feat(local-chat): 显式本地路由 v2,接入 Antigravity(agy) / explicit local routing v2 with Antigravity (agy) - #251
feat(local-chat): 显式本地路由 v2,接入 Antigravity(agy) / explicit local routing v2 with Antigravity (agy)#251raysonmeng wants to merge 2 commits into
Conversation
- 默认模式:房间成员的 chat 发言以 ✅[房间成员指令] 注入 Claude 与 Codex, 连接时注入成员指令说明;task_completed、进出房间与白板始终为 📨 通报。 - 限制模式:abg <命令> --room-untrusted 或 AGENTBRIDGE_ROOM_UNTRUSTED=1, 恢复不可信通报与安全前导;仅本机 abg room trust 名单成员的 chat 按指令处理。 - 新增 abg room trust|untrust <roomId> <agentId> 与 abg room trusted [roomId], 名单保存在 <collab 目录>/room-trust.json(0600),每条事件重新读取, 读取失败时不信任任何人,写入时不覆盖无法解析的文件。 - 信任依据为 broker 认证后写入的 from.agentId;safeField 清除正文中伪造的 ✅ 与标记短语;Codex 收件箱按可信属性分批注入,重试保留原属性。 - 同步 CLAUDE_INSTRUCTIONS、abg init 写入的房间规则、CLI 帮助、中英文手册、 HTML 手册、CODEX-ROOMS.md 与安全模型文档,并重新构建插件包。 升级说明:默认行为由不可信通报改为成员发言即指令;已执行 abg init 的项目 需重新执行 abg init 更新房间规则;运行中的 daemon 需先 abg kill, --room-untrusted 才会生效。 验证:bun run typecheck 通过;bun test src 1979 pass / 4 fail,失败的 publish.test.ts 1 条与 e2e-cli.test.ts 3 条在 v0.1.31 基线上同样失败; bun run verify:plugin-sync 通过。两轮独立交叉审查,第 2 轮仅余注释问题, 修复后经主 Agent 核对通过。 Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…ing v2 with Antigravity (agy) 中文: - Claude、Codex、agy 之间只通过显式 send/reply 通信:必须指定收件人,回复必须带原消息 in_reply_to;daemon 校验后投递到对方原生会话,不再收集或转发普通模型输出。 - 新增 `abg agy`(保留原生 TUI,默认 --dangerously-skip-permissions,--safe 关闭)、`abg agy attach`(在 agy 终端工具里常驻,通过原生 agentapi 投递入站消息)、`abg chat`(--list / --inbox / --from --to --message [--reply-to])。 - 本地成员上线/下线通知与 online profile(id/sessionId/name/model/modelSource)。 - 移除旧的隐式转发、marker 路由、on_busy / require_reply / wrap_up / idempotency_key,旧参数显式拒绝;新客户端拒绝旧 daemon(fail-closed)。 - 审查修复:拒绝自发自收;agy 会话内 `abg chat` 发送方钉死为 agy:<本会话>;预算提示不再引导已移除的 wrap_up/steer;README 中英文与 docs 同步为显式路由描述。 English: - Claude, Codex and agy exchange business messages only via explicit send/reply with a named recipient; replies must cite the original in_reply_to. The daemon validates and delivers into the recipient's native session; ordinary model output is never collected or forwarded. - Add `abg agy` (native TUI, --dangerously-skip-permissions by default, --safe to opt out), `abg agy attach` (persistent adapter inside agy's terminal tool, inbound via native agentapi) and `abg chat`. - Local membership notices and online profiles. - Remove implicit forwarding, marker routing and legacy turn controls (now explicitly rejected); new clients refuse old daemons. - Review fixes: reject self-addressed messages; pin the sender to agy:<session> inside an agy session; drop wrap_up/steer advice from the budget directive; sync README (en/zh) and docs. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
|
Thanks for the PR! Before we can merge it, please sign our lightweight Contributor License Agreement — it keeps the project able to offer a future commercial edition alongside the open-source one. Reply here with: I have read the CLA Document and I hereby sign the CLA xianglong.meng seems not to be a GitHub user. You need a GitHub account to be able to sign the CLA. If you have already a GitHub account, please add the email address used for this commit to your account. |
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: e48618bf0d
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| const accepted = claude.send({ ...systemMessage("system_local_chat", message + | ||
| (canReply ? `\n需要回复时调用 reply(to="${from}", text=回复, in_reply_to="${context.messageId}")。` : ""), "room"), id: context.messageId }, false); |
There was a problem hiding this comment.
Keep explicit local messages out of the Room channel
When any Codex or agy request is explicitly addressed to Claude, this hard-codes its source as "room". ClaudeAdapter.pushViaChannel consequently emits user/user_id/source_type as Room/room/room, even though its instructions reserve user="Room" for agents on other machines and say only ✅-prefixed room lines are trusted; this local payload has neither room trust marker. The new Codex→Claude path is therefore presented under the external-room trust boundary instead of as authenticated local collaboration, so Claude can treat the request as untrusted or ignore it. Preserve distinct local attribution, including the actual sender, rather than using "room" here.
Useful? React with 👍 / 👎.
摘要 / Summary
中文
in_reply_to。daemon 校验后投递到对方原生会话,不再收集或转发普通模型输出。abg agy:保留原生 TUI,默认--dangerously-skip-permissions,--safe/AGENTBRIDGE_SAFE=1关闭。abg agy attach:在 agy 终端工具里常驻,入站消息经原生agentapi send-message投递。abg chat:--list/--inbox/--from --to --message [--reply-to]。id / sessionId / name / model / modelSource)。on_busy/require_reply/wrap_up/idempotency_key,旧参数显式拒绝;新客户端拒绝旧 daemon(fail-closed)。docs/antigravity.md。English
in_reply_to. The daemon validates and delivers into the recipient's native session; ordinary model output is never collected or forwarded.abg agy(native TUI, skip-permissions by default,--safeto opt out),abg agy attach(persistent adapter inside agy's terminal tool; inbound via native agentapi),abg chat.docs/antigravity.md.交叉审查 / Cross review
两轮、每轮 2 个正交视角的独立 reviewer(逻辑/测试 + 安全/集成/文档)。第一轮发现 4 个真实问题并已修复;第二轮两个全新 reviewer 均报告 0 个真实问题。
Two rounds of two orthogonal independent reviewers. Round 1 found 4 real issues (fixed below); round 2 (fresh reviewers) reported 0.
审查修复 / Review fixes:
sender === recipient)/ reject self-addressed messages.abg chat发送方钉死为agy:<本会话>,拒绝冒充user/claude/codex/ pin the sender toagy:<session>inside an agy session.wrap_up/ steer;相应测试断言按现行规格更新(旧断言要求提示含wrap_up,与"wrap_up被拒绝"冲突)/ budget directive no longer advises removedwrap_up/steer; the test assertion was updated to the current spec.docs/CODEX-ROOMS.md、docs/TROUBLESHOOTING.md同步为显式路由描述 / docs synced.已知信任边界(已写入文档):agy 会话之外,任何持有本 pair control token 的同用户进程都等同本机操作员。
Known trust boundary (documented): outside a native agy session, any same-user process holding the pair control token acts as the local operator.
未阻塞的后续建议 / Non-blocking follow-ups:
abg chat --inbox/agentbridge_local_inbox返回全 pair 回复记录,可按调用方过滤。docs/antigravity.md示例 pair 名chat易与子命令混淆。StatusBuffer/multipartyActive死代码待清理;attachAgy重连/队列缺测试。测试 / Test plan
bun run typecheck通过 / passesbun test src/unit-test:1839 pass / 0 failbun test src:仅src/integration-test/e2e-cli.test.ts中agentbridge kill …用例失败;在未含本改动的干净 HEAD 上同样失败(既有 flaky,非本 PR 回归)/ only the pre-existing flakyagentbridge kill …e2e cases fail, identically on a clean HEADbun run verify:plugin-sync与 plugin 版本检查通过 / bundles in sync, manifests aligned at 0.1.31abg --pair <p> claude/abg --pair <p> codex --new/abg --pair <p> agy;agy 内批准abg agy attach后,abg --pair <p> chat --list显示agy:<id>在线reply(to="agy", text=…)→ agy 原生会话收到带message_id的消息;agy 执行abg chat --from agy --to claude --reply-to <id> --message …→ Claude 收到回复abg chat --from user --to codex …被拒绝;自己发给自己被拒绝abg chat明确报错且不发送、不停止现有会话🤖 Generated with Claude Code