Commit Graph

34 Commits

Author SHA1 Message Date
Levi Neely 7b870443bb remove desktop notification for bypass requests
Bypass approval now flows through:
1. GUI - via event stream and banner
2. CLI - via agent loop (to be implemented)

Removed:
- bypass_notify.go (D-Bus notification)
- BypassNotifyFunc type and all references
- godbus/dbus dependency

The bypass event is still published via SetBypassPending.
2026-10-06 14:03:07 +02:00
Ollie Agent 223a8f1235 remove plumber references 2026-08-18 13:32:43 +02:00
Ollie Agent bf262cba16 manage namespace directory lifecycle 2026-08-18 13:31:52 +02:00
Ollie Agent bdafc30022 replace landrun with native Landlock sandbox 2026-08-18 12:36:27 +02:00
Ollie Agent 59c4ed23ac merge paths utilities into util 2026-08-16 18:37:03 +02:00
Ollie Agent aca5546ea5 refactor environment utilities and file tools 2026-08-16 18:20:50 +02:00
Ollie Agent 81933e5281 refactor toolsrv into client protocol and metadata packages 2026-08-16 17:22:59 +02:00
Levi Neely dd0021fd9a fix: restore sessions after 9P listener is ready
ConsumeFeed dials the 9P socket. Moving session restore to after
the listener starts ensures the socket exists when feed consumers
connect.
2026-08-13 20:55:02 +02:00
Levi Neely edd5ade471 refactor: simplify bypass - toolsrv is the broker, olliesrv is just a client
- Remove olliesrv's bypass broker machinery (pendingCh, EvaluateRequest, etc)
- Session bypass loop now just reads from toolsrv's bypass/pending and notifies
- Notification handler writes directly to toolsrv's bypass/resolve (fire and forget)
- Remove bypass/ directory from olliesrv's 9P namespace
- Remove session/*/bypass file (policy can be added back to toolsrv later if needed)

The flow is now:
1. toolsrv blocks tool execution, exposes request via bypass/pending
2. olliesrv reads from toolsrv, shows D-Bus notification
3. User clicks approve/deny, olliesrv writes to toolsrv's bypass/resolve
4. toolsrv unblocks and executes (or denies)
2026-08-12 11:01:29 +02:00
Levi Neely 3a68b0be53 Fix bypass broker and stop command
- Wire BypassBroker into fs.Config before creating root tree
- Move defer bypassBroker.Close() outside block scope (was closing immediately)
- Rewrite /bypass/ FS nodes to match toolsrv's expected interface:
  - bypass/pending: blocking read returning JSON {id,cmd,cwd,env}
  - bypass/resolve: write JSON {id,approved,error}
- Add NextPending() method to broker with channel-based blocking
- Add JSON tags to Request struct for proper serialization
- Start bypass loop for restored sessions (was only for new sessions)
- Add context cancellation support to CallTool (closes fid on cancel)
2026-08-12 09:16:59 +02:00
Levi Neely 62a7d0d13f bypass: remove socket-based execution (dead code)
The old bypass broker used a Unix socket to receive requests and
execute commands locally. This was replaced by the 9P-based flow
where toolsrv executes commands after receiving approval from
olliesrv.

Removed:
- acceptLoop, handleConn, executeAndStream, executeWithSudo
- sendFrame, indexOf, socketDir helpers
- SocketPath and Credential config options
- Frame constants (FrameData, FrameExit)
- net.Conn field on Request

The broker now only handles:
- Policy management (global + per-session)
- Request evaluation (EvaluateRequest)
- Rate limiting
- User notification callbacks

Execution happens in toolsrv, not olliesrv.
2026-08-12 08:51:19 +02:00
Levi Neely 1fc051e3bf refactor: move olliesrv and toolsrv packages to cmd/*/internal/
Move server-only packages under their respective cmd directories:

olliesrv:
- agent/ -> cmd/olliesrv/internal/agent/
- backend/ -> cmd/olliesrv/internal/backend/
- bypass/ -> cmd/olliesrv/internal/bypass/
- fs/ -> cmd/olliesrv/internal/fs/
- prompts/ -> cmd/olliesrv/internal/prompts/
- session/ -> cmd/olliesrv/internal/session/

toolsrv:
- Server-only code (exec9p, fs9p, server9p, spec9p, auth9p) -> cmd/toolsrv/
- sandbox/ -> cmd/toolsrv/internal/sandbox/
- Keep shared client code (client9p, spawn, registry, meta) in toolsrv/
- Add toolsrv/types.go for shared types (ToolResult, ToolResultContent)

This enforces package boundaries - code in cmd/*/internal/ cannot be
imported by external packages, while shared code remains importable.
2026-08-10 20:16:44 +02:00
Ollie Agent 74635b8e00 refactor: items 8-10, 12, 13 from code review
- Move parseRetryAfter to backend.go (where it's called)
- Extract paths.RuntimeDir() replacing 3 divergent XDG_RUNTIME_DIR impls
- Rename CodeWhispererBackend → KiroBackend, NewCodeWhisperer → NewKiro
- Export RPCRequest/RPCError/OutputNotification from toolsrv/rpcwire.go
- Factor tools/lsp/cmdutil: Run() and RunCustom() for 7 LSP binaries
2026-08-09 11:32:31 +02:00
Ollie Agent c7aea0db59 rename elevate→bypass throughout
The sandbox escape mechanism is a bypass, not privilege elevation.
The old name caused the agent to confuse it with sudo.

- elevate/ → bypass/ (package, types, tests)
- elevate_notify.go → bypass_notify.go
- Namespace: /elevate → /bypass, session/*/elevate → session/*/bypass
- Tool arg: "elevated" → "bypass"
- Env: OLLIE_ELEVATE_SOCKET → OLLIE_BYPASS_SOCKET
- File: elevate-policy.yaml → bypass-policy.yaml
- All docs, prompts, and scripts updated
2026-08-09 02:22:39 +02:00
Ollie Agent 8152dec075 all: delete dead code, tighten API surface
toolsrv:
- Delete WithOnClose, WithOnEnvSet, SetOnExit (dead Options)
- Delete ListDetached, ListDetachedInfo (only ListDetachedRaw used)
- Delete Execute (dead wrapper)
- Delete CWD, ToolRegistry, SessionID, InjectContent (dead accessors)
- Delete ExecuteInSandbox, ExecuteElevated (zero external callers)
- Delete Summaries, RefreshLoaded from Registry (dead)
- Delete DialSSH (alias for RemoteDial)
- Simplify Dial: takes socket string directly, kill Addr/LocalAddr/SSHAddr
- Rename Server receiver e → s
- Unexport context import (no longer needed in tools.go)

session:
- Delete SaveFuncs, AgentAt, AgentCount, NextUncheckedStep
- Delete SetDisallowTools, SaveAllSessions

env:
- Delete Set, Get, All, Format, managed (dead exports)
- Unexport LoadFile → loadFile

fs:
- Delete HandlerCtx.ToolReg, Skills, SaveFn (never read by handlers)
- Delete Config.MkdirAll, Config.SkillsRegistry (dead plumbing)
- Delete AgentLog: Plan, SetPlan, PrevPrompt, Mu, LogInfo, Remote methods
- Delete unused type aliases (NodeOption, FileTree, FileConfig, etc.)

backend:
- Delete ClosePool, PoolStats (dead), New() (dead)
- Delete kiroTokenExpiringSoon standalone func (dead)
- Unexport SharedTransport/SharedClient → sharedTransport/sharedClient

skills:
- Delete entire package (zero importers; feature works via tool scripts)

agent:
- Delete BroadcastChange (dead duplicate of notifyChange)
- Delete HasHistory, ToolCallCount, CompactionModel, SetCompactionModel
- Unexport SetReply, BuildPreamble, DefaultPromptsDir
2026-08-08 15:51:13 +02:00
Ollie Agent 3b83b9d373 all: delete dead interfaces, kill globalRootState
- agent: delete 'state' interface (one implementation: *History). run()
  now takes *History directly.
- agent: delete 'backendNamer' interface. resolveCompactionModel takes
  backend.Backend directly.
- fs: delete Shutdown/InterruptAll/Lookup wrappers that took *Tree they
  never used. Callers (olliesrv) now call session.* directly.
- fs: delete globalRootState. sessionBindings uses ctx.Root.Data.(*RootState)
  via the HandlerCtx that was always available.
2026-08-08 14:58:47 +02:00
Ollie Agent 1372a6b55b Remove OLLIE_ELEVATE_SOCKET from config: derived from XDG_RUNTIME_DIR convention
- Removed from env.go managed list and defaults map
- main.go and shell.go derive path from XDG_RUNTIME_DIR directly
- main.go sets OLLIE_ELEVATE_SOCKET in process env for subprocesses
2026-08-05 19:43:52 +02:00
Levi Neely 593584a673 Move mount/ package to ollie-9p
FUSE mount is a client-side QoL feature, not a server concern.
Usage: ollie-9p mount <address> [mountpoint]
2026-08-04 16:38:44 +02:00
Levi Neely 66850e822f cleanup: remove dead code from olliesrv
- Remove unused GroupTable.Remove() method, rename Add to Populate
- Remove unused toolPrompt field from Server struct and Config
- Remove unused ModelCache type alias
- Remove unused toolsrv import
- Flatten if true {} blocks (debugging remnants)
- Convert fcallTypeName switch to map lookup
- Remove unused Tree.Unmount() method

-44 lines
2026-08-04 10:19:12 +02:00
Levi Neely 6d902ba7e9 9p: default log level to warn, not debug
The 9P logger was hardcoded to LevelDebug, causing all 9P operations
to print timing info to stdout. This blocked the server on terminal
output, hurting GUI responsiveness.

Now uses NewLogger('9p') which:
- Defaults to the sink's level (warn)
- Can be overridden with OLLIE_9P_LOG=debug

Also updates kde submodule with incremental session tree updates.
2026-08-03 19:52:07 +02:00
Ollie Agent 9af742acd6 fs/lifecycle: fix nil MkdirAll panic blocking agent creation and autoload
The panic at fs/lifecycle.go:463 was a nil function pointer: fs.Config.MkdirAll
is a func field, not a method, and the struct literal in cmd/olliesrv/main.go
omitted it, defaulting to nil. When CreateAgent called
rs.cfg.MkdirAll(...), it panicked before ever reaching the autoload loop.

- Add MkdirAll: os.MkdirAll to fs.Config in main.go
- Spawn tool server in Create() so empty session/new sessions are
  operational, then reuse it in CreateAgent (else if sess.proc != nil)
- Wrap create agent error with fmt.Errorf for clearer messages
- Add panic stack trace to stderr for debugging
2026-08-02 21:16:12 +02:00
Ollie Agent 8fba664f11 cleanup / unify toolsrv bootstrap 2026-08-02 20:08:45 +02:00
Ollie Agent e25157ffcd multiplex toolsrv, wip zero-tool server 2026-08-02 19:18:39 +02:00
Ollie Agent e1e03e50ae Inline handle into Start; rename Serve→Start, Shutdown→Kill
- handle() is gone — the dispatch + panic recovery is inlined into
  the per-request goroutine in Start(). Panic recovery is lifecycle,
  not protocol handling.
- Serve → Start: accepts a connection and runs the 9P loop
- Shutdown → Kill: stops accepting, cancels sessions, waits for
  goroutines to drain.
- 2 methods remain on *Server: Start, Kill. Server is purely lifecycle.
- All 9P protocol handlers are package-level functions.
2026-08-02 16:18:32 +02:00
Ollie Agent 1e126ce76a Replace imperative 9P filesystem with declarative EDSL
The old fs/session/ package (14 files) and cmd/olliesrv/elevate_tree.go
(imperative FileTree implementations) are gone. Replaced by a single
declarative EDSL in fs/spec.go that declares the entire 9P namespace.

cmd/olliesrv/server.go simplified from 1430 to 825 lines:
- Deleted pathType() (110 lines) — tree.Stat() now handles all path resolution
- Deleted isSessionFile(), dirMode(), filePerm() — all from tree's info
- Deleted fsRoute/routes/route/routeDir — single rootTree, no route table
- Deleted elevateTree — EDSL handles /elevate/ in spec.go
- Deleted handleWrite(), readDNS(), helpPath() — dead code
- Deleted all 5 per-fid result fields — EDSL Request handlers manage state
- Deleted all path-based intercepts in read()/write() — entry.RequestRespMode()
- Deleted all path-depth hacks in makeStat() — custom Stat() closures in EDSL
- Deleted all content-length compute logic — info.Size() from tree
- Removed imports: agent, backend, elevate, paths, toolsrv, json

New fs/ package:
- spec.go — single EDSL declaration of the entire namespace
- builder.go — BuildTree() validates and compiles spec into *Tree
- tree.go — configurable FileTree implementation
- fsnode.go — Dir(), Leaf(), TemplateDir(), NodeOption constructors
- agentfiles.go / sessionfiles.go / rootfiles.go / elevatefiles.go
  — handler implementations wired by the EDSL
- lifecycle.go — Create, Kill, Rename, Shutdown, InterruptAll
- persist.go, procfiles.go
- edsl.md — documentation of the EDSL
2026-08-02 15:22:17 +02:00
Ollie Agent fd5b215268 eventwait: redesign as global /eventwait with structured delta events
BREAKING CHANGE: /session/eventwait is removed. Use /eventwait instead.

The old event system had several problems:
1. eventwait lived inside /session/ (per-session) but events are global
2. It returned the entire session index on every event, growing unboundedly
3. No structured event data — consumers couldn't tell WHAT happened

New design:
- Global /eventwait at the root of the 9P namespace
- Events are structured delta lines: '<scope> <action> <path>'
  e.g. 'S new session/foo', 'A kill session/foo/agent/bar'
- Ring buffer capped at 100 events (bounded memory)
- Offset-based blocking reads (consumers track position)
- Per-event granularity: S=new/kill/rename, A=new/kill/rename

Call sites updated:
- Session create → 'S new session/{name}'
- Agent create → 'A new session/{name}/agent/{aid}'
- Session kill → 'A kill ...' per agent + 'S kill session/{name}'
- Session rename → 'S rename session/{old} session/{new}'
- Agent rename → 'A rename session/{name}/agent/{old} ...'

KDE GUI updated to use ollie-9p read /eventwait instead of
plan9port 9p read session/eventwait.
2026-08-02 10:25:33 +02:00
Ollie Agent 937e6aef3b update: agent loop, session persistence, 9P filesystem, server, and remote sandbox 2026-08-01 15:06:49 +02:00
Levi Neely cfa2f49f8c remove no9p flag — 9P is the only interface now
The flag had no remaining purpose after D-Bus removal. 9P listener
is always enabled. The if-true blocks remain for now (cosmetic).
2026-07-31 20:56:52 +02:00
Levi Neely 43d0db520a remove D-Bus adapter from olliesrv
Delete dbus/dbus.go — the entire D-Bus SessionManager service is gone.
No more 150ms poll loop, no more signal emission, no more method handlers.

- Remove ollie/dbus import, nodbus flag, dbusAdapter variable
- Remove OnSessionCreated/Killed/Renamed hooks from Config
- Remove EnableDBus from Config
- Elevation notifications connect to session bus directly (godbus stays
  as a dependency solely for org.freedesktop.Notifications)

All clients now use 9P exclusively. D-Bus is dead.
2026-07-31 20:41:02 +02:00
Ollie Agent 3d65d787a2 elevate: broker credential support for privileged tool execution 2026-07-30 23:37:57 +02:00
Ollie Agent 0cea373207 mount: document purpose and fix misleading comment
Add README.md explaining the network transparency role of the mount
package. Replace 'kept as a convenience' comment with one that explains
why it exists and how it differs from local 9pfuse.
2026-07-30 21:23:25 +02:00
Ollie Agent dd8520abb7 Revert "remove dead mount/ package and olliesrv mount subcommand"
This reverts commit bcfdda26b4.
2026-07-30 21:19:11 +02:00
Ollie Agent bcfdda26b4 remove dead mount/ package and olliesrv mount subcommand
The FUSE-based 9P mount (mount/) was unused — all actual mounting
uses 9pfuse via ollie-remount. Remove the package, the olliesrv mount
subcommand, and the go-fuse dependency.
2026-07-30 21:18:52 +02:00
Ollie Agent 96dc6e442b main.go for olliesrv 2026-07-30 21:14:26 +02:00