operator-main
f2640397ed
feat(messaging): balanced TOOL parsing, DM shorthand, box.exec, tools.list
...
- response-harvester: extract [TOOL]/[EXEC] JSON args with balanced-brace
scanning (']' and nesting inside args no longer truncate calls); add
[DM {...}] shorthand mapping to dm.send; native aliases (dm, box,
tools) plus arg-synonym normalization; formatters and expanded hints.
- exec-constrained: new read-only box.exec op (27 allowlisted box-ctl
reads) and tools.list op backed by --list-ops for dynamic discovery.
- prompt_envelope: advertise dm.send/box.exec/tools.list in every timer
DM; add dm_call builder.
- lookup_engine + regex_patterns.json: canonical tool_call pattern
accepts the DM engine, ']' in args, one nesting level.
- tests/test_tool_calls.py: 38 tests; docs/INBAND-MESSAGING-SPEC.md:
accepted decision record (Final).
2026-10-06 07:29:16 +00:00
operator-main
345eb09559
fix(watchdog): eliminate SIGPIPE+pipefail phantom failures in health checks
...
echo "$list" | grep -q under set -o pipefail exits 141 whenever grep
matches before echo finishes writing, so healthy browsers were reported
'CDP up but no page target' and killed every 2 min fleet-wide (load 19+).
Use [[ == *glob* ]] (no pipe, no race) for the page/muse.ai stages, and
grep -c (reads to EOF, never early-exits) for the netns check.
2026-10-06 07:28:20 +00:00
operator
7444b52763
Fix split-brain swarm dispatch: narrow harvester SWARM_WORKER_POOL to [muse]
...
The 2026-10-05 fix note claimed dev/def were removed from the pool but the
code still listed [dev, def, muse]. The harvester's every-minute systemd
dispatch raced the pool daemon claiming slots as dev/def, which refuse on
attribution grounds (dev FAILs fast, def freezes until the 60-min reaper) -
the fleet-wide dev-FAIL-fast + def-frozen pattern on every swarm.
Pool now matches swarm_worker/daemon.py WORKER_POOL exactly: muse only,
the single fully authenticated auxiliary worker. Reporting/harvest paths
untouched.
2026-10-06 03:14:02 +00:00
operator
740648e973
approvals: stale-wait cleanup, key-decision notify, TTLs, key/browser isolation
...
- bin/approvals.py: responded-wait filtering + auto-mark, key-decision sidechat-first notify (notified flag, --message, --allow-main-chat), TTL defaults (input 30m / browser 30m / key 2h), cross-type guard (browser actions cannot resolve key requests), sweep_expired_key_requests; restores check_node_key_request fallback in inspect_node_approvals
- bin/box-ctl.py + bin/super-cli.py (approvals hunks only): --message/--allow-main-chat passthrough on allow/deny, clear/clear-all actions, def sidechat routing; restores sys.exit(1) on dismiss failure
- bin/fleet-alert-check.sh: TTL-aware state_machine (EXPIRED action), auto-deny expired browser approvals (fail closed), auto-dismiss expired input waits, targeted per-agent DM for input waits
- bin/job-dispatch.py + bin/gravity.py: KEY_APPROVAL excluded from auto-approval
Reviewed by 5 independent reviewers (all APPROVE/APPROVE WITH NOTES); integration gate GO (17/17 tests). TUI hunks in super-cli.py intentionally excluded.
2026-10-06 00:49:46 +00:00
operator
adfcd2e602
feat(box): passkey fetch, agent key-approval flow, unified lookups, tmux agent UX
...
- box passkey [show|fetch] (+ muse passkey): documents VM-only passkey
(/srv/box/passkey.txt, fallback /etc/netvm/passkey.txt on 34.139.37.135),
probes VM over SSH with graceful fallback; --json supported. No secrets on bl.
- approvals: request_key_approval / check_node_key_request; KEY_APPROVAL status
surfaced in `box approvals check`; allow/deny resolve + audit to box-ctl.jsonl;
never auto-approved. New `box approvals request-key <node> --reason`.
- box lookup (summary|fleet|threads|unread|approvals|key|docs) and docs-lookup
engine with lookup_internal/ database (docs_internal symlink).
- muse-tmux: non-TTY attach falls back to scrollback capture; prune NameError fix.
- box/muse passthrough for tmux/muse/docs; thread list/view alias + prefix resolve.
- Docs: AGENTS.md, AGENT-TOOLING.md, BOX-WEB-SURFACE-GUIDE.md, README.
- Tests: key-approval + passkey tests; sync stale sidechat UUIDs and manifest name.
- .gitignore runtime trackers (subagent-sessions, conversation-nudge-tracker).
2026-10-05 20:18:47 +00:00
operator
59c9965791
feat(swarm-worker): dispatch prose swarm slots to ephemeral Muse subagents
...
- daemon: route non-shell slot tasks to a fresh subagent session on dev/def/muse
via muse_hybrid; add bin/ to sys.path so muse_hybrid/prompt_envelope import
under the tmux supervisor
- prompt_envelope: add wrap_subagent_task() - plain task assignment without
[TOOL tmux/swarm/cron] meta tags (subagents refused those as relayed test traffic)
- box-ctl/reporter: swarm-attach accepts optional session-id, stored as
slot.subagent_session_id
- executor: _looks_like_shell requires an existing executable (prose like
'verify ...' no longer misread as shell)
- poller: pick up pending swarms as well as running
- response-harvester: monitor running slot subagent sessions from swarms.json,
allow '/' in RESULT/VERB job ids, archive ephemeral threads on any verdict
(OK or FAIL), reap slot sessions for terminal swarms
2026-10-05 20:18:46 +00:00
operator
fc765f270b
fix(swarm-worker): isolate session to /tmp/tmux-muse.sock and filter terminal slots in poller
2026-10-05 19:21:10 +00:00
box-ctl
528d9497d9
Add job exec-sigkill-investigation-20261005 via box-ctl
2026-10-05 19:08:55 +00:00
operator
45edc5432c
feat(approvals): integrate approval-hold detection and auto-remediation into fleet alert, loop diagnostics, and muse API
2026-10-05 17:43:04 +00:00
operator
611181b81e
docs(runbook): add fleet resource optimization, timer consolidation, and headless throttling runbook
2026-10-05 17:42:32 +00:00
operator
d72b63bfd1
docs(netvm): document watchdog, swarm-worker, and alert relay in README; track approvals CLI
2026-10-05 17:42:01 +00:00
operator
4f4b8768b6
feat(alert): wire idempotent fleet-alert relay into check loop and stop stale chrome scopes
2026-10-05 17:41:04 +00:00
operator
9e833d0c4b
feat(swarm): launch live swarm worker daemon under tmux supervisor
2026-10-05 17:29:16 +00:00
operator
7fc15eb127
feat(operators): amendment workflow and automated drive watchdog daemon
2026-10-05 17:15:50 +00:00
operator
2cc77d8008
amend(operators): update AGENTS.md via dev - append Relay Connectivity Verification
2026-10-05 17:15:00 +00:00
operator
111b21ab97
docs: reference agent_md, shared operator drive templates, and operator runbook in README
2026-10-05 16:52:20 +00:00
operator
cc8702b38c
feat(operators): agent markdown drive management via Hatch and SSH runbook
2026-10-05 16:51:56 +00:00
operator
653166e202
docs: add tmux stability post-mortem and update AGENT-TOOLING with hybrid tmux and direct operator directives
2026-10-05 16:48:44 +00:00
operator
9722879724
feat(tmux,envelope): add hybrid node/container execution to muse-tmux and naturalize prompt envelope to operator directive
2026-10-05 16:47:24 +00:00
operator
2608fa114f
docs: document streamlined Work Order and tmux envelope integration
2026-10-05 16:42:48 +00:00
operator
f61ceb5f04
fix(envelope): strip host container key references from prompt envelope to eliminate agent refusal loops
2026-10-05 16:41:42 +00:00
operator-main
a9ab825554
fix(netvm): hardcoded dev CDP port refs 9460 -> 9455
...
Follow-up to 8c39dc3 : four scripts hardcoded dev's CDP port instead of
reading netvm-registry.py. Aligned with the corrected registry (9455).
Session: sidechat/dev-cdp-partition
2026-10-05 16:40:40 +00:00
operator-main
8c39dc3fad
fix(netvm): dev CDP port 9460 -> 9455
...
NODES.md advertised dev's CDP on 9460, but the fleet-facing path is the
relay netvm-cdp-relay.py 10.201.36.2:9455 -> 127.0.0.1:9455, and
netvm-names.sh never pinned dev (hash default = 9455). The watchdog kept
relaunching dev's browser on 9460 while the relay sat orphaned on 9455.
- NODES.md: dev cdp_port 9460 -> 9455 (registry is the watchdog's source)
- bin/netvm-names.sh: pin def=9450, dev=9455 (was hash-default only)
Reported by 646 as xop-e09 partition; verified hop-by-hop before fix.
Session: sidechat/dev-cdp-partition
2026-10-05 16:39:49 +00:00
operator
1e86ed8a44
retention piece 1: immediate rotations for chat-history / job-log / followups (b67084660385)
...
- chat-history.jsonl rotates at 10MB or 7d -> logs/archive/*.jsonl.gz + .sha256
- job-log.jsonl rotates at 2MB or 14d -> same archive layout
- followups.json archives resolved>7d / escalated>30d -> followups.archive.jsonl (append-only)
- verify wrapper: sha256 -c, gzip -t, clean listing, spot-extract JSON + ts bounds
- driver + hourly systemd user timer (retention-rotations.timer)
- archive-only: nothing is ever deleted; thread backfill excluded (needs human-reviewed preview)
First run 2026-10-05 16:35Z: chat-history 29.7MB + job-log 4.7MB rotated and verified; followups 0 eligible of 163.
2026-10-05 16:37:14 +00:00
operator
1d2440c1f8
feat(envelope): inject Work Order header and shared tmux directives into prompt envelope
2026-10-05 16:31:35 +00:00
operator
1809a1a8e2
feat(cli): add 'box tmux' domain to manage headless sessions with auto-logging
2026-10-05 16:27:19 +00:00
operator
4e512a0742
feat(tmux): persist session output and send-keys actions to logs/tmux/<session>.log via pipe-pane
2026-10-05 16:24:36 +00:00
operator
973dbc3636
feat(tmux): ensure automatic session logging to logs/tmux/<session>.log via pipe-pane
2026-10-05 16:24:34 +00:00
operator
b828ce1985
fix(cli): resolve symlink path before looking up swarms.json in 'box swarm status'
2026-10-05 16:24:21 +00:00
operator
945e6bb481
feat(tmux): implement 2-hour inactivity session TTL reaper and prune command
2026-10-05 16:23:45 +00:00
operator
c13ee20ea4
feat(cli): add prefix matching to 'box swarm status'
2026-10-05 16:23:07 +00:00
operator
0ca0fd0c1a
feat(tmux): add shared muse tmux socket manager with CLI and agent [TOOL tmux.*] integration
2026-10-05 16:11:19 +00:00
operator
07c67e5da3
fix(cli): parse swarm object correctly in 'box swarm status'
2026-10-05 16:06:50 +00:00
operator
ea2f208083
feat(netvm): auto-recover and bring up node netns if down when invoking muse-cli
2026-10-05 16:06:25 +00:00
operator
063ed2b47b
fix(cli): treat leading non-flag argument as target account for precise error feedback
2026-10-05 16:05:50 +00:00
operator
983b5c668c
feat(cli): add 'box swarm' domain (list, status, spawn, prune)
2026-10-05 16:04:56 +00:00
operator
c74ebaa658
feat(loop): add main-loop brain module for opm sidechat thinking and operator steering
2026-10-05 16:02:58 +00:00
operator
e912f25dd7
feat(muse-cli): streamlined account argument handling and extracted clean inner invocation wrapper
2026-10-05 16:02:46 +00:00
operator
a0297b733a
feat(jobs): track auto-work templates and update work-finder definition
2026-10-05 16:01:51 +00:00
operator
fd3ef5dc2d
feat(auth): auto-launch background browser if CDP is down during cookie extraction
2026-10-05 15:59:58 +00:00
operator
d529d9ebab
feat(core): node veth idempotency, multi-node cdp ports, brain last ids persistence, and pulse interval variable
2026-10-05 15:59:18 +00:00
operator
94d6502289
docs: sync onboarding runbooks, node inventory, bridge mappings, and box api docs
2026-10-05 15:58:37 +00:00
operator
7c6c3a8fbf
feat(cli): add interactive chat REPL mode for native muse CLI
2026-10-05 15:58:33 +00:00
operator
e44d6c77f4
fix(harvester): restore #!/usr/bin/env python3 shebang at top of response-harvester.py
2026-10-05 15:58:23 +00:00
operator
447e9c1cc7
feat(swarm): bridge swarm slot dispatch to native muse_hybrid subagent sessions
2026-10-05 15:56:59 +00:00
operator
7b1998f00e
docs: add native interactive muse cli wrapper and documentation
2026-10-05 15:50:24 +00:00
operator
008b689bee
fix(swarm): keep stuck-slot reaper & verified dispatch while reverting worker pool to dev, def, muse
2026-10-05 15:38:00 +00:00
operator
7f92679281
feat(cli): add 'box ssh' command suite (mint, list, show) with auto signers registration
2026-10-05 15:33:38 +00:00
operator
26535791e5
feat(auth): provision SSH signing keys for 646 and opm and register in allowed_signers
2026-10-05 15:27:34 +00:00
box-ctl
8d305bacf7
Chain job ops-audit-step3 -> ops-audit-alert via box-ctl
2026-10-05 15:26:14 +00:00