Skip to content
UHPUHPDeveloper Guide
Independent resource · Not affiliated with HarnessRouter · Site data checked 13 Sep 2026

Sources

Primary sources and verification references

The evidence set used to separate normative UHP behavior, HarnessRouter implementation changes, upstream harness behavior, independent implementations, adjacent standards and adoption claims.

Verified: Protocol: 2026-09-12Static SSG

Living implementation guides do not override the versioned normative specification/schema. When a convenience guide and the versioned contract disagree, this site follows the versioned contract.

HarnessRouter current release and runtime evidence

Section titled “HarnessRouter current release and runtime evidence”

At the 13 September cutoff, HarnessRouter stable is v0.16.1 / tag target 8f976f90. Checked upstream main is later a7406cbd after PR #165 published UHP 2026-09-12 and the optional Harness Plugins sub-protocol. PR #165 explicitly distinguishes protocol publication from Community Edition runtime support: at that merge point the CE gateway still serves 2026-08-11 and reports no plugin capability. The conformance package is now 2026.9.12 with 74 checks, while the checked-in live HarnessRouter result remains the prior-suite 64/64 Full block. Stable v0.16.1 still carries PR #155’s exact custom-endpoint model mapping, OpenAI Responses format, connection-level disabled_tools and pinned Codex 0.154.0 behavior. The released backend set remains ten.

The preceding v0.16.0 / PR #151 adds the hosted HarnessRouter service as an optional Community Edition provider: the CE gateway brokers the /v1/connect hand-off, keeps pairing/provider credentials server-side, stores the returned endpoint/model-catalog coordinates, queries hosted balance server-side and preserves the hosted Gemini relay path. The PR records selected candidate turns through the hosted row for Claude Code, Codex app-server and Gemini CLI. This is provider/runtime evidence, not UHP conformance or an all-model/backend matrix.

PR #148 records Vercel 43/44, TokenRouter 43/44, OpenAI 44/44, Azure 44/44 and OpenRouter 43/44 for Codex on the app-server path. Earlier Codex provider columns were measured through codex exec. These are HarnessRouter provider/runtime results, not UHP conformance.

PR #139 remains the preceding resume/API-mode fidelity release. It makes HarnessRouter’s Hermes adapter explicitly select the Responses API for later GPT-family models on Azure Foundry, including gpt-6-astra, and makes a missing Claude Code/OpenCode native resume explicit to users and the support-matrix recall judge.

The v0.15.6 line remains separately bounded: PR #135 moves HarnessRouter’s DeepSeek Harness adapter to 0.1.2rc1 and composes configured MCP servers into the dsh sdk profile while correcting OMP URL MCP/tool metadata; PR #136 makes model availability tri-state; PR #137 tightens model/retry/error attribution; PR #138 adds real MCP-server verification to the custom-harness dimension. PR #140 later reran the previously partial dsh OpenRouter column after the shared account was topped up: 38 model pairs, 189/189 scenario runs, no retests and no substitution on HarnessRouter 0.15.7 with the retained dsh 0.1.2rc1 adapter. That evidence shipped in v0.15.8 and remains provider/runtime evidence, not UHP conformance.

DeepSeek Harness and Oh My Pi upstream references

Section titled “DeepSeek Harness and Oh My Pi upstream references”

DeepSeek Harness upstream latest prerelease is v0.1.5-rc.2 / tag fb2c4b9e, published 10 September 2026 at 15:09:34 UTC; checked upstream master is c291e796. RC2 itself is a narrow Web-client release: both likes and dislikes require confirmation before feedback is recorded, failed submissions preserve the entered feedback and show a notice, and delivered-file cards/spacing/code-file icons are refined. The integration-facing rc.1 baseline remains the earlier DeepSeek-V41-Flash (deepseek-flash) default, continuable-subagent controls, SessionHandle/session-lock ownership, launch-environment proxy support, MCP repeated-cursor protection, filtered-subagent guidance aligned to effective tool access and shell-only minimal/sdk-minimal defaults. Current master additionally deprecates new production use of synchronous arbitrary Session-history readers in favor of projections and explicit asynchronous historical reads. HarnessRouter nevertheless measures dsh 0.1.2rc1 in its adapter. VulnCheck’s 8 September advisory assigns CVE-2026-82533 / CVSS v4 9.4 to the upstream application before 0.1.2-alpha.1; first-party patch 3e24087b authenticates the browser Host API and the v0.1.2-alpha.1 release notes require a one-time launch token for network Web access. Do not infer the CVE status of HarnessRouter’s separately named SDK pin from lexical version comparison.

Oh My Pi upstream latest is v18.1.19 / tag and checked main e4dd2ec3, published 12 September 2026 at 23:57:09 UTC. Stable v18.1.19 promotes the previously tracked post-v18.1.18 MCP reconnect lifetime, DeepSeek V4.1 Flash, replay-safe empty-tool-call retry, per-fallback reasoning effort, persistent /btw and JSON print-mode exit-status fixes into released behavior. It also adds live pending-tool result/display continuity, speculative-session invalidation after argument transformation, Codex OAuth account compatibility, Windows zcode:// callback repair, OS-backed file locks and PowerShell 5.1 installation fixes. These are upstream harness/runtime/platform semantics, not changes to UHP, MCP or ACP wire behavior. HarnessRouter’s OMP integration/evidence remains pinned to 18.1.13. Upstream latest and adapter evidence are intentionally separate coordinates.

HarnessRouter support-matrix and conformance evidence

Section titled “HarnessRouter support-matrix and conformance evidence”

Current UHP is 2026-09-12; current suite coverage is 74 checks under 2026.9.12. The checked-in live HarnessRouter result remains the 4 September 64/64 Full, zero failed/skipped/errored run under prior suite 2026.8.11.post1; it is not a 74/74 result. PR #93’s 695-pair matrix, PR #119’s 705/705 OMP scenarios, PR #138’s custom-harness MCP dimension, PR #139’s later resume/API-mode fidelity, PR #140’s dsh OpenRouter 189/189 provider rerun, PR #148’s Codex app-server provider rerun, PR #151’s hosted-provider candidate checks and PR #155’s custom-endpoint/pinned-Codex candidate evidence remain separate evidence classes.

uhp-go’s published evidence remains 63/63 Full, zero skipped for its pinned revision. AIWG, SuperQode and mini-ork are client-side implementations, not server-conformance results.

HarnessRouter backend support does not establish native UHP adoption by the upstream project. Pydantic AI Harness, TrueForge, Docker Agent, Strands Agents, Deep Agents, Prime Agent, Antigravity CLI and GitHub Agentic Workflows are tracked here as adjacent harness architectures or orchestration layers even though none is a released HarnessRouter backend.

Pydantic AI Harness stable v0.31.0 / d8787b74, published 12 September 2026 at 00:54:49 UTC, remains an Alpha-classified capability/harness library with first-party MCP tooling and an explicitly experimental ACP server. The release tag and checked upstream main are the same d8787b74 commit at this cutoff. v0.31.0 adds opt-in eager streamed CodeMode execution with a documented early-side-effect/provider-trust boundary, first-class SubAgents delegation start/end events and CodeMode sandbox result-shape corrections. It also promotes PR #849’s ACP approval-status correction, PR #848’s serialized-history reconstruction fix and PR #851’s pydantic-ai-slim>=2.40.0 dependency floor into released behavior. These are harness/runtime/adapter semantics, not changes to ACP, MCP or UHP wire behavior. Reviewed primary sources do not establish native UHP adoption, a HarnessRouter backend or UHP conformance evidence for it.

TrueForge’s observed application prerelease is @truefoundry/trueforge@0.2.0-rc.6, published 11 September 2026 at 16:35:16 UTC, from version/package commit 480e485d985976bab952dfaac244226c7a49a8cc. RC6 promotes PR #685’s x-tfy-metadata gateway context, PR #706’s destination-specific actor/subject vend-token handling and PR #714’s type-discriminated remote-vs-TrueFoundry MCPServerManifest into released application behavior. RC4’s PR #627 service-key scheduled-execution boundary remains inherited. RC6 also persists/synchronizes agent descriptions and paginates/searches the agents API. Checked upstream main is later e097f21d; PR #720 advances only the Helm package to appVersion 0.2.0-rc.6 / image 0.2.0-rc.6-480e485, and PR #676 changes documentation imagery. These are TrueForge runtime/identity/API and packaging/documentation semantics, not UHP, ACP, A2A or MCP wire changes. Primary documentation describes a complete agent loop exposed through a chat UI and HTTP API/TypeScript SDK, with remote MCP header/OAuth auth, SKILL.md skills, sandboxing, approvals, subagents, compaction and session state. Local mode has no login by default and upstream says to keep it on localhost; hosted deployments can use OIDC. Reviewed sources do not establish native UHP, ACP or A2A support, a HarnessRouter backend or UHP conformance evidence for TrueForge.

Docker Agent stable v1.137.0, published 9 September 2026, is a Docker CLI agent runtime with declarative YAML, multi-agent orchestration, MCP tools and OCI distribution. Stable documentation also exposes agents through MCP, A2A and ACP and can delegate coding subagents to Claude Code, Codex, OpenCode and Pi. The stable release removes session_plan, adds multimodal capability filtering/image-output guards, sequential rewrite-hook pipelines and additional safety classification. Checked upstream main is 56473dca, where PR #4023 adds generated-media stream deltas as unreleased behavior explicitly excluding progressive display, remote binary streaming, persistence and TUI delivery. Reviewed sources do not establish native UHP adoption, a HarnessRouter backend or UHP conformance evidence for Docker Agent.

Strands Agents stable Python v1.55.0 and TypeScript v1.17.0, both published 8 September 2026, are independently versioned SDK releases for an in-process model-driven agent harness. Stable docs define the agent loop and first-party MCP integration in both languages; first-party A2A client/server code is present but explicitly marked experimental. A strands-acp entry exists in the Strands integrations catalog, but reviewed first-party SDK sources do not establish native ACP support. No reviewed primary source establishes native UHP adoption, a HarnessRouter backend or UHP conformance evidence for Strands Agents.

Deep Agents stable Python 0.7.13, TypeScript 1.13.3 and deepagents-acp@0.1.29 are separately versioned packages in LangChain’s harness family. The project explicitly describes Deep Agents as an opinionated/batteries-included harness above LangGraph, with planning, filesystem/context management, subagents, execution backends, memory, approvals and skills/tools. Python documents first-party MCP tool consumption; the TypeScript monorepo publishes the first-party ACP stdio server. The current official ACP protocol matrix does not directly probe that server. Checked TypeScript main eb859e8b contains an unreleased fix that scopes model/tool call counters to each parent/subagent boundary, preventing parallel channel collisions and serial budget rewind. Reviewed sources do not establish native A2A or UHP support, a HarnessRouter backend or UHP conformance evidence for Deep Agents.

Prime Agent stable v0.9.4, published 8 September 2026, is Prime Intellect’s self-improving RLM harness for coding, research and long-running work. Checked upstream main is 427ea4c7. First-party docs define a persistent Python control environment, recursive/background subagents, daemon-backed continuity and a Continual Harness that can refine supplemental prompts, memories, skill descriptions and reusable subagent specifications with snapshots/rollback. Stable v0.9.4 exposes ACP mode and accepts client-supplied stdio/HTTP MCP servers inside ACP sessions; the current official ACP matrix does not list Prime Agent. Its direct agent-to-agent messaging is an internal runtime mechanism rather than established A2A-protocol support. No reviewed primary source establishes native UHP adoption, a HarnessRouter backend or UHP conformance evidence.

Antigravity CLI stable 1.2.0, published 10 September 2026 at 01:43:29 UTC, is Google’s terminal-first Antigravity agent surface. Tag and checked main are both 34406bef. First-party documentation says it shares Antigravity 2.0’s core agent engine and exposes headless automation, persistent conversations, custom agents/subagents, plugins, Agent Skills, rules, hooks, permissions and MCP. Stable 1.2.0 adds the operating-system-managed remote-control start/status/stop lifecycle for persistent machine reachability, fixes globally installed plugin MCP initialization/status handling and compatibility with third-party MCP tool schemas that omit additionalProperties, makes content-filter stops explicit and restores older-conversation resume compatibility. Reviewed sources do not establish native UHP, ACP or A2A-protocol adoption, a HarnessRouter backend or UHP conformance evidence for Antigravity CLI.

GitHub Agentic Workflows stable v0.88.7, published 8 September 2026 at 15:34:49 UTC, is GitHub’s Markdown-to-Actions agentic-workflow compiler/orchestration layer. Its tag target is bde36791 and checked upstream main is 099efdda at this cutoff. Stable primary sources describe built-in Copilot, Claude Code, Codex, Gemini and Pi engines, read-only/sandboxed agent jobs, SafeOutputs-controlled writes and an MCP Gateway behind the Agent Workflow Firewall. Stable v0.88.7 also hardens incomplete-work finality, artifact packaging, OTLP credential handling and operational reliability. Reviewed sources do not establish native UHP, ACP or A2A-protocol support, a HarnessRouter backend or UHP conformance evidence.

