Sitelet https://github.com/raysonmeng/agent-bridge/pull/251
Skip to content

feat(local-chat): 显式本地路由 v2,接入 Antigravity(agy) / explicit local routing v2 with Antigravity (agy) - #251

Open
raysonmeng wants to merge 2 commits into
masterfrom
feat/agy-explicit-routing
Open

raysonmeng wants to merge 2 commits into
masterfrom
feat/agy-explicit-routing

Conversation

@raysonmeng

Copy link
Copy Markdown
Owner

⚠️ 本 PR 基于 feat/room-trusted-senders,因此同时包含其提交 8fe303b(房间成员发言默认按本机用户指令注入,--room-untrusted 开启限制模式),该分支尚未单独开 PR。
This PR stacks on feat/room-trusted-senders and therefore also contains 8fe303b (room member chat treated as local-user instructions by default; --room-untrusted for restricted mode), which has no PR of its own yet.

摘要 / Summary

中文

  • Claude、Codex、agy 之间只通过显式 send/reply 通信:必须指定收件人;回复必须带原消息 in_reply_to。daemon 校验后投递到对方原生会话,不再收集或转发普通模型输出。
  • 新增命令:
    • abg agy:保留原生 TUI,默认 --dangerously-skip-permissions,--safe / AGENTBRIDGE_SAFE=1 关闭。
    • abg agy attach:在 agy 终端工具里常驻,入站消息经原生 agentapi send-message 投递。
    • abg chat:--list / --inbox / --from --to --message [--reply-to]。
  • 本地成员上线/下线通知与 online profile(id / sessionId / name / model / modelSource)。
  • 移除隐式转发、marker 路由,以及 on_busy / require_reply / wrap_up / idempotency_key,旧参数显式拒绝;新客户端拒绝旧 daemon(fail-closed)。
  • 设计说明:docs/antigravity.md。

English

  • Claude, Codex and agy exchange business messages only via explicit send/reply with a named recipient; replies must cite the original in_reply_to. The daemon validates and delivers into the recipient's native session; ordinary model output is never collected or forwarded.
  • New commands: abg agy (native TUI, skip-permissions by default, --safe to opt out), abg agy attach (persistent adapter inside agy's terminal tool; inbound via native agentapi), abg chat.
  • Local membership notices and online profiles.
  • Implicit forwarding, marker routing and legacy turn controls removed and explicitly rejected; new clients refuse old daemons.
  • Design notes: docs/antigravity.md.

交叉审查 / Cross review

两轮、每轮 2 个正交视角的独立 reviewer(逻辑/测试 + 安全/集成/文档)。第一轮发现 4 个真实问题并已修复;第二轮两个全新 reviewer 均报告 0 个真实问题。
Two rounds of two orthogonal independent reviewers. Round 1 found 4 real issues (fixed below); round 2 (fresh reviewers) reported 0.

审查修复 / Review fixes:

  1. 拒绝自发自收(sender === recipient)/ reject self-addressed messages.
  2. agy 会话内 abg chat 发送方钉死为 agy:<本会话>,拒绝冒充 user/claude/codex / pin the sender to agy:<session> inside an agy session.
  3. 预算提示不再引导已移除的 wrap_up / steer;相应测试断言按现行规格更新(旧断言要求提示含 wrap_up,与"wrap_up 被拒绝"冲突)/ budget directive no longer advises removed wrap_up/steer; the test assertion was updated to the current spec.
  4. README(中/英)、docs/CODEX-ROOMS.md、docs/TROUBLESHOOTING.md 同步为显式路由描述 / docs synced.

已知信任边界(已写入文档):agy 会话之外,任何持有本 pair control token 的同用户进程都等同本机操作员。
Known trust boundary (documented): outside a native agy session, any same-user process holding the pair control token acts as the local operator.

未阻塞的后续建议 / Non-blocking follow-ups:

  • abg chat --inbox / agentbridge_local_inbox 返回全 pair 回复记录,可按调用方过滤。
  • docs/antigravity.md 示例 pair 名 chat 易与子命令混淆。
  • 目标离线时反复发送会占满 256 个路由名额(10 分钟后释放)。
  • StatusBuffer / multipartyActive 死代码待清理;attachAgy 重连/队列缺测试。

测试 / Test plan

  • bun run typecheck 通过 / passes
  • bun test src/unit-test:1839 pass / 0 fail
  • bun test src:仅 src/integration-test/e2e-cli.test.ts 中 agentbridge kill … 用例失败;在未含本改动的干净 HEAD 上同样失败(既有 flaky,非本 PR 回归)/ only the pre-existing flaky agentbridge kill … e2e cases fail, identically on a clean HEAD
  • bun run verify:plugin-sync 与 plugin 版本检查通过 / bundles in sync, manifests aligned at 0.1.31
  • E2E(手动):同一目录三个终端 abg --pair <p> claude / abg --pair <p> codex --new / abg --pair <p> agy;agy 内批准 abg agy attach 后,abg --pair <p> chat --list 显示 agy:<id> 在线
  • E2E:Claude reply(to="agy", text=…) → agy 原生会话收到带 message_id 的消息;agy 执行 abg chat --from agy --to claude --reply-to <id> --message … → Claude 收到回复
  • E2E:agy 内执行 abg chat --from user --to codex … 被拒绝;自己发给自己被拒绝
  • E2E:旧 daemon + 新客户端 → abg chat 明确报错且不发送、不停止现有会话

🤖 Generated with Claude Code

xianglong.meng and others added 2 commits September 18, 2026 14:22
- 默认模式:房间成员的 chat 发言以 ✅[房间成员指令] 注入 Claude 与 Codex,
  连接时注入成员指令说明;task_completed、进出房间与白板始终为 📨 通报。
- 限制模式:abg <命令> --room-untrusted 或 AGENTBRIDGE_ROOM_UNTRUSTED=1,
  恢复不可信通报与安全前导;仅本机 abg room trust 名单成员的 chat 按指令处理。
- 新增 abg room trust|untrust <roomId> <agentId> 与 abg room trusted [roomId],
  名单保存在 <collab 目录>/room-trust.json(0600),每条事件重新读取,
  读取失败时不信任任何人,写入时不覆盖无法解析的文件。
- 信任依据为 broker 认证后写入的 from.agentId;safeField 清除正文中伪造的
  ✅ 与标记短语;Codex 收件箱按可信属性分批注入,重试保留原属性。
- 同步 CLAUDE_INSTRUCTIONS、abg init 写入的房间规则、CLI 帮助、中英文手册、
  HTML 手册、CODEX-ROOMS.md 与安全模型文档,并重新构建插件包。

升级说明:默认行为由不可信通报改为成员发言即指令;已执行 abg init 的项目
需重新执行 abg init 更新房间规则;运行中的 daemon 需先 abg kill,
--room-untrusted 才会生效。

验证:bun run typecheck 通过;bun test src 1979 pass / 4 fail,失败的
publish.test.ts 1 条与 e2e-cli.test.ts 3 条在 v0.1.31 基线上同样失败;
bun run verify:plugin-sync 通过。两轮独立交叉审查,第 2 轮仅余注释问题,
修复后经主 Agent 核对通过。

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…ing v2 with Antigravity (agy)

中文:
- Claude、Codex、agy 之间只通过显式 send/reply 通信:必须指定收件人,回复必须带原消息 in_reply_to;daemon 校验后投递到对方原生会话,不再收集或转发普通模型输出。
- 新增 `abg agy`(保留原生 TUI,默认 --dangerously-skip-permissions,--safe 关闭)、`abg agy attach`(在 agy 终端工具里常驻,通过原生 agentapi 投递入站消息)、`abg chat`(--list / --inbox / --from --to --message [--reply-to])。
- 本地成员上线/下线通知与 online profile(id/sessionId/name/model/modelSource)。
- 移除旧的隐式转发、marker 路由、on_busy / require_reply / wrap_up / idempotency_key,旧参数显式拒绝;新客户端拒绝旧 daemon(fail-closed)。
- 审查修复:拒绝自发自收;agy 会话内 `abg chat` 发送方钉死为 agy:<本会话>;预算提示不再引导已移除的 wrap_up/steer;README 中英文与 docs 同步为显式路由描述。

English:
- Claude, Codex and agy exchange business messages only via explicit send/reply with a named recipient; replies must cite the original in_reply_to. The daemon validates and delivers into the recipient's native session; ordinary model output is never collected or forwarded.
- Add `abg agy` (native TUI, --dangerously-skip-permissions by default, --safe to opt out), `abg agy attach` (persistent adapter inside agy's terminal tool, inbound via native agentapi) and `abg chat`.
- Local membership notices and online profiles.
- Remove implicit forwarding, marker routing and legacy turn controls (now explicitly rejected); new clients refuse old daemons.
- Review fixes: reject self-addressed messages; pin the sender to agy:<session> inside an agy session; drop wrap_up/steer advice from the budget directive; sync README (en/zh) and docs.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@github-actions

Copy link
Copy Markdown
Contributor

Thanks for the PR! Before we can merge it, please sign our lightweight Contributor License Agreement — it keeps the project able to offer a future commercial edition alongside the open-source one. Reply here with:


I have read the CLA Document and I hereby sign the CLA


xianglong.meng seems not to be a GitHub user. You need a GitHub account to be able to sign the CLA. If you have already a GitHub account, please add the email address used for this commit to your account.
You can retrigger this bot by commenting recheck in this Pull Request. Posted by the CLA Assistant Lite bot.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-30T09:55:18.587692Z e48618b PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: e48618bf0d

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread src/daemon.ts
Comment on lines +675 to +676
const accepted = claude.send({ ...systemMessage("system_local_chat", message +
(canReply ? `\n需要回复时调用 reply(to="${from}", text=回复, in_reply_to="${context.messageId}")。` : ""), "room"), id: context.messageId }, false);

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Keep explicit local messages out of the Room channel

When any Codex or agy request is explicitly addressed to Claude, this hard-codes its source as "room". ClaudeAdapter.pushViaChannel consequently emits user/user_id/source_type as Room/room/room, even though its instructions reserve user="Room" for agents on other machines and say only ✅-prefixed room lines are trusted; this local payload has neither room trust marker. The new Codex→Claude path is therefore presented under the external-room trust boundary instead of as authenticated local collaboration, so Claude can treat the request as untrusted or ignore it. Preserve distinct local attribution, including the actual sender, rather than using "room" here.

Useful? React with 👍 / 👎.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant