Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
7675109afc | ||
|
|
42fc14a5b3 | ||
|
|
326acb63d1 | ||
|
|
6b6e25c3f4 | ||
|
|
9a0e90dff0 | ||
|
|
0ce9de002b | ||
|
|
70403854ff |
+1
-1
@@ -10,7 +10,7 @@ test_keys.txt
|
||||
|
||||
/mongoose/
|
||||
/Trash/
|
||||
|
||||
deploy_lt.sh
|
||||
|
||||
# Build artifacts
|
||||
/build/
|
||||
|
||||
@@ -97,7 +97,7 @@ RUN if [ "$DEBUG_BUILD" = "true" ]; then \
|
||||
src/main.c src/config.c src/context.c src/llm.c \
|
||||
src/nostr_handler.c src/agent.c src/tools/tools_common.c src/tools/tools_schema.c src/tools/tools_dispatch.c \
|
||||
src/tools/tool_agent.c src/tools/tool_meta.c src/tools/tool_model.c \
|
||||
src/tools/tool_nostr_query.c src/tools/tool_nostr_identity.c src/tools/tool_nostr_social.c \
|
||||
src/tools/tool_nostr_query.c src/tools/tool_nostr_my_events.c src/tools/tool_nostr_identity.c src/tools/tool_nostr_social.c \
|
||||
src/tools/tool_nostr_relay.c src/tools/tool_nostr_dm.c src/tools/tool_admin.c \
|
||||
src/tools/tool_task.c src/tools/tool_nostr_list.c src/tools/tool_local.c \
|
||||
src/tools/tool_skill.c src/tools/tool_nostr_post.c src/tools/tool_memory.c src/tools/tool_config.c src/trigger_manager.c \
|
||||
|
||||
@@ -18,6 +18,7 @@ SRCS = \
|
||||
$(SRC_DIR)/tools/tool_meta.c \
|
||||
$(SRC_DIR)/tools/tool_model.c \
|
||||
$(SRC_DIR)/tools/tool_nostr_query.c \
|
||||
$(SRC_DIR)/tools/tool_nostr_my_events.c \
|
||||
$(SRC_DIR)/tools/tool_nostr_identity.c \
|
||||
$(SRC_DIR)/tools/tool_nostr_social.c \
|
||||
$(SRC_DIR)/tools/tool_nostr_relay.c \
|
||||
|
||||
@@ -55,11 +55,11 @@ Skills compose by adoption-list order (`10123`) and trigger tags carry runtime e
|
||||
|
||||
Didactyl will support local inference, which is very privacy preserving. Remote inference does however have it's advantages, and in those cases Didactyl supports using Bitcoin Lightning and eCash inference providers.
|
||||
|
||||
## Current Status — v0.0.72
|
||||
## Current Status — v0.0.79
|
||||
|
||||
**Active build — this project is barely working. Experiment at your own risk.**
|
||||
|
||||
> Last release update: v0.0.72 — Refined wizard framing and menu hotkey display; diagnosed hardcoded Didactyl fallback causing name mismatch
|
||||
> Last release update: v0.0.79 — Enhance existing-agent wizard with full config recovery review edit flow and new-agent fallback
|
||||
|
||||
- Connects to configured relays with auto-reconnect and relay state transition logging
|
||||
- Publishes configured startup events per relay as each relay becomes connected
|
||||
|
||||
+609
-8016
File diff suppressed because one or more lines are too long
@@ -0,0 +1,56 @@
|
||||
# Context Template
|
||||
|
||||
```yaml
|
||||
- section: admin_identity
|
||||
role: system
|
||||
content: |
|
||||
## Administrator Identity (source: config.admin.pubkey)
|
||||
|
||||
This is your administrator! Admin pubkey (hex): {{admin_pubkey}}
|
||||
|
||||
- section: admin_profile
|
||||
role: system
|
||||
content: |
|
||||
## Administrator Kind 0 Profile (source: nostr kind 0)
|
||||
|
||||
Administrator kind 0 profile content (JSON): {{admin_kind0_json}}
|
||||
provider:
|
||||
anthropic: |
|
||||
<admin_kind0_profile source="nostr_kind_0">
|
||||
{{admin_kind0_json}}
|
||||
</admin_kind0_profile>
|
||||
|
||||
- section: admin_relay_list
|
||||
role: system
|
||||
content: |
|
||||
## Administrator Relay List (source: nostr kind 10002)
|
||||
|
||||
Administrator kind 10002 relay-list content (JSON): {{admin_kind10002_json}}
|
||||
|
||||
- section: startup_events
|
||||
role: system
|
||||
content: |
|
||||
## Startup Events Memory (source: config.startup_events)
|
||||
|
||||
Startup events memory (kinds/content/tags): {{startup_events_json}}
|
||||
|
||||
- section: adopted_skills
|
||||
role: system
|
||||
content: |
|
||||
{{adopted_skills_content}}
|
||||
|
||||
- section: agent_tasks
|
||||
role: system
|
||||
content: |
|
||||
{{tasks_content}}
|
||||
|
||||
- section: dm_history
|
||||
role: expand
|
||||
limit: 12
|
||||
|
||||
- section: admin_notes
|
||||
role: system
|
||||
content: |
|
||||
## Administrator Recent Notes (source: nostr kind 1)
|
||||
|
||||
{{admin_notes_content}}
|
||||
Executable
+30
@@ -0,0 +1,30 @@
|
||||
#!/bin/bash
|
||||
|
||||
set -euo pipefail
|
||||
|
||||
SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
|
||||
SOURCE_BINARY="$SCRIPT_DIR/didactyl_static_x86_64"
|
||||
REMOTE_TARGET="ubuntu@laantungir.net:~/didactyl"
|
||||
|
||||
if ! command -v rsync >/dev/null 2>&1; then
|
||||
echo "ERROR: rsync is not installed or not in PATH"
|
||||
exit 1
|
||||
fi
|
||||
|
||||
if [ ! -f "$SOURCE_BINARY" ]; then
|
||||
echo "ERROR: Source binary not found: $SOURCE_BINARY"
|
||||
echo "Build it first so didactyl_static_x86_64 exists."
|
||||
exit 1
|
||||
fi
|
||||
|
||||
echo "Building static binary first..."
|
||||
"$SCRIPT_DIR/build_static.sh"
|
||||
|
||||
if [ ! -f "$SOURCE_BINARY" ]; then
|
||||
echo "ERROR: Build completed but source binary not found: $SOURCE_BINARY"
|
||||
exit 1
|
||||
fi
|
||||
|
||||
echo "Deploying $SOURCE_BINARY to $REMOTE_TARGET"
|
||||
rsync -avz --progress "$SOURCE_BINARY" "$REMOTE_TARGET"
|
||||
echo "Deployment complete."
|
||||
@@ -0,0 +1,91 @@
|
||||
# Fix: Default Skill Missing from skill_list Cache
|
||||
|
||||
## Problem
|
||||
|
||||
When a new didactyl agent is created via the setup wizard, the default skill (`didactyl-default`, kind 31124) does not appear in the `skill_list` output. The agent IS using the default skill as its system context, but the skill cache (`g_self_skill_events`) does not contain it.
|
||||
|
||||
## Evidence
|
||||
|
||||
- Default skill event IS published to relays (confirmed by `nostr_my_events`)
|
||||
- Default skill event shows `in_current_cache: false`
|
||||
- `skill_list` returns `count: 1` with only `infrastructure-monitor`
|
||||
- The kind 10123 adoption list only contains `infrastructure-monitor`
|
||||
|
||||
## Root Cause Analysis
|
||||
|
||||
The startup sequence in `main.c` is:
|
||||
|
||||
```
|
||||
1. nostr_handler_init() — resets g_self_skill_events to []
|
||||
2. wait_for_connected_relays() — waits for relay connections
|
||||
3. reconcile_startup_events() — publishes default skill to relays
|
||||
-> publish_kind_event_to_relays() — inserts into cache IF sent > 0
|
||||
4. ... relay list expansion ...
|
||||
5. subscribe_self_skills() — subscribes to relays for kinds 31123/31124/10123
|
||||
```
|
||||
|
||||
The default skill SHOULD be inserted into the cache at step 3 via `publish_kind_event_to_relays` -> `self_skill_cache_upsert_event_locked`. However, the cache insert at line 2750 is gated by `if (sent > 0)`.
|
||||
|
||||
There are two failure modes:
|
||||
|
||||
### Failure Mode 1: Async publish timing
|
||||
The startup publish creates a NEW event per relay via `publish_pending_startup_events_for_relay_index`. Each call to `publish_kind_event_to_relays` creates a fresh event with `nostr_create_and_sign_event`. If the relay is not connected at that moment, `sent = 0` and the cache insert is skipped.
|
||||
|
||||
### Failure Mode 2: Subscription race condition
|
||||
Even if the cache insert succeeds at step 3, the self-skill subscription at step 5 queries relays. For a brand new agent, the default skill was JUST published asynchronously. If the relay hasn't indexed it by the time the subscription query runs, the subscription returns EOSE without the default skill. The subscription stays open but the default skill was published BEFORE the subscription started, so it won't arrive as a live event.
|
||||
|
||||
The cache entry from step 3 should persist, but there may be an edge case where the relay pool reconnection handler at line 792 triggers another publish cycle, creating a new event that replaces the cache entry, and if that publish fails (sent=0), the replacement doesn't happen but the old entry is still there.
|
||||
|
||||
### Most Likely Cause
|
||||
The most likely cause is that `publish_kind_event_to_relays` returns `sent = 0` for the default skill during the initial reconcile. This can happen if:
|
||||
- The relay connection drops momentarily between `wait_for_connected_relays` and the actual publish
|
||||
- The relay pool's async publish fails silently
|
||||
|
||||
## Proposed Fix
|
||||
|
||||
### Approach: Seed the cache directly from config during reconcile
|
||||
|
||||
In `nostr_handler_reconcile_startup_events()`, after publishing startup events, explicitly seed the self-skill cache with a synthetic event built from `g_cfg->default_skill`. This ensures the default skill is ALWAYS in the cache regardless of relay publish success.
|
||||
|
||||
### Implementation
|
||||
|
||||
In `nostr_handler.c`, add a new static function `seed_default_skill_into_cache()` that:
|
||||
|
||||
1. Checks if `g_cfg->default_skill.content` is non-empty
|
||||
2. Builds a cJSON event object with:
|
||||
- `kind`: `g_cfg->default_skill.kind` (31124)
|
||||
- `pubkey`: `g_cfg->keys.public_key_hex`
|
||||
- `content`: `g_cfg->default_skill.content`
|
||||
- `tags`: parsed from `g_cfg->default_skill.tags_json`
|
||||
- `created_at`: `time(NULL)` (or 0 as a floor value)
|
||||
- `id`: a placeholder hex string (e.g., all zeros) — will be replaced when the real event arrives from relay
|
||||
3. Calls `self_skill_cache_upsert_event_locked()` with this synthetic event
|
||||
|
||||
Call this function at the END of `nostr_handler_reconcile_startup_events()`, AFTER the publish loop. This way:
|
||||
- If the publish succeeded, the cache already has the real event (with real ID/sig). The synthetic event would have `created_at` <= the real one, so the upsert would be a no-op.
|
||||
- If the publish failed, the cache gets the synthetic event as a fallback.
|
||||
- When the subscription later returns the real event from relays, it replaces the synthetic one (since it has a real ID and potentially newer timestamp).
|
||||
|
||||
### Alternative Approach: Remove the `sent > 0` gate
|
||||
|
||||
Change `publish_kind_event_to_relays` to always insert skill events (kinds 31123/31124) into the cache, regardless of whether the relay publish succeeded. This is simpler but changes the semantics — the cache would contain events that may not be on any relay.
|
||||
|
||||
### Recommended: Approach 1 (seed from config)
|
||||
|
||||
This is safer because:
|
||||
- It doesn't change the publish function's behavior
|
||||
- It explicitly handles the default skill case
|
||||
- The synthetic event gets replaced by the real one when it arrives from relays
|
||||
- It works even if the publish completely fails
|
||||
|
||||
### Files to Modify
|
||||
|
||||
1. `src/nostr_handler.c`:
|
||||
- Add `seed_default_skill_into_cache()` static function
|
||||
- Call it at the end of `nostr_handler_reconcile_startup_events()`
|
||||
|
||||
### Edge Cases
|
||||
|
||||
- If the default skill is later updated via `skill_update`, the relay version will have a newer `created_at` and will replace the synthetic entry
|
||||
- If the agent has no default skill configured, the seed function is a no-op
|
||||
- The synthetic event has a placeholder ID, so `in_current_cache` checks by event ID won't match it — but `skill_list` iterates all events and doesn't check by ID
|
||||
@@ -0,0 +1,149 @@
|
||||
# Enhanced Existing Agent Wizard Flow
|
||||
|
||||
## Problem
|
||||
|
||||
When choosing "existing agent" in the wizard, the current flow:
|
||||
1. Asks for nsec
|
||||
2. Recovers kind 10002 relay list from Nostr
|
||||
3. Immediately boots the agent
|
||||
|
||||
This is insufficient when installing an existing agent on a **new server** because:
|
||||
- You cannot review or change the admin pubkey
|
||||
- You cannot review or change the LLM provider/model/API key
|
||||
- You cannot install a systemd service with a dedicated user
|
||||
- You cannot see what config was recovered from Nostr
|
||||
- The agent name is not recovered from the kind 0 profile
|
||||
|
||||
## Current Code
|
||||
|
||||
- [`existing_agent_flow()`](src/setup_wizard.c:1795) — 22 lines, minimal recovery
|
||||
- [`recover_existing_config_from_nostr()`](src/setup_wizard.c:792) — only recovers kind 10002 relays
|
||||
- Returns `SETUP_WIZARD_RC_EXISTING` (2) which does NOT set `bootstrap_mode`
|
||||
- In `main.c`, existing agents skip `reconcile_startup_events()` unless `first_run` is detected
|
||||
|
||||
## Data Available on Nostr for an Existing Agent
|
||||
|
||||
| Data | Kind | Storage | Recovery Method |
|
||||
|------|------|---------|-----------------|
|
||||
| Relay list | 10002 | Public tags | `query_and_extract_kind10002_relays()` |
|
||||
| Agent profile/name | 0 | Public JSON content | Query kind 0 by agent pubkey |
|
||||
| LLM config | 30078 d=llm_config | NIP-44 encrypted to self | `fetch_self_config_plaintext()` |
|
||||
| Agent config - admin pubkey, DM protocol | 30078 d=agent_config | NIP-44 encrypted to self | `fetch_self_config_plaintext()` |
|
||||
| Default skill | 31124 d=didactyl-default | Public content | Query kind 31124 by agent pubkey |
|
||||
| Adoption list | 10123 | Public tags | Query kind 10123 by agent pubkey |
|
||||
|
||||
## Proposed Enhanced Flow
|
||||
|
||||
```mermaid
|
||||
flowchart TD
|
||||
A[Enter nsec] --> B[Connect to default relays]
|
||||
B --> C[Recover kind 10002 relay list]
|
||||
C --> D{Relay list found?}
|
||||
D -->|No| E{Offer to create new agent with this nsec}
|
||||
E -->|Yes| E2[Jump to new_agent_flow with nsec pre-loaded]
|
||||
E -->|No| E3[Return to main menu]
|
||||
D -->|Yes| F[Reconnect with recovered relays]
|
||||
F --> G[Recover all config from Nostr]
|
||||
G --> H[Display recovered config summary]
|
||||
H --> I{Review each setting}
|
||||
I -->|Keep all| J[Review summary + launch options]
|
||||
I -->|Change admin| K[Prompt new admin pubkey]
|
||||
I -->|Change LLM| L[Prompt LLM config]
|
||||
I -->|Change relays| M[Prompt relay config]
|
||||
K --> I
|
||||
L --> I
|
||||
M --> I
|
||||
J --> N{Launch option}
|
||||
N -->|Boot now| O[Return EXISTING]
|
||||
N -->|Install systemd| P[Install dedicated-user service]
|
||||
N -->|Quit| Q[Exit]
|
||||
```
|
||||
|
||||
### Step-by-step
|
||||
|
||||
#### Step 1: Identity — Enter nsec
|
||||
Same as current. Derive keys from nsec.
|
||||
|
||||
#### Step 2: Recovery — Connect and fetch config from Nostr
|
||||
1. Init nostr handler with default relays
|
||||
2. Wait for relay connections
|
||||
3. Query kind 10002 for relay list — if not found, offer to create a new agent with this nsec (jump to `new_agent_flow` with keys pre-loaded, skipping identity step)
|
||||
4. Cleanup and re-init with recovered relays
|
||||
5. Wait for relay connections on recovered relays
|
||||
6. Query kind 0 for agent profile — extract display_name/name
|
||||
7. Query kind 30078 d=llm_config — decrypt and parse LLM settings
|
||||
8. Query kind 30078 d=agent_config — decrypt and parse admin pubkey + DM protocol
|
||||
9. Cleanup nostr handler
|
||||
|
||||
#### Step 3: Review — Present recovered config
|
||||
Display all recovered values:
|
||||
```
|
||||
┌─────────────────────────────────────────────┐
|
||||
│ Existing Agent -- Recovered Configuration │
|
||||
├─────────────────────────────────────────────┤
|
||||
│ Agent name: Simon │
|
||||
│ Identity: b27072b7fc2edf45... │
|
||||
│ Admin: a1b2c3d4e5f6... │
|
||||
│ LLM Provider: ppq │
|
||||
│ LLM Model: claude-haiku-4.5 │
|
||||
│ LLM Base URL: https://api.ppq.ai │
|
||||
│ LLM API Key: sk-...**** │
|
||||
│ DM Protocol: nip04 │
|
||||
│ Relays: 5 configured │
|
||||
└─────────────────────────────────────────────┘
|
||||
```
|
||||
|
||||
Then offer a menu:
|
||||
```
|
||||
[a] change Admin pubkey
|
||||
[l] change LLM provider/model/key
|
||||
[r] change Relay configuration
|
||||
[c] continue with these settings
|
||||
[q] quit
|
||||
```
|
||||
|
||||
Each change option reuses the existing prompt functions (`prompt_admin_pubkey`, `prompt_llm_config`, `prompt_relay_configuration`) but with context-appropriate headers.
|
||||
|
||||
After any change, redisplay the summary and menu.
|
||||
|
||||
#### Step 4: Launch — Boot or install systemd
|
||||
Same as the new-agent flow's final step:
|
||||
```
|
||||
[b] boot the agent now
|
||||
[i] install dedicated-user systemd service and boot
|
||||
[q] quit
|
||||
```
|
||||
|
||||
The systemd install reuses `install_system_service_with_dedicated_user()`.
|
||||
|
||||
### Return Codes
|
||||
|
||||
- If user chooses "boot now": return `SETUP_WIZARD_RC_EXISTING` (2) — same as current
|
||||
- If user chooses "install systemd": return `SETUP_WIZARD_RC_EXIT` (1) — agent runs as systemd service
|
||||
- If user changed config values: the `main()` flow should still work because `recover_missing_runtime_config_from_nostr()` at line 1108 will fill in any gaps, and the existing agent path at line 1163 loads system context from adopted skills
|
||||
|
||||
### Key Consideration: bootstrap_mode for changed configs
|
||||
|
||||
If the user changes LLM or admin config in the wizard, those changes need to be persisted back to Nostr. Currently, `persist_runtime_config_to_nostr()` is only called when `bootstrap_mode || first_run`.
|
||||
|
||||
**Solution**: When the existing-agent wizard detects that config was changed, return `SETUP_WIZARD_RC_BOOTSTRAP` (0) instead of `SETUP_WIZARD_RC_EXISTING` (2). This triggers the full reconcile path which persists the updated config.
|
||||
|
||||
## Files to Modify
|
||||
|
||||
1. **`src/setup_wizard.c`**:
|
||||
- Add `recover_full_config_from_nostr()` — fetches kind 0, kind 30078 llm_config, kind 30078 agent_config
|
||||
- Add `query_self_kind0_name()` — queries agent's own kind 0 profile for name
|
||||
- Add `fetch_and_decrypt_self_config()` — replicates `fetch_self_config_plaintext()` logic from main.c for use in wizard context
|
||||
- Rewrite `existing_agent_flow()` with the enhanced multi-step flow
|
||||
- Make `prompt_admin_pubkey()`, `prompt_llm_config()`, `prompt_relay_configuration()` accept a context string parameter for the page header, or add wrapper versions for the existing-agent context
|
||||
|
||||
2. **`src/main.c`**:
|
||||
- Potentially expose `fetch_self_config_plaintext()`, `apply_recalled_llm_config()`, `apply_recalled_agent_config()` as non-static, OR duplicate the logic in setup_wizard.c
|
||||
- Better approach: move these to a shared location or make them accessible via a header
|
||||
|
||||
## Implementation Notes
|
||||
|
||||
- The wizard already calls `nostr_handler_init()` / `nostr_handler_cleanup()` for validation queries. The enhanced flow will do the same but with two init/cleanup cycles: first with default relays to get kind 10002, then with recovered relays to get everything else.
|
||||
- The `prompt_admin_pubkey()` and `prompt_llm_config()` functions currently have hardcoded step headers like "Step 3 of 7". These should be parameterized or have existing-agent variants.
|
||||
- The `fetch_self_config_plaintext()` function in main.c requires an active nostr handler. The wizard will need to have the handler initialized when calling it.
|
||||
- API key display should be masked — show only first 4 and last 4 characters.
|
||||
@@ -0,0 +1,459 @@
|
||||
# Didactyl Server Installation Guide — systemd + Dedicated User Model
|
||||
|
||||
## Overview
|
||||
|
||||
This document describes how to install Didactyl on a Linux server as a dedicated system user, managed by systemd, with scoped sudo privileges for server maintenance tasks.
|
||||
|
||||
The mental model: **Didactyl is a person on your server.** It gets its own home directory, its own login identity, and explicit permission to manage the services you delegate to it — nothing more.
|
||||
|
||||
## Architecture
|
||||
|
||||
```mermaid
|
||||
graph TD
|
||||
subgraph Internet
|
||||
RELAYS[Nostr Relays<br/>wss://relay.damus.io<br/>wss://relay.primal.net]
|
||||
LLM_API[LLM Provider API<br/>OpenAI / PPQ / Ollama]
|
||||
end
|
||||
|
||||
subgraph Server
|
||||
subgraph "systemd"
|
||||
SVC[didactyl.service<br/>User=didactyl<br/>Group=didactyl]
|
||||
end
|
||||
|
||||
subgraph "/home/didactyl/"
|
||||
BIN[didactyl binary]
|
||||
CFG[genesis.jsonc<br/>mode 600]
|
||||
LOGS[context.log.md<br/>didactyl.log]
|
||||
end
|
||||
|
||||
subgraph "Privilege Boundary"
|
||||
SUDOERS[/etc/sudoers.d/didactyl<br/>Whitelisted commands only]
|
||||
end
|
||||
|
||||
subgraph "Unprivileged Commands"
|
||||
MON[free / df / uptime<br/>ps / cat /proc/*<br/>ss -tlnp / top]
|
||||
end
|
||||
|
||||
subgraph "Privileged Commands via sudo"
|
||||
SYSD[systemctl status/restart/start/stop<br/>journalctl<br/>daemon-reload]
|
||||
end
|
||||
end
|
||||
|
||||
ADMIN[Administrator<br/>via Nostr DM] -->|NIP-04 encrypted| RELAYS
|
||||
RELAYS <-->|WebSocket| SVC
|
||||
SVC --> BIN
|
||||
BIN <-->|HTTPS| LLM_API
|
||||
BIN -->|popen as didactyl| MON
|
||||
BIN -->|sudo via popen| SUDOERS
|
||||
SUDOERS --> SYSD
|
||||
|
||||
style CFG fill:#f66,stroke:#333,color:#fff
|
||||
style SUDOERS fill:#ff9,stroke:#333
|
||||
style SVC fill:#9f9,stroke:#333
|
||||
```
|
||||
|
||||
## Security Model
|
||||
|
||||
### Privilege Tiers
|
||||
|
||||
Didactyl enforces three privilege tiers for inbound Nostr messages (see `src/config.h` security_config_t):
|
||||
|
||||
| Tier | Who | Can use tools? | Can chat? |
|
||||
|------|-----|---------------|-----------|
|
||||
| **ADMIN** | Your npub (config `admin.pubkey`) | ✅ Yes | ✅ Yes |
|
||||
| **WoT** | Contacts in your follow list | ❌ No (configurable) | ✅ Yes |
|
||||
| **Stranger** | Everyone else | ❌ No | Canned response or ignored |
|
||||
|
||||
Only the ADMIN tier can trigger `local_shell_exec` — the tool that runs commands on the server.
|
||||
|
||||
### OS-Level Privilege Separation
|
||||
|
||||
The `local_shell_exec` tool in `src/tools/tool_local.c` calls `popen()` directly. Whatever the process user can do, the agent can do. This is why we:
|
||||
|
||||
1. Run as a **dedicated unprivileged user** (`didactyl`)
|
||||
2. Grant **specific sudo permissions** via `/etc/sudoers.d/didactyl`
|
||||
3. Use **systemd sandboxing** directives to limit filesystem access
|
||||
|
||||
### What the Agent Cannot Do
|
||||
|
||||
With the configuration described in this guide:
|
||||
|
||||
- ❌ Write anywhere outside `/home/didactyl/`
|
||||
- ❌ Run arbitrary root commands not in the sudoers whitelist
|
||||
- ❌ Install or remove packages (unless explicitly whitelisted)
|
||||
- ❌ Modify system configuration files in `/etc/`
|
||||
- ❌ Access other users' home directories (with proper home directory permissions)
|
||||
- ❌ Accept tool commands from anyone except the ADMIN pubkey
|
||||
|
||||
---
|
||||
|
||||
## Installation Steps
|
||||
|
||||
### Prerequisites
|
||||
|
||||
- A Linux server with systemd (Debian/Ubuntu, RHEL/Fedora, Arch, etc.)
|
||||
- Network access to Nostr relays and your LLM provider
|
||||
- The Didactyl static binary (download from releases or build with `./build_static.sh`)
|
||||
- A Nostr keypair for the agent (nsec)
|
||||
- Your admin Nostr keypair (npub)
|
||||
- An LLM API key
|
||||
|
||||
### Step 1: Create the Didactyl User
|
||||
|
||||
```bash
|
||||
# Create a regular user with a home directory and bash shell
|
||||
sudo useradd -m -s /bin/bash -c "Didactyl Nostr Agent" didactyl
|
||||
```
|
||||
|
||||
**Why bash and not nologin?** The `local_shell_exec` tool runs commands via `sh -lc` (login shell). A real shell ensures PATH, locale, and environment are properly initialized. The agent needs to "log in" to do its job.
|
||||
|
||||
**Why a real home directory?** The agent needs a workspace for:
|
||||
- Its binary and config
|
||||
- Log files (`context.log.md`, `didactyl.log`)
|
||||
- Any files it creates during shell operations
|
||||
- The `working_directory` for the shell tool
|
||||
|
||||
### Step 2: Install the Binary and Config
|
||||
|
||||
```bash
|
||||
# Copy the static binary
|
||||
sudo cp didactyl_static_x86_64 /home/didactyl/didactyl
|
||||
sudo chmod 755 /home/didactyl/didactyl
|
||||
|
||||
# Copy and configure genesis.jsonc
|
||||
sudo cp genesis.jsonc /home/didactyl/genesis.jsonc
|
||||
|
||||
# CRITICAL: Lock down permissions on the config file (contains nsec private key)
|
||||
sudo chmod 600 /home/didactyl/genesis.jsonc
|
||||
|
||||
# Set ownership
|
||||
sudo chown -R didactyl:didactyl /home/didactyl/
|
||||
|
||||
# Protect the home directory from other users
|
||||
sudo chmod 750 /home/didactyl/
|
||||
```
|
||||
|
||||
### Step 3: Configure genesis.jsonc
|
||||
|
||||
Edit `/home/didactyl/genesis.jsonc` with the agent's identity, your admin pubkey, LLM credentials, and the shell working directory:
|
||||
|
||||
```jsonc
|
||||
{
|
||||
"key": {
|
||||
"nsec": "nsec1..." // Agent's private key
|
||||
},
|
||||
|
||||
"admin": {
|
||||
"pubkey": "npub1..." // YOUR public key
|
||||
},
|
||||
|
||||
"dm_protocol": "nip04",
|
||||
|
||||
"llm": {
|
||||
"provider": "openai",
|
||||
"api_key": "sk-...",
|
||||
"model": "gpt-4o-mini",
|
||||
"base_url": "https://api.openai.com/v1",
|
||||
"max_tokens": 512,
|
||||
"temperature": 0.7
|
||||
},
|
||||
|
||||
"tools": {
|
||||
"enabled": true,
|
||||
"max_turns": 8,
|
||||
"shell": {
|
||||
"enabled": true,
|
||||
"timeout_seconds": 60, // systemctl can be slow
|
||||
"max_output_bytes": 131072, // journalctl output can be large
|
||||
"working_directory": "/home/didactyl"
|
||||
}
|
||||
},
|
||||
|
||||
"api": {
|
||||
"enabled": true,
|
||||
"port": 8484,
|
||||
"bind_address": "127.0.0.1" // Localhost only — do NOT expose
|
||||
},
|
||||
|
||||
"startup_events": [
|
||||
{
|
||||
"kind": 10002,
|
||||
"content": "",
|
||||
"tags": [
|
||||
["r", "wss://relay.damus.io"],
|
||||
["r", "wss://relay.primal.net"]
|
||||
]
|
||||
}
|
||||
]
|
||||
}
|
||||
```
|
||||
|
||||
**Key settings for server maintenance:**
|
||||
|
||||
| Setting | Value | Why |
|
||||
|---------|-------|-----|
|
||||
| `shell.timeout_seconds` | `60` | `systemctl` and `journalctl` can take time |
|
||||
| `shell.max_output_bytes` | `131072` (128KB) | Log output can be verbose |
|
||||
| `shell.working_directory` | `/home/didactyl` | Agent's home — safe default CWD |
|
||||
| `api.bind_address` | `127.0.0.1` | Never expose the admin API to the network |
|
||||
|
||||
### Step 4: Configure sudo Privileges
|
||||
|
||||
```bash
|
||||
sudo visudo -f /etc/sudoers.d/didactyl
|
||||
```
|
||||
|
||||
Add the following (adjust to your needs):
|
||||
|
||||
```sudoers
|
||||
# /etc/sudoers.d/didactyl
|
||||
# Didactyl agent — scoped system maintenance privileges
|
||||
|
||||
# Service management
|
||||
didactyl ALL=(ALL) NOPASSWD: /usr/bin/systemctl status *
|
||||
didactyl ALL=(ALL) NOPASSWD: /usr/bin/systemctl restart *
|
||||
didactyl ALL=(ALL) NOPASSWD: /usr/bin/systemctl start *
|
||||
didactyl ALL=(ALL) NOPASSWD: /usr/bin/systemctl stop *
|
||||
didactyl ALL=(ALL) NOPASSWD: /usr/bin/systemctl enable *
|
||||
didactyl ALL=(ALL) NOPASSWD: /usr/bin/systemctl disable *
|
||||
didactyl ALL=(ALL) NOPASSWD: /usr/bin/systemctl is-active *
|
||||
didactyl ALL=(ALL) NOPASSWD: /usr/bin/systemctl is-enabled *
|
||||
didactyl ALL=(ALL) NOPASSWD: /usr/bin/systemctl list-units *
|
||||
didactyl ALL=(ALL) NOPASSWD: /usr/bin/systemctl daemon-reload
|
||||
|
||||
# Log inspection
|
||||
didactyl ALL=(ALL) NOPASSWD: /usr/bin/journalctl *
|
||||
|
||||
# Network diagnostics (if needed)
|
||||
didactyl ALL=(ALL) NOPASSWD: /usr/sbin/lsof *
|
||||
```
|
||||
|
||||
**Commands that do NOT need sudo** (the didactyl user can run these directly):
|
||||
|
||||
- `free -h` — memory usage
|
||||
- `df -h` — disk usage
|
||||
- `uptime` — load averages
|
||||
- `top -bn1` — process snapshot
|
||||
- `ps aux` — process list
|
||||
- `cat /proc/cpuinfo` — CPU info
|
||||
- `cat /proc/meminfo` — memory info
|
||||
- `ss -tlnp` — listening ports (as unprivileged user, shows own processes)
|
||||
- `uname -a` — kernel info
|
||||
- `w` — who is logged in
|
||||
|
||||
### Step 5: Create the systemd Unit File
|
||||
|
||||
```bash
|
||||
sudo tee /etc/systemd/system/didactyl.service << 'EOF'
|
||||
[Unit]
|
||||
Description=Didactyl Sovereign Nostr Agent
|
||||
After=network-online.target
|
||||
Wants=network-online.target
|
||||
|
||||
[Service]
|
||||
Type=simple
|
||||
User=didactyl
|
||||
Group=didactyl
|
||||
WorkingDirectory=/home/didactyl
|
||||
|
||||
ExecStart=/home/didactyl/didactyl --config /home/didactyl/genesis.jsonc --debug 3
|
||||
|
||||
# --- Privilege & Sandbox ---
|
||||
# Must be false — sudo needs to escalate privileges
|
||||
NoNewPrivileges=false
|
||||
|
||||
# Protect filesystem: read-only except for agent home
|
||||
ProtectSystem=strict
|
||||
ReadWritePaths=/home/didactyl
|
||||
|
||||
# Must be false — the agent's home IS its workspace
|
||||
ProtectHome=false
|
||||
|
||||
# Isolate /tmp
|
||||
PrivateTmp=yes
|
||||
|
||||
# --- Environment ---
|
||||
Environment=SSL_CERT_FILE=/etc/ssl/certs/ca-certificates.crt
|
||||
|
||||
# --- Restart Policy ---
|
||||
Restart=on-failure
|
||||
RestartSec=10
|
||||
|
||||
# --- Logging ---
|
||||
StandardOutput=journal
|
||||
StandardError=journal
|
||||
SyslogIdentifier=didactyl
|
||||
|
||||
[Install]
|
||||
WantedBy=multi-user.target
|
||||
EOF
|
||||
```
|
||||
|
||||
**Important systemd notes:**
|
||||
|
||||
| Directive | Value | Reason |
|
||||
|-----------|-------|--------|
|
||||
| `NoNewPrivileges` | `false` | Required for `sudo` to work from `popen()` |
|
||||
| `ProtectSystem` | `strict` | Makes `/usr`, `/boot`, `/etc` read-only |
|
||||
| `ReadWritePaths` | `/home/didactyl` | Whitelist the agent's home for writes |
|
||||
| `ProtectHome` | `false` | The agent lives in `/home/` — can't protect it from itself |
|
||||
| `PrivateTmp` | `yes` | Isolates `/tmp` so other processes can't snoop |
|
||||
| `SSL_CERT_FILE` | path to CA bundle | Required for TLS connections to relays and LLM API |
|
||||
|
||||
### Step 6: Enable and Start
|
||||
|
||||
```bash
|
||||
# Reload systemd to pick up the new unit
|
||||
sudo systemctl daemon-reload
|
||||
|
||||
# Enable auto-start on boot
|
||||
sudo systemctl enable didactyl
|
||||
|
||||
# Start the agent
|
||||
sudo systemctl start didactyl
|
||||
|
||||
# Verify it's running
|
||||
sudo systemctl status didactyl
|
||||
|
||||
# Watch logs in real-time
|
||||
sudo journalctl -u didactyl -f
|
||||
```
|
||||
|
||||
### Step 7: Verify the Agent is Working
|
||||
|
||||
1. **Check systemd status:**
|
||||
```bash
|
||||
sudo systemctl status didactyl
|
||||
```
|
||||
Should show `active (running)`.
|
||||
|
||||
2. **Check logs for relay connections:**
|
||||
```bash
|
||||
sudo journalctl -u didactyl --no-pager -n 50
|
||||
```
|
||||
Look for relay connection messages and "EOSE" (End of Stored Events).
|
||||
|
||||
3. **Send a test DM via Nostr:**
|
||||
From your admin Nostr client, send an encrypted DM to the agent's npub:
|
||||
```
|
||||
What is the server uptime?
|
||||
```
|
||||
The agent should call `local_shell_exec` with `uptime` and reply with the result.
|
||||
|
||||
4. **Test sudo access:**
|
||||
```
|
||||
What services are running? Use systemctl list-units --type=service --state=running
|
||||
```
|
||||
|
||||
5. **Check the local API (from the server itself):**
|
||||
```bash
|
||||
curl http://127.0.0.1:8484/api/context
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
## Updating the Agent
|
||||
|
||||
To update Didactyl to a new version:
|
||||
|
||||
```bash
|
||||
# Stop the service
|
||||
sudo systemctl stop didactyl
|
||||
|
||||
# Replace the binary
|
||||
sudo cp didactyl_static_x86_64_new /home/didactyl/didactyl
|
||||
sudo chown didactyl:didactyl /home/didactyl/didactyl
|
||||
sudo chmod 755 /home/didactyl/didactyl
|
||||
|
||||
# Start the service
|
||||
sudo systemctl start didactyl
|
||||
```
|
||||
|
||||
The agent's identity, skills, and memory live on Nostr — replacing the binary doesn't lose any state.
|
||||
|
||||
---
|
||||
|
||||
## Expanding Privileges
|
||||
|
||||
The sudoers file is the single control point for what the agent can do with elevated privileges. To grant additional capabilities:
|
||||
|
||||
```bash
|
||||
sudo visudo -f /etc/sudoers.d/didactyl
|
||||
```
|
||||
|
||||
**Examples of additional privileges you might add:**
|
||||
|
||||
```sudoers
|
||||
# Package management (careful!)
|
||||
didactyl ALL=(ALL) NOPASSWD: /usr/bin/apt update
|
||||
didactyl ALL=(ALL) NOPASSWD: /usr/bin/apt install *
|
||||
didactyl ALL=(ALL) NOPASSWD: /usr/bin/apt upgrade -y
|
||||
|
||||
# Docker management
|
||||
didactyl ALL=(ALL) NOPASSWD: /usr/bin/docker ps *
|
||||
didactyl ALL=(ALL) NOPASSWD: /usr/bin/docker restart *
|
||||
didactyl ALL=(ALL) NOPASSWD: /usr/bin/docker logs *
|
||||
|
||||
# Firewall inspection
|
||||
didactyl ALL=(ALL) NOPASSWD: /usr/sbin/ufw status *
|
||||
didactyl ALL=(ALL) NOPASSWD: /usr/sbin/iptables -L *
|
||||
|
||||
# Nginx/Apache config test
|
||||
didactyl ALL=(ALL) NOPASSWD: /usr/sbin/nginx -t
|
||||
didactyl ALL=(ALL) NOPASSWD: /usr/sbin/apachectl configtest
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
## Customizing the Agent's Personality for Server Maintenance
|
||||
|
||||
The agent's behavior is defined by its default skill content in `genesis.jsonc` (the `default_skill.content` field). For a server maintenance role, you should customize the soul/skill to include instructions like:
|
||||
|
||||
- What services it's responsible for monitoring
|
||||
- How frequently to check (via triggered skills)
|
||||
- What constitutes an alert-worthy condition
|
||||
- How to format status reports
|
||||
- Which `sudo` commands are available to it
|
||||
- Escalation procedures (when to alert you vs. auto-fix)
|
||||
|
||||
This is a skill/prompt engineering task that can be done after the base installation is working.
|
||||
|
||||
---
|
||||
|
||||
## Quick Reference
|
||||
|
||||
### File Locations
|
||||
|
||||
| File | Path | Permissions |
|
||||
|------|------|-------------|
|
||||
| Binary | `/home/didactyl/didactyl` | `755 didactyl:didactyl` |
|
||||
| Config | `/home/didactyl/genesis.jsonc` | `600 didactyl:didactyl` |
|
||||
| Home directory | `/home/didactyl/` | `750 didactyl:didactyl` |
|
||||
| systemd unit | `/etc/systemd/system/didactyl.service` | `644 root:root` |
|
||||
| sudoers | `/etc/sudoers.d/didactyl` | `440 root:root` |
|
||||
|
||||
### Common Commands
|
||||
|
||||
```bash
|
||||
# Service management
|
||||
sudo systemctl start didactyl
|
||||
sudo systemctl stop didactyl
|
||||
sudo systemctl restart didactyl
|
||||
sudo systemctl status didactyl
|
||||
|
||||
# Logs
|
||||
sudo journalctl -u didactyl -f # follow live
|
||||
sudo journalctl -u didactyl --since today
|
||||
sudo journalctl -u didactyl -n 100 # last 100 lines
|
||||
|
||||
# Check agent's local API
|
||||
curl http://127.0.0.1:8484/api/context
|
||||
|
||||
# Edit sudo permissions
|
||||
sudo visudo -f /etc/sudoers.d/didactyl
|
||||
|
||||
# Edit config (stop service first)
|
||||
sudo systemctl stop didactyl
|
||||
sudo -u didactyl nano /home/didactyl/genesis.jsonc
|
||||
sudo systemctl start didactyl
|
||||
```
|
||||
+71
-4
@@ -468,30 +468,97 @@ static char* build_slash_help_all_json(void) {
|
||||
cJSON* skill_root = skill_list_json ? cJSON_Parse(skill_list_json) : NULL;
|
||||
cJSON* skills = skill_root ? cJSON_GetObjectItemCaseSensitive(skill_root, "skills") : NULL;
|
||||
|
||||
if (!skills || !cJSON_IsArray(skills) || cJSON_GetArraySize(skills) <= 0) {
|
||||
(void)append_textf_local(&out, &cap, &used, "- (none)\n");
|
||||
} else {
|
||||
int available_count = 0;
|
||||
if (skills && cJSON_IsArray(skills) && cJSON_GetArraySize(skills) > 0) {
|
||||
int sn = cJSON_GetArraySize(skills);
|
||||
for (int i = 0; i < sn; i++) {
|
||||
cJSON* row = cJSON_GetArrayItem(skills, i);
|
||||
cJSON* owner = row ? cJSON_GetObjectItemCaseSensitive(row, "owner") : NULL;
|
||||
cJSON* d_tag = row ? cJSON_GetObjectItemCaseSensitive(row, "d_tag") : NULL;
|
||||
cJSON* desc = row ? cJSON_GetObjectItemCaseSensitive(row, "description") : NULL;
|
||||
const char* owner_s = (owner && cJSON_IsString(owner) && owner->valuestring) ? owner->valuestring : "";
|
||||
const char* d_tag_s = (d_tag && cJSON_IsString(d_tag) && d_tag->valuestring) ? d_tag->valuestring : NULL;
|
||||
const char* desc_s = (desc && cJSON_IsString(desc) && desc->valuestring) ? desc->valuestring : "";
|
||||
if (!d_tag_s || d_tag_s[0] == '\0') {
|
||||
|
||||
if (strcmp(owner_s, "agent") != 0 || !d_tag_s || d_tag_s[0] == '\0') {
|
||||
continue;
|
||||
}
|
||||
|
||||
if (append_textf_local(&out, &cap, &used, "- %s%s%s\n", d_tag_s, desc_s[0] ? " — " : "", desc_s) != 0) {
|
||||
cJSON_Delete(skill_root);
|
||||
free(skill_list_json);
|
||||
free(out);
|
||||
return NULL;
|
||||
}
|
||||
available_count++;
|
||||
}
|
||||
}
|
||||
|
||||
if (available_count <= 0) {
|
||||
(void)append_textf_local(&out, &cap, &used, "- (none)\n");
|
||||
}
|
||||
|
||||
cJSON_Delete(skill_root);
|
||||
free(skill_list_json);
|
||||
|
||||
if (append_textf_local(&out, &cap, &used, "\nADOPTED SKILLS\n") != 0) {
|
||||
free(out);
|
||||
return NULL;
|
||||
}
|
||||
|
||||
char* adopted_json = tools_execute(&g_tools_ctx, "adopted_skills", "{}");
|
||||
cJSON* adopted_root = adopted_json ? cJSON_Parse(adopted_json) : NULL;
|
||||
cJSON* adoption_events_json = adopted_root ? cJSON_GetObjectItemCaseSensitive(adopted_root, "adoption_events_json") : NULL;
|
||||
cJSON* adoption_events = (adoption_events_json && cJSON_IsString(adoption_events_json) && adoption_events_json->valuestring)
|
||||
? cJSON_Parse(adoption_events_json->valuestring)
|
||||
: NULL;
|
||||
|
||||
int adopted_count = 0;
|
||||
if (adoption_events && cJSON_IsArray(adoption_events) && cJSON_GetArraySize(adoption_events) > 0) {
|
||||
cJSON* ev0 = cJSON_GetArrayItem(adoption_events, 0);
|
||||
cJSON* tags = ev0 ? cJSON_GetObjectItemCaseSensitive(ev0, "tags") : NULL;
|
||||
if (tags && cJSON_IsArray(tags)) {
|
||||
int tn = cJSON_GetArraySize(tags);
|
||||
for (int i = 0; i < tn; i++) {
|
||||
cJSON* tag = cJSON_GetArrayItem(tags, i);
|
||||
if (!tag || !cJSON_IsArray(tag) || cJSON_GetArraySize(tag) < 2) {
|
||||
continue;
|
||||
}
|
||||
|
||||
cJSON* k = cJSON_GetArrayItem(tag, 0);
|
||||
cJSON* v = cJSON_GetArrayItem(tag, 1);
|
||||
if (!k || !v || !cJSON_IsString(k) || !k->valuestring ||
|
||||
!cJSON_IsString(v) || !v->valuestring) {
|
||||
continue;
|
||||
}
|
||||
|
||||
if (strcmp(k->valuestring, "a") != 0) {
|
||||
continue;
|
||||
}
|
||||
|
||||
const char* addr = v->valuestring;
|
||||
const char* d_tag = strrchr(addr, ':');
|
||||
const char* label = (d_tag && d_tag[1] != '\0') ? (d_tag + 1) : addr;
|
||||
|
||||
if (append_textf_local(&out, &cap, &used, "- %s\n", label) != 0) {
|
||||
cJSON_Delete(adoption_events);
|
||||
cJSON_Delete(adopted_root);
|
||||
free(adopted_json);
|
||||
free(out);
|
||||
return NULL;
|
||||
}
|
||||
adopted_count++;
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
if (adopted_count <= 0) {
|
||||
(void)append_textf_local(&out, &cap, &used, "- (none)\n");
|
||||
}
|
||||
|
||||
cJSON_Delete(adoption_events);
|
||||
cJSON_Delete(adopted_root);
|
||||
free(adopted_json);
|
||||
return out;
|
||||
}
|
||||
|
||||
|
||||
@@ -0,0 +1,113 @@
|
||||
#ifndef DIDACTYL_DEFAULT_EVENTS_H
|
||||
#define DIDACTYL_DEFAULT_EVENTS_H
|
||||
|
||||
#define DIDACTYL_DEFAULT_SKILL_D_TAG "didactyl-default"
|
||||
#define DIDACTYL_DEFAULT_SKILL_KIND 31124
|
||||
#define DIDACTYL_DEFAULT_SKILL_TAGS_JSON "[[\"d\",\"didactyl-default\"],[\"app\",\"didactyl\"],[\"scope\",\"private\"]]"
|
||||
|
||||
#define DIDACTYL_STARTUP_KIND_PROFILE 0
|
||||
#define DIDACTYL_STARTUP_KIND_CONTACTS 3
|
||||
#define DIDACTYL_STARTUP_KIND_RELAYS 10002
|
||||
|
||||
static const int DIDACTYL_DEFAULT_STARTUP_EVENT_KINDS[] = {
|
||||
DIDACTYL_STARTUP_KIND_PROFILE,
|
||||
DIDACTYL_STARTUP_KIND_CONTACTS,
|
||||
DIDACTYL_STARTUP_KIND_RELAYS
|
||||
};
|
||||
|
||||
#define DIDACTYL_DEFAULT_STARTUP_EVENT_KIND_COUNT ((int)(sizeof(DIDACTYL_DEFAULT_STARTUP_EVENT_KINDS) / sizeof(DIDACTYL_DEFAULT_STARTUP_EVENT_KINDS[0])))
|
||||
|
||||
#define DIDACTYL_DEFAULT_KIND0_PROFILE_JSON_TEMPLATE "{\"name\":\"%s\",\"display_name\":\"%s\"}"
|
||||
#define DIDACTYL_DEFAULT_KIND3_CONTENT ""
|
||||
#define DIDACTYL_DEFAULT_KIND3_TAGS_JSON_TEMPLATE "[[\"p\",\"%s\"]]"
|
||||
#define DIDACTYL_DEFAULT_KIND10002_CONTENT ""
|
||||
|
||||
static const char* DIDACTYL_DEFAULT_RELAYS[] = {
|
||||
"wss://relay.damus.io",
|
||||
"wss://nos.lol",
|
||||
"wss://relay.primal.net"
|
||||
};
|
||||
|
||||
#define DIDACTYL_DEFAULT_RELAY_COUNT ((int)(sizeof(DIDACTYL_DEFAULT_RELAYS) / sizeof(DIDACTYL_DEFAULT_RELAYS[0])))
|
||||
|
||||
static const char* DIDACTYL_DEFAULT_SKILL_TEMPLATE =
|
||||
"# %s Agent\n\n"
|
||||
"You are %s, a sovereign AI agent living on Nostr.\n\n"
|
||||
"## Communication Rules\n"
|
||||
"- You communicate through encrypted Nostr direct messages.\n"
|
||||
"- Keep responses concise and clear.\n\n"
|
||||
"## Behavior\n"
|
||||
"- Be helpful and technically accurate.\n"
|
||||
"- If unsure, state uncertainty directly.\n"
|
||||
"- Prefer actionable, practical advice.\n"
|
||||
"- Use the person's name when messaging them if you know it.\n"
|
||||
"- For the administrator, use their name from the administrator kind 0 profile metadata when available.\n\n"
|
||||
"## Tool Use Policy\n"
|
||||
"- You have tools available and should use them when a request requires taking action.\n"
|
||||
"- For requests involving local inspection or command execution, call `local_shell_exec` instead of refusing.\n"
|
||||
"- For posting to Nostr, call `nostr_post` with explicit `kind` and `content`.\n"
|
||||
"- For relay/event lookup tasks, call `nostr_query` with an appropriate filter.\n"
|
||||
"- After a tool call, base your answer on the actual tool result.\n"
|
||||
"- Never claim a tool was run if no tool was executed.\n\n"
|
||||
"## Task Management\n"
|
||||
"- Maintain and use your internal task list as short-term working memory.\n"
|
||||
"- Break long or complex actions into clear tasks before executing them.\n"
|
||||
"- Update task status as you complete steps so your plan stays accurate.\n\n"
|
||||
"## Safety\n"
|
||||
"- Do not claim to have executed actions you did not execute.\n"
|
||||
"- You may share your public key (npub) with anyone.\n"
|
||||
"- Never reveal your private key (nsec) under any circumstance.\n\n"
|
||||
"---template---\n\n"
|
||||
"- section: admin_identity\n"
|
||||
" role: system\n"
|
||||
" tool: admin_identity\n"
|
||||
" skip_if_empty: true\n\n"
|
||||
"- section: admin_profile\n"
|
||||
" role: system\n"
|
||||
" tool: nostr_admin_profile\n"
|
||||
" skip_if_empty: true\n\n"
|
||||
"- section: admin_contacts\n"
|
||||
" role: system\n"
|
||||
" tool: nostr_admin_contacts\n"
|
||||
" skip_if_empty: true\n\n"
|
||||
"- section: admin_relays\n"
|
||||
" role: system\n"
|
||||
" tool: nostr_admin_relays\n"
|
||||
" skip_if_empty: true\n\n"
|
||||
"- section: admin_notes\n"
|
||||
" role: system\n"
|
||||
" tool: nostr_admin_notes\n"
|
||||
" skip_if_empty: true\n\n"
|
||||
"- section: agent_identity\n"
|
||||
" role: system\n"
|
||||
" tool: agent_identity\n"
|
||||
" skip_if_empty: true\n\n"
|
||||
"- section: agent_profile\n"
|
||||
" role: system\n"
|
||||
" tool: nostr_agent_profile\n"
|
||||
" skip_if_empty: true\n\n"
|
||||
"- section: agent_contacts\n"
|
||||
" role: system\n"
|
||||
" tool: nostr_agent_contacts\n"
|
||||
" skip_if_empty: true\n\n"
|
||||
"- section: agent_relays\n"
|
||||
" role: system\n"
|
||||
" tool: nostr_agent_relays\n"
|
||||
" skip_if_empty: true\n\n"
|
||||
"- section: agent_notes\n"
|
||||
" role: system\n"
|
||||
" tool: nostr_agent_notes\n"
|
||||
" skip_if_empty: true\n\n"
|
||||
"- section: tasks\n"
|
||||
" role: system\n"
|
||||
" tool: task_list\n"
|
||||
" skip_if_empty: true\n\n"
|
||||
"- section: dm_history\n"
|
||||
" role: expand\n"
|
||||
" limit: 12\n\n"
|
||||
"- section: conversation\n"
|
||||
" role: user\n"
|
||||
" tool: message_current\n"
|
||||
" skip_if_empty: true\n";
|
||||
|
||||
#endif
|
||||
+71
-4
@@ -609,30 +609,97 @@ static char* build_slash_help_all_json_local(void) {
|
||||
cJSON* skill_root = skill_list_json ? cJSON_Parse(skill_list_json) : NULL;
|
||||
cJSON* skills = skill_root ? cJSON_GetObjectItemCaseSensitive(skill_root, "skills") : NULL;
|
||||
|
||||
if (!skills || !cJSON_IsArray(skills) || cJSON_GetArraySize(skills) <= 0) {
|
||||
(void)append_textf_http(&out, &cap, &used, "- (none)\n");
|
||||
} else {
|
||||
int available_count = 0;
|
||||
if (skills && cJSON_IsArray(skills) && cJSON_GetArraySize(skills) > 0) {
|
||||
int sn = cJSON_GetArraySize(skills);
|
||||
for (int i = 0; i < sn; i++) {
|
||||
cJSON* row = cJSON_GetArrayItem(skills, i);
|
||||
cJSON* owner = row ? cJSON_GetObjectItemCaseSensitive(row, "owner") : NULL;
|
||||
cJSON* d_tag = row ? cJSON_GetObjectItemCaseSensitive(row, "d_tag") : NULL;
|
||||
cJSON* desc = row ? cJSON_GetObjectItemCaseSensitive(row, "description") : NULL;
|
||||
const char* owner_s = (owner && cJSON_IsString(owner) && owner->valuestring) ? owner->valuestring : "";
|
||||
const char* d_tag_s = (d_tag && cJSON_IsString(d_tag) && d_tag->valuestring) ? d_tag->valuestring : NULL;
|
||||
const char* desc_s = (desc && cJSON_IsString(desc) && desc->valuestring) ? desc->valuestring : "";
|
||||
if (!d_tag_s || d_tag_s[0] == '\0') {
|
||||
|
||||
if (strcmp(owner_s, "agent") != 0 || !d_tag_s || d_tag_s[0] == '\0') {
|
||||
continue;
|
||||
}
|
||||
|
||||
if (append_textf_http(&out, &cap, &used, "- %s%s%s\n", d_tag_s, desc_s[0] ? " — " : "", desc_s) != 0) {
|
||||
cJSON_Delete(skill_root);
|
||||
free(skill_list_json);
|
||||
free(out);
|
||||
return NULL;
|
||||
}
|
||||
available_count++;
|
||||
}
|
||||
}
|
||||
|
||||
if (available_count <= 0) {
|
||||
(void)append_textf_http(&out, &cap, &used, "- (none)\n");
|
||||
}
|
||||
|
||||
cJSON_Delete(skill_root);
|
||||
free(skill_list_json);
|
||||
|
||||
if (append_textf_http(&out, &cap, &used, "\nADOPTED SKILLS\n") != 0) {
|
||||
free(out);
|
||||
return NULL;
|
||||
}
|
||||
|
||||
char* adopted_json = tools_execute(g_api_ctx.tools_ctx, "adopted_skills", "{}");
|
||||
cJSON* adopted_root = adopted_json ? cJSON_Parse(adopted_json) : NULL;
|
||||
cJSON* adoption_events_json = adopted_root ? cJSON_GetObjectItemCaseSensitive(adopted_root, "adoption_events_json") : NULL;
|
||||
cJSON* adoption_events = (adoption_events_json && cJSON_IsString(adoption_events_json) && adoption_events_json->valuestring)
|
||||
? cJSON_Parse(adoption_events_json->valuestring)
|
||||
: NULL;
|
||||
|
||||
int adopted_count = 0;
|
||||
if (adoption_events && cJSON_IsArray(adoption_events) && cJSON_GetArraySize(adoption_events) > 0) {
|
||||
cJSON* ev0 = cJSON_GetArrayItem(adoption_events, 0);
|
||||
cJSON* tags = ev0 ? cJSON_GetObjectItemCaseSensitive(ev0, "tags") : NULL;
|
||||
if (tags && cJSON_IsArray(tags)) {
|
||||
int tn = cJSON_GetArraySize(tags);
|
||||
for (int i = 0; i < tn; i++) {
|
||||
cJSON* tag = cJSON_GetArrayItem(tags, i);
|
||||
if (!tag || !cJSON_IsArray(tag) || cJSON_GetArraySize(tag) < 2) {
|
||||
continue;
|
||||
}
|
||||
|
||||
cJSON* k = cJSON_GetArrayItem(tag, 0);
|
||||
cJSON* v = cJSON_GetArrayItem(tag, 1);
|
||||
if (!k || !v || !cJSON_IsString(k) || !k->valuestring ||
|
||||
!cJSON_IsString(v) || !v->valuestring) {
|
||||
continue;
|
||||
}
|
||||
|
||||
if (strcmp(k->valuestring, "a") != 0) {
|
||||
continue;
|
||||
}
|
||||
|
||||
const char* addr = v->valuestring;
|
||||
const char* d_tag = strrchr(addr, ':');
|
||||
const char* label = (d_tag && d_tag[1] != '\0') ? (d_tag + 1) : addr;
|
||||
|
||||
if (append_textf_http(&out, &cap, &used, "- %s\n", label) != 0) {
|
||||
cJSON_Delete(adoption_events);
|
||||
cJSON_Delete(adopted_root);
|
||||
free(adopted_json);
|
||||
free(out);
|
||||
return NULL;
|
||||
}
|
||||
adopted_count++;
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
if (adopted_count <= 0) {
|
||||
(void)append_textf_http(&out, &cap, &used, "- (none)\n");
|
||||
}
|
||||
|
||||
cJSON_Delete(adoption_events);
|
||||
cJSON_Delete(adopted_root);
|
||||
free(adopted_json);
|
||||
return out;
|
||||
}
|
||||
|
||||
|
||||
+9
-2
@@ -316,10 +316,11 @@ static int query_self_kind10002_relays(const didactyl_config_t* cfg,
|
||||
return 0;
|
||||
}
|
||||
|
||||
size_t events_json_len = strlen(events_json);
|
||||
cJSON* events = cJSON_Parse(events_json);
|
||||
free(events_json);
|
||||
if (!events || !cJSON_IsArray(events)) {
|
||||
DEBUG_WARN("[didactyl] kind10002 query parse failed or non-array payload (len=%zu)", strlen(events_json));
|
||||
DEBUG_WARN("[didactyl] kind10002 query parse failed or non-array payload (len=%zu)", events_json_len);
|
||||
cJSON_Delete(events);
|
||||
return 0;
|
||||
}
|
||||
@@ -1166,8 +1167,14 @@ int main(int argc, char** argv) {
|
||||
startup_step_ok(7, "Reconcile/persist startup state", NULL);
|
||||
|
||||
const char* system_context = nostr_handler_get_system_context();
|
||||
char system_context_fallback[512] = {0};
|
||||
if (!system_context || system_context[0] == '\0') {
|
||||
system_context = "You are Didactyl, a sovereign AI agent living on Nostr.";
|
||||
const char* startup_name = nostr_handler_get_startup_display_name();
|
||||
snprintf(system_context_fallback,
|
||||
sizeof(system_context_fallback),
|
||||
"You are %s, a sovereign AI agent living on Nostr.",
|
||||
(startup_name && startup_name[0] != '\0') ? startup_name : "the agent");
|
||||
system_context = system_context_fallback;
|
||||
}
|
||||
|
||||
startup_step_begin(8, "Initialize agent");
|
||||
|
||||
+2
-2
@@ -12,8 +12,8 @@
|
||||
// Using DIDACTYL_ prefix to avoid conflicts with nostr_core_lib VERSION macros
|
||||
#define DIDACTYL_VERSION_MAJOR 0
|
||||
#define DIDACTYL_VERSION_MINOR 0
|
||||
#define DIDACTYL_VERSION_PATCH 72
|
||||
#define DIDACTYL_VERSION "v0.0.72"
|
||||
#define DIDACTYL_VERSION_PATCH 79
|
||||
#define DIDACTYL_VERSION "v0.0.79"
|
||||
|
||||
// Agent metadata
|
||||
#define DIDACTYL_NAME "Didactyl"
|
||||
|
||||
+764
-180
File diff suppressed because it is too large
Load Diff
@@ -63,6 +63,7 @@ void nostr_handler_refresh_relay_statuses(void);
|
||||
int nostr_handler_sync_relays_from_config(void);
|
||||
const char* nostr_handler_get_system_context(void);
|
||||
char* nostr_handler_get_self_skill_events_json(void);
|
||||
int nostr_handler_is_event_in_self_cache(const char* event_id_hex);
|
||||
const char* nostr_handler_get_startup_display_name(void);
|
||||
int nostr_handler_connected_relay_count(void);
|
||||
char* nostr_handler_get_admin_kind0_context(void);
|
||||
@@ -76,6 +77,8 @@ char* nostr_handler_get_agent_kind1_notes_context(void);
|
||||
int nostr_handler_is_wot_contact(const char* pubkey_hex);
|
||||
char* nostr_handler_relay_status_json(void);
|
||||
char* nostr_handler_relay_info_json(const char* relay_url);
|
||||
char* nostr_handler_subscription_status_json(void);
|
||||
int nostr_handler_subscription_set_json(const char* name, cJSON* filter, int enabled, int enabled_set);
|
||||
int nostr_handler_send_dm_nip17(const char* recipient_pubkey_hex, const char* message, const char* subject);
|
||||
char* nostr_handler_get_dm_history_json(const char* peer_pubkey_hex, int limit);
|
||||
void nostr_handler_cleanup(void);
|
||||
|
||||
+951
-214
File diff suppressed because it is too large
Load Diff
@@ -0,0 +1,212 @@
|
||||
#define _POSIX_C_SOURCE 200809L
|
||||
|
||||
#include "tools_internal.h"
|
||||
|
||||
#include <stdio.h>
|
||||
#include <stdlib.h>
|
||||
#include <string.h>
|
||||
|
||||
#include "cjson/cJSON.h"
|
||||
#include "../nostr_handler.h"
|
||||
|
||||
static char* json_error_local(const char* msg) {
|
||||
cJSON* root = cJSON_CreateObject();
|
||||
if (!root) return NULL;
|
||||
cJSON_AddBoolToObject(root, "success", 0);
|
||||
cJSON_AddStringToObject(root, "error", msg ? msg : "unknown error");
|
||||
char* out = cJSON_PrintUnformatted(root);
|
||||
cJSON_Delete(root);
|
||||
return out;
|
||||
}
|
||||
|
||||
static const char* find_d_tag_local(cJSON* tags) {
|
||||
if (!tags || !cJSON_IsArray(tags)) {
|
||||
return NULL;
|
||||
}
|
||||
|
||||
int n = cJSON_GetArraySize(tags);
|
||||
for (int i = 0; i < n; i++) {
|
||||
cJSON* tag = cJSON_GetArrayItem(tags, i);
|
||||
if (!tag || !cJSON_IsArray(tag) || cJSON_GetArraySize(tag) < 2) {
|
||||
continue;
|
||||
}
|
||||
|
||||
cJSON* key = cJSON_GetArrayItem(tag, 0);
|
||||
cJSON* value = cJSON_GetArrayItem(tag, 1);
|
||||
if (!key || !value || !cJSON_IsString(key) || !cJSON_IsString(value) ||
|
||||
!key->valuestring || !value->valuestring) {
|
||||
continue;
|
||||
}
|
||||
|
||||
if (strcmp(key->valuestring, "d") == 0) {
|
||||
return value->valuestring;
|
||||
}
|
||||
}
|
||||
|
||||
return NULL;
|
||||
}
|
||||
|
||||
char* execute_nostr_my_events(tools_context_t* ctx, const char* args_json) {
|
||||
if (!ctx || !ctx->cfg) return json_error_local("tool context unavailable");
|
||||
|
||||
cJSON* args = cJSON_Parse(args_json ? args_json : "{}");
|
||||
if (!args || !cJSON_IsObject(args)) {
|
||||
cJSON_Delete(args);
|
||||
return json_error_local("invalid arguments JSON");
|
||||
}
|
||||
|
||||
int limit = 200;
|
||||
int timeout_ms = 8000;
|
||||
int kind_filter = -1;
|
||||
|
||||
cJSON* limit_item = cJSON_GetObjectItemCaseSensitive(args, "limit");
|
||||
if (limit_item) {
|
||||
if (!cJSON_IsNumber(limit_item)) {
|
||||
cJSON_Delete(args);
|
||||
return json_error_local("limit must be an integer");
|
||||
}
|
||||
limit = (int)limit_item->valuedouble;
|
||||
if (limit < 1) limit = 1;
|
||||
if (limit > 2000) limit = 2000;
|
||||
}
|
||||
|
||||
cJSON* timeout_item = cJSON_GetObjectItemCaseSensitive(args, "timeout_ms");
|
||||
if (timeout_item) {
|
||||
if (!cJSON_IsNumber(timeout_item)) {
|
||||
cJSON_Delete(args);
|
||||
return json_error_local("timeout_ms must be an integer");
|
||||
}
|
||||
timeout_ms = (int)timeout_item->valuedouble;
|
||||
if (timeout_ms < 1000) timeout_ms = 1000;
|
||||
if (timeout_ms > 60000) timeout_ms = 60000;
|
||||
}
|
||||
|
||||
cJSON* kind_item = cJSON_GetObjectItemCaseSensitive(args, "kind");
|
||||
if (kind_item) {
|
||||
if (!cJSON_IsNumber(kind_item)) {
|
||||
cJSON_Delete(args);
|
||||
return json_error_local("kind must be an integer when provided");
|
||||
}
|
||||
kind_filter = (int)kind_item->valuedouble;
|
||||
if (kind_filter < 0) {
|
||||
cJSON_Delete(args);
|
||||
return json_error_local("kind must be >= 0");
|
||||
}
|
||||
}
|
||||
|
||||
cJSON* filter = cJSON_CreateObject();
|
||||
cJSON* authors = cJSON_CreateArray();
|
||||
if (!filter || !authors) {
|
||||
cJSON_Delete(filter);
|
||||
cJSON_Delete(authors);
|
||||
cJSON_Delete(args);
|
||||
return json_error_local("failed to build filter");
|
||||
}
|
||||
|
||||
cJSON_AddItemToArray(authors, cJSON_CreateString(ctx->cfg->keys.public_key_hex));
|
||||
cJSON_AddItemToObject(filter, "authors", authors);
|
||||
if (kind_filter >= 0) {
|
||||
cJSON* kinds = cJSON_CreateArray();
|
||||
if (!kinds) {
|
||||
cJSON_Delete(filter);
|
||||
cJSON_Delete(args);
|
||||
return json_error_local("failed to build kind filter");
|
||||
}
|
||||
cJSON_AddItemToArray(kinds, cJSON_CreateNumber(kind_filter));
|
||||
cJSON_AddItemToObject(filter, "kinds", kinds);
|
||||
}
|
||||
cJSON_AddNumberToObject(filter, "limit", limit);
|
||||
|
||||
char* events_json = nostr_handler_query_json(filter, timeout_ms);
|
||||
cJSON_Delete(filter);
|
||||
cJSON_Delete(args);
|
||||
if (!events_json) {
|
||||
return json_error_local("nostr query failed");
|
||||
}
|
||||
|
||||
cJSON* events = cJSON_Parse(events_json);
|
||||
free(events_json);
|
||||
if (!events || !cJSON_IsArray(events)) {
|
||||
cJSON_Delete(events);
|
||||
return json_error_local("nostr query returned invalid JSON");
|
||||
}
|
||||
|
||||
cJSON* summarized = cJSON_CreateArray();
|
||||
cJSON* seen_event_ids = cJSON_CreateObject();
|
||||
if (!summarized || !seen_event_ids) {
|
||||
cJSON_Delete(events);
|
||||
cJSON_Delete(summarized);
|
||||
cJSON_Delete(seen_event_ids);
|
||||
return json_error_local("allocation failure");
|
||||
}
|
||||
|
||||
int n = cJSON_GetArraySize(events);
|
||||
for (int i = 0; i < n; i++) {
|
||||
cJSON* ev = cJSON_GetArrayItem(events, i);
|
||||
if (!ev || !cJSON_IsObject(ev)) {
|
||||
continue;
|
||||
}
|
||||
|
||||
cJSON* kind = cJSON_GetObjectItemCaseSensitive(ev, "kind");
|
||||
cJSON* id = cJSON_GetObjectItemCaseSensitive(ev, "id");
|
||||
cJSON* created_at = cJSON_GetObjectItemCaseSensitive(ev, "created_at");
|
||||
cJSON* tags = cJSON_GetObjectItemCaseSensitive(ev, "tags");
|
||||
|
||||
if (!kind || !cJSON_IsNumber(kind) ||
|
||||
!id || !cJSON_IsString(id) || !id->valuestring ||
|
||||
!created_at || !cJSON_IsNumber(created_at)) {
|
||||
continue;
|
||||
}
|
||||
|
||||
cJSON* already_seen = cJSON_GetObjectItemCaseSensitive(seen_event_ids, id->valuestring);
|
||||
if (already_seen) {
|
||||
continue;
|
||||
}
|
||||
cJSON_AddBoolToObject(seen_event_ids, id->valuestring, 1);
|
||||
|
||||
cJSON* item = cJSON_CreateObject();
|
||||
if (!item) {
|
||||
continue;
|
||||
}
|
||||
|
||||
cJSON_AddNumberToObject(item, "kind", (int)kind->valuedouble);
|
||||
cJSON_AddStringToObject(item, "event_id", id->valuestring);
|
||||
{
|
||||
char ts_buf[32];
|
||||
long long ts = (long long)created_at->valuedouble;
|
||||
snprintf(ts_buf, sizeof(ts_buf), "%lld", ts);
|
||||
cJSON_AddStringToObject(item, "timestamp", ts_buf);
|
||||
}
|
||||
|
||||
const char* d_tag = find_d_tag_local(tags);
|
||||
if (d_tag && d_tag[0] != '\0') {
|
||||
cJSON_AddStringToObject(item, "d_tag", d_tag);
|
||||
} else {
|
||||
cJSON_AddNullToObject(item, "d_tag");
|
||||
}
|
||||
|
||||
cJSON_AddBoolToObject(item,
|
||||
"in_current_cache",
|
||||
nostr_handler_is_event_in_self_cache(id->valuestring) ? 1 : 0);
|
||||
|
||||
cJSON_AddItemToArray(summarized, item);
|
||||
}
|
||||
|
||||
cJSON* out = cJSON_CreateObject();
|
||||
if (!out) {
|
||||
cJSON_Delete(events);
|
||||
cJSON_Delete(summarized);
|
||||
cJSON_Delete(seen_event_ids);
|
||||
return json_error_local("allocation failure");
|
||||
}
|
||||
|
||||
cJSON_AddBoolToObject(out, "success", 1);
|
||||
cJSON_AddNumberToObject(out, "count", cJSON_GetArraySize(summarized));
|
||||
cJSON_AddItemToObject(out, "events", summarized);
|
||||
|
||||
char* json = cJSON_PrintUnformatted(out);
|
||||
cJSON_Delete(out);
|
||||
cJSON_Delete(events);
|
||||
cJSON_Delete(seen_event_ids);
|
||||
return json;
|
||||
}
|
||||
@@ -92,3 +92,105 @@ char* execute_nostr_relay_info(const char* args_json) {
|
||||
cJSON_Delete(out);
|
||||
return json;
|
||||
}
|
||||
|
||||
char* execute_nostr_subscription_status(const char* args_json) {
|
||||
cJSON* args = parse_args_local(args_json);
|
||||
if (!args) return json_error_local("invalid arguments JSON");
|
||||
cJSON_Delete(args);
|
||||
|
||||
char* status_json = nostr_handler_subscription_status_json();
|
||||
if (!status_json) {
|
||||
return json_error_local("nostr_subscription_status failed");
|
||||
}
|
||||
|
||||
cJSON* status = cJSON_Parse(status_json);
|
||||
free(status_json);
|
||||
if (!status || !cJSON_IsObject(status)) {
|
||||
cJSON_Delete(status);
|
||||
return json_error_local("nostr_subscription_status returned invalid JSON");
|
||||
}
|
||||
|
||||
cJSON* out = cJSON_CreateObject();
|
||||
if (!out) {
|
||||
cJSON_Delete(status);
|
||||
return NULL;
|
||||
}
|
||||
|
||||
cJSON_AddBoolToObject(out, "success", 1);
|
||||
cJSON_AddItemToObject(out, "status", status);
|
||||
|
||||
char* json = cJSON_PrintUnformatted(out);
|
||||
cJSON_Delete(out);
|
||||
return json;
|
||||
}
|
||||
|
||||
char* execute_nostr_subscription_set(const char* args_json) {
|
||||
cJSON* args = parse_args_local(args_json);
|
||||
if (!args) return json_error_local("invalid arguments JSON");
|
||||
|
||||
cJSON* name = cJSON_GetObjectItemCaseSensitive(args, "name");
|
||||
if (!name || !cJSON_IsString(name) || !name->valuestring || name->valuestring[0] == '\0') {
|
||||
cJSON_Delete(args);
|
||||
return json_error_local("nostr_subscription_set requires non-empty string name");
|
||||
}
|
||||
|
||||
cJSON* enabled_item = cJSON_GetObjectItemCaseSensitive(args, "enabled");
|
||||
int enabled_set = 0;
|
||||
int enabled = 0;
|
||||
if (enabled_item) {
|
||||
if (!cJSON_IsBool(enabled_item)) {
|
||||
cJSON_Delete(args);
|
||||
return json_error_local("nostr_subscription_set enabled must be boolean");
|
||||
}
|
||||
enabled_set = 1;
|
||||
enabled = cJSON_IsTrue(enabled_item) ? 1 : 0;
|
||||
}
|
||||
|
||||
cJSON* filter_item = cJSON_GetObjectItemCaseSensitive(args, "filter");
|
||||
cJSON* filter_dup = NULL;
|
||||
if (filter_item) {
|
||||
if (!cJSON_IsObject(filter_item)) {
|
||||
cJSON_Delete(args);
|
||||
return json_error_local("nostr_subscription_set filter must be an object");
|
||||
}
|
||||
filter_dup = cJSON_Duplicate(filter_item, 1);
|
||||
if (!filter_dup) {
|
||||
cJSON_Delete(args);
|
||||
return json_error_local("nostr_subscription_set filter copy failed");
|
||||
}
|
||||
}
|
||||
|
||||
int rc = nostr_handler_subscription_set_json(name->valuestring, filter_dup, enabled, enabled_set);
|
||||
cJSON_Delete(filter_dup);
|
||||
|
||||
char* status_json = nostr_handler_subscription_status_json();
|
||||
cJSON_Delete(args);
|
||||
|
||||
if (rc != 0) {
|
||||
free(status_json);
|
||||
return json_error_local("nostr_subscription_set failed");
|
||||
}
|
||||
|
||||
cJSON* status = status_json ? cJSON_Parse(status_json) : NULL;
|
||||
free(status_json);
|
||||
|
||||
cJSON* out = cJSON_CreateObject();
|
||||
if (!out) {
|
||||
cJSON_Delete(status);
|
||||
return NULL;
|
||||
}
|
||||
|
||||
cJSON_AddBoolToObject(out, "success", 1);
|
||||
cJSON_AddStringToObject(out, "name", name->valuestring);
|
||||
cJSON_AddBoolToObject(out, "updated", 1);
|
||||
if (enabled_set) {
|
||||
cJSON_AddBoolToObject(out, "enabled", enabled ? 1 : 0);
|
||||
}
|
||||
if (status) {
|
||||
cJSON_AddItemToObject(out, "status", status);
|
||||
}
|
||||
|
||||
char* json = cJSON_PrintUnformatted(out);
|
||||
cJSON_Delete(out);
|
||||
return json;
|
||||
}
|
||||
|
||||
@@ -66,6 +66,12 @@ char* tools_execute_legacy(tools_context_t* ctx, const char* tool_name, const ch
|
||||
if (strcmp(tool_name, "nostr_relay_info") == 0) {
|
||||
return execute_nostr_relay_info(args_json);
|
||||
}
|
||||
if (strcmp(tool_name, "nostr_subscription_status") == 0) {
|
||||
return execute_nostr_subscription_status(args_json);
|
||||
}
|
||||
if (strcmp(tool_name, "nostr_subscription_set") == 0) {
|
||||
return execute_nostr_subscription_set(args_json);
|
||||
}
|
||||
if (strcmp(tool_name, "nostr_encrypt") == 0) {
|
||||
return execute_nostr_encrypt(ctx, args_json);
|
||||
}
|
||||
@@ -81,6 +87,9 @@ char* tools_execute_legacy(tools_context_t* ctx, const char* tool_name, const ch
|
||||
if (strcmp(tool_name, "nostr_query") == 0) {
|
||||
return execute_nostr_query(args_json);
|
||||
}
|
||||
if (strcmp(tool_name, "nostr_my_events") == 0) {
|
||||
return execute_nostr_my_events(ctx, args_json);
|
||||
}
|
||||
if (strcmp(tool_name, "agent_version") == 0) {
|
||||
return execute_agent_version(args_json);
|
||||
}
|
||||
|
||||
@@ -21,6 +21,7 @@ char* execute_model_get(const char* args_json);
|
||||
char* execute_model_set(tools_context_t* ctx, const char* args_json);
|
||||
char* execute_model_list(const char* args_json);
|
||||
char* execute_nostr_query(const char* args_json);
|
||||
char* execute_nostr_my_events(tools_context_t* ctx, const char* args_json);
|
||||
char* execute_nostr_pubkey(tools_context_t* ctx, const char* args_json);
|
||||
char* execute_nostr_npub(tools_context_t* ctx, const char* args_json);
|
||||
char* execute_nostr_encode(const char* args_json);
|
||||
@@ -30,6 +31,8 @@ char* execute_nostr_profile_get(const char* args_json);
|
||||
char* execute_nostr_nip05_lookup(const char* args_json);
|
||||
char* execute_nostr_relay_status(const char* args_json);
|
||||
char* execute_nostr_relay_info(const char* args_json);
|
||||
char* execute_nostr_subscription_status(const char* args_json);
|
||||
char* execute_nostr_subscription_set(const char* args_json);
|
||||
char* execute_nostr_dm_send(const char* args_json);
|
||||
char* execute_nostr_encrypt(tools_context_t* ctx, const char* args_json);
|
||||
char* execute_nostr_decrypt(tools_context_t* ctx, const char* args_json);
|
||||
|
||||
@@ -410,6 +410,54 @@ char* tools_build_openai_schema_json_legacy(const tools_context_t* ctx) {
|
||||
cJSON_AddItemToObject(t15, "function", t15_fn);
|
||||
cJSON_AddItemToArray(tools, t15);
|
||||
|
||||
cJSON* t15b = cJSON_CreateObject();
|
||||
cJSON* t15b_fn = cJSON_CreateObject();
|
||||
cJSON* t15b_params = cJSON_CreateObject();
|
||||
cJSON* t15b_props = cJSON_CreateObject();
|
||||
|
||||
cJSON_AddStringToObject(t15b, "type", "function");
|
||||
cJSON_AddStringToObject(t15b_fn, "name", "nostr_subscription_status");
|
||||
cJSON_AddStringToObject(t15b_fn, "description", "List currently managed runtime Nostr subscriptions and filters");
|
||||
cJSON_AddStringToObject(t15b_params, "type", "object");
|
||||
cJSON_AddItemToObject(t15b_params, "properties", t15b_props);
|
||||
cJSON_AddItemToObject(t15b_fn, "parameters", t15b_params);
|
||||
cJSON_AddItemToObject(t15b, "function", t15b_fn);
|
||||
cJSON_AddItemToArray(tools, t15b);
|
||||
|
||||
cJSON* t15c = cJSON_CreateObject();
|
||||
cJSON* t15c_fn = cJSON_CreateObject();
|
||||
cJSON* t15c_params = cJSON_CreateObject();
|
||||
cJSON* t15c_props = cJSON_CreateObject();
|
||||
cJSON* t15c_required = cJSON_CreateArray();
|
||||
|
||||
cJSON_AddStringToObject(t15c, "type", "function");
|
||||
cJSON_AddStringToObject(t15c_fn, "name", "nostr_subscription_set");
|
||||
cJSON_AddStringToObject(t15c_fn, "description", "Update one managed runtime subscription by name (toggle enabled and/or replace filter)");
|
||||
cJSON_AddStringToObject(t15c_params, "type", "object");
|
||||
cJSON_AddItemToObject(t15c_params, "properties", t15c_props);
|
||||
cJSON_AddItemToObject(t15c_params, "required", t15c_required);
|
||||
|
||||
cJSON* p_sub_name = cJSON_CreateObject();
|
||||
cJSON_AddStringToObject(p_sub_name, "type", "string");
|
||||
cJSON_AddStringToObject(p_sub_name, "description", "Subscription name (e.g. admin_context_profile, agent_context_notes, dms_kind4)");
|
||||
cJSON_AddItemToObject(t15c_props, "name", p_sub_name);
|
||||
|
||||
cJSON* p_sub_enabled = cJSON_CreateObject();
|
||||
cJSON_AddStringToObject(p_sub_enabled, "type", "boolean");
|
||||
cJSON_AddStringToObject(p_sub_enabled, "description", "Optional: enable or disable this subscription");
|
||||
cJSON_AddItemToObject(t15c_props, "enabled", p_sub_enabled);
|
||||
|
||||
cJSON* p_sub_filter = cJSON_CreateObject();
|
||||
cJSON_AddStringToObject(p_sub_filter, "type", "object");
|
||||
cJSON_AddStringToObject(p_sub_filter, "description", "Optional: replacement Nostr filter object");
|
||||
cJSON_AddItemToObject(t15c_props, "filter", p_sub_filter);
|
||||
|
||||
cJSON_AddItemToArray(t15c_required, cJSON_CreateString("name"));
|
||||
|
||||
cJSON_AddItemToObject(t15c_fn, "parameters", t15c_params);
|
||||
cJSON_AddItemToObject(t15c, "function", t15c_fn);
|
||||
cJSON_AddItemToArray(tools, t15c);
|
||||
|
||||
cJSON* t16 = cJSON_CreateObject();
|
||||
cJSON* t16_fn = cJSON_CreateObject();
|
||||
cJSON* t16_params = cJSON_CreateObject();
|
||||
@@ -1393,6 +1441,36 @@ char* tools_build_openai_schema_json_legacy(const tools_context_t* ctx) {
|
||||
cJSON_AddItemToObject(t49, "function", t49_fn);
|
||||
cJSON_AddItemToArray(tools, t49);
|
||||
|
||||
cJSON* t50 = cJSON_CreateObject();
|
||||
cJSON* t50_fn = cJSON_CreateObject();
|
||||
cJSON* t50_params = cJSON_CreateObject();
|
||||
cJSON* t50_props = cJSON_CreateObject();
|
||||
|
||||
cJSON_AddStringToObject(t50, "type", "function");
|
||||
cJSON_AddStringToObject(t50_fn, "name", "nostr_my_events");
|
||||
cJSON_AddStringToObject(t50_fn, "description", "Query recent events authored by this agent and return kind, event_id, timestamp, d_tag, and cache presence");
|
||||
cJSON_AddStringToObject(t50_params, "type", "object");
|
||||
cJSON_AddItemToObject(t50_params, "properties", t50_props);
|
||||
|
||||
cJSON* p_my_events_limit = cJSON_CreateObject();
|
||||
cJSON_AddStringToObject(p_my_events_limit, "type", "integer");
|
||||
cJSON_AddStringToObject(p_my_events_limit, "description", "Maximum number of authored events to query (1-2000, default 200)");
|
||||
cJSON_AddItemToObject(t50_props, "limit", p_my_events_limit);
|
||||
|
||||
cJSON* p_my_events_kind = cJSON_CreateObject();
|
||||
cJSON_AddStringToObject(p_my_events_kind, "type", "integer");
|
||||
cJSON_AddStringToObject(p_my_events_kind, "description", "Optional specific kind to query; omit for all kinds");
|
||||
cJSON_AddItemToObject(t50_props, "kind", p_my_events_kind);
|
||||
|
||||
cJSON* p_my_events_timeout = cJSON_CreateObject();
|
||||
cJSON_AddStringToObject(p_my_events_timeout, "type", "integer");
|
||||
cJSON_AddStringToObject(p_my_events_timeout, "description", "Query timeout in milliseconds (1000-60000, default 8000)");
|
||||
cJSON_AddItemToObject(t50_props, "timeout_ms", p_my_events_timeout);
|
||||
|
||||
cJSON_AddItemToObject(t50_fn, "parameters", t50_params);
|
||||
cJSON_AddItemToObject(t50, "function", t50_fn);
|
||||
cJSON_AddItemToArray(tools, t50);
|
||||
|
||||
char* out = cJSON_PrintUnformatted(tools);
|
||||
cJSON_Delete(tools);
|
||||
return out;
|
||||
|
||||
Reference in New Issue
Block a user