AIWG 2026.7.24 - Sandbox runtime readiness and setup manifest CLI

AIWG 2026.7.24 - Sandbox runtime readiness and setup manifest CLI

Released: 2026-07-29 Channel: stable

AIWG 2026.7.24 aligns Cockpit with the current agentic-sandbox runtime contract and exposes the setup manifest workflow as first-class CLI commands. The release keeps Cockpit opt-in and version-locked while broadening the runtime signals it can safely render for host, container, Docker, and VM targets.

What changed

  • Cockpit Inventory now gates VM fast-start controls by advertised provider

capability. Cloud Hypervisor rows can expose snapshot, restore, fork, and warm-pool actions; libvirt rows can expose checkpoint, restore, and warm-pool actions when the executor advertises them.

  • Restore, fork, and warm-pool requests now use the sandbox `runtime_options`

launch intent and poll the async operation resource through terminal state.

  • Cockpit surfaces sandbox MCP discovery, GPU/VFIO posture, Apple Silicon

runtime posture, local container fallback availability, and mTLS readiness as capability-driven status rather than fixed assumptions.

  • MCP proxy calls through Cockpit now require a separately scoped MCP bearer

file, while discovery remains display-safe metadata.

  • Local Docker lifecycle fallback is now explicit opt-in for development, and

non-Linux libvirt reconnect fallback requires explicit operator opt-in.

  • Codex project-local addon skills now deploy to `.agents/skills/`, matching the

native Codex project skill loader while keeping indexed generated artifacts separate.

  • `aiwg setup-generate`, `aiwg setup-validate`, and `aiwg setup-run` provide the

CLI entry points for authoring, validating, and dry-running `setup.aiwg.io/v1` manifests.

Cockpit and sandbox compatibility

The new Cockpit runtime controls are intentionally capability-gated. Older agentic-sandbox builds still render inventory and sessions, but unavailable provider actions stay disabled with the executor-provided reason. This keeps the UI usable during mixed-version upgrades while making the newer fast-start VM and transport readiness paths visible when the sandbox supports them.

The Apple Silicon validation baseline is the unsigned, unnotarized agentic-sandbox `v2026.7.14` developer package. Runtime-option delegation, MCP discovery, bootstrap readiness, and degraded-libvirt gating require a sandbox build from main after `v2026.7.14` until those commits are covered by a newer sandbox tag.

Package matrix

All three packages publish in CalVer lockstep:

[email protected]
@aiwg/[email protected]
@aiwg/[email protected]

Upgrade

Full local-corpus distribution:

npm install --global [email protected]

Lightweight signed-web distribution:

npm install --global @aiwg/[email protected]

Install or refresh Cockpit through the base CLI so it remains version-locked to the installed AIWG release:

aiwg use cockpit
aiwg cockpit