fix: transport escalation exempts log reads, get_entity accepts slug alias, add restart_service + push_file tools
Some checks failed
ci / build-test (push) Has been cancelled
ci / docker-build (push) Has been cancelled
ci / web (push) Has been cancelled
Desktop App / Build Linux (amd64) (push) Has been cancelled
Desktop App / Attach to Release (push) Has been cancelled

P0: Transport escalation in classifyAndGate (server.go:745) now exempts
    log-inspection commands (tail/head/cat/journalctl on *.log or /logs/)
    from the /opt//etc//var/lib/ gating on LXC targets. Fixes the
    'tail -3 /opt/seanime/data/logs/seanime.log queued for approval' bug.

P1: queryEntity returns actionable error when slug_or_id param is empty
    ('slug_or_id is required') instead of silent 'entity not found: '.

P2: Added slugArg() helper (server.go) so get_entity, get_relations,
    get_blast_radius, and explain accept 'slug' as an alias for their
    declared param name. Solves the discoverability inconsistency where
    every tool used a different param name for the same concept.

P3: Two new MCP tools:
    - restart_service(target, service) — systemctl restart wrapper,
      correctly classified config_mutation (requires approval)
    - push_file(target, source_path, dest_path, backup=true) — pct push
      from Proxmox host into LXC, with optional backup. Classified
      config_mutation. LXC-only for now.

P4: Updated homelab-lxc-ops skill with MCP tools preference table.

Plus: Wails desktop build now uses build-tag approach for frontend embed
      (assets_embed.go + assets_stub.go), so go build ./... works on
      clean checkout without the frontend built first.

Version: 0.31.0 → 0.32.0
This commit is contained in:
2026-08-15 17:38:26 +02:00
parent 7160eee1e1
commit 8fbe39cf2a
11 changed files with 162 additions and 12 deletions

View File

@@ -0,0 +1,12 @@
//go:build desktop
package main
import "embed"
// assets is the embedded web SPA. Built only with the `desktop` tag, which is
// set by `make desktop` after it copies web/dist/* into cmd/desktop/frontend/dist
// (a gitignored build artifact). See assets_stub.go for the default build.
//
//go:embed frontend/dist
var assets embed.FS

View File

@@ -0,0 +1,12 @@
//go:build !desktop
package main
import "embed"
// assets is an empty FS for the default (non-desktop) build. The real embedded
// SPA lives in assets_embed.go behind the `desktop` build tag, because
// frontend/dist is a gitignored artifact that only exists after `make desktop`
// copies web/dist/* into it. This stub lets `go build ./...` compile cleanly on
// a fresh checkout without the frontend built.
var assets embed.FS

1
cmd/desktop/frontend/dist/.gitkeep vendored Normal file
View File

@@ -0,0 +1 @@
placeholder

View File

@@ -3,7 +3,7 @@ package main
import (
"crypto/rand"
"crypto/sha256"
"embed"
_ "embed" // required by the //go:embed icon.png directive below
"encoding/base64"
"encoding/json"
"fmt"
@@ -27,8 +27,10 @@ import (
"github.com/zalando/go-keyring"
)
//go:embed frontend/dist
var assets embed.FS
// assets is the embedded web SPA, defined in assets_embed.go (`desktop` build
// tag, real //go:embed frontend/dist) and assets_stub.go (default build, empty
// FS). frontend/dist is a gitignored artifact populated by `make desktop`; the
// stub keeps `go build ./...` working on a clean checkout.
//go:embed icon.png
var iconPNG []byte