Commit Graph

165 Commits

Author SHA1 Message Date
operator 2fa2955fb3 feat(harvester): add opportunistic harvest_main_feed with zero navigation and per-node fault isolation 2026-10-04 16:45:34 +00:00
operator 8bfe94d0f3 test(nav): add unit test suite for main chat policy, sidechat routing, and transfer lifecycle 2026-10-04 16:43:50 +00:00
operator-main cf8f59b737 fix(watchdog): generalize CDP page health check for Muse targets 2026-10-04 16:39:30 +00:00
operator 87fd93e7a6 feat(dm): implement Reset-at-Begin and Leave-in-Sidechat pattern to preserve Main Chat DOM 2026-10-04 16:39:23 +00:00
operator aa125bb7be feat(onboarding): propagate NEEDS_SIGNUP (code 4) through onboard-driver and muse-signin 2026-10-04 16:37:26 +00:00
operator 7a35b684c4 feat: unified fleet CLI, Main Chat preservation policy, sidechat routing, and file transfers
- Added CHAT_POLICY.md and README.md banner enforcing sidechat-first and file-transfer-first rules.
- Added strict Main Chat block to super dm send and super dm wo with --allow-main-chat override.
- Implemented file transfer staging and metadata registry in super dm send-file and super dm files (with clean subcommand).
- Added full job lifecycle management (show, create, enable, disable, delete, run --follow) to super-cli.py and box-ctl.py.
- Audited all jobs in jobs/*.json and redirected automated dispatches away from Main Chat.
- Hardened chromebox-watchdog.sh with systemd user session environment exports and stale singleton cleanup.
- Added compose_check command choice to muse-chat-api.py.
2026-10-04 16:34:25 +00:00
operator 4a935bd0c7 feat(automation): sidechat auto-provisioning, response harvester, followup sweeper, and super CLI 2026-10-04 16:23:10 +00:00
box-ctl a214355f16 box-ctl: expand actions (vars, strat, loop) + harden input validation 2026-10-04 16:17:10 +00:00
operator-main a32670731f chromebox-watchdog: fix kill loop on slow cold starts
Two fixes: (1) retry health check 4x with 15s gaps after relaunch instead of single 25s check; (2) skip kill if browser launched <2min ago (probably still starting). Prevents watchdog from killing a working-but-slow browser.

Session: sidechat/chromebox-ops
2026-10-04 13:17:13 +00:00
operator-main 5f0a77d04b Integrate cdp_queue into CDP path
All CDP sessions now go through per-node queue (max 2 concurrent, priority levels). DM sends use high priority. Graceful fallback if module unavailable.

Session: sidechat/chromebox-ops
2026-10-04 13:15:59 +00:00
operator-main 0d25696860 docs: exec-server -> exec-constrained stale references (bl:8444)
- docs/TOKEN_POLICY.md: rewritten for exec-constrained.py (named ops,
  -n exec-constrained, {op,args,ts,nonce} envelope; rotate endpoint gone)
- bin/chromebox-gateway.py: exec-server naming -> shared exec token files
- docs/DM-HTTPS-DESIGN-646.md + docs/DM-OVER-HTTPS-DESIGN.md: port
  8443->8444, namespace exec-server->exec-constrained, envelope updated,
  cloudflared port fix marked done 2026-10-04
2026-10-04 13:04:45 +00:00
operator-main 6e9421644a Add cdp_queue.py: per-browser CDP operation queue
Per-node FIFO, max 2 concurrent, priority levels (high/normal/low), flock-based cross-process coordination. DM sends use high priority.

Session: sidechat/chromebox-ops
2026-10-04 13:04:24 +00:00
operator-main f9dce15a6d netvm-topology.sh: relay check by connectivity, not pidfiles
Pidfiles go stale and lie. Primary verdict now curls the veth IP:port. Also pins registry CDP ports (hash-derived CDP_PORT was wrong).

Session: sidechat/chromebox-ops
2026-10-04 12:41:40 +00:00
operator-main 343920e0c3 Watchdog upgrades: stage-specific logging + new CDP relay watchdog
chromebox-watchdog.sh: HEALTH_FAIL_REASON pinpoints which health stage failed (no process / CDP unreachable / no Chat page); chromium stdout redirected to per-profile chromebox-<profile>.log; 10MB log rotation (one generation); Chat title match relaxed to .*Chat.

bin/cdp-relay-watchdog.sh (new): keeps per-node CDP relays alive. Two-stage check: (1) host veth IP assigned (fail-loud, no auto-fix — veth recreation touches WireGuard/iptables), (2) relay connectivity via curl to veth IP:port (never trust pidfiles — observed stale 2026-10-04). Restarts dead/misrouted relays in-netns. Runs via systemd timer every 5min. Pattern mirrors chromebox-watchdog.sh.

Session: sidechat/chromebox-ops
2026-10-04 12:40:56 +00:00
operator-main 45741f1151 bin/box-chat.py + box-chat-cdp.py — read-only bl helper for Box thread oversight
Session: sidechat/box-chat
2026-10-04 04:31:39 +00:00
operator-main 844aa73bd9 UUID-based sidechat reuse for heartbeat\n\n- Add url command to muse-chat-api.py\n- Dispatcher: reuse_key -> thread UUID mapping in job-sidechats.json\n- Capture UUID after first send, reuse on subsequent runs\n- Fixes multi-spawn bug (was matching by auto-generated title) 2026-10-04 04:03:28 +00:00
operator-main a9812cd355 Add box-ctl.py: allowlisted bl helper for Box API mutations\n\n- 14 actions: timer-list/status/create/delete/start/stop/enable/disable,\n job-list/get/put/delete/trigger, notify\n- Name regex ^[a-z0-9-]{1,64}$, full job schema validation per design §6\n- Cron→OnCalendar conversion + systemd-analyze verification\n- Fixed unit templates (only validated name interpolated)\n- Git commits on job put/delete; audit log to box-ctl.jsonl\n- No shell=True, no string interpolation into commands\n- Tested: full lifecycle on bl (boxtest job) 2026-10-04 04:02:19 +00:00
operator-main 72574baa4b Replace Ctrl+J with click-based chat activation\n\n- New _ensure_chat_active(): compose -> switcher -> nav-chat priority\n- hatch-nav-chat click recovers from stripped /thread/new state\n- Ctrl+J needed keyboard focus which stripped states lack 2026-10-04 03:46:47 +00:00
operator-main 7d48123835 Heartbeat to sidechat with reuse\n\n- Dispatcher: reuse existing sidechat by name (not create new each time)\n- Heartbeat job: sidechat.create=true, name_template=heartbeat (fixed) 2026-10-04 03:40:25 +00:00
operator-main 12dca45107 cmd_sidechat_create: navigate to main first\n\nReliability test found success poisons next run (browser left on\n/thread/new with stripped DOM). Now navigates to main via Ctrl+J\nat start for known good state. 2026-10-04 03:38:46 +00:00
operator-main f8b6475396 cmd_sidechat_create: exact header check for panel state\n\ninnerText.includes was always true (switcher button text).\nNow checks for exact Side chats header text node, loops up to 5x. 2026-10-04 03:38:22 +00:00
operator-main 8ff4dd0e30 cmd_sidechat_create: check + first, open panel only if needed\n\nAvoids unnecessary switcher click when panel already open. 2026-10-04 03:37:32 +00:00
operator-main 4379610d06 cmd_sidechat_create: verified working selectors\n\nDOM investigation found:\n- Switcher: [data-testid=hatch-chat-switcher-trigger] (idempotent)\n- Plus: [data-testid=hatch-chat-compose] (SVG, no text)\n- Old text-based checks were false-positive on DM content 2026-10-04 03:37:01 +00:00
operator-main bc4cd77a52 Fix sidechat selectors from DOM investigation\n\n- + button: [data-testid=hatch-chat-compose] (SVG, no text)\n- Panel: [data-testid=hatch-chat-switcher-trigger] (idempotent)\n- ensure_sidebar: check + button presence, not text (was false-positive\n on DM text containing Side chats) 2026-10-04 03:36:06 +00:00
operator-main 1cffacc7d1 Sidechat: render wait, direct send, stderr logging\n\n- Wait for Side chats to render before finding + button\n- Dispatcher: send_to_current_chat for sidechat jobs\n- Log stderr on create failure 2026-10-04 03:29:21 +00:00
operator-main 5feca52602 cmd_sidechat_create: remove Ctrl+J toggle\n\nPanel is always open; Ctrl+J toggle was closing it.\nJust find the + button directly. 2026-10-04 03:26:17 +00:00
operator-main 7938322e6d cmd_sidechat_create: Ctrl+J opens chat panel via CDP\n\nSidebar is actually the chat panel (Ctrl+J toggle).\nUse proven Input.dispatchKeyEvent like cmd_sidechat_main. 2026-10-04 03:25:37 +00:00
operator-main 34082045cc Nail sidechat create: direct send, no ID lookup\n\n- cmd_sidechat_create: simplified, just create and return\n- job-dispatch: after create, send via direct API to current chat\n- No thread ID parsing needed; thread lookup via URL for later ops 2026-10-04 03:23:34 +00:00
operator-main 4524907663 sidechat_manager: Use data-testid for sidebar button\n\nReliable selector hatch-chat-switcher-trigger instead of\nflaky text matching. 2026-10-04 03:20:42 +00:00
operator-main c57a05963a Fix sidechat CDP and button selectors\n\n- sidechat_manager._ev: use id=1 and returnByValue to match ev()\n- cmd_sidechat_create: find + button via Side chats header proximity\n- cmd_sidechat_create: use cmd_send for initial message (not DOM hack)\n- Integrate ensure_sidebar with retry 2026-10-04 03:19:48 +00:00
operator-main 7a6e54fed2 sidechat_manager: Fix CDP id mismatch\n\n_e() used id=100, muse-chat-api.py ev() uses id=1.\nOn shared websocket, responses mismatched. 2026-10-04 03:16:10 +00:00
operator-main 2074145e22 muse-chat-api.py: Integrate sidechat_manager.ensure_sidebar\n\nUse robust sidebar opener with exponential backoff retry\ninstead of single-attempt click. Fixes flaky NOSIDEBAR errors. 2026-10-04 03:15:07 +00:00
operator-main 50ddecb02e muse-chat-api.py: Get real thread ID after sidechat create\n\nSend system message to trigger ID assignment, poll for\n/thread/<uuid> instead of accepting /thread/new placeholder. 2026-10-04 03:13:07 +00:00
operator-main 942f37e21c job-dispatch.py: Send job DM to sidechat directly\n\nWhen sidechat.create=true, the job DM now goes to the sidechat\nitself (via thread ID), not to main chat. Keeps main clean;\nthe sidechat IS the workspace. 2026-10-04 03:11:11 +00:00
operator-main 39e47ab2ef muse-chat-api.py: Fix sidechat create URL race\n\nPoll for /thread/ URL up to 15s instead of fixed 5s sleep.\nWas capturing base URL before navigation settled. 2026-10-04 03:10:52 +00:00
operator-main 35bd358b78 job-dispatch.py: Add sidechat creation support\n\nWhen job has sidechat.create=true, creates sidechat via\nmuse-chat-api.py in sender context, includes URL in DM. 2026-10-04 03:09:42 +00:00
operator-main 78dbf8f131 Add job-dispatch.py: JOB system dispatcher\n\nReads job JSON, renders prompt template, sends DM via dm.py,\nlogs to job-log.jsonl. Tested end-to-end: canary-test job\ndispatched successfully (DM 36bd80aa SENT and VERIFIED). 2026-10-04 03:06:46 +00:00
operator-main 70b82f5a8b Add sidechat_manager.py: robust sidebar operations with retry and logging\n\n- ensure_sidebar() with exponential backoff (2s, 4s, 6s)\n- list_sidechats() with heuristic parsing\n- log_sidechat_op() for audit trail to sidechat-log.jsonl\nAddresses flaky NOSIDEBAR errors from hardcoded sleeps. 2026-10-04 02:49:38 +00:00
operator-main 7c591c73bc Add shared rate_limiter.py module\n\nModular rate limiter any .py script can use:\n from rate_limiter import rate_limit_wait\n rate_limit_wait(agent)\n\nToken bucket per agent: 1 op/3s sustained, burst 5, max 20/min.\nState in /tmp/netvm-rate-limit.json. 2026-10-04 02:40:56 +00:00
operator-main c48fbc03f6 muse-chat-api: Dont block sends on dialogs without IPs\n\ncheck_approvals was raising APPROVAL_NEEDED for false positives\n(dialogs without IP addresses, likely chat content misidentified).\nOnly IP-based permission dialogs should block. Others are ignored. 2026-10-04 02:32:38 +00:00
operator-main d82bf58e78 DM: signed-DM pipeline (dm-sign.sh) + attribution unification + honest docs
- New bin/dm-sign.sh: produce signed DMs (ssh-keygen -Y sign, namespace
  dm) in the [from:X] [id:Y] wire format that dm.py verify-sig checks.
  dm.py referenced it in usage but it never existed.
- dm.py: rewrite stale docstring/argparse (claimed verification was
  removed / delivery unconfirmed — it does recipient-side read-back with
  3 retries); unify all attribution on [from:X]/[id:Y] (was three
  formats: [from X], [X], [from:X]); fix dm_thread double-attribution;
  --no-verify kept as a documented no-op; raw mode sends verbatim and
  reuses the embedded [id:Y] for the audit log; navigation/send/park
  now all target the recipient browser (fixes cross-operator side-chat
  sends); drop dead --from-sender flag.
- Register dm-signers/operator-main.pub.
- Round-trip verified: sign (operator-main) -> send --raw via opm
  loopback -> read-back SENT+VERIFIED -> verify-sig GOOD.
2026-10-04 02:31:37 +00:00
operator-main 6189793748 agent-health.sh: Verify CDP port liveness, not just API success\n\nThe watchdog only checked if the API responded, missing zombie\nbrowsers (process alive but CDP not listening). Now explicitly\nchecks via ss -tln in the netns before trying the API.\nAlso: kill by exact PIDs instead of unreliable pkill patterns,\nand warn if port still bound after kill. 2026-10-04 02:23:20 +00:00
operator-main 5dddedb667 muse-chat-api: Press chat button to refocus Main Chat\n\nUser confirmed pressing the chat button properly refocuses Main Chat.\nSimpler and more reliable than searching for Main chat text in sidebar. 2026-10-04 02:11:41 +00:00
operator-main c83fb7c294 muse-chat-api: Use fuzzy matching for Main chat button\n\nExact match was too fragile - if the UI text differs slightly,\nit returns NOTFOUND and the browser stays on the side chat.\nNow uses substring + shortest-first like cmd_sidechat_use. 2026-10-04 02:04:19 +00:00
operator-main 062e46a6f8 chat-state tap: per-node main+sidechat reporter for box
chat-state-check.py: polls each node Chromium via CDP, captures main
chat + up to 5 side chats (last 10 DOM-visible messages each, 500
chars). Structural React selectors; picks the most common non-empty
list across repeated renders.
chat-state-report.py: signs and POSTs the report to the board
/api/box/chat-state/report ingest (namespace health, 5-min timer).

Session: sidechat/box-console
2026-10-04 01:59:00 +00:00
operator-main e5c85c7940 muse-chat-api: Fix cmd_sidechat_main to click Main chat button\n\nWas navigating to https://muse.ai/ (landing page) which restores the\nlast-viewed chat (often a side chat like Manage Muse agents). Now opens\nthe sidebar and clicks the Main chat element directly. 2026-10-04 01:58:41 +00:00
operator-main 77d904d344 dm.py: Fix dm_thread to pass to_agent correctly\n\nWas calling dm_send(to_agent, target, attributed) which set the\nsender to the recipient and omitted the to_agent param. Now calls\ndm_send(from_agent, target, attributed, to_agent=to_agent). 2026-10-04 01:29:26 +00:00
operator-main d3c19425e8 muse-chat-api.py upload: verify via Remove-attachment button 2026-10-04 01:28:47 +00:00
operator-main c759ca353f muse-chat-api.py upload: ev1() skips CDP chatter on verify 2026-10-04 01:28:19 +00:00
operator-main 716b31a7e6 muse-chat-api.py upload: verify chip by own-text (React swaps the input) 2026-10-04 01:27:55 +00:00