Repository navigation
Conversation
…ildren - version 0.1.3 -> 0.1.5. The native aegis is v0.1.5 (pilot-protocol/aegis fix/aegis-lifecycle, ce5be55): nothing it starts (the L2 judge server, the model download) outlives it any more. - artifacts: all four platforms. darwin/amd64 is new: 0.1.3 had no darwin/amd64 native, so v1.12+ pilotctl refused to install the app on Intel Macs and older pilotctl installed the linux/amd64 ELF, which fails with "exec format error". - artifacts move from the dev R2 bucket (pub-2328865f…) to the prod bucket (pub-f09f9a4e…), under io.pilot.aegis/0.1.5/<os>-<arch>/. - drop the submission's own aegis.help. The generated <ns>.help handler is registered under the same name and replaced it, so `aegis --help` was unreachable and the manifest listed aegis.help twice. The four native tarballs (sha256 + size in artifacts[]) must be on the prod bucket, and the four adapter bundles built from a template that has the cli lifecycle fixes, before this merges. See the PR for the order. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
The darwin tarballs the first commit pinned (b9fb3077…, a2351b01…) were local build outputs that are gone; they were never uploaded, so nothing could ever serve those bytes. Rebuilt from aegis 8ceabce with the same flags and packaging. The Linux natives reproduce byte for byte (same sha256 as before); the Mach-O ones differ only in LC_UUID and the ad-hoc signature page hash, which ld64 derives from the build location. darwin/arm64 d3541bf9…be9975 470891 B (bin 079fd32d…) darwin/amd64 bb46a068…c3077b 531001 B (bin 78223796…) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What changes
8ceabce): nothing aegis starts outlives itpub-2328865f…pub-f09f9a4e…aegis.helpaegis --helpmethod was shadowed by the generated discovery handler, so it could never be reached.darwin/amd64
macos-x86_64release asset.io.pilot.aegis has no bundle for this platform (darwin/amd64).exec format error.cargo build --release --target x86_64-apple-darwin(Mach-O x86_64, minos 10.12), run under Rosetta below.Natives (
artifacts[])Built from aegis
8ceabce(tree-identical toce5be55):cargo buildfor the two macOS targets;cargo zigbuildforx86_64-unknown-linux-muslandaarch64-unknown-linux-musl, static, like the 0.1.3 natives;--remap-path-prefix, so no local paths are embedded.They are packaged as
aegis-0.1.5-<os>-<arch>/bin/aegis, the same layout andexec_pathscheme as 0.1.3. The tarballs are deterministic: fixed mtime 1790244350, uid/gid 0, no owner names, gzip mtime 0. Repackaging the same binaries gives the same sha256.bin/aegissha256d3541bf9…be9975079fd32d…6b211bb46a068…c3077b78223796…71a57700e70fd…44273d76c2fb44…1f87338df7c1a…473a0674aa3f17…ed254To ship CI-built binaries from a
v0.1.5tag instead, repackage them the same way and updatesha256/sizehere.Verified (TEST-ONLY key, nothing uploaded or signed with a real key)
Checks on the submission:
pilot-app verify-submission: VERIFY OK, 4 platforms,native-delivery (install.json) … 4 asset(s).pilot-app verify-update: UPDATE GATE OK, 0.1.5 ≥ 0.1.3.pilot-app verifyon the four built bundles: VERIFY OK.I built the bundles from this submission with
publish.BuildBundle, from a scratch template: #111, then #116, then #117. The adapter binaries are byte-identical to the ones exercised below. For the runs, the adapter staged the natives over HTTP from a local mirror of the exact tarballs above; that is the only difference from a real install. The lifecycle harness drove the app: darwin/amd64 under Rosetta, Linux indocker --init.aegis.help×200aegis.version×200, which execs the staged nativeaegis.status×200 p50 (0.1.3 on darwin/arm64: 226 ms)install-modelspast the 60 s timeoutinstall-modelsin flighthelp×20 (0.1.3: exit 1)Which template
The same aegis checks, built from #114's head (808243f), show:
aegis.statusp50: 41.8 ms, with one childguard process per call.#116 alone, without the SIGTERM-first line from #117/#114, leaves the download running (
ppid=1) on macOS when the app is stopped mid-call. Details are in the comments on #114 and #116.Catalogue follow-up (not in this PR)
The per-platform entries, the proposed
metadata.jsonand the upload steps are prepared outside the repo. The bundle sha/size values there come from the TEST-ONLY build, so they are placeholders. Things the catalogue PR will need:fs.write $APP, so the lint marks the app stateful and refuses the bump without it (checked locally). Approve with{"id":"io.pilot.aegis","version":"0.1.5",…}incatalogue/stateful-apps.json, or with the PR label.$APPholds only the staged native; aegis keeps its own state in the daemon user's~/.aegis. With that approval, the lint's bundle checks pass on the four bundles.metadata.json.publish-rich-from-r2.shreuses the existingcatalogue/apps/io.pilot.aegis/metadata.jsonand refreshes only publisher,size.bundle_bytes, the demo and next_steps. The duplicateaegis.help, the changelog andinstalled_byteshave to be fixed by hand, andmetadata_sha256updated.Update 2026-09-24: darwin pins rebuilt, re-verified
Why the darwin pins changed (commit 9d4f860). The darwin tarballs the first commit pinned were local build outputs. They were never uploaded, and they no longer exist, so no server could ever have served those bytes. I rebuilt all four natives from aegis
8ceabcewith the same flags (--remap-path-prefix,--locked, rustc 1.96.0) and the same packaging.700e70fd…,38df7c1a….cmp -lshows 48 bytes, and no path strings. ld64 ties that UUID to the build location.natives/<os>-<arch>/aegis-0.1.5-<os>-<arch>.tar.gzfrom the prepared publish dir, or CI-built natives repackaged the same way (then updateartifacts[]again).Re-verified. The template is #116's head
a0d7665(it includes #111 and #114). The bundles were built from this submission withpublish.BuildBundleand a TEST-ONLY key.pilot-app verifypasses on all 4 bundles.verify-submission: VERIFY OK, 4 assets.The adapter staged the exact native tarballs above from a local HTTP mirror; install.json URLs are the only difference from a real install. A rewritten lifecycle harness drove the app: sandbox-exec on macOS (darwin/amd64 under Rosetta),
docker --initon Linux.ppid=1after a flagged scan (both SIGTERM and SIGKILL of the app), and left the curl withppid=1in 2/2 in-flight rounds.Offline,
aegis.versionreturns a clean IPC error (install assets: stage: fetch …) until the native can be downloaded.🤖 Generated with Claude Code