block / block/buzz

feat(desktop): support owner-reviewed local team snapshot imports

Open
#5,352 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Rust
Stars
32.7k
Forks
4.3k
Avg merge
1d 13h
Merged PRs (30d)
253

Description

**Motivation**

Buzz Desktop owns local agent and team state, but external tooling currently has no supported way to submit a deterministic team snapshot for owner review. The alternatives are manual repetition, undocumented state-file edits, or fragile accessibility automation. This is a focused first implementation slice of the broader secured Desktop control proposal in #4869.

**Proposed solution**

Add a versioned, same-user local Desktop control endpoint and matching `buzz desktop` commands with a deliberately narrow initial surface:

- `buzz desktop status --json` reports whether the running Desktop supports the protocol;
- `buzz desktop import-team-snapshot` submits a bounded snapshot with an idempotency key;
- Desktop stores the request durably, brings the existing snapshot-review UI forward, and leaves the owner to approve or reject the exact import;
- the endpoint never returns private keys or provider credentials and never bypasses existing validation or review.

On Unix platforms, the endpoint should use a user-only `0600` Unix-domain socket, reject non-owner peers, cap request size and read time, and return structured protocol errors. Unsupported platforms should fail explicitly rather than exposing a weaker transport.

**Alternatives considered**

- Accessibility automation is possible but brittle and cannot guarantee exact configuration or idempotency.
- Editing Desktop state files bypasses validation and keyring boundaries.
- Relay-side drafts do not provide durable receipt into the local Desktop review flow.
- A general remote HTTP administration API would create a much larger attack surface.

**Additional context**

This issue intentionally limits #4869 to owner-reviewed team snapshot imports and protocol status. Runtime registration, lifecycle management, settings, and Windows transport can follow separately after the security boundary and review flow are validated.

Proposed verification:

- protocol framing, peer authorization, permissions, timeouts, and payload limits;
- durable pending-import and idempotency behavior;
- CLI status/import success and structured failure cases;
- full repository CI (`./bin/just ci`).

Closest existing issue: #4869. No duplicate implementation PR was found.

---
[aidevops.sh](https://aidevops.sh) v3.32.238 plugin for [OpenCode](https://opencode.ai) v1.18.9 with gpt-5.6-sol

Contributor guide

Open the contributing guide

Research direction

Start by reviewing the broader secured Desktop control proposal in #4869 and locating the existing snapshot-review UI and `buzz desktop` command entry points. Verify the Unix-socket security requirements, durable pending-import and idempotency behavior, structured failures, and the listed CLI cases, then run `./bin/just ci` when the implementation is complete.

Written by the indexing model from the issue text.

Assessment

Tech stack
rust
Domain
cli, desktop, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.