Files
box/docs/INBAND-MESSAGING-SPEC.md
operator-main f2640397ed feat(messaging): balanced TOOL parsing, DM shorthand, box.exec, tools.list
- response-harvester: extract [TOOL]/[EXEC] JSON args with balanced-brace
  scanning (']' and nesting inside args no longer truncate calls); add
  [DM {...}] shorthand mapping to dm.send; native aliases (dm, box,
  tools) plus arg-synonym normalization; formatters and expanded hints.
- exec-constrained: new read-only box.exec op (27 allowlisted box-ctl
  reads) and tools.list op backed by --list-ops for dynamic discovery.
- prompt_envelope: advertise dm.send/box.exec/tools.list in every timer
  DM; add dm_call builder.
- lookup_engine + regex_patterns.json: canonical tool_call pattern
  accepts the DM engine, ']' in args, one nesting level.
- tests/test_tool_calls.py: 38 tests; docs/INBAND-MESSAGING-SPEC.md:
  accepted decision record (Final).
2026-10-06 07:29:16 +00:00

3.2 KiB
Raw Permalink Blame History

In-Band Internal Messaging: Directives, Parsing, Exec Surface

Status: Final — accepted by the owner on 2026-10-06 ("i accept the scope contract, mark it Final").

Box is the main surface. All operator work goes through Box (box.muse-dev.online). The web UI, box CLI, and agents share the same API endpoints. No UI-only powers.

Background (researched facts, not decisions)

  • Agents receive timer/job DMs wrapped by bin/prompt_envelope.py (wrap()), currently advertising [TOOL swarm.spawn], [TOOL cron.create],(tmux worker pointer, [RESULT] verdict rule.
  • Agents reply with in-band directives. bin/response-harvester.py parse_tool_calls() extracts [TOOL op {json}] / [EXEC …], fenced
    the `exec-constrained` HTTPS daemon (`op` allowlist + per-op
    validate/build) and the result is posted back into the originating thread.
    
  • Implemented this session, uncommitted: balanced-brace JSON scanning (no more first-] truncation), [DM {…}] shorthand for dm.send, new box.exec (read-only box-ctl actions) and tools.list (dynamic op discovery) ops, native aliases (dm, box, tools, …), expanded envelope/tool-hint verb lists, tests/test_tool_calls.py (38 tests).
  • Related specs: docs/DM_SPEC.md (WO + logging layer), docs/DM_SPEC.md (control plane), docs/JOB-SPEC.md (scheduler/distributor), CHAT_POLICY.md (sidechat-first).

Scope contract (accepted)

  • Artifact boundary: this record covers directive syntax/parsing ([TOOL]/[EXEC]/[DM], fenced blocks), the exec op surface (box.exec, tools.list, native aliases), and timer-message/envelope content. Out of scope: gateway/browser transport, swarm worker reliability and the failed-slot backlog, new box CLI verbs, CHAT_POLICY.md changes.
  • Done means: D1–D5 settled in writing below; owner explicitly accepts this record (Draft → Final). Nothing else is a completion dependency.
  • Deferred stages (each needs its own interview): swarm reliability target, box CLI inspection verbs for in-band traffic.

Decisions

# Decision Status
D1 Scope boundary = A (directives + exec surface + envelope; transport, swarm reliability, new CLI verbs, chat policy out) settled
D2 box.exec = read-only v1 (19 no-arg + 8 one-arg reads); side-effecting box actions stay out, dedicated ops cover writes settled
D3 [DM …] = strict JSON-only; bare forms without a JSON object are silently ignored settled
D4 Broken-JSON directives are skipped silently (no reply, no record) settled
D5 tools.list returns every op with its side_effecting flag; enforcement stays in per-op validation + identity permissions settled

Risks / validation (to fill as decisions settle)

  • Full suite: 235–244 tests (count varies run to run), 3–4 failures, all in test_approvals / test_copy_actions, which import only approvals / gravity / muse_tui — none of this record's modules. Pre-existing/environmental, unrelated to the directive changes. Focused suites green (38 tool-call + 32 docs/prompts tests).