Implement One Provider Identity
Resolve configuration once to one opaque provider ID. Register one RuntimeProviderBundle under
that identity. Bind every surface, receipt, resource handle, and persisted sandbox record to it.
Provider-owned modules must own provider-specific commands, endpoint or socket authority, runtime
resource identity, network preparation, lifecycle operations, recovery, and cleanup. Generic
orchestration must consume bundle surfaces. It must not import a provider implementation or branch
on a provider name.
If the current contract lacks a required provider-owned behavior, propose the narrow contract
extension and its tests. Do not add an ambient environment switch or a central provider-name
branch as a substitute.
Persist the selected provider ID in SandboxEntry.openshellDriver. Start, stop, rebuild, snapshot,
restore, recovery, inference changes, and destroy must resolve the same bundle from persisted
state. Reject missing, unknown, reused, or drifted authority before mutation.
Validate and Qualify
Follow the focused checks in Implementation and Review.
Run the current type, repository, contract, activation, provider, and architecture checks that the
diff affects.
Local and CI checks establish contract behavior. They do not replace protected qualification or
the complete supported live E2E matrix against the commit under review. When a maintainer requests
a GitHub Actions run, follow Run Maintainer E2E.
Report
Return:
- accepted product scope and intended delivery state;
- provider ID, topology, authority model, and persisted state boundary;
- implemented, unsupported, and extended bundle surfaces;
- remaining provider-name branches in generic orchestration;
- focused validation tied to the commit under review;
- protected qualification and full E2E evidence, or the missing gate; and
- credential, recovery, cleanup, and ownership obligations.