diff --git a/docs/agent-lifecycle/persistence.md b/docs/agent-lifecycle/persistence.md index 4e7d6813..2c30bd1e 100644 --- a/docs/agent-lifecycle/persistence.md +++ b/docs/agent-lifecycle/persistence.md @@ -123,8 +123,7 @@ small and carry the semantic per-turn history the operator scrolls back through when debugging a regression. Age-only within the `stream` kind — no row cap — so a chatty turn doesn't lose its stream history sooner than a quiet one. The trade-off (accepted): a -misbehaving harness could now skip its own cleanup, which the old -host-side sweep was meant to prevent — but a compromised harness is +misbehaving harness can skip its own cleanup — but a compromised harness is already inside the container trust boundary ([`docs/trust-boundary/security.md`](../trust-boundary/security.md)), and these are ephemeral local artifacts, so cleaning them up where they live is the honest fix. @@ -536,12 +535,11 @@ container lifetime: recursively so the agent user can read/write it. Wildcard matches the single agent that container sees; `-h` skips symlinks the agent might have planted. -4. **Chown the `~/.claude/` bind-mount** recursively. Legacy - `claude` wrote `.credentials.json` 0600 root:root; the - current harness reads `~/.claude/` as the agent user to decide - Online vs NeedsLogin in `login::has_session`. Without the - chown the existing credentials get silently treated as "no - session" and the operator re-prompts every boot. +4. **Chown the `~/.claude/` bind-mount** recursively. The harness reads + `~/.claude/` as the agent user to decide Online vs NeedsLogin in + `login::has_session`. Without the chown, credentials owned by + another uid get silently treated as "no session" and the operator + re-prompts every boot. 5. **Hand the socket dir `/run/hive-agent/` to the agent user**, `0751`, not recursive. hive-priv creates it `0751 root` on the host before every start; the harness binds its sockets diff --git a/docs/scheduler/coordinator.md b/docs/scheduler/coordinator.md index 60aae812..f031cad0 100644 --- a/docs/scheduler/coordinator.md +++ b/docs/scheduler/coordinator.md @@ -74,7 +74,7 @@ Cheap — no build slot: | `DestroyContainer` | `nixos-container destroy` + un-registration (drop from the roster, clear the ephemeral runtime dir). Runs downstream of a `Stop`, so deliberately excluded from `takes_container_down` — the container is already down by the time it claims | | `PurgeState` | the `purge = true` half of a destroy: delete the agent's state subvolume (via hive-priv) plus its state/applied dirs. Own node because it's conditional and the irreversible step | | `DestroyBookkeeping` | the post-destroy tail — meta sync, fail pending approvals, drop the power intent, notify the manager, rescan, re-emit the tombstone. Same split rationale as `RebuildBookkeeping`/`Swap`. Its `purge` flag only selects the wording of the approval-failure reason and the manager notification — the destructive work is `PurgeState`'s | -| `SetWanted` | write the durable power intent (`wanted = Up`/`Offline`) as the head node of a power-op DAG, replacing the old pre-submit side effect. Takes the agent lease even though it's a store write, so the intent write and the tail `Reconcile` are atomic per-agent — two racing power ops can't clobber each other's intent before either reconciles | +| `SetWanted` | write the durable power intent (`wanted = Up`/`Offline`) as the head node of a power-op DAG. Takes the agent lease even though it's a store write, so the intent write and the tail `Reconcile` are atomic per-agent — two racing power ops can't clobber each other's intent before either reconciles | | `FinalizeDeploy` | deploy phase 3 — drop the rollback ref, plant `deployed/`, commit the staged `flake.lock`. The first two git steps are fatal on purpose, so a confirmed-good deploy's outcome and the repo's state can't disagree | | `ResolveApproval` | tail of an approval-carrying DAG — resolve the approval row from how the work ended (`AfterAny`, one node emitted per outcome). Agentless: the approval row already names its agent | | `EmitRebuilt` | tail of a rebuild/perm-change — emit the agent's `Rebuilt` manager event (ok/fail per outcome, nothing on cancel). One node per agent _and_ per outcome | @@ -288,7 +288,7 @@ Every submit enqueues a fresh DAG; a multi-agent DAG has no single agent to key a dedup on. Cancel only applies to DAGs that are still fully queued (an in-flight nix build isn't -interruptible) — each op is one DAG now, so there are no child DAGs to cascade to. +interruptible) — each op is one DAG, so there are no child DAGs to cascade to. Roll-up state: `Failed` if any node failed, else `Running` / `Queued` / `Cancelled` / `Done`. The snapshot retains the 50 most recent terminal DAGs — a flat cap over the whole sorted list, not per template, since @@ -325,7 +325,7 @@ one multi-resource root avoids by construction. `UpdateMetaInputs` approvals map onto the ordinary `meta-update` shapes. The scheduler fires `actions::resolve_approval_dag` exactly once when **any** approval-carrying DAG settles terminal — deploys -included, since their outcome is now the DAG's own state (including +included, since their outcome is the DAG's own state (including cancelled-while-queued, which fails the approval instead of dangling it). ### Wire shape diff --git a/docs/tools/forge.md b/docs/tools/forge.md index 3a43c748..c31ba652 100644 --- a/docs/tools/forge.md +++ b/docs/tools/forge.md @@ -26,8 +26,8 @@ markdown-docs > docs/tools/forge-cli.md`. **Kind-namespaced commands (preferred):** hive-forge groups issue/PR operations under `issue` and `pr` parent commands — `hive-forge pr close 42`, `hive-forge issue create --title …`, `hive-forge pr status 42`. The -`pr ` / `issue ` forms validate the number's kind (for example `pr close` -refuses an issue number, which the old generic `close` couldn't). Run +`pr ` / `issue ` forms validate the number's kind (for example, `pr close` +refuses an issue number). Run `hive-forge pr --help` / `hive-forge issue --help` for the full subcommand list (show/create/edit/status/merge/reviews/commits/diff/view/comment/ comments/close/reopen/labels/assign/dependency/reaction/timeline as applicable). diff --git a/docs/tools/subagent.md b/docs/tools/subagent.md index 392fd1fc..e7fec906 100644 --- a/docs/tools/subagent.md +++ b/docs/tools/subagent.md @@ -11,8 +11,7 @@ Shipped default-on for every agent — `nix/agent-modules/mcp.nix` injects `subagent` into `services.hyperhive.agent.extraMcpServers` via `lib.mkDefault` (`allowedTools = ["*"]`), same as `bash`. Default-on rather than unconditional: an `agent.nix` can override or drop the entry, which is -what `mkDefault` is there for. The operator's own framing: default-on for -now, a real opt-in capability later. +what `mkDefault` is there for. For what the tools do and when an agent should reach for them, see the `subagent` MCP server's own tool descriptions and the @@ -237,8 +236,8 @@ that works answers about as fast as it did before. A five-second cap bounds the one case neither covers: a child that neither speaks nor exits, reported as started, with the end-of-turn todo left to say how it goes. That todo still carries every failure that happens later in the -turn, exactly as before; the only one it no longer repeats is the miss -`continue` has just handed the caller directly. +turn; it doesn't repeat the miss `continue` already handed the caller +directly. ## A killed turn diff --git a/docs/web-ui/agent.md b/docs/web-ui/agent.md index 1a273d40..78e6bee4 100644 --- a/docs/web-ui/agent.md +++ b/docs/web-ui/agent.md @@ -52,9 +52,8 @@ at a given viewport width. Two columns: - **Model badge** (`model · ▾`): a real picker — selecting it opens a `Dropdown` of `state.available_models`, selecting one POSTs `/api/model` immediately (same endpoint the `/model ` slash - command uses). No longer buried in the overflow menu — the design - guide's own named anti-example (control disconnected from - display) this rewrite exists to fix. + command uses). A visible header badge, not tucked inside a menu — + control and its display sit together. - **Effort badge** (`effort · ▾`): same shape, `/api/effort`, shown when `state.available_efforts` is non-empty. - On an ACP agent both pickers list what its session offers (its