Skip to content

feat(ai): add remote coding agent sessions for SSH hosts - #1545

Merged
ZacharyZcR merged 19 commits into
Termix-SSH:dev-2.9.1from
ZacharyZcR:feat/host-ai-agents
Oct 3, 2026
Merged

ZacharyZcR merged 19 commits into
Termix-SSH:dev-2.9.1from
ZacharyZcR:feat/host-ai-agents

Conversation

@ZacharyZcR

@ZacharyZcR ZacharyZcR commented Oct 2, 2026 •

Copy link
Copy Markdown
Member

Summary

Add an AI Agent action to host cards and SSH terminal toolbars. Users can run Pi, OpenCode, Claude Code, or Codex on an SSH host with their existing Termix AI Provider, streamed replies, tool activity, native permission prompts, cancellation, stop/resume, and saved history. The implementation uses native CLI protocols without a Paseo dependency.

The host panel includes an official runtime installer and a separate scoped SSH forwarding setup action. Node.js comes from nodejs.org with SHA-256 verification; fixed official agent packages come from registry.npmjs.org with locked SHA-512 integrity. Installation uses an isolated user prefix and disables third-party registries and lifecycle download scripts. Forwarding setup backs up and validates a source/account-scoped loopback rule, reloads OpenSSH with rollback on failure, and verifies an actual bind through a fresh SSH connection.

Conversation workflow

  • Enter sends or queues a message; Shift+Enter inserts a newline. Escape interrupts the focused agent and pauses its queue. IME composition is protected.
  • Persist up to 20 FIFO messages per session, with editing, removal, pause, and continue. A completed turn advances the queue; cancellation, remote errors, and archive pause it.
  • Name and search sessions, archive/restore them, and preserve independent composer drafts. Archive stops the process without deleting history.
  • Upload files, paste images, or reference files within the remote working directory. Uploaded files stay in the SSH user's session directory. Images use native agent inputs; other files are referenced by remote path. Limits are 1 MiB per file, four per message, and 100 per session. Vision support depends on the provider/model.
  • Review Git status and staged/unstaged/untracked file changes. Create an isolated branch/worktree from HEAD and open a new session there without moving uncommitted changes. Hooks, external diff, and textconv are disabled for these operations.
  • Reconnect interrupted browser streams with backoff, refresh saved snapshots, and resume after their sequence cursor without duplicates. Text is checkpointed every second. Server/SSH restarts still require Resume; previously dispatched commands are never automatically replayed.

Boundaries

Provider secrets stay server-side behind an authenticated, inference-only SSH reverse proxy. Host access, AI opt-in/RBAC, selected model, and the existing private-endpoint allowlist are enforced. Targets require Node.js 22.19+, a selected CLI, and loopback remote forwarding. Claude requires Anthropic Messages; Codex requires Responses support. Pi tools run with the SSH account's authority. The UI retains the most recent 2,000 events; native history remains on the host. No mobile-native UI or cross-host migration is included.

Also fix an existing timing-sensitive identity test by awaiting its asynchronous credentials request.

Validation

  • 202 AI plugin tests pass, including four native protocol/image fixtures, queue dispatch/cancellation through HTTP routes, access isolation, real temporary Git worktrees, file path/size boundaries, keyboard/IME behavior, and dropped-stream recovery.
  • TypeScript, ESLint, locale checks, and production plugin build pass.
  • Private integration deployment preserves previous fixes. Browser acceptance with Pi and a real self-hosted GLM provider verified attachment reading, pasted-image upload, file references, rename/draft restoration, Git status/diff/worktree creation, queue editing/pause/continue, and archive/stop.
  • Earlier acceptance covered official runtime installation, fresh SSH forwarding verification, native history resume, and real OpenCode inference. Claude/Codex fixtures do not imply real Anthropic/Responses inference acceptance. Image upload success does not imply vision support from the GLM endpoint.

See plugins/ai/AGENTS-FEATURE.md for permissions, persistence, limits, and runtime requirements.

@ZacharyZcR
ZacharyZcR marked this pull request as ready for review October 2, 2026 04:56
Agent sessions lived in a single ctx.kv value holding up to 2000 events,
which passed the 256 KB kv limit within minutes of a normal run. Every
save after that failed, so history, nativeId, queue and archive changes
were lost and every event wrote a kv audit row.

Sessions, events and queued prompts now have their own tables. A running
agent appends events in batches at most once a second with a lazy save;
session and queue changes save immediately. Prompts, drafts and stored
event text are capped in UTF-8 bytes to fit MySQL TEXT. kv:own is no
longer requested.

The OpenCode server now requires a per-session password, so other local
accounts on the host cannot drive the agent through its loopback port.
…store

# Conflicts:
#	plugins/ai/locales/en.json
#	plugins/ai/locales/translated/zh_CN.json
@ZacharyZcR
ZacharyZcR merged commit 9327f88 into Termix-SSH:dev-2.9.1 Oct 3, 2026
3 checks passed
LukeGus pushed a commit that referenced this pull request Oct 3, 2026
* feat(ai): add host coding agent sessions with configured providers

* Wait for agent initialization and shutdown before resuming sessions

* Keep Pi transcripts outside its configuration migration directory

* Cover Pi session directory separation

* Update core permission catalog expectations for remote agents

* Install remote agent runtimes from verified official sources

* Wait for the identity panel credentials request in its test

* Add scoped SSH forwarding setup for remote agents

* Verify forwarding setup through a fresh SSH connection

* Bound the SSH forwarding verification timeout

* Return the forwarding verification callback result

* fix(ai): support agent send and interrupt keyboard shortcuts

* feat(ai): add agent queues attachments worktrees and session recovery

* fix(ai): handle deleted workspace paths and duplicate status events

* fix(ai): accept file references in root workspaces

* fix(ai): refresh paused queues after agent errors

* fix(ai): store agent sessions in plugin tables and lock down OpenCode

Agent sessions lived in a single ctx.kv value holding up to 2000 events,
which passed the 256 KB kv limit within minutes of a normal run. Every
save after that failed, so history, nativeId, queue and archive changes
were lost and every event wrote a kv audit row.

Sessions, events and queued prompts now have their own tables. A running
agent appends events in batches at most once a second with a lazy save;
session and queue changes save immediately. Prompts, drafts and stored
event text are capped in UTF-8 bytes to fit MySQL TEXT. kv:own is no
longer requested.

The OpenCode server now requires a per-session password, so other local
accounts on the host cannot drive the agent through its loopback port.

* test(upgrade): include agent session tables in the reviewed upgrade SQL
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant