Compare commits

...

5 Commits

Author SHA1 Message Date
will.anderson dcf050ee3c fix(agentic): workspace root security — edit_file scoping, trailing-slash normalization, conditional state_set
Neuron Soul CI / build (pull_request) Has been cancelled
2026-06-22 11:46:44 -05:00
Tim Lingo 1b83b18c39 propose(agentic): read agent_workspace_root from request body and persist to state
Neuron Soul CI / build (pull_request) Successful in 7m45s
Completes the UI<->soul contract for #23 (scope file/command tools to an agent
workspace root). #23 made the tools read state_get("agent_workspace_root"), but
nothing set that key from the desktop UI, so the agent panel's Workspace Folder
was cosmetic and tools ran unscoped (default-allow). This reads the root the UI
now sends on each agentic request and state_sets it before tool dispatch, so
agent_workspace_root() picks it up for the turn.

Minimal + pattern-matching (same json_get/state_set shape used throughout chat.el).
Empty body field => unscoped (backward-compatible) and preserves the env fallback.

FOR WILL'S REVIEW — do not merge without sign-off:
- Ownership model: set state from body each turn (so clearing the folder un-scopes)
  vs. only-when-nonempty. Flagged inline.
- Pairs with neuron-ui PR #32 (ChatRequest.agentWorkspaceRoot).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-19 19:56:20 -05:00
will.anderson ddd858d2ec fix(deploy): extend rollout timeout to 8m for GKE Autopilot cold starts
Neuron Soul CI / build (push) Has been cancelled
Deploy Soul to GKE / deploy (push) Failing after 5m48s
2026-06-19 15:35:34 -05:00
will.anderson 996dd3860a fix: replace embedded python with sed in deploy-gke manifest update step
Neuron Soul CI / build (push) Successful in 7m6s
Deploy Soul to GKE / deploy (push) Failing after 8m11s
2026-06-19 15:25:22 -05:00
will.anderson 6f4adf7640 self-review 2026-06-19: filter auto_term to Memory/BacklogItem/Entity only
Knowledge nodes dominated the WM-autobiographical auto_term slot:
'Numeric tier strings...' (a Knowledge node) always scored highest
in WM and its first word 'Numeric' became the curiosity seed every
scan — activating more Numeric nodes, keeping that node in WM,
repeating indefinitely.

Fix: only derive auto_term from Memory, BacklogItem, or Entity nodes.
Knowledge nodes are reference material, not live context. Dynamic/
personal nodes carry the salience worth radiating from.

Also patches proactive_curiosity directly in dist/neuron.c (ELC
cannot compile soul.el within timeout — fallback build pattern).
2026-06-19 08:49:42 -05:00
5 changed files with 121 additions and 37 deletions
+5 -18
View File
@@ -214,23 +214,10 @@ jobs:
cd /tmp/infra-update cd /tmp/infra-update
DEPLOY_DIR="platform/k8s/neuron-mcp" DEPLOY_DIR="platform/k8s/neuron-mcp"
python3 -c " sed -i "s/^ replicas: .*/ replicas: 1/" "${DEPLOY_DIR}/deployment-${SLOT}.yaml"
import re, sys sed -i "s/^ replicas: .*/ replicas: 0/" "${DEPLOY_DIR}/deployment-${IDLE}.yaml"
echo " deployment-${SLOT}.yaml: replicas set to 1"
slot = sys.argv[1] echo " deployment-${IDLE}.yaml: replicas set to 0"
idle = sys.argv[2]
def set_replicas(path, count):
with open(path) as f:
content = f.read()
content = re.sub(r'^( replicas: )\d+', r'\g<1>' + str(count), content, count=1, flags=re.MULTILINE)
with open(path, 'w') as f:
f.write(content)
print(f' {path}: replicas set to {count}')
set_replicas(f'{DEPLOY_DIR}/deployment-{slot}.yaml', 1)
set_replicas(f'{DEPLOY_DIR}/deployment-{idle}.yaml', 0)
" "$SLOT" "$IDLE"
git config user.email "ci@neurontechnologies.ai" git config user.email "ci@neurontechnologies.ai"
git config user.name "Neuron CI" git config user.name "Neuron CI"
@@ -246,7 +233,7 @@ set_replicas(f'{DEPLOY_DIR}/deployment-{idle}.yaml', 0)
echo "Verifying neuron-mcp-${SLOT} is healthy..." echo "Verifying neuron-mcp-${SLOT} is healthy..."
kubectl rollout status deployment/"neuron-mcp-${SLOT}" \ kubectl rollout status deployment/"neuron-mcp-${SLOT}" \
--namespace=neuron-prod \ --namespace=neuron-prod \
--timeout=3m --timeout=8m
echo "Active service endpoints:" echo "Active service endpoints:"
kubectl get endpoints neuron-mcp -n neuron-prod kubectl get endpoints neuron-mcp -n neuron-prod
+22 -5
View File
@@ -219,15 +219,32 @@ fn proactive_curiosity() -> Bool {
// str_find_chars finds the first space/colon/bracket delimiter. sp > 3 guards against // str_find_chars finds the first space/colon/bracket delimiter. sp > 3 guards against
// very short or bracket-prefixed labels like "[BacklogItem]" (sp=0, not > 3 → skipped). // very short or bracket-prefixed labels like "[BacklogItem]" (sp=0, not > 3 → skipped).
// EL scoping: state_set/state_get pattern used because let inside if creates inner scope. // EL scoping: state_set/state_get pattern used because let inside if creates inner scope.
// (2026-06-11 self-review) //
// NODE TYPE FILTER (2026-06-19 self-review): only derive auto_term from Memory,
// BacklogItem, or Entity nodes. Knowledge nodes are stable reference material —
// using their first word as a curiosity seed creates a self-reinforcing loop: e.g.
// "Numeric tier strings in Engram..." (a Knowledge node) -> auto_term="Numeric" ->
// activates all "Numeric" nodes -> keeps that Knowledge node dominant in WM forever.
// Knowledge nodes should be REACHED by curiosity seeds, not drive them. Only dynamic
// personal/work nodes (Memory, BacklogItem, Entity) carry live contextual salience
// worth radiating from. (2026-06-11 origin; filter added 2026-06-19 self-review)
state_set("cseed_auto", "") state_set("cseed_auto", "")
let wm_top_j: String = engram_wm_top_json(1) let wm_top_j: String = engram_wm_top_json(1)
let wm_top_n: String = json_array_get(wm_top_j, 0) let wm_top_n: String = json_array_get(wm_top_j, 0)
let wm_top_lbl: String = json_get(wm_top_n, "label") let wm_top_lbl: String = json_get(wm_top_n, "label")
if !str_eq(wm_top_lbl, "") { let wm_top_type: String = json_get(wm_top_n, "node_type")
let sp: Int = str_find_chars(wm_top_lbl, " :([") // state_set/state_get pattern: EL let-inside-if creates inner scope only.
if sp > 3 { state_set("allow_auto", "0")
state_set("cseed_auto", str_slice(wm_top_lbl, 0, sp)) if str_eq(wm_top_type, "Memory") { state_set("allow_auto", "1") }
if str_eq(wm_top_type, "BacklogItem") { state_set("allow_auto", "1") }
if str_eq(wm_top_type, "Entity") { state_set("allow_auto", "1") }
let allow_auto: String = state_get("allow_auto")
if str_eq(allow_auto, "1") {
if !str_eq(wm_top_lbl, "") {
let sp: Int = str_find_chars(wm_top_lbl, " :([")
if sp > 3 {
state_set("cseed_auto", str_slice(wm_top_lbl, 0, sp))
}
} }
} }
let auto_term: String = state_get("cseed_auto") let auto_term: String = state_get("cseed_auto")
+20 -3
View File
@@ -418,7 +418,8 @@ fn path_within_root(path: String, root: String) -> Bool {
return false return false
} }
if str_starts_with(path, "/") { if str_starts_with(path, "/") {
return str_starts_with(path, root) let root_normalized: String = root + "/"
return str_starts_with(path, root_normalized)
} }
return true return true
} }
@@ -509,12 +510,17 @@ fn dispatch_tool(tool_name: String, tool_input: String) -> String {
let path: String = json_get(tool_input, "path") let path: String = json_get(tool_input, "path")
let old_text: String = json_get(tool_input, "old_text") let old_text: String = json_get(tool_input, "old_text")
let new_text: String = json_get(tool_input, "new_text") let new_text: String = json_get(tool_input, "new_text")
let content: String = fs_read(path) let root: String = agent_workspace_root()
if !path_within_root(path, root) {
return json_safe("denied: path is outside the agent workspace root")
}
let resolved: String = resolve_in_root(path, root)
let content: String = fs_read(resolved)
if str_eq(content, "") { if str_eq(content, "") {
return json_safe("{\"error\":\"file not found\"}") return json_safe("{\"error\":\"file not found\"}")
} }
let updated: String = str_replace(content, old_text, new_text) let updated: String = str_replace(content, old_text, new_text)
fs_write(path, updated) fs_write(resolved, updated)
return json_safe("{\"ok\":true}") return json_safe("{\"ok\":true}")
} }
if str_eq(tool_name, "remember") { if str_eq(tool_name, "remember") {
@@ -631,6 +637,17 @@ fn handle_chat_agentic(body: String) -> String {
return "{\"error\":\"message required\",\"reply\":\"\"}" return "{\"error\":\"message required\",\"reply\":\"\"}"
} }
// Workspace scope (#23): the desktop UI sends the user-chosen Agent Workspace root
// on every agentic request. Persist it to state so agent_workspace_root() and the
// path/command tool guards that read it confine this turn's file/command tools to
// that subtree. Only set when non-empty: an empty/absent field means the client sent
// no root (or cleared the field), and we must not overwrite a server-configured root
// from NEURON_AGENT_ROOT with an empty string, which would silently un-scope the agent.
let ws_root: String = json_get(body, "agent_workspace_root")
if !str_eq(ws_root, "") {
state_set("agent_workspace_root", ws_root)
}
let req_model: String = json_get(body, "model") let req_model: String = json_get(body, "model")
let model: String = if str_eq(req_model, "") { chat_default_model() } else { req_model } let model: String = if str_eq(req_model, "") { chat_default_model() } else { req_model }
Generated Vendored
+18 -4
View File
@@ -285,10 +285,24 @@ el_val_t proactive_curiosity(void) {
el_val_t wm_top_j = engram_wm_top_json(1); el_val_t wm_top_j = engram_wm_top_json(1);
el_val_t wm_top_n = json_array_get(wm_top_j, 0); el_val_t wm_top_n = json_array_get(wm_top_j, 0);
el_val_t wm_top_lbl = json_get(wm_top_n, EL_STR("label")); el_val_t wm_top_lbl = json_get(wm_top_n, EL_STR("label"));
if (!str_eq(wm_top_lbl, EL_STR(""))) { el_val_t wm_top_type = json_get(wm_top_n, EL_STR("node_type"));
el_val_t sp = str_find_chars(wm_top_lbl, EL_STR(" :([")); state_set(EL_STR("allow_auto"), EL_STR("0"));
if (sp > 3) { if (str_eq(wm_top_type, EL_STR("Memory"))) {
state_set(EL_STR("cseed_auto"), str_slice(wm_top_lbl, 0, sp)); state_set(EL_STR("allow_auto"), EL_STR("1"));
}
if (str_eq(wm_top_type, EL_STR("BacklogItem"))) {
state_set(EL_STR("allow_auto"), EL_STR("1"));
}
if (str_eq(wm_top_type, EL_STR("Entity"))) {
state_set(EL_STR("allow_auto"), EL_STR("1"));
}
el_val_t allow_auto = state_get(EL_STR("allow_auto"));
if (str_eq(allow_auto, EL_STR("1"))) {
if (!str_eq(wm_top_lbl, EL_STR(""))) {
el_val_t sp = str_find_chars(wm_top_lbl, EL_STR(" :(["));
if (sp > 3) {
state_set(EL_STR("cseed_auto"), str_slice(wm_top_lbl, 0, sp));
}
} }
} }
el_val_t auto_term = state_get(EL_STR("cseed_auto")); el_val_t auto_term = state_get(EL_STR("cseed_auto"));
Generated Vendored
+56 -7
View File
@@ -1042,12 +1042,36 @@ el_val_t call_neuron_mcp(el_val_t tool_name, el_val_t args_json);
el_val_t agentic_tools_literal(void); el_val_t agentic_tools_literal(void);
el_val_t agentic_tools_with_web(void); el_val_t agentic_tools_with_web(void);
el_val_t dispatch_tool(el_val_t tool_name, el_val_t tool_input); el_val_t dispatch_tool(el_val_t tool_name, el_val_t tool_input);
el_val_t json_array_append(el_val_t arr, el_val_t item);
el_val_t append_tool_log(el_val_t log, el_val_t name);
el_val_t exec_tool_block(el_val_t block);
el_val_t agentic_blob(el_val_t model, el_val_t system, el_val_t tools_json, el_val_t messages, el_val_t origin, el_val_t approval, el_val_t iteration, el_val_t tools_log, el_val_t content, el_val_t queue, el_val_t results, el_val_t next);
el_val_t extract_all_text(el_val_t s);
el_val_t strip_citations(el_val_t s);
el_val_t agentic_api_turn(el_val_t model, el_val_t safe_sys, el_val_t tools_json, el_val_t messages);
el_val_t agentic_engine(el_val_t session_id, el_val_t blob);
el_val_t handle_chat_agentic(el_val_t body); el_val_t handle_chat_agentic(el_val_t body);
el_val_t handle_session_approve(el_val_t session_id, el_val_t body);
el_val_t handle_chat_as_soul(el_val_t body); el_val_t handle_chat_as_soul(el_val_t body);
el_val_t handle_dharma_room_turn(el_val_t body); el_val_t handle_dharma_room_turn(el_val_t body);
el_val_t handle_dharma_room_turn_agentic(el_val_t body); el_val_t handle_dharma_room_turn_agentic(el_val_t body);
el_val_t auto_persist(el_val_t req, el_val_t resp); el_val_t auto_persist(el_val_t req, el_val_t resp);
el_val_t strengthen_chat_nodes(el_val_t activation_nodes); el_val_t strengthen_chat_nodes(el_val_t activation_nodes);
el_val_t safety_self_harm_phrases(void);
el_val_t safety_abuse_phrases(void);
el_val_t safety_general_hard_phrases(void);
el_val_t safety_soft_phrases(void);
el_val_t safety_normalize(el_val_t message);
el_val_t safety_any_match(el_val_t text, el_val_t phrases_json);
el_val_t safety_count_match(el_val_t text, el_val_t phrases_json);
el_val_t safety_detect_bell_level(el_val_t message);
el_val_t safety_classify_hard_bell(el_val_t message);
el_val_t safety_soft_directive(void);
el_val_t safety_hard_directive(el_val_t hard_type);
el_val_t safety_augment_system(el_val_t system, el_val_t user_msg);
el_val_t safety_contact_path(void);
el_val_t handle_safety_contact_get(void);
el_val_t handle_safety_contact_post(el_val_t body);
el_val_t auth_headers(el_val_t tok); el_val_t auth_headers(el_val_t tok);
el_val_t axon_get(el_val_t path); el_val_t axon_get(el_val_t path);
el_val_t axon_post(el_val_t path, el_val_t body); el_val_t axon_post(el_val_t path, el_val_t body);
@@ -1110,6 +1134,7 @@ el_val_t session_update_meta_timestamp(el_val_t session_id);
el_val_t session_auto_title(el_val_t session_id, el_val_t first_message); el_val_t session_auto_title(el_val_t session_id, el_val_t first_message);
el_val_t handle_session_approve(el_val_t session_id, el_val_t body); el_val_t handle_session_approve(el_val_t session_id, el_val_t body);
el_val_t strip_query(el_val_t path); el_val_t strip_query(el_val_t path);
el_val_t flag_true(el_val_t body, el_val_t key);
el_val_t err_404(el_val_t path); el_val_t err_404(el_val_t path);
el_val_t err_405(el_val_t method, el_val_t path); el_val_t err_405(el_val_t method, el_val_t path);
el_val_t route_health(void); el_val_t route_health(void);
@@ -1144,6 +1169,9 @@ el_val_t local_node_count;
el_val_t snapshot_usable; el_val_t snapshot_usable;
el_val_t boot_num; el_val_t boot_num;
el_val_t is_genesis; el_val_t is_genesis;
el_val_t guard_disk;
el_val_t guard_disk_len;
el_val_t safe_to_seed;
el_val_t lang_profile(el_val_t code, el_val_t word_order, el_val_t morph_type, el_val_t has_case, el_val_t has_gender, el_val_t script_dir, el_val_t agreement, el_val_t null_subject) { el_val_t lang_profile(el_val_t code, el_val_t word_order, el_val_t morph_type, el_val_t has_case, el_val_t has_gender, el_val_t script_dir, el_val_t agreement, el_val_t null_subject) {
el_val_t r = native_list_empty(); el_val_t r = native_list_empty();
@@ -25890,14 +25918,28 @@ el_val_t proactive_curiosity(void) {
el_val_t wm_top_j = engram_wm_top_json(1); el_val_t wm_top_j = engram_wm_top_json(1);
el_val_t wm_top_n = json_array_get(wm_top_j, 0); el_val_t wm_top_n = json_array_get(wm_top_j, 0);
el_val_t wm_top_lbl = json_get(wm_top_n, EL_STR("label")); el_val_t wm_top_lbl = json_get(wm_top_n, EL_STR("label"));
if (!str_eq(wm_top_lbl, EL_STR(""))) { el_val_t wm_top_type = json_get(wm_top_n, EL_STR("node_type"));
el_val_t sp = str_find_chars(wm_top_lbl, EL_STR(" :([")); state_set(EL_STR("allow_auto"), EL_STR("0"));
if (sp > 3) { if (str_eq(wm_top_type, EL_STR("Memory"))) {
state_set(EL_STR("cseed_auto"), str_slice(wm_top_lbl, 0, sp)); state_set(EL_STR("allow_auto"), EL_STR("1"));
}
if (str_eq(wm_top_type, EL_STR("BacklogItem"))) {
state_set(EL_STR("allow_auto"), EL_STR("1"));
}
if (str_eq(wm_top_type, EL_STR("Entity"))) {
state_set(EL_STR("allow_auto"), EL_STR("1"));
}
el_val_t allow_auto = state_get(EL_STR("allow_auto"));
if (str_eq(allow_auto, EL_STR("1"))) {
if (!str_eq(wm_top_lbl, EL_STR(""))) {
el_val_t sp = str_find_chars(wm_top_lbl, EL_STR(" :(["));
if (sp > 3) {
state_set(EL_STR("cseed_auto"), str_slice(wm_top_lbl, 0, sp));
}
} }
} }
el_val_t auto_term = state_get(EL_STR("cseed_auto")); el_val_t auto_term = state_get(EL_STR("cseed_auto"));
el_val_t results_auto = ({ el_val_t _if_result_101 = 0; if (str_eq(auto_term, EL_STR(""))) { _if_result_101 = (EL_STR("[]")); } else { _if_result_101 = (engram_activate_json(auto_term, 1)); } _if_result_101; }); el_val_t results_auto = ({ el_val_t _if_result_3 = 0; if (str_eq(auto_term, EL_STR(""))) { _if_result_3 = (EL_STR("[]")); } else { _if_result_3 = (engram_activate_json(auto_term, 1)); } _if_result_3; });
el_val_t found_auto = json_array_len(results_auto); el_val_t found_auto = json_array_len(results_auto);
el_val_t total_found = (found + found_auto); el_val_t total_found = (found + found_auto);
el_val_t safe_auto = str_replace(auto_term, EL_STR("\""), EL_STR("'")); el_val_t safe_auto = str_replace(auto_term, EL_STR("\""), EL_STR("'"));
@@ -25908,6 +25950,7 @@ el_val_t proactive_curiosity(void) {
return 0; return 0;
} }
el_val_t pulse_count(void) { el_val_t pulse_count(void) {
el_val_t s = state_get(EL_STR("soul.pulse")); el_val_t s = state_get(EL_STR("soul.pulse"));
if (str_eq(s, EL_STR(""))) { if (str_eq(s, EL_STR(""))) {
@@ -28915,7 +28958,13 @@ int main(int _argc, char** _argv) {
state_set(EL_STR("soul_engram_api_key"), engram_api_key_raw); state_set(EL_STR("soul_engram_api_key"), engram_api_key_raw);
state_set(EL_STR("soul.running"), EL_STR("true")); state_set(EL_STR("soul.running"), EL_STR("true"));
is_genesis = str_eq(soul_cgi_id, EL_STR("ntn-genesis")); is_genesis = str_eq(soul_cgi_id, EL_STR("ntn-genesis"));
if (is_genesis) { guard_disk = ({ el_val_t _if_result_25 = 0; if (str_eq(engram_url_raw, EL_STR(""))) { _if_result_25 = (fs_read(snapshot)); } else { _if_result_25 = (EL_STR("")); } _if_result_25; });
guard_disk_len = str_len(guard_disk);
safe_to_seed = !((guard_disk_len > 200000) && (engram_node_count() < (guard_disk_len / 16000)));
if (is_genesis && !safe_to_seed) {
println(el_str_concat(el_str_concat(el_str_concat(el_str_concat(EL_STR("[soul] GUARD: loaded "), int_to_str(engram_node_count())), EL_STR(" nodes but snapshot file is ")), int_to_str(guard_disk_len)), EL_STR(" bytes \xe2\x80\x94 refusing to seed/save over a real graph")));
}
if (is_genesis && safe_to_seed) {
el_val_t edge_count_now = engram_edge_count(); el_val_t edge_count_now = engram_edge_count();
if (edge_count_now < 100) { if (edge_count_now < 100) {
init_soul_edges(); init_soul_edges();
@@ -28926,7 +28975,7 @@ int main(int _argc, char** _argv) {
state_set(EL_STR("soul_snapshot_path"), snapshot); state_set(EL_STR("soul_snapshot_path"), snapshot);
engram_save(snapshot); engram_save(snapshot);
} }
if (is_genesis) { if (is_genesis && safe_to_seed) {
el_val_t snap = state_get(EL_STR("soul_snapshot_path")); el_val_t snap = state_get(EL_STR("soul_snapshot_path"));
if (!str_eq(snap, EL_STR(""))) { if (!str_eq(snap, EL_STR(""))) {
engram_save(snap); engram_save(snap);