Watch
0
0
Fork
You've already forked hyperhive
0

docs: state current behaviour, drop remaining change-log wording

Refs #3902
This commit is contained in:
atlas 2026-10-02 08:26:37 +02:00 • committed by mara
commit 37b8ca20d1
5 changed files with 16 additions and 20 deletions

View file

@ -123,8 +123,7 @@ small and carry the semantic per-turn history the operator scrolls
back through when debugging a regression. Age-only within the back through when debugging a regression. Age-only within the
`stream` kind — no row cap — so a chatty turn doesn't lose its stream `stream` kind — no row cap — so a chatty turn doesn't lose its stream
history sooner than a quiet one. The trade-off (accepted): a history sooner than a quiet one. The trade-off (accepted): a
misbehaving harness could now skip its own cleanup, which the old misbehaving harness can skip its own cleanup — but a compromised harness is
host-side sweep was meant to prevent — but a compromised harness is
already inside the container trust boundary already inside the container trust boundary
([`docs/trust-boundary/security.md`](../trust-boundary/security.md)), and these are ephemeral local ([`docs/trust-boundary/security.md`](../trust-boundary/security.md)), and these are ephemeral local
artifacts, so cleaning them up where they live is the honest fix. artifacts, so cleaning them up where they live is the honest fix.
@ -536,12 +535,11 @@ container lifetime:
recursively so the agent user can read/write it. Wildcard recursively so the agent user can read/write it. Wildcard
matches the single agent that container sees; `-h` skips matches the single agent that container sees; `-h` skips
symlinks the agent might have planted. symlinks the agent might have planted.
4. **Chown the `~/.claude/` bind-mount** recursively. Legacy 4. **Chown the `~/.claude/` bind-mount** recursively. The harness reads
`claude` wrote `.credentials.json` 0600 root:root; the `~/.claude/` as the agent user to decide Online vs NeedsLogin in
current harness reads `~/.claude/` as the agent user to decide `login::has_session`. Without the chown, credentials owned by
Online vs NeedsLogin in `login::has_session`. Without the another uid get silently treated as "no session" and the operator
chown the existing credentials get silently treated as "no re-prompts every boot.
session" and the operator re-prompts every boot.
5. **Hand the socket dir `/run/hive-agent/<name>` to the agent 5. **Hand the socket dir `/run/hive-agent/<name>` to the agent
user**, `0751`, not recursive. hive-priv creates it `0751 root` user**, `0751`, not recursive. hive-priv creates it `0751 root`
on the host before every start; the harness binds its sockets on the host before every start; the harness binds its sockets

View file

@ -74,7 +74,7 @@ Cheap — no build slot:
| `DestroyContainer` | `nixos-container destroy` + un-registration (drop from the roster, clear the ephemeral runtime dir). Runs downstream of a `Stop`, so deliberately excluded from `takes_container_down` — the container is already down by the time it claims | | `DestroyContainer` | `nixos-container destroy` + un-registration (drop from the roster, clear the ephemeral runtime dir). Runs downstream of a `Stop`, so deliberately excluded from `takes_container_down` — the container is already down by the time it claims |
| `PurgeState` | the `purge = true` half of a destroy: delete the agent's state subvolume (via hive-priv) plus its state/applied dirs. Own node because it's conditional and the irreversible step | | `PurgeState` | the `purge = true` half of a destroy: delete the agent's state subvolume (via hive-priv) plus its state/applied dirs. Own node because it's conditional and the irreversible step |
| `DestroyBookkeeping` | the post-destroy tail — meta sync, fail pending approvals, drop the power intent, notify the manager, rescan, re-emit the tombstone. Same split rationale as `RebuildBookkeeping`/`Swap`. Its `purge` flag only selects the wording of the approval-failure reason and the manager notification — the destructive work is `PurgeState`'s | | `DestroyBookkeeping` | the post-destroy tail — meta sync, fail pending approvals, drop the power intent, notify the manager, rescan, re-emit the tombstone. Same split rationale as `RebuildBookkeeping`/`Swap`. Its `purge` flag only selects the wording of the approval-failure reason and the manager notification — the destructive work is `PurgeState`'s |
| `SetWanted` | write the durable power intent (`wanted = Up`/`Offline`) as the head node of a power-op DAG, replacing the old pre-submit side effect. Takes the agent lease even though it's a store write, so the intent write and the tail `Reconcile` are atomic per-agent — two racing power ops can't clobber each other's intent before either reconciles | | `SetWanted` | write the durable power intent (`wanted = Up`/`Offline`) as the head node of a power-op DAG. Takes the agent lease even though it's a store write, so the intent write and the tail `Reconcile` are atomic per-agent — two racing power ops can't clobber each other's intent before either reconciles |
| `FinalizeDeploy` | deploy phase 3 — drop the rollback ref, plant `deployed/<id>`, commit the staged `flake.lock`. The first two git steps are fatal on purpose, so a confirmed-good deploy's outcome and the repo's state can't disagree | | `FinalizeDeploy` | deploy phase 3 — drop the rollback ref, plant `deployed/<id>`, commit the staged `flake.lock`. The first two git steps are fatal on purpose, so a confirmed-good deploy's outcome and the repo's state can't disagree |
| `ResolveApproval` | tail of an approval-carrying DAG — resolve the approval row from how the work ended (`AfterAny`, one node emitted per outcome). Agentless: the approval row already names its agent | | `ResolveApproval` | tail of an approval-carrying DAG — resolve the approval row from how the work ended (`AfterAny`, one node emitted per outcome). Agentless: the approval row already names its agent |
| `EmitRebuilt` | tail of a rebuild/perm-change — emit the agent's `Rebuilt` manager event (ok/fail per outcome, nothing on cancel). One node per agent _and_ per outcome | | `EmitRebuilt` | tail of a rebuild/perm-change — emit the agent's `Rebuilt` manager event (ok/fail per outcome, nothing on cancel). One node per agent _and_ per outcome |
@ -288,7 +288,7 @@ Every submit enqueues a fresh DAG; a multi-agent DAG has no single agent
to key a dedup on. to key a dedup on.
Cancel only applies to DAGs that are still fully queued (an in-flight nix build isn't Cancel only applies to DAGs that are still fully queued (an in-flight nix build isn't
interruptible) — each op is one DAG now, so there are no child DAGs to cascade to. interruptible) — each op is one DAG, so there are no child DAGs to cascade to.
Roll-up state: `Failed` if any node failed, else `Running` / `Queued` / Roll-up state: `Failed` if any node failed, else `Running` / `Queued` /
`Cancelled` / `Done`. The snapshot retains the 50 most recent terminal `Cancelled` / `Done`. The snapshot retains the 50 most recent terminal
DAGs — a flat cap over the whole sorted list, not per template, since DAGs — a flat cap over the whole sorted list, not per template, since
@ -325,7 +325,7 @@ one multi-resource root avoids by construction.
`UpdateMetaInputs` approvals map onto the ordinary `UpdateMetaInputs` approvals map onto the ordinary
`meta-update` shapes. The scheduler fires `actions::resolve_approval_dag` `meta-update` shapes. The scheduler fires `actions::resolve_approval_dag`
exactly once when **any** approval-carrying DAG settles terminal — deploys exactly once when **any** approval-carrying DAG settles terminal — deploys
included, since their outcome is now the DAG's own state (including included, since their outcome is the DAG's own state (including
cancelled-while-queued, which fails the approval instead of dangling it). cancelled-while-queued, which fails the approval instead of dangling it).
### Wire shape ### Wire shape

View file

@ -26,8 +26,8 @@ markdown-docs > docs/tools/forge-cli.md`.
**Kind-namespaced commands (preferred):** hive-forge groups issue/PR operations **Kind-namespaced commands (preferred):** hive-forge groups issue/PR operations
under `issue` and `pr` parent commands — `hive-forge pr close 42`, under `issue` and `pr` parent commands — `hive-forge pr close 42`,
`hive-forge issue create --title …`, `hive-forge pr status 42`. The `hive-forge issue create --title …`, `hive-forge pr status 42`. The
`pr <verb>` / `issue <verb>` forms validate the number's kind (for example `pr close` `pr <verb>` / `issue <verb>` forms validate the number's kind (for example, `pr close`
refuses an issue number, which the old generic `close` couldn't). Run refuses an issue number). Run
`hive-forge pr --help` / `hive-forge issue --help` for the full subcommand `hive-forge pr --help` / `hive-forge issue --help` for the full subcommand
list (show/create/edit/status/merge/reviews/commits/diff/view/comment/ list (show/create/edit/status/merge/reviews/commits/diff/view/comment/
comments/close/reopen/labels/assign/dependency/reaction/timeline as applicable). comments/close/reopen/labels/assign/dependency/reaction/timeline as applicable).

View file

@ -11,8 +11,7 @@ Shipped default-on for every agent — `nix/agent-modules/mcp.nix` injects
`subagent` into `services.hyperhive.agent.extraMcpServers` via `lib.mkDefault` `subagent` into `services.hyperhive.agent.extraMcpServers` via `lib.mkDefault`
(`allowedTools = ["*"]`), same as `bash`. Default-on rather than (`allowedTools = ["*"]`), same as `bash`. Default-on rather than
unconditional: an `agent.nix` can override or drop the entry, which is unconditional: an `agent.nix` can override or drop the entry, which is
what `mkDefault` is there for. The operator's own framing: default-on for what `mkDefault` is there for.
now, a real opt-in capability later.
For what the tools do and when an agent should reach for them, see the For what the tools do and when an agent should reach for them, see the
`subagent` MCP server's own tool descriptions and the `subagent` MCP server's own tool descriptions and the
@ -237,8 +236,8 @@ that works answers about as fast as it did before. A five-second cap
bounds the one case neither covers: a child that neither speaks nor bounds the one case neither covers: a child that neither speaks nor
exits, reported as started, with the end-of-turn todo left to say how it exits, reported as started, with the end-of-turn todo left to say how it
goes. That todo still carries every failure that happens later in the goes. That todo still carries every failure that happens later in the
turn, exactly as before; the only one it no longer repeats is the miss turn; it doesn't repeat the miss `continue` already handed the caller
`continue` has just handed the caller directly. directly.
## A killed turn ## A killed turn

View file

@ -52,9 +52,8 @@ at a given viewport width. Two columns:
- **Model badge** (`model · <name> ▾`): a real picker — selecting it opens - **Model badge** (`model · <name> ▾`): a real picker — selecting it opens
a `Dropdown` of `state.available_models`, selecting one POSTs a `Dropdown` of `state.available_models`, selecting one POSTs
`/api/model` immediately (same endpoint the `/model <name>` slash `/api/model` immediately (same endpoint the `/model <name>` slash
command uses). No longer buried in the overflow menu — the design command uses). A visible header badge, not tucked inside a menu —
guide's own named anti-example (control disconnected from control and its display sit together.
display) this rewrite exists to fix.
- **Effort badge** (`effort · <level> ▾`): same shape, `/api/effort`, - **Effort badge** (`effort · <level> ▾`): same shape, `/api/effort`,
shown when `state.available_efforts` is non-empty. shown when `state.available_efforts` is non-empty.
- On an ACP agent both pickers list what its session offers (its - On an ACP agent both pickers list what its session offers (its