Watch
0
0
Fork
You've already forked hyperhive
0

hive-subagent-mcp: run an agent's subagents on its runtime

The subagent daemon now reads the parent agent's runtime at startup
(`hive_runtime::RuntimeSpec`, from the harness's `HIVE_RUNTIME` /
`HIVE_ACP_*`, which `mcp.nix` forwards onto its unit). On claude
nothing changes. On ACP, each run drives an `AcpRuntime` whose session
id is kept per name under the harness dir: `start` archives the old one,
`continue` loads it (and fails when none is recorded), `interrupt` sends
`session/cancel`, a role goes in front of the first prompt, and
permission requests get the answers a claude subagent's tool list
gives. The unit loads `backendEnvironmentFile` on ACP only, so the
agent can authenticate.

The end-of-turn handling moves out of the claude loop into `after_turn`
unchanged, so both loops share it.

Refs #4391
This commit is contained in:
atlas 2026-09-30 01:39:21 +02:00 • committed by mara
commit 84d4808d54
10 changed files with 689 additions and 71 deletions

View file

@ -228,6 +228,10 @@ in
On `"acp"`, `model`, `effortLevel` and `autoCompact` have no effect
(the model is whatever the agent is configured with), and neither the
web UI's cancel button nor `/compact` works yet.
Subagents (`hive-subagent-daemon`) run on the same runtime. On
`"acp"`, each subagent run spawns its own copy of the ACP agent, which
also gets `services.hyperhive.agent.backendEnvironmentFile`.
'';
};

View file

@ -391,6 +391,13 @@ in
# `null` when the agent has no groups declared, which systemd drops
# — the same "absent" the harness itself would see.
HIVE_TOOL_GROUPS = config.systemd.services.hive-agent.environment.HIVE_TOOL_GROUPS or null;
# The harness's runtime selection, forwarded the same way, so an ACP
# agent's subagents run on its ACP agent. All four are absent on a
# claude agent, which the daemon reads as claude.
HIVE_RUNTIME = config.systemd.services.hive-agent.environment.HIVE_RUNTIME or null;
HIVE_ACP_COMMAND = config.systemd.services.hive-agent.environment.HIVE_ACP_COMMAND or null;
HIVE_ACP_ARGS = config.systemd.services.hive-agent.environment.HIVE_ACP_ARGS or null;
HIVE_ACP_ENV = config.systemd.services.hive-agent.environment.HIVE_ACP_ENV or null;
# Same `services.hyperhive.agent.availableModels` the harness's own assertions gate
# the primary session's model against, so a subagent can't be spawned
# on a model the operator didn't make available to this agent. The
@ -451,7 +458,19 @@ in
}
// lib.optionalAttrs (containerMemoryMaxBytes != null) {
MemoryHigh = toString subagentMemoryHigh;
};
}
//
lib.optionalAttrs
(
config.services.hyperhive.agent.runtime == "acp"
&& config.services.hyperhive.agent.backendEnvironmentFile != null
)
{
# An ACP subagent authenticates to its provider with the same
# credentials as the harness's ACP agent. Claude subagents are
# not handed this file.
EnvironmentFile = "-${config.services.hyperhive.agent.backendEnvironmentFile}";
};
};
# Persistent streamable-http MCP daemon for the built-in hyperhive

View file

@ -134,6 +134,10 @@ in
inherit pkgs self nixosSystem;
inherit (pkgs) lib;
};
module-eval-agent-runtime = import ./module-eval/agent-runtime.nix {
inherit pkgs self nixosSystem;
inherit (pkgs) lib;
};
module-eval-agent-icon = import ./module-eval/agent-icon.nix {
inherit pkgs self nixosSystem;
inherit (pkgs) lib;

View file

@ -0,0 +1,73 @@
# `checks.module-eval-agent-runtime` — see ./lib.nix for the shared
# rationale (why this suite exists, naming convention, "evaluates
# not executes").
{
pkgs,
lib,
self,
nixosSystem,
}:
let
inherit
(import ./lib.nix {
inherit
pkgs
lib
self
nixosSystem
;
})
agentWith
runGroup
;
backendEnv = "/agents/a1/harness/backend.env";
# Both arms carry a backend file, so the claude arm's lack of one on the
# subagent unit is the gate and not a missing input.
agentOn =
runtime:
agentWith {
services.hyperhive.agent = {
inherit runtime;
backendEnvironmentFile = backendEnv;
acp.command = "/bin/agent";
acp.args = [ "acp" ];
};
};
claude = agentOn "claude";
acp = agentOn "acp";
subagent = machine: machine.systemd.services.hive-subagent-daemon;
harness = machine: machine.systemd.services.hive-agent;
runtimeVars = [
"HIVE_RUNTIME"
"HIVE_ACP_COMMAND"
"HIVE_ACP_ARGS"
"HIVE_ACP_ENV"
];
cases = [
{
# The daemon reads these with `hive_runtime::RuntimeSpec`, the same
# parser as the harness, so equal values mean the same runtime.
name = "an ACP agent's subagent daemon gets the harness's runtime selection";
ok = lib.all (
var: (subagent acp).environment.${var} or null == (harness acp).environment.${var}
) runtimeVars;
}
{
name = "an ACP agent's subagent daemon loads the backend credentials";
ok = (subagent acp).serviceConfig.EnvironmentFile or null == "-${backendEnv}";
}
{
# Unset is what `RuntimeSpec` reads as claude, and a claude subagent
# is not handed the backend file.
name = "a claude agent's subagent daemon has no runtime selection and no backend file";
ok =
lib.all (var: (subagent claude).environment.${var} or null == null) runtimeVars
&& !((subagent claude).serviceConfig ? EnvironmentFile);
}
];
in
runGroup "agent-runtime" cases