Skip to content

Add ai.harnesses.experimental and ai.workspaces.experimental - #318

Draft
kajogo777 wants to merge 4 commits into
mainfrom
harnesses-experimental
Draft

kajogo777 wants to merge 4 commits into
mainfrom
harnesses-experimental

Conversation

@kajogo777

@kajogo777 kajogo777 commented Sep 29, 2026 •

Copy link
Copy Markdown
Collaborator

Moves harness-sdk into ai as two experimental areas: ai.harnesses.experimental drives Claude Code and Codex (run, stream, steer, stop, approve, resume, fork, TUI), and ai.workspaces.experimental says where they run (local or Vercel Sandbox).

from ai.harnesses import experimental as harnesses
from ai.workspaces import experimental as workspaces

async with harnesses.claude_code(workspace=workspaces.Local(".")) as agent:
    result = await agent.run("What does this repo do?")
  • New extras claude-code and sandbox, checked at construction (InstallationError). import ai loads neither.
  • Examples in examples/harnesses/, plus examples/apps/afk and examples/apps/deepysec (without its vulnerable fixture).
  • Docs: basics/harnesses, basics/workspaces, and their reference pages.
  • Live tests are opt-in (-m live); plain pytest stays offline.
  • CI: a no-extras job, and claude-agent-sdk in the SDK compatibility job.

Proposal defaults taken: two top-level areas, ToolCall keeps its name, live tests stay out of CI.

Verified: full CI check list, the live suite against real CLIs and sandboxes, and every harness example, afk, and deepysec end to end.

Before merge: vercel/vercel-py#415 is merged and vercel-sandbox now tracks its main; once it's released, set the sandbox extra's floor and drop the git pins. Rerun pytest -m sandbox on the merged API.

Move harness-sdk into ai as two experimental areas. A harness drives a
coding-agent CLI someone else owns (Claude Code, Codex): run, stream
ai.types events, steer, stop, approve tool calls, resume, fork, hand off,
and open the CLI's own TUI. A workspace is where it runs: a local
directory or a Vercel Sandbox microVM.

- Errors gain an Error suffix and split into harnesses and workspaces
  errors modules; both bases subclass ai.AIError.
- claude_code() and VercelSandbox() check their extras (claude-code,
  sandbox) at construction and raise ai.errors.InstallationError.
- codex() refuses sandbox modes that cannot run inside a microVM, and
  codex transcripts name tool calls by native item kind.
- Examples in examples/harnesses, plus the afk and deepysec apps.
- Docs pages, reference pages, skill notes, and contributor guidance.
@vercel

vercel Bot commented Sep 29, 2026

Copy link
Copy Markdown

You must have Developer access to commit code to Vercel Labs on Vercel. If you contact an administrator and receive Developer access, commit again to see your changes.

Learn more: https://vercel.com/docs/accounts/team-members-and-roles/access-roles#team-level-roles

@kajogo777 kajogo777 added the feature New functionality label Sep 29, 2026
@socket-security

socket-security Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Addedpypi/​pytest@​9.1.187100100100100
Addedpypi/​vercel-sandbox@​0.7.094100100100100
Addedpypi/​claude-agent-sdk@​0.2.16099100100100100
Updatedpypi/​vercel-oidc@​0.8.0 ⏵ 0.9.0100100100100100
Addedpypi/​ai@​0.7.0100100100100100
Addedpypi/​pytest-asyncio@​1.4.0100100100100100
Addedpypi/​pytest-timeout@​2.4.0100100100100100

View full report

@kajogo777
kajogo777 requested review from 1st1 and anbuzin September 29, 2026 17:25
@vercel-security-reviewer

Copy link
Copy Markdown

Security review details

vercel/vercel-py#415 merged to main (not released yet). Point the dev
group and the afk and deepysec apps at main; uv.lock pins the commit.

The merged API moved terminal I/O onto `InteractiveSession.stream`, an
anyio byte stream that raises at end of stream instead of returning
b"". Use it, and treat a raise in the ready-marker loops as the end.
Local.pty() started the holder with asyncio.create_subprocess_exec, and
on Linux asyncio kills a still-tracked child when its event loop closes,
so every named pty ended with the process that created it. The holder
now daemonizes (--daemon) and releases its launcher over a pipe once its
socket and pid file exist; Local.pty() waits for the launcher. Reading
the pid file no longer races the holder's cleanup.
The no-extras job installs ai without extras and checks that claude_code() and VercelSandbox() raise InstallationError, and that import ai loads neither optional package. The compatibility job adds claude-agent-sdk at its minimum and latest versions, since the claude-code extra depends on its private transport API.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

feature New functionality

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant