Commit Graph

420 Commits

Author SHA1 Message Date
Levi Neely 190ad4bcdf unify DirStore: single type replaces FlatDir, Union, ToolStore
- New store.DirStore with options: WithReadOnly(), WithIndex(fn)
- Supports single/multi dir, synthetic idx, ListDir, MkdirAll
- Removes UtilStore, ExecStore, ToolStore wrapper types
- toolIndex extracted as standalone function
- All stores in server.go use store.NewDirStore()
- SkillStore stays as-is (different storage model)
2026-05-19 17:07:47 +02:00
Levi Neely 8c2f4a8754 hierarchical SessionStore: /s/ is now a regular route entry
SessionStore accepts paths like id/file, id/t/tool, new, idx.
All /s/ dispatch logic removed from server handlers.
Remaining /s/ refs are metadata only (makeStat, fileOwnerGroup).

- SessionStore.Stat/Open/Delete/Rename/Create handle hierarchical paths
- SessionStore.ListDir for subdirectory listing
- Tool idx filtering moved into SessionStore.openEntry
- SessionStore.MkdirAll delegates to ToolStore
- Removed: sessionFileStore, sessionAllowTools, filterToolIndex,
  OpenFiltered, storeReadCtx, storeBlockingRead from server.go
- routeStore passes full suffix (not pathBase) to stores
2026-05-19 16:52:17 +02:00
Levi Neely 8f0dfdef37 generic read/write dispatch via store entry flags
- Add OneShot, IsBlocking, Async to StoreEntry interface
- FileSpec gains OneShot/Async fields; session entries annotated
- read() is fully generic: openEntry → check flags → dispatch
- handleWrite() reduced to 5 lines via routeStore
- clunk uses entry.Async() instead of hardcoded isAsyncWrite
- Root store for /backends and /help (consistent semantics)
- ToolStore.OpenFiltered for per-session allowTools on idx
- Remove storeReadCtx, storeBlockingRead, isAsyncWrite
2026-05-19 16:39:48 +02:00
Levi Neely 000ad64673 enforce permissions on all paths, use system user/group
- fileOwnerGroup: session internals owned by agent/agent,
  everything else by current system user and primary group
- checkPerm: always enforce, remove no-enforcement bypass
- Directory modes: /s/{sid}=755, /s/{sid}/t=500, /s=755,
  /u,/x=555, /p=664, /a=744, /sk=754, /tmp=777, /tr=766
- File modes: /p/=664, /sk/=664, /s/{sid}/t/*=500
- Session store: sh=550, b/bfg/bbg=555
2026-05-19 16:16:36 +02:00
Levi Neely 629a841cf5 perms: /p/ is owner+user-group rw, agent-group read-only, other denied
uid=ollie gid=user; dir=0750 files=0640. Agents can read prompts
but cannot modify them. Users (non-agent connections) have full access.
2026-05-19 15:59:19 +02:00
Levi Neely c6da56b1d8 perms: session tools (s/{sid}/t/) are owner-only (0700)
Prevents agents from accessing other sessions' tools.
2026-05-19 15:56:26 +02:00
Levi Neely 57e341f907 gitignore: add build artifact 2026-05-19 15:54:24 +02:00
Levi Neely c366cee82c fix: return EOF instead of EIO on read past end of file 2026-05-19 15:52:25 +02:00
Levi Neely 7368b4cfe4 fix: mount proxy uses OLLIE_UNAME so checkPerm identifies session owner 2026-05-19 15:33:27 +02:00
Levi Neely d9622dfc7a fix: deadlock in session rename (lock ordering inversion) 2026-05-19 15:26:33 +02:00
Levi Neely 4cf8a666e3 9p: numeric uname principal, atomic UID counter
Session uname is now a numeric UID (>=10000) separate from the session
name. Rename no longer affects identity — the mount keeps working with
the same principal.

- SessionStore uses atomic.Uint32 for UID generation
- Session.Uname() returns the immutable principal
- SessionByUname() lookup for attach-time group assignment
- fileOwnerGroup uses principal, not session name
- WithMount() passed from createSession
2026-05-19 15:06:26 +02:00
Levi Neely a25dab6ee5 9p: permission model for session files
Session files now have owner=session_id, group=agent. Permission
checking is enforced on open for session files only:

  prompt/fifo.in: mode 0022 (group+other write, owner cannot)
  ctl:            mode 0222 (everyone can write)

Self-prompt rejection is now a natural consequence of the permission
model — the session (owner) has no write bit on its own prompt file.
Cross-agent prompting works via group 'agent' write bit. User access
works via 'other' write bit.

On attach, sessions are added to group 'agent', other users to 'user'.
Removed the explicit self-prompt check from clunk.
2026-05-19 14:22:12 +02:00
Levi Neely f9c9bc8969 9p: uname-based self-prompt rejection + ollie-9p-mount
Store Uname from Tattach on each connection. Reject writes to
s/{id}/prompt when the connection's uname matches the target session
(self-prompt). Cross-agent prompting remains allowed.

Add ollie-9p-mount: a FUSE-to-9P proxy that attaches with a custom
uname derived from $OLLIE_SESSION_ID. Each session gets a transparent
mount — tools use ordinary file I/O and the identity is carried by the
underlying 9P connection.

Also adds a group registry (AddGroup/RemoveGroup/InGroup) on the server
for future access control use cases.
2026-05-19 14:10:22 +02:00
Levi Neely c1f02cdee1 fix: pass OLLIE_SESSION_ID to BuildAgentEnv for prompt resolution 2026-05-18 12:31:43 +02:00
Levi Neely 479ac1b9d4 sessionfile: defer backend/model overrides until after agent= in handleCfg
Ensures manual model/backend settings always win over agent.json defaults
regardless of line order in ctl writes.
2026-05-18 12:16:34 +02:00
Levi Neely 06b0775b66 fix new file 2026-05-17 14:11:01 +02:00
Levi Neely 5ec6ac6fe8 session: use agent config backend/model as defaults; fix stubCore for ToolCallCount 2026-05-17 00:15:40 +02:00
Levi Neely c075964a1f move t/ into s/{sid}/t/; add allowTools filtering at 9P layer 2026-05-16 23:55:14 +02:00
Levi Neely 393460f767 s/new: show generation params in spec template 2026-05-16 07:48:19 +02:00
Levi Neely 5b86ff06fb cfg: expose all generation params in session cfg file 2026-05-16 05:36:10 +00:00
Levi Neely 73b166d276 store: expand ~ and env vars in cwd at session creation
When cwd was passed with ~ or $HOME (e.g. ~/src/myproj), it was used
unexpanded in BuildAgentEnv -> resolvePrompt, causing prompt commands
to fail silently (invalid cmd.Dir) and producing an empty system prompt.

Apply os.ExpandEnv + paths.ExpandHome before cwd is used anywhere.
2026-05-11 14:20:19 +02:00
Levi Neely b4237c326c remove chatwait file from 9p filesystem 2026-05-08 14:42:46 +02:00
Levi Neely 182682cbb7 agents: use OLLIE_AGENTS_PATH for multi-dir agent resolution 2026-05-08 13:01:22 +02:00
Levi Neely 323ae311fe chatwait: return immediately when session is idle
Fixes a race where the client starts a new chatwait read after the
turn has ended (EnsureTrailingNewline already fired), causing a
5-second blocking delay before the shell prompt reappears.
2026-05-08 12:15:36 +02:00
Levi Neely 46c57923ec add chatwait: blocking read that streams new chat content
Replaces polling with a blocking file that returns new bytes as they
are appended to the session log. Unblocks immediately on end-of-turn
(EnsureTrailingNewline) so frontends exit cleanly.
2026-05-08 12:08:34 +02:00
Levi Neely 77c20cf43d support OLLIE_PROMPTS_PATH: multi-dir prompt store via NewFlatDirUnion 2026-05-08 11:59:22 +02:00
Levi Neely 11618a7960 respect OLLIE_DEFAULT_AGENT env var in session creation 2026-05-08 11:33:28 +02:00
Logan Neely 88ea073135 olliesrv: add -strict and -yolo flags
-strict: only tool steps allowed, inline code rejected.
-yolo: skip landrun sandbox for execute_code.
2026-05-07 22:27:27 +02:00
Levi Neely 9bfccebff6 change tools to hierarchical 2026-04-30 14:38:47 +02:00
Levi Neely 7c113c1db4 docs: update session files list and ctl commands 2026-04-30 09:07:49 +02:00
Levi Neely 61c169af3b move store package from core into 9p/store 2026-04-30 07:53:39 +02:00
Levi Neely 4aa815b50c server: add cost to readable session files
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-04-27 18:14:34 +02:00
Levi Neely fee59a2f7c 9p: add 10s read timeout to all store read operations 2026-04-27 13:23:54 +02:00
Levi Neely b44ce18d54 server: dispatch handleWrite on empty writes from writable fids
Fids opened OWRITE or ORDWR with zero bytes written were silently
dropped on clunk — the old writeBuf-length guard prevented handleWrite
from being called, leaving the previous file content intact.

Track writable by open mode instead, and remove the blanket empty-input
early return in handleWrite. /s/new retains its own empty guard since
a zero-byte write there is meaningless.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-04-26 12:49:58 +02:00
Levi Neely fb4d76a3aa server, docs: remove batch jobs; rename spec -> cfg
BatchStore removed from server. s/new always creates an interactive
session. Filesystem layout updated: batch dirspec gone, cfg replaces
spec in session dirspec, s/job -> s/b, s/q -> s/bfg, s/sched -> s/bbg.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-04-24 08:41:46 +02:00
Levi Neely b432ba987c server: update mode mappings for spec; drop removed session files
spec is 0666; offset/statewait/systemprompt/models/ctxsz/usage are
0444 explicitly. Remove mode cases for state, backend, model, agent,
cwd, params, cwdwait, usagewait, ctxszwait. Update README.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-04-24 07:42:58 +02:00
Levi Neely f1a60264e2 docs: document batch job vs interactive session dirspec distinction
s/new routes to BatchStore (one-and-done lifecycle) when the write
contains a \n---\n separator, and to SessionStore (multi-turn) otherwise.
Document both dirspecs separately: batch jobs have spec/state/statewait/
result/usage/ctxsz/log; interactive sessions have the full file set.
Also add missing params file to session dirspec.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-04-24 07:14:22 +02:00
Levi Neely c464879c1b docs: update README for s/b/ unification and new filesystem entries
Remove b/ directory (merged into s/ after namespace unification).
Add job/q/sched/cleanup scripts under s/, document tr/ and tmp/
endpoints, fix t/idx entry, update backing stores table, and correct
olliesrv mount subcommand signature.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-04-24 07:05:52 +02:00
Levi Neely 8d5be7212f 9p: remove /b/ namespace, batch jobs served via /s/
All /b/ routing removed from pathType, read, remove, handleWrite,
readDir, and makeStat. The batchStore field is gone from Server;
SessionStore now handles both session and batch job lifecycle.

-154 lines from server.go.
2026-04-23 18:49:45 +02:00
Levi Neely 9f5286c8b2 feat: add tail file mode to session makeStat 2026-04-22 12:29:35 +02:00
Levi Neely cb206a7387 docs: update README for refactor (stores, prompts, sandbox) 2026-04-22 10:35:38 +02:00
Levi Neely 2df001a5eb server: report content length for session files in stat
makeStat was missing a case for /s/{id}/{file} paths, so stat
reported Length=0 and clients (cat via 9pfuse) read zero bytes.
2026-04-22 09:38:33 +02:00
Levi Neely 426a6ac7bc remove tracked binary, add .gitignore 2026-04-21 21:10:50 +02:00
Levi Neely f411589519 server: adapt to Store+StoreEntry model
- Replace Get/Put calls with storeRead/storeWrite helpers
- Replace Wait calls with storeBlockingRead helper
- Wrapper types override Open instead of Get
- Use OpenStore for session/batch child stores
- All store fields typed as Store
2026-04-21 20:07:37 +02:00
Levi Neely ee1710b2cb server: use Open instead of JobStore/SessionFileStore
- FlatDirStore alias points to BlobStore
- Server fields use BlobStore for flat stores
- Replace JobStore/SessionFileStore with Open
- Type-assert for Wait/LogInfo where needed
- Rename store variable to sfs to avoid package shadowing
2026-04-21 19:03:19 +02:00
Levi Neely d5bc214bd0 server: delegate SessionFileStore construction to SessionStore
- Wire SaveTranscript into SessionStoreConfig
- sessionFileStore now calls sessionStore.SessionFileStore
2026-04-21 18:29:00 +02:00
Levi Neely d6bf477531 server: adapt to store storeConfig architecture
- FlatDirStore alias points to store.Store interface
- UtilStore/ExecStore/ToolStore embed interface not pointer
- NewFlatDirStore/NewSkillStore return interfaces
- Rename ChatInfo->LogInfo
2026-04-21 18:23:28 +02:00
Levi Neely 6936c1c959 flatten: merge internal/p9 into package main
Removes internal/p9/ directory. store.go and server.go merged into
root server.go alongside main.go. No logic changes.
2026-04-21 16:44:02 +02:00
Levi Neely 73b634b6d3 store: use core Session/SessionStore/SessionFileStore, remove local implementations
Server no longer owns sessions map or session lifecycle methods.
SessionStore and SessionFileStore are type aliases to core.
Fid path rewriting on rename handled via OnRename callback.
2026-04-21 16:37:43 +02:00
Levi Neely b6d579d74c store: use core BatchStore, FormatEvent, LoadAgentConfig; remove local batchstore 2026-04-21 16:29:38 +02:00