Commit Graph

21 Commits

Author SHA1 Message Date
operator 34b0ef9fe2 chore(fleet): sync operator memory, hatch menu dialogs, and watchdog alerts 2026-10-07 00:25:51 +00:00
operator 740648e973 approvals: stale-wait cleanup, key-decision notify, TTLs, key/browser isolation
- bin/approvals.py: responded-wait filtering + auto-mark, key-decision sidechat-first notify (notified flag, --message, --allow-main-chat), TTL defaults (input 30m / browser 30m / key 2h), cross-type guard (browser actions cannot resolve key requests), sweep_expired_key_requests; restores check_node_key_request fallback in inspect_node_approvals

- bin/box-ctl.py + bin/super-cli.py (approvals hunks only): --message/--allow-main-chat passthrough on allow/deny, clear/clear-all actions, def sidechat routing; restores sys.exit(1) on dismiss failure

- bin/fleet-alert-check.sh: TTL-aware state_machine (EXPIRED action), auto-deny expired browser approvals (fail closed), auto-dismiss expired input waits, targeted per-agent DM for input waits

- bin/job-dispatch.py + bin/gravity.py: KEY_APPROVAL excluded from auto-approval

Reviewed by 5 independent reviewers (all APPROVE/APPROVE WITH NOTES); integration gate GO (17/17 tests). TUI hunks in super-cli.py intentionally excluded.
2026-10-06 00:49:46 +00:00
operator adfcd2e602 feat(box): passkey fetch, agent key-approval flow, unified lookups, tmux agent UX
- box passkey [show|fetch] (+ muse passkey): documents VM-only passkey
  (/srv/box/passkey.txt, fallback /etc/netvm/passkey.txt on 34.139.37.135),
  probes VM over SSH with graceful fallback; --json supported. No secrets on bl.
- approvals: request_key_approval / check_node_key_request; KEY_APPROVAL status
  surfaced in `box approvals check`; allow/deny resolve + audit to box-ctl.jsonl;
  never auto-approved. New `box approvals request-key <node> --reason`.
- box lookup (summary|fleet|threads|unread|approvals|key|docs) and docs-lookup
  engine with lookup_internal/ database (docs_internal symlink).
- muse-tmux: non-TTY attach falls back to scrollback capture; prune NameError fix.
- box/muse passthrough for tmux/muse/docs; thread list/view alias + prefix resolve.
- Docs: AGENTS.md, AGENT-TOOLING.md, BOX-WEB-SURFACE-GUIDE.md, README.
- Tests: key-approval + passkey tests; sync stale sidechat UUIDs and manifest name.
- .gitignore runtime trackers (subagent-sessions, conversation-nudge-tracker).
2026-10-05 20:18:47 +00:00
operator 74d093d259 feat(prompts): work-first envelope with spawn/followup tool calls at top and bottom 2026-10-05 05:43:26 +00:00
operator c0add2a4ce feat(runtime): embed box.muse-dev.online thread url and tool execution directives into followups, nudges, and dispatches 2026-10-05 05:27:47 +00:00
operator dc1b4f8ce6 fix(dispatch): eliminate noisy SSH signatures from routine job prompts and activate real tool triggers 2026-10-05 04:04:41 +00:00
operator d09e1c4872 feat(sidechats): auto-archive completed ephemeral job threads via hybrid gateway 2026-10-05 03:57:06 +00:00
operator 31c03e0d0f feat(box): enable real-time agent tool triggers and capabilities expansion 2026-10-05 03:41:43 +00:00
operator ec547b28ac feat(sidechats): headless gateway new channel auto-provisioning and dedicated heartbeat channel 2026-10-05 02:27:23 +00:00
operator d6ca600394 feat(relay): add subagent spawn, thread tools, and container box client
- Upgrade exec-constrained.py with subagent.spawn, thread.list, thread.view, pipeline.run ops
- Grant full ops permissions to all fleet agent identities (646, pip, muse, opm)
- Implement bin/box-relay.sh zero-dependency client supporting bearer and SSH signature auth
- Add fast hybrid gateway path to dm.py for sub-2s verified deliveries
- Fix wait=0 handling in super-cli.py subagent deployments
- Add hourly check-in jobs and scheduler for 646, pip, muse
- Document agent tooling and relay APIs in docs/AGENT-TOOLING.md
2026-10-04 23:30:18 +00:00
operator 1a271b1bbd feat(hybrid-gateway): integrate muse-cli with Cloudflare netns isolation, symmetric sidechat routing, and 646-pip sync unblock 2026-10-04 22:54:01 +00:00
operator-main 550e30901b fix: placement verification and sidechat policy enforcement
- dm.py: placement-aware verify (verify_placement), checked_uuid logging, placement_mismatch events
- main-chat-watchdog.py: P0 alerts on placement_mismatch
- box-ctl.py: notify routes to sidechat, box policy command
- jobs: ops-audit and pipe-demo use sidechats
- response-harvester.py: chain deduplication

Session: sidechat/ops-restore
2026-10-04 18:29:13 +00:00
operator 7a35b684c4 feat: unified fleet CLI, Main Chat preservation policy, sidechat routing, and file transfers
- Added CHAT_POLICY.md and README.md banner enforcing sidechat-first and file-transfer-first rules.
- Added strict Main Chat block to super dm send and super dm wo with --allow-main-chat override.
- Implemented file transfer staging and metadata registry in super dm send-file and super dm files (with clean subcommand).
- Added full job lifecycle management (show, create, enable, disable, delete, run --follow) to super-cli.py and box-ctl.py.
- Audited all jobs in jobs/*.json and redirected automated dispatches away from Main Chat.
- Hardened chromebox-watchdog.sh with systemd user session environment exports and stale singleton cleanup.
- Added compose_check command choice to muse-chat-api.py.
2026-10-04 16:34:25 +00:00
operator 4a935bd0c7 feat(automation): sidechat auto-provisioning, response harvester, followup sweeper, and super CLI 2026-10-04 16:23:10 +00:00
operator-main 844aa73bd9 UUID-based sidechat reuse for heartbeat\n\n- Add url command to muse-chat-api.py\n- Dispatcher: reuse_key -> thread UUID mapping in job-sidechats.json\n- Capture UUID after first send, reuse on subsequent runs\n- Fixes multi-spawn bug (was matching by auto-generated title) 2026-10-04 04:03:28 +00:00
operator-main 7d48123835 Heartbeat to sidechat with reuse\n\n- Dispatcher: reuse existing sidechat by name (not create new each time)\n- Heartbeat job: sidechat.create=true, name_template=heartbeat (fixed) 2026-10-04 03:40:25 +00:00
operator-main 1cffacc7d1 Sidechat: render wait, direct send, stderr logging\n\n- Wait for Side chats to render before finding + button\n- Dispatcher: send_to_current_chat for sidechat jobs\n- Log stderr on create failure 2026-10-04 03:29:21 +00:00
operator-main 34082045cc Nail sidechat create: direct send, no ID lookup\n\n- cmd_sidechat_create: simplified, just create and return\n- job-dispatch: after create, send via direct API to current chat\n- No thread ID parsing needed; thread lookup via URL for later ops 2026-10-04 03:23:34 +00:00
operator-main 942f37e21c job-dispatch.py: Send job DM to sidechat directly\n\nWhen sidechat.create=true, the job DM now goes to the sidechat\nitself (via thread ID), not to main chat. Keeps main clean;\nthe sidechat IS the workspace. 2026-10-04 03:11:11 +00:00
operator-main 35bd358b78 job-dispatch.py: Add sidechat creation support\n\nWhen job has sidechat.create=true, creates sidechat via\nmuse-chat-api.py in sender context, includes URL in DM. 2026-10-04 03:09:42 +00:00
operator-main 78dbf8f131 Add job-dispatch.py: JOB system dispatcher\n\nReads job JSON, renders prompt template, sends DM via dm.py,\nlogs to job-log.jsonl. Tested end-to-end: canary-test job\ndispatched successfully (DM 36bd80aa SENT and VERIFIED). 2026-10-04 03:06:46 +00:00