From a65dbee98256ecaa82e453acc5cb05f80213d22d Mon Sep 17 00:00:00 2001 From: atlas Date: Wed, 23 Sep 2026 17:50:33 +0200 Subject: [PATCH] docs: delete two more stale manager-override claims MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit destroy has no manager-name check (actions.rs:837 says the root container is 'destroyable like any other'), and crash-watch has no name check at all (polls every managed container uniformly). The pointer to broker.rs/actions.rs/crash_watch.rs for 'owner-check logic' is also stale — none of the three hold any. --- docs/agent-lifecycle/agent-hierarchy.md | 11 ----------- 1 file changed, 11 deletions(-) diff --git a/docs/agent-lifecycle/agent-hierarchy.md b/docs/agent-lifecycle/agent-hierarchy.md index e3b484d3..e9d7d7c6 100644 --- a/docs/agent-lifecycle/agent-hierarchy.md +++ b/docs/agent-lifecycle/agent-hierarchy.md @@ -131,17 +131,6 @@ Manager}` switch picks the MCP tool allow-list claude sees. Both are injected uniformly via `systemd.globalEnvironment` for every container including the manager, so all token/state paths resolve through it the same way everywhere. -- **Scattered ownership checks** — a handful of independent -manager-only overrides exist across `hive-c0re` today: `destroy` -refusing to act on the manager, and crash-watch skipping -the manager (it autorestarts via systemd instead of going through -the crash-watch loop). Each is planned to become a capability -check instead of a manager-name check — see the -module docs for `stores/broker.rs`, `actions.rs`, -and `workers/crash_watch.rs` for the current owner-check logic in -each. (The harness handles reminder cancellation fully in-agent — see -the note on `CancelLooseEndKind::Reminder` in -`hive-c0re/src/socket_server/mod.rs`.) None of the above is a stable interface — treat the module doc