P1 spine: monorepo, shared WS protocol, server daemon

- npm workspaces (shared / server / web), TS strict, project refs
- @arboretum/shared: multiplexed WS protocol (JSON control + binary
  output frames: 1B type + u32le channel), flow-control constants
  (ACK 256K, HIGH 384K, LOW 128K, lagging 2M), REST types
- git-arboretum server: Fastify 5 + node:sqlite (single native dep:
  node-pty prebuilt), token auth (sha256 at rest, HMAC cookie, global
  login rate limit + backoff), strict Origin check on /api and /ws,
  PtyManager (2MiB ring with monotonic offset, resync replay = reset +
  256KiB tail, pause/resume only when ALL interactive clients exceed
  HIGH, observers never throttle, lagging clients resync), WS gateway
  (attach/stdin/resize/ack, heartbeat 30s), SIGTERM→SIGKILL 5s grace
- CLI: arboretum [--port 7317] [--bind 127.0.0.1] — non-loopback bind
  requires an explicit safety flag
- Smoke-tested: login/401/403-origin/spawn bash/kill/grace-SIGKILL all
  green

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
Johan LEROY
2026-06-11 22:04:09 +02:00
parent 8733c17e44
commit f6f73329b9
25 changed files with 4467 additions and 474 deletions

View File

@@ -0,0 +1,31 @@
// Types REST partagés (préfixe /api/v1) — sous-ensemble P1.
import type { SessionSummary } from './protocol.js';
export interface ApiError {
error: { code: string; message: string; details?: unknown };
}
export interface LoginRequest {
token: string;
}
export interface LoginResponse {
ok: true;
label: string;
}
export interface MeResponse {
ok: true;
tokenLabel: string;
serverVersion: string;
}
export interface CreateSessionRequest {
cwd: string;
/** binaire à lancer — défaut "claude" ; "bash" sert aux tests d'acceptation sans quota */
command?: 'claude' | 'bash';
}
export interface SessionsListResponse {
sessions: SessionSummary[];
}
export interface SessionResponse {
session: SessionSummary;
}