feat(discord): git verbs for the Discord Sage on the shared-signals root, seat identity through a package credential helper, vault record protocol (#1509)
Row 24. A writable root that is a git work tree may carry a git object in the binding; the seat then has git_status, git_commit (explicit paths, seat author, Requested-by trailer from the envelope requester, push at once per D6), git_pull (ff-only) and git_push (one branch, never force), plus reserve_id and per-write clone locks under protocol vault. Git children run with no host config and one credential helper, bin/git-credential.mjs, reading the 0600 seat token file named in the binding; the fleet helper serves only the Gitea hosts. Suite 58/58, node 143. rev-code-02 APPROVED round 1 (#1509 comment 26375, tree 82ab962f). Co-Authored-By: Claude Fable 5.1 <[email protected]>
This commit is contained in:
+27
-1
@@ -25,7 +25,7 @@ echo "toolchain: node $(node --version)"
|
||||
echo
|
||||
|
||||
# --- syntax ---
|
||||
for f in packages/discord/src/*.mjs packages/discord/extension/*.mjs packages/discord/tests/*.mjs packages/discord/fixtures/*.mjs scripts/discord.sh scripts/discord-service.sh; do
|
||||
for f in packages/discord/src/*.mjs packages/discord/bin/*.mjs packages/discord/extension/*.mjs packages/discord/tests/*.mjs packages/discord/fixtures/*.mjs scripts/discord.sh scripts/discord-service.sh; do
|
||||
case "$f" in
|
||||
*.sh) bash -n "$f" >/dev/null 2>&1 ;;
|
||||
*) node --check "$f" >/dev/null 2>&1 ;;
|
||||
@@ -91,6 +91,32 @@ if [ -x "$PI_BIN" ]; then
|
||||
>"$SANDBOX/pi-web.out" 2>"$SANDBOX/pi-web.err"
|
||||
grep -qxF 'PROBE ["list_dir","read_file","search","web_fetch","web_search"]' "$SANDBOX/pi-web.err" && grep -q '"command":"get_state","success":true' "$SANDBOX/pi-web.out"
|
||||
check "real pi with a web key exposes the three reads plus web_fetch and web_search, and no write tool without a writable root" $?
|
||||
# A git root (row 24): a sandbox work tree with an origin, a 0600 token
|
||||
# file whose content is shaped nothing like a real token.
|
||||
GITROOT="$SANDBOX/gitroot"
|
||||
git init -q -b main "$GITROOT" && git -C "$GITROOT" -c user.name=t -c user.email=t@t commit -q --allow-empty -m init
|
||||
git init -q --bare -b main "$SANDBOX/gitremote.git" && git -C "$GITROOT" remote add origin "$SANDBOX/gitremote.git"
|
||||
printf 'not_a_real_token_just_a_test_value_x\n' >"$SANDBOX/gittoken" && chmod 0600 "$SANDBOX/gittoken"
|
||||
GIT_JSON="{\"branch\":\"main\",\"identity\":\"sage\",\"tokenFile\":\"$SANDBOX/gittoken\",\"author\":\"Sage <[email protected]>\"}"
|
||||
TOOLS_GIT="{\"roots\":[{\"name\":\"docs\",\"path\":\"$SANDBOX/toolroot\"},{\"name\":\"ss\",\"path\":\"$GITROOT\",\"write\":true,\"git\":$GIT_JSON}],\"maxFileBytes\":4096,\"maxCallsPerTurn\":8}"
|
||||
printf '{"type":"get_state","id":"a"}\n' | MOSAIC_DISCORD_TOOLS="$TOOLS_GIT" timeout 60 "$PI_BIN" $PI_COMMON --no-builtin-tools \
|
||||
--extension "$EXT_DIR/tools.mjs" --extension "$PROBE" --tools list_dir,read_file,search,write_file,edit_file,git_status,git_commit,git_pull,git_push \
|
||||
>"$SANDBOX/pi-git.out" 2>"$SANDBOX/pi-git.err"
|
||||
grep -qxF 'PROBE ["edit_file","git_commit","git_pull","git_push","git_status","list_dir","read_file","search","write_file"]' "$SANDBOX/pi-git.err" && grep -q '"command":"get_state","success":true' "$SANDBOX/pi-git.out" && [ "$(git -C "$GITROOT" rev-list --count HEAD)" = "1" ] && ! grep -rq 'not_a_real_token' "$SANDBOX/pi-git.out" "$SANDBOX/pi-git.err"
|
||||
check "real pi with a git root exposes the reads, writes and the four git verbs, commits nothing at start, and never shows the token" $?
|
||||
TOOLS_VAULT="{\"roots\":[{\"name\":\"ss\",\"path\":\"$GITROOT\",\"write\":true,\"git\":${GIT_JSON%\}},\"protocol\":\"vault\"}}],\"maxFileBytes\":4096,\"maxCallsPerTurn\":8}"
|
||||
printf '{"type":"get_state","id":"a"}\n' | MOSAIC_DISCORD_TOOLS="$TOOLS_VAULT" timeout 60 "$PI_BIN" $PI_COMMON --no-builtin-tools \
|
||||
--extension "$EXT_DIR/tools.mjs" --extension "$PROBE" --tools list_dir,read_file,search,write_file,edit_file,git_status,git_commit,git_pull,git_push,reserve_id \
|
||||
>"$SANDBOX/pi-vault.out" 2>"$SANDBOX/pi-vault.err"
|
||||
grep -qxF 'PROBE ["edit_file","git_commit","git_pull","git_push","git_status","list_dir","read_file","reserve_id","search","write_file"]' "$SANDBOX/pi-vault.err" && grep -q '"command":"get_state","success":true' "$SANDBOX/pi-vault.out"
|
||||
check "real pi with protocol vault adds reserve_id to the git verbs" $?
|
||||
TOOLS_GIT_RO="{\"roots\":[{\"name\":\"ss\",\"path\":\"$GITROOT\",\"git\":$GIT_JSON}],\"maxFileBytes\":4096,\"maxCallsPerTurn\":8}"
|
||||
printf '{"type":"get_state","id":"a"}\n' | MOSAIC_DISCORD_TOOLS="$TOOLS_GIT_RO" timeout 60 "$PI_BIN" $PI_COMMON --no-builtin-tools \
|
||||
--extension "$EXT_DIR/tools.mjs" --extension "$PROBE" --tools list_dir,read_file,search \
|
||||
>"$SANDBOX/pi-gitro.out" 2>"$SANDBOX/pi-gitro.err"
|
||||
GITRO_RC=$?
|
||||
[ "$GITRO_RC" -ne 0 ] && grep -q 'git needs write: true' "$SANDBOX/pi-gitro.err" && ! grep -q 'PROBE' "$SANDBOX/pi-gitro.err"
|
||||
check "real pi refuses a git key on a read-only root (fail closed)" $?
|
||||
printf '{"type":"get_state","id":"a"}\n' | timeout 60 "$PI_BIN" $PI_COMMON --no-tools --extension "$PROBE" \
|
||||
>"$SANDBOX/pi-notools.out" 2>"$SANDBOX/pi-notools.err"
|
||||
grep -qxF 'PROBE []' "$SANDBOX/pi-notools.err"
|
||||
|
||||
Reference in New Issue
Block a user