agentc Toolkit - #29
Merged
Merged
Conversation
…rkflow The toolkit is a small set of static tools — curl, jq, ripgrep and a CA bundle — that later gets mounted read-only into every container so an image that ships nothing still has something to bootstrap with. It is versioned on its own: scripts/toolkit/manifest.sh is the sole input, CI republishes only when that file changes, and it refuses to overwrite an existing toolkit-v<N> tag so the version has to be bumped alongside. Every download is pinned to a SHA-256 that is checked before anything is unpacked, and the archive is written deterministically, so an unchanged manifest reproduces the same bytes.
ToolkitManager installs the bundle for the running architecture into ~/.agentc/toolkit/v<N> on first use and AgentSession mounts it read-only at /agent-isolation/toolkit. Failing to install one is a warning, not an error: a session without a toolkit behaves exactly as it did before, using whatever the image ships. --toolkit <path> points at a local bundle, which is how you exercise a manifest change before it is published, and --no-toolkit opts out. Nothing is mounted when --respect-image-entrypoint is in play, since without the bootstrap nothing would put it on PATH. ToolkitManifestTests reads the shell manifest and ToolkitManager side by side so the version agentc downloads cannot drift from the one CI publishes.
… when the image has none The toolkit's bin directory is appended before any configuration gets to touch PATH, and every configuration prepends, so it stays in last place: curl resolves to the image's own build wherever there is one and to the toolkit's only where there is not. This is the opposite of what the curl configuration did by installing into $HOME/.local/bin, where it shadowed the image. The CA bundle matters just as much. On an image with no trust store, HTTPS fails outright — including the 'curl … | bash' line nearly every agent installer is built around — so CURL_CA_BUNDLE, SSL_CERT_FILE and GIT_SSL_CAINFO are pointed at the bundled roots, but only when the image ships none of its own, leaving a privately-trusted CA baked into an image working as before.
… not shadow The suite builds a bundle from the manifest in this checkout rather than downloading a published one, so a manifest change is exercised on the branch that makes it, and skips itself when the bundle cannot be built. Beyond 'curl exists', the tests pin the placement: debian:latest resolves curl, jq and rg to /agent-isolation/toolkit/bin, buildpack-deps:scm keeps resolving curl to /usr/bin, --no-toolkit leaves the container with neither, and an HTTPS fetch succeeds either way — with CURL_CA_BUNDLE set only on the images that have no trust store to override.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
No description provided.