9f2a0e836d
- bin/tmux_auto_approver.py: multi-socket worker discovery across user and netns sockets - Regex matching engine with 7 terminal prompt rules and hard security guardrails - bin/box-onboard-tui.py: dedicated 4-tab curses TUI for fleet connects, tmux workers, rules, and audit logs - Audit logging stream in logs/tmux/auto-approvals.jsonl and state in .state/ - Unit test suites covering engine, rules, guardrails, and curses rendering
169 lines
7.5 KiB
Markdown
169 lines
7.5 KiB
Markdown
# Tmux Worker Tally & Regex Auto-Approvals over HTTPS (No SSH)
|
||
|
||
> **Box is the main surface.** All operator work goes through Box (`box.muse-dev.online`).
|
||
> The web UI, `box` CLI, and agents share the same unified API endpoints and runtimes.
|
||
|
||
**Date:** 2026-10-06
|
||
**Status:** Implemented (`bin/tmux_auto_approver.py`, `bin/box-onboard-tui.py`, `bin/super-cli.py`)
|
||
**Scope:** Tmux worker tallies, automated regex approval engine for on-board Muse Code runs & autonomous agent workers, and dedicated interactive TUI console (`box onboard-tui`).
|
||
|
||
---
|
||
|
||
## 1. Architecture
|
||
|
||
```
|
||
┌──────────────────────────────────────────────┐
|
||
│ https://box.muse-dev.online/ │
|
||
│ (Web Dashboard & API Gateway) │
|
||
└──────────────────────┬───────────────────────┘
|
||
│
|
||
HTTPS Signed Ops / CLI Dispatch
|
||
│
|
||
┌──────────────────────▼───────────────────────┐
|
||
│ Unified Box CLI Engine │
|
||
│ (box tmux tally / box tmux auto ...) │
|
||
└───────┬───────────────────────────────┬──────┘
|
||
│ │
|
||
┌──────────────▼─────────────┐ ┌─────────────▼──────────────┐
|
||
│ bin/box-onboard-tui.py │ │ bin/tmux_auto_approver.py │
|
||
│ (Dedicated 4-Tab Console) │ │ (Multi-Socket Regex Daemon)│
|
||
└──────────────┬─────────────┘ └─────────────┬──────────────┘
|
||
│ │
|
||
│ │
|
||
┌───────────────────────┴───────────────────────────────┴───────────────────────┐
|
||
│ Tmux Sockets Monitored │
|
||
│ • /tmp/tmux-muse.sock (shared host workers) │
|
||
│ • /tmp/tmux-1000/default (dev/def runner panes & muse-code %37) │
|
||
│ • /tmp/tmux-1000/lte (lte operator pane) │
|
||
│ • /tmp/tmux-<agent>.sock (per-agent netns sockets: pip, 646, opm, dev, def) │
|
||
└───────────────────────────────────────────────────────────────────────────────┘
|
||
```
|
||
|
||
---
|
||
|
||
## 2. Tmux Auto-Approval Regex Match Engine
|
||
|
||
The auto-approval engine monitors scrollback across all agent panes and matches approval prompts against priority rules:
|
||
|
||
| Rule ID | Category | Trigger Pattern | Response Key | Press Enter | Description |
|
||
|---|---|---|---|---|---|
|
||
| `muse_code_run_numbered` | `muse_code` | `Would you like to run the following[\s\S]*?›\s*1\.\s*Yes,?\s*proceed` | `1` | `false` | Muse Code interactive run menu (selects option 1) |
|
||
| `muse_code_run_yn` | `muse_code` | `›\s*1\.\s*Yes,?\s*proceed\s*\(y\)` | `1` | `false` | Active selection indicator on `1. Yes, proceed (y)` |
|
||
| `muse_code_allow_execution` | `muse_code` | `Allow\s+execution\s+of\b[\s\S]*?\[y/N\]` | `y` | `true` | Approves script execution confirmation |
|
||
| `choice_abc` | `choice` | `(?i)(?:choose\|choice\|select)[\s\S]*?^\s*[A-Z]\s*[.\)\-:]\s+\S` | `A` | `true` | Lettered decision choice menus |
|
||
| `menu_numbered` | `menu` | `(?i)(?:Option:\|Selection:)[\s\S]*?^\s*\(?1\)?\s+[A-Za-z]` | `1` | `true` | Numbered selection menus |
|
||
| `confirm_yn` | `confirm` | `([yY]/[nN]\|\[[yY]/[nN]\])\s*[\]:)>]?\s*$` | `y` | `true` | Line-end confirmation prompts |
|
||
| `enter_to_continue` | `enter` | `(?i)(?:Press\s+\[?Enter\]?\s+to\s+continue)` | `Enter` | `false` | Enter-to-continue banners |
|
||
|
||
### Guardrails (Never Auto-Approved)
|
||
- `[sudo] password for ...` / `password:` prompts
|
||
- Passkeys, private key passphrases, and PIN prompts
|
||
- Destructive operations (`rm -rf /`, `mkfs.*`)
|
||
|
||
When a guardrail pattern is detected, the engine flags `is_blocked=true`, emits a warning audit log, and notifies the human operator.
|
||
|
||
---
|
||
|
||
## 3. CLI Commands
|
||
|
||
### Tmux Worker Tally & Management
|
||
```bash
|
||
# Tally all active tmux sessions, panes, and workers across sockets
|
||
box tmux tally
|
||
box tmux tally --json
|
||
|
||
# List active sessions
|
||
box tmux list
|
||
|
||
# Spawn new background worker session
|
||
box tmux new my-worker -c "python3 run_tasks.py"
|
||
```
|
||
|
||
### Auto-Approval Control
|
||
```bash
|
||
# Query master state and per-agent policies
|
||
box tmux auto status
|
||
box tmux auto status --json
|
||
|
||
# Master enable / disable
|
||
box tmux auto on
|
||
box tmux auto off
|
||
|
||
# Enable / disable for specific agent
|
||
box tmux auto on --node muse
|
||
box tmux auto off --node 646
|
||
|
||
# Execute single-pass scan and auto-approve all active prompts right now
|
||
box tmux auto once
|
||
box tmux auto once --dry-run
|
||
|
||
# Run background monitor daemon
|
||
box tmux auto watch --interval 1.0
|
||
|
||
# Tail structured audit log stream
|
||
box tmux auto logs -n 20
|
||
|
||
# Test regex match against custom prompt text
|
||
box tmux auto match "Would you like to run the following ... › 1. Yes, proceed (y)"
|
||
```
|
||
|
||
### Onboard Connects
|
||
```bash
|
||
# View all fleet nodes & client onboard connects
|
||
box onboard connects
|
||
box onboard connects --json
|
||
|
||
# Start client onboarding
|
||
box onboard start dev2 --email client@example.com --for 646
|
||
|
||
# Submit OTP verification code
|
||
box onboard submit-otp dev2 123456
|
||
```
|
||
|
||
### Dedicated Interactive TUI
|
||
```bash
|
||
# Launch full 4-tab interactive TUI
|
||
box onboard-tui
|
||
box tui onboard
|
||
```
|
||
|
||
---
|
||
|
||
## 4. HTTPS Remote Operations (`exec-constrained.py`)
|
||
|
||
Available via `https://exec.muse-dev.online/exec` with signature verification:
|
||
|
||
| Op | Parameters | Description | Permission |
|
||
|---|---|---|---|
|
||
| `tmux.tally` | `{}` | Returns complete worker tally across all sockets (JSON) | `DEFAULT_PERMS` (Read-only) |
|
||
| `tmux.auto_status` | `{}` | Returns auto-approval toggle state & rule set (JSON) | `DEFAULT_PERMS` (Read-only) |
|
||
| `onboard.connects` | `{}` | Returns consolidated fleet and client connects (JSON) | `DEFAULT_PERMS` (Read-only) |
|
||
| `tmux.auto_toggle` | `{"enabled": bool, "node"?: str}` | Toggles master or per-agent auto-approval state | Known-Identities-Only |
|
||
|
||
---
|
||
|
||
## 5. Audit Logging
|
||
|
||
Every auto-approval and blocked guardrail event is written to:
|
||
`/home/super/Projects/NetVM/logs/tmux/auto-approvals.jsonl`
|
||
|
||
Sample event payload:
|
||
```json
|
||
{
|
||
"action": "AUTO_APPROVED",
|
||
"socket": "/tmp/tmux-1000/default",
|
||
"pane": "%37",
|
||
"session": "muse",
|
||
"agent": "muse",
|
||
"rule_id": "muse_code_run_numbered",
|
||
"rule_name": "Muse Code Run (Numbered)",
|
||
"key_sent": "1",
|
||
"press_enter": false,
|
||
"excerpt": "Would you like to run the following ... › 1. Yes, proceed (y)",
|
||
"dry_run": false,
|
||
"success": true,
|
||
"timestamp": "2026-10-06T19:34:19.599811+00:00",
|
||
"ts": 1791315259.6
|
||
}
|
||
```
|