fix: drop stale claim that ruth is always reachable in allowedRecipients

The sentence 'ruth is always reachable regardless of the list' documents
a bug in check_send_allowed (name-based carve-out), not intended
behavior. The structural parent carve-out is fine to mention since it's
topology-based, not name-based.

Updated example to show [ "operator" ] (restrict to operator-only)
and replaced the ruth-name claim with a note about the parent carve-out.
This commit is contained in:
iris 2026-06-05 18:34:44 +02:00 committed by mara
commit f2d57c8538

View file

@ -488,9 +488,9 @@ ttl_seconds?, to?)`, `answer(id, answer)`.
message to a prior id for thread rendering. Per-agent
`hyperhive.allowedRecipients` (default: empty = unrestricted) limits
which names `send` accepts — useful for sandboxing: set
`[ "ruth" ]` to restrict a sub-agent to ruth-only chatter
(`ruth` is the manager's logical name). `ruth` is always reachable
regardless of the list.
`[ "operator" ]` to restrict a sub-agent to operator messages only
(the topology parent is always reachable regardless of this list —
that carve-out is structural, keyed on parent relationship, not name).
- `recv` — drain inbox. Without `wait_seconds` (or `0`) returns
immediately. Positive value parks the turn up to that many seconds
(cap 180) — incoming messages wake instantly. `max` (default 1, cap