Files
box/docs/BOX-TMUX-AUTO-HTTPS.md
T

169 lines
7.5 KiB
Markdown
Raw Normal View History

# Tmux Worker Tally & Regex Auto-Approvals over HTTPS (No SSH)
> **Box is the main surface.** All operator work goes through Box (`box.muse-dev.online`).
> The web UI, `box` CLI, and agents share the same unified API endpoints and runtimes.
**Date:** 2026-10-06
**Status:** Implemented (`bin/tmux_auto_approver.py`, `bin/box-onboard-tui.py`, `bin/super-cli.py`)
**Scope:** Tmux worker tallies, automated regex approval engine for on-board Muse Code runs & autonomous agent workers, and dedicated interactive TUI console (`box onboard-tui`).
---
## 1. Architecture
```
┌──────────────────────────────────────────────┐
│ https://box.muse-dev.online/ │
│ (Web Dashboard & API Gateway) │
└──────────────────────┬───────────────────────┘
│
HTTPS Signed Ops / CLI Dispatch
│
┌──────────────────────▼───────────────────────┐
│ Unified Box CLI Engine │
│ (box tmux tally / box tmux auto ...) │
└───────┬───────────────────────────────┬──────┘
│ │
┌──────────────▼─────────────┐ ┌─────────────▼──────────────┐
│ bin/box-onboard-tui.py │ │ bin/tmux_auto_approver.py │
│ (Dedicated 4-Tab Console) │ │ (Multi-Socket Regex Daemon)│
└──────────────┬─────────────┘ └─────────────┬──────────────┘
│ │
│ │
┌───────────────────────┴───────────────────────────────┴───────────────────────┐
│ Tmux Sockets Monitored │
│ • /tmp/tmux-muse.sock (shared host workers) │
│ • /tmp/tmux-1000/default (dev/def runner panes & muse-code %37) │
│ • /tmp/tmux-1000/lte (lte operator pane) │
│ • /tmp/tmux-<agent>.sock (per-agent netns sockets: pip, 646, opm, dev, def) │
└───────────────────────────────────────────────────────────────────────────────┘
```
---
## 2. Tmux Auto-Approval Regex Match Engine
The auto-approval engine monitors scrollback across all agent panes and matches approval prompts against priority rules:
| Rule ID | Category | Trigger Pattern | Response Key | Press Enter | Description |
|---|---|---|---|---|---|
| `muse_code_run_numbered` | `muse_code` | `Would you like to run the following[\s\S]*?›\s*1\.\s*Yes,?\s*proceed` | `1` | `false` | Muse Code interactive run menu (selects option 1) |
| `muse_code_run_yn` | `muse_code` | `›\s*1\.\s*Yes,?\s*proceed\s*\(y\)` | `1` | `false` | Active selection indicator on `1. Yes, proceed (y)` |
| `muse_code_allow_execution` | `muse_code` | `Allow\s+execution\s+of\b[\s\S]*?\[y/N\]` | `y` | `true` | Approves script execution confirmation |
| `choice_abc` | `choice` | `(?i)(?:choose\|choice\|select)[\s\S]*?^\s*[A-Z]\s*[.\)\-:]\s+\S` | `A` | `true` | Lettered decision choice menus |
| `menu_numbered` | `menu` | `(?i)(?:Option:\|Selection:)[\s\S]*?^\s*\(?1\)?\s+[A-Za-z]` | `1` | `true` | Numbered selection menus |
| `confirm_yn` | `confirm` | `([yY]/[nN]\|\[[yY]/[nN]\])\s*[\]:)>]?\s*$` | `y` | `true` | Line-end confirmation prompts |
| `enter_to_continue` | `enter` | `(?i)(?:Press\s+\[?Enter\]?\s+to\s+continue)` | `Enter` | `false` | Enter-to-continue banners |
### Guardrails (Never Auto-Approved)
- `[sudo] password for ...` / `password:` prompts
- Passkeys, private key passphrases, and PIN prompts
- Destructive operations (`rm -rf /`, `mkfs.*`)
When a guardrail pattern is detected, the engine flags `is_blocked=true`, emits a warning audit log, and notifies the human operator.
---
## 3. CLI Commands
### Tmux Worker Tally & Management
```bash
# Tally all active tmux sessions, panes, and workers across sockets
box tmux tally
box tmux tally --json
# List active sessions
box tmux list
# Spawn new background worker session
box tmux new my-worker -c "python3 run_tasks.py"
```
### Auto-Approval Control
```bash
# Query master state and per-agent policies
box tmux auto status
box tmux auto status --json
# Master enable / disable
box tmux auto on
box tmux auto off
# Enable / disable for specific agent
box tmux auto on --node muse
box tmux auto off --node 646
# Execute single-pass scan and auto-approve all active prompts right now
box tmux auto once
box tmux auto once --dry-run
# Run background monitor daemon
box tmux auto watch --interval 1.0
# Tail structured audit log stream
box tmux auto logs -n 20
# Test regex match against custom prompt text
box tmux auto match "Would you like to run the following ... › 1. Yes, proceed (y)"
```
### Onboard Connects
```bash
# View all fleet nodes & client onboard connects
box onboard connects
box onboard connects --json
# Start client onboarding
box onboard start dev2 --email client@example.com --for 646
# Submit OTP verification code
box onboard submit-otp dev2 123456
```
### Dedicated Interactive TUI
```bash
# Launch full 4-tab interactive TUI
box onboard-tui
box tui onboard
```
---
## 4. HTTPS Remote Operations (`exec-constrained.py`)
Available via `https://exec.muse-dev.online/exec` with signature verification:
| Op | Parameters | Description | Permission |
|---|---|---|---|
| `tmux.tally` | `{}` | Returns complete worker tally across all sockets (JSON) | `DEFAULT_PERMS` (Read-only) |
| `tmux.auto_status` | `{}` | Returns auto-approval toggle state & rule set (JSON) | `DEFAULT_PERMS` (Read-only) |
| `onboard.connects` | `{}` | Returns consolidated fleet and client connects (JSON) | `DEFAULT_PERMS` (Read-only) |
| `tmux.auto_toggle` | `{"enabled": bool, "node"?: str}` | Toggles master or per-agent auto-approval state | Known-Identities-Only |
---
## 5. Audit Logging
Every auto-approval and blocked guardrail event is written to:
`/home/super/Projects/NetVM/logs/tmux/auto-approvals.jsonl`
Sample event payload:
```json
{
"action": "AUTO_APPROVED",
"socket": "/tmp/tmux-1000/default",
"pane": "%37",
"session": "muse",
"agent": "muse",
"rule_id": "muse_code_run_numbered",
"rule_name": "Muse Code Run (Numbered)",
"key_sent": "1",
"press_enter": false,
"excerpt": "Would you like to run the following ... › 1. Yes, proceed (y)",
"dry_run": false,
"success": true,
"timestamp": "2026-10-06T19:34:19.599811+00:00",
"ts": 1791315259.6
}
```