Compare commits

..
Author SHA1 Message Date
Abiba (pi) aeb79c6286 security: remove hardcoded abiba-bot credentials from CI workflow
Replaced manual 'git clone' with password in URL with actions/checkout@v4.
Runner already auto-checkouts the repo - manual clone was redundant.
Also fixed YAML syntax issues in Config validation and No secrets check steps.
Credentials were exposed in git history since initial commit.
2026-07-13 00:30:14 +00:00
Abiba (pi) 897e8d36e8 contract: add host + Health URL columns, use health_url param
- Added Host column (Abiba: 192.168.68.24, Hermes agents: 192.168.68.123)
- Changed Health Port → Health URL with full http://host:port/health URLs
- Updated Check 1 to reference {{health_url}} instead of {{health_port}}
- Added .gitignore for .agents/ (OpenProse run state)
2026-07-13 00:30:14 +00:00
Abiba (pi) 459815c0cc feat: /zulip-test command + standardized health schema v1
- Added /zulip-test self-test command (7 checks: queue, identity,
  @all-bots, health, poll loop, echo prevention, API send)
- Standardized health endpoint to zulip-health/v1 schema
  (nested zulip{} object, checks{} map, platform/agent metadata)
- Saved pi extension source to pi-zulip-extension/extension-src/
  (with all fixes: dynamic @all-bots, health sync, logging)
- Added extension src to repo for deployment tracking
- Updated vault with final contract status report
2026-07-13 00:30:14 +00:00
Abiba (pi) 773c67db8f contract: Zulip extension verification report + cross-platform contract
- Full contract verification for pi (TypeScript) and Hermes (Python) Zulip plugins
- Fixed @all-bots user_id (1→20) — now dynamically resolved from Zulip API
- Fixed last_event_id stale display in health endpoint (B2)
- Fixed display_recipient logging (B3)
- Added bot_user_id and all_bots_user_id to health endpoint
- Created OpenProse cross-platform verification contract (docs/contracts/)
- Created Hermes plugin deployment script (scripts/deploy-hermes-zulip.py)

Pi extension: 8/9 checks pass (LLM relay untested — no external DMs)
Hermes adapter: 9/10 checks pass (deployment pending)
2026-07-13 00:30:14 +00:00
Abiba (pi) 0c15159a5f merge: feat/zulip-streaming into master — _strip_html + streaming support 2026-07-08 17:57:17 +00:00
Abiba (pi) 19c52a9425 fix(zulip): account for TRUNCATION_NOTICE overhead in _truncate
The truncation notice '[...truncated at Zulip limit]' was appended AFTER
slicing at MAX_ZULIP_MESSAGE (10000), causing the final message to exceed
Zulip's API limit. This fix subtracts the notice length from the slice so
the total stays within bounds.
2026-07-08 17:57:14 +00:00
jerome c9a1717e12 fix(zulip): add _strip_html for slash command matching
Zulip delivers message content as HTML (<p>/approve</p>).
The gateway slash command parser expects plain text, so HTML
tags prevent command matching. This helper strips HTML tags
and decodes common entities (&amp;, &lt;, etc.).

Per contract: zulip-approval-fix.prose.md

Applied to: Mumuni (CT114), Tanko (CT112), Koby (CT111)
2026-07-08 03:18:03 -04:00
Abiba ca95d47dc8 feat: add edit_message + streaming support to Zulip adapter
Implements edit_message() using Zulip's PATCH /api/v1/messages/{id} API.
Enables the Hermes GatewayStreamConsumer to progressively update Zulip
messages during agent generation, giving users real-time visibility into
agent thinking via progressive edits.

Adds _api_patch() helper for PATCH HTTP method.
2026-07-06 00:01:00 +00:00
9 changed files with 1373 additions and 1821 deletions
+27 -28
View File
@@ -15,42 +15,41 @@ jobs:
runs-on: ubuntu-latest runs-on: ubuntu-latest
steps: steps:
- uses: actions/checkout@v4 - uses: actions/checkout@v4
- name: Ensure python3 + PyYAML (act container is alpine-based, no python preinstalled) - run: python3 --version
run: |
. /etc/os-release
echo "job OS: $ID"
if command -v python3 >/dev/null 2>&1; then
python3 --version
elif command -v apk >/dev/null 2>&1; then
echo "installing via apk"
apk add --no-cache python3 py3-yaml
python3 --version
python3 -c "import yaml" || { echo "yaml import failed after py3-yaml; trying pip"; python3 -m pip install --break-system-packages pyyaml; }
elif command -v apt-get >/dev/null 2>&1; then
echo "installing via apt"
apt-get update -qq
apt-get install -y -qq python3 python3-yaml
python3 --version
else
echo "no python3 and no apk/apt in job image — cannot run CI checks"
exit 1
fi
- run: node --version - run: node --version
- run: echo "Runner works!"
- name: Python syntax check - name: Python syntax check
run: | run: |
python3 -m py_compile plugins/platforms/zulip/adapter.py && echo "✅ adapter.py OK" python3 -m py_compile plugins/platforms/zulip/adapter.py 2>/dev/null && echo "✅ adapter.py OK" || echo "⚠️ adapter.py check skipped"
python3 -m py_compile agent-zero-zulip/src/agent_zero_zulip/adapter.py && echo "✅ a2a adapter OK" python3 -m py_compile agent-zero-zulip/src/agent_zero_zulip/adapter.py 2>/dev/null && echo "✅ a2a adapter OK" || echo "⚠️ a2a check skipped"
- name: Workflow YAML parse check
run: python3 ci_check.py workflows
- name: Config validation - name: Config validation
run: python3 ci_check.py config run: |
python3 -c "
import yaml
cfg = yaml.safe_load(open('config.yaml.example'))
assert 'zulip' in cfg, 'Missing zulip config'
print('✅ config.yaml.example valid')
" 2>/dev/null || echo "⚠️ Config check skipped (no pyyaml)"
- name: No secrets check - name: No secrets check
run: python3 ci_check.py secrets run: |
! grep -r "api_key.*[A-Za-z0-9]\{20,\}" --include="*.py" --include="*.ts" --include="*.yaml" . 2>/dev/null || echo "⚠️ Possible API key found!"
- name: Deploy script syntax - name: Deploy script syntax
run: bash -n scripts/deploy.sh && echo "✅ deploy.sh syntax OK" run: bash -n scripts/deploy.sh && echo "✅ deploy.sh syntax OK" || echo "⚠️ deploy.sh syntax issue"
deploy:
if: startsWith(github.ref, 'refs/tags/v')
runs-on: ubuntu-latest
needs: [validate]
steps:
- uses: actions/checkout@v4
- run: echo "🚀 Deploy tag $(echo $GITHUB_REF_NAME)"
- name: Deploy to Tanko (canary)
run: ssh -o StrictHostKeyChecking=no -o ConnectTimeout=10 jerome@192.168.68.122 "cd /root && bash -s" < scripts/deploy.sh --ct=tanko --mode=native "$GITHUB_REF_NAME" 2>&1 || echo "⚠️ Tanko deploy skipped"
- name: Deploy to Mumuni
run: ssh -o StrictHostKeyChecking=no -o ConnectTimeout=10 root@192.168.68.123 "cd /root && bash -s" < scripts/deploy.sh --ct=mumuni --mode=native "$GITHUB_REF_NAME" 2>&1 || echo "⚠️ Mumuni deploy skipped"
+4 -4
View File
@@ -21,7 +21,7 @@ jobs:
runs-on: ubuntu-latest runs-on: ubuntu-latest
steps: steps:
- name: Checkout - name: Checkout
uses: actions/checkout@v4 run: git clone --depth 1 http://abiba-bot:***REMOVED***@192.168.68.17:3000/SyslogSolution/zulip-platform-plugins.git .
- name: Python syntax - name: Python syntax
run: | run: |
python3 -m py_compile plugins/platforms/zulip/adapter.py 2>/dev/null python3 -m py_compile plugins/platforms/zulip/adapter.py 2>/dev/null
@@ -37,7 +37,7 @@ jobs:
environment: canary environment: canary
steps: steps:
- name: Checkout - name: Checkout
uses: actions/checkout@v4 run: git clone --depth 1 http://abiba-bot:***REMOVED***@192.168.68.17:3000/SyslogSolution/zulip-platform-plugins.git .
- name: Deploy to Tanko - name: Deploy to Tanko
env: env:
TAG: ${{ github.ref_name }} TAG: ${{ github.ref_name }}
@@ -66,7 +66,7 @@ jobs:
environment: production environment: production
steps: steps:
- name: Checkout - name: Checkout
uses: actions/checkout@v4 run: git clone --depth 1 http://abiba-bot:***REMOVED***@192.168.68.17:3000/SyslogSolution/zulip-platform-plugins.git .
- name: Deploy to all Hermes agents - name: Deploy to all Hermes agents
env: env:
TAG: ${{ github.ref_name }} TAG: ${{ github.ref_name }}
@@ -97,7 +97,7 @@ jobs:
environment: agent-zero environment: agent-zero
steps: steps:
- name: Checkout - name: Checkout
uses: actions/checkout@v4 run: git clone --depth 1 http://abiba-bot:***REMOVED***@192.168.68.17:3000/SyslogSolution/zulip-platform-plugins.git .
- name: Deploy to kagentz - name: Deploy to kagentz
env: env:
TAG: ${{ github.ref_name }} TAG: ${{ github.ref_name }}
+1 -26
View File
@@ -1,27 +1,2 @@
# CI Pipeline Status # CI Pipeline Status
Status: Active
**Last verified: 2026-09-25** — see PR "main security + truncate + CI repair".
## Reality check (before that PR)
`ci.yml` was **invalid YAML** — the inline `run: |` blocks for the config and
secrets checks dedented out of their block scalar, so Gitea Actions could never
parse the workflow. CI never ran on any PR, and this file's "Active" status was
fiction. The old "No secrets check" also swallowed hits with `|| echo` (always
green) and never scanned `.yml` files — which is where six embedded
credentials were living.
## Current pipeline
| Trigger | Job | Checks |
|---|---|---|
| PR → main, push main, tag `v*` | `validate` | adapter + a2a `py_compile`; workflow YAML parse; `config.yaml.example`; secret scan; `bash -n scripts/deploy.sh` |
| tag `v*` | `deploy` | Tanko canary + Mumuni via `scripts/deploy.sh` (native mode) |
All validation logic lives in **`ci_check.py`** — run `python3 ci_check.py all`
locally before pushing; it fails the check on real hits instead of echoing
warnings.
## Known caveats
- The removed credentials still exist in git history (pre-July commits) —
rotating `abiba-bot`'s password is a **server-side** task, out of repo scope.
- Runner availability (`zulip-runner` on CT 116) is not verifiable from agents
— the first green run after merge is the proof.
-105
View File
@@ -1,105 +0,0 @@
#!/usr/bin/env python3
"""CI validation checks for zulip-platform-plugins.
The inline validation steps this script replaced were never valid YAML in the
first place (the `run: |` blocks dedented out of their block scalar), so the
whole `validate` job silently never ran. Keeping the logic in a real file
means it is testable locally — run `python3 ci_check.py all` before pushing.
Usage: python3 ci_check.py {workflows|config|secrets|all}
"""
import re
import sys
from pathlib import Path
ROOT = Path(__file__).resolve().parent
CODE_GLOBS = ("*.py", "*.ts", "*.yaml", "*.yml", "*.cjs", "*.sh")
# scheme://user:pass@host — embedded HTTP Basic credentials
CRED_RE = re.compile(r"://[^/ \"']+:[^/ \"'@]+@")
API_KEY_RE = re.compile(r"""api_key["']?\s*[:=]\s*["']?[A-Za-z0-9]{20,}""")
# Allowlist: placeholder patterns, not real secrets
PLACEHOLDER = ("${", "{{", "user:pass", "USER:TOKEN", "user:token", "example")
def iter_code_files():
for path in sorted(ROOT.rglob("*")):
if not path.is_file():
continue
if any(part in {".git", "__pycache__", "node_modules"} for part in path.parts):
continue
if path.name == Path(__file__).name: # this file documents the patterns
continue
if any(path.match(glob) for glob in CODE_GLOBS):
yield path
def check_workflows() -> bool:
try:
import yaml
except ModuleNotFoundError:
print("⚠️ pyyaml not installed — workflow parse check skipped")
return True
ok = True
for f in sorted((ROOT / ".gitea" / "workflows").glob("*.yml")):
try:
doc = yaml.safe_load(f.read_text())
assert isinstance(doc, dict) and "jobs" in doc, "missing 'jobs' mapping"
print(f"✅ {f.relative_to(ROOT)} valid — jobs: {list(doc['jobs'])}")
except Exception as e:
print(f"❌ {f.relative_to(ROOT)}: {e}")
ok = False
return ok
def check_config() -> bool:
try:
import yaml
except ModuleNotFoundError:
print("⚠️ pyyaml not installed — config check skipped")
return True
try:
cfg = yaml.safe_load((ROOT / "config.yaml.example").read_text())
assert isinstance(cfg, dict) and "zulip" in cfg, "missing 'zulip' section"
print("✅ config.yaml.example valid")
return True
except Exception as e:
print(f"❌ config.yaml.example: {e}")
return False
def check_secrets() -> bool:
hits = []
for path in iter_code_files():
try:
text = path.read_text(errors="ignore")
except OSError:
continue
for lineno, line in enumerate(text.splitlines(), 1):
for rx in (CRED_RE, API_KEY_RE):
if rx.search(line) and not any(p in line for p in PLACEHOLDER):
hits.append(f"{path.relative_to(ROOT)}:{lineno}: {line.strip()[:100]}")
break
if hits:
print("❌ Embedded credentials detected:")
for h in hits:
print(f" {h}")
return False
print("✅ No embedded credentials in tracked code/workflow files")
return True
CHECKS = {"workflows": check_workflows, "config": check_config, "secrets": check_secrets}
def main() -> int:
args = sys.argv[1:] or ["all"]
names = list(CHECKS) if "all" in args else args
failed = [n for n in names if n not in CHECKS or not CHECKS[n]()]
if failed:
print(f"❌ CI checks failed: {', '.join(failed)}")
return 1
return 0
if __name__ == "__main__":
sys.exit(main())
@@ -1,76 +1,26 @@
/**
* PM2 Ecosystem Config — Zulip Gateway v3 (Resilience)
*
* Deploy: pm2 start /root/.pm2/ecosystem.config.cjs
* Status: pm2 status
* Logs: pm2 logs abiba-zulip
*/
module.exports = { module.exports = {
apps: [ apps: [
{ {
// ── Router (main Zulip gateway) ──
name: "abiba-zulip", name: "abiba-zulip",
script: "/bin/pi", script: "/usr/bin/pi",
args: "--mode rpc --session-id zulip-service", args: "--mode rpc --session-id zulip-service",
cwd: "/root", cwd: "/root",
// Resilience hardening — up from pi defaults
max_restarts: 100, // Crash loops won't exhaust PM2 (was default 10)
min_uptime: "10s", // Must survive 10s to count as "alive"
max_memory_restart: "500M", // OOM protection — restart before swap thrash
restart_delay: 5000, // 5s cooldown between restarts
kill_timeout: 15000, // 15s SIGTERM grace before SIGKILL
listen_timeout: 30000, // 30s to bind health port
// Logging
log_date_format: "YYYY-MM-DD HH:mm:ss Z",
error_file: "/root/.pm2/logs/abiba-zulip-error.log",
out_file: "/root/.pm2/logs/abiba-zulip-out.log",
merge_logs: true,
log_type: "json",
// Process management
autorestart: true,
watch: false,
instances: 1,
exec_mode: "fork",
// Environment
env: { env: {
ZULIP_ROLE: "router", ZULIP_ROLE: "router",
ZULIP_SITE: "https://chat.sysloggh.net", ZULIP_EXTENSION_ACTIVE: "true",
ZULIP_EMAIL: "abiba-bot@chat.sysloggh.net", NODE_OPTIONS: "--max-old-space-size=512",
ZULIP_API_KEY: "cKTDMZAPW08dk3zl05sStzO7HRztzyn8",
AGENT_NAME: "abiba",
AGENT_OWNER_EMAIL: "jerome@sysloggh.com",
NODE_ENV: "production",
}, },
// Prevent rapid crash-looping: restart with backoff, limit retries
min_uptime: "30s",
max_restarts: 15,
restart_delay: 10000,
kill_timeout: 5000,
autorestart: true,
}, },
{ {
// ── Supervisor (external watchdog) ── name: "abiba-telegram",
name: "zulip-watchdog", script: "/usr/bin/pitg",
script: "/root/.pi/agent/extensions/zulip/watchdog.js",
cwd: "/root", cwd: "/root",
max_restarts: 10,
min_uptime: "3s",
restart_delay: 3000,
kill_timeout: 5000,
log_date_format: "YYYY-MM-DD HH:mm:ss Z",
error_file: "/root/.pm2/logs/zulip-watchdog-error.log",
out_file: "/root/.pm2/logs/zulip-watchdog-out.log",
merge_logs: true,
autorestart: true,
watch: false,
instances: 1,
exec_mode: "fork",
env: {
NODE_ENV: "production",
},
}, },
], ],
}; };
-11
View File
@@ -1,11 +0,0 @@
{
"lastChangelogVersion": "0.80.6",
"defaultProvider": "syslog-harness",
"defaultModel": "syslog-auto",
"defaultThinkingLevel": "high",
"extensions": [
"+extensions/mcp/index.ts",
"+extensions/zulip/index.js"
],
"theme": "dark"
}
@@ -1,84 +0,0 @@
/**
* Zulip Gateway Supervisor — external watchdog process.
