Repository navigation
plat 633
| Field | Value |
|---|---|
| State | fixed on main |
| Priority | P1 |
| Product | brain |
| Area | storage |
| Summary | Brain is a plain Git folder like every other product: the Brain chat edits its files and runs git in a shell; Brain tools only store; brain_backup is removed |
Owner, 2026-10-06: "agent should get raw access to file system and it should use git normally"; "we should not limit to a tool"; "the tool should just store stuff.. but git backup will work via terminal"; two-way, "like all other agents products". Why: the brain_backup tool wrapper wedged in BACKUP_OUTCOME_UNKNOWN on RTS (its git errors were hidden; every retry refused) and its commit arguments were rejected 8 times in a row.
- Brain picks up direct edits in its folder (new, changed, removed files; new directories) before every call. Done.
-
Done. Brain's folder moves into the documents tree as
Brain/(copied from the state folder at startup, old copy kept), app-owned 0700, a Git working folder with its remote from Brain's backup settings and a credential helper readingBRAIN_GITHUB_PAT. -
Done. The Brain chat gets a shell on
Brain/(folder guard write grant) for admins and Owners of the whole Brain; changes are recorded as theirs. -
Done (surface).
brain_backup, the Brain tab's Git panel and its/api/knowledgebase/gitroute, and deletion reservations are removed; Brain tools only store. Left: delete the now-unreached backup internals inpkg/knowledgebase(backup.go receipts/push intents, git_workspace.go Files Git copies) and the backup status view. - A terminal on
Brain/in the Brain tab.
-
Brain/is admin-only in the Files proxy (workspace_proxy_policy.go); app-owned 0700; no folder guard includes it except the Brain chat of someone who is Owner of Brain's root (brainShellGrant), whose shell starts there. - Git:
EnsureGitRepositoryrunsgit initif needed, excludes.kb-registry.json, setsoriginfrom the backup destination and a credential helper readingBRAIN_GIT_TOKEN(set in that shell's environment from the destination'spat_secret); commits are authored as the person. The workspace server passesBRAIN_GIT_*and git's author/committer variables. - After each shell or file-edit command in that chat, Brain re-reads the folder (
SyncDisk) as that person. - Tests:
TestBrainPicksUpDirectEditsInItsFolder,TestBrainNotesMoveIntoDocumentsOnceAndStayAdminOnly; backup-tool and reservation tests removed. - Not verified live: needs an RTS deploy, then from the Brain chat
git status/ commit / push to the configured repository. The current push failure (could not read Username) should then show git's real message.
Deployed 8ae73b047: notes moved into /data/video-studio/docs/Brain (13 files, 0700; old folder kept as live.moved-…). Two problems in the owner's first Brain chat turn:
- The shell ran as the owner's slot account (
slotctl: could not start … permission denied): slot accounts cannot enter the app-onlyBrain/. Fixed: a command working inBrain/whose folder guard grantsBrain/runs as the service account, still confined by Landlock (isBrainFolderCommand, testTestOnlyGrantedBrainFolderCommandsRunAsTheService). -
git initfailed in the server with no message. The error now includes git's exec error, and Brain sets up the repository at service start and logs[BRAIN] Git folder ready|not ready.
Owner: Brain's folder and chat are for "only brain writers and owners"; Readers get "no chat, just files". bootstrap reports can_write (Editor or Owner of any folder; administrators always); the server refuses Brain chat turns from anyone else; the Brain tab shows a Reader only the Files view (their folders, parents as path only), with no chat and no Access/Models/Secrets views. Test TestOnlyWritersAndOwnersCanWriteSomewhere. Not deployed.
Next (agreed): a dedicated brain slot account owns Brain/ (shared group with the service account) and runs Brain-folder commands; writers get the shell limited to their Editor/Owner folders; git for writers and Owners of the whole Brain.
RTS: the Brain chat could not point backup at https://github.com/mprealtrainingsys/brain.git (BACKUP_REMOTE_CHANGED, "changing the destination requires operator reconciliation"), a rule from the receipt-based backup. With Brain as a plain Git folder, an app-set destination can now be changed (the token secret is kept unless a new one is given), and the folder's origin follows at once. A destination set by the deployment's environment stays operator-only. Not deployed.
Auto-synced from docs/ on main. Edit there, not here.