- bin/tmux_auto_approver.py: multi-socket worker discovery across user and netns sockets - Regex matching engine with 7 terminal prompt rules and hard security guardrails - bin/box-onboard-tui.py: dedicated 4-tab curses TUI for fleet connects, tmux workers, rules, and audit logs - Audit logging stream in logs/tmux/auto-approvals.jsonl and state in .state/ - Unit test suites covering engine, rules, guardrails, and curses rendering
7.5 KiB
Tmux Worker Tally & Regex Auto-Approvals over HTTPS (No SSH)
Box is the main surface. All operator work goes through Box (
box.muse-dev.online). The web UI,boxCLI, and agents share the same unified API endpoints and runtimes.
Date: 2026-10-06
Status: Implemented (bin/tmux_auto_approver.py, bin/box-onboard-tui.py, bin/super-cli.py)
Scope: Tmux worker tallies, automated regex approval engine for on-board Muse Code runs & autonomous agent workers, and dedicated interactive TUI console (box onboard-tui).
1. Architecture
┌──────────────────────────────────────────────┐
│ https://box.muse-dev.online/ │
│ (Web Dashboard & API Gateway) │
└──────────────────────┬───────────────────────┘
│
HTTPS Signed Ops / CLI Dispatch
│
┌──────────────────────▼───────────────────────┐
│ Unified Box CLI Engine │
│ (box tmux tally / box tmux auto ...) │
└───────┬───────────────────────────────┬──────┘
│ │
┌──────────────▼─────────────┐ ┌─────────────▼──────────────┐
│ bin/box-onboard-tui.py │ │ bin/tmux_auto_approver.py │
│ (Dedicated 4-Tab Console) │ │ (Multi-Socket Regex Daemon)│
└──────────────┬─────────────┘ └─────────────┬──────────────┘
│ │
│ │
┌───────────────────────┴───────────────────────────────┴───────────────────────┐
│ Tmux Sockets Monitored │
│ • /tmp/tmux-muse.sock (shared host workers) │
│ • /tmp/tmux-1000/default (dev/def runner panes & muse-code %37) │
│ • /tmp/tmux-1000/lte (lte operator pane) │
│ • /tmp/tmux-<agent>.sock (per-agent netns sockets: pip, 646, opm, dev, def) │
└───────────────────────────────────────────────────────────────────────────────┘
2. Tmux Auto-Approval Regex Match Engine
The auto-approval engine monitors scrollback across all agent panes and matches approval prompts against priority rules:
| Rule ID | Category | Trigger Pattern | Response Key | Press Enter | Description |
|---|---|---|---|---|---|
muse_code_run_numbered |
muse_code |
Would you like to run the following[\s\S]*?›\s*1\.\s*Yes,?\s*proceed |
1 |
false |
Muse Code interactive run menu (selects option 1) |
muse_code_run_yn |
muse_code |
›\s*1\.\s*Yes,?\s*proceed\s*\(y\) |
1 |
false |
Active selection indicator on 1. Yes, proceed (y) |
muse_code_allow_execution |
muse_code |
Allow\s+execution\s+of\b[\s\S]*?\[y/N\] |
y |
true |
Approves script execution confirmation |
choice_abc |
choice |
(?i)(?:choose|choice|select)[\s\S]*?^\s*[A-Z]\s*[.\)\-:]\s+\S |
A |
true |
Lettered decision choice menus |
menu_numbered |
menu |
(?i)(?:Option:|Selection:)[\s\S]*?^\s*\(?1\)?\s+[A-Za-z] |
1 |
true |
Numbered selection menus |
confirm_yn |
confirm |
([yY]/[nN]|\[[yY]/[nN]\])\s*[\]:)>]?\s*$ |
y |
true |
Line-end confirmation prompts |
enter_to_continue |
enter |
(?i)(?:Press\s+\[?Enter\]?\s+to\s+continue) |
Enter |
false |
Enter-to-continue banners |
Guardrails (Never Auto-Approved)
[sudo] password for .../password:prompts- Passkeys, private key passphrases, and PIN prompts
- Destructive operations (
rm -rf /,mkfs.*)
When a guardrail pattern is detected, the engine flags is_blocked=true, emits a warning audit log, and notifies the human operator.
3. CLI Commands
Tmux Worker Tally & Management
# Tally all active tmux sessions, panes, and workers across sockets
box tmux tally
box tmux tally --json
# List active sessions
box tmux list
# Spawn new background worker session
box tmux new my-worker -c "python3 run_tasks.py"
Auto-Approval Control
# Query master state and per-agent policies
box tmux auto status
box tmux auto status --json
# Master enable / disable
box tmux auto on
box tmux auto off
# Enable / disable for specific agent
box tmux auto on --node muse
box tmux auto off --node 646
# Execute single-pass scan and auto-approve all active prompts right now
box tmux auto once
box tmux auto once --dry-run
# Run background monitor daemon
box tmux auto watch --interval 1.0
# Tail structured audit log stream
box tmux auto logs -n 20
# Test regex match against custom prompt text
box tmux auto match "Would you like to run the following ... › 1. Yes, proceed (y)"
Onboard Connects
# View all fleet nodes & client onboard connects
box onboard connects
box onboard connects --json
# Start client onboarding
box onboard start dev2 --email client@example.com --for 646
# Submit OTP verification code
box onboard submit-otp dev2 123456
Dedicated Interactive TUI
# Launch full 4-tab interactive TUI
box onboard-tui
box tui onboard
4. HTTPS Remote Operations (exec-constrained.py)
Available via https://exec.muse-dev.online/exec with signature verification:
| Op | Parameters | Description | Permission |
|---|---|---|---|
tmux.tally |
{} |
Returns complete worker tally across all sockets (JSON) | DEFAULT_PERMS (Read-only) |
tmux.auto_status |
{} |
Returns auto-approval toggle state & rule set (JSON) | DEFAULT_PERMS (Read-only) |
onboard.connects |
{} |
Returns consolidated fleet and client connects (JSON) | DEFAULT_PERMS (Read-only) |
tmux.auto_toggle |
{"enabled": bool, "node"?: str} |
Toggles master or per-agent auto-approval state | Known-Identities-Only |
5. Audit Logging
Every auto-approval and blocked guardrail event is written to:
/home/super/Projects/NetVM/logs/tmux/auto-approvals.jsonl
Sample event payload:
{
"action": "AUTO_APPROVED",
"socket": "/tmp/tmux-1000/default",
"pane": "%37",
"session": "muse",
"agent": "muse",
"rule_id": "muse_code_run_numbered",
"rule_name": "Muse Code Run (Numbered)",
"key_sent": "1",
"press_enter": false,
"excerpt": "Would you like to run the following ... › 1. Yes, proceed (y)",
"dry_run": false,
"success": true,
"timestamp": "2026-10-06T19:34:19.599811+00:00",
"ts": 1791315259.6
}