Some checks failed
ci/woodpecker/pr/ci Pipeline failed
Invert the delivery verdict from negative to positive evidence. Previously, success was declared by the ABSENCE of a draft snippet on a prompt line: if the `❯|^>|│ >` glyph matched nothing (busy-receiver draft on an unmatched line, or wrong-pane drift), an UNSUBMITTED message read as "✓ delivered" exit 0 — a silent worker->lead relay stall (filed by UC-LEAD, PR #3046: three review verdicts reported delivered but never surfaced for ~50 min). Fix: success now requires POSITIVE evidence — either the queued banner, or the REPL input box located AND clear of the message tail. If the input box cannot be located, status is `unconfirmed` -> exit 2 + stderr ("could not confirm submission ... may be UNDELIVERED"). The near-dead `*)` indeterminate default also flips from silently returning 0 to exit 2. Bracketed-paste and double-Enter delivery mechanics are unchanged; queued/draft/delivered semantics are preserved, only the failure-mode default direction changes. Adds `test-send-message-verdict.sh`: 3 real tmux-pane fixtures (delivered / unconfirmed-glyphless / draft) locking the fail-loud verdict logic, and upgrades `test-send-message-socket.sh` fixtures from a glyphless bash prompt to `❯`-prompt REPLs so the patched binary can read delivery positively. Reproduce-first evidence (baseline vs patched, glyphless-pane fixture): baseline: rc=0, stdout "✓ delivered to =noglyph" (silent false positive) patched: rc=2, stderr "could not confirm submission ... may be UNDELIVERED" Test results after port: test-send-message-verdict.sh -> PASS=3 FAIL=0 test-send-message-socket.sh -> ok Firewall: grep -niE 'jason|woltje|jarvis' on changed files = 0 hits; tools/quality/scripts/verify-sanitized.sh -> sanitization gate passed. shellcheck: 1 pre-existing SC2034 finding (unused loop var `attempt`, present identically in baseline) carried through; 0 new findings. Part of #891
141 lines
7.1 KiB
Bash
Executable File
141 lines
7.1 KiB
Bash
Executable File
#!/usr/bin/env bash
|
||
# send-message.sh — reliably deliver a message to a tmux pane running an
|
||
# interactive REPL (e.g. a Claude Code / Codex agent).
|
||
#
|
||
# WHY THIS EXISTS
|
||
# Pasting multi-line text into an interactive agent REPL via `tmux send-keys`
|
||
# is unreliable: the text lands in the input box but a single trailing Enter
|
||
# in the same keystroke stream is frequently swallowed, so the message sits as
|
||
# an UNSUBMITTED DRAFT ("Press up to edit queued messages") and the agent never
|
||
# sees it. The mechanical fix is: paste as a bracketed paste (so embedded
|
||
# newlines don't submit early), pause, then send Enter as its OWN keystroke,
|
||
# pause, and send Enter again to flush. An extra Enter on an empty prompt is a
|
||
# no-op in Claude Code, so the double-Enter is safe.
|
||
#
|
||
# USAGE
|
||
# send-message.sh [-L socket_name] -t <target> -m "message"
|
||
# send-message.sh [-L socket_name] -t <target> -f <file>
|
||
# echo "message" | send-message.sh [-L socket_name] -t <target>
|
||
# ssh host bash -s -- -L socket -t <target> -b "$(base64 -w0 <<<msg)" < send-message.sh
|
||
#
|
||
# OPTIONS
|
||
# -L NAME tmux socket name passed to `tmux -L NAME` (optional)
|
||
# -t TARGET tmux target: session, or session:window.pane [required]
|
||
# -m MESSAGE message text (single- or multi-line)
|
||
# -f FILE read message from FILE instead of -m
|
||
# -b BASE64 message as base64 (ssh-safe transport; decoded internally)
|
||
# -r N Enter-flush attempts (default 2)
|
||
# -v verbose: print a short tail of the pane after delivery
|
||
# -h help
|
||
#
|
||
# EXIT CODES
|
||
# 0 delivered (submitted) or queued (agent busy; will process when free)
|
||
# 1 tmux target not found
|
||
# 2 submission NOT confirmed — either still an unsubmitted draft, or the REPL
|
||
# input prompt could not be located to confirm the message actually landed.
|
||
# Delivery is NEVER inferred from absence of evidence: if we cannot positively
|
||
# see the input box clear of the message (or the queued banner), we fail loud
|
||
# so the sender learns immediately instead of a silent worker->lead stall.
|
||
# 3 usage error
|
||
set -uo pipefail
|
||
|
||
SOCKET_NAME=""; TARGET=""; MSG=""; FILE=""; B64=""; RETRIES=2; VERBOSE=0
|
||
usage() { sed -n '2,34p' "$0"; exit "${1:-3}"; }
|
||
|
||
while getopts "L:t:m:f:b:r:vh" o; do
|
||
case "$o" in
|
||
L) SOCKET_NAME=$OPTARG ;;
|
||
t) TARGET=$OPTARG ;; m) MSG=$OPTARG ;; f) FILE=$OPTARG ;; b) B64=$OPTARG ;;
|
||
r) RETRIES=$OPTARG ;; v) VERBOSE=1 ;; h) usage 0 ;; *) usage 3 ;;
|
||
esac
|
||
done
|
||
|
||
[ -n "$TARGET" ] || { echo "ERROR: -t TARGET is required" >&2; usage 3; }
|
||
if [ -n "$B64" ]; then MSG=$(printf '%s' "$B64" | base64 -d) || { echo "ERROR: bad -b base64" >&2; exit 3; }
|
||
elif [ -n "$FILE" ]; then [ -r "$FILE" ] || { echo "ERROR: cannot read $FILE" >&2; exit 3; }; MSG=$(cat -- "$FILE")
|
||
elif [ -z "$MSG" ] && [ ! -t 0 ]; then MSG=$(cat)
|
||
fi
|
||
[ -n "$MSG" ] || { echo "ERROR: empty message (use -m, -f, or stdin)" >&2; exit 3; }
|
||
|
||
tmux_cmd=(tmux)
|
||
if [ -n "$SOCKET_NAME" ]; then
|
||
tmux_cmd+=(-L "$SOCKET_NAME")
|
||
fi
|
||
|
||
# tmux accepts `=session` for some commands, but pane-level commands such as
|
||
# capture-pane require a pane-qualified target. Keep exact-session addressing
|
||
# convenient while avoiding accidental prefix matches.
|
||
EFFECTIVE_TARGET=$TARGET
|
||
if [[ "$TARGET" == =* && "$TARGET" != *:* ]]; then
|
||
EFFECTIVE_TARGET="${TARGET}:0.0"
|
||
fi
|
||
|
||
# Target must resolve to a live pane.
|
||
if ! "${tmux_cmd[@]}" list-panes -t "$EFFECTIVE_TARGET" >/dev/null 2>&1; then
|
||
echo "ERROR: tmux target not found: $TARGET" >&2; exit 1
|
||
fi
|
||
|
||
QUEUED_RE='Press up to edit queued messages'
|
||
# A distinctive tail of the message to spot an unsubmitted draft on the input line.
|
||
snippet=$(printf '%s' "$MSG" | tr '\n' ' ' | tr -s ' ' | sed 's/[^[:print:]]//g' | tail -c 32)
|
||
|
||
# 1) Paste the body as a bracketed paste so multi-line content does not submit
|
||
# line-by-line. load-buffer/paste-buffer is far safer than `send-keys -l`.
|
||
# Buffer name MUST be unique per invocation: concurrent senders on the shared
|
||
# tmux server race a fixed name (load overwrites load, -d deletes underneath),
|
||
# cross-delivering or dropping messages — bit the fleet on the 2026-07-09
|
||
# simultaneous restart (briefs swapped between sessions).
|
||
BUF="__mosaic_send_$$_$(date +%s%N)"
|
||
printf '%s' "$MSG" | "${tmux_cmd[@]}" load-buffer -b "$BUF" -
|
||
# -p = bracketed paste when the client supports it; fall back if not.
|
||
"${tmux_cmd[@]}" paste-buffer -d -p -b "$BUF" -t "$EFFECTIVE_TARGET" 2>/dev/null \
|
||
|| "${tmux_cmd[@]}" paste-buffer -d -b "$BUF" -t "$EFFECTIVE_TARGET" \
|
||
|| "${tmux_cmd[@]}" delete-buffer -b "$BUF" 2>/dev/null
|
||
# ^ -d deletes the buffer only on a SUCCESSFUL paste; if both attempts fail
|
||
# (e.g. the target vanished since the liveness check), delete explicitly —
|
||
# named buffers are exempt from tmux's buffer-limit eviction, so orphans
|
||
# would otherwise accumulate forever.
|
||
sleep 0.5
|
||
|
||
# 2) Submit, then POSITIVELY confirm submission; flush with another Enter if it is
|
||
# still a draft. Success requires positive evidence — the queued banner, OR the
|
||
# REPL input box located AND clear of our message tail. The historical bug was
|
||
# treating ABSENCE of a draft as delivery: if the prompt glyph was never matched
|
||
# (wrong pane / prompt-glyph drift), an unsubmitted message read as "delivered"
|
||
# and worker->lead relays stalled silently. We now default to UNCONFIRMED and only
|
||
# upgrade to delivered on positive evidence; anything we cannot confirm fails loud.
|
||
status="unconfirmed"
|
||
for attempt in $(seq 1 $((RETRIES + 1))); do
|
||
"${tmux_cmd[@]}" send-keys -t "$EFFECTIVE_TARGET" Enter
|
||
sleep 1.2
|
||
pane=$("${tmux_cmd[@]}" capture-pane -t "$EFFECTIVE_TARGET" -p 2>/dev/null)
|
||
|
||
if printf '%s' "$pane" | grep -qF "$QUEUED_RE"; then
|
||
status="queued"; break
|
||
fi
|
||
# Locate the REPL input box (prompt glyph). If we cannot see it, we have NO
|
||
# evidence of submission state — stay UNCONFIRMED and retry; never infer delivery.
|
||
promptline=$(printf '%s' "$pane" | grep -E '❯|^>|│ >' | tail -1)
|
||
if [ -z "$promptline" ]; then
|
||
status="unconfirmed"; continue
|
||
fi
|
||
# Input box located AND still carrying our tail => unsubmitted draft. Flush + retry.
|
||
# (Submitted messages scroll up into history; a draft stays on the ❯ line.)
|
||
if [ -n "$snippet" ] && printf '%s' "$promptline" | grep -qF "$snippet"; then
|
||
status="draft"; continue
|
||
fi
|
||
# Input box located AND clear of our tail => positively submitted. This is the
|
||
# only path to success besides the queued banner.
|
||
status="delivered"; break
|
||
done
|
||
|
||
[ "$VERBOSE" = 1 ] && { echo "--- pane tail ($TARGET) ---"; printf '%s\n' "$pane" | tail -4; echo "---"; }
|
||
|
||
case "$status" in
|
||
delivered) echo "✓ delivered to $TARGET"; exit 0 ;;
|
||
queued) echo "✓ queued to $TARGET (agent busy — will process when it returns to prompt)"; exit 0 ;;
|
||
draft) echo "✗ still an unsubmitted draft on $TARGET after $RETRIES flush attempts" >&2; exit 2 ;;
|
||
unconfirmed) echo "✗ could not confirm submission on $TARGET: REPL input prompt not locatable after $((RETRIES + 1)) attempts — message may be UNDELIVERED (check target/pane, retry, or escalate)" >&2; exit 2 ;;
|
||
*) echo "✗ could not confirm submission on $TARGET (unexpected state '$status')" >&2; exit 2 ;;
|
||
esac
|