Skip to content

feat: machine nodes — NyxBot and specialists use the owner's machines; NyxBot features move to the assistant workspace (0.40.0) - #1722

Merged
chronoai-kai merged 6 commits into
mainfrom
nyxbot/machine-nodes
Oct 1, 2026
Merged

chronoai-kai merged 6 commits into
mainfrom
nyxbot/machine-nodes

Conversation

@chronoai-kai

Copy link
Copy Markdown
Contributor

Summary

NyxBot and its specialists can use the owner's machines (a host, a remote VM or a container) through credential nodes. They can run commands, edit files, use git and SDKs through the owner's connected NyxID services, and operate the desktop and browser with cua-driver. The owner can watch live, take over and hand back. Version 0.40.0.

  • Capabilities. The machine's owner opts in locally:
    • shell, files (confined to workspace roots, TOCTOU-safe opens) and computer (cua-driver);
    • nyxid node setup for one command, the nyxid-node-machine container image (Xvfb, Chromium, cua), and --separate-users VMs.
  • Authority.
    • Chat keys only and owner turns only; guests are refused.
    • NyxBot uses every accessible machine; specialists need machine grants.
    • A per-machine machine_confirm (none, changes or all) uses action cards. Webhook automations add their confirmation policy on top.
    • Signed WebSocket machine requests carry a replay window; the server issues jobs, and a job is honoured only while it is live.
  • Connected services without credentials on the machine.
    • A per-job loopback gateway, bound to the services each command declares.
    • SDK variables and git insteadOf come from a server-generated, catalog-driven environment spec.
    • Git smart-HTTP runs through the owner's connected GitHub credential, injected server-side.
    • Streamed uploads keep backpressure and are never retried on another node; buffered calls may use service pools with failover.
  • Live desktop.
    • Native capture on the owner's live view: X11 on Linux, ScreenCaptureKit on macOS.
    • Changed-tile JPEG frames at 30 Hz with zero idle traffic, and a separate owner input path.
    • Takeover preempts agent work immediately, and the agent sees nothing during owner control.
  • Saved logins.
    • Encrypted and write-only. nyx__machine_fill_login types through a force-installed filler extension and a native messaging host: origin and field checks, password-type pinning, TOTP computed in NyxID, output scrubbing.
    • On single-user machines, filling is off until the owner opts in, with a warning.
  • Hardening.
    • Agent children run with PR_SET_NO_NEW_PRIVS and a seccomp filter that denies namespace creation.
    • The container's Chromium runs sandboxed under a canonical seccomp profile.
    • Setup pins the image to the server version.
    • Single-user installs warn that agent commands can read the node's own credentials, and show a "Not isolated" badge.
  • NyxBot setup. nyxid__machine_setup_link and nyxid__machine_pair; registration tokens never enter chat; NyxBot wakes when the machine connects.
  • Assistant workspace (user request). Automations (0.39.0), Machines (with a Saved logins tab), machine setup, pairing and the live desktop now live under /assistant/* with assistant-sidebar entries.
    • /automations redirects with its parameters preserved.
    • Studio keeps Developer > Triggers and generic Nodes, with a read-only machine summary.

Performance (D17)

Measurement Result
Exec overhead, CLI loopback 7.0 ms p50 / 36.9 ms p95 (budget ≤ 50)
100 MiB download, direct → gateway 508 → 518 MiB/s
12 MiB git clone, direct → gateway 0.68 → 0.77 s
Capability report → NyxBot wake 17.9 ms (budget < 10 s)
Live desktop, typing / scrolling (container, 1280×800) 30.3 / 29.3 fps
Owner input → frame 30.9 ms p50 / 70.1 ms p95
Takeover during stalled agent work 0.79 ms
Idle desktop traffic 0 B/s

macOS desktop numbers need Screen Recording and Accessibility permissions; the repeatable command is in docs/MACHINE_NODES.md.

Rollout

Upgrade the backend first, then nodes. Machine features are opt-in on each node. No new required environment variables.

Verification

  • Backend (MongoDB replica set): handlers 2106, services 3909 (5 ignored benchmarks), rest 1140; clippy 1.98.1 -D warnings clean.
  • CLI and machine crate: 1435 passed. Frontend: 4077 passed; type-check, lint (0 errors) and build pass.
  • Extension freshness and unit tests, plus the production container e2e: sandbox, NoNewPrivs, namespace denial, git and desktop.
  • Three review rounds (17 + 6 + 1 findings) fixed. The design doc is docs/MACHINE_NODES.md.

chrono-kw added 5 commits October 1, 2026 09:34
… (shell, files, git through connected services, live desktop, saved logins)
…eover preemption, sandboxed browser, native live desktop, assistant workspace placement
Comment thread backend/src/services/machine_transport_tests.rs Fixed
Comment thread backend/src/services/machine_transport_tests.rs Fixed
Comment thread backend/src/services/machine_transport_tests.rs Fixed
Comment thread backend/src/services/machine_transport_tests.rs Fixed
Comment thread backend/src/services/machine_transport_tests.rs Fixed
Comment thread backend/src/services/machine_transport_tests.rs Fixed
Comment thread backend/src/services/machine_transport_tests.rs Fixed
Comment thread backend/src/services/machine_transport_tests.rs Fixed
Comment thread backend/src/services/machine_transport_tests.rs Fixed
@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown

📊 Code coverage

Component Lines Threshold Status Δ vs base
Backend (nyxid) 87.54% 73% ✅ 🔻 -0.15
CLI (nyxid-cli) 71.22% 64% ✅ 🔻 -1.37
Frontend (vitest) 71.61% 15% ✅ 🔺 +0.15

Gate: line coverage must stay at or above the threshold. Ratchet plan (W21): Backend → 55%, CLI → 50%, Frontend → 30% by quarter end.

…, read-only permissions for machine container CI job
@chronoai-kai
chronoai-kai merged commit 479840e into main Oct 1, 2026
35 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants