openpencil/packages/harness
Danila Poyarkov daef57d52d
build: update dependencies (#873)
* build: update dependencies

Update the AI SDK providers, Vue, Reka UI, Valibot, Zod, es-toolkit,
CodeMirror, Storybook, Playwright, Hono and other dependencies to their
current releases, consistently across workspaces.

The Tauri plugin packages must match their Rust crates, and the new plugin
crates require Tauri 2.12, so Cargo.lock, @tauri-apps/api and the Tauri CLI
move to 2.12 as well.

* build(harness): update the AI SDK harness packages

@ai-sdk/harness 1.0.74 pinned ai 7.0.67, so the workspace carried a second
copy of ai next to the root one; 1.0.138 depends on the same ai release.

The Pi adapter no longer takes a model: HarnessAgent does. The settings
were spread from untyped records, so the compiler could not reject the
stale key and the chosen model would have been dropped; they are plain
literals now.

PiAuthOptions is now PiAuthenticationMode, and auth accepts an environment
record. Pass the gateway key that way instead of writing it into the
process-wide environment while a session is created. Derive the thinking
level from the adapter's settings, which adds 'max'.

* build: hold vue-tsc at 3.3.11

vue-tsc 3.3.12 no longer sees a v-slot binding inside a component that
also has an event listener, so check:vue reports "Cannot find name
'control'" in MCPConnectionEditor and ProfileEditor. 3.3.11 checks them
cleanly.

* fix(ai): keep retryability for provider errors reported mid-stream

From ai 7.0.80 a provider error after the response stream starts is a StreamProviderError rather than an APICallError, so classifyAIChatError lost its isRetryable.

* feat(desktop): accept updates only when signed for their version

Tauri CLI 2.12 records the app version in each updater signature, and
updater 2.13 checks it against the version latest.json announces. With
requireSignedVersion it also rejects signatures that carry no version, so a
tampered manifest cannot pair a newer version number with an older, still
validly signed bundle.

Release assembly now fails when a signature does not name the version
being released, instead of shipping one that installed apps would reject.

* docs: note the dependency update's security fixes in the changelog

* feat(ai): recommend the latest models

The provider packages now know Claude Sonnet 5.5 and Opus 5.5 and the GPT-6
series. Make Sonnet 5.5 and GPT-6.1 Sol the defaults, list Opus 5.5, Fable
5.1, GPT-6 Astra and GPT-6 Luna, and replace the two free OpenRouter models
that OpenRouter no longer serves.

* build: align the fig package's valibot with the workspace
2026-10-04 12:48:24 +00:00
..
src build: update dependencies (#873) 2026-10-04 12:48:24 +00:00
tests feat(ai): add HarnessAgent sidecar foundation (#560) 2026-08-19 17:41:10 +03:00
AGENTS.md docs: route contributors through per-domain guides and ship npm license text (#785) 2026-09-29 01:02:06 +04:00
package.json build: update dependencies (#873) 2026-10-04 12:48:24 +00:00
README.md refactor(ai): ship Harness as optional companion (#561) 2026-08-19 20:04:35 +03:00
tsconfig.json feat(ai): add HarnessAgent sidecar foundation (#560) 2026-08-19 17:41:10 +03:00
tsdown.config.ts feat(ai): add HarnessAgent sidecar foundation (#560) 2026-08-19 17:41:10 +03:00

@open-pencil/harness

Optional Node companion runtime for coding-agent harness sessions. It owns the backend-neutral session lifecycle, opaque resume-state persistence, and the JSONL sidecar protocol used by host applications.

The first backend uses AI SDK HarnessAgent, Pi, and local just-bash. Pi runs in the Node host process; just-bash provides an isolated in-memory workspace and shell without requiring cloud infrastructure.

Current scope

  • Backend-neutral, streaming session service.
  • Atomic, bounded persistence of opaque harness resume state.
  • JSONL stdio sidecar transport.
  • Pi + just-bash backend.

The package is installed as an optional companion CLI for the desktop application. It is not bundled into every Tauri build; install @open-pencil/harness globally to make the openpencil-harness command available. Credentials are supplied to the companion process at runtime and are never written to resume-state storage.

Local sandbox limitation

just-bash is process-local and in-memory. Multi-turn sessions work while the sidecar remains alive, but its sandbox cannot be reattached after a process restart. Persisted opaque state establishes the session contract; durable restart recovery requires a persistent sandbox provider in a later integration.