← 提示词库 Meta/muse-code/skills/fleet-manager/references/verbs.md 原文 md
🌐 中英双语对照

fleet-manager verbs (scripts/fleet_manager.py) / fleet-manager 动词(scripts/fleet_manager.py)

The verb contract is shared with host-manager: one JSON object per verb,
one exit-code table, one receipt line per write. fleet-manager adds a
machine to every target and the machine verbs. <fleet> <verb> --help
prints the flags of one verb.

动词契约与 host-manager 共享:每个动词对应一个 JSON 对象、一张退出码表,每次写入对应一行回执。fleet-manager 在每个目标上增加了机器部分,并新增机器类动词。<fleet> <verb> --help 可打印某个动词的标志。

<fleet> = python3 <skill-dir>/scripts/fleet_manager.py
<fleet> [--mode herdr|tmux|auto] [--asked-by <who>] <verb> …

Envelope / 信封结构

Every verb prints exactly one object on stdout, success or failure:

无论成功或失败,每个动词都在 stdout 上恰好打印一个对象:

key meaning
outcome what happened, one word: a verb's own success word (healthy, detected, context, listed, machines, status, read, dialog, attach_command, resources, waited, ready, sent, notified, not_shown, keys_sent, answered, opened, interrupted, closed, adopted, forgotten, connected, fetched) or a failure word from the exit table
provider what served the verb: herdr, tmux, or null when none was selected
ref the target the verb acted on (a handle, an address, a machine label); null for fleet-wide reads
capabilities tmux: liveness, scrollback, guarded_input, attach_by_name; Herdr: those four plus agent_status, dialogs, prompt_readiness, wait, wait_for_output, workspace, tab, worktree, notify
progress one line per step already taken (also echoed to stderr)
next the one command that moves things forward; empty when there is nothing to do (no success word is ok; every failure word carries one, doctor when nothing more specific applies)
receipt write verbs only: what, session (the identity tuple), who, when (ISO-8601 UTC), and the same as one line (with the HH:MM UTC clock)
error failures only: the first thing wrong
text reads that render something (the board, a read, a dialog, the context digest)
键 含义
outcome 发生了什么,用一个词表示:动词自身的成功词(healthy、detected、context、listed、machines、status、read、dialog、attach_command、resources、waited、ready、sent、notified、not_shown、keys_sent、answered、opened、interrupted、closed、adopted、forgotten、connected、fetched),或退出码表中的失败词
provider 由谁服务该动词:herdr、tmux,未选中任何提供方时为 null
ref 动词作用的目标(一个句柄、一个地址、一个机器标签);全舰队读取时为 null
capabilities tmux:liveness、scrollback、guarded_input、attach_by_name;Herdr:上述四项外加 agent_status、dialogs、prompt_readiness、wait、wait_for_output、workspace、tab、worktree、notify
progress 每个已执行的步骤对应一行(同时回显到 stderr)
next 推动事情向前的那一条命令;无事可做时为空(没有任何成功词是 ok;每个失败词都对应一条,无更具体者时为 doctor)
receipt 仅写入类动词:what、session(身份元组)、who、when(ISO-8601 UTC),以及合并为一行 line 的同一内容(使用 HH:MM UTC 时钟)
error 仅失败时出现:最先出问题的地方
text 会渲染内容的读取(面板、一次读取、一个对话框、上下文摘要)

Exit codes:

退出码:

One verb streams instead: events (one line per change, for one Monitor;
events --once is one object).

有一个动词改以流方式工作:events(每次变更一行,面向单个 Monitor;events --once 则输出一个对象)。

Addresses / 地址

s3 (a handle the board minted) or machine[:server]/<ref>: machine is
local or a machine label; server is a Herdr session name (default: the
profile's); ref is a pane id (w1:p2), a unique live agent name, a human
label (the pane's label, its terminal title, its tab's or its workspace's
label — exact first, then a unique case-insensitive match; two matches name
the candidates), or a tmux session name. Pane ids, names and labels are
server-local: never drop the machine part.

s3(面板铸造的句柄)或 machine[:server]/<ref>:machine 是 local 或一个机器标签;server 是一个 Herdr 会话名(默认:profile 的会话名);ref 是一个窗格 id(w1:p2)、一个唯一的存活代理名、一个人工标签(窗格的标签、其终端标题、其标签页或工作区的标签——先精确匹配,再唯一的大小写不敏感匹配;出现两个匹配时会列出候选),或一个 tmux 会话名。窗格 id、名称与标签都是服务器局部的:绝不省略机器部分。

A handle-shaped address nobody minted (send s17 …, when a human named the
session s17) is not refused as an unknown handle: it is resolved like any
other name — one fleet read, every session's name and the labels a human
sees, exact first then a unique case-insensitive match; two answers name the
candidates, none is no_such_session. A handle this skill minted always
wins over a session named like it.

一个无人铸造却形似句柄的地址(当有人把会话命名为 s17 时的 send s17 …)不会被当作未知句柄而拒绝:它像其他任何名称一样被解析——一次全舰队读取,覆盖每个会话的名称与人工可见的标签,先精确匹配再唯一的大小写不敏感匹配;得到两个答案时列出候选,而不是返回 no_such_session。本技能铸造的句柄总是优先于恰好同名的会话。

A handle carries the identity tuple
(provider, machine, server, ref, cwd, engine) — server is the Herdr
socket path or the tmux socket label the verb actually used, stored on the
handle at open/adopt/list and compared like every other field — and every
write verb checks the whole tuple first: a restored pane is not the prior
process and a pane id or name can be reissued to a new one; a mismatch is
identity_mismatch (exit 3) naming adopt <address>, which takes the
session now under the address on purpose. list shows such a handle as
drift (…) and never re-points it at the stranger.

句柄携带身份元组 (provider, machine, server, ref, cwd, engine)——server 是该动词实际使用的 Herdr 套接字路径或 tmux 套接字标签,在 open/adopt/list 时存入句柄并与其他字段一样参与比较——每个写入动词都先检查整个元组:恢复出来的窗格不再是原先的进程,而且窗格 id 或名称可能被重新分配给新进程;不匹配即为 identity_mismatch(退出码 3),并指名 adopt <address>,用于有意接管现在位于该地址下的会话。list 会把这样的句柄显示为 drift (…),且绝不把它重新指向陌生的会话。

【评论】身份元组在每次写入前整体校验,是对"窗格 id 被重新分配给新进程"这类竞态的防护设计。

Read verbs (allow-listable) / 读取类动词(可列入允许清单)