The 10 September announcement starts a cross-network KYA collaboration around common agent-trust principles, operator traceability, shared certification requirements and continuous transaction monitoring. It does not, in the reviewed sources, publish a common KYA protocol schema/version/conformance suite or a UHP binding. Visa Trusted Agent Protocol, Mastercard Verifiable Intent and Ant AMP are pre-existing mechanisms named as foundations for the collaboration, not proof that they already share one wire format.

Loop engineering is tracked here as emerging engineering terminology, not a protocol standard. The reviewed sources distinguish the outer loop’s recurrence, goal/evaluation and continuation policy from the harness execution environment. Oh My Pi v18.1.16 supplies one concrete product-level example through /loop --while / --until shell conditions, but that remains an OMP runtime primitive rather than a portable protocol operation. The site’s UHP relationship is an architectural mapping: UHP can provide a stable execution/lifecycle seam inside such a loop, but UHP 2026-09-12 does not define the outer scheduler, evaluator or stopping policy.

The official Filesystems WG charter is merged, but its Filesystem Operations for Resources SEP remains Ideating. Current released MCP 2026-07-28 remains the baseline; do not treat planned create/update/delete/stat behavior as released protocol behavior.

A2A CLI stable software v0.2.0 was published 9 September 2026 with tag target cacb1e2c; checked post-release main is 187400f9. Its post-tag line first updates the Homebrew formula and then adds cookbook/example documentation and smoke coverage for --exec, configuration, messages/tasks and transport usage. The CLI is a harness-facing official A2A client with JSON-RPC/HTTP+JSON/gRPC, executable transport plugins and a bundled Agent Skill, but its CLI behavior specification remains Review/pre-Proposed and applies to A2A Protocol v1.0. The release does not change A2A wire semantics, create a UHP↔A2A binding or establish UHP conformance.

  • Normative source beats implementation convenience. The versioned UHP specification/schema is authoritative for protocol behavior.
  • Release tag and current main are separate coordinates. Stable HarnessRouter is v0.16.1 / 8f976f90; checked main is later a7406cbd because UHP 2026-09-12 was published after the stable release.
  • Protocol publication and reference-runtime support are separate. UHP 2026-09-12 / conformance 2026.9.12 has 74 checks, while the checked-in HarnessRouter live result remains the prior-suite 64/64 block and PR #165 says CE still serves 2026-08-11 at that merge point.
  • Backend support is not native adoption. A HarnessRouter adapter proves HarnessRouter can drive an upstream harness, not that the upstream project implements UHP.
  • Provider, backend, model and MCP-tool availability are different coordinates. A working path in one dimension does not imply the others.
  • A Working Group charter is not released protocol behavior. Filesystems WG ownership/direction is official, while its planned write methods remain Ideating standards work until the SEP process advances them.
  • Verification methodology is not conformance. PR #138 closes a HarnessRouter custom-harness MCP test gap, PR #139 hardens later resume/API-mode fidelity, PR #140 closes the dsh OpenRouter provider-matrix gap, PR #148 records a Codex/app-server provider rerun, PR #151 records selected hosted-provider candidate checks and PR #155 records custom-endpoint/tool-policy behavior plus a pinned-Codex candidate check; none is a substitute for the current 74-check UHP suite.
  • Measured evidence is revision-bounded. PR #93, PR #119, PR #138, PR #139, PR #140, PR #148, PR #151, PR #155, uhp-go and the checked-in HarnessRouter conformance result each have different evidence scopes and source revisions.
  • Adapter pin and upstream latest are separate. HarnessRouter dsh 0.1.2rc1 is not DeepSeek Harness v0.1.5-rc.2; OMP 18.1.13 adapter evidence is not upstream v18.1.19.
  • Software release and specification maturity are separate. A2A CLI v0.2.0 is a stable software release while its CLI specification remains Review/pre-Proposed; neither coordinate changes A2A Protocol v1.0 or UHP.
  • Commerce trust and harness execution are separate. KYA cross-network identity/trust signals do not create a UHP task/session binding, replace network-local decisioning or imply that a trusted agent is authorized for every action.