Skip to content

agentc Toolkit - #29

Merged
laosb merged 7 commits into
mainfrom
feat/agentc-toolkit
Aug 28, 2026
Merged

laosb merged 7 commits into
mainfrom
feat/agentc-toolkit

Conversation

@laosb

@laosb laosb commented Aug 28, 2026

Copy link
Copy Markdown
Owner

No description provided.

laosb added 7 commits August 28, 2026 03:31
…rkflow

The toolkit is a small set of static tools — curl, jq, ripgrep and a CA
bundle — that later gets mounted read-only into every container so an image
that ships nothing still has something to bootstrap with.

It is versioned on its own: scripts/toolkit/manifest.sh is the sole input,
CI republishes only when that file changes, and it refuses to overwrite an
existing toolkit-v<N> tag so the version has to be bumped alongside. Every
download is pinned to a SHA-256 that is checked before anything is unpacked,
and the archive is written deterministically, so an unchanged manifest
reproduces the same bytes.
ToolkitManager installs the bundle for the running architecture into
~/.agentc/toolkit/v<N> on first use and AgentSession mounts it read-only at
/agent-isolation/toolkit. Failing to install one is a warning, not an error:
a session without a toolkit behaves exactly as it did before, using whatever
the image ships.

--toolkit <path> points at a local bundle, which is how you exercise a
manifest change before it is published, and --no-toolkit opts out. Nothing is
mounted when --respect-image-entrypoint is in play, since without the
bootstrap nothing would put it on PATH.

ToolkitManifestTests reads the shell manifest and ToolkitManager side by side
so the version agentc downloads cannot drift from the one CI publishes.
… when the image has none

The toolkit's bin directory is appended before any configuration gets to touch
PATH, and every configuration prepends, so it stays in last place: curl
resolves to the image's own build wherever there is one and to the toolkit's
only where there is not. This is the opposite of what the curl configuration
did by installing into $HOME/.local/bin, where it shadowed the image.

The CA bundle matters just as much. On an image with no trust store, HTTPS
fails outright — including the 'curl … | bash' line nearly every agent
installer is built around — so CURL_CA_BUNDLE, SSL_CERT_FILE and GIT_SSL_CAINFO
are pointed at the bundled roots, but only when the image ships none of its own,
leaving a privately-trusted CA baked into an image working as before.
… not shadow

The suite builds a bundle from the manifest in this checkout rather than
downloading a published one, so a manifest change is exercised on the branch
that makes it, and skips itself when the bundle cannot be built.

Beyond 'curl exists', the tests pin the placement: debian:latest resolves
curl, jq and rg to /agent-isolation/toolkit/bin, buildpack-deps:scm keeps
resolving curl to /usr/bin, --no-toolkit leaves the container with neither,
and an HTTPS fetch succeeds either way — with CURL_CA_BUNDLE set only on the
images that have no trust store to override.
@laosb
laosb merged commit e65571a into main Aug 28, 2026
0 of 11 checks passed
@laosb
laosb deleted the feat/agentc-toolkit branch August 28, 2026 08:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant