Release OpenEnv 0.6.1 - #1258
cursor[bot] wants to merge 3 commits into
Conversation
Bump 0.6.1.dev0 to 0.6.1 and align the two lockfiles that pin the editable openenv version, so validate-env-locks stays green. Co-authored-by: benjamin.burtenshaw <benjamin.burtenshaw@huggingface.co>
Co-authored-by: benjamin.burtenshaw <benjamin.burtenshaw@huggingface.co>
Co-authored-by: benjamin.burtenshaw <benjamin.burtenshaw@huggingface.co>
There was a problem hiding this comment.
Release status: refreshed 2026-09-30 06:25 UTC (supersedes earlier notes)
Candidate head 9eab9d93 = main 4f4c85fb + three version lines. Planned release: Thursday 1 Oct 2026, 08:00 Brussels (06:00 UTC run). The PR title/body still say 0.6.1 and 10:00; this comment is authoritative.
Version changed 0.6.1 -> 0.7.0 (decision needed from Ben; this is my default)
Since the last refresh, main gained RFC 005 public API: #1098 (turn-based agentic harness types: HarnessEnvironment, AgenticHarnessAdapter, HarnessProcess, events, MCP bridge; 18 new names in openenv.core.harness.__all__, 20 -> 38) and #1100 (production /harness WebSocket route; create_app(..., mode=) plus OPENENV_MODE now honored by create_fastapi_app). New public surface is a minor bump under the standard used for 0.5.0 and 0.6.0. A true 0.6.1 would need a reviewed rollback. If Ben prefers 0.6.1, revert the three version lines and re-run TestPyPI.
Release notes (draft)
- Added: RFC 005 turn-based agentic harness API in
openenv.core.harness(#1098) and the production/harnessWebSocket route for harness environments (#1100).create_app/create_fastapi_appacceptmode=and readOPENENV_MODE(default stays simulation). - Fixed: Novita Dockerfile
ARGsubstitution no longer corruptsFROM; thenovita_tbench2_simpleexample stops its sandbox on readiness timeout (#1235). - Refactor:
openenv.core.harnessis now a package; declared API unchanged (#1097). - Repo only: governance doc (#1261),
justfile(#1096), Harbor docs rendering (#1272).
Full comparison: v0.6.0...9eab9d9
Review of what landed on main since the last candidate
- Main CI on
4f4c85fbis green except the known nightlysync-global-collection(missingHF_TOKEN), not a release gate. #1098/#1100 merged by burtenshaw with approval and no unresolved review threads. - No release blocker found. Non-blocking observation: for non-class env factories,
_factory_produces_harness_envinstantiates the factory once (thenclose()s it) at route registration in production mode. Cheap for most envs, but heavy factories pay a startup cost. - #1099 (approved, bounds
HarnessMCPBridge.stop()with an open stream) is not in the candidate; it needs Approve-and-run for fork CI. Recommendation: ship 0.7.0 without it and follow with a patch.
Evidence at 9eab9d93
- Exact-head CI: 12/12 pass (test 3.11/3.12, thinkingbox x2, lint, package build/smoke, Linux Docker runtime validation, validate-env-locks, CodeQL, env docs, snapshot); merge state CLEAN.
- Local: 3167 passed / 103 skipped (CI selection);
ruff format/ruff checkclean,usortflags only the two known pre-existing files;uv build+twine checkpass; py3.11 wheel and py3.12 sdist clean installs report 0.7.0 with CLI and all 38harness.__all__names importable; real Echo reset/list_tools/step/state smoke passes. - TestPyPI
0.7.0.dev171(run 36677362101, fromtestpypi/0.7.0@bd722ca3= candidate + scratch-only workflow commit; serialized behindautomation-locks/openenv-release-0.7.0, released). Wheel sha256f3338150cd7e27a63c46e18806a2e276c497ae1d2c1586e2ca71e87bc5123d4f; all 174 packagedopenenv/**files are byte-identical to a local build of the candidate. Fresh 3.11 install with[novita]from that artifact: version, imports, CLI and Echo smoke pass.
Still to do on Thursday
- Refresh onto main immediately before merge; re-run CI, and TestPyPI only if package bytes change.
- Mark ready, merge (exact-head guard), tag
v0.7.0on the merge commit, runpublish-pypi.yml. - Verify fresh production PyPI install, GitHub release assets, then open the
0.7.1.dev0bump PR by hand (the workflow's bump job cannot create PRs in this org). - Version decision from Ben (above).
Sent by Cursor Automation: Release


Release PR: v0.6.1
Planned release: Thursday, October 1, 2026 at 10:00 Europe/Brussels (08:00 UTC).
Candidate base:
9e0fd9ba(main tip). 3 commits sincev0.6.0. This is the rolling release PR for the week and will be refreshed onto the final candidate head before merge.Version: 0.6.1, and no decision is needed. Unlike 0.6.0 this week adds no public surface — one bug fix plus an internal refactor whose declared API is unchanged (evidence below). That is a patch under the same standard used for 0.5.0 and 0.6.0.
Release notes
ARGsubstitution no longer corruptsFROM:ARG BASEdeclared beforeARG BASE_IMAGEused to rewriteFROM $BASE_IMAGEtopython:3.12_IMAGE, because defaults were substituted name by name. Substitution is now longest-name-first, so declaration order no longer matters (#1235).Not in the wheel, but shipped to the repo this week:
novita_tbench2_simpleexample now waits for readiness inside itstry, so a readiness timeout stops the paid sandbox instead of leaking it, and a new parse-level test asserts that invariant for everyexamples/novita_*.py(#1235).openenv.core.harnessis now a package, with the rollout implementation moved toopenenv.core.harness.rollout(#1097).API compatibility of the harness split
Checked rather than assumed, by installing
openenv==0.6.0and this candidate's wheel side by side and diffingopenenv.core.harness:__all__is identical in both: the same 20 declared names.ABC,Any,Callable,Generic,Protocol,TypeVar,TypedDict,abstractmethod,annotations,dataclass,field,json,math,runtime_checkable) and seven types that were never declared there —JsonRpcErrorCode,JsonRpcResponse,Tool(canonical homeopenenv.core.env_server.mcp_types),State(…env_server.interfaces),StepResult(openenv.core.client_types), plusLLMResponseandSessionT. All seven remain importable fromopenenv.core.harness.rollout.So nothing in the declared API moved. Anyone who relied on an undeclared transitive import such as
from openenv.core.harness import jsonis affected; that seems acceptable for a patch, but say so if you disagree and I will restore the re-exports instead.Full candidate comparison: v0.6.0...9e0fd9b
Release-maintenance changes in this PR
0.6.1.dev0→0.6.1inpyproject.toml, plus the matching editable-openenvpin inenvs/grid_world_env/uv.lockandtests/validation_runtime/uv.lock(the only two locks that track the current version; without themvalidate-env-locksfails).Outstanding blockers
workflow_dispatchis 403 for the release token, so this goes through atestpypi/0.6.1branch carrying thepush:trigger, as for 0.5.0 and 0.6.0.mainimmediately before merge and rerun required checks if the head moves.Not in this candidate: #1181 (Level 2 runtime probes, still awaiting
zkwentz), #1098–#1100 (approval-gated CI plus open findings), and the fork PRs that still cannot run repository CI. #1222 (FastMCP 4) stays blocked: v4 keys session state byctx.session_idand our server-side connection is rebuilt per call, so that is a scheduled migration rather than a cap bump.Local verification already done
uv sync --frozen --all-groups --all-extras --dry-run --no-install-projectpasses in both touched lock directories (thevalidate-env-lockscommand).0.6.1for bothimportlib.metadataandopenenv.__version__, andopenenv --helpworks.Release Checklist
Before opening this PR
pyproject.tomlversion changed from0.6.1.dev0→0.6.1hf-staging/is NOT in this PR's diffprint(),breakpoint(), orTODOadded to release-critical pathsCI gates (must be green before merge)
testpasses on Python 3.11testpasses on Python 3.12lintpasses (usort + ruff)Package CIbuilds, checks, and smoke-tests wheel/sdist installsTestPyPI validation (before merging)
0.6.1.devNpublished from this candidate headPost-merge steps
v0.6.1against the exact merge commit onmainpublish-pypi.ymlcompleted (expectOpen post-release bump PRto fail — GitHub Actions cannot create PRs in this org; open it by hand)pip install openenv==0.6.1verified from production PyPIRFC Status