25 Commits

Author SHA1 Message Date
operator c11d1d83ae feat(retention): implement Piece 2 job archival, CLI wiring, and rotation driver 2026-10-07 03:28:38 +00:00
operator 04339bad14 feat(box): wire tmux tallies, auto-approvals, and onboard connects into CLI and API
- bin/box-ctl.py: wire tmux-tally, tmux-auto-status, tmux-auto-toggle, tmux-auto-once, and onboard-connects actions with idempotent allowlists
- bin/exec-constrained.py: register tmux.tally, tmux.auto_status, and onboard.connects ops for HTTPS execution
- bin/super-cli.py: wire box tmux dispatch to approver, add cmd_run/cmd_watch, and json unread formatting
- .agents/skills/box/SKILL.md: document tmux worker tally and auto-approval capabilities
2026-10-07 00:25:27 +00:00
operator 740648e973 approvals: stale-wait cleanup, key-decision notify, TTLs, key/browser isolation
- bin/approvals.py: responded-wait filtering + auto-mark, key-decision sidechat-first notify (notified flag, --message, --allow-main-chat), TTL defaults (input 30m / browser 30m / key 2h), cross-type guard (browser actions cannot resolve key requests), sweep_expired_key_requests; restores check_node_key_request fallback in inspect_node_approvals

- bin/box-ctl.py + bin/super-cli.py (approvals hunks only): --message/--allow-main-chat passthrough on allow/deny, clear/clear-all actions, def sidechat routing; restores sys.exit(1) on dismiss failure

- bin/fleet-alert-check.sh: TTL-aware state_machine (EXPIRED action), auto-deny expired browser approvals (fail closed), auto-dismiss expired input waits, targeted per-agent DM for input waits

- bin/job-dispatch.py + bin/gravity.py: KEY_APPROVAL excluded from auto-approval

Reviewed by 5 independent reviewers (all APPROVE/APPROVE WITH NOTES); integration gate GO (17/17 tests). TUI hunks in super-cli.py intentionally excluded.
2026-10-06 00:49:46 +00:00
operator 59c9965791 feat(swarm-worker): dispatch prose swarm slots to ephemeral Muse subagents
- daemon: route non-shell slot tasks to a fresh subagent session on dev/def/muse
  via muse_hybrid; add bin/ to sys.path so muse_hybrid/prompt_envelope import
  under the tmux supervisor
- prompt_envelope: add wrap_subagent_task() - plain task assignment without
  [TOOL tmux/swarm/cron] meta tags (subagents refused those as relayed test traffic)
- box-ctl/reporter: swarm-attach accepts optional session-id, stored as
  slot.subagent_session_id
- executor: _looks_like_shell requires an existing executable (prose like
  'verify ...' no longer misread as shell)
- poller: pick up pending swarms as well as running
- response-harvester: monitor running slot subagent sessions from swarms.json,
  allow '/' in RESULT/VERB job ids, archive ephemeral threads on any verdict
  (OK or FAIL), reap slot sessions for terminal swarms
2026-10-05 20:18:46 +00:00
operator d72b63bfd1 docs(netvm): document watchdog, swarm-worker, and alert relay in README; track approvals CLI 2026-10-05 17:42:01 +00:00
operator 7fc15eb127 feat(operators): amendment workflow and automated drive watchdog daemon 2026-10-05 17:15:50 +00:00
operator cc8702b38c feat(operators): agent markdown drive management via Hatch and SSH runbook 2026-10-05 16:51:56 +00:00
operator 7f92679281 feat(cli): add 'box ssh' command suite (mint, list, show) with auto signers registration 2026-10-05 15:33:38 +00:00
operator 4193a2bd59 feat(swarm): add box swarm prune --stale-hours command and archive stale swarms 2026-10-05 15:18:51 +00:00
box-ctl 719f739c41 Add job auto-work-sweep-j10 via box-ctl 2026-10-05 05:48:42 +00:00
operator c90e096192 feat(autonomy): add followup.create primitive and tool-continuation directives to enforce silence-kills-work 2026-10-05 05:24:45 +00:00
operator b88209d7a1 feat(autonomy): autonomous swarm worker orchestration, nudge triggers, and recursive loop 2026-10-05 04:32:06 +00:00
operator-main b0454289ae feat(box): recursive job workflow -- job-result, job-status, job-next, job-chain 2026-10-05 04:14:04 +00:00
operator 9f27dbd592 feat(main-loop): expand fleet dual monitoring to dev, verify box-relay paths and sidechat brain execution 2026-10-05 01:53:23 +00:00
operator aba4bce682 feat(fleet): expand VALID_AGENTS to include dev and def 2026-10-05 01:38:26 +00:00
operator-main 0822960810 Add main-loop enable/disable per-agent toggle
- self_main_loop.py: 'enabled' map in config (default all True);
  do_check skips disabled agents (marks disabled:true in results);
  new enable/disable actions with optional --agent.
- box-ctl.py: main-loop enable|disable [--agent <name>] actions,
  USAGE updated.

Check skips disabled agents so the loop can be toggled per
Chromebox without stopping the systemd timer.

Session: sidechat/chromebox-ops
2026-10-04 18:52:54 +00:00
operator-main e93e9b6122 Add self_main_loop.py main-chat self-monitor + box main-loop action
Reads each fleet agent's muse.ai Main chat on a 5-min systemd timer
(self-main-loop.timer). On new messages since the per-agent watermark,
posts a concise digest to that agent's prompting sidechat (dm.py, opm
as neutral sender - mirrors box notify), prompting the operator to
check main chat via DM/box. Escapes the main-chat-goes-unread failure
mode. No backfill on first run; silent when nothing new; read/send
failures logged without killing the timer; flock overlap guard.

box-ctl.py: main-loop check | status (fleet section).

Session: sidechat/chromebox-ops
2026-10-04 18:39:46 +00:00
operator-main f679ced960 Add identity-audit-check.sh and box identity-audit action
identity-audit-check.sh: proper script replacing the identity-audit-watch
cron inline SSH one-liner. Reads a bl-local cache of the VM audit JSON
(bl cannot SSH to VM; VM hourly audit should push to var/identity-audit.json).
Exits 0 clean, 1 on drift, 2 if cache missing.

box-ctl.py: new identity-audit action returning drift as JSON.
2026-10-04 18:35:57 +00:00
operator-main a76a776a87 Add cdp-latency-check.sh and box cdp-latency action
Proper script replacing the inline-SSH latency monitor. Probes each relay /json/version via pinned ports from netvm-names.sh, outputs name:latency_ms:code per node. box-ctl.py cdp-latency runs it and returns JSON.
2026-10-04 18:34:52 +00:00
operator-main 2db0d92d5a Add chrome-error-scan.sh and box chrome-errors action
Self-contained per-profile chrome log scanner with watermark-based
new-match detection. Box CLI action returns JSON per-profile counts.

Session: sidechat/chromebox-ops
2026-10-04 18:34:09 +00:00
operator-main 31ed4e2f99 Add relay-health-check.sh and box relay-health action
Converts the cdp-relay-health-monitor from inline SSH (nested quoting
bugs) to a proper self-contained script on bl. Uses pinned ports from
netvm-names.sh as single source of truth.

New files/actions:
- bin/relay-health-check.sh: checks all four CDP relays, exits 0/1
- box-ctl.py relay-health: JSON wrapper for the Box CLI

Session: sidechat/chromebox-ops
2026-10-04 18:32:44 +00:00
operator-main 550e30901b fix: placement verification and sidechat policy enforcement
- dm.py: placement-aware verify (verify_placement), checked_uuid logging, placement_mismatch events
- main-chat-watchdog.py: P0 alerts on placement_mismatch
- box-ctl.py: notify routes to sidechat, box policy command
- jobs: ops-audit and pipe-demo use sidechats
- response-harvester.py: chain deduplication

Session: sidechat/ops-restore
2026-10-04 18:29:13 +00:00
operator 7a35b684c4 feat: unified fleet CLI, Main Chat preservation policy, sidechat routing, and file transfers
- Added CHAT_POLICY.md and README.md banner enforcing sidechat-first and file-transfer-first rules.
- Added strict Main Chat block to super dm send and super dm wo with --allow-main-chat override.
- Implemented file transfer staging and metadata registry in super dm send-file and super dm files (with clean subcommand).
- Added full job lifecycle management (show, create, enable, disable, delete, run --follow) to super-cli.py and box-ctl.py.
- Audited all jobs in jobs/*.json and redirected automated dispatches away from Main Chat.
- Hardened chromebox-watchdog.sh with systemd user session environment exports and stale singleton cleanup.
- Added compose_check command choice to muse-chat-api.py.
2026-10-04 16:34:25 +00:00
box-ctl a214355f16 box-ctl: expand actions (vars, strat, loop) + harden input validation 2026-10-04 16:17:10 +00:00
operator-main a9812cd355 Add box-ctl.py: allowlisted bl helper for Box API mutations\n\n- 14 actions: timer-list/status/create/delete/start/stop/enable/disable,\n job-list/get/put/delete/trigger, notify\n- Name regex ^[a-z0-9-]{1,64}$, full job schema validation per design §6\n- Cron→OnCalendar conversion + systemd-analyze verification\n- Fixed unit templates (only validated name interpolated)\n- Git commits on job put/delete; audit log to box-ctl.jsonl\n- No shell=True, no string interpolation into commands\n- Tested: full lifecycle on bl (boxtest job) 2026-10-04 04:02:19 +00:00