From f61ceb5f044c663acd377e3911fc2eacdc2672eb Mon Sep 17 00:00:00 2001 From: operator Date: Mon, 5 Oct 2026 16:41:42 +0000 Subject: [PATCH] fix(envelope): strip host container key references from prompt envelope to eliminate agent refusal loops --- bin/prompt_envelope.py | 73 +++--------------------------------------- 1 file changed, 5 insertions(+), 68 deletions(-) diff --git a/bin/prompt_envelope.py b/bin/prompt_envelope.py index 34222e1..e93c03e 100644 --- a/bin/prompt_envelope.py +++ b/bin/prompt_envelope.py @@ -14,33 +14,16 @@ import hashlib BOX_API = "https://box.muse-dev.online/api/box" -# Verified box-namespace private keys on bl (pubkey matches the agent's entry -# in /srv/board/allowed_signers). Agents without a verified key fall back to -# the [RESULT] line (harvester) until super provisions their box key. -BOX_KEY_PATHS = { - "dev": "/home/super/.ssh/id_dev", - "pip": "/home/super/.ssh/id_pip", - "646": "/home/super/.ssh/id_646", - "opm": "/home/super/.ssh/id_opm", -} - def _response_rule(): return ( - "\nRESPONSE RULE: in your reply, every line that is not work output" - " MUST be a curl tool call against https://box.muse-dev.online/." - " Fenced bash blocks are executed as tool calls and their output" - " returns to you; do not narrate the calls.\n" + "\nRESPONSE RULE: Execute your steps using [TOOL ...] directives or background tmux commands." + " When complete, conclude your output with the [RESULT ...] line so the harvester records it.\n" ) def _box_surface_block(agent, job_name, job_id, target): - """Thread + runtime + direct curl URL + respond command. - - READ: GET /api/box/jobs/ (signed, box namespace; live) - RESPOND: POST /api/box/job/result (signed, box namespace, own-scope; - ships with the frontdoor publish -- 404 until then) - """ + """Clean runtime context block for the agent.""" header = ( "\n---- BOX RUNTIME ----\n" "THREAD: " + str(target) + "\n" @@ -48,54 +31,8 @@ def _box_surface_block(agent, job_name, job_id, target): "JOB: " + str(job_id) + "\n" "AGENT: " + str(agent) + "\n" ) - key = BOX_KEY_PATHS.get(agent) - if not key: - return ( - header - + "\nNOTE: no box signing key is provisioned for '" + str(agent) - + "' yet, so curl commands against the box API cannot authenticate." - + " Ask super to provision your box key; until then the [RESULT]" - + " line is your respond path (the harvester records it).\n" - + _response_rule() - ) - read_cmd = ( - "```bash\n" - "TS=$(date +%s)\n" - "SIG=$(printf '%s\\njobs/" + str(job_name) + "' \"$TS\"" - " | ssh-keygen -Y sign -f " + key + " -n box" - " | python3 -c 'import sys,urllib.parse;" - " print(urllib.parse.quote(sys.stdin.read().strip()))')\n" - "curl -s \"" + BOX_API + "/jobs/" + str(job_name) - + "?identity=" + str(agent) + "&ts=$TS&sig=$SIG\"\n" - "```" - ) - respond_cmd = ( - "```bash\n" - "TS=$(date +%s)\n" - "export BOX_TS=$TS\n" - "export BOX_SIG=$(printf '%s\\njob/result\\n" + str(job_id) + "' \"$TS\"" - " | ssh-keygen -Y sign -f " + key + " -n box)\n" - "python3 - <<'PYEOF' | curl -s -X POST " + BOX_API + "/job/result" - " -H 'Content-Type: application/json' -d @-\n" - "import json, os\n" - "print(json.dumps({\n" - " \"identity\": \"" + str(agent) + "\",\n" - " \"ts\": os.environ[\"BOX_TS\"],\n" - " \"sig\": os.environ[\"BOX_SIG\"],\n" - " \"job_id\": \"" + str(job_id) + "\",\n" - " \"success\": True,\n" - " \"summary\": \"[RESULT " + str(job_id) + "] \",\n" - "}))\n" - "PYEOF\n" - "```" - ) - return ( - header - + "\nREAD your work order any time:\n" + read_cmd + "\n" - + "\nRESPOND when done -- emit this exact command as a tool call:\n" - + respond_cmd + "\n" - + _response_rule() - ) + return header + _response_rule() + UUID_RE = re.compile(r"[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}")