From 5af1f6a8e5f89aab9b4086cd8a0c0e56343a49c7 Mon Sep 17 00:00:00 2001 From: atlas Date: Fri, 11 Sep 2026 16:13:31 +0200 Subject: [PATCH] docs, mcp.nix: an overridable default is not unconditional, and there are four subagent tools MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit `docs/tools/subagent.md` and `docs/tools/bash.md` both described their MCP server as injected "unconditionally". Both entries are `lib.mkDefault`, and the module says why one line above each: "so an agent.nix can still override/disable the entry", "so the operator's own agent.nix can override the entry". The word matters for the subagent one in particular. The same comment block records the framing that it is default-on for now and should become a real capability gate later, so "can I turn this off today?" is a question an operator has — and "unconditionally" answers it as "patch nix/" when the answer is one override in agent.nix. Both pages now say default, and say what the default yields to. The other direction on the same page: `subagentHttpPort`'s option description and the unit comment beside it both listed three tools, `start`/`continue`/`interrupt`. The daemon serves four. #4101, which introduced it, is titled with the three-verb phrasing, so `status` landed afterwards and never reached either description — while `subagent.md` had the full set all along. The option description renders into the generated options doc, so it is the one an operator reads. Closes #4231. --- docs/tools/bash.md | 9 +++++---- docs/tools/subagent.md | 6 ++++-- nix/agent-modules/mcp.nix | 4 ++-- 3 files changed, 11 insertions(+), 8 deletions(-) diff --git a/docs/tools/bash.md b/docs/tools/bash.md index 2fa6f7c3..a5855be0 100644 --- a/docs/tools/bash.md +++ b/docs/tools/bash.md @@ -2,10 +2,11 @@ Background shell execution via `hive-bash-daemon`. Tools land as `mcp__bash__` (the MCP server name is `bash`, not `hyperhive`). -Available on every agent unconditionally — `nix/agent-modules/mcp.nix` always -injects bash into `hyperhive.extraMcpServers` (with `allowedTools = -["*"]`), so `mcp__bash__*` is in `--allowedTools` for every claude -invocation regardless of tool groups. +Available on every agent by default — `nix/agent-modules/mcp.nix` injects +bash into `hyperhive.extraMcpServers` via `lib.mkDefault` (with +`allowedTools = ["*"]`), so `mcp__bash__*` is in `--allowedTools` for +every claude invocation regardless of tool groups. Default rather than +unconditional: an `agent.nix` can override or drop the entry. ## Tools diff --git a/docs/tools/subagent.md b/docs/tools/subagent.md index 0cc682dd..6f19d885 100644 --- a/docs/tools/subagent.md +++ b/docs/tools/subagent.md @@ -8,8 +8,10 @@ capability than a background shell command, so it gets its own deployable/restartable unit rather than living inside the bash daemon. Shipped default-on for every agent — `nix/agent-modules/mcp.nix` injects -`subagent` into `hyperhive.extraMcpServers` unconditionally (`allowedTools -= ["*"]`), same as `bash`. The operator's own framing: default-on for +`subagent` into `hyperhive.extraMcpServers` via `lib.mkDefault` +(`allowedTools = ["*"]`), same as `bash`. Default-on rather than +unconditional: an `agent.nix` can override or drop the entry, which is +what `mkDefault` is there for. The operator's own framing: default-on for now, a real opt-in capability later. For what the tools do and when an agent should reach for them, see the diff --git a/nix/agent-modules/mcp.nix b/nix/agent-modules/mcp.nix index 3d3f2c65..45a91b50 100644 --- a/nix/agent-modules/mcp.nix +++ b/nix/agent-modules/mcp.nix @@ -203,7 +203,7 @@ in example = 8794; description = '' Loopback port `hive-subagent-daemon` serves its MCP tools - (`start`/`continue`/`interrupt`) on. Independent daemon (own crate, + (`start`/`continue`/`status`/`interrupt`) on. Independent daemon (own crate, `hive-subagent-mcp`) — a subagent spawns a full nested `claude` process, a much heavier capability than a bash command, worth its own deployable/restartable unit. Same shape/reasoning as @@ -308,7 +308,7 @@ in # Subagent task runner daemon — independent of `hive-bash-daemon` (own # crate, own process): spawns nested claude sessions on request, serves - # the `start`/`continue`/`interrupt` MCP tools directly over + # the `start`/`continue`/`status`/`interrupt` MCP tools directly over # streamable-http on `hyperhive.mcp.subagentHttpPort`. No task files — # this daemon's only state is an in-memory map of currently-running # processes, live only as long as the process is (see