feat: add Claude Sonnet 5.5 to bundled model catalog - #6110
Yeachan-Heo wants to merge 8 commits into
Conversation
…acOS On macOS, the ownership ledger previously exited(70) when: 1. Process::from_pid() returned None for a child that had already exited 2. darwin_unique_id() returned None for entitled/setuid children (EPERM) 3. Ledger write failed on a live child This behavior caused the shell runtime to crash on almost every bash tool call on macOS, even though the spawned processes were working correctly. Changes: - Introduce observe_pid() corroboration: when from_pid fails, query the kernel to determine if the child is genuinely absent or just temporarily unobservable. If confirmed absent/reaped, record the pid like Linux does. - Allow unique_id to be absent for live children: if the child is confirmed live but unique_id cannot be read (EPERM for entitled processes), record an empty unique_id instead of crashing. - Keep exit(70) only for genuine integrity failures: ledger write errors and HMAC computation errors on a live, identifiable child. - Update decision logic to be testable: extract observed_spawn_incarnation() function for unit testing without spawning actual processes. Add regression tests: - spawn_identity_decisions(): unit test covering all observation outcomes - spawned_reaped_child_does_not_require_ledger_identity(): macOS-specific test that spawns /bin/true and observes the behavior after reaping - spawn_ledger_write_failure_exits_70(): verifies exit(70) still triggers on real integrity failures - fast_and_entitled_children_preserve_runtime_and_signed_ledger(): integration test (macOS only) that spawns /bin/true in a tight loop 200x and runs /usr/bin/top -l 1 to ensure the runtime stays alive Fixes #6085
…ldren - Remove the restriction that rejected Darwin records with empty darwinUniqueId - These records now tracked by pid:incarnation in ownedProcesses for cleanup at retirement - HMAC verification already handles empty unique_id (verifies pid:incarnation:) - Complements pi-shell handling of fast-exiting entitled children - pi-shell/process.rs: Add comment explaining pid reuse protection in unique_id() - The final live_bsdinfo() check verifies start time hasn't changed - For entitled children denying bsdinfo access, caller must corroborate via other means - Re-check happens after read to allow incarnation-only identity records - Add tests for authenticateOwnershipRecord: - Darwin record with unique id (unchanged behavior) - Darwin record without unique id (new incarnation-only tracking) - Bad signature (rejected)
…n registration - When no unique id is available (signed id undefined AND uniqueIdentity(pid) undefined), call retainOwnedProcess() and return true instead of false in track(). This prevents scanOwnership from failing and the periodic timer from SIGKILL-ing the supervisor. - Add separate trackGuardian() method for strict guardian registration at startup. Only the guardian registration requires a unique id; regular process tracking accepts incarnation-only records. - Export DarwinAncestryTracker type and createDarwinAncestryTracker function to enable unit testing. - Accept optional uniqueIdentity injection in createDarwinAncestryTracker so the tracker decision logic can be tested without real libproc calls. - Add comprehensive unit tests: - incarnation-only record with uniqueIdentity -> undefined keeps scan ok and retains process - guardian registration without unique id still fails - track() succeeds and retains process when uniqueIdentity returns undefined - trackGuardian() requires a unique id (signed or resolved) Fixes part of #6086
…protected shell-guardian changes
…ateOwnershipRecord cargo fmt -p pi-shell and biome --write for the check:rs / biome blockers (probepark, #6086). Use the previously unused authenticateOwnershipRecord import for the positive path the reviewer flagged as untested: an incarnation-only record authenticates, and a Darwin unique id is bound into the signature (a record forged by adding one is rejected).
…bility Both darwin_spawn_ledger test and spawned_reaped_child_does_not_require_ledger_identity test were failing on macOS because /bin/true does not exist on macOS. The correct path is /usr/bin/true which is present on macOS. Fixes macOS-gated tests: - crates/pi-shell/src/shell.rs: spawned_reaped_child_does_not_require_ledger_identity - crates/pi-shell/tests/darwin_spawn_ledger.rs: fast_and_entitled_children_preserve_runtime_and_signed_ledger
Add claude-sonnet-5-5 model entries to the following providers: - anthropic - github-copilot - jetbrains-junie - kiro - opencode-zen - venice Mirror Sonnet 5 metadata (context window, max output tokens, vision, thinking). Pricing: $2/M input, $10/M output, $0.20/M cache read (same as Sonnet 5). Add verification test to ensure Sonnet 5.5 is bundled across all providers. Note: Exact model ID (claude-sonnet-5-5 vs claude-3-5-sonnet-20260928) is inferred from naming patterns. Runtime discovery via Anthropic /v1/models API will resolve the actual model ID when available. See compatibility gate requirements in the PR.
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
💡 Codex Reviewgajae-code/packages/coding-agent/src/exec/bash-shell-guardian.ts Lines 192 to 196 in f4e94b6 When Darwin denies the unique-ID query, this branch reports successful tracking without adding the process to https://github.com/Yeachan-Heo/gajae-code/blob/f4e94b6ac6b7a5becb0622ccf6ec8415be4f9a0a/packages/ai/src/models.json#L5660-L5661 The commit explicitly states that AGENTS.md reference: AGENTS.md:L22-L22 gajae-code/packages/coding-agent/test/bash-shell-guardian.test.ts Lines 107 to 109 in f4e94b6 any casts from the guardian tests
This test and several following cases cast minimal process stubs to AGENTS.md reference: AGENTS.md:L124-L124 gajae-code/packages/coding-agent/test/bash-shell-guardian.test.ts Lines 164 to 166 in f4e94b6 There is no mock being installed before this AGENTS.md reference: AGENTS.md:L126-L126 gajae-code/packages/coding-agent/test/bash-shell-guardian.test.ts Lines 174 to 178 in f4e94b6 On every non-Darwin test runner, AGENTS.md reference: AGENTS.md:L167-L171 gajae-code/crates/pi-shell/src/shell.rs Lines 71 to 74 in f4e94b6 This model-catalog commit also changes macOS process identity handling, guardian containment, daemon generations, and notification manifests—an independent runtime fix with separate failure and rollback risks that is absent from the commit description. Split these changes into atomic commits so the catalog update and process-control fix can be reviewed, reverted, and released independently. AGENTS.md reference: AGENTS.md:L175-L175 https://github.com/Yeachan-Heo/gajae-code/blob/f4e94b6ac6b7a5becb0622ccf6ec8415be4f9a0a/packages/ai/src/models.json#L5660-L5664 The commit changes shipped behavior in both AGENTS.md reference: AGENTS.md:L201-L201 ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
|
Heads-up: this branch is stacked on an old #6086 head (78d2d0c). Besides the Sonnet 5.5 catalog change ( Suggest rebasing onto dev so the PR contains only |
|
Superseded by a clean redo (this branch had unrelated commits / a full models.json rewrite / a placeholder signature). — |
Changes
Add Claude Sonnet 5.5 support to the bundled model catalog for all providers that already support Claude Sonnet 5:
Model Details
Model ID:
claude-sonnet-5-5Release date: 2026-09-28 (official source: https://www.anthropic.com/claude-sonnet-5-5)
Mirrored metadata from Claude Sonnet 5:
Verification
Added verification test in
packages/ai/test/preset-catalog-models.test.ts:All tests pass:
bun test packages/ai/test/preset-catalog-models.test.ts✓Compatibility Gate
Model ID verification status: The model ID
claude-sonnet-5-5is inferred from Anthropic's naming patterns (claude-sonnet-4-5, claude-sonnet-4-6, etc.). This has NOT been verified against the actual Anthropic /v1/models API due to environment constraints.Runtime discovery: gajae-code clients with Anthropic credentials will discover the actual Sonnet 5.5 model ID at runtime via
GET /api/modelsendpoint. The bundled catalog is used as a fallback when dynamic discovery is unavailable.Old client compatibility: Released gjc 0.18.0 does not have claude-sonnet-5-5 in its bundled catalog. When this catalog is released:
Required follow-up: Verify that claude-sonnet-5-5 is available via Anthropic's /v1/models endpoint and update model ID in presets if needed. See gajae-code-presets PR for additional compatibility testing.
Files Changed
packages/ai/src/models.json: Added claude-sonnet-5-5 entries to all 6 providerspackages/ai/test/preset-catalog-models.test.ts: Added verification testTesting