Files
gbrain/recipes/agent-voice/code/lib/sessions.mjs
T
e9fa51d46e v0.40.0.0 feat: agent-voice (Mars + Venus) + copy-into-host-repo skillpack paradigm (#1128)
* feat: agent-voice reference skillpack (Mars + Venus) + copy-into-host-repo install paradigm

Ships a new skillpack paradigm: gbrain holds the REFERENCE content;
`gbrain integrations install agent-voice --target <repo>` COPIES it into
the operator's host agent repo where it becomes user-owned and mutable.
Future refresh is diff-and-propose against per-file SHA-256 hashes from
.gbrain-source.json, not blind overwrite.

What ships:
- recipes/agent-voice.md entrypoint + recipes/agent-voice/ bundle
- Two voice personas (Mars dual-mode SOLO/DEMO, Venus executive assistant)
  with PII / private-agent-name / hardcoded-path scrubbed out
- WebRTC-first browser client (call.html) with ?test=1 gated instrumentation
  and Web Audio API tee -> MediaRecorder capture for E2E roundtrip testing
- Read-only tool router (D14-A allow-list: search, query, get_page,
  list_pages, find_experts, get_recent_salience, get_recent_transcripts,
  read_article). Write ops permanently denylisted; opt-in via local override
- Persona-aware prompt builder with identity-first composition + Unicode
  sanitization for OpenAI Realtime API safety
- Upstream-error classifier (HTTP 429/500/503 -> soft-fail, plumbing -> hard)
- Three SKILL.md skills (voice-persona-mars, voice-persona-venus,
  voice-post-call) with routing-eval.jsonl fixtures
- 99 host-side tests (vitest-compatible, runs in bun) covering registry,
  prompt-shape privacy guards, tool allow-list, upstream classifier
- install/manifest.json + refresh-algorithm.md + post-install-hint.md

Privacy infrastructure:
- scripts/check-no-pii-in-agent-voice.sh wired into bun run verify
  Shape regex (phone/email/SSN/JWT/bearer/credit-card) + path patterns +
  $AGENT_VOICE_PII_BLOCKLIST env-driven name blocklist
- scripts/import-from-upstream.sh + scripts/upstream-scrub-table.txt
  Deterministic refresh from upstream voice-agent source. Placeholder-
  driven (envsubst-expanded at run time) so no private names land in
  checked-in files
- recipes/agent-voice/code/lib/personas/private-name-blocklist.json
  Single source of truth for the regex contract (shape categories +
  path patterns + env-var contract for operator-specific names)

src/ surface:
- src/commands/integrations.ts gains `install <recipe-id>` subcommand
  with install_kind: 'local-managed' | 'copy-into-host-repo' discriminator.
  Path-traversal hardening (rejects '..', absolute paths, symlink escapes).
  Refuses target == gbrain itself, missing .git, existing files (without
  --overwrite). Writes .gbrain-source.json with per-file SHA-256. Appends
  resolver rows to host repo's RESOLVER.md or AGENTS.md.
- test/integrations-install.test.ts: 11 cases (happy path, manifest shape,
  no upstream_repo field per D11-A, resolver appending, file modes,
  refusal cases, dry-run)

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* chore: bump version and changelog (v0.36.0.0)

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(privacy): scrub literal private agent names from prompt-shape tests + guard script

The prompt-shape tests carried regex patterns naming the literal banned terms
(Garry/Steph/Garrison/Solomon/Herbert/Wintermute) inline. CLAUDE.md's
"never use Wintermute in any public artifact" applies to test source files
too. Master's check-privacy.sh correctly caught this.

Replaced with env-driven check that reads AGENT_VOICE_PII_BLOCKLIST (the
single source of truth from private-name-blocklist.json). Same enforcement
guarantee via the env var, zero literal names in shipped source.

Also scrubbed the literal /data/.openclaw/ from the guard script's comment
and the literal 'tell_wintermute' from the venus write-tools test.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* feat: ship all v0.36.0.0 deferred items in this PR (E2E + evals + pipeline + refresh + multilingual + twilio deprecation)

Closes the "deferred to follow-up" section of the v0.36.0.0 CHANGELOG.

E2E tests + harness (env-gated):
- tests/e2e/voice-roundtrip.test.mjs — spawns server, drives puppeteer + fake-audio, three-tier assertions (CONNECTION hard, NON-SILENT hard, SEMANTIC soft via Whisper + LLM judge). Upstream errors (429/500/503, WS 1011/1013) soft-fail via lib/upstream-classifier.mjs.
- tests/e2e/voice-full-flow.test.mjs — wraps openclaw doing the install, then runs the roundtrip. Friction-discovery flavor, NOT a ship gate.
- tests/e2e/lib/browser-audio.mjs — puppeteer + fake-audio harness; reads window._gbrainTest namespace; PCM RMS-variance helper.
- tests/e2e/lib/whisper-judge.mjs — Whisper transcription + LLM-judge for SEMANTIC tier.
- tests/e2e/audio-fixtures/utterance-{add,joke,brain-query}.wav — 16kHz mono WAV via `say` + ffmpeg, committed for reproducibility.
- test/fixtures/claw-test-scenarios/voice-agent-install/{BRIEF.md, scenario.json, expected.json} — labeled BENCHMARK_FRICTION, blocks_ship=false.

LLM-judge persona evals + synthetic canonical baselines:
- tests/evals/judge.mjs — gateway-routed 3-model (Claude + GPT + Gemini) harness with 4-strategy JSON repair + 2/3-quorum aggregation (per the v0.27.x cross-modal pattern). Pass criterion: every axis mean ≥7 AND no model <5.
- tests/evals/fixtures/{mars-solo,mars-demo,venus,persona-routing,mars-multilingual}.jsonl — 5 fixture sets covering all axes.
- tests/evals/{mars-eval,venus-eval,mars-multilingual-eval,persona-routing-eval}.mjs — per-axis drivers.
- tests/evals/baseline-runs/canonical/*.json — agent-authored synthetic exemplars (PII-impossible by construction; demonstrate expected pass shape; never overwrite with live model output).
- tests/evals/baseline-runs/.gitignore — live receipts excluded.

DIY pipeline (Option B):
- code/pipeline.mjs — streaming STT (Deepgram nova-2) + LLM (Claude Sonnet 4.6 streaming SSE with sentence-boundary TTS dispatch) + TTS (Cartesia primary, OpenAI TTS fallback). 20-turn history cap, exponential-backoff reconnects, 25s keepalives, VAD presets (quiet/normal/noisy/very_noisy), barge-in via STT speechStart → LLM interrupt. Modular adapters for swapping providers.

--refresh mode (D3-A diff-and-propose):
- src/commands/integrations.ts: refreshRecipeIntoHostRepo() + classifyForRefresh() implementing the five states from refresh-algorithm.md (unchanged-identical, unchanged-stale, locally-modified, source-deleted, host-deleted, new-in-manifest). Transaction journal at .gbrain-source.refresh.log. Default policy: preserve operator's local edits (keep-mine); --auto take-theirs to overwrite; --dry-run for preview.
- test/integrations-install.test.ts: 7 new test cases pinning each classification state + default-preserve behavior + take-theirs overwrite + transaction journal + refusal on uninstalled target.

Mars multilingual restore:
- code/lib/personas/mars.mjs: explicit cross-lingual rule (Mandarin, Spanish, French, Japanese, Korean default to English but follow the speaker). Voice (Orus) supports the languages natively.
- tests/unit/mars-prompt-shape.test.mjs: assertion flipped from "MUST NOT claim multilingual" to "declares cross-lingual capability with English bias."
- tests/evals/fixtures/mars-multilingual.jsonl: 5 fixtures across Mandarin/Spanish/Japanese/French + explicit switch-back, pinned by mars-multilingual-eval.mjs.

Twilio recipe deprecation:
- recipes/twilio-voice-brain.md: deprecation banner pointing at agent-voice.md. Frontmatter version bumped to 0.8.2. Will be removed in v0.37.

Verify: bun run verify clean, 6736+ unit tests pass, 18/18 install+refresh tests pass, 96/98 host-side persona/tool/classifier tests pass (2 skipped env-gated).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: update CHANGELOG — all v0.36.0.0 deferred items now shipped in this PR

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* chore: rebump version v0.36.0.0 → v0.37.0.0

Captures the wave-1 + wave-2 scope at the v0.37 slot. The bump reflects
the size of what this PR ships: copy-into-host-repo install paradigm
(new install_kind discriminator + new install/refresh subcommand) +
Mars/Venus voice agent reference + 5,500+ LOC of vendored scrubbed
code + 4 LLM-judge eval suites + 2 env-gated E2E test suites + DIY
Option B pipeline + 18-case install subcommand test coverage. A minor
bump felt too small.

Side fix: privacy guard caught two stale literal "wintermute" and
"/data/.openclaw/" references in wave-2 files
(voice-full-flow.test.mjs comment, expected.json blocklist payload).
Both replaced with env-driven references to $AGENT_VOICE_PII_BLOCKLIST
matching the D15-A pattern from the original review.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* chore: rebump v0.37.0.0 → v0.40.0.0

Jumps past the v0.37/v0.38/v0.39 slots master might claim in subsequent
PRs. The wave's scope (copy-into-host-repo skillpack paradigm + agent-voice
+ install/refresh + LLM-judge evals + DIY pipeline + Mars multilingual)
justifies a larger version arithmetic step.

Files bumped:
- VERSION 0.37.0.0 → 0.40.0.0
- package.json 0.37.0.0 → 0.40.0.0
- CHANGELOG.md header + "To take advantage of v0.40.0.0" block
- recipes/twilio-voice-brain.md deprecation banner (now "removed in v0.41")
- recipes/agent-voice/tests/evals/mars-multilingual-eval.mjs comment

Left alone: master's pre-existing "v0.37+" roadmap labels in src/core/calibration/*,
src/core/cycle/*, DESIGN.md, CLAUDE.md, etc. Those are master's author-intent
references to "the next planned release" relative to master's frame at the time —
rewriting them just to keep numbering consistent would overreach.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-22 21:54:13 -07:00

209 lines
6.0 KiB
JavaScript

/**
* sessions.mjs — voice-agent session management.
*
* Pure functions, no side effects, fully testable.
*
* Session model:
* - Voice sessions track auth state (code-based + pre-auth flows).
* - Tokens are short-lived (1h default) for callers who verified.
* - LogicalSession tracks reconnects + disconnect reasons for QA.
*
* Identity: the operator's identity is set via `OPERATOR_IDENTITY` env var
* or the `identity` arg to preAuthenticate. Defaults to the generic
* 'operator' if unset — never hardcoded to a real name.
*/
import { randomBytes } from 'node:crypto';
const DEFAULT_IDENTITY = process.env.OPERATOR_IDENTITY || 'operator';
export class SessionManager {
constructor() {
this.sessions = new Map();
this.current = null;
this.maxSessions = 5;
}
create() {
const id = 'vs_' + randomBytes(16).toString('hex');
this.sessions.set(id, {
authCode: null,
authenticated: false,
identity: null,
createdAt: Date.now(),
preAuth: false,
});
this.current = id;
this._cleanup();
return id;
}
get(id) {
return this.sessions.get(id || this.current) || null;
}
getCurrent() {
return this.get(this.current);
}
restore(id) {
if (this.sessions.has(id)) {
this.current = id;
return true;
}
return false;
}
setAuthCode(code) {
const s = this.getCurrent();
if (s) {
if (s.authCode) return false; // Already has code — don't regenerate
s.authCode = code;
return true;
}
return false;
}
getAuthCode() {
return this.getCurrent()?.authCode || null;
}
verify(code) {
const s = this.getCurrent();
if (!s || !s.authCode) return { verified: false, reason: 'No code sent' };
const digits = String(code || '').replace(/\D/g, '');
if (digits === s.authCode) {
s.authenticated = true;
s.identity = DEFAULT_IDENTITY;
return { verified: true };
}
return { verified: false, reason: 'Code does not match' };
}
preAuthenticate(identity) {
const s = this.getCurrent();
if (s) {
s.authenticated = true;
s.identity = identity || DEFAULT_IDENTITY;
s.preAuth = true;
return true;
}
return false;
}
isAuthenticated() {
const s = this.getCurrent();
return !!(s && s.authenticated);
}
getIdentity() {
return this.getCurrent()?.identity || null;
}
_cleanup() {
const keys = [...this.sessions.keys()];
if (keys.length > 10) {
for (const k of keys.slice(0, keys.length - 10)) {
const s = this.sessions.get(k);
if (s?.authenticated || s?.preAuth) continue; // Keep authed sessions
this.sessions.delete(k);
}
}
// Hard cap: expire sessions older than 2 hours
const twoHoursAgo = Date.now() - 2 * 3600000;
for (const [k, s] of this.sessions) {
if (s.createdAt < twoHoursAgo) this.sessions.delete(k);
}
}
}
export class TokenManager {
constructor() {
this.tokens = new Map();
}
generate(identity = DEFAULT_IDENTITY, hours = 1) {
const token = randomBytes(32).toString('hex');
const expires = Date.now() + (hours !== undefined ? hours : 1) * 3600000;
this.tokens.set(token, { expires, identity });
this._cleanup();
return { token, expires: new Date(expires).toISOString() };
}
validate(token) {
if (!token) return null;
const data = this.tokens.get(token);
if (!data) return null;
if (data.expires <= Date.now()) {
this.tokens.delete(token);
return null;
}
return data;
}
_cleanup() {
const now = Date.now();
for (const [k, v] of this.tokens) {
if (v.expires <= now) this.tokens.delete(k);
}
}
}
export class LogicalSession {
constructor() {
this.id = 'vl_' + Date.now() + '_' + Math.random().toString(36).slice(2, 6);
this.startTime = Date.now();
this.reconnects = 0;
this.notified = false;
this.disconnectReasons = [];
}
recordDisconnect(code, reason) {
this.disconnectReasons.push({ code, reason, at: Date.now() });
this.reconnects++;
}
}
// ── Rating ────────────────────────────────────────────────
/**
* Compute a 0-10 call quality rating from transcript + duration + reconnect count.
* Used for post-call summaries; not user-facing.
*/
export function calculateRating(transcript, duration, reconnects = 0, identity = '') {
let rating = 7;
const issues = [];
if (duration < 15) { rating -= 2; issues.push('too short'); }
if (duration < 5) { rating -= 1; issues.push('extremely short'); }
if (reconnects > 0) { rating -= 1; issues.push(`${reconnects} reconnect(s)`); }
if (reconnects > 3) { rating -= 1; issues.push('excessive reconnects'); }
if (identity === 'unverified' && duration > 30) { rating -= 1; issues.push('unverified'); }
if (transcript.length <= 2) { rating -= 2; issues.push('minimal conversation'); }
const hadReconnect = transcript.some((t) => t.text?.includes('Reconnecting'));
if (hadReconnect) { rating -= 1; issues.push('connection dropped'); }
return { rating: Math.max(0, Math.min(10, rating)), issues };
}
export function ratingEmoji(score) {
return score >= 8 ? '⭐' : score >= 5 ? '🟡' : '🔴';
}
// ── Auth tool gating ──────────────────────────────────────
// Note: voice-callable tool gating lives in `../tools.mjs` (D14-A allow-list).
// The arrays below are LEGACY helpers retained for compatibility with the
// vendored prompt + bridge code, and they intentionally name no specific
// upstream agent. The canonical source of "is this tool callable?" is
// `dispatchTool()` in `tools.mjs`, which always wins.
const AUTH_REQUIRED = new Set(['log_to_brain', 'set_reminder', 'send_message']);
const AUTH_FREE = new Set(['send_auth_code', 'verify_code', 'take_message']);
export function requiresAuth(toolName) {
return AUTH_REQUIRED.has(toolName);
}
export function isAuthFlowTool(toolName) {
return AUTH_FREE.has(toolName);
}