verb does
doctor [--no-start] [--no-install] healthy (or needs_user_action / no_provider / provider_unreachable): checks rows (python, herdr, tmux, machines_directory, provider), every machine's reachability, the one next command; starts a stopped Herdr server, installs tmux when that needs no password
detect [--no-start] [--no-install] the provider decision for this host: reason (herdr_reachable, herdr_started, herdr_down, tmux_available, tmux_installed, requested, no_provider), providers rows (installed, reachable, server, version, capabilities)
context [--reset] one digest: sessions rows (each with identity and group: waiting-on-you, ready-for-review, working, idle; an MSP host's sessions come from one muse sessions --host <host> per online host of yours, four at a time under a per-host deadline (FLEET_MANAGER_MSP_LIST_TIMEOUT_S, 8 s) — a pending request is waiting-on-you, a running turn working, else idle — and carry provider: msp; a host that does not answer, or not in time, is unreachable with the transport's own message or "did not answer within N s (listing pending; ask again)", never "0 sessions"; strangers' hosts and sessions are never read or rendered), groups, machines with reachability (connected, stale, unreachable, disabled, or unverified for a directory row whose connect stopped before verification — its next is that connect, never an outage), coverage/unknowns, resources (cpu_count, load_1m, memory_available_mb, disk_free_mb, sampled_at), changed since the last call, items (outage, recovered; the cadence is under Outage cadence below), text
list [<machine>] [--dialogs] [--hint] the board (text), the compact inventory, and rows (one per server with agents, state, next_step); blocked first; every machine, connected or not. A Herdr row carries labels — the names a human sees (pane from the snapshot's panes, tab, workspace; empty ones and a tab's or workspace's own number left out) — and the board and context print the pane's name, else its tab's, in quotes beside the session, so the name a human gave a pane is on the board they read; a workspace label (usually what open --label wrote) stays in the row and addressable
machines Herdr's saved list plus ~/.config/muse/machines.toml, plus your MSP hosts (muse hosts over the transport CLI, with TBH_AGENTS_SESSION_PROTOCOL on; provider msp, source msp, the host's transport id as label and target): this machine's own advert, the hosts of your own login family (ids carrying your login as a dash-bounded token, msp-<user>-<host> and the like), every host you saved with connect <host id> or that an ssh row's label already names, every host holding a session this skill opened or adopted, and any host you name in the turn — never the rest of a shared directory, whose size is msp.directory (advertising, shown, not_shown) and one notes line; each with provider, modes (the modes it supports — an MSP host whose id an ssh-registered row already carries as its label or id is that one row with msp added — its sessions are read through its ssh provider, open on it prefers msp), reachability (an MSP host: connected when muse hosts says online, unreachable when offline — never a login), note, next; shadowed names directory rows Herdr also saves; with the flag on, msp (state, note, hosts) and, when the source is not available, one notes line saying why (no CLI, an older build without the muse verbs, a transport that does not answer)
status <addr> the identity tuple, live, agent status, identity_ok / identity_drift for a handle; a session that no longer exists is no_such_session (exit 3) — "gone", while provider_unreachable (exit 6) is "unknown"; an agentless Herdr pane this skill holds (a shell pane, an adopted raw pane) is status: no_agent with liveness_only: true; an MSP session answers through host-manager's status --mode msp --ref (group beside status)
read <addr> [--lines N] [--chars N] [--tail] [--source visible|recent|recent-unwrapped] the session's recent output (text, lines, the native status); --tail is the last --lines rows (default 60) of its visible screen as the engine drew them (blank rows and rule lines squeezed), chrome and all — you read it as you would in attach; an MSP session has no screen: --tail and the plain read are the same transport tail, status its group
dialog <addr> [--lines N] what a blocked session is asking (Herdr)
resources [<machine>] load, CPUs, memory, disk under $HOME on this host and every reachable machine (portable shell probes down the ladder)
wait <addr> [--until s1,s2] [--duration S] Herdr agent wait on one session (never a poll): waited with reached true or false and the last status; default states idle, done or blocked; default duration 600 s, enforced by the helper (Herdr's own --timeout is a backstop 5 s behind it); a Herdr-side error is a failure envelope — no_such_session (exit 3) for a target Herdr does not know, exit 6 otherwise — never read out of Herdr's prose
events [--interval S] [--once] [--kinds …] [--duration S] [--replay-baseline] the fleet stream for one Monitor (Herdr events.subscribe per reachable server; unreachable machines re-probed every --interval)
动词 作用
doctor [--no-start] [--no-install] healthy(或 needs_user_action / no_provider / provider_unreachable):checks 各行(python、herdr、tmux、machines_directory、provider)、每台机器的可达性、那一条 next 命令;会启动停着的 Herdr 服务器,并在无需密码时安装 tmux
detect [--no-start] [--no-install] 本主机的提供方决策:reason(herdr_reachable、herdr_started、herdr_down、tmux_available、tmux_installed、requested、no_provider)、providers 各行(installed、reachable、server、version、capabilities)
context [--reset] 一份摘要:sessions 各行(每行含 identity 与 group:waiting-on-you、ready-for-review、working、idle;你的 MSP 主机的会话来自对每台在线主机各执行一次 muse sessions --host <host>,每次四条、受每主机时限约束(FLEET_MANAGER_MSP_LIST_TIMEOUT_S,8 秒)——待处理的请求为 waiting-on-you,正在运行的轮次为 working,否则为 idle——并带有 provider: msp;不应答或未按时应答的主机为 unreachable,附传输层自身的消息或 "did not answer within N s (listing pending; ask again)",绝不会是 "0 sessions";陌生人的主机与会话绝不读取、绝不渲染)、groups、带可达性的机器(connected、stale、unreachable、disabled,或对 connect 在验证完成前中断的目录行标注 unverified——其 next 就是那次 connect,绝不是故障)、coverage/unknowns、resources(cpu_count、load_1m、memory_available_mb、disk_free_mb、sampled_at)、距上次调用以来 changed 的内容、items(outage、recovered;节奏见下文 Outage cadence 一节)、text
list [<machine>] [--dialogs] [--hint] 面板(text)、紧凑的 inventory 以及 rows(每台服务器一行,含 agents、state、next_step);阻塞者优先;涵盖每台机器,无论是否连接。Herdr 行携带 labels——人工可见的名称(pane 来自快照中的窗格、tab、workspace;空名称以及标签页或工作区自身的编号不列入)——且面板和 context 会在会话旁用引号打印窗格名,无窗格名时打印其标签页名,让人为窗格起的名字出现在他们所读的面板上;工作区标签(通常是 open --label 写入的内容)保留在行内且保持可寻址
machines Herdr 保存的列表加上 ~/.config/muse/machines.toml,再加上你的 MSP 主机(通过传输 CLI 执行 muse hosts,并开启 TBH_AGENTS_SESSION_PROTOCOL;provider 为 msp,source 为 msp,以主机的传输 id 作为标签与目标):包括本机自身的通告、你自己登录家族的主机(id 中以短横线界定的标记携带你的登录名,如 msp-<user>-<host> 等)、你用 connect <host id> 保存过的每台主机或 ssh 行标签已指名的主机、持有本技能所开或所接管会话的每台主机,以及你在本轮中点名的任何主机——绝不包含共享目录中的其余部分,其规模以 msp.directory(advertising、shown、not_shown)和一行 notes 表示;每台主机附 provider、modes(它支持的模式——若某 MSP 主机的 id 已被某条 ssh 注册行作为标签或 id 携带,则它就是那一行并加上 msp——其会话经由其 ssh 提供方读取,对其执行 open 时优先 msp)、reachability(MSP 主机:muse hosts 显示在线则为 connected,离线则为 unreachable——绝不归因于登录)、note、next;shadowed 指出 Herdr 也保存了的目录行;开关打开时还有 msp(state、note、hosts),以及当来源不可用时用一行 notes 说明原因(无 CLI、没有 muse 动词的旧版本、传输不应答)
status <addr> 身份元组、live、代理状态、句柄的 identity_ok / identity_drift;不再存在的会话是 no_such_session(退出码 3)——即"已消失",而 provider_unreachable(退出码 6)是"未知";本技能持有的无代理 Herdr 窗格(shell 窗格、接管的原始窗格)为 status: no_agent 且 liveness_only: true;MSP 会话通过 host-manager 的 status --mode msp --ref 应答(group 显示在 status 旁)
read <addr> [--lines N] [--chars N] [--tail] [--source visible|recent|recent-unwrapped] 会话的近期输出(text、lines、原生的 status);--tail 是其可见屏幕的最后 --lines 行(默认 60),按引擎绘制的样子呈现(压缩空行与分隔线),界面装饰一并包含——就像在 attach 中那样阅读;MSP 会话没有屏幕:--tail 与普通读取是同一个传输层尾部,status 即其 group
dialog <addr> [--lines N] 被阻塞的会话正在询问什么(Herdr)
resources [<machine>] 本主机及每台可达机器上的负载、CPU、内存、$HOME 所在磁盘(沿阶梯逐级使用可移植的 shell 探测)
wait <addr> [--until s1,s2] [--duration S] 对单个会话执行 Herdr agent wait(绝不是轮询):返回 waited,附 reached 真或假以及最后的 status;默认状态为 idle、done 或 blocked;默认时长 600 秒,由本助手强制执行(Herdr 自身的 --timeout 作为落后 5 秒的兜底);Herdr 侧错误是一个失败信封——Herdr 不认识的目标为 no_such_session(退出码 3),否则为退出码 6——绝不从 Herdr 的自然语言文本中推断
events [--interval S] [--once] [--kinds …] [--duration S] [--replay-baseline] 面向单个 Monitor 的全舰队事件流(每台可达服务器一个 Herdr events.subscribe;不可达机器每个 --interval 重新探测一次)

fetch <machine> <path> / 单文件取回

One report or library file home from a machine, by content hash.

从机器取回一份报告或一个库文件回家,依据内容哈希。

Steer verbs (allow-listable by subcommand) / 操纵类动词(可按子命令列入允许清单)

verb does
send <addr> <text> [--automated] a notification only a human watching the pane sees (Herdr notification show; tmux display-message); never types, and the agent never receives it — never sent: notified when Herdr reports it shown, not_shown for a tmux status-line message (it reaches only an attached client) or a Herdr shown: false; either says nothing was typed in message and its next is the --type form
approve <addr> [--key K] [--force] / deny <addr> … answers a recognised y/N or numbered dialog (Herdr); refused when the session is not blocked or the dialog is unreadable (--key after reading it). approve reads the dialog first: Enter confirms the highlighted choice (a ❯/› row, or a bare > only on a numbered row — Codex's > You are in <dir> banner is never the choice), so when that choice is not the affirmative one it refuses (code: agent_blocked, highlighted) and next is the attach command. When Herdr calls the session idle but the screen shows a dialog (Codex's directory trust, a fresh Muse trust prompt in some drives), the refusal carries code: agent_blocked and next is the one command that answers it: approve <addr> --force when the affirmative choice is highlighted, else the attach command
send <addr> --keys <key…> named keys for any other dialog (Herdr), under the composer guard; a row of the dialog's own choice block is not held text, so keys go through to answer it — a line a person typed is held text whatever shape it has
动词 作用
send <addr> <text> [--automated] 一种只有正盯着窗格的人才能看到的通知(Herdr notification show;tmux display-message);绝不键入任何内容,代理也永远收不到——成功词绝不是 sent:Herdr 报告已显示时为 notified,tmux 状态行消息(只会到达已连接的客户端)或 Herdr shown: false 时为 not_shown;两种情况都在 message 中写明 nothing was typed,且其 next 是 --type 形式
approve <addr> [--key K] [--force] / deny <addr> … 回答一个可识别的 y/N 或编号对话框(Herdr);当会话并非阻塞状态或对话框不可读时拒绝(读完对话框后才定 --key)。approve 先读取对话框:Enter 确认高亮的选项(❯/› 所在行,或仅编号行上的裸 >——Codex 的 > You are in <dir> 横幅绝不是选项),因此当该选项不是肯定项时它会拒绝(code: agent_blocked,附 highlighted),next 是 attach 命令。当 Herdr 认为会话空闲而屏幕上却显示对话框(Codex 的目录信任、某些驱动器上 Muse 新出现的信任提示)时,拒绝携带 code: agent_blocked,且 next 是回答它的那一条命令:肯定项高亮时为 approve <addr> --force,否则为 attach 命令
send <addr> --keys <key…> 为其他任何对话框发送指定的按键(Herdr),受输入行守卫约束;对话框自身选项块中的一行不算被占用的文本,因此按键可以直达以回答它——而人键入的一行无论什么形状都是被占用的文本

Guarded verbs (permission prompt) / 受守卫动词(需权限批准)

verb does
adopt <machine[:server]>/<ref> [--name N] mints a handle for a session this skill did not open, with its identity recorded (--name is a Herdr agent rename); a name another session already answers to is name_taken (exit 3) naming the holder, and nothing is adopted or renamed
attach <addr> the command a human runs to sit in front of the session; nothing is executed
stop <addr> interrupts the current turn (ctrl-c); the session stays; an agentless Herdr pane gets pane send-keys c-c into its shell; an MSP session has no ctrl-c — unsupported_by_provider naming close
close <addr> [--confirm "<the human's words>"] closes the pane / kills the tmux session; a live session (working, blocked, a non-shell program in any of its panes) is session_live (exit 3) without --confirm; on an MSP session host-manager's close --confirm ends its work (the running turn interrupted, its tasks stopped) and the receipt says the host keeps the row listed idle until it unloads it — gone is the host's own not_found (no_such_session); a repeat with the words is closed again
forget <label> [--confirm "<words>"] drops a machines.toml row (forgotten); session_live while it has live sessions unless confirmed; a Herdr-saved machine is Herdr's (next is herdr machine remove <id> — Herdr 0.9.0 takes the id from machine list --json, not the label)
动词 作用
adopt <machine[:server]>/<ref> [--name N] 为一个非本技能开启的会话铸造句柄,并记录其身份(--name 是 Herdr 的代理重命名);若另一个会话已应答同名,则为 name_taken(退出码 3)并指名持有者,且不做任何接管或重命名
attach <addr> 供人坐到会话面前所运行的命令;不执行任何东西
stop <addr> 中断当前轮次(ctrl-c);会话保留;无代理的 Herdr 窗格会向其 shell 发送 pane send-keys c-c;MSP 会话没有 ctrl-c——返回 unsupported_by_provider 并指名 close
close <addr> [--confirm "<the human's words>"] 关闭窗格 / 杀掉 tmux 会话;存活会话(工作中、被阻塞、任一窗格内有非 shell 程序)在无 --confirm 时返回 session_live(退出码 3);在 MSP 会话上,host-manager 的 close --confirm 结束其工作(正在运行的轮次被中断,其任务被停止),且回执说明主机把该行保持为空闲列出状态直至卸载它——gone 则是主机自身的 not_found(no_such_session);带着那句话重复执行会再次返回 closed
forget <label> [--confirm "<words>"] 删除一条 machines.toml 行(forgotten);其下还有存活会话时返回 session_live,除非已确认;Herdr 保存的机器归 Herdr 管(next 是 herdr machine remove <id>——Herdr 0.9.0 从 machine list --json 取 id,而不是标签)

send <addr> <text> --type [--wait] [--until …] [--timeout ms] [--automated] [--no-verify] [--verify-seconds S] [--steer] / 以提示词形式键入文本

On an MSP session --type is a message the agent receives as its next turn
(delivery: message) and --steer steers the running turn instead
(delivery: steer), both through host-manager's send; --wait, --until,
--timeout and the verify flags are listed under not_applied. A bare
send or --keys there is unsupported_by_provider: no pane, no composer.

在 MSP 会话上,--type 是代理将作为其下一轮收到的消息(delivery: message),而 --steer 则改为操纵正在运行的轮次(delivery: steer),两者都经由 host-manager 的 send;--wait、--until、--timeout 与各校验标志列在 not_applied 之下。在那里,裸 send 或 --keys 是 unsupported_by_provider:没有窗格,没有输入行。

Types the text into the session as a prompt: the form for the agent, whether
an instruction, a steer, a question or a reminder (--type; relayed text
adds --automated). A permission prompt in every
caller: the shipped allow-list template carries no text-send glob because
a glob cannot separate the notification form from --type and an allow
match wins (the notification form itself stays allow-listable by
subcommand).

把文本作为提示词键入会话:这是面向代理的形式,无论是指令、操纵、提问还是提醒(--type;转发的文本加 --automated)。对每个调用方都是一次权限提示:随附的允许清单模板不含针对文本 send 的 glob,因为 glob 无法把通知形式与 --type 区分开,而允许匹配优先(通知形式本身仍可按子命令列入允许清单)。

【评论】模板拒绝为文本 send 提供 glob,是因为允许匹配优先于询问;通配符会把"仅通知"的授权放大为"代写提示词"的授权。

open [<machine[:server]>] [--engine K] [--cwd D] [--name N] [--prompt-file PATH|-] [--worktree PATH] [--engine-arg=FLAG …] [--purpose TEXT] [--label TEXT] [--exact-name] [--unattended] [--timeout ms] / 打开新会话

Zero required arguments: local, muse, the repository root (else the
current directory), an auto name (<dir>-<n>; a taken name gets -2/-3,
--exact-name refuses with name_taken). Success is opened with
identity, created: true and a receipt.

无必填参数:机器默认 local、引擎默认 muse、目录默认仓库根(否则当前目录)、名称自动生成(<dir>-<n>;被占用则依次得 -2/-3,--exact-name 会以 name_taken 拒绝)。成功返回 opened,附 identity、created: true 和一份 receipt。

connect <ssh-target|label> [--label N] [--mode herdr|tmux] [--session S] [--no-login] / 连接远程机器

One command, one progress line per step; it stops at the first thing
wrong with next. via says herdr or ssh-master; remote carries what
that path observed.

一条命令,每步一行 progress;在第一处出错即停止并给出 next。via 标明 herdr 或 ssh-master;remote 携带该路径观测到的内容。

Provider rule and remote ladder / 提供方规则与远程阶梯

Herdr when installed and its server answers (started when down, never
installed); tmux otherwise (installed when that needs no password; else the
exact command in next); --mode overrides; Windows: no_provider. A
machine that advertises MSP is provider msp whatever the pin: its
sessions are host-manager's mode C, reached through host-manager's helper
(FLEET_MANAGER_HOST_MANAGER, else the host-manager skill beside this
one) — one call of it per verb, the two skills one record of the session.
No ssh ever goes to an MSP host id, and no session or command id is minted
here: host-manager's provider does that. resources does not read an MSP
host (no shell; reachability: unsupported), events does not watch one
(context does).

已安装且其服务器应答时用 Herdr(停着就启动,绝不安装);否则用 tmux(无需密码时安装;否则把确切命令放进 next);--mode 可覆盖;Windows 为 no_provider。通告 MSP 的机器无论钉定什么都以 msp 为提供方:其会话是 host-manager 的模式 C,经由 host-manager 的助手(FLEET_MANAGER_HOST_MANAGER,否则用本技能旁边的 host-manager 技能)访问——每个动词只调用它一次,两个技能共享同一份会话记录。ssh 绝不会发往 MSP 主机 id,这里也不铸造任何会话或命令 id:那是 host-manager 提供方的职责。resources 不读取 MSP 主机(没有 shell;reachability: unsupported),events 不监视它(由 context 负责)。

A machine is reached down one ladder: the forwarded Herdr socket (a
fleet-manager@<home host> pane on that server runs the command and its
output comes back through the pane) → the existing ssh ControlMaster
(BatchMode=yes, ControlMaster=no, never a fresh login) → unreachable
with connect as the next command. Output comes home through the pane or
the master and stops above FLEET_MANAGER_COPY_CAP_BYTES (4 MiB) on either
rung with the cap named; this host owns the record.

到达一台机器只经一条阶梯:转发的 Herdr 套接字(该服务器上的 fleet-manager@<home host> 窗格运行命令,其输出经窗格返回)→ 既有的 ssh ControlMaster(BatchMode=yes、ControlMaster=no,绝不重新登录)→ unreachable,next 为 connect。输出经窗格或 master 回家,在任一级上超过 FLEET_MANAGER_COPY_CAP_BYTES(4 MiB)即止并指明上限;记录归本主机所有。

Outage cadence: a machine that stops answering
is skipped for two minutes (a successful connect <label> ends that window
early) and keeps its last group in context as stale; one outage item
after ten minutes, one recovered item when it returns.

中断节奏:停止应答的机器被跳过两分钟(成功的 connect <label> 会提前结束该窗口),并在 context 中把其最后的分组保持为 stale;十分钟后产生一条 outage 项,恢复时产生一条 recovered 项。

Copying home is lazy. No verb copies a file per round: context and list
pull status only (one snapshot per machine). fetch is the only copy, by
content hash, and a repeated fetch of an unchanged file is one round trip
and no bytes. Symlinks are never followed; code comes home through a PR.

拷贝回家是惰性的。没有任何动词每轮都拷贝文件:context 与 list 只拉取状态(每台机器一个快照)。fetch 是唯一的拷贝,按内容哈希进行,对未变文件的重复 fetch 只花一次往返、零字节。符号链接绝不被跟随;代码通过 PR 回家。

Environment / 环境变量

TBH_AGENTS_SESSION_PROTOCOL (host-manager's flag: on lists MSP hosts and opens on them; off is the old path byte for byte), the transport CLI override host-manager honours (named in its references/mode-msp.md), FLEET_MANAGER_HOST_MANAGER (host-manager's skill directory; default: the sibling host-manager), FLEET_MANAGER_MSP_HELPER_TIMEOUT_S (300: one host-manager call), FLEET_MANAGER_MSP_LIST_TIMEOUT_S (8: one host's session listing inside a digest; past it the host is "not answered yet"); HERDR_BIN_PATH, HERDR_SOCKET_PATH (Herdr's own); FLEET_MANAGER_SSH, _DIR (forwards and masters, /tmp/fleet-manager-<uid>), _STATE (~/.local/share/muse/fleet-manager/state.json), _MACHINES (~/.config/muse/machines.toml), _SESSION, _REMOTE_SOCKET, _TMUX_SOCKET (a private tmux server), _ASKED_BY, _CONNECT_TIMEOUT_S (25; a login step gets at least the smaller of 5 s and that, however little budget is left), _SERVER_WAIT_S (12: how long a just-started remote server may take to answer over the forward), _COPY_CAP_BYTES, _CALL_TIMEOUT_S / _SSH_TIMEOUT_S / _API_TIMEOUT_S, _NOW (injected clock for tests).

TBH_AGENTS_SESSION_PROTOCOL(host-manager 的开关:开时列出 MSP 主机并可在其上打开;关时走旧路径、逐字节一致)、host-manager 认可的传输 CLI 覆盖项(在其 references/mode-msp.md 中指名)、FLEET_MANAGER_HOST_MANAGER(host-manager 的技能目录;默认:同级的 host-manager)、FLEET_MANAGER_MSP_HELPER_TIMEOUT_S(300:一次 host-manager 调用)、FLEET_MANAGER_MSP_LIST_TIMEOUT_S(8:摘要内一台主机的会话列举时限;超时后该主机为"尚未应答");HERDR_BIN_PATH、HERDR_SOCKET_PATH(Herdr 自身);FLEET_MANAGER_SSH、_DIR(转发与 master,/tmp/fleet-manager-<uid>)、_STATE(~/.local/share/muse/fleet-manager/state.json)、_MACHINES(~/.config/muse/machines.toml)、_SESSION、_REMOTE_SOCKET、_TMUX_SOCKET(一个私有 tmux 服务器)、_ASKED_BY、_CONNECT_TIMEOUT_S(25;登录步骤至少获得 5 秒与该值中较小者,无论剩余预算多少)、_SERVER_WAIT_S(12:刚启动的远端服务器经转发应答可等待的时长)、_COPY_CAP_BYTES、_CALL_TIMEOUT_S / _SSH_TIMEOUT_S / _API_TIMEOUT_S、_NOW(测试用注入时钟)。