Commit Graph

33 Commits

Author SHA1 Message Date
operator 0a45133d28 feat(watchers): add box stability watcher daemon, recovery guardrails, and CLI integration
- Add dedicated watchers/ project folder with box-stability-watcher.py supervisor
- Monitor host load, memory, swap saturation, and crash-looping services
- Implement tiered mitigations: yellow renicing, orange SIGSTOP pause with 60s grace, red shedding
- Distinguish user-launched agents (allowed on desktop default socket) from automated box workloads
- Wire first-class box stability CLI subcommand and top-line host status in fleet status
- Harden tmux.service with cgroup memory limits to prevent OS freeze and OOM avalanches
- Add 10-test unit test suite covering thresholds, safety whitelist, pause/resume, and isolation
2026-10-07 17:49:14 +00:00
operator c11d1d83ae feat(retention): implement Piece 2 job archival, CLI wiring, and rotation driver 2026-10-07 03:28:38 +00:00
operator 094bd7d691 feat(muse): harden choice watcher concurrency, add rules dictionary, resume pool, and session bind 2026-10-07 01:50:18 +00:00
operator e25d2cf4cc feat(systemd): add and enable continuous tmux-auto-approver user daemon 2026-10-07 00:49:23 +00:00
operator 04339bad14 feat(box): wire tmux tallies, auto-approvals, and onboard connects into CLI and API
- bin/box-ctl.py: wire tmux-tally, tmux-auto-status, tmux-auto-toggle, tmux-auto-once, and onboard-connects actions with idempotent allowlists
- bin/exec-constrained.py: register tmux.tally, tmux.auto_status, and onboard.connects ops for HTTPS execution
- bin/super-cli.py: wire box tmux dispatch to approver, add cmd_run/cmd_watch, and json unread formatting
- .agents/skills/box/SKILL.md: document tmux worker tally and auto-approval capabilities
2026-10-07 00:25:27 +00:00
operator 0c6d2235ab feat(kpi): add autonomous worker auto-spawn engine and watchdog reconciliation 2026-10-06 23:03:52 +00:00
operator ae4df2f29c feat(kpi): expand KPI runtime monitoring, prompt advisory envelopes, and missing field resiliency 2026-10-06 20:02:48 +00:00
operator 4998ffddb6 feat(tui): SGR mouse fallback, focus partition highlights, multi-trigger context menus & box tui
- bin/muse-tui.py:
  * Parse raw SGR 1006 (\033[<btn;x;yM/m) and Xterm mouse escape sequences in _handle_escape_sequence fallback.
  * Multi-trigger context menus: Button 3, Button 2, Ctrl/Shift/Alt+Click, double-click, click on active item, or click [⚡] / [sid] target.
  * Render permanent [⚡] action target across all sidebar thread rows.
  * Separate focus partitions for FLEET AGENTS and SIDECHATS with partition-specific wheel scrolling and keyboard navigation (j/k, Enter, h/l).
  * Space key support in NORMAL mode to open context menus.
  * Active pane highlighting and updated footer hints.
- bin/super-cli.py:
  * Add 'box tui' command dispatching directly to muse-tui.py --mode box.
- tests:
  * Add unit tests in test_context_menus.py, test_focus_highlight.py, and test_main_nav.py (51/51 passing).
2026-10-06 19:29:22 +00:00
Muse Sidechat c9143a558b fix: truthful fleet status in blind shells + agent-health circuit breaker
box fleet status / approvals check misreported every node as STOPPED /
CDP-unreachable from sandboxed shells (own PID+net namespaces: pgrep
blind, no route to 10.201.x.x, no sudo). Fleet was healthy throughout.

- bin/host_evidence.py (new): host watchdog evidence fallback. Recent
  timer runs (journal -o json, exact UNIT match) with no newer failure
  line in cdp-relay-watchdog.log / chromebox-watchdog.log (both
  silent-when-healthy) prove a node is up. def/dev have no watchdog
  coverage: browser verdict via chromebox-<node>.log freshness
  (alive-only), CDP verdict unknown.
- super-cli.py: effective status/source/evidence per node. Host
  evidence decides ONLY the fully-blind pattern (both local probes
  negative); live local signals always win. New UNKNOWN badge, [*]
  footnote; approvals UNREACHABLE splits into BLIND / OFFLINE(host
  agrees) / unreachable-evidence-inconclusive, with honest footer.
  proc_alive/cdp_ok keep local-probe meaning; status/source/evidence
  are new JSON fields.
- approvals.py: host_cdp_ok flag on the unreachable path.
- agent-health.sh: restart circuit breaker. 3 consecutive futile
  restarts (restart leaves agent still failing) opens the circuit:
  no more kills for 1800s, ALERT to log+journal, half-open probe
  after cooldown, reset on any success. Stops the def murder loop
  (57 restarts / 155 API FAILs for an account-layer failure).
- tests/test_fleet_status.py (25), tests/test_agent_health.py (6).
- CHROMEBOX-RUNBOOK.md: blind-shell status + futile-restart sections.

Tests: 98/98 focused green (agent_health + fleet_status +
completion + tool_calls). Live-verified: 4 ACTIVE [*] + 2 UNKNOWN.
2026-10-06 18:16:14 +00:00
operator 740648e973 approvals: stale-wait cleanup, key-decision notify, TTLs, key/browser isolation
- bin/approvals.py: responded-wait filtering + auto-mark, key-decision sidechat-first notify (notified flag, --message, --allow-main-chat), TTL defaults (input 30m / browser 30m / key 2h), cross-type guard (browser actions cannot resolve key requests), sweep_expired_key_requests; restores check_node_key_request fallback in inspect_node_approvals

- bin/box-ctl.py + bin/super-cli.py (approvals hunks only): --message/--allow-main-chat passthrough on allow/deny, clear/clear-all actions, def sidechat routing; restores sys.exit(1) on dismiss failure

- bin/fleet-alert-check.sh: TTL-aware state_machine (EXPIRED action), auto-deny expired browser approvals (fail closed), auto-dismiss expired input waits, targeted per-agent DM for input waits

- bin/job-dispatch.py + bin/gravity.py: KEY_APPROVAL excluded from auto-approval

Reviewed by 5 independent reviewers (all APPROVE/APPROVE WITH NOTES); integration gate GO (17/17 tests). TUI hunks in super-cli.py intentionally excluded.
2026-10-06 00:49:46 +00:00
operator adfcd2e602 feat(box): passkey fetch, agent key-approval flow, unified lookups, tmux agent UX
- box passkey [show|fetch] (+ muse passkey): documents VM-only passkey
  (/srv/box/passkey.txt, fallback /etc/netvm/passkey.txt on 34.139.37.135),
  probes VM over SSH with graceful fallback; --json supported. No secrets on bl.
- approvals: request_key_approval / check_node_key_request; KEY_APPROVAL status
  surfaced in `box approvals check`; allow/deny resolve + audit to box-ctl.jsonl;
  never auto-approved. New `box approvals request-key <node> --reason`.
- box lookup (summary|fleet|threads|unread|approvals|key|docs) and docs-lookup
  engine with lookup_internal/ database (docs_internal symlink).
- muse-tmux: non-TTY attach falls back to scrollback capture; prune NameError fix.
- box/muse passthrough for tmux/muse/docs; thread list/view alias + prefix resolve.
- Docs: AGENTS.md, AGENT-TOOLING.md, BOX-WEB-SURFACE-GUIDE.md, README.
- Tests: key-approval + passkey tests; sync stale sidechat UUIDs and manifest name.
- .gitignore runtime trackers (subagent-sessions, conversation-nudge-tracker).
2026-10-05 20:18:47 +00:00
operator d72b63bfd1 docs(netvm): document watchdog, swarm-worker, and alert relay in README; track approvals CLI 2026-10-05 17:42:01 +00:00
operator 7fc15eb127 feat(operators): amendment workflow and automated drive watchdog daemon 2026-10-05 17:15:50 +00:00
operator cc8702b38c feat(operators): agent markdown drive management via Hatch and SSH runbook 2026-10-05 16:51:56 +00:00
operator-main a9ab825554 fix(netvm): hardcoded dev CDP port refs 9460 -> 9455
Follow-up to 8c39dc3: four scripts hardcoded dev's CDP port instead of
reading netvm-registry.py. Aligned with the corrected registry (9455).

Session: sidechat/dev-cdp-partition
2026-10-05 16:40:40 +00:00
operator 1809a1a8e2 feat(cli): add 'box tmux' domain to manage headless sessions with auto-logging 2026-10-05 16:27:19 +00:00
operator b828ce1985 fix(cli): resolve symlink path before looking up swarms.json in 'box swarm status' 2026-10-05 16:24:21 +00:00
operator c13ee20ea4 feat(cli): add prefix matching to 'box swarm status' 2026-10-05 16:23:07 +00:00
operator 07c67e5da3 fix(cli): parse swarm object correctly in 'box swarm status' 2026-10-05 16:06:50 +00:00
operator 983b5c668c feat(cli): add 'box swarm' domain (list, status, spawn, prune) 2026-10-05 16:04:56 +00:00
operator 7f92679281 feat(cli): add 'box ssh' command suite (mint, list, show) with auto signers registration 2026-10-05 15:33:38 +00:00
operator 5ff32b5202 feat(exec): add template aliases, tolerant read-only validation, and thread titling filter 2026-10-05 15:14:24 +00:00
operator f60394cd9b feat(subagent): implement subagent lifecycle tracking and core loop reactive wakeup
- Implement bin/subagent_tracker.py with session registry in subagent-sessions.json
- Register spawned sessions automatically in super-cli.py cmd_deploy
- Add check_subagents() to bin/self_main_loop.py with thread updated watermark comparison
- Add 15-minute stall watchdog with automated parent alerting
- Support 'box subagent spawn' top-level command alias in super-cli.py
- Add symmetrical pip-opm sidechat routing in job-sidechats.json
2026-10-04 23:40:04 +00:00
operator d6ca600394 feat(relay): add subagent spawn, thread tools, and container box client
- Upgrade exec-constrained.py with subagent.spawn, thread.list, thread.view, pipeline.run ops
- Grant full ops permissions to all fleet agent identities (646, pip, muse, opm)
- Implement bin/box-relay.sh zero-dependency client supporting bearer and SSH signature auth
- Add fast hybrid gateway path to dm.py for sub-2s verified deliveries
- Fix wait=0 handling in super-cli.py subagent deployments
- Add hourly check-in jobs and scheduler for 646, pip, muse
- Document agent tooling and relay APIs in docs/AGENT-TOOLING.md
2026-10-04 23:30:18 +00:00
operator f88e3c4f57 feat(cred): add meta-audit command to inspect Accounts Center linked profiles and sync opm/pip accounts 2026-10-04 23:03:27 +00:00
operator 75e6e745a9 feat(core-loop): implement dual-monitoring, fast gateway dispatch, dedicated pip tasks sidechat, and 2m cadence 2026-10-04 23:02:04 +00:00
operator 1a271b1bbd feat(hybrid-gateway): integrate muse-cli with Cloudflare netns isolation, symmetric sidechat routing, and 646-pip sync unblock 2026-10-04 22:54:01 +00:00
operator 178ddc5dbf feat(cred): harden client onboarding with Instagram linking portal, age verification bypass, and fleet runbook 2026-10-04 21:43:32 +00:00
operator-main 550e30901b fix: placement verification and sidechat policy enforcement
- dm.py: placement-aware verify (verify_placement), checked_uuid logging, placement_mismatch events
- main-chat-watchdog.py: P0 alerts on placement_mismatch
- box-ctl.py: notify routes to sidechat, box policy command
- jobs: ops-audit and pipe-demo use sidechats
- response-harvester.py: chain deduplication

Session: sidechat/ops-restore
2026-10-04 18:29:13 +00:00
operator 33a0f295b6 feat(pipeline): register 3-stage ops-audit pipeline definitions and wire super-cli prune command 2026-10-04 17:23:28 +00:00
operator 2b19d2cb45 feat(pipeline): add stop and prune commands to pipeline engine and CLI
- Add stop_pipeline and prune_pipelines to bin/pipeline_engine.py
- Support prefix matching and custom cancellation reason
- Wire 'super pipeline stop <run_id>' and 'super pipeline prune [--max-age H]' into bin/super-cli.py
2026-10-04 16:58:15 +00:00
operator 7a35b684c4 feat: unified fleet CLI, Main Chat preservation policy, sidechat routing, and file transfers
- Added CHAT_POLICY.md and README.md banner enforcing sidechat-first and file-transfer-first rules.
- Added strict Main Chat block to super dm send and super dm wo with --allow-main-chat override.
- Implemented file transfer staging and metadata registry in super dm send-file and super dm files (with clean subcommand).
- Added full job lifecycle management (show, create, enable, disable, delete, run --follow) to super-cli.py and box-ctl.py.
- Audited all jobs in jobs/*.json and redirected automated dispatches away from Main Chat.
- Hardened chromebox-watchdog.sh with systemd user session environment exports and stale singleton cleanup.
- Added compose_check command choice to muse-chat-api.py.
2026-10-04 16:34:25 +00:00
operator 4a935bd0c7 feat(automation): sidechat auto-provisioning, response harvester, followup sweeper, and super CLI 2026-10-04 16:23:10 +00:00