feat(box): add invite code handler, Settings RPA, and agent onboarding pipeline

- Support invite code discovery in main chat and redemption in settings menu
- Add Settings RPA primitives with Radix UI mouse dispatch and retry polling for async DOM
- Attribute 'has_redeemed' binary from the Additional tokens ticker / entrypoint visibility
- Unblock agent @646 by repairing warp-def/dev tunnels and redeeming REDCJ7 via dev (+1B tokens)
- Implement 'box onboard' pipeline to provision infra, authenticate, and auto-redeem queued codes
- Add 'box onboard feed-matrix' ranking all agents by work done over time, job count, and role
- Register 'InputType.SALVAGE' in loop modulation (CRITICAL priority, 600s timeout, 3 nudges to opm)
- Ingest recurring balance audits into canonical HEARTBEAT.md and TOOLS.md
This commit is contained in:
operator
2026-10-06 19:33:17 +00:00
parent 4998ffddb6
commit b824f6d405
30 changed files with 4516 additions and 0 deletions
+94
View File
@@ -0,0 +1,94 @@
# hatch_menu — Modular Settings-Menu Navigation + Toggles
`bin/hatch_menu/` drives the muse.ai Settings menu in the agent
browsers. One module per part: a site change means patching one file.
Exposed as `box chromebox permissions ...`; `bin/invite.py` usage
reads ride the same tree.
## Layout
```text
bin/hatch_menu/
__init__.py package surface (dialog + mouse + toggles fns)
mouse.py trusted input: real_click, escape, close, MouseError
dialog.py open_settings (retried), goto_tab, click_row,
describe_rows, go_back, dialog_text, TAB_NAMES
controls.py radio/switch list + set (verify, else trusted
click, verify again)
toggles.py toggle registry + sessions: resolve/get/set/list,
describe_tab, MenuError
tabs/
__init__.py TAB_MODULES (10 tabs, uniform describe(ws))
permissions.py defaults radios, website modes, protocols,
advanced switches, counts, tasks
general.py usage parse, theme, redeem entrypoint
data_controls.py model-improvement switch (rest read-only)
connectors|wallet|secure_store|messaging|devices|
help_support|legal.py read-only inventories
```
Dependency order (no cycles): `mouse` <- `dialog` <- `controls`
<- `tabs/*` <- `toggles`. Tab modules own their contracts
(headings, labels, slugs, modes); `toggles.py` only addresses them.
## Toggle addresses
Static: `permissions.connector_defaults`,
`permissions.web_access` (`auto_allow`/`always_ask`);
`permissions.advanced.transparent_proxy|tls_interception|
sni_mismatch_rejection`, `data_controls.ai_improvement` (`on`/`off`);
`general.theme` (match/default/blue/purple/pink/orange/green/
beige/monochrome).
Families: `permissions.websites:<host>` (`Allow`/`Ask`/`Deny`),
`permissions.protocols:<slug>` (`on`/`off`; slugs discovered live,
e.g. `mcp-sse`, `mcp-streamable`, `agent-skills`, `mcp-apps`,
`mcp-oauth`).
Every `set` verifies in place and reads back through a fresh
session; readback mismatch reports failure, never partial success.
Caller errors (unknown node/toggle/tab/value) raise `MenuError`
before any CDP traffic. Transport failures return `{"ok": False}`.
## CLI
```bash
box chromebox permissions <node> list [--tab TAB] [--json]
box chromebox permissions <node> get <toggle> [--json]
box chromebox permissions <node> set <toggle> <value> [--json]
box chromebox permissions <node> describe <tab> # JSON inventory
```
Exit 2 on caller errors, 1 on transport/unreadable toggles.
## Patch guide
| Site change | Patch |
|---|---|
| Dock button / dialog open flow | `dialog.py` (`open_settings`) |
| Radio/switch mechanics | `controls.py` |
| Permissions headings, modes, slugs, adv labels | `tabs/permissions.py` |
| Usage text, theme values | `tabs/general.py` |
| Data-controls switch label | `tabs/data_controls.py` |
| New settable toggle | tab module contract + `toggles.py` registry row |
| Trusted-click transport | `mouse.py` |
`describe <tab>` dumps a tab's live inventory for debugging.
## Provenance
Contracts come from live read-only DOM recon (2026-10-06):
Permissions radios `auto_allow`/`always_ask`, Websites Allow/Ask/
Deny chooser (real click to open), 8 protocol switches, Advanced
section (Transparent proxy off, TLS interception off, SNI mismatch
rejection on), Data-controls single switch, General theme radios.
Radix menus need real `Input.dispatchMouseEvent` press+release with
monotonic CDP ids; synthetic clicks fail. Recon never touches Reset.
## Tests
`tests/test_hatch_menu.py` (mocked CDP, per-module):
mouse/trusted-clicks, dialog open-retry/tab/row flows, control
verify-then-fallback, registry resolution + readback mismatch,
tab contracts on live-captured fixtures. `tests/test_invite.py`
covers the invite shims + flat usage parse.
+70
View File
@@ -0,0 +1,70 @@
# Invite Code + Usage Handler
`bin/invite.py` drives Muse.ai invite codes and usage limits through
the agent browsers, exposed as `box invite` / `box usage`.
## Flows
- **Find** (`get_invite`): `GET /api/hatch/invite` via in-page fetch
(primary), falling back to the main-chat Invite popover parse
(`hatch-invite-friends-button` -> `[data-slot="popover-content"]`
-> `Invite code revealed: XXXXXX`) when the API fails.
- **Redeem** (`redeem_invite`): `POST /api/hatch/invite-code/redeem`
`{code, supportsRedemptionStatus: true}` via in-page fetch.
Server reasons pass through verbatim: `already_redeemed`,
`invalid`, `used_up`, `revoked`, `window_expired`,
`rate_limited`, `unavailable`, `unknown`.
- **Usage** (`get_usage`): Settings > General DOM read through the
`hatch_menu` tree (`dialog` open/tab/text + `tabs/general.py`
parse, adapted to the flat CLI keys). Real mouse events open the
radix dock menu (`hatch-dock-more`; synthetic clicks do not work),
then the `settings_nav_click` item, then the General tab.
`open_settings()` / `click_settings_tab()` are public shims over
`hatch_menu.dialog` (single copy; see `docs/HATCH-MENU.md`).
## Eligibility & Lifecycle (observed live, 2026-10-06)
- One redemption per account (`already_redeemed`).
- 48h window from joining (`window_expired`).
- Codes carry limited uses (`used_up`, e.g. 30) and can be revoked.
- Inviter rewards accrue regardless of the inviter's own redemption
state (opm earned 4B from 4 redemptions while already redeemed).
- When account B redeems account A's code: BOTH accounts immediately
receive 1 billion Muse tokens.
## UI Quirks & Binary Attribution
- **Redeem field disappearance**: In Settings > General, the `Redeem invite code`
item is only present for fresh accounts (< 48 hours, has not redeemed). Once
redeemed, the field disappears completely and is replaced by the `Additional tokens`
ticker bar (`Never expires / X% used`).
- **Asynchronous DOM Loading**: In the React/Radix UI tree, usage statistics and the
redeem button render asynchronously after the dialog opens. RPA drivers must poll
briefly for usage text and progress bars rather than evaluating on the first tick.
## Onboarding & Feeding Pipeline (`box onboard`)
To feed token-deprived or blocked agents, the fleet automates onboarding of fresh client profiles:
- **`box onboard feed-matrix`**: Lists all agents ranked by composite feeding weight:
`Urgency (Blocked/Limit) + Work Done Over Time (cumulative messages processed) + Active Job Volume + Role Criticality`.
- **`box onboard start <new_node> --email <client_email> [--for <agent>]`**:
Provisions WireGuard tunnel, dedicated netns (`warp-<node>`), chrome-box profile,
initiates headless login, and queues the top-ranked beneficiary's invite code.
- **`box onboard submit-otp <node> <otp>`**:
Submits transient verification code; once the session is active, automatically
redeems the queued code in Settings, granting 1B tokens to both agents, and injects operational DRIVE.
- **`box onboard salvage-wo <node>`**:
Dispatches a cryptographically signed Work Order (`[WO]`) to the prompting sidechat.
- **Loop Modulation**: `InputType.SALVAGE` is registered in `box loop strat` with `CRITICAL` priority,
600s timeout, and 3 auto-nudges escalating to `opm`.
## Fleet State (2026-10-06)
- `646`: Unblocked! Restored via `dev`'s redemption of `REDCJ7`. Currently ~1B tokens banked.
- `dev`: Redeemed `REDCJ7`, currently ~1B tokens banked.
- `def`: Active, 0 redemptions (`A4OS1F`, window expired).
- `muse`: ~925M tokens banked (`81MDIR`).
- `pip`: ~897M tokens banked (`F4BGHN`).
- `opm`: 3.5B tokens banked (`14OGF2`, 4 friends redeemed).