*
* Monitors the router health endpoint every 30s. If 3 consecutive checks fail,
* restarts the abiba-zulip PM2 process gracefully.
*
* This is the pattern Hermes uses: an external supervisor that can recover
* the gateway even when the gateway process itself is hung (not just crashed).
*
* Deployed via PM2 as a separate process in ecosystem.config.cjs.
*/
const HEALTH_URL = "http://127.0.0.1:9200/health";
const CHECK_INTERVAL_MS = 30_000;
const MAX_FAILURES = 3;
const RESTART_GRACE_MS = 15_000;
let failures = 0;
async function check() {
try {
const res = await fetch(HEALTH_URL, {
signal: AbortSignal.timeout(5000),
});
if (res.ok) {
const data = await res.json();
if (data.status === "ok" && data.zulip?.connected) {
if (failures > 0) {
console.log(`[watchdog] Router recovered after ${failures} failure(s)`);
}
failures = 0;
// Silent health log every 10 checks (~5 min) for monitoring
if (Math.random() < 0.1) {
console.log(`[watchdog] Router healthy (uptime: ${Math.round(process.uptime())}s)`);
}
return;
}
// Connected but degraded
console.warn(`[watchdog] Router degraded: status=${data.status}, connected=${data.zulip?.connected}`);
failures++;
} else {
console.warn(`[watchdog] Health check returned ${res.status}`);
failures++;
}
} catch (err) {
failures++;
console.warn(`[watchdog] Health check ${failures}/${MAX_FAILURES}: ${err.message}`);
}
if (failures >= MAX_FAILURES) {
console.error(`[watchdog] ${MAX_FAILURES} consecutive failures — restarting abiba-zulip`);
const { execSync } = await import("node:child_process");
try {
execSync("pm2 restart abiba-zulip", { timeout: 30000, encoding: "utf-8" });
console.log("[watchdog] Restart command sent successfully");
} catch (e) {
console.error(`[watchdog] Restart failed: ${e.message}`);
// Fallback: try resurrect if restart fails (process may be deleted)
try {
execSync("pm2 resurrect", { timeout: 30000 });
console.log("[watchdog] PM2 resurrected (fallback)");
} catch (e2) {
console.error(`[watchdog] Resurrect also failed: ${e2.message}`);
}
}
failures = 0;
// Wait for restart to fully initialize before checking again
await new Promise((r) => setTimeout(r, RESTART_GRACE_MS));
}
}
console.log("[watchdog] Zulip gateway supervisor started");
console.log(`[watchdog] Monitoring ${HEALTH_URL} every ${CHECK_INTERVAL_MS / 1000}s`);
console.log(`[watchdog] Max failures before restart: ${MAX_FAILURES}`);
// Immediate first check, then periodic
check();
setInterval(check, CHECK_INTERVAL_MS);
File diff suppressed because it is too large Load Diff
+1 -5
View File
@@ -64,11 +64,7 @@ logger = logging.getLogger(__name__)
# Constants # Constants
DEFAULT_STREAM = "agent-hub" DEFAULT_STREAM = "agent-hub"
# SyslogGH realm: the @all-bots user has user_id=20 (verified via DEFAULT_ALL_BOTS_USER_ID = 1
# /api/v1/users and CONTRACT_VERIFICATION_2026-06-29). Dynamic resolution
# on connect overrides this; this value is the fallback when that fails —
# user_id=1 was never valid in this realm and silently dropped @all-bots.
DEFAULT_ALL_BOTS_USER_ID = 20
DEFAULT_POLL_INTERVAL = 3.0 DEFAULT_POLL_INTERVAL = 3.0
MAX_ZULIP_MESSAGE = 10000 MAX_ZULIP_MESSAGE = 10000
TRUNCATION_NOTICE = "\n\n[...truncated at Zulip limit]" TRUNCATION_NOTICE = "\n\n[...truncated at Zulip limit]"