docs: delete two more stale manager-override claims

destroy has no manager-name check (actions.rs:837 says the root
container is 'destroyable like any other'), and crash-watch has no
name check at all (polls every managed container uniformly). The
pointer to broker.rs/actions.rs/crash_watch.rs for 'owner-check logic'
is also stale — none of the three hold any.
This commit is contained in:
atlas 2026-09-23 17:50:33 +02:00 • committed by mara
commit a65dbee982

View file

@ -131,17 +131,6 @@ Manager}` switch picks the MCP tool allow-list claude sees. Both are
injected uniformly via `systemd.globalEnvironment` for every injected uniformly via `systemd.globalEnvironment` for every
container including the manager, so all token/state paths resolve container including the manager, so all token/state paths resolve
through it the same way everywhere. through it the same way everywhere.
- **Scattered ownership checks** — a handful of independent
manager-only overrides exist across `hive-c0re` today: `destroy`
refusing to act on the manager, and crash-watch skipping
the manager (it autorestarts via systemd instead of going through
the crash-watch loop). Each is planned to become a capability
check instead of a manager-name check — see the
module docs for `stores/broker.rs`, `actions.rs`,
and `workers/crash_watch.rs` for the current owner-check logic in
each. (The harness handles reminder cancellation fully in-agent — see
the note on `CancelLooseEndKind::Reminder` in
`hive-c0re/src/socket_server/mod.rs`.)
<!-- vale write-good.Passive = YES --> <!-- vale write-good.Passive = YES -->
None of the above is a stable interface — treat the module doc None of the above is a stable interface — treat the module doc