Files
synapbus/internal/secrets/types.go
T
Algis DumbrisandClaude Opus 4.6 ff5d0c49f4 feat(018): dynamic agent spawning — primitives + doc-gardener demo
Ships the MVP slice of spec 018 (dynamic agent spawning):

- 5 new SQLite migrations (021-025): goals + goal_tasks + agent_proposals
  + reputation_evidence + secrets + harness_runs.task_id. The legacy
  `tasks` table (channel auctions) and `agent_trust` table (reactions
  workflow) are left untouched — the new schema coexists.

- 4 new internal packages, fully tested:
  - internal/goals: Goal struct + store + service, slug collision dedup,
    backing-channel auto-create via ChannelCreator adapter
  - internal/goaltasks: goal_tasks table with denormalized 16 KB
    ancestry snapshots, single-statement optimistic-lock atomic claim,
    recursive-CTE cost rollup, state machine, per-billing-code rollup
  - internal/secrets: NaCl-secretbox encrypted blobs, user/agent/task
    scope precedence, sanitized env injection, master-key bootstrap
  - internal/trust additions: ConfigHash (deterministic SHA-256 of
    model + prompt + tools + skills + mcp + subagents, sorted),
    DelegationCap (tier + tool-scope + budget + depth enforcement),
    append-only Ledger with exponential time-decay rolling score and
    70%-of-parent child seeding. Existing trust package unchanged.

- Critical invariants under test:
  - 50-goroutine concurrent claim race → exactly one winner per round
  - ConfigHash stable under shuffled array inputs, sensitive to
    capability changes
  - DelegationCap full tier × tool-scope matrix
  - Ledger time-decay + parent seed at 70 % ± 1 %
  - Secret name sanitization, scope precedence, plaintext never
    returned via MCP-equivalent paths

- internal/agents/types.go extended with dynamic-spawning columns
  (config_hash, parent_agent_id, spawn_depth, system_prompt,
  autonomy_tier, tool_scope_json, quarantined_at). Existing tests
  still pass.

- cmd/docgardener: self-contained demo binary driving the end-to-end
  flow. `docgardener run` creates a goal, builds a task tree with
  denormalized ancestry, spawns 3 specialists (each going through
  real delegation-cap validation and config-hash computation and
  70 %-of-parent reputation seeding), claims tasks atomically, runs
  them through the state machine, records reputation evidence.
  `docgardener report` queries all of that back out and renders a
  rich dark-mode HTML report (header, spend metrics, task tree,
  spawned-agent cards with reputation bars, cost breakdown, artifacts,
  timeline).

- examples/doc-gardener: start.sh / run_task.sh / report.sh / stop.sh
  mirroring the cold-topic-explainer pattern. Launches an isolated
  synapbus instance on port 18089, drives the demo, renders
  report.html, cleans up. Full README documenting what's real vs
  deferred, plus examples/README.md listing both examples.

- specs/018: tasks.md updated with MVP completion status; legacy tasks
  naming collision noted.

Deferred (marked explicitly in example README):
- Real LLM-driven coordinator (needs MCP tool wiring + prompt
  iteration)
- Real subprocess runs (needs reactor integration with task_id on
  ExecRequest)
- Full MCP tool surface (contracts are written at
  specs/018-dynamic-agent-spawning/contracts/mcp-tools.md)
- Svelte /goals UI (REST endpoints remain a follow-up)
- Full budget race + quarantine auto-trigger wiring
- Full resource-request → secrets fulfill reaction-workflow path

Cross-compiles clean for linux/amd64 and darwin/arm64 with no CGO
(SC-010). All new package tests pass (SC-004, SC-005, SC-007).

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-14 15:29:21 +03:00

63 lines
2.0 KiB
Go

// Package secrets provides encrypted, scoped secret storage for SynapBus.
//
// Secrets are stored in SQLite, encrypted at rest with NaCl secretbox under a
// local 32-byte master key (kept in <data-dir>/secrets.key with 0600 perms).
// Secrets are scoped to a user, agent, or task and are intended to be injected
// into subprocess environments as sanitized A-Z0-9_ variable names. The MCP
// surface never returns plaintext values — only names and availability.
package secrets
import (
"errors"
"time"
)
// Scope type constants. The same values are used in the secrets.scope_type
// column (CHECK constraint enforced at the SQL level).
const (
ScopeUser = "user"
ScopeAgent = "agent"
ScopeTask = "task"
)
// Sentinel errors for the secrets package.
var (
// ErrNotFound is returned when no active secret matches the lookup.
ErrNotFound = errors.New("secret not found")
// ErrAlreadyRevoked is returned when revoking a secret that is already revoked.
ErrAlreadyRevoked = errors.New("secret already revoked")
// ErrInvalidName is returned when a secret name fails sanitization.
ErrInvalidName = errors.New("invalid secret name: must be non-empty and contain only A-Z, 0-9, _")
// ErrMasterKeyMissing is returned when the master key file cannot be read or generated.
ErrMasterKeyMissing = errors.New("secrets master key missing or unreadable")
)
// Secret is a stored, encrypted secret row. The plaintext value is never
// included — callers fetch it explicitly via Store.Get.
type Secret struct {
ID int64
Name string
ScopeType string
ScopeID int64
CreatedBy int64
CreatedAt time.Time
RevokedAt *time.Time
LastUsedAt *time.Time
}
// Info is the public, value-free projection of a Secret used for listings
// exposed via MCP / API. It deliberately has no value field.
type Info struct {
Name string
ScopeType string
ScopeID int64
Available bool
LastUsedAt *time.Time
}
// Scope identifies a (type, id) pair used when listing or building env maps.
type Scope struct {
Type string
ID int64
}