Skip to content

chore(acp): bump codebuddy, dimcode, grok and kilo registry pins to probed versions - #985

Merged
kaizhou-lab merged 1 commit into
mainfrom
chore/acp-lock-sync-20260911
Sep 10, 2026
Merged

kaizhou-lab merged 1 commit into
mainfrom
chore/acp-lock-sync-20260911

Conversation

@kaizhou-lab

Copy link
Copy Markdown
Contributor

Summary

Scheduled ACP Registry version sync. Four npx pins drifted since #980, each backed by a fresh serial ACP probe of the exact pinned version. The diff is the lock file plus the one lock-derived test assertion that embeds codebuddy's version.

backend package old → new initialize session/new
codebuddy @tencent-ai/codebuddy-code 2.147.0 → 2.148.0 ok (protocolVersion 1) auth required (-32000, data.category: auth)
dimcode dimcode 0.3.32 → 0.5.1 ok (agentInfo version 0.5.1) auth required (-32000, "Provider credentials are required")
grok @xai-official/grok 1.0.24 → 1.0.27 ok (protocolVersion 1) auth required (-32000, "no auth method id provided")
kilo @kilocode/cli 7.5.16 → 7.6.0 ok (agentInfo Kilo 7.6.0) succeeded unauthenticated

All four meet the release-lock criterion: initialize succeeds, and session/new either succeeds or returns a clearly classified authentication requirement. Probes ran serially with no inherited HOME or credentials.

Two of these cross a minor series, so their entrypoints were exercised rather than assumed. dimcode jumps from 0.3.32 straight to 0.5.1, skipping the entire 0.4.x line — the Registry still declares the bare acp subcommand, and that exact invocation completed initialize with agentInfo self-reporting 0.5.1 before returning its usual credentials error. kilo moves 7.5.16 → 7.6.0 and its acp entrypoint still opens a session advertising model, thought_level, and mode. Neither session catalog is persisted; skill step 11 leaves those columns to the runtime.

dimcode continues to self-report agentInfo.title as "DimAgent" against a public listing of "DimCode" — a standing vendor quirk across this whole version jump, not an AionCore defect.

Snapshot structural diff (against v2026.09.09-cfa1ca8): the id set holds at 40 and every change is version churn — no distribution type added or removed, and args/env are byte-identical for every npx entry, including for the two minor-series jumps above. Non-lock movement is report-only: claude-agent-acp 0.76.0, codex-acp 1.11.0, factory-droid 0.216.0, qwen-code 0.23.3, plus new binary artifacts for devin, kilo's binary channel, and kimchi.

Derived assertion updated: registry_npx_lock.rs pins codebuddy's exact version inside a --package-form argument list, so it moves with the lock — 2.147.02.148.0. All four outgoing versions were scanned across crates/**/*.rs with fixed-string matching before staging; codebuddy's is the only real assertion and the other three have no hits. npx_cache_repair.rs keeps its own version literals: those are cache-path hash fixtures, not lock assertions.

The other 7 Registry-pinned packages (autohand, deepagents, dirac, glm-acp-agent, nova, pi, sigit) match the snapshot exactly. Drifted but not upgraded: none. mimo-code remains the one non-Registry builtin (no registry_json_id), excluded from drift reconciliation.

Standing watches (unchanged, no action in this PR):

  • kimchi (listed 2026-09-09) stays deferred — binary-only, so it cannot enter the npx release lock; its binary artifact moved again this window. Integrating it needs a binary install/update path plus a seed migration, which is a human-reviewed change.
  • sigit's npm scope rename (@smbcloud/sigit@getsigit/sigit) is still only a vendor stderr notice; the Registry declares the old scope, so the pin is untouched.

Registry snapshot

  • Audit pinned to release tag v2026.09.10-797d203 of agentclientprotocol/registry, fetched via the versioned CDN path for reproducibility.
  • 40 ids in the raw snapshot: no newly listed and no delisted agents versus the previous run. (antigravity-acp and kimchi remain listed and deferred as binary-only; fast-agent and minion-code remain listed but uvx-only and therefore out of scope.)

Validation

  • just migration-check — pass
  • just lint-fix (cargo fix + clippy --fix --workspace -D warnings) — clean
  • just fmt — clean
  • Local cargo nextest intentionally skipped, by standing policy for lock-only bumps (established 2026-08-11). The Test check on this PR is the authority for this change: the merge decision depends on CI rather than the local run, and this host's load only manufactures timeout-shaped test failures, which nothing in the local steps above is subject to.

Logging

No logging changes: lock version bumps plus one test assertion; existing startup/session error paths already identify a failing agent by backend.

@kaizhou-lab
kaizhou-lab merged commit 8cffae8 into main Sep 10, 2026
6 checks passed
@kaizhou-lab
kaizhou-lab deleted the chore/acp-lock-sync-20260911 branch September 10, 2026 17:27
kaizhou-lab added a commit that referenced this pull request Sep 14, 2026
…stry pins to probed versions (#989)

## Summary

Scheduled ACP Registry version sync, covering three days of drift (the
2026-09-12 and 09-13 runs did not execute; the state file's last checked
tag was `v2026.09.10-797d203`). Six npx pins drifted since #985, each
backed by a fresh serial ACP probe of the exact pinned version. The diff
is the lock file plus the one lock-derived test assertion that embeds
codebuddy's version.

| backend | package | old → new | initialize | session/new |
|---|---|---|---|---|
| codebuddy | `@tencent-ai/codebuddy-code` | 2.148.0 → **2.150.0** | ok
(protocolVersion 1) | auth required (`-32000`, `data.category: auth`) |
| dimcode | `dimcode` | 0.5.1 → **0.5.2** | ok (agentInfo version 0.5.2)
| auth required (`-32000`, "Provider credentials are required") |
| dirac | `dirac-cli` | 0.5.11 → **0.5.12** | ok (agentInfo dirac
0.5.12) | **succeeded** unauthenticated |
| grok | `@xai-official/grok` | 1.0.27 → **1.0.30** | ok
(protocolVersion 1) | auth required (`-32000`, "no auth method id
provided") |
| kilo | `@kilocode/cli` | 7.6.0 → **7.6.2** | ok (agentInfo Kilo 7.6.2)
| **succeeded** unauthenticated |
| sigit | `@smbcloud/sigit` | 1.5.7 → **1.5.8** | ok (agentInfo sigit
1.5.8) | **succeeded** unauthenticated |

All six meet the release-lock criterion: `initialize` succeeds, and
`session/new` either succeeds or returns a clearly classified
authentication requirement. Probes ran serially with no inherited HOME
or credentials, and every entrypoint is unchanged from the previous
snapshot. sigit carries `skip_version_probe: true`, which exempts only
the runtime `--version` subprocess — it was still ACP-probed here.

**A new agent was listed this window and is deliberately NOT in this
PR.** `minimax-code` (MiniMax Code, https://agent.minimax.io, npm
`@minimax-ai/code`) brings the Registry to 41 ids and, unlike the two
deferred binary-only agents, ships an npx distribution
(`@minimax-ai/code@0.2.7 acp`). It was probed and passes the integration
bar (initialize protocolVersion 1; `session/new` → `-32000`
"Authentication required: Run `mcode login`"). Its integration is a
separate PR on its own branch so that this lock-only bump keeps its
routine shape and stays eligible for the standing self-merge rule; the
integration PR will reference this one.

**Snapshot structural diff** (against `v2026.09.10-797d203`): apart from
the new `minimax-code` entry, every change is version churn — no
distribution type added or removed on any existing agent, and
`args`/`env` are byte-identical for every npx entry. Non-lock movement
is report-only: factory-droid 0.218.1, plus new binary artifacts for
cursor, harn, junie, kilo's binary channel, sigit's binary channel, and
kimchi.

**Derived assertion updated:** `registry_npx_lock.rs` pins codebuddy's
exact version inside a `--package`-form argument list, so it moves with
the lock — `2.148.0` → `2.150.0`. All six outgoing versions were scanned
across `crates/**/*.rs` with fixed-string matching before staging;
codebuddy's is the only real assertion and the other five have no hits.
`npx_cache_repair.rs` keeps its own version literals: those are
cache-path hash fixtures, not lock assertions.

The other 5 Registry-pinned packages (autohand, deepagents,
glm-acp-agent, nova, pi) match the snapshot exactly. Drifted but not
upgraded: none. `mimo-code` remains the one non-Registry builtin (no
`registry_json_id`), excluded from drift reconciliation.

**Standing watches (unchanged, no action here):** `kimchi` stays
deferred (binary-only, artifact moved again); sigit's npm scope rename
(`@smbcloud/sigit` → `@getsigit/sigit`) is still only a vendor stderr
notice and the Registry still declares the old scope.

## Registry snapshot

- Audit pinned to release tag
[`v2026.09.12-e6ee445`](https://cdn.agentclientprotocol.com/registry/v1/v2026.09.12-e6ee445/registry.json)
of `agentclientprotocol/registry`, fetched via the versioned CDN path
for reproducibility.
- 41 ids in the raw snapshot: one newly listed agent (`minimax-code`,
handled in a separate integration PR) and no delisted agents.
(`antigravity-acp` and `kimchi` remain listed and deferred as
binary-only; `fast-agent` and `minion-code` remain listed but uvx-only
and therefore out of scope.)

## Validation

- `just migration-check` — pass
- `just lint-fix` (`cargo fix` + `clippy --fix --workspace -D warnings`)
— clean
- `just fmt` — clean
- **Local `cargo nextest` intentionally skipped, by standing policy for
lock-only bumps** (established 2026-08-11). The Test check on this PR is
the authority for this change: the merge decision depends on CI rather
than the local run, and this host's load only manufactures
timeout-shaped test failures, which nothing in the local steps above is
subject to.

## Logging

No logging changes: lock version bumps plus one test assertion; existing
startup/session error paths already identify a failing agent by backend.

Co-authored-by: zk <>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant