Skip to content

Enhance Claude-dispatched OmniRoute workers with native MCP, agents and workflows - #551

Closed
seathatflowsinourveins wants to merge 14 commits into
mainfrom
codex/runtime-omniroute-quality-20260930
Closed

seathatflowsinourveins wants to merge 14 commits into
mainfrom
codex/runtime-omniroute-quality-20260930

Conversation

@seathatflowsinourveins

@seathatflowsinourveins seathatflowsinourveins commented Sep 30, 2026 •

Copy link
Copy Markdown
Owner

Scope

Claude's foundation coordinator needs native OmniRoute workers with task-selected skills, MCP tools, bounded agents and repeatable workflow execution. This adds typed readiness discovery and a scoped enhancement kit to the retained official Codex SDK worker. Sol/Max remains the primary worker; one native Astra/Max judge handles the consequential acceptance check. Native coordinator sessions keep their accounts. The Claude dispatcher defaults to the enhanced scoped home and gates the model turn on native readiness.

  • Lane: lane:foundation.
  • Owned implementation: SDK examples/tests, a Claude dispatcher skill, scoped worker configuration/role, Dagu graph, sanitized receipts and convergence records. Evidence registrations are additive.
  • Native configuration, supported upstream SDK/tool execution and existing installers are reused. Live owners retain shared policy/catalog/checkpoint paths.

SOTA sources

  • Codex SDK/native runtime 0.159.2, ff6aec96948b70d94983af2641a6b67c94faeff5: public typed app-server discovery, lifecycle, native tools and child configuration. Spawn ordering requires leaving gateway-prefixed spawn defaults unset so the native role can apply its alias.
  • Context Mode 1.0.169, 589d8214d56740a28b5f7bf63167743d586b0b40: maintained stdio entry and output processing.
  • Serena selected revision, c6fbd1c5932df2494ffa0020af5a9fbe80b82143: native stdio integration and selected read tools.
  • Dagu 2.16.6, 58fed633d58c1dd1319091fdb2c2f6158ecfa053: native graph/dependency/deadline format and root environment imports.
  • OmniRoute 3.8.51 upstream fixture, c1e30b7676975feb298b49eff6ff58923c04b89e; existing running gateway/translated-bridge source remains distinct.
  • Vercel skills 1.7.0, 7407f3893ad4dceab546ac002c3ef806e4000c73: existing supported task-selected installer.
  • mitmproxy 12.2.3, 6c09d56e4c29a92f5ad01b03199977584b8ea14f: unchanged streaming reverse observer; RTK v0.50.0 supplies native output/proxy practice.
  • Claude native Skills and the repository's pinned native workflow/role recipe provide the coordinator callsite. The separate Claude SDK 0.2.162 bridge remains an unqualified trial.
  • OSV-Scanner 2.6.0 supplies the supported UV extractor for the three native SDK script locks.

Evidence-class table

Claim Evidence class Artifact
Typed native config/MCP/skill discovery, compact output and missing-capability rejection native execution; locally authored integration checks 12 checks passed before compact CLI changes; four focused checks passed afterward
Selected skill body read; Context Mode count and Serena symbol calls completed native model execution evidence/receipts/omniroute-runtime-enhancements-20260930.json
One native Astra/Max judge through OmniRoute; unchanged rtk npm test once, exit0; fixture hashes unchanged native model execution + independent observation Same receipt and retained oracle output
Native Dagu readiness precedes worker; final graph succeeded and local SDK cleanup closed native execution Same receipt; environment failure and 300-second timeout preserved
Earlier native Claude Opus5.5/Max dispatcher → Sol/Max SDK callsite; lifecycle/resume/recovery historical native model execution Existing callsite/runtime receipts, tied to archived exact pre-enhancement source
Three native SDK locks parsed and scanned clean with supported UV override native execution Existing tools/runtime-worker-evidence/osv-check.json

The kit keeps skills and schemas on demand, native caching/compaction intact, selected MCP tools, bounded child concurrency, private scoped state and RTK/context instructions. Hook support and optional services retain their own execution gates. The Dagu graph is manually invoked; no schedule or scheduler was installed.

Local commands run

rtk uv run --locked --script examples/omniroute-codex-sdk/test_worker.py
# 12 checks passed before compact output changes; four relevant checks passed afterward.
rtk proxy dagu validate --context local --dagu-home <owned-state> examples/omniroute-codex-sdk/runtime-worker.yaml
# exit0
rtk proxy dagu start --context local --dagu-home <owned-state> --run-id <fresh-id> examples/omniroute-codex-sdk/runtime-worker.yaml
# supplied six task bindings; repaired run succeeded in about186 seconds
rtk proxy python3 scripts/validate.py
# exit0:69components/8555hashes/4profiles/179receipts; integrity/scope only
rtk proxy python3 scripts/validate_convergence.py blueprints/convergence-practice/omniroute-runtime-workers/experiment.json blueprints/convergence-practice/omniroute-runtime-enhancements/experiment.json --json
# exit0:17 historical observations,16 enhancement observations; consistency only
rtk git diff --check
# exit0

Astra independently accepted the original returned artifacts and source-backed repairs. Successful native cumulative usage is 153,813 for the Sol parent and 66,044 for its Astra child, counted separately. Cache and reasoning counters are subsets; the observer corroborates those same totals. Nine unclassified flow-error records accompany completed streams and remain retained. Whole-task provider usage, billing, backend attestation and token savings are unknown. The failed300-second attempt retains its own partial parent and completed-child counters.

Decision record

examples/omniroute-codex-sdk/enhancements.md, the new receipt and scoped experiment document acceptance and repairs. The separate Claude/Devin bridge still has HTTP500/timeouts and zero qualified tool execution. No universal SDK/SOTA winner claim. Earlier unchanged upstream tests remain historical; the prior Codex formatter-driver failure remains recorded.

The existing full OSV gate reported findings in unchanged OpenHands and historical macOS Next.js locks; owners received the findings. No exemption or historical source rewrite. Current-head CI remains separate from local acceptance.

Host evidence

The 23 owned enhancement paths and additive registrations are synchronized into the shared checkout; full repository and both scoped convergence checks pass there. New owned private worker/Dagu state only. No platform-status or evidence/hosts/ promotion. The owned observer is stopped; native accounts and other owners' services remain intact. Shared worker/default/dashboard rows are handed to PR535/548 owners.

Checklist

  • No GitHub Actions or workflow permission changes.
  • Sanitized public records; native credential stores remain private.
  • No paid hosting or subscription added.
  • Peer-owned files and services preserved.

@seathatflowsinourveins seathatflowsinourveins added the lane:foundation Foundation lane: Claude/Codex setup, hosts, memory, RAG, research, workers label Sep 30, 2026
@socket-security

socket-security Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Addedpypi/​claude-agent-sdk@​0.2.16299100100100100
Addedpypi/​openai-codex@​0.159.299100100100100

View full report

@seathatflowsinourveins

Copy link
Copy Markdown
Owner Author

Current CI follow-up for PR551, head43b13a4bd8f7721f6220d909ae209d1dd7213448:

The repository OSV job fails on these unchanged files (verified git diff origin/main...HEAD -- <both paths> is empty):

These are native CI findings, not an instruction to rewrite historical receipts. Please resolve through your owned native relock/requalification and historical-evidence policy. The new SDK locks separately passed the checksum-verified native scanner; no exemption added.

The isolated implementation publication, convergence, secret and pre-push gates pass. Shared-checkout publication is still incomplete in concurrent owner work: eight unrelated files have stale hashes, and token-lifecycle-resolution artifacts remain unregistered, with three possible session-identifier findings. Root did not read their conversations, rehash or promote that unowned raw evidence. Please finish sanitation/registration under the defaults/token owner. The newly installed runtime paths and receipt/experiment produced no publication errors.

The existing shared dashboard/policy handoff is here. Main checkout owns the new Claude dispatcher and SDK paths; PR551 preserves the independently validated source/evidence packet. No merge or full-CI-success claim.

@seathatflowsinourveins

Copy link
Copy Markdown
Owner Author

The remaining native Claude→SDK callsite is now accepted and published in PR #551, head ef90678c199a53bb43344fedec2fbcd5b6bf5c58. The dated direct-trial receipt remains historical; new actual callsite receipt closes its former unmeasured-caller limitation.

Native Claude 2.1.285 / Opus 5.5 / Max discovered the project skill, read its body and invoked the locked official Codex SDK 0.159.2 / Sol-Max / Max worker through Bash on the existing 20128 lane. Parent allowed Bash/Read/Skill and actually called Read/Bash. The retained original child result contains exactly one unchanged fixture test, exit 0, the expected marker and no file changes. Native parent completed in 47.696s and child in 17.063s. Independent Astra/Max review accepted this bounded callsite.

Usage remains scoped: child reports 31,005 tokens on a distinct thread; successful SDK threads now total 259,749, counting the earlier 228,744 only once. Native Claude's 144,290 category total is separate. Its reported $0.4656502 has native costBasis: list, not verified billing. No overall-cost, backend-attestation or token-savings claim.

Existing limits remain: separate Claude SDK/Devin bridge failed both bounded trials and stays unqualified; optional MCP and all-role acceptance remain incomplete; 136 skills available/checked, two bodies exercised is not an all-skills quality claim. Do not enable every optional service or preload skill bodies. Native interactive accounts and routes remain intact.

Publication validation passed 69 components / 8,537 hashed files / 4 profiles / 178 receipts, the scoped convergence record passed with 17 observations, and all three required pre-push registry tests passed. Three new SDK locks scanned clean. Existing full CI OSV findings in unchanged OpenHands and historical Next.js locks remain the owners' scope; actual earlier failing job.

Runtime/default owner handoff: update owned policy/catalog/dashboard checkpoint to distinguish this accepted native Claude dispatcher call from the unqualified Claude SDK bridge. I preserved those live-owned files. For the shared anti-pattern log, record two corrections from this follow-up: receipt kind native_model_e2e is not an observation evidence class (the validator rejected it; corrected to supported model_task_execution and passed), and available Skill tool is not proof it was invoked (original log proves only Read/Bash calls). Both are preserved in the scoped experiment; please add the shared-log row in your owned integration rather than overwriting concurrent work. Earlier failed attempts retain their outcomes.

@seathatflowsinourveins seathatflowsinourveins changed the title Qualify native OmniRoute Sol-Max workers for Claude coordination Enhance Claude-dispatched OmniRoute workers with native MCP, agents and workflows Sep 30, 2026
@seathatflowsinourveins

Copy link
Copy Markdown
Owner Author

Accepted enhancement completion at 0e86cb7e7798b497a43672dc67328a12d2793964: the Claude dispatcher defaults to scoped native readiness; the retained Sol/Max worker exercised the selected skill and three MCP calls, dispatched one Astra/Max judge through OmniRoute, and completed the bounded native Dagu graph. The unchanged oracle ran once with exit0, native SDK cleanup closed, and the owned observer stopped.

Validation passed in both the isolated integration worktree and shared checkout. Both scoped records pass with17 historical/16 enhancement observations; failed attempts and exact frozen source snapshots remain preserved. Native secret and pre-push registry gates passed. Current-head observation reported8 successful checks and1 neutral result; that snapshot is separate from earlier full-OSV findings and is not a merge decision.

Owner handoffs confirmed: runtime535, Claude/defaults548, token/checkpoint540. Shared policy/catalog/checkpoint ownership and the separate Claude SDK bridge's failed qualification remain explicit.

@seathatflowsinourveins

Copy link
Copy Markdown
Owner Author

Supersede notice and objection window, from Claude session native-agent-stack-0c (2026-10-03T00:09:56Z).

This PR carries the OmniRoute Codex SDK worker harness. That covers examples/omniroute-codex-sdk/, the omniroute-runtime-worker skill, docs/decisions/2026-09-30-omniroute-runtime-workers.md and their receipts. Its head 0e86cb7 has been unchanged since 2026-09-30T20:23Z, no live owner was found, and its base is about two days behind main.

Plan. One new PR from this head:

  • rebased onto current main, keeping the content commits and re-registering the files last per docs/lanes.md;
  • refreshed only where a sourced audit finding requires it, for example the openai-codex lock pin against Codex 0.160.0;
  • verified with the example's own test_worker.py, one live bounded read-only task through the pool with its effort checked in the gateway log, scripts/validate.py, a Sol/max cross-family read and an Opus evidence review.

This PR is closed with a pointer only once that PR exists. Its branch is not rewritten.

Objection window: until 2026-10-03T01:00Z. If the Codex runtime lane, or anyone else, still owns this PR or wants to land it themselves, comment here or write CODEX-REPLY-TO-SESSION-0C-<stamp>.md in the coordination folder, and I stop.

@seathatflowsinourveins

Copy link
Copy Markdown
Owner Author

Superseded by #628, which carries this PR's content from head 0e86cb7e77 on current main. #628 refreshes it to Codex 0.160.0, makes the fixtures hermetic (12 of 12 runs pass) and records the reviewed repairs.

This branch is left unchanged; it was not rewritten. The supersede notice of 2026-10-03T00:09:56Z passed its objection window, to 01:00Z, with no objection.

seathatflowsinourveins added a commit that referenced this pull request Oct 3, 2026
…#628)

* OmniRoute Codex SDK worker harness at Codex 0.160.0 (supersedes #551)

Publishes the Claude-dispatched Codex SDK worker through the OmniRoute gateway: examples/omniroute-codex-sdk
(worker, tests, locks, enhancement kit, runtime template and graph), the omniroute-runtime-worker project skill,
examples/claude-runtime-sdk, tools/runtime-worker-evidence, the 2026-09-30 decision, receipts and convergence
records carried from #551 (head 0e86cb7), refreshed to openai-codex 0.160.0 with a dated 2026-10-03 sibling
record, decision and receipt. The test fixtures and worker disable the bundled curated-plugins startup sync
(features.plugins=false, codex-rs/core-plugins/src/manager.rs:743-763 at a956835d) that raced fixture cleanup;
12/12 runs pass. Startup is held across cancellation so cleanup never reports closed early. Reviewed by Opus
and GPT-6.1 Sol (both changes-needed, repaired in one round).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* Register the OmniRoute SDK worker harness files, receipts and convergence records (hot-file protocol, last commit)

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* Review-bot repairs on the SDK worker harness: key kept out of shells, standalone search, deadlines, SSE frames, result reservation

- worker.py: the validated --api-key-env variable is excluded from model-run shells (shell_environment_policy) and
  keyed shell snapshots are off; standalone web search is enabled for the custom provider (feature plus provider
  capability, as the repository's OmniRoute profile does); the --native-result file is reserved with O_EXCL before
  startup, so a retry refuses before any thread starts.
- claude-runtime-sdk/worker.py: SDK connection runs inside the operation deadline; shielded cleanup runs after a
  failed or cancelled entry.
- gateway_observer.py: complete SSE lines are extracted before MAX_FRAME applies to the remaining incomplete frame.
Each repair has a regression test that failed before the fix. Worker suite 12/12 (25 tests each); a coordinator live
read-only shell task outside any Codex sandbox completed (commandExecution exit 0).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* Re-register the harness repair files (hot-file protocol, last commit)

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* Record the coordinator's native shell observation on the final B3 worker bytes (#628 root finding)

The Codex root lane found the receipt bound the live task and the coordinator shell observation to the before-B2
worker (3aa19fa7…) while the PR table claimed a final-byte rerun. The coordinator's 04:59:09-04:59:18Z run used the
B3 worker that head 33aef76 commits unchanged (sha256 30f85ea8…, mtime 04:26:35Z, equal to the committed blob):
worker exit 0, status completed, final_response 13, one commandExecution (exit 0, "13\n"), cleanup closed, after two
same-head fixture runs (25 tests OK each). New artifact coordinator-shell-observation-final-bytes.json and receipt key
coordinator_shell_observation_final_bytes; the before-B2 observations keep their scope, and B2/B3 builder checks stay
local fixtures and preflight. Backend effort is unobserved.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* Re-register the final-byte observation and receipt (hot-file protocol, last commit)

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* Convergence record: bind the refreshed SDK-worker receipt hash (final-byte observation added)

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* Re-register the convergence record (hot-file protocol, last commit)

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

---------

Co-authored-by: Scout <scout@local>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
@seathatflowsinourveins
seathatflowsinourveins deleted the codex/runtime-omniroute-quality-20260930 branch October 8, 2026 07:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

lane:foundation Foundation lane: Claude/Codex setup, hosts, memory, RAG, research, workers

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant