app

package
v0.3.0-alpha.1 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 11, 2026 License: MIT Imports: 35 Imported by: 0

Documentation

Overview

Package app composes Relayer's configuration, PTY sessions, and terminal UI. Keeping this wiring separate lets both the canonical cmd/relayer entrypoint and the documented root compatibility entrypoint stay tiny.

Index

Constants

This section is empty.

Variables

View Source
var ErrAuditVerificationFailed = errors.New("audit verification detected issues")
View Source
var ErrCleanupUncertain = errors.New("desktop runtime cleanup not confirmed")

ErrCleanupUncertain marks a failed runtime start whose rollback could not prove that every partially started session was removed. Desktop controllers must quarantine the lifecycle and must not launch a candidate or rollback run while this sentinel is present.

View Source
var ErrEmptyManualDecision = errors.New("a manual decision cannot be empty")

ApplyDecision resolves the canonical pending occurrence again immediately before encoding and delivery. This CAS boundary prevents a stale policy or UI result from acknowledging a newer prompt from the same session. ErrEmptyManualDecision reports a manual decision carrying no answer.

View Source
var ErrPreflightBlocked = errors.New("relayer diagnostics detected a blocker")

ErrPreflightBlocked is returned only after a complete, display-safe doctor report has been written. Entrypoints use it to select a non-zero exit status without appending a second error message to the report.

Functions

func Run

func Run(arguments []string, diagnostics io.Writer) error

Run parses the public CLI, initializes the process owner and starts Bubble Tea. It never returns while sessions are still owned by the manager.

func RunPreflight

func RunPreflight(ctx context.Context, options PreflightOptions) (preflight.Report, error)

RunPreflight builds the effective Relayer plan and inspects it without creating a configuration, opening an audit sink, constructing a terminal backend or starting an agent. Expected operational failures are represented by static checks rather than raw errors so presentation layers cannot leak configuration paths or user-controlled values.

func RunWithOutput

func RunWithOutput(arguments []string, output io.Writer, diagnostics io.Writer) error

RunWithOutput is the canonical public CLI entry. Version output is kept separate from diagnostics and is handled before configuration, audit, or backend initialization.

Types

type DesktopMetadata

type DesktopMetadata struct {
	RunID            string `json:"runID"`
	ConfigPath       string `json:"configPath"`
	ConfigRevision   string `json:"-"`
	Backend          string `json:"backend"`
	PolicyAction     string `json:"policyAction"`
	PolicyDryRun     bool   `json:"policyDryRun"`
	AuditEnabled     bool   `json:"auditEnabled"`
	AuditMode        string `json:"auditMode"`
	AuditPath        string `json:"auditPath,omitempty"`
	TelemetryEnabled bool   `json:"telemetryEnabled"`
	TelemetryProm    string `json:"telemetryPrometheus,omitempty"`
	Configuration    bool   `json:"configurationCreated"`
}

DesktopMetadata contains non-sensitive run settings suitable for a GUI.

type DesktopOptions

type DesktopOptions struct {
	ConfigPath  string
	InitialSize terminal.Size
	Diagnostics io.Writer
}

DesktopOptions configures the headless runtime used by desktop frontends. It deliberately does not inherit the deprecated pane flags from the CLI.

type DesktopPlan

type DesktopPlan struct {
	// contains filtered or unexported fields
}

DesktopPlan is an immutable, Go-only preflight result. Preparing a plan may read configuration and resolve executables, but it never opens audit files, terminal backends or child processes.

func PrepareDesktopRuntime

func PrepareDesktopRuntime(options DesktopOptions) (*DesktopPlan, error)

PrepareDesktopRuntime performs every validation that can safely happen before an existing desktop run is stopped.

type DesktopRuntime

type DesktopRuntime struct {
	// contains filtered or unexported fields
}

DesktopRuntime owns one complete Relayer run without assuming a terminal UI. Consumers remain responsible for reducing Events and for never exposing free-form sensitive event fields.

func NewDesktopRuntime

func NewDesktopRuntime(parent context.Context, options DesktopOptions) (*DesktopRuntime, error)

NewDesktopRuntime preserves the historical one-call API.

func StartDesktopRuntime

func StartDesktopRuntime(parent context.Context, plan *DesktopPlan, runID string) (_ *DesktopRuntime, returnErr error)

StartDesktopRuntime starts an immutable preflight plan under the externally reserved identity shared by GUI events, tmux ownership and audit records.

func (*DesktopRuntime) AnsiOutput

func (r *DesktopRuntime) AnsiOutput(sessionID string) (string, error)

func (*DesktopRuntime) ApplyDecision

func (r *DesktopRuntime) ApplyDecision(
	ctx context.Context,
	sessionID string,
	event adapters.Event,
	decision adapters.Decision,
	manualInput string,
) error

func (*DesktopRuntime) BeginRestart

func (r *DesktopRuntime) BeginRestart(ctx context.Context) error

BeginRestart is the stricter desktop transition used before another run is allowed to start. Unlike a normal application shutdown it explicitly stops every session, including tmux sessions configured to persist on exit. A non-nil result means cleanup is uncertain and callers must not start a replacement run.

func (*DesktopRuntime) BeginShutdown

func (r *DesktopRuntime) BeginShutdown(ctx context.Context) error

BeginShutdown stops backend I/O while deliberately keeping the audit recorder open. Desktop frontends use this phase to unblock and join all in-flight decision goroutines before Close writes the final run records.

func (*DesktopRuntime) Close

func (r *DesktopRuntime) Close(ctx context.Context) error

Close stops supervision, closes every owned backend and then closes audit. It is idempotent and preserves the first complete shutdown result.

func (*DesktopRuntime) Evaluate

func (r *DesktopRuntime) Evaluate(event adapters.Event) policy.Evaluation

func (*DesktopRuntime) Events

func (r *DesktopRuntime) Events() <-chan session.Event

func (*DesktopRuntime) Metadata

func (r *DesktopRuntime) Metadata() DesktopMetadata

func (*DesktopRuntime) Output

func (r *DesktopRuntime) Output(sessionID string) (string, error)

func (*DesktopRuntime) PendingEvent

func (r *DesktopRuntime) PendingEvent(ctx context.Context, sessionID string) (*adapters.Event, error)

func (*DesktopRuntime) RecordAudit

func (r *DesktopRuntime) RecordAudit(entry audit.Entry) error

RecordAudit is a synchronous, fail-closed persistence boundary for desktop decisions. Callers must not perform a backend write when it returns an error.

func (*DesktopRuntime) Resize

func (r *DesktopRuntime) Resize(ctx context.Context, sessionID string, size terminal.Size) error

func (*DesktopRuntime) SendLine

func (r *DesktopRuntime) SendLine(ctx context.Context, sessionID, line string) error

SendLine submits ordinary single-line text through the backend's atomic processor boundary. It never falls back to raw Send or decision resolution.

func (*DesktopRuntime) Sessions

func (r *DesktopRuntime) Sessions() []DesktopSession

func (*DesktopRuntime) Snapshot

func (r *DesktopRuntime) Snapshot(ctx context.Context, sessionID string) (terminal.Snapshot, error)

func (*DesktopRuntime) StartupLogs

func (r *DesktopRuntime) StartupLogs() []string

func (*DesktopRuntime) Stop

func (r *DesktopRuntime) Stop(ctx context.Context, sessionID string) error

func (*DesktopRuntime) SupportedDecisions

func (r *DesktopRuntime) SupportedDecisions(event adapters.Event) []adapters.Decision

SupportedDecisions reports the semantic answers the interface may offer for this exact event. An interface that guesses instead would show an Allow button on a prompt whose adapter has no verified bytes for accepting it.

type DesktopSession

type DesktopSession struct {
	ID      string `json:"id"`
	Name    string `json:"name"`
	Command string `json:"command"`
	Backend string `json:"backend"`
	Adapter string `json:"adapter"`
	Shell   bool   `json:"shell"`

	// Simulated marks one of the synthetic Bash agents substituted for an empty
	// agent list. They are indistinguishable from a real agent on screen, which
	// in a supervision tool means an operator can believe they are watching a
	// coding agent while watching a scripted mock.
	Simulated bool `json:"simulated"`
}

DesktopSession is display-safe startup metadata. Shell bodies, environment values and prompt matches never cross this boundary.

type PreflightOptions

type PreflightOptions struct {
	ConfigPath string
}

PreflightOptions selects the existing configuration inspected by the read-only doctor shared by command-line and desktop frontends.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL