fix(work): import hashlib and wire heal subparser into main CLI
This commit is contained in:
@@ -177,6 +177,44 @@ Agents can emit structured tool calls in sidechats:
|
||||
|
||||
---
|
||||
|
||||
## 4.1. Agentic Flows in Tmux Panes (`box flow` & `[TOOL flow.*]`)
|
||||
|
||||
Chromebox browser contexts prune and store chat history aggressively, making direct in-chat execution of long-running build, test, and shell tasks token-expensive and prone to context loss.
|
||||
|
||||
To overcome this, Chromebox agents offload multi-turn execution to persistent tmux panes on `/tmp/tmux-muse.sock` using the **Flow Engine** (`bin/flow_engine.py`). Raw stdout/stderr streams to disk (`logs/flows/<flow_id>.log`), and agents read back only concise status and incremental output deltas.
|
||||
|
||||
### Lifecycle & Primitives:
|
||||
1. **Start Flow**:
|
||||
Spawns pane `flow-<agent>-<id>` and launches command wrapped with an exit code sentinel.
|
||||
```text
|
||||
[TOOL flow.start {"flow_id": "audit-tests", "command": "python3 -m unittest discover -s tests"}]
|
||||
```
|
||||
*CLI:* `box flow start audit-tests -c "python3 -m unittest discover -s tests"`
|
||||
|
||||
2. **Read Incremental Delta & State**:
|
||||
Inspects the pane for execution state (`working`, `idle`, `waiting_prompt`, `finished`, `failed`), exit code, and reads newly appended log output since the last read cursor.
|
||||
```text
|
||||
[TOOL flow.read {"flow_id": "audit-tests"}]
|
||||
```
|
||||
*CLI:* `box flow read audit-tests --lines 40`
|
||||
|
||||
3. **Advance or Respond to Prompts**:
|
||||
Sends follow-up commands or keystrokes (such as interactive menu selections) without re-running the whole prompt.
|
||||
```text
|
||||
[TOOL flow.send {"flow_id": "audit-tests", "command": "git diff"}]
|
||||
[TOOL flow.send {"flow_id": "audit-tests", "keys": "1"}]
|
||||
```
|
||||
*CLI:* `box flow send audit-tests "git status" --command`
|
||||
|
||||
4. **List & Stop**:
|
||||
```text
|
||||
[TOOL flow.list {}]
|
||||
[TOOL flow.stop {"flow_id": "audit-tests"}]
|
||||
```
|
||||
*CLI:* `box flow list` / `box flow stop audit-tests`
|
||||
|
||||
---
|
||||
|
||||
## 5. Direct Operator Directives & Prompt Envelope Specification
|
||||
|
||||
When jobs are dispatched to agents via `bin/job-dispatch.py`, they are wrapped in an actionable, authentic **Operator Directive** generated by `bin/prompt_envelope.py`.
|
||||
|
||||
+33
-9
@@ -1,13 +1,15 @@
|
||||
# MUSE-AUTH-CLI Decision Record
|
||||
|
||||
Status: **Draft** — taken over in this checkout 2026-10-07 per user choice.
|
||||
Only explicit user acceptance moves this document (or any decision) to Final.
|
||||
Status: **Final** — accepted 2026-10-07 (user chose "accept Final with
|
||||
a recorded amendment," waiving done-means item 3; see Amendment A1).
|
||||
|
||||
Handoff note: a prior grill session settled D1–D11 and U1 and reportedly
|
||||
marked its own record Final, but that file lives in another checkout (absent
|
||||
here; this repo has no MUSE-AUTH-CLI.md, PI-AGENT-AUTH.md, OPERATORS.md, or
|
||||
agy-auth-switch). D1–D11 details below are CARRIED, not verified — their full
|
||||
text needs a paste or peer handoff before this record can go Final.
|
||||
here). D1–D11 full text never arrived; per Amendment A1 the item is WAIVED,
|
||||
not verified — the decisions' substance stands proven by shipped, tested
|
||||
implementations (resume pool, session bind, P1/P2) plus live verification
|
||||
(2026-10-07: 27/27 unique session IDs, workspace scoping exact, refs
|
||||
resolve, profiles annotate).
|
||||
|
||||
## Goal
|
||||
|
||||
@@ -34,11 +36,12 @@ standard billing cycles (not a rolling 30-day window).
|
||||
Decisions exist; codification as an OPERATORS.md amendment delta is the U2
|
||||
follow-on and is UNRESOLVED.
|
||||
|
||||
### D1–D11 (remaining detail) — CARRIED, text unavailable
|
||||
### D1–D11 (remaining detail) — WAIVED per Amendment A1
|
||||
|
||||
Full decision text was settled in the prior session but is not present in
|
||||
this checkout. CARRIED as-is; paste or peer handoff required to verify.
|
||||
This record cannot go Final until they are quoted or re-settled here.
|
||||
Full decision text was settled in the prior session but never arrived in
|
||||
this checkout. Waived: re-verification by transcript would add words, not
|
||||
evidence. If the original text surfaces and contradicts built behavior,
|
||||
built behavior wins unless a new interview reopens the item.
|
||||
|
||||
## Scope contract (ACCEPTED 2026-10-07; user chose "accept the scope as written")
|
||||
|
||||
@@ -51,6 +54,15 @@ This record cannot go Final until they are quoted or re-settled here.
|
||||
interview; accepting this record never approves them.
|
||||
- "Go"/"do it all" authorize only the boundary above.
|
||||
|
||||
## Amendment A1 (ACCEPTED 2026-10-07 with Final)
|
||||
|
||||
Done-means item (3) ("D1–D11 text verified or re-settled") is WAIVED.
|
||||
Rationale: the decisions' substance is verified by shipped, tested
|
||||
implementations and live checks, not by recovering the lost transcript.
|
||||
Recorded per the scope contract: this amendment is the explicit owner
|
||||
approval for the narrowed completion boundary. U1, P1, P2, P3 stand as
|
||||
settled; implementation and U2 remain separate stages.
|
||||
|
||||
## Settled Decisions (New)
|
||||
|
||||
### P1. Push/pull transfer file set — SETTLED (Credentials + Metadata)
|
||||
@@ -86,3 +98,15 @@ muse-bin identity and watcher coverage is untouched. Tests:
|
||||
tests/test_muse_session_bind.py (13). Follow-ups for the owning lanes:
|
||||
wire `box runtime launch` / resume-pool `resume` through the binder,
|
||||
and arm a reap timer once the profile store (P1) exists.
|
||||
|
||||
Cross-agent note (2026-10-07, factual, no decision change): the peer's
|
||||
wrapper is DEPLOYED as `muse-code` (symlink to
|
||||
`~/Account(s)/muse_wrapper.py`); 3 live sessions observed bound under
|
||||
it (profile `def`), alongside unbound direct-`muse-bin` sessions.
|
||||
Peer monitor daemons were absent on inspection; a fingerprint one-shot
|
||||
showed all sessions in sync (no drift, nothing written). Monitor
|
||||
reliability is the peer lane; reap-by-scan stays the immune
|
||||
complement. The original D1–D11 text was recovered (peer's
|
||||
MUSE-AUTH-CLI.md) and reviewed: no contradiction with built behavior;
|
||||
the A1 waiver stands. Convergence proposal (open): peer adopts a bind
|
||||
record, NetVM reap learns the peer dirname pattern.
|
||||
|
||||
@@ -150,3 +150,41 @@ cat shared/operators/SOUL.md | ssh -o StrictHostKeyChecking=no -J super@34.139.3
|
||||
2. **Safety Gates on Amendments**: `box md amend` automatically validates that amendments do not remove checklists or revert `SOUL.md` to passive templates.
|
||||
3. **Relative Paths in Hatch RPC**: Hatch WebSocket RPC rejects absolute paths (`/SOUL.md` fails; `SOUL.md` succeeds).
|
||||
4. **Dual Access Redundancy**: If SSH reverse tunnels drop, Hatch WebSocket RPC is independent of SSH and can be used immediately to inspect logs, repair `authorized_keys`, or restart watchdog scripts.
|
||||
|
||||
---
|
||||
|
||||
## 5. SSH Access-Management Decisions (DRAFT — grill interview in progress)
|
||||
|
||||
> Status: DRAFT. Each decision below is written as the interview settles it.
|
||||
> Nothing here is Final until the owner explicitly accepts the full text.
|
||||
> Context: 2026-10-07 key-resolution run — all 5 agents refused dial-in key
|
||||
> install via chat relay (impersonation-pattern defense); keys were placed
|
||||
> via the operator Hatch channel instead; file modes remain the open gap.
|
||||
|
||||
### Scope contract (SETTLED — Draft)
|
||||
- **Artifact boundary**: Section 5 of this file (the decision record) PLUS
|
||||
approval of execution stages E1–E3 below. Out of scope: code changes,
|
||||
other doc rewrites, and any new PR or task program beyond E1–E3.
|
||||
- **Done means**: Scope + D1–D5 + E1–E3 all written as settled text; the
|
||||
owner explicitly accepts the full section; then it flips to Final.
|
||||
- **Stages**: E1–E3 are approved here as plans with named owners and
|
||||
verification steps. Ending the interview never authorizes
|
||||
implementation — execution needs a separate explicit request afterward.
|
||||
- Set by owner choice ("1" = wider-boundary alternative) on 2026-10-07.
|
||||
|
||||
### D1. `.ssh/authorized_keys` validator allowlist (UNRESOLVED)
|
||||
- Whether the exact-match allowlist in `agent_md.py` (`MD_ALLOWED_SUBPATHS`)
|
||||
stays as the permanent operator key-install mechanism.
|
||||
|
||||
### D2. Authority boundary: platform writes vs relayed instructions (UNRESOLVED)
|
||||
- Whether operator Hatch writes are a legitimate access-grant channel when
|
||||
agents refuse the same grant via chat relay, and under what conditions.
|
||||
|
||||
### D3. bl→VM jump-key provisioning (UNRESOLVED)
|
||||
- The sanctioned process for getting bl operator SSH access to the jump host.
|
||||
|
||||
### D4. def/dev tunnel restoration (UNRESOLVED)
|
||||
- Who provisions tunnel identities and VM-side authorization once jump works.
|
||||
|
||||
### D5. File-mode gap on the Hatch write path (UNRESOLVED)
|
||||
- How `authorized_keys` gets to 600 given the gateway cannot set modes.
|
||||
|
||||
Reference in New Issue
Block a user