fix(runner): align Codex ACPX admission digest

This commit is contained in:
Dotta 2026-09-03 02:20:11 -05:00
parent a9c5d81af6
commit c7731dc7dc
4 changed files with 47 additions and 4 deletions

View File

@ -98,7 +98,7 @@ impl AcpxProviderDescriptor {
"1.6.2",
Some("@openai/codex"),
Some("0.148.0"),
"sha256:94049b3e3c3aee87de62703786e4fa81d031d7bd979f99bdf516d84f28791a79",
"sha256:7a923b3829884d3cabcc9659d22cace3f86813e7bfffc90974b10140a45bc400",
),
"pi" => return Err(DurableRunnerError::invalid(
"ACPX agent pi is not executable through the verified runnerd provider boundary",
@ -1337,7 +1337,7 @@ mod tests {
"1.6.2",
json!("@openai/codex"),
json!("0.148.0"),
"sha256:94049b3e3c3aee87de62703786e4fa81d031d7bd979f99bdf516d84f28791a79",
"sha256:7a923b3829884d3cabcc9659d22cace3f86813e7bfffc90974b10140a45bc400",
)
};
json!({

View File

@ -15,7 +15,7 @@ use serde_json::{json, Value};
use sha2::{Digest, Sha256};
const CODEX_ACPX_DIGEST: &str =
"sha256:94049b3e3c3aee87de62703786e4fa81d031d7bd979f99bdf516d84f28791a79";
"sha256:7a923b3829884d3cabcc9659d22cace3f86813e7bfffc90974b10140a45bc400";
fn temporary_directory(label: &str) -> PathBuf {
let nonce = SystemTime::now()

View File

@ -253,7 +253,7 @@ try {
claude:
"sha256:9d73d1f0f121fb96cc8badb28c22d5bff02d8582eb2e40360a81c189e1b9422a",
codex:
"sha256:94049b3e3c3aee87de62703786e4fa81d031d7bd979f99bdf516d84f28791a79",
"sha256:7a923b3829884d3cabcc9659d22cace3f86813e7bfffc90974b10140a45bc400",
},
artifacts: {
nodeCommand: {

View File

@ -34,6 +34,28 @@ const nodePatch = await readFile(
new URL("../../../patches/node@24.11.0.patch", import.meta.url),
"utf8",
);
const qualifiedProfiles = await readFile(
new URL("../src/drivers/acpx/qualified-profiles.ts", import.meta.url),
"utf8",
);
const runnerdAcpxBackend = await readFile(
new URL(
"../runner/crates/runner-core/src/acpx_provider_backend.rs",
import.meta.url,
),
"utf8",
);
const providerPackBuilder = await readFile(
new URL("../scripts/build-provider-pack.mjs", import.meta.url),
"utf8",
);
const nativeSessionExecutor = await readFile(
new URL(
"../../../server/src/services/native-runtime/native-session-executor.ts",
import.meta.url,
),
"utf8",
);
test("the runner pins every qualified ACPX production dependency", () => {
assert.equal(runnerPackage.dependencies.node, "24.11.0");
@ -53,6 +75,27 @@ test("the runner pins every qualified ACPX production dependency", () => {
);
});
test("the patched Codex ACP command digest stays aligned across launch boundaries", () => {
const profileMatch = /agent: "codex"[\s\S]*?commandDigest:\s*"(sha256:[a-f0-9]{64})"/.exec(
qualifiedProfiles,
);
assert.ok(profileMatch, "qualified Codex ACPX profile digest");
const digest = profileMatch[1];
assert.match(
runnerdAcpxBackend,
new RegExp(`"codex"[\\s\\S]*?${digest}`),
);
assert.match(
providerPackBuilder,
new RegExp(`acpxProfileDigests:[\\s\\S]*?codex:[\\s\\S]*?${digest}`),
);
assert.match(
nativeSessionExecutor,
new RegExp(`REMOTE_PROVIDER_PACK_PROFILE_DIGESTS[\\s\\S]*?codex:[\\s\\S]*?${digest}`),
);
});
test("the package exposes only the reviewed runner CLI binaries", () => {
assert.deepEqual(runnerPackage.bin, {
"paperclip-runner-eval-session": "./dist/cli/eval-session.js",