Commit Graph

81 Commits

Author SHA1 Message Date
Levi Neely 9b7de31a07 add doc.go files; decompose agent package
doc.go:
- agent, backend, session, fs, bypass, toolclient (olliesrv)
- server, sandbox, registry (toolsrv)
- protocol, metadata (toolsrv shared)
- log, util, skills

agent package decomposition:
- chat.go: chat log, streaming, plan methods
- state.go: State, Reply, WaitChange, SignalCh, emit
- peer.go: AddPeer, RemovePeer, Peers
- subagent.go: Depth, IncChildren, DecChildren, ActiveChildren
- agent.go: 881 → 638 lines (core struct, identity, backend, runtime)
2026-08-27 10:03:58 +02:00
Ollie Agent 3f8c8df38a Improve workflow-aware tool ranking 2026-08-20 19:01:21 +02:00
Levi Neely 4ff37741e2 subagent: fix timeout and premature response issues
Timeout fix:
- Add Timeout field to ToolInfo (protocol) and MetaFile (metadata)
- proc.go respects tool-declared timeout before falling back to 30s default
- subagent_spawn.meta declares timeout=0 (no timeout) so the tool is
  never killed prematurely while waiting for the sub-agent to finish
- Tool schema declares timeout with 'do not set' guidance to prevent
  the LLM from adding a short timeout

Premature response fix:
- Inject behavioral prefix into sub-agent prompt: complete all work
  before responding, report results not intentions
- Sub-agent's final text is returned to parent; this instruction ensures
  it contains accomplished work, not a plan
2026-08-20 10:59:23 +02:00
Levi Neely 74ba5ae7ac remove maxSteps and ResetsCounter entirely
The step budget mechanism is gone. Agents run until they finish,
are interrupted by the user, or (for sub-agents) hit the timeout.

No replacement. The human is the kill switch.
2026-08-17 09:48:58 +02:00
Ollie Agent 16a2b72051 consolidate 9P clients 2026-08-16 18:56:11 +02:00
Ollie Agent e5f1dbb0e6 update tool discovery utility import 2026-08-16 18:38:32 +02:00
Ollie Agent aca5546ea5 refactor environment utilities and file tools 2026-08-16 18:20:50 +02:00
Ollie Agent 81933e5281 refactor toolsrv into client protocol and metadata packages 2026-08-16 17:22:59 +02:00
Levi Neely 250ad4b233 agent/new: sub-agent support via rdwr with prompt=
Writing to session/{s}/agent/new with a prompt= key now blocks
until the agent completes its task, then returns the reply and
destroys the transient agent. Without prompt=, behaves as before
(creates agent, returns ID).

Also:
- Move ParsePayload/UnescapeValue to shared ollie/toolsrv package
- Remove duplicate implementations from cmd/toolsrv/internal/server
- Add session.CreateAgentWithParams for direct AgentParams usage
- Eliminate flattenParams/unescapeValue redundancy in fs package
2026-08-14 14:48:12 +02:00
Levi Neely d64f6c1d76 proc: rename ListDetachedRaw→ListProcs, use proc/list rdwr (agent-filtered)
ListProcs now does rdwr to toolsrv proc/list with the agent ID.
Returns pre-formatted text. Ctl proc handler uses it directly.
Removed all ListDetachedRaw map-parsing logic.
2026-08-13 22:22:54 +02:00
Levi Neely fd4a3afa4f move tool catalog to toolsrv: add /all file, tools_all ctl command
- Remove /tools from olliesrv root (toolsrv owns all tool state)
- Add /all file to toolsrv namespace (lists all available tools on disk)
- Add ListAllTools() to toolsrv client library
- Add tools_all ctl command to agent (reads from toolsrv/all)
- Update system prompt with tools_all usage
2026-08-13 21:58:08 +02:00
Levi Neely 9b98a958cc fix: treat meta cmd as shell command string, prepend tools dir to PATH
- ResolveTool now returns cmd field as-is instead of trying to resolve
  it as a binary path. This allows meta-only tools to use full shell
  command strings with env vars, pipes, and subshells.

- Prepend ~/.config/ollie/tools to PATH when executing tools so cmd
  fields can reference other tools by name.
2026-08-12 18:44:16 +02:00
Levi Neely 1d5e9c4f8d fix: background proc output capture and status display
- Detach background proc context from request context so processes survive
  after the 9P request returns (fixes premature SIGTERM)
- Add /proc/list file to toolsrv showing all procs with state
- Show status (running/exited (N)) in agent proc list
- Keep exited procs in tracker until explicitly dismissed
- Skip 'list' entry in ListDetachedRaw
2026-08-12 14:10:08 +02:00
Levi Neely 85435447bf fix: clean shutdown without connection errors
- Use read deadline + context check instead of forcibly closing connections
- ReadBypassPending now takes context and exits cleanly on cancellation
- Remove forced conn.Close() loop from Kill() - context cancellation suffices
2026-08-12 12:40:40 +02:00
Levi Neely 3a68b0be53 Fix bypass broker and stop command
- Wire BypassBroker into fs.Config before creating root tree
- Move defer bypassBroker.Close() outside block scope (was closing immediately)
- Rewrite /bypass/ FS nodes to match toolsrv's expected interface:
  - bypass/pending: blocking read returning JSON {id,cmd,cwd,env}
  - bypass/resolve: write JSON {id,approved,error}
- Add NextPending() method to broker with channel-based blocking
- Add JSON tags to Request struct for proper serialization
- Start bypass loop for restored sessions (was only for new sessions)
- Add context cancellation support to CallTool (closes fid on cancel)
2026-08-12 09:16:59 +02:00
Levi Neely 9bb3cd76b8 Remove sudo mechanism from bypass system
The sudo credential broker was never functional and added complexity
without value. This removes:

- Sudo field from bypass Request structs (broker, client, toolsrv)
- Sudo parameter from EvaluateRequest interface and implementations
- Sudo/ResetsCounter fields from MetaFile and Variant structs
- sudo: true from system_logs.meta variants
- All sudo documentation from writing-tools.md, tool-registry.md,
  core.md, evolution.md, and misc.md

Bypass remains fully functional for sandbox escapes. Tools that need
elevated privileges should handle that internally or be run manually.
2026-08-12 08:58:41 +02:00
Levi Neely 8bb5c098cc bypass: route approval through 9P instead of Unix socket
This refactors the bypass (sandbox escape) mechanism to work with remote
toolsrv deployments. Previously, bypass used a Unix socket which only
works when toolsrv runs locally. Now:

1. toolsrv exposes bypass/{pending,resolve} 9P files
   - pending: blocking read returns next bypass request as JSON
   - resolve: write JSON {id, approved, error} to complete request

2. olliesrv reads bypass/pending in a loop per session
   - Evaluates requests through the existing bypass broker
   - Policy check, rate limiting, user notification all stay in olliesrv
   - Writes approval/denial back to bypass/resolve

3. When approved, toolsrv executes the command directly (no sandbox)
   - Execution happens on toolsrv's host (local or remote)
   - Output streams back through the normal tool call path

This enables bypass to work when toolsrv is remote:
- User sees the approval notification locally
- Command executes on the remote host outside its sandbox

Architecture:
  toolsrv (remote)          olliesrv (local)
  ┌─────────────────┐      ┌──────────────────┐
  │ sandboxed cmd   │      │ bypass broker    │
  │      ↓          │      │  - policy        │
  │ bypass.Submit() │──────│  - notification  │
  │      ↓          │ 9P   │  - rate limit    │
  │ wait for result │←─────│  - user approval │
  │      ↓          │      └──────────────────┘
  │ execute direct  │
  └─────────────────┘
2026-08-12 08:48:32 +02:00
Ollie Agent de5456e4aa toolsrv: fix per-agent tool registry to actually work
The registry was keyed by agent ID but read it from a shared env map
(st.env["OLLIE_UNAME"]) that all agents overwrote — making it
effectively per-session with a race condition.

Fix: pass agent ID explicitly through the protocol at every call site.

- ctl protocol: 'load <agentID> <tool>', 'unload <agentID> <tool>'
- tools file: rdwr (Request) — write agent ID, read filtered list
- proc/new payload: 'agent=<id>' field required
- Client: SetAgentID() stores identity, included in all operations
- Empty agent ID is a hard error everywhere
- Setting OLLIE_UNAME via env ctl is blocked (prevents reintroduction)
2026-08-11 16:26:12 +02:00
Ollie Agent 0d1eeaa46b fix: background process lifecycle, streaming output, and connection deadlocks
- Timeout: timeout=0 means no deadline (was defaulting to 30s)
- Signal: send to process group (-pgid) not just process; SIGTERM no longer
  cancels context (only SIGKILL does); cmd.Cancel sends SIGTERM with 5s WaitDelay
- Streaming: background procs stream output in real-time via procWriter;
  shell tool no longer buffers all output into a bash variable
- Proc tree: olliesrv exposes proc/{id}/out, proc/{id}/ctl, proc/{id}/status
  as proper 9P directory (was broken flat file)
- Connection: proc handlers dial fresh toolsrv conn per request via
  Session.DialToolServer() to avoid deadlocking the agent's blocked conn
- Stat format: key=value (exited=true, exit_code=N, id=N) matching client parser
- GC: procs auto-removed 10min after LastRead (exited procs only)
- Rename: PID -> ID throughout (synthetic, not OS PID)
- Ctl commands: term (SIGTERM), kill (SIGKILL), signal <n>, dismiss
- System prompt: correct ollie-9p commands for proc management
2026-08-11 09:44:08 +02:00
Ollie Agent aa270525a5 agent: background process interrupts — auto-inject output at safe points
When a tool call includes "background": true, it executes via
proc/new.bg and returns immediately with a PID in a
<system-proc-background> tag. The agent tracks active background
processes and injects their output as <system-proc-interrupt> blocks
alongside subsequent tool results.

The model sees background updates without polling. It can react to
build failures, log events, etc. naturally. Kill via PID when done.

Implementation:
- toolsrv client: CallToolBackground (uses proc/new.bg as rdwr)
- toolsrv: proc/new.bg upgraded from write-only to request-response
- agent: bgTracker collects last 20 lines of output per proc
- agent loop: injects interrupts after execToolCalls, before h.update
- system prompt: documents the background mechanism and rules
2026-08-11 08:23:00 +02:00
Ollie Agent 586edc1332 agent: replace ReadOnly with explicit scope field (read/write/global)
Rename ToolInfo.ReadOnly bool → ToolInfo.Scope string with three values:
- "read"  — path-scoped read, never conflicts (always parallel)
- "write" — path-scoped write, conflicts on same file path only
- "global" — full serialization barrier, runs alone

Tools declare scope in their .meta file. If unset, inferred from path
arg presence (write if path exists, global otherwise).

This correctly classifies lsp_rename as global (cross-file workspace
edits) despite having a path argument. The path arg in lsp_rename is
a symbol coordinate, not a resource scope.

All .meta files updated: readOnly:true → scope:read,
readOnly:false → scope:global, lsp_rename gets scope:global.
2026-08-11 07:56:00 +02:00
Levi Neely e8239927de toolsrv: move Registry to cmd/toolsrv, keep only client SDK in shared package
Split toolsrv/registry.go:
- cmd/toolsrv/registry.go: Registry type with session-scoped tool state
  (Load, Unload, Loaded, Lookup, Revision methods)
- toolsrv/registry.go: shared types only (ToolInfo, ToolsPath, DiscoverTools)

The toolsrv/ package is now a pure client SDK:
- Dial, Conn for 9P connection
- ToolInfo, ToolResult, HostInfo types
- DiscoverTools for listing available tools

Server-only code lives in cmd/toolsrv/:
- Registry for session-scoped tool state
- 9P handlers and execution logic
- Sandbox integration
2026-08-10 20:57:32 +02:00
Levi Neely a0315a558a refactor: move toolsrv spawn/process management to toolclient
Move spawn.go from toolsrv/ to cmd/olliesrv/internal/toolclient/:
- Process, ProcessKeeper, Spawn, SpawnRemote now in toolclient package
- toolsrv/ now only contains client code (Dial, Conn, etc.)

This clarifies the architecture:
- toolsrv/ = client SDK for connecting to toolsrv
- cmd/toolsrv/ = the toolsrv server
- cmd/olliesrv/internal/toolclient/ = olliesrv's toolsrv process management

Removed ProcessKeeper tests from toolsrv integration tests since they
now belong to toolclient.
2026-08-10 20:49:22 +02:00
Levi Neely 1fc051e3bf refactor: move olliesrv and toolsrv packages to cmd/*/internal/
Move server-only packages under their respective cmd directories:

olliesrv:
- agent/ -> cmd/olliesrv/internal/agent/
- backend/ -> cmd/olliesrv/internal/backend/
- bypass/ -> cmd/olliesrv/internal/bypass/
- fs/ -> cmd/olliesrv/internal/fs/
- prompts/ -> cmd/olliesrv/internal/prompts/
- session/ -> cmd/olliesrv/internal/session/

toolsrv:
- Server-only code (exec9p, fs9p, server9p, spec9p, auth9p) -> cmd/toolsrv/
- sandbox/ -> cmd/toolsrv/internal/sandbox/
- Keep shared client code (client9p, spawn, registry, meta) in toolsrv/
- Add toolsrv/types.go for shared types (ToolResult, ToolResultContent)

This enforces package boundaries - code in cmd/*/internal/ cannot be
imported by external packages, while shared code remains importable.
2026-08-10 20:16:44 +02:00
Levi Neely 85df48b0c3 agent: remove dead streaming code
WithOutputStream context never crossed IPC boundary to toolsrv,
so streamed was always false. Simplify to just emit result directly.
2026-08-10 20:07:35 +02:00
Levi Neely b01189e731 toolsrv: fix multiline content truncation in tool args
Bug: spec9p.go was double-processing payloads - parseKV unescaped
\n to newlines, then rebuilt the payload without re-escaping,
then fs9p.go's parsePayload tried to unescape again. Result:
multiline content like file contents was truncated to first line.

Fix: Pass raw payload data through to fs9p.go. Escaping/unescaping
happens once in parsePayload.

Also:
- Add proper one-pass unescape function (handles \\n correctly)
- Add TestIntegration_MultilineContent to verify fix
- Add InputSchema verification to TestIntegration_ToolExecution
2026-08-10 20:06:35 +02:00
Levi Neely 89493c32da toolsrv 9P: session ID, JSON tool schemas, remote deployment
- Pass session ID via --session-id flag (not env var) so tool registry is configured when olliesrv spawns toolsrv

- /tools now returns JSON array with full ToolInfo including InputSchema (fixes Bedrock validation error requiring type: object)

- Implement SpawnRemote: deploy ~/.config/ollie via tarball over SSH, set XDG_CONFIG_HOME so tools/*.meta are found on remote

- Add --no-auth flag for debugging Tauth issues
2026-08-10 19:34:00 +02:00
Levi Neely 611e0194c9 toolsrv: skip tool execution tests when tools dir unavailable
Tests now skip gracefully in CI environments where ~/.config/ollie/tools
doesn't exist, instead of failing with 'no tool registry configured'.

Also added OLLIE_SESSION_ID to test server startup.
2026-08-10 19:18:45 +02:00
Levi Neely 565acfb07b toolsrv: improve integration tests to match real usage
- Parse ToolResult JSON the same way agent/runtime.go does
- Verify Content structure, Type field, and IsError flag
- Add TestIntegration_ToolExecutionError for failed commands
- Tests now verify the wire format matches what olliesrv expects
2026-08-10 19:15:56 +02:00
Levi Neely c9789de2bd toolsrv: fix ReadAt offset for request-response files
After Write(), the file offset is at the end of the written data.
For request-response files (like proc/new), we need to read the
result from offset 0, not from the current offset.

Changed CallTool() to use ReadAt(buf, 0) instead of io.ReadAll()
which uses Read() and inherits the wrong offset.

Same fix was already applied to token reading in Dial().

Added TestIntegration_ToolExecution to verify the full tool
execution path works end-to-end.
2026-08-10 19:14:09 +02:00
Levi Neely 11c67a7fb1 toolsrv: implement 9P Tauth authentication
Replace HMAC-based registration with proper 9P Tauth flow:
- First client to connect sets the secret via Tauth afid write
- Server stores secret in memory, returns session token
- Subsequent clients must provide matching secret
- Secret never in env vars or disk, only transmitted over socket

Changes:
- server9p.go: Authenticate() replaces RegisterAgent/GetAgent
- client9p.go: Dial() does Tauth handshake (write secret, read token)
- spawn.go: generates secret, no longer passes via TOOLSRV_SECRET env
- auth9p.go: simplified to just GenerateSecret()
- spec9p.go: removed /register file, token validation at connection level
- cmd/toolsrv/server.go: handleAuth/handleAuthWrite/handleAuthRead

Security model:
- Session generates secret on Spawn()
- All agents share session's secret via ProcessKeeper
- Socket permissions (local) or SSH (remote) protect transport
- Secret dies with toolsrv process, new secret on respawn

Added integration tests verifying:
- First connection sets secret
- Reconnect with same secret works
- Wrong secret rejected
- ProcessKeeper reconnect/respawn behavior
- Concurrent connections
2026-08-10 19:03:10 +02:00
Levi Neely 427cadeb29 toolsrv: remove JSON-RPC, add compat stubs for 9P transition
BREAKING CHANGE: Removes all JSON-RPC toolsrv code.

Deleted files:
- server.go, rpcserver.go, rpcwire.go (JSON-RPC server)
- conn.go, dial.go (JSON-RPC client)
- exec.go, stream.go, detach.go (old execution tied to Server)
- spawn.go, transport.go, processkeeper.go, remote.go (spawning)
- shell_validate.go (tied to old Server)

New/modified:
- compat.go: Stub types to keep agent/session/fs packages compiling
  - Conn, Process, ProcessKeeper with TODO implementations
  - Spawn, SpawnRemote stubs
  - HostInfo, RemoteConfig, Option types
  - All marked TODO for 9P implementation

- cmd/toolsrv/main.go: Updated to use 9P model
  - Requires TOOLSRV_SECRET env var
  - Builds fsedsl tree
  - serve9P placeholder for 9P protocol handling

- exec9p.go: Added ToolResult types, limitedWriter, plan9Namespace

The codebase compiles but toolsrv is non-functional until:
1. serve9P implements 9P protocol
2. Conn stubs are replaced with lib9p client
3. Spawn/ProcessKeeper spawn 9P server
2026-08-10 16:48:40 +02:00
Levi Neely 6fc7cf999b toolsrv: use fsedsl for namespace spec
- spec9p.go: fsedsl-based namespace specification
  - ToolsrvCtx with Server, Agent, Proc
  - Handlers as package-level functions
  - Follows fs/spec.go pattern

- server9p.go: simplified to state management only
  - Agent registration with HMAC tokens
  - BuildTree() creates fsedsl tree
  - Removed redundant 9P protocol handling

The 9P protocol serving will use the same pattern as olliesrv
(cmd/olliesrv/server.go), which takes a *fsedsl.Tree and handles
all 9P message types generically.
2026-08-10 15:52:34 +02:00
Levi Neely d37404ebd3 toolsrv: add 9P server implementation
New files:
- server9p.go: 9P server for tool execution
  - Agent registration with HMAC-signed tokens
  - Token → cwd mapping for secure execution context
  - Full 9P protocol handling (version, attach, walk, open, read, write, stat, clunk)
  - Namespace: /register, /ctl, /tools, /proc/*, /info

- auth9p.go: Authentication helpers
  - GenerateSecret(): 32-byte random secret
  - ComputeRegistrationSig(): HMAC-SHA256 signature for registration

- server9p_test.go: Unit tests for auth and server

Security model:
- olliesrv spawns toolsrv with shared secret (env or file)
- Agent registration: olliesrv signs (agentID, cwd) → token
- Every tool call includes token; toolsrv verifies and looks up cwd
- Prevents unauthorized cwd manipulation from untrusted actors (LLM)
2026-08-10 15:43:20 +02:00
Levi Neely 1cd158926a rename ollie-remote to toolsrv
- cmd/ollie-remote -> cmd/toolsrv
- Update all references in toolsrv package
- Update justfile build targets
- Binary now installed as ~/.local/bin/toolsrv
2026-08-10 15:01:42 +02:00
Levi Neely ced1389549 toolsrv: add 9P-based tool server foundation
New files:
- fs9p.go: FS9P struct with /proc-based execution model
  - /proc/new (rdwr): blocking tool execution
  - /proc/new.bg: background/detached execution
  - /proc/<pid>/out, wait, stat, ctl: process management
  - /tools, /ctl, /info: tool registry and host info
  - Payload format: key=value lines, newline delimited

- exec9p.go: Decoupled tool execution
  - ExecuteTool: standalone function for tool execution
  - executeSandboxed: sandbox execution without Server deps
  - executeBypassDirect: bypass broker without Server deps

- fs9p_test.go: Unit tests for FS9P

Design notes:
- Background execution is the internal model
- Foreground (/proc/new rdwr) blocks until completion
- No per-connection state (cwd/env passed per-call or at attach)
- Session ID scoping via registry, not env propagation

This is the foundation - actual 9P serving and integration pending.
2026-08-10 14:53:13 +02:00
Ollie Agent fbe8059cf5 maintainability: docs, contracts, structural cleanup
- doc/boot-sequence.md: init chain from main → fs.NewRoot → session.Init
- Event protocol: comprehensive table on Event struct (all roles, semantics)
- RPC server moved from cmd/ollie-remote into toolsrv/rpcserver.go
  (binary is now a 93-line thin wrapper)
- SetSessionEnv folded into NewAgent (no post-construction wiring needed)
- AgentCfg → AgentParams (distinguish from AgentConfig JSON schema)
- ToolResult/ToolResultContent shared types in toolsrv/rpcwire.go
- toolsrv/shell.go → toolsrv/exec.go (name matches purpose)
- Resume unified: single path, always through Keeper
- AGENTS.md: fix fs/builder.go → fsedsl/builder.go, handlers_*.go
- fsedsl/Tree: document dual-mode (EDSL lazy vs Manual Mount)
- Truncation stack documented at defaultToolResultMaxBytes
- Integration test rewritten to use srv.ServeRPC directly
2026-08-09 21:45:56 +02:00
Ollie Agent 2d74ffb95e prompt audit: trim system prompt, kill dead code, improve maintainability
- System prompt: ~200 → ~80 lines (removed tool-first table, API docs,
  output protocol, dead 9P entries)
- Removed AllowTools entirely (field, RPC, configs)
- Removed PRIME_* env vars, replaced with typed struct fields
- Merged tool listing + docs into single renderTools()
- Killed BuildToolListing, changed OnToolsChanged to func() signal
- Typed Preamble.Section (compile-time safety)
- Added protocol docs on extractToolResult
- Added session/ package godoc
- Moved output protocol to per-agent prompts
- Rewrote data/agents/README.md
- Moved 7 reference docs from doc/resources/ to doc/
- Deleted PromptEnv() dead function
2026-08-09 14:13:52 +02:00
Ollie Agent 2b4d577e39 refactor: architectural cleanup (5 items)
1. Standardize ctl dispatch: hoist rootCtlHandlers and sessionCtlHandlers
   to package-level vars, matching the agent pattern.

2. Fix error wrapping: %v → %w in toolsrv/shell.go (only 2 instances;
   backend/ was already clean).

3. Canonicalize tool server access: LoadTool now only uses
   session.ToolsConn() — removed fallback to agent.ToolServer().

4. Centralize event handler wiring: wireAgentEvents(sessID, ag, al)
   replaces separate SetOutput + wireAgentStateEvents calls. Documents
   the contract.

5. Split toolsrv/shell.go: validation patterns, ValidateCode, and rate
   limiting moved to shell_validate.go (86 lines). shell.go retains
   execution logic (594 lines).
2026-08-09 12:46:36 +02:00
Ollie Agent 74635b8e00 refactor: items 8-10, 12, 13 from code review
- Move parseRetryAfter to backend.go (where it's called)
- Extract paths.RuntimeDir() replacing 3 divergent XDG_RUNTIME_DIR impls
- Rename CodeWhispererBackend → KiroBackend, NewCodeWhisperer → NewKiro
- Export RPCRequest/RPCError/OutputNotification from toolsrv/rpcwire.go
- Factor tools/lsp/cmdutil: Run() and RunCustom() for 7 LSP binaries
2026-08-09 11:32:31 +02:00
Ollie Agent 9c90cb8954 refactor: reduce redundancy, remove dead code, improve structure
- Fix CodeWhisperer SetModel cache invalidation bug
- Remove dead code: gemini stub, orphaned comments, kiroMetadataEvent
- Extract paths.NewUUID() replacing 3 duplicate UUID implementations
- Export toolsrv.BuildToolListing, deduplicate tool listing render
- Extract baseBackend struct (Name/Model/SetModel) embedded in all backends
- Unify backend factory post-processing (7 if-blocks → 1)
- Split fs/handlers.go (888 lines) into handlers_{root,session,agent}.go
- Strip dead filesystem-backed tree code from fsedsl (WithReadOnly,
  WithIndex, WithResolver, ValidateReadMode, resolve/writePath fallbacks)
2026-08-09 11:23:25 +02:00
Ollie Agent c7aea0db59 rename elevate→bypass throughout
The sandbox escape mechanism is a bypass, not privilege elevation.
The old name caused the agent to confuse it with sudo.

- elevate/ → bypass/ (package, types, tests)
- elevate_notify.go → bypass_notify.go
- Namespace: /elevate → /bypass, session/*/elevate → session/*/bypass
- Tool arg: "elevated" → "bypass"
- Env: OLLIE_ELEVATE_SOCKET → OLLIE_BYPASS_SOCKET
- File: elevate-policy.yaml → bypass-policy.yaml
- All docs, prompts, and scripts updated
2026-08-09 02:22:39 +02:00
Ollie Agent 455434608a all: merge toolsrv files, fix context hierarchy, remove dead params
toolsrv:
- Merge rpc.go into conn.go (wire types already there)
- Merge tools.go + discover.go into registry.go
- Merge accessors.go into server.go
- 4 files eliminated

fs:
- HandlerCtx.Context now carries the session context (set via
  sessionBindings Applier). Previously it was the daemon context
  which never cancels — handlers checking ctx.Done() now properly
  detect session kill/pause.
- Session-scoped blocking handlers (streamAgentChat, blockAgentStateWait)
  merge session context with per-read timeout via mergeCtx(). A session
  kill now immediately unblocks readers without waiting for the 5s timeout.
- Remove redundant manual AfterFunc in blockAgentStateWait.

session:
- Remove unused _ string parameter from WaitEvent
2026-08-08 16:13:55 +02:00
Ollie Agent 705a7226a2 all: merge thin packages and small files
- Merge detach/ into toolsrv/detach.go (single consumer)
  Rename Process → DetachedProcess to avoid collision with spawn.go
- Merge agent/state.go into loop.go (types used only there)
- Merge agent/runtime.go into runtime.go (formerly build_runtime.go)
- Merge agent/compaction.go + models.go into history.go
- Merge agent/new.go into agent.go (constructor lives with struct)
- Rename ResultTier → MemoryTier (TierHot/Warm/Cold → MemoryHot/Warm/Cold)
- Rename build_runtime.go → runtime.go
2026-08-08 15:56:26 +02:00
Ollie Agent 8152dec075 all: delete dead code, tighten API surface
toolsrv:
- Delete WithOnClose, WithOnEnvSet, SetOnExit (dead Options)
- Delete ListDetached, ListDetachedInfo (only ListDetachedRaw used)
- Delete Execute (dead wrapper)
- Delete CWD, ToolRegistry, SessionID, InjectContent (dead accessors)
- Delete ExecuteInSandbox, ExecuteElevated (zero external callers)
- Delete Summaries, RefreshLoaded from Registry (dead)
- Delete DialSSH (alias for RemoteDial)
- Simplify Dial: takes socket string directly, kill Addr/LocalAddr/SSHAddr
- Rename Server receiver e → s
- Unexport context import (no longer needed in tools.go)

session:
- Delete SaveFuncs, AgentAt, AgentCount, NextUncheckedStep
- Delete SetDisallowTools, SaveAllSessions

env:
- Delete Set, Get, All, Format, managed (dead exports)
- Unexport LoadFile → loadFile

fs:
- Delete HandlerCtx.ToolReg, Skills, SaveFn (never read by handlers)
- Delete Config.MkdirAll, Config.SkillsRegistry (dead plumbing)
- Delete AgentLog: Plan, SetPlan, PrevPrompt, Mu, LogInfo, Remote methods
- Delete unused type aliases (NodeOption, FileTree, FileConfig, etc.)

backend:
- Delete ClosePool, PoolStats (dead), New() (dead)
- Delete kiroTokenExpiringSoon standalone func (dead)
- Unexport SharedTransport/SharedClient → sharedTransport/sharedClient

skills:
- Delete entire package (zero importers; feature works via tool scripts)

agent:
- Delete BroadcastChange (dead duplicate of notifyChange)
- Delete HasHistory, ToolCallCount, CompactionModel, SetCompactionModel
- Unexport SetReply, BuildPreamble, DefaultPromptsDir
2026-08-08 15:51:13 +02:00
Ollie Agent 06a996e967 all: replace toolsrv.Runner interface with *toolsrv.Conn
The agent always talks to a *Conn (never a *Server directly).
Replace the Runner interface with the concrete type throughout:

- Runtime.ToolServer is now *toolsrv.Conn
- BuildRuntime takes *toolsrv.Conn
- session.Config, SessionInfra, InfraConfig use *toolsrv.Conn
- All inline type assertions in agent.go deleted — methods called
  directly on *Conn (SetEnv, SetCWD, Close, Detach, ListDetachedRaw,
  SignalDetached, GetDetachedOutput, DismissDetached, SetAllowTools,
  SetOnToolsChanged, Ping, ToolRegistryRevision)
- Added Conn.ToolRegistryRevision() that returns 0 (remote connections
  don't support revision tracking; use push-based OnToolsChanged instead)
- Deleted the Runner interface and its test
- Renamed LoadToolOnRunner → LoadToolOnConn
2026-08-08 15:10:01 +02:00
Ollie Agent 63c4cd6173 all: kill dead code, remove classifier system, clean up names
Dead code removed:
- agent: firstSentence, Checkpoint, WaitForChange, InitCond, cfgDir,
  execServer, SaveTo, SaveFull, saveTo, saveToFull, sanitizeMessages,
  LoadPersistedAgent, RestoreHistory, Restore, PersistedAgent type
- toolsrv: entire tier.go (MemoryTier, MemoryTierArgs, OutputFormat,
  CanParallelize on Server), same methods on Conn
- cmd/ollie-remote: can_parallelize, memory_tier, memory_tier_args RPC
  handlers
- toolsrv/rpc_integration_test: all classifier tests
- fs/lifecycle: state(root) dead helper

Renames:
- session.Session receiver: 'a' → 's' throughout
- SaveSession(path) → Save() (dead parameter removed)
- execServer() eliminated — callers use ag.runtime.ToolServer directly

The agent-package save/restore chain was entirely dead: PersistSession
in session/persist.go reads agent accessors directly and never called
SaveTo/SaveFull.
2026-08-08 14:52:10 +02:00
Ollie Agent b6694d409a agent/toolsrv: replace classifier system with ToolMeta map
The entire classifier indirection (interfaces, type assertions, RPC
methods for classification, closure wrappers in BuildRuntime) is replaced
by a simple map[string]ToolInfo on Runtime.

The .meta file is read once into ToolInfo. The loop reads fields directly:
  rt.ToolMeta[name].ReadOnly       (was: rt.CanParallelize(name))
  rt.ToolMeta[name].Tier           (was: rt.MemoryTier(name, args))
  rt.ToolMeta[name].OutputFormat   (was: rt.OutputFormat(name))
  rt.ToolMeta[name].ResetsCounter  (was: rt.ResetsCounter(name))

Removed: ParallelClassifier, MemoryTierClassifier, OutputFormatClassifier
interfaces, toolClassifier type, and all closure-wrapping in BuildRuntime.

The RPC methods on Server/Conn stay (used by ollie-remote) but the agent
no longer routes through them.
2026-08-08 14:33:23 +02:00
Ollie Agent 38b35f1ba5 toolsrv/agent: rename ClassifyTool→CanParallelize, ClassifyTier→MemoryTier
Rename throughout: Go methods, interface types, Runtime fields, wire
protocol RPCs, tests, and ollie-remote.

- IsParallelRead / ParallelClassifier → CanParallelize
- ResultTier / ResultTierArgs / TierClassifier → MemoryTier / MemoryTierArgs / MemoryTierClassifier
- Wire: is_parallel_read → can_parallelize, result_tier → memory_tier, result_tier_args → memory_tier_args
2026-08-08 14:29:41 +02:00
Ollie Agent 32ff54f708 agent: simplify configuration/instantiation layers
- Kill agentConfig struct. run() takes (*Runtime, TurnCtx, state) directly.
  TurnCtx holds only 7 per-turn closures; stable config reads come from Runtime.

- Lazy tool refresh: toolsNeedRefresh() checks ToolRegistryRevision() on the
  tool server. Skips ListTools IPC when registry hasn't changed. Remote Conn
  falls back to always-refetch (same as before).

- AgentConfig.GenParams() method replaces the 16-line manual field copy in
  BuildRuntime.

- Remove CfgBackend/CfgModel from Runtime. Callers read cfg.Backend/cfg.Model
  directly since they already have the AgentConfig in scope.
2026-08-08 14:19:46 +02:00