Skip to content

FROM task/908-cli-first-class TO development - #909

Merged
ryaneggz merged 9 commits into
developmentfrom
task/908-cli-first-class
Aug 31, 2026
Merged

FROM task/908-cli-first-class TO development#909
ryaneggz merged 9 commits into
developmentfrom
task/908-cli-first-class

Conversation

@ryaneggz

Copy link
Copy Markdown
Collaborator

Closes #908

Stacked on #907. Retarget as the stack lands.

Why

#905 and #907 moved the kind: "default" harnesses and tools out of the image and left the four optional harnesses behind. Your boundary β€” inside the sandbox the CLI provisions harnesses and tools β€” has no carve-out for optional ones, and I had been scoping them out as though it did.

They were not merely leftover. opencode, grok-build, and hermes are all installUser: "root", and harness.ts:256 installs with stdio: "inherit", so local-target.ts selects the interactive branch. Evaluated against the real code:

user=root stdio="inherit" -> ["sudo","--","npm","install","-g","opencode-ai"]
$ sudo -n -- true
sudo: a password is required

/etc/sudoers.d/sandbox has no NOPASSWD, so oh harness install opencode hangs on a password prompt no agent can answer. The build arg was the only working path β€” which is why the Dockerfile blocks could not simply be deleted, and why this PR is a fix as much as a cleanup.

No sudoers change was needed

All four relocate to the sandbox user. I read the upstream installers rather than assuming:

Harness Was Now
opencode npm install -g as root npm --prefix /home/sandbox/.local β€” identical to claude-code
deepagents already sandbox + uv tool install unchanged; its build arg was pure redundancy
grok-build HOME=/opt/grok-build GROK_BIN_DIR=… installer honours GROK_BIN_DIR; pointed at ~/.local/bin
hermes root β†’ /usr/local/lib/hermes-agent installer honours HERMES_INSTALL_DIR, and its own get_command_link_dir() already picks $HOME/.local/bin for a non-root install

Every harness in the catalog is now installUser: "sandbox". No security posture moves.

What changed

  • All four ARG/RUN pairs, the compose build.args block, and the now-dead /opt/grok-build and /usr/local/lib/hermes-agent chowns are gone.
  • buildArg removed from HarnessEntry entirely β€” it was dead metadata: declared, set four times, read by no code. tool-catalog-boundary.sh already banned the same field in the tool catalog with "that field carries a Dockerfile invariant this catalog cannot satisfy"; the two catalogs no longer disagree.
  • provision-defaults.sh reads the full catalog and installs any non-default entry whose install.<key> is true, so declared intent survives a fresh home mount. isInstallFlagEnabled already reads oh.json β€” no new env plumbing.
  • verify-sandbox-image.sh widens to "no harness of any kind is baked", and gains the inverse for tools: every kind: "baked-in" tool must be present, or the whole check would pass on an image missing everything.
  • sandbox-compatibility.yml's optional-installer job loses its subject. It now boots the image and runs oh harness install <id> for each optional harness, asserting the binary lands under /home/sandbox/.local β€” the path operators actually use, rather than one that no longer exists.

Explicitly kept

INSTALL_HERMES keeps its runtime life as a container environment variable: link-providers.sh:111 vendors the Hermes skill pack from it and entrypoint.sh:169 wires auth.json. Only its build-arg role is gone, and a test now pins that distinction. cc-safety-net, docker-cli, gh, and the base toolchain stay baked. INSTALL_PYTHON_KERNEL is not a harness and is untouched.

A test was enshrining the bug

harness.test.ts had a case named "installs live instead of skipping the install" asserting calls.some((c) => c.cmd === "sudo") β€” it codified the exact defect that made the command hang. It now asserts the opposite: no install shells out to sudo at all.

Mutation-verified

Five against the widened provisioning probe, four against the CI-contract probe, each confirmed to exit 1:

Mutation Result
reinstate ARG INSTALL_HERMES caught
re-bake opencode-ai in the Dockerfile caught
optional harness back to installUser: "root" caught
buildArg field returns caught
hermes installs to /usr/local again caught
compat job reintroduces a --build-arg caught
compat job drops its vacuity guard caught
compat job drops the home-mount location assertion caught
compat job renamed away caught

The opt-in provisioning path was also exercised directly: setting install.opencode: true in oh.json made provision-defaults.sh --verify report opencode as missing, confirming declared intent is honoured rather than silently ignored.

Verification

EVAL=0 (103 probes, no regressions). npx vitest run 952 passed / 8 failed β€” the known compose-args.test.ts baseline. shellcheck 0, tsc --noEmit 0, npm run build 0. Local image build and booted-container checks follow in a comment.

oh is meant to split by execution target -- on the host it provisions the host
or the sandbox, and inside the sandbox it provisions the sandbox with harnesses
and tools. The second half did not work for the two harnesses most people use.

claude-code and codex carried installUser: "root", which against the local
execution target becomes sudo -n -- npm install -g, and /etc/sudoers.d/sandbox
grants sandbox ALL=(ALL) ALL with no NOPASSWD. sudo -n true returns "a password
is required". Both now match the pi entry directly above them: installUser
"sandbox", npm --prefix /home/sandbox/.local install -g. That lands them inside
the home mount, so they also survive container recreate and can be upgraded in
place in a running remote sandbox rather than requiring an image rebuild.

claude-code deliberately does not get --ignore-scripts. Its postinstall copies
the native binary over a placeholder; with the flag the install succeeds and
claude --version then fails with "claude native binary not installed". Verified
both ways against a scratch prefix.

provision-harnesses.sh follows provision-python.sh: the same mode flag, the same
root to gosu sandbox re-exec, the same ownership diagnostics, the same die-with-
the-command-to-re-run style. --print-env is absent because this provisioner
exports nothing downstream. It reads the catalog through oh harness list --json
and installs through oh harness install, so the shell knows no ids, packages,
prefixes, or argv, and the TypeScript catalog stays the only description.

No default harness carries a version pin today, so an existing install is never
replaced and the script says so in its own output rather than implying it
refreshes.

The entrypoint hook runs after link-providers.sh, not before. link-providers'
only binary dependency is cc-safety-net, which stays baked, and it is the
boot-critical hard gate; a network-dependent best-effort step does not belong in
front of the step that decides whether the boot is viable. Provisioning warns
and continues, so an offline sandbox still comes up as a usable shell.

BAKE_HARNESSES defaults to true and gates only the $AGENTS loop, not the whole
RUN. INSTALL_OPENCODE and INSTALL_GROK_BUILD are separate opt-ins and turning
them off as a side effect would be a silent regression. Nothing leaves the image
in this change.
An adversarial audit of #903 found five defects that six green checks missed.

The serious one is a boot hang. oh harness list --json probes every entry in
the catalog, not just the three defaults, and one of them is t3code, whose
verifyArgv is npx --no-install t3 --version. npx contacts the registry, and
probeInstalled passed no timeoutMs, so spawnSync waited without bound. Against
an unreachable registry the auditor's run was still going at 2m30 when their own
timeout killed it. On any boot where DNS resolves but the registry does not
answer, the entrypoint blocks before sleep infinity, exceeds the 300s
start_period, and never goes healthy -- and restart: unless-stopped does not
rescue an unhealthy-but-alive container. Warn-and-continue cannot help, because
a hang never reaches the if !. It hangs while listing, before any install, so
BAKE_HARNESSES=true did not avoid it either.

Bounded at three layers, because each fails differently: a 15s timeoutMs on the
probe spawn, reported as unknown rather than a crash; a --defaults filter on
oh harness list so the boot path probes three entries instead of nine and never
runs npx; and a timeout wrapper on the entrypoint call so the boot is bounded
whatever the CLI does. Measured against the auditor's exact command: 2m30 and
killed, to 17.0s full-catalog and 1.55s with --defaults.

The install loop read from a herestring while installs run with stdio inherit,
so an installer that reads stdin consumed the rest of the loop. Reproduced with
a stub: three missing harnesses, one installed, exit 0, success printed. Latent
with npm, live the moment a default uses the curl | bash shape two catalog
entries already use. Installs now read from /dev/null.

The script force-exported OH_EXECUTION_TARGET=local, which short-circuits the
in-container check, while the prefix is hardcoded to /home/sandbox/.local, and
every error told the operator to re-run with no mention of where. On the host
that provisioned the host. It now refuses unless inside the sandbox, reusing the
CLI's own runningInsideSandbox predicate rather than inventing a check, and the
entrypoint asserts the local target explicitly -- the documented raw docker run
recipe never passes SANDBOX_NAME, so the guard would otherwise have silently
skipped provisioning for the prebuilt-image flavor.

The probe asserted that ARG BAKE_HARNESSES was declared, not that anything used
it: deleting the gate left it green. It now checks the ARG is referenced by the
RUN that installs $AGENTS and by the one that bakes pi, and that both stages
declare it. Deleting either declaration also used to pass.

ARG is stage-scoped, so BAKE_HARNESSES=false unbaked claude-code and codex but
left pi baked in the home stage while the else-branch claimed otherwise. The
home stage now declares and honors the flag.

Also: OH_SANDBOX_USER was advertised but illusory, since the catalog hardcodes
the user and prefix; it is gone. The final log line no longer claims to have
provisioned anything in --verify mode.
PR #903 wired provision-harnesses.sh into the boot path but shipped it behind
ARG BAKE_HARNESSES=true, so every default harness was already present when the
provisioner ran and the install path never executed. All four defects that PR's
audit found lived in code a green CI run and a normal boot both skip.

Delete the bake rather than flip its default: remove ARG BAKE_HARNESSES, ARG
AGENTS, the PKG map and the $AGENTS loop in `base`, and the gated pi install in
`home`. A build arg that can re-bake is a dormant path that would restore both
the shadowed /usr/lib/node_modules copy and the untested boot install.

Make the install path CI-visible, since it is now load-bearing on every boot:

- The boot smoke asserts the outcome β€” each default harness resolves under
  NPM_USER_PREFIX via `type -P`, is owned by the reconciled sandbox uid, and
  prints its own version β€” and refuses to pass when the catalog reports no
  defaults. It boots on a fresh home volume, so this runs real npm work.
- verify-sandbox-image.sh gains the negative: reading the catalog out of the
  image itself, no kind:"default" harness may be installed.
- start_period goes 300s -> 600s in both compose files to cover the install,
  and the boot-guard probe now derives the smoke deadline from the healthcheck
  window instead of pinning a literal that a start_period bump could invert.
- The probe and unit assertions invert from "the bake is gated" to "no default
  harness package appears in the Dockerfile", reading the package names out of
  installArgv so they cannot drift from the catalog.

cc-safety-net stays baked. Opt-in INSTALL_* harnesses are untouched.

Costs this accepts, documented in installation.md: a first boot on a fresh home
mount needs network and runs 60-180s longer; an offline first boot yields a
usable shell with no agent CLIs; ~/.npm now lives in the home mount.

Closes #904
Per the ownership boundary β€” the in-sandbox CLI provisions harnesses and tools β€”
herdr and cloudflared are tools, so the image should not carry them. #905 did
this for the default harnesses; this does it for the default tools.

The obvious template does not work. #897's tailscale entry root-installs to
/usr/local/bin, and commands/tool.ts:309 passes stdio:"inherit", so
local-target.ts:113-116 selects the INTERACTIVE branch β€” plain `sudo --`, no
-n. /etc/sudoers.d/sandbox grants `sandbox ALL=(ALL) ALL` with no NOPASSWD, so
`oh tool install <root tool>` hangs on a password prompt no agent can answer.
Verified in a running sandbox: `sudo -n -- true` β†’ "a password is required".
(#897's tailscale has the same defect; flagged there, not fixed here.)

So install to ~/.local/bin as the sandbox user instead, the same correction
#900 made for the harnesses. No sudo, survives container recreation in the home
mount, and upgradeable in place by a running sandbox.

- ToolKind gains "default". herdr 0.7.4 and cloudflared 2026.8.2 become
  kind:"default", installUser:"sandbox", with per-arch pinned URLs and
  sha256 verification into $NPM_USER_PREFIX/bin. Checksums measured by
  downloading both arches, not copied from anywhere.
- provision-harnesses.sh generalizes over both catalogs and becomes
  provision-defaults.sh (OH_PROVISION_DEFAULTS, timeout 180s β†’ 240s). It
  dies rather than reporting success when neither catalog yields a default.
- The Dockerfile loses the herdr RUN, ARG HERDR_VERSION, and the whole
  cloudflared apt block β€” with it the bookworm-suite workaround that existed
  only because Cloudflare publishes no trixie suite. Docker's is now the only
  third-party apt source.
- Both oracles generalize: verify-sandbox-image.sh rejects a baked default
  harness OR tool, reading each catalog out of the image; the boot smoke
  asserts every default in both catalogs resolves under NPM_USER_PREFIX,
  is owned by the sandbox uid, and prints a version.
- The herdr version+checksum pin moves from the Dockerfile to the catalog,
  and herdr-default.test.ts follows it.

Costs, documented in installation.md: an offline first boot on a fresh home
mount now has no herdr, so `oh shell` lands in a plain shell with tmux as the
fallback multiplexer. The entrypoint says so explicitly on failure.

Closes #906
… path

#905 and #907 moved the default harnesses and tools out of the image but left
the four optional harnesses behind. The boundary β€” inside the sandbox the CLI
provisions harnesses and tools β€” has no carve-out for optional ones.

They were not merely leftover. opencode, grok-build, and hermes are all
installUser:"root", and harness.ts:256 installs with stdio:"inherit", so
local-target.ts selects the INTERACTIVE branch: plain `sudo --`, no -n.
/etc/sudoers.d/sandbox has no NOPASSWD, so `oh harness install opencode` hangs
on a password prompt no agent can answer. The build arg was the only working
path, which is why the Dockerfile blocks could not simply be deleted.

All four relocate to the sandbox user, verified by reading the upstream
installers rather than guessing: opencode takes an npm --prefix like
claude-code; grok's installer honours GROK_BIN_DIR; hermes honours
HERMES_INSTALL_DIR and its get_command_link_dir() already picks ~/.local/bin
for a non-root install; deepagents was already sandbox-installed via uv. So no
sudoers change is needed and no security posture moves.

- Delete all four ARG/RUN pairs, the compose build.args block, and the dead
  /opt/grok-build and /usr/local/lib/hermes-agent chowns. INSTALL_HERMES keeps
  its RUNTIME life β€” link-providers.sh vendors the Hermes skill pack from it
  and entrypoint.sh wires auth.json β€” so only its build-arg role goes.
- Remove `buildArg` from HarnessEntry entirely. It was dead metadata: declared,
  set four times, read by nothing. tool-catalog-boundary.sh already banned the
  same field in the tool catalog.
- provision-defaults.sh now reads the full catalog and also installs any
  non-default entry whose install.<key> is true, so declared intent survives a
  fresh home mount. isInstallFlagEnabled already reads oh.json, so this needs
  no new env plumbing.
- verify-sandbox-image.sh widens to "no harness of any kind is baked", and
  gains the inverse for tools: every kind:"baked-in" tool must be present, or
  the check passes on an image missing everything.
- sandbox-compatibility.yml's optional-installer job loses its subject. It now
  boots the image and runs `oh harness install` for each optional harness,
  asserting the binary lands under /home/sandbox/.local β€” the path operators
  actually use, instead of one that no longer exists.

harness.test.ts had a case asserting `cmd === "sudo"`, codifying the very
defect this fixes. It now asserts no install shells out to sudo at all.

Closes #908
@ryaneggz

Copy link
Copy Markdown
Collaborator Author

Verification results

The image ships no harness at all

ok: no harness is baked into the image (claude-code codex pi opencode grok-build deepagents hermes t3code prime-agent)
ok: no default tool is baked into the image (herdr cloudflared)
ok: every baked-in tool is present (docker-cli gh)
verify-sandbox-image: all checks passed

The third line is the one that matters most β€” without it the first two would pass on an image missing everything.

All four optional harnesses install through the CLI, into the home mount

Booted the built image and ran the exact flow the new CI job runs, as the sandbox user with no sudo anywhere:

Harness Resolved path Owner Version
opencode /home/sandbox/.local/bin/opencode sandbox 1.18.25
grok /home/sandbox/.local/bin/grok sandbox grok 0.2.39 (55a20b703)
deepagents /home/sandbox/.local/bin/deepagents sandbox deepagents-cli 0.3.0
hermes /home/sandbox/.local/bin/hermes sandbox Hermes Agent v0.20.6 (2026.8.27)

Nothing leaked into a system path: /usr/local/bin holds none of them, and neither /opt/grok-build nor /usr/local/lib/hermes-agent exists.

Hermes is the one I want to call out. Its relocation was inferred from reading the upstream installer (HERMES_INSTALL_DIR plus get_command_link_dir() picking $HOME/.local/bin for non-root) rather than tested, so it was the highest-risk claim in the PR body. It installs and reports its version correctly.

A near-miss in the CI job I wrote

deepagents --version prints an upstream DeprecationWarning as its first line and the actual version on its third. A version check that read only the first line would fail here. The job greps the whole captured output, so it matches β€” verified explicitly rather than assumed:

$ grep -Eq '(^|[^[:alnum:]])v?[0-9]+([.][0-9]+)+([^[:alnum:]]|$)' <<<"$out" && echo MATCH
MATCH

This is not a size win, and I don't want to imply otherwise

#907 this PR
du -sx / 1,403,552 KB 1,401,476 KB
layer sum 1.94 GB 1.93 GB

~2 MB, which is noise. The build args all defaulted to false, so the default image was never carrying these harnesses β€” what this PR removes is the ability to bake them, not bytes that were being baked. The value here is ownership plus the sudo fix, not image size.

Local checks

EVAL=0 (103 probes, no regressions). npx vitest run 952 passed / 8 failed β€” the known compose-args.test.ts baseline. shellcheck 0, tsc --noEmit 0, npm run build 0.

Separate finding, not fixed here

deepagents-cli is deprecated upstream: "deepagents-cli is deprecated and will not receive further releases. Use the managed-deepagents package (uv tool install managed-deepagents, then mda) instead." The catalog still points at the retired package. Out of scope for this PR; worth its own issue.

The new compatibility job reaches four third-party endpoints. Hermes' own
installer hard-fails the whole install when its internal `npm install` step
blips, which took the job down on a commit that was correct β€” the rerun passed
unchanged, on the same SHA.

A vendor's transient error must not block this repo's merges. One retry absorbs
it. The contract is unchanged: a genuine break β€” wrong user, wrong path, a sudo
prompt β€” fails both attempts and still fails the job.

The probe now asserts both halves, so neither the retry nor the hard failure
after it can be dropped silently.
@ryaneggz

Copy link
Copy Markdown
Collaborator Author

Follow-up: the CI failure was in the job, not the change

The failed run was re-run on the same SHA and passed, verifying all four optional harnesses β€” hermes included, whose own installer logs Hermes Agent itself does not require or retain root access. So the relocation is sound; what I had built was a flaky required check.

18da66d4 retries each install once before failing. I made a merge-blocking check depend on four third-party endpoints, and Hermes' installer hard-fails its entire run when its internal npm install blips (upstream does this deliberately β€” a silent partial install used to be worse). One retry absorbs that.

The contract is unchanged. A genuine break β€” wrong user, wrong path, a sudo prompt β€” fails both attempts and still fails the job. The probe asserts both halves, so neither the retry nor the hard failure after it can be dropped silently:

Mutation Result
retry loop reduced to one attempt caught
retries but never fails hard caught

Now 6/6 green, CLEAN / MERGEABLE.

Separate issue filed

#910 β€” deepagents-cli is deprecated upstream and directs users to managed-deepagents / mda. The catalog still installs the retired package. Left as an issue rather than fixed here: it is not a rename (the binary changes from deepagents to mda, moving binary, verifyArgv, the banner line, and the docs), and there is a prior question about whether the entry should follow upstream or be retired.

The source-level regex I added in #906 cannot distinguish a JS backtick from a
backtick inside prose β€” notInstallableReason has several. It passed only because
every ${...} in the catalog happened to precede the first prose backtick.
Adding a tool below them flips it to a false failure, which is exactly what
happened on the #858 branch.

The per-token ban, with the bash -lc body exempted, covers what is actually
checkable.
@ryaneggz
ryaneggz changed the base branch from task/906-tools-out-of-image to development August 31, 2026 20:38
@ryaneggz ryaneggz changed the title FROM task/908-cli-first-class TO task/906-tools-out-of-image FROM task/908-cli-first-class TO development Aug 31, 2026
development's tree at 744e5c3 is byte-identical to cdf7f42, an ancestor of
this branch, so development adds no content this branch lacks.
@ryaneggz
ryaneggz merged commit ecfda4c into development Aug 31, 2026
6 checks passed
@ryaneggz
ryaneggz deleted the task/908-cli-first-class branch August 31, 2026 21:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant