only the working-tree seed
moves to the upstream reference. Falls back to fork main when the
reference clone isn't available (preserves legacy behavior). Tagged
AR-14a.
2. requires_labels on contexts/composites — airouter context + both
airouter composites declare requires_labels: [airouter] so the
dispatcher's _collect_supported_harnesses (with the matching agent-
runtimes change) advertises them only on dispatchers carrying the
airouter label. Stops the main dispatcher from claiming airouter-
labeled tasks and dying at init time. Composites that wrap label-
restricted contexts MUST redeclare their own requires_labels — no
auto-traversal of layers (kept simple).
3. agent-repo/v1/finalize.sh — AR-21 diff-against-upstream verification.
New env-var protocol:
- AGENT_EXPECTED_CHANGED_FILES (comma-separated paths that MUST
appear in `git diff <ref/main>..HEAD`)
- AGENT_FORBIDDEN_CHANGED_FILES (paths that MUST NOT appear)
finalize.sh fails the task (exit 1) if either invariant is violated;
the branch is still pushed for forensics so the operator can inspect.
Catches BOTH the false-success mode (item 30 — agent reports succeeded
but never changed the target file) AND the destructive-Write mode
(item 21 — task 4a2f2988 stripped 9 unrelated functions). Also writes
diff_verified, diff_mismatch, diff_changed_files into ci_metadata.json.
CRS pulls all three on next CP poll — no agent-runtimes image rebuild
needed for the framework parts. The matching dispatcher poller filter
ships in agent-runtimes (separate commit).
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
31 lines
1.1 KiB
YAML
31 lines
1.1 KiB
YAML
kind: context
|
|
name: airouter
|
|
version: 1
|
|
description: "Airouter.ch Qwen3.6 — OpenAI-compatible agentic runner"
|
|
requires: []
|
|
provides: [agentic-runner]
|
|
|
|
# Label-gated capability: only dispatchers with the `airouter` label have the
|
|
# ESO mount + Ollama setup needed to run this context. Filter prevents the
|
|
# main dispatcher from claiming airouter tasks (real incident: 2026-05-08
|
|
# dogfood batch, gotchas-airouter.md item 29).
|
|
requires_labels: [airouter]
|
|
|
|
env:
|
|
OPENAI_BASE_URL: "https://api.airouter.ch/v1"
|
|
# Agentic runner reads the api key from this file at request time.
|
|
# init.sh stages a 0600 agent-owned copy from the ESO mount to this path.
|
|
OPENAI_API_KEY_FILE: "/var/agent-secrets/airouter/api_key"
|
|
|
|
secrets_required:
|
|
- name: airouter
|
|
account_ref: "airouter"
|
|
mount_path: /run/agent/secrets/airouter
|
|
# 0400 (root-only) — defense in depth. The agent user CANNOT read this
|
|
# mount; init.sh runs as root and installs a 0600 agent-owned copy at
|
|
# OPENAI_API_KEY_FILE (above). Matches the minimax pattern.
|
|
mode: "0400"
|
|
|
|
scripts:
|
|
init: ./init.sh
|