fix(work): import hashlib and wire heal subparser into main CLI

This commit is contained in:
operator
2026-10-09 23:13:43 +00:00
parent c3b4b1cd28
commit f75977ca6e
202 changed files with 4185 additions and 4142 deletions
+38
View File
@@ -177,6 +177,44 @@ Agents can emit structured tool calls in sidechats:
---
## 4.1. Agentic Flows in Tmux Panes (`box flow` & `[TOOL flow.*]`)
Chromebox browser contexts prune and store chat history aggressively, making direct in-chat execution of long-running build, test, and shell tasks token-expensive and prone to context loss.
To overcome this, Chromebox agents offload multi-turn execution to persistent tmux panes on `/tmp/tmux-muse.sock` using the **Flow Engine** (`bin/flow_engine.py`). Raw stdout/stderr streams to disk (`logs/flows/<flow_id>.log`), and agents read back only concise status and incremental output deltas.
### Lifecycle & Primitives:
1. **Start Flow**:
Spawns pane `flow-<agent>-<id>` and launches command wrapped with an exit code sentinel.
```text
[TOOL flow.start {"flow_id": "audit-tests", "command": "python3 -m unittest discover -s tests"}]
```
*CLI:* `box flow start audit-tests -c "python3 -m unittest discover -s tests"`
2. **Read Incremental Delta & State**:
Inspects the pane for execution state (`working`, `idle`, `waiting_prompt`, `finished`, `failed`), exit code, and reads newly appended log output since the last read cursor.
```text
[TOOL flow.read {"flow_id": "audit-tests"}]
```
*CLI:* `box flow read audit-tests --lines 40`
3. **Advance or Respond to Prompts**:
Sends follow-up commands or keystrokes (such as interactive menu selections) without re-running the whole prompt.
```text
[TOOL flow.send {"flow_id": "audit-tests", "command": "git diff"}]
[TOOL flow.send {"flow_id": "audit-tests", "keys": "1"}]
```
*CLI:* `box flow send audit-tests "git status" --command`
4. **List & Stop**:
```text
[TOOL flow.list {}]
[TOOL flow.stop {"flow_id": "audit-tests"}]
```
*CLI:* `box flow list` / `box flow stop audit-tests`
---
## 5. Direct Operator Directives & Prompt Envelope Specification
When jobs are dispatched to agents via `bin/job-dispatch.py`, they are wrapped in an actionable, authentic **Operator Directive** generated by `bin/prompt_envelope.py`.
+33 -9
View File
@@ -1,13 +1,15 @@
# MUSE-AUTH-CLI Decision Record
Status: **Draft** — taken over in this checkout 2026-10-07 per user choice.
Only explicit user acceptance moves this document (or any decision) to Final.
Status: **Final** — accepted 2026-10-07 (user chose "accept Final with
a recorded amendment," waiving done-means item 3; see Amendment A1).
Handoff note: a prior grill session settled D1–D11 and U1 and reportedly
marked its own record Final, but that file lives in another checkout (absent
here; this repo has no MUSE-AUTH-CLI.md, PI-AGENT-AUTH.md, OPERATORS.md, or
agy-auth-switch). D1–D11 details below are CARRIED, not verified — their full
text needs a paste or peer handoff before this record can go Final.
here). D1–D11 full text never arrived; per Amendment A1 the item is WAIVED,
not verified — the decisions' substance stands proven by shipped, tested
implementations (resume pool, session bind, P1/P2) plus live verification
(2026-10-07: 27/27 unique session IDs, workspace scoping exact, refs
resolve, profiles annotate).
## Goal
@@ -34,11 +36,12 @@ standard billing cycles (not a rolling 30-day window).
Decisions exist; codification as an OPERATORS.md amendment delta is the U2
follow-on and is UNRESOLVED.
### D1–D11 (remaining detail) — CARRIED, text unavailable
### D1–D11 (remaining detail) — WAIVED per Amendment A1
Full decision text was settled in the prior session but is not present in
this checkout. CARRIED as-is; paste or peer handoff required to verify.
This record cannot go Final until they are quoted or re-settled here.
Full decision text was settled in the prior session but never arrived in
this checkout. Waived: re-verification by transcript would add words, not
evidence. If the original text surfaces and contradicts built behavior,
built behavior wins unless a new interview reopens the item.
## Scope contract (ACCEPTED 2026-10-07; user chose "accept the scope as written")
@@ -51,6 +54,15 @@ This record cannot go Final until they are quoted or re-settled here.
interview; accepting this record never approves them.
- "Go"/"do it all" authorize only the boundary above.
## Amendment A1 (ACCEPTED 2026-10-07 with Final)
Done-means item (3) ("D1–D11 text verified or re-settled") is WAIVED.
Rationale: the decisions' substance is verified by shipped, tested
implementations and live checks, not by recovering the lost transcript.
Recorded per the scope contract: this amendment is the explicit owner
approval for the narrowed completion boundary. U1, P1, P2, P3 stand as
settled; implementation and U2 remain separate stages.
## Settled Decisions (New)
### P1. Push/pull transfer file set — SETTLED (Credentials + Metadata)
@@ -86,3 +98,15 @@ muse-bin identity and watcher coverage is untouched. Tests:
tests/test_muse_session_bind.py (13). Follow-ups for the owning lanes:
wire `box runtime launch` / resume-pool `resume` through the binder,
and arm a reap timer once the profile store (P1) exists.
Cross-agent note (2026-10-07, factual, no decision change): the peer's
wrapper is DEPLOYED as `muse-code` (symlink to
`~/Account(s)/muse_wrapper.py`); 3 live sessions observed bound under
it (profile `def`), alongside unbound direct-`muse-bin` sessions.
Peer monitor daemons were absent on inspection; a fingerprint one-shot
showed all sessions in sync (no drift, nothing written). Monitor
reliability is the peer lane; reap-by-scan stays the immune
complement. The original D1–D11 text was recovered (peer's
MUSE-AUTH-CLI.md) and reviewed: no contradiction with built behavior;
the A1 waiver stands. Convergence proposal (open): peer adopts a bind
record, NetVM reap learns the peer dirname pattern.
+38
View File
@@ -150,3 +150,41 @@ cat shared/operators/SOUL.md | ssh -o StrictHostKeyChecking=no -J super@34.139.3
2. **Safety Gates on Amendments**: `box md amend` automatically validates that amendments do not remove checklists or revert `SOUL.md` to passive templates.
3. **Relative Paths in Hatch RPC**: Hatch WebSocket RPC rejects absolute paths (`/SOUL.md` fails; `SOUL.md` succeeds).
4. **Dual Access Redundancy**: If SSH reverse tunnels drop, Hatch WebSocket RPC is independent of SSH and can be used immediately to inspect logs, repair `authorized_keys`, or restart watchdog scripts.
---
## 5. SSH Access-Management Decisions (DRAFT — grill interview in progress)
> Status: DRAFT. Each decision below is written as the interview settles it.
> Nothing here is Final until the owner explicitly accepts the full text.
> Context: 2026-10-07 key-resolution run — all 5 agents refused dial-in key
> install via chat relay (impersonation-pattern defense); keys were placed
> via the operator Hatch channel instead; file modes remain the open gap.
### Scope contract (SETTLED — Draft)
- **Artifact boundary**: Section 5 of this file (the decision record) PLUS
approval of execution stages E1–E3 below. Out of scope: code changes,
other doc rewrites, and any new PR or task program beyond E1–E3.
- **Done means**: Scope + D1–D5 + E1–E3 all written as settled text; the
owner explicitly accepts the full section; then it flips to Final.
- **Stages**: E1–E3 are approved here as plans with named owners and
verification steps. Ending the interview never authorizes
implementation — execution needs a separate explicit request afterward.
- Set by owner choice ("1" = wider-boundary alternative) on 2026-10-07.
### D1. `.ssh/authorized_keys` validator allowlist (UNRESOLVED)
- Whether the exact-match allowlist in `agent_md.py` (`MD_ALLOWED_SUBPATHS`)
stays as the permanent operator key-install mechanism.
### D2. Authority boundary: platform writes vs relayed instructions (UNRESOLVED)
- Whether operator Hatch writes are a legitimate access-grant channel when
agents refuse the same grant via chat relay, and under what conditions.
### D3. bl→VM jump-key provisioning (UNRESOLVED)
- The sanctioned process for getting bl operator SSH access to the jump host.
### D4. def/dev tunnel restoration (UNRESOLVED)
- Who provisions tunnel identities and VM-side authorization once jump works.
### D5. File-mode gap on the Hatch write path (UNRESOLVED)
- How `authorized_keys` gets to 600 given the gateway cannot set modes.