fix(envelope): strip host container key references from prompt envelope to eliminate agent refusal loops

This commit is contained in:
operator
2026-10-05 16:41:42 +00:00
parent a9ab825554
commit f61ceb5f04
+5 -68
View File
@@ -14,33 +14,16 @@ import hashlib
BOX_API = "https://box.muse-dev.online/api/box"
# Verified box-namespace private keys on bl (pubkey matches the agent's entry
# in /srv/board/allowed_signers). Agents without a verified key fall back to
# the [RESULT] line (harvester) until super provisions their box key.
BOX_KEY_PATHS = {
"dev": "/home/super/.ssh/id_dev",
"pip": "/home/super/.ssh/id_pip",
"646": "/home/super/.ssh/id_646",
"opm": "/home/super/.ssh/id_opm",
}
def _response_rule():
return (
"\nRESPONSE RULE: in your reply, every line that is not work output"
" MUST be a curl tool call against https://box.muse-dev.online/."
" Fenced bash blocks are executed as tool calls and their output"
" returns to you; do not narrate the calls.\n"
"\nRESPONSE RULE: Execute your steps using [TOOL ...] directives or background tmux commands."
" When complete, conclude your output with the [RESULT ...] line so the harvester records it.\n"
)
def _box_surface_block(agent, job_name, job_id, target):
"""Thread + runtime + direct curl URL + respond command.
READ: GET /api/box/jobs/<name> (signed, box namespace; live)
RESPOND: POST /api/box/job/result (signed, box namespace, own-scope;
ships with the frontdoor publish -- 404 until then)
"""
"""Clean runtime context block for the agent."""
header = (
"\n---- BOX RUNTIME ----\n"
"THREAD: " + str(target) + "\n"
@@ -48,54 +31,8 @@ def _box_surface_block(agent, job_name, job_id, target):
"JOB: " + str(job_id) + "\n"
"AGENT: " + str(agent) + "\n"
)
key = BOX_KEY_PATHS.get(agent)
if not key:
return (
header
+ "\nNOTE: no box signing key is provisioned for '" + str(agent)
+ "' yet, so curl commands against the box API cannot authenticate."
+ " Ask super to provision your box key; until then the [RESULT]"
+ " line is your respond path (the harvester records it).\n"
+ _response_rule()
)
read_cmd = (
"```bash\n"
"TS=$(date +%s)\n"
"SIG=$(printf '%s\\njobs/" + str(job_name) + "' \"$TS\""
" | ssh-keygen -Y sign -f " + key + " -n box"
" | python3 -c 'import sys,urllib.parse;"
" print(urllib.parse.quote(sys.stdin.read().strip()))')\n"
"curl -s \"" + BOX_API + "/jobs/" + str(job_name)
+ "?identity=" + str(agent) + "&ts=$TS&sig=$SIG\"\n"
"```"
)
respond_cmd = (
"```bash\n"
"TS=$(date +%s)\n"
"export BOX_TS=$TS\n"
"export BOX_SIG=$(printf '%s\\njob/result\\n" + str(job_id) + "' \"$TS\""
" | ssh-keygen -Y sign -f " + key + " -n box)\n"
"python3 - <<'PYEOF' | curl -s -X POST " + BOX_API + "/job/result"
" -H 'Content-Type: application/json' -d @-\n"
"import json, os\n"
"print(json.dumps({\n"
" \"identity\": \"" + str(agent) + "\",\n"
" \"ts\": os.environ[\"BOX_TS\"],\n"
" \"sig\": os.environ[\"BOX_SIG\"],\n"
" \"job_id\": \"" + str(job_id) + "\",\n"
" \"success\": True,\n"
" \"summary\": \"[RESULT " + str(job_id) + "] <one-line summary>\",\n"
"}))\n"
"PYEOF\n"
"```"
)
return (
header
+ "\nREAD your work order any time:\n" + read_cmd + "\n"
+ "\nRESPOND when done -- emit this exact command as a tool call:\n"
+ respond_cmd + "\n"
+ _response_rule()
)
return header + _response_rule()
UUID_RE = re.compile(r"[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}")