75 Commits

Author SHA1 Message Date
operator-646 f6dc3233f6 Investigate StrictModes dial-in denial on container 646
- No hatch user exists; dial-in identity is root (pubkey-only)
- Root auth path is StrictModes-clean; /home/hatch not consulted
- Empirical: root dial-in on VM:2226 SUCCEEDED with /home/hatch
  still group-writable -- neither chmod g-w nor StrictModes no needed
- Flagged: super@bl key only in /home/hatch/.ssh (never read by sshd)

Fixes #215
2026-10-09 22:54:50 +00:00
operator-646 97f0e4e50e Verify SSH dial-in perms for container 646
- chmod 600 ~/.ssh/authorized_keys (already 600, verified)
- sshd listening on :22, reverse tunnel VM 127.0.0.1:2226 -> container:22 up
- authorized key present (super@bl); key-auth step belongs to key holder

Fixes #213
2026-10-09 22:49:00 +00:00
operator 6595169a3c docs(policy): agy hold-all exit criteria grill record (Final)
E1-E6: supervised 3-observation proof bar per kind, independent flips,
automatic on proof, single-miss rollback, fleet-wide, grill questions
stay coordinator-gated. Scope accepted verbatim in-record.
2026-10-08 04:03:45 +00:00
operator 41499e069d feat(identity): per-scope network identity plane (slices 1-5)
Fingerprint map + pure resolver (account umbrella / key-level scope
rule), live Warp provider on warp-* structures, broker lifecycle
(up/down/cycle/exec/routes/status/bind), wireguard+socks boilerplate
stubs, agent-manager bind integration. CLI carries emails and
fingerprints only; key bytes never appear. 41 committed tests.
2026-10-08 04:03:45 +00:00
operator 0a45133d28 feat(watchers): add box stability watcher daemon, recovery guardrails, and CLI integration
- Add dedicated watchers/ project folder with box-stability-watcher.py supervisor
- Monitor host load, memory, swap saturation, and crash-looping services
- Implement tiered mitigations: yellow renicing, orange SIGSTOP pause with 60s grace, red shedding
- Distinguish user-launched agents (allowed on desktop default socket) from automated box workloads
- Wire first-class box stability CLI subcommand and top-line host status in fleet status
- Harden tmux.service with cgroup memory limits to prevent OS freeze and OOM avalanches
- Add 10-test unit test suite covering thresholds, safety whitelist, pause/resume, and isolation
2026-10-07 17:49:14 +00:00
operator c11d1d83ae feat(retention): implement Piece 2 job archival, CLI wiring, and rotation driver 2026-10-07 03:28:38 +00:00
operator 094bd7d691 feat(muse): harden choice watcher concurrency, add rules dictionary, resume pool, and session bind 2026-10-07 01:50:18 +00:00
operator e25d2cf4cc feat(systemd): add and enable continuous tmux-auto-approver user daemon 2026-10-07 00:49:23 +00:00
operator 34b0ef9fe2 chore(fleet): sync operator memory, hatch menu dialogs, and watchdog alerts 2026-10-07 00:25:51 +00:00
operator 0065d11e97 feat(supervision): add choice watcher daemon, HTTPS spec docs, and test suites
- bin/muse_choice_watcher.py + systemd/muse-choices-reconcile.*: automatic choice answering and timer reconciliation
- bin/digest.py: fleet log and health summarization
- docs/BOX-*-HTTPS.md: comprehensive HTTPS execution contracts and API documentation
- docs/MUSE-CHOICES-POLICY.md & docs/SUPERVISION-SPEC.md: autonomous execution specs
- tests/test_*.py: unit test suites for HTTPS API, choice watcher, fleet heal, and swarm pruning
2026-10-07 00:25:46 +00:00
operator 9f2a0e836d feat(tmux): implement multi-socket worker tally, regex auto-approver, and onboard TUI
- bin/tmux_auto_approver.py: multi-socket worker discovery across user and netns sockets
- Regex matching engine with 7 terminal prompt rules and hard security guardrails
- bin/box-onboard-tui.py: dedicated 4-tab curses TUI for fleet connects, tmux workers, rules, and audit logs
- Audit logging stream in logs/tmux/auto-approvals.jsonl and state in .state/
- Unit test suites covering engine, rules, guardrails, and curses rendering
2026-10-07 00:25:14 +00:00
operator ae4df2f29c feat(kpi): expand KPI runtime monitoring, prompt advisory envelopes, and missing field resiliency 2026-10-06 20:02:48 +00:00
operator b824f6d405 feat(box): add invite code handler, Settings RPA, and agent onboarding pipeline
- Support invite code discovery in main chat and redemption in settings menu
- Add Settings RPA primitives with Radix UI mouse dispatch and retry polling for async DOM
- Attribute 'has_redeemed' binary from the Additional tokens ticker / entrypoint visibility
- Unblock agent @646 by repairing warp-def/dev tunnels and redeeming REDCJ7 via dev (+1B tokens)
- Implement 'box onboard' pipeline to provision infra, authenticate, and auto-redeem queued codes
- Add 'box onboard feed-matrix' ranking all agents by work done over time, job count, and role
- Register 'InputType.SALVAGE' in loop modulation (CRITICAL priority, 600s timeout, 3 nudges to opm)
- Ingest recurring balance audits into canonical HEARTBEAT.md and TOOLS.md
2026-10-06 19:33:17 +00:00
Muse Sidechat 66c8900a58 feat: setup-fed watchdog supervision for all registry nodes
Close the def/dev supervision gap at the source: every node brought
up gets watched, and every supervisor enumerates the registry.

- bin/ensure-node-supervision.sh (new, idempotent): appends the
  NODES.md row (netvm-names port, honors CDP_PORT_OVERRIDE so it
  never fights provision's picker) and installs/enables
  chromebox-watchdog-<node>.timer. --all heals drift (registry +
  /etc/netvm identities). Template verified byte-identical to the
  installed def unit.
- netvm-node-up.sh: calls ensure (non-fatal) at the end. Provision
  and the onboarding pipeline reach it transitively.
- relay-health-check.sh, cdp-latency-check.sh: registry-driven
  watched_nodes() + LIB_ONLY guards (were hardcoded 4 nodes).
- tests/test_node_supervision.py (6): row add/idempotent/override,
  timer render, node-up wiring, both watched_nodes().
- CHROMEBOX-RUNBOOK.md: setup-fed supervision section.

Pairs with the registry-driven relay/chromebox watchdogs: new rows
are picked up on the next run with no per-node code edits.
2026-10-06 19:28:29 +00:00
Muse Sidechat c9143a558b fix: truthful fleet status in blind shells + agent-health circuit breaker
box fleet status / approvals check misreported every node as STOPPED /
CDP-unreachable from sandboxed shells (own PID+net namespaces: pgrep
blind, no route to 10.201.x.x, no sudo). Fleet was healthy throughout.

- bin/host_evidence.py (new): host watchdog evidence fallback. Recent
  timer runs (journal -o json, exact UNIT match) with no newer failure
  line in cdp-relay-watchdog.log / chromebox-watchdog.log (both
  silent-when-healthy) prove a node is up. def/dev have no watchdog
  coverage: browser verdict via chromebox-<node>.log freshness
  (alive-only), CDP verdict unknown.
- super-cli.py: effective status/source/evidence per node. Host
  evidence decides ONLY the fully-blind pattern (both local probes
  negative); live local signals always win. New UNKNOWN badge, [*]
  footnote; approvals UNREACHABLE splits into BLIND / OFFLINE(host
  agrees) / unreachable-evidence-inconclusive, with honest footer.
  proc_alive/cdp_ok keep local-probe meaning; status/source/evidence
  are new JSON fields.
- approvals.py: host_cdp_ok flag on the unreachable path.
- agent-health.sh: restart circuit breaker. 3 consecutive futile
  restarts (restart leaves agent still failing) opens the circuit:
  no more kills for 1800s, ALERT to log+journal, half-open probe
  after cooldown, reset on any success. Stops the def murder loop
  (57 restarts / 155 API FAILs for an account-layer failure).
- tests/test_fleet_status.py (25), tests/test_agent_health.py (6).
- CHROMEBOX-RUNBOOK.md: blind-shell status + futile-restart sections.

Tests: 98/98 focused green (agent_health + fleet_status +
completion + tool_calls). Live-verified: 4 ACTIVE [*] + 2 UNKNOWN.
2026-10-06 18:16:14 +00:00
Muse Sidechat a9f014f9fa feat: completion-enforcement loop (fallback, proof, emit-model, auditor)
Close the loop so dispatched work actually completes on bl:

- on_no_result fallback in followup-sweeper (op + job forms via
  exec-constrained registry / job-dispatch), seeded on the three
  autonomy-pulse jobs; fallback_due() dedupes the gravity path
- gravity.py: add __main__ entry (loop-remediator.timer was a no-op),
  300s re-arm budget, fallback firing + stamp/skip logic
- harvester: proof-of-result followups (result_has_evidence),
  acted-variant NACK, emit-model tool-hint wording
- envelope: RESPONSE RULE states the emit model (agents EMIT
  directives verbatim; runtime executes; works from bare containers)
- completion-audit.py + systemd 15-min timer: per-family funnel,
  swarm drain, followup backlog; digest DM when degraded, 6h heartbeat
- tests/test_completion.py (29 tests), JOB-SPEC.md docs

Tests: 67/67 focused green (completion + tool_calls).
2026-10-06 08:20:14 +00:00
operator-main f2640397ed feat(messaging): balanced TOOL parsing, DM shorthand, box.exec, tools.list
- response-harvester: extract [TOOL]/[EXEC] JSON args with balanced-brace
  scanning (']' and nesting inside args no longer truncate calls); add
  [DM {...}] shorthand mapping to dm.send; native aliases (dm, box,
  tools) plus arg-synonym normalization; formatters and expanded hints.
- exec-constrained: new read-only box.exec op (27 allowlisted box-ctl
  reads) and tools.list op backed by --list-ops for dynamic discovery.
- prompt_envelope: advertise dm.send/box.exec/tools.list in every timer
  DM; add dm_call builder.
- lookup_engine + regex_patterns.json: canonical tool_call pattern
  accepts the DM engine, ']' in args, one nesting level.
- tests/test_tool_calls.py: 38 tests; docs/INBAND-MESSAGING-SPEC.md:
  accepted decision record (Final).
2026-10-06 07:29:16 +00:00
operator adfcd2e602 feat(box): passkey fetch, agent key-approval flow, unified lookups, tmux agent UX
- box passkey [show|fetch] (+ muse passkey): documents VM-only passkey
  (/srv/box/passkey.txt, fallback /etc/netvm/passkey.txt on 34.139.37.135),
  probes VM over SSH with graceful fallback; --json supported. No secrets on bl.
- approvals: request_key_approval / check_node_key_request; KEY_APPROVAL status
  surfaced in `box approvals check`; allow/deny resolve + audit to box-ctl.jsonl;
  never auto-approved. New `box approvals request-key <node> --reason`.
- box lookup (summary|fleet|threads|unread|approvals|key|docs) and docs-lookup
  engine with lookup_internal/ database (docs_internal symlink).
- muse-tmux: non-TTY attach falls back to scrollback capture; prune NameError fix.
- box/muse passthrough for tmux/muse/docs; thread list/view alias + prefix resolve.
- Docs: AGENTS.md, AGENT-TOOLING.md, BOX-WEB-SURFACE-GUIDE.md, README.
- Tests: key-approval + passkey tests; sync stale sidechat UUIDs and manifest name.
- .gitignore runtime trackers (subagent-sessions, conversation-nudge-tracker).
2026-10-05 20:18:47 +00:00
operator 611181b81e docs(runbook): add fleet resource optimization, timer consolidation, and headless throttling runbook 2026-10-05 17:42:32 +00:00
operator 7fc15eb127 feat(operators): amendment workflow and automated drive watchdog daemon 2026-10-05 17:15:50 +00:00
operator cc8702b38c feat(operators): agent markdown drive management via Hatch and SSH runbook 2026-10-05 16:51:56 +00:00
operator 653166e202 docs: add tmux stability post-mortem and update AGENT-TOOLING with hybrid tmux and direct operator directives 2026-10-05 16:48:44 +00:00
operator 2608fa114f docs: document streamlined Work Order and tmux envelope integration 2026-10-05 16:42:48 +00:00
operator 1e86ed8a44 retention piece 1: immediate rotations for chat-history / job-log / followups (b67084660385)
- chat-history.jsonl rotates at 10MB or 7d -> logs/archive/*.jsonl.gz + .sha256
- job-log.jsonl rotates at 2MB or 14d -> same archive layout
- followups.json archives resolved>7d / escalated>30d -> followups.archive.jsonl (append-only)
- verify wrapper: sha256 -c, gzip -t, clean listing, spot-extract JSON + ts bounds
- driver + hourly systemd user timer (retention-rotations.timer)
- archive-only: nothing is ever deleted; thread backfill excluded (needs human-reviewed preview)
First run 2026-10-05 16:35Z: chat-history 29.7MB + job-log 4.7MB rotated and verified; followups 0 eligible of 163.
2026-10-05 16:37:14 +00:00
operator 4e512a0742 feat(tmux): persist session output and send-keys actions to logs/tmux/<session>.log via pipe-pane 2026-10-05 16:24:36 +00:00
operator 945e6bb481 feat(tmux): implement 2-hour inactivity session TTL reaper and prune command 2026-10-05 16:23:45 +00:00
operator 0ca0fd0c1a feat(tmux): add shared muse tmux socket manager with CLI and agent [TOOL tmux.*] integration 2026-10-05 16:11:19 +00:00
operator 94d6502289 docs: sync onboarding runbooks, node inventory, bridge mappings, and box api docs 2026-10-05 15:58:37 +00:00
operator 7c6c3a8fbf feat(cli): add interactive chat REPL mode for native muse CLI 2026-10-05 15:58:33 +00:00
operator 7b1998f00e docs: add native interactive muse cli wrapper and documentation 2026-10-05 15:50:24 +00:00
operator-main 86f0082ffc feat(main-loop): digest response protocol — actionable digests, reply verbs, closure metrics
Session: sidechat/main-loop-protocol
2026-10-05 00:48:38 +00:00
operator b2920b0da0 docs: formalize fleet autonomous development handoff charter
- Detail operator role allocations (646 lead dev, opm coordinator, pip overseer)
- Document hierarchical subagent delegation & core loop wakeup architecture
- Provide complete sidechat routing matrix and active timer catalog
- Define immediate autonomous development milestones for fleet operators
2026-10-04 23:41:23 +00:00
operator d6ca600394 feat(relay): add subagent spawn, thread tools, and container box client
- Upgrade exec-constrained.py with subagent.spawn, thread.list, thread.view, pipeline.run ops
- Grant full ops permissions to all fleet agent identities (646, pip, muse, opm)
- Implement bin/box-relay.sh zero-dependency client supporting bearer and SSH signature auth
- Add fast hybrid gateway path to dm.py for sub-2s verified deliveries
- Fix wait=0 handling in super-cli.py subagent deployments
- Add hourly check-in jobs and scheduler for 646, pip, muse
- Document agent tooling and relay APIs in docs/AGENT-TOOLING.md
2026-10-04 23:30:18 +00:00
operator 1a271b1bbd feat(hybrid-gateway): integrate muse-cli with Cloudflare netns isolation, symmetric sidechat routing, and 646-pip sync unblock 2026-10-04 22:54:01 +00:00
operator-main 1e82f3adba Document 2026-10-04 followup fix set in LOOP-MANAGEMENT.md (backfill semantics, final_nudge_target, placement gate, multi-RESULT) 2026-10-04 20:09:56 +00:00
operator-main ad9dbca7eb Restore followup/DM reliability fixes wiped by 19:43Z tree-clean
Re-applies three workstreams lost when 793d3d7 committed over uncommitted
edits, reconciled against the parallel track's committed dm.py changes:
- followup-sweeper.py: backfill thread_uuid after successful nudge sends;
  record final_nudge_target=main on final-nudge routing (C1/C2)
- response-harvester.py: resolve followups on main-chat replies when
  final_nudge_target=main (C3); harvest ALL [RESULT] markers per message
- dm.py: pre-send placement gate (fail closed when post-nav URL lacks the
  target thread UUID; skips main) — purely additive over 793d3d7+f268d3d
- sidechat_manager.py: wait_for_chat_list() settle-poll for list population
  race (sidebar button renders before titles load)
- new: bin/tests/test_followup_fixes.py (25 tests), bin/placement-audit.py,
  bin/dm-log-taxonomy.py, bin/session-probe.py,
  docs/SIDECHAT-RELIABILITY.md, docs/UUID-ROTATION.md

Verified: 25/25 tests pass, py_compile clean, sweeper/harvester dry-runs clean.
Known limitation: gate catches wrong-placement, not wrong-mapping (false
autoprovision adopting the parked thread needs a creation check).
2026-10-04 20:06:58 +00:00
operator-main 550e30901b fix: placement verification and sidechat policy enforcement
- dm.py: placement-aware verify (verify_placement), checked_uuid logging, placement_mismatch events
- main-chat-watchdog.py: P0 alerts on placement_mismatch
- box-ctl.py: notify routes to sidechat, box policy command
- jobs: ops-audit and pipe-demo use sidechats
- response-harvester.py: chain deduplication

Session: sidechat/ops-restore
2026-10-04 18:29:13 +00:00
operator 1d739f6b6a feat(loop): codify external intrinsic loop management, progressive remediation, and operational runbook
- Add bin/gravity.py loop diagnostics, reconstruction, and progressive remediation
- Wire hard-break alerting to job-log audit and operator direct message
- Add comprehensive architecture and operational specification in docs/LOOP-MANAGEMENT.md
- Add sidechat thread auto-provisioning fallback on 'Navigated to: None' in bin/dm.py
- Support Muse unconfirmed signup error handling in bin/muse-signin.py
- Track dynamic pipe sidechat mappings in job-sidechats.json
2026-10-04 16:52:54 +00:00
operator-main b8f02af572 docs: add Box Web Surface and orchestration architecture guide 2026-10-04 16:50:57 +00:00
operator 7a35b684c4 feat: unified fleet CLI, Main Chat preservation policy, sidechat routing, and file transfers
- Added CHAT_POLICY.md and README.md banner enforcing sidechat-first and file-transfer-first rules.
- Added strict Main Chat block to super dm send and super dm wo with --allow-main-chat override.
- Implemented file transfer staging and metadata registry in super dm send-file and super dm files (with clean subcommand).
- Added full job lifecycle management (show, create, enable, disable, delete, run --follow) to super-cli.py and box-ctl.py.
- Audited all jobs in jobs/*.json and redirected automated dispatches away from Main Chat.
- Hardened chromebox-watchdog.sh with systemd user session environment exports and stale singleton cleanup.
- Added compose_check command choice to muse-chat-api.py.
2026-10-04 16:34:25 +00:00
operator-main eba6c6965f Add CHROMEBOX-RUNBOOK.md: operator guide for the fleet browser stack
Covers architecture, watchdogs, queue, monitors, common failures, and 2am triage.

Session: sidechat/chromebox-ops
2026-10-04 13:27:29 +00:00
operator-main 0d25696860 docs: exec-server -> exec-constrained stale references (bl:8444)
- docs/TOKEN_POLICY.md: rewritten for exec-constrained.py (named ops,
  -n exec-constrained, {op,args,ts,nonce} envelope; rotate endpoint gone)
- bin/chromebox-gateway.py: exec-server naming -> shared exec token files
- docs/DM-HTTPS-DESIGN-646.md + docs/DM-OVER-HTTPS-DESIGN.md: port
  8443->8444, namespace exec-server->exec-constrained, envelope updated,
  cloudflared port fix marked done 2026-10-04
2026-10-04 13:04:45 +00:00
operator-646 3dd9d9ffaf docs: DM-over-HTTPS design from operator-646 2026-10-04 05:27:55 +00:00
dom-inspector-4 ef453ccb26 Verify + extend DOM-SETTINGS/SEARCH/NOTIFICATIONS (2026-10-04, 3 nodes)
Session: sidechat/dom-settings
2026-10-04 04:31:11 +00:00
dom-panel-inspector 7d0ccba64c docs/DOM-CHAT-PANEL.md — re-verified 2026-10-04 on opm/muse/pip; unread indicator, stripped state, row differences
Session: sidechat/dom-panel
2026-10-04 04:29:16 +00:00
dom-inspector-5 e28b10edc8 DOM inspector 5/5: verify page structure + edge states, regenerate index
Session: sidechat/dom-structure
2026-10-04 04:29:10 +00:00
dom-inspector-2 c50667b626 DOM message surface re-verified 2026-10-04 (3 nodes): .group/msg nesting fix, ownership-split menus, More reactions dialog, dividers, virtualization, DM text formats
Session: sidechat/dom-messages
2026-10-04 04:28:21 +00:00
dom-inspector-3 bbe1ebb76a docs/DOM-APPROVALS.md — approval/permission dialog DOM surface reference
Session: sidechat/dom-approvals
2026-10-04 04:27:16 +00:00
operator-main 4b9f4889e3 docs/BOX-API-DESIGN-THREADS.md — per-agent thread oversight API contract (draft)
Session: main
2026-10-04 04:16:15 +00:00
operator-main 61d59de30d Box API design: timer and job endpoints\n\n- 14 endpoints with full schemas, JSON canonical (not YAML)\n- Allowlisted box-ctl.py helper (no raw systemctl over SSH)\n- Auto-confirmed vs agent-confirmed split for [REQ]/[CONFIRM] 2026-10-04 03:59:01 +00:00