docs: state current behaviour, drop remaining change-log wording
Refs #3902
This commit is contained in:
parent
9545151b8d
commit
37b8ca20d1
5 changed files with 16 additions and 20 deletions
|
|
@ -123,8 +123,7 @@ small and carry the semantic per-turn history the operator scrolls
|
||||||
back through when debugging a regression. Age-only within the
|
back through when debugging a regression. Age-only within the
|
||||||
`stream` kind — no row cap — so a chatty turn doesn't lose its stream
|
`stream` kind — no row cap — so a chatty turn doesn't lose its stream
|
||||||
history sooner than a quiet one. The trade-off (accepted): a
|
history sooner than a quiet one. The trade-off (accepted): a
|
||||||
misbehaving harness could now skip its own cleanup, which the old
|
misbehaving harness can skip its own cleanup — but a compromised harness is
|
||||||
host-side sweep was meant to prevent — but a compromised harness is
|
|
||||||
already inside the container trust boundary
|
already inside the container trust boundary
|
||||||
([`docs/trust-boundary/security.md`](../trust-boundary/security.md)), and these are ephemeral local
|
([`docs/trust-boundary/security.md`](../trust-boundary/security.md)), and these are ephemeral local
|
||||||
artifacts, so cleaning them up where they live is the honest fix.
|
artifacts, so cleaning them up where they live is the honest fix.
|
||||||
|
|
@ -536,12 +535,11 @@ container lifetime:
|
||||||
recursively so the agent user can read/write it. Wildcard
|
recursively so the agent user can read/write it. Wildcard
|
||||||
matches the single agent that container sees; `-h` skips
|
matches the single agent that container sees; `-h` skips
|
||||||
symlinks the agent might have planted.
|
symlinks the agent might have planted.
|
||||||
4. **Chown the `~/.claude/` bind-mount** recursively. Legacy
|
4. **Chown the `~/.claude/` bind-mount** recursively. The harness reads
|
||||||
`claude` wrote `.credentials.json` 0600 root:root; the
|
`~/.claude/` as the agent user to decide Online vs NeedsLogin in
|
||||||
current harness reads `~/.claude/` as the agent user to decide
|
`login::has_session`. Without the chown, credentials owned by
|
||||||
Online vs NeedsLogin in `login::has_session`. Without the
|
another uid get silently treated as "no session" and the operator
|
||||||
chown the existing credentials get silently treated as "no
|
re-prompts every boot.
|
||||||
session" and the operator re-prompts every boot.
|
|
||||||
5. **Hand the socket dir `/run/hive-agent/<name>` to the agent
|
5. **Hand the socket dir `/run/hive-agent/<name>` to the agent
|
||||||
user**, `0751`, not recursive. hive-priv creates it `0751 root`
|
user**, `0751`, not recursive. hive-priv creates it `0751 root`
|
||||||
on the host before every start; the harness binds its sockets
|
on the host before every start; the harness binds its sockets
|
||||||
|
|
|
||||||
|
|
@ -74,7 +74,7 @@ Cheap — no build slot:
|
||||||
| `DestroyContainer` | `nixos-container destroy` + un-registration (drop from the roster, clear the ephemeral runtime dir). Runs downstream of a `Stop`, so deliberately excluded from `takes_container_down` — the container is already down by the time it claims |
|
| `DestroyContainer` | `nixos-container destroy` + un-registration (drop from the roster, clear the ephemeral runtime dir). Runs downstream of a `Stop`, so deliberately excluded from `takes_container_down` — the container is already down by the time it claims |
|
||||||
| `PurgeState` | the `purge = true` half of a destroy: delete the agent's state subvolume (via hive-priv) plus its state/applied dirs. Own node because it's conditional and the irreversible step |
|
| `PurgeState` | the `purge = true` half of a destroy: delete the agent's state subvolume (via hive-priv) plus its state/applied dirs. Own node because it's conditional and the irreversible step |
|
||||||
| `DestroyBookkeeping` | the post-destroy tail — meta sync, fail pending approvals, drop the power intent, notify the manager, rescan, re-emit the tombstone. Same split rationale as `RebuildBookkeeping`/`Swap`. Its `purge` flag only selects the wording of the approval-failure reason and the manager notification — the destructive work is `PurgeState`'s |
|
| `DestroyBookkeeping` | the post-destroy tail — meta sync, fail pending approvals, drop the power intent, notify the manager, rescan, re-emit the tombstone. Same split rationale as `RebuildBookkeeping`/`Swap`. Its `purge` flag only selects the wording of the approval-failure reason and the manager notification — the destructive work is `PurgeState`'s |
|
||||||
| `SetWanted` | write the durable power intent (`wanted = Up`/`Offline`) as the head node of a power-op DAG, replacing the old pre-submit side effect. Takes the agent lease even though it's a store write, so the intent write and the tail `Reconcile` are atomic per-agent — two racing power ops can't clobber each other's intent before either reconciles |
|
| `SetWanted` | write the durable power intent (`wanted = Up`/`Offline`) as the head node of a power-op DAG. Takes the agent lease even though it's a store write, so the intent write and the tail `Reconcile` are atomic per-agent — two racing power ops can't clobber each other's intent before either reconciles |
|
||||||
| `FinalizeDeploy` | deploy phase 3 — drop the rollback ref, plant `deployed/<id>`, commit the staged `flake.lock`. The first two git steps are fatal on purpose, so a confirmed-good deploy's outcome and the repo's state can't disagree |
|
| `FinalizeDeploy` | deploy phase 3 — drop the rollback ref, plant `deployed/<id>`, commit the staged `flake.lock`. The first two git steps are fatal on purpose, so a confirmed-good deploy's outcome and the repo's state can't disagree |
|
||||||
| `ResolveApproval` | tail of an approval-carrying DAG — resolve the approval row from how the work ended (`AfterAny`, one node emitted per outcome). Agentless: the approval row already names its agent |
|
| `ResolveApproval` | tail of an approval-carrying DAG — resolve the approval row from how the work ended (`AfterAny`, one node emitted per outcome). Agentless: the approval row already names its agent |
|
||||||
| `EmitRebuilt` | tail of a rebuild/perm-change — emit the agent's `Rebuilt` manager event (ok/fail per outcome, nothing on cancel). One node per agent _and_ per outcome |
|
| `EmitRebuilt` | tail of a rebuild/perm-change — emit the agent's `Rebuilt` manager event (ok/fail per outcome, nothing on cancel). One node per agent _and_ per outcome |
|
||||||
|
|
@ -288,7 +288,7 @@ Every submit enqueues a fresh DAG; a multi-agent DAG has no single agent
|
||||||
to key a dedup on.
|
to key a dedup on.
|
||||||
|
|
||||||
Cancel only applies to DAGs that are still fully queued (an in-flight nix build isn't
|
Cancel only applies to DAGs that are still fully queued (an in-flight nix build isn't
|
||||||
interruptible) — each op is one DAG now, so there are no child DAGs to cascade to.
|
interruptible) — each op is one DAG, so there are no child DAGs to cascade to.
|
||||||
Roll-up state: `Failed` if any node failed, else `Running` / `Queued` /
|
Roll-up state: `Failed` if any node failed, else `Running` / `Queued` /
|
||||||
`Cancelled` / `Done`. The snapshot retains the 50 most recent terminal
|
`Cancelled` / `Done`. The snapshot retains the 50 most recent terminal
|
||||||
DAGs — a flat cap over the whole sorted list, not per template, since
|
DAGs — a flat cap over the whole sorted list, not per template, since
|
||||||
|
|
@ -325,7 +325,7 @@ one multi-resource root avoids by construction.
|
||||||
`UpdateMetaInputs` approvals map onto the ordinary
|
`UpdateMetaInputs` approvals map onto the ordinary
|
||||||
`meta-update` shapes. The scheduler fires `actions::resolve_approval_dag`
|
`meta-update` shapes. The scheduler fires `actions::resolve_approval_dag`
|
||||||
exactly once when **any** approval-carrying DAG settles terminal — deploys
|
exactly once when **any** approval-carrying DAG settles terminal — deploys
|
||||||
included, since their outcome is now the DAG's own state (including
|
included, since their outcome is the DAG's own state (including
|
||||||
cancelled-while-queued, which fails the approval instead of dangling it).
|
cancelled-while-queued, which fails the approval instead of dangling it).
|
||||||
|
|
||||||
### Wire shape
|
### Wire shape
|
||||||
|
|
|
||||||
|
|
@ -26,8 +26,8 @@ markdown-docs > docs/tools/forge-cli.md`.
|
||||||
**Kind-namespaced commands (preferred):** hive-forge groups issue/PR operations
|
**Kind-namespaced commands (preferred):** hive-forge groups issue/PR operations
|
||||||
under `issue` and `pr` parent commands — `hive-forge pr close 42`,
|
under `issue` and `pr` parent commands — `hive-forge pr close 42`,
|
||||||
`hive-forge issue create --title …`, `hive-forge pr status 42`. The
|
`hive-forge issue create --title …`, `hive-forge pr status 42`. The
|
||||||
`pr <verb>` / `issue <verb>` forms validate the number's kind (for example `pr close`
|
`pr <verb>` / `issue <verb>` forms validate the number's kind (for example, `pr close`
|
||||||
refuses an issue number, which the old generic `close` couldn't). Run
|
refuses an issue number). Run
|
||||||
`hive-forge pr --help` / `hive-forge issue --help` for the full subcommand
|
`hive-forge pr --help` / `hive-forge issue --help` for the full subcommand
|
||||||
list (show/create/edit/status/merge/reviews/commits/diff/view/comment/
|
list (show/create/edit/status/merge/reviews/commits/diff/view/comment/
|
||||||
comments/close/reopen/labels/assign/dependency/reaction/timeline as applicable).
|
comments/close/reopen/labels/assign/dependency/reaction/timeline as applicable).
|
||||||
|
|
|
||||||
|
|
@ -11,8 +11,7 @@ Shipped default-on for every agent — `nix/agent-modules/mcp.nix` injects
|
||||||
`subagent` into `services.hyperhive.agent.extraMcpServers` via `lib.mkDefault`
|
`subagent` into `services.hyperhive.agent.extraMcpServers` via `lib.mkDefault`
|
||||||
(`allowedTools = ["*"]`), same as `bash`. Default-on rather than
|
(`allowedTools = ["*"]`), same as `bash`. Default-on rather than
|
||||||
unconditional: an `agent.nix` can override or drop the entry, which is
|
unconditional: an `agent.nix` can override or drop the entry, which is
|
||||||
what `mkDefault` is there for. The operator's own framing: default-on for
|
what `mkDefault` is there for.
|
||||||
now, a real opt-in capability later.
|
|
||||||
|
|
||||||
For what the tools do and when an agent should reach for them, see the
|
For what the tools do and when an agent should reach for them, see the
|
||||||
`subagent` MCP server's own tool descriptions and the
|
`subagent` MCP server's own tool descriptions and the
|
||||||
|
|
@ -237,8 +236,8 @@ that works answers about as fast as it did before. A five-second cap
|
||||||
bounds the one case neither covers: a child that neither speaks nor
|
bounds the one case neither covers: a child that neither speaks nor
|
||||||
exits, reported as started, with the end-of-turn todo left to say how it
|
exits, reported as started, with the end-of-turn todo left to say how it
|
||||||
goes. That todo still carries every failure that happens later in the
|
goes. That todo still carries every failure that happens later in the
|
||||||
turn, exactly as before; the only one it no longer repeats is the miss
|
turn; it doesn't repeat the miss `continue` already handed the caller
|
||||||
`continue` has just handed the caller directly.
|
directly.
|
||||||
|
|
||||||
## A killed turn
|
## A killed turn
|
||||||
|
|
||||||
|
|
|
||||||
|
|
@ -52,9 +52,8 @@ at a given viewport width. Two columns:
|
||||||
- **Model badge** (`model · <name> ▾`): a real picker — selecting it opens
|
- **Model badge** (`model · <name> ▾`): a real picker — selecting it opens
|
||||||
a `Dropdown` of `state.available_models`, selecting one POSTs
|
a `Dropdown` of `state.available_models`, selecting one POSTs
|
||||||
`/api/model` immediately (same endpoint the `/model <name>` slash
|
`/api/model` immediately (same endpoint the `/model <name>` slash
|
||||||
command uses). No longer buried in the overflow menu — the design
|
command uses). A visible header badge, not tucked inside a menu —
|
||||||
guide's own named anti-example (control disconnected from
|
control and its display sit together.
|
||||||
display) this rewrite exists to fix.
|
|
||||||
- **Effort badge** (`effort · <level> ▾`): same shape, `/api/effort`,
|
- **Effort badge** (`effort · <level> ▾`): same shape, `/api/effort`,
|
||||||
shown when `state.available_efforts` is non-empty.
|
shown when `state.available_efforts` is non-empty.
|
||||||
- On an ACP agent both pickers list what its session offers (its
|
- On an ACP agent both pickers list what its session offers (its
|
||||||
|
|
|
||||||
Loading…
Reference in a new issue