docs: delete two more stale manager-override claims
destroy has no manager-name check (actions.rs:837 says the root container is 'destroyable like any other'), and crash-watch has no name check at all (polls every managed container uniformly). The pointer to broker.rs/actions.rs/crash_watch.rs for 'owner-check logic' is also stale — none of the three hold any.
This commit is contained in:
parent
d2c4c8d4a3
commit
a65dbee982
1 changed files with 0 additions and 11 deletions
|
|
@ -131,17 +131,6 @@ Manager}` switch picks the MCP tool allow-list claude sees. Both are
|
|||
injected uniformly via `systemd.globalEnvironment` for every
|
||||
container including the manager, so all token/state paths resolve
|
||||
through it the same way everywhere.
|
||||
- **Scattered ownership checks** — a handful of independent
|
||||
manager-only overrides exist across `hive-c0re` today: `destroy`
|
||||
refusing to act on the manager, and crash-watch skipping
|
||||
the manager (it autorestarts via systemd instead of going through
|
||||
the crash-watch loop). Each is planned to become a capability
|
||||
check instead of a manager-name check — see the
|
||||
module docs for `stores/broker.rs`, `actions.rs`,
|
||||
and `workers/crash_watch.rs` for the current owner-check logic in
|
||||
each. (The harness handles reminder cancellation fully in-agent — see
|
||||
the note on `CancelLooseEndKind::Reminder` in
|
||||
`hive-c0re/src/socket_server/mod.rs`.)
|
||||
<!-- vale write-good.Passive = YES -->
|
||||
|
||||
None of the above is a stable interface — treat the module doc
|
||||
|
|
|
|||
Loading…
Reference in a new issue