Commit Graph

14 Commits

Author SHA1 Message Date
Ollie Agent a4972cd456 Separate chat persistence from live delivery via chat.raw
Streaming partials were appended to log.raw per chunk, each carrying the
full cumulative content, so one response left dozens of partial lines
persisted. GUI clients parsing the snapshot re-rendered the growing block
once per partial (O(N^2)) and replayed all historical partials on every
reconnect, causing intermittent rendering loops.

Partials are no longer persisted: AppendBlock writes only finalized
blocks to log.raw; SetPartial broadcasts the in-flight block without
storing it. New chat.raw StreamRaw file is the authoritative live JSONL
source (finalized history replay, then live deltas); log.raw is a
finalized-only one-shot snapshot. GUI streams chat.raw, never polls
log.raw.
2026-10-10 15:57:48 +02:00
Levi Neely 6cf283044e docs: add chat file to namespace documentation
- AGENTS.md: four views (log.raw, log, chat, block)
- system_prompt.md: add chat to agent file table
- architecture-9p.md: add chat to namespace table
- evolution.md: correct Phase 40 (chat not deleted)
2026-10-09 19:16:20 +02:00
Levi Neely 57c40d541e Migrate chat log to JSONL format
Server changes:
- format/block.go: Block struct with JSONL marshaling, RenderBlock for text
- Deleted format/event.go, format.go, format_test.go (old delimiter format)
- agent/chat.go: Dual logs (rawLog JSONL + textLog rendered text)
- agent/chatlog.go: Streaming via flushPartial/closeBlock, skip internal events
- fs/spec.go: New files log.raw (JSONL), log (text), block (ID lookup)
- Removed chat/chat.raw/chat.search from namespace

GUI changes:
- chatblockmodel: JSONL parsing via QJsonDocument, removed regex state machine
- ollie9pclient: Read from log.raw for replay, removed old streaming code
- Added Context type to block enum, filter context/state/usage from display

Docs updated: AGENTS.md, system_prompt.md, architecture-*.md, scripts/o
2026-10-09 18:52:40 +02:00
Levi Neely d65c06f27b implement namespace-bounded capability model
Per-agent file ownership with Unix permission enforcement:
- Agent directories owned by agent ID (UID), group 'agent' (GID)
- Private files (plan, ctl, fifo): mode 0600 - owner only
- Group-readable (chat, log): mode 0440 - owner + agent group
- World-readable (state, id): mode 0444 - observable by all
- Prompt: mode 0220 - CLI and owner can write

virtfs: fix UID/GID inheritance through nested paths
- Added findChildWithInheritance() to accumulate inherited UID/GID
- Stat now correctly shows agent ID as owner for nested files

server: admin bypass for server owner
- serverAdmin variable captures the Unix user running olliesrv
- Admin bypass includes empty uname, 'admin', or server owner

Documentation updates:
- fs/doc.go: 'The Namespace IS the Security Model'
- registry/doc.go: capability-based tool access
- peer.go: capability-based peer access
- lessons-learned.md: 'Model compliance is not a security boundary'
- architecture-9p.md: per-agent file ownership section

Security evaluation:
- Added experiments/security-eval/ with NERV attack corpus adaptation
- Test scripts for Landlock sandbox validation
- RESULTS.md documenting 0% ASR on hostile operations

This implements the NERV thesis: 'An agent can only access resources
explicitly bound into its namespace.' Enforcement is structural via
file permissions, not behavioral via model compliance.
2026-10-06 17:41:27 +02:00
Levi Neely a90ca6b57c remove unused feed file and observer agent support
The feed file was documented but never used by any frontend
or script. The observer agent pattern was never adopted.

- Remove feed.go, FeedWrite, ConsumeFeed
- Remove WatchFeed constant
- Remove feed file from 9P namespace
- Remove ConsumeFeed goroutine spawns from session
- Update docs (architecture-9p, architecture-ide, architecture, usage)

The event stream now covers real-time observation patterns better.
2026-10-06 12:55:39 +02:00
Levi Neely 86fbc90b43 server: remove statewait file, use event stream instead
The event stream with filtering replaces statewait:
- echo filter | rdwrs event

Removed:
- statewait file from agent namespace
- All non-historical references in docs and code

The state file remains for simple polling reads.
2026-10-06 12:44:02 +02:00
Levi Neely 7e7c29c900 docs: update to reflect event stream pattern over statewait
- AGENTS.md: simplified architecture description
- architecture-9p.md: examples use event stream with filtering
- usage.md: o tui and wiring examples use rdwrs event
2026-10-06 12:40:58 +02:00
Levi Neely f86c8d3cdc docs: update all references from eventwait to event 2026-10-06 12:08:35 +02:00
Ollie Agent d33549eca1 Document one-tool capability bootstrap 2026-08-20 18:31:31 +02:00
Levi Neely 7055444748 agent peers: bidirectional peer links with topology-controlled messaging
Add peer/ directory to each agent's 9P namespace. Agents communicate
by writing to peer/{name}, which delivers to the target's prompt handler.
Only declared peers can be messaged — the directory is the ACL.

Implementation:
- Agent struct: peers map + AddPeer/RemovePeer/Peers methods
- fs/spec.go: peer/ Each node (write-only entries), peeradd/peerdel/peers ctl commands
- Bidirectional: peeradd A on B also adds B on A
- Peers constrained to same session
- Persisted with session state (PersistedAgent.Peers field)
- peeradd/peerdel trigger immediate session save

Docs updated: system_prompt.md, AGENTS.md, README.md, architecture-9p.md,
architecture-core.md, architecture.md, usage.md.
2026-08-19 17:22:30 +02:00
Ollie Agent 2ba9ba036c Document native Landlock and persist session yolo 2026-08-18 12:49:25 +02:00
Levi Neely d279bbae86 Update docs: goals, index split, namespace changes
- README: Add goal/goalstatus/goalwait, fix plan location, add agent/new and agent/idx
- architecture-9p: Add goal files to session namespace, document index formats
- evolution: Add Phase 26 for goals, workflows, and index split
2026-08-17 13:51:04 +02:00
Ollie Agent b9a9fae542 Deduplicate architecture documentation 2026-08-16 19:53:40 +02:00
Ollie Agent 02f130f79e Update 9P architecture documentation 2026-08-16 19:50:35 +02:00