feat(ws1): non-Claude in-process invokers + FastAPI HTTP API (WS1, code only) #44
No reviewers
Labels
No labels
app
bug
ci
compliance
content
dependencies
docs
documentation
duplicate
enhancement
github_actions
good first issue
help wanted
infra
invalid
javascript
needs-triage
python
question
tests
wontfix
No milestone
No project
No assignees
1 participant
Due date
No due date set.
Dependencies
No dependencies set.
Reference: adam/orchestrator#44
Loading…
Add table
Reference in a new issue
No description provided.
Delete branch "feat/ws1-inprocess-models-http-api"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Summary
agent_team/invoker_multi.py(new): unified in-process invoker for non-Claude models;multi_invoke(prompt, *, model)dispatches to GPT-4.1 (cross_reviewer), DeepSeek (fast_coder), or Gemini (scanner) via the orchestrator'smodels.py;bind_multi_invoker()wires the review loop seam; all model imports are lazy (no import-time side effects)nodes/review_loop_llm.py:default_plan_reviewerswapped frommake_run_py_invoker()(subprocess) tomake_cross_reviewer_invoker()(in-process GPT-4.1, WS1); subprocess path retained asmake_run_py_invoker()for opt-in usenodes/builders_llm.py: newmake_fast_coder_invoker()in-process DeepSeek path; old subprocess path renamed tosubprocess_build()(opt-in fallback);default_build()now delegates tomake_fast_coder_invoker()agent_team/api.py(new): FastAPI HTTP API with bearer-token auth (AGENT_TEAM_API_TOKENenv, constant-time comparison); endpointsPOST /tasks,GET /tasks/{thread_id},POST /orchestrator/invoke; default bind host127.0.0.1;serve()helper for attended deploy; code only — NOT startedrun-team.py:_cmd_servecallsbind_multi_invoker()alongsidebind_subscription_invoker()so non-Claude seams go live at daemon startuptests/test_ws1_invoker_multi_api.py(new): 21 tests;tests/test_builders_llm.py: updated 2 tests to reflect renamed subprocess pathCI status
ruff checkclean ·pytest -q— 1065 passedSecurity notes (inline adversarial review)
_get_token()raisesRuntimeErroron missing/emptyAGENT_TEAM_API_TOKENso the server cannot start without a secret. Token comparison useshmac.compare_digest(constant-time).127.0.0.1hard-coded in themake_appsignature; theserve()call also sets it explicitly, so a mis-typed call toserve(host="0.0.0.0")is the only escape path and requires a deliberate code change./orchestrator/invoke: uses list-form argv ([sys.executable, str(run_py), request.prompt]) — noshell=True, sorequest.promptcannot be shell-interpolated. However, the prompt text IS passed as a subprocess argument; a hostile prompt could attempt argument injection ifrun.pydoes further shell expansion. Mitigation:run.pyreceives the prompt assys.argv[1](a single string, not shell-parsed). Flag for GPT-4.1 cross-review.AGENT_TEAM_API_TOKENread from env at request time, never hardcoded or logged.invoker_multi.py: no authentication or authz on the in-process model calls — they run with the same credentials as the daemon process. Acceptable for the 127.0.0.1-bound, VPN-only surface.OUTSTANDING (attended — do NOT merge until done)
orchestrator/invokesubprocess argument-passing and the bearer-token timing guarantee./sh-security-review— formal security sign-off on the new HTTP API surface (bearer-token auth, 127.0.0.1 bind, subprocess prompt-passing).pip install fastapi uvicornon the box (or add to the box's requirements)AGENT_TEAM_API_TOKENin~/secrev.env(strong random token, never committed)orchestratorsystemd unitcurl -H "Authorization: Bearer <token>" http://127.0.0.1:8765/tasks— expect 405 (method not allowed), confirming the API is upGenerated by Claude Code