diff --git a/hive-c0re/src/agent_config/resource_limits.rs b/hive-c0re/src/agent_config/resource_limits.rs index 54cbb07e..46ea47df 100644 --- a/hive-c0re/src/agent_config/resource_limits.rs +++ b/hive-c0re/src/agent_config/resource_limits.rs @@ -225,8 +225,8 @@ pub fn write(map: &BTreeMap) -> std::io::Result<()> { /// /// # Errors /// -/// Propagates whatever [`write`] fails with. An unreadable or malformed -/// existing file is *not* an error — [`read`] degrades to an empty map, +/// Propagates whatever the `write` function fails with. An unreadable or malformed +/// existing file is *not* an error — the `read` function degrades to an empty map, /// so this call rewrites the file from scratch. pub fn set_limits(name: &str, limits: &AgentLimits) -> std::io::Result<()> { let mut current = read(); diff --git a/hive-c0re/src/container_view.rs b/hive-c0re/src/container_view.rs index 7bf4d88b..445ccaac 100644 --- a/hive-c0re/src/container_view.rs +++ b/hive-c0re/src/container_view.rs @@ -89,7 +89,7 @@ pub struct ContainerView { /// /// Takes `hive` because the effective resource limits are a per-field /// fallback onto the hive-wide `agent_cpu_quota` / `agent_memory_max`, -/// and those live on [`HiveEnv`], not on disk. Both callers already +/// and those live on [`crate::coordinator::HiveEnv`], not on disk. Both callers already /// hold a `Coordinator`, so this is a parameter rather than a global. pub async fn build_all(hive: &crate::coordinator::HiveEnv) -> Vec { let raw = lifecycle::list().await.unwrap_or_default(); diff --git a/hive-c0re/src/coordinator.rs b/hive-c0re/src/coordinator.rs index 4f1cf362..d2823532 100644 --- a/hive-c0re/src/coordinator.rs +++ b/hive-c0re/src/coordinator.rs @@ -81,7 +81,7 @@ pub struct Coordinator { /// Operator pronouns (free text) — `she/her` by default, set via /// the NixOS module option `services.hive-c0re.operatorPronouns`. /// Reaches each container as the `HIVE_OPERATOR_PRONOUNS` env var - /// (injected into systemd.services..environment by the + /// (injected into `systemd.services..environment` by the /// meta flake); the harness substitutes it into the agent / /// manager system prompt at boot. pub operator_pronouns: String, diff --git a/hive-c0re/src/forge/mod.rs b/hive-c0re/src/forge/mod.rs index 468d3904..51d44dc2 100644 --- a/hive-c0re/src/forge/mod.rs +++ b/hive-c0re/src/forge/mod.rs @@ -373,7 +373,7 @@ async fn ensure_all_orgs_and_repos(token: &str) { ci_runner::ensure_ci_runner_registered(token).await; } -/// Poll the local Forgejo API until it answers, bounded by [`READY_TIMEOUT`]. +/// Poll the local Forgejo API until it answers, with a timeout of 1 minute. /// The whole boot provisioning below hits the API, and [`is_present`] only /// confirms the container exists — not that Forgejo is *listening*. A /// `nixos-rebuild` that restarts hive-forge and hive-c0re together races: @@ -489,7 +489,7 @@ pub async fn ensure_all() { /// /// `webhook_secret` is the HMAC secret Forgejo will attach as /// `X-Hub-Signature-256` on each delivery; hive-c0re verifies this header -/// in [`crate::dashboard::webhook::post_webhook_config_pr`]. +/// in the dashboard webhook handler (`post_webhook_config_pr`). /// /// An org-level hook covers every repo in `agent-configs` automatically, /// so no per-repo setup is needed as new agents are provisioned. diff --git a/hive-c0re/src/forge/users.rs b/hive-c0re/src/forge/users.rs index cbd8ea20..27a40b7e 100644 --- a/hive-c0re/src/forge/users.rs +++ b/hive-c0re/src/forge/users.rs @@ -73,7 +73,7 @@ const CORE_TOKEN_SCOPES: &str = "read:admin,write:admin,read:user,write:user,rea /// Pull the access token out of forgejo's success message. Format /// has shifted across versions (table form vs. "Access token was -/// successfully created: "), so just hunt the output for the +/// successfully created: ``"), so just hunt the output for the /// first long hex-looking word. fn extract_token(output: &str) -> Option { output diff --git a/hive-c0re/src/job_queue/mod.rs b/hive-c0re/src/job_queue/mod.rs index e6011105..59738009 100644 --- a/hive-c0re/src/job_queue/mod.rs +++ b/hive-c0re/src/job_queue/mod.rs @@ -279,7 +279,7 @@ impl JobQueue { /// difference from the older lease-declaration test: lease-exemption is /// exactly what lets one DAG build for `a` while another holds `a`'s lease, /// so both are running and both name `a`. Anything keying this set by agent - /// alone will silently drop one — see [`super::scheduler`]. + /// alone will silently drop one — see [`scheduler`]. /// /// `label` is the node's own wire tag ([`NodeKind::as_str`]), the same /// vocabulary the graph wire ships as a node's label, so a pill and a @@ -361,7 +361,7 @@ impl JobQueue { filter_nodes_by_state(nodes, states) } - /// Per-state counts over the **same** groups [`Queue::graph_snapshot`] + /// Per-state counts over the **same** groups [`JobQueue::graph_snapshot`] /// serves. /// /// Supplies the same two things and nothing else: the lock, and @@ -413,7 +413,7 @@ fn find_node(sched: &Sched, id: u64) -> Option { .find_map(|n| (n.id.get() == id).then_some(n.id)) } -/// [`Queue::graph_snapshot`]'s `states` ask, applied to the already- +/// [`JobQueue::graph_snapshot`]'s `states` ask, applied to the already- /// projected node list: keeps every node — root or descendant — whose own /// `state` is named. /// @@ -433,7 +433,7 @@ fn filter_nodes_by_state(nodes: Vec, states: Option<&[State]>) -> Vec .collect() } -/// The visible **group** set for [`Queue::graph_snapshot`]: every live group +/// The visible **group** set for [`JobQueue::graph_snapshot`]: every live group /// root, plus the newest [`MAX_HISTORY_DAGS`] settled ones. /// /// Selected *structurally* — a root is a node with no parent. The typed diff --git a/hive-c0re/src/job_queue/model.rs b/hive-c0re/src/job_queue/model.rs index be77e688..a188b3ba 100644 --- a/hive-c0re/src/job_queue/model.rs +++ b/hive-c0re/src/job_queue/model.rs @@ -274,7 +274,7 @@ pub enum NodeKind { /// /// Weak-edged (`DepWhen::AFTER_ANY`) like [`NodeKind::DeployTail`], so it runs on /// success, failure **and cancel** alike and decides internally. It reads its - /// dependencies' terminal states off its own [`Claim::deps`] rather than + /// dependencies' terminal states from the node's dependency list rather than /// re-deriving them from the world the way `DeployTail` reads git: a node is /// *told* how the work it follows ended, it does not go back out and ask. /// @@ -324,7 +324,7 @@ pub enum NodeKind { /// How a hive-c0re node describes itself to a generic graph viewer. /// -/// Every field in [`WireNode::data`] here used to be a named column on +/// Every field in the wire node's `data` representation here used to be a named column on /// `NodeView`, meaningful for one node kind and `null` on all the others. As /// free-form data it costs the wire type nothing, and a generic consumer /// renders it without knowing what any of it means. diff --git a/hive-c0re/src/job_queue/resource.rs b/hive-c0re/src/job_queue/resource.rs index dbb3fdc0..a3c08f07 100644 --- a/hive-c0re/src/job_queue/resource.rs +++ b/hive-c0re/src/job_queue/resource.rs @@ -1,7 +1,7 @@ //! The concrete resource type the rebuild queue schedules over — the bridge -//! from hive-c0re's [`NodeKind`] onto the domain-agnostic `hive-jobq` crate. +//! from hive-c0re's [`super::model::NodeKind`] onto the domain-agnostic `hive-jobq` crate. //! `hive-jobq` is generic over a resource type `R: Clone + Eq + Hash` and a node -//! payload `N`; here `R` is [`Resource`] and `N` is [`NodeKind`] directly (each +//! payload `N`; here `R` is [`Resource`] and `N` is [`super::model::NodeKind`] directly (each //! variant carries the agent it targets). //! //! **A node's resources are declared where the node is constructed** with diff --git a/hive-c0re/src/main.rs b/hive-c0re/src/main.rs index c43d5385..c59450ff 100644 --- a/hive-c0re/src/main.rs +++ b/hive-c0re/src/main.rs @@ -67,7 +67,7 @@ enum Cmd { /// Run the coordinator daemon. Serve { /// Path to a JSON config file holding the host-level daemon config - /// (the [`ServeConfig`](crate::coordinator::ServeConfig) shape: + /// (the [`ServeConfig`] shape: /// the container-injected `HiveEnv` fields + the hive-c0re-local /// `model_prices` table). Used as the base; any per-flag override /// below wins over the file. Absent → start from the built-in diff --git a/hive-c0re/src/matrix.rs b/hive-c0re/src/matrix.rs index ed019656..8872ba10 100644 --- a/hive-c0re/src/matrix.rs +++ b/hive-c0re/src/matrix.rs @@ -337,7 +337,7 @@ async fn login_user(client: &reqwest::Client, agent: &str, password: &str) -> Re /// Auto-recovery helper: reset a user's matrix password via the admin API /// when the locally stored password is missing. Requires a valid hive admin /// token at [`admin_token_path()`]. Returns the new password (already -/// persisted to [`password_path(name)`]) on success. +/// persisted to [`password_path`]) on success. /// /// Called by [`ensure_user_for`] when registration returns `M_USER_IN_USE` /// but the password file is absent — covers the case where agent state dirs @@ -766,7 +766,7 @@ pub async fn ensure_user_for( /// can pass [`random_password`] to keep the existing throwaway /// behaviour. /// -/// **Not idempotent** (unlike [`forge::provision_user_token`]): the +/// **Not idempotent** (unlike [`crate::forge::provision_user_token`]): the /// matrix UIAA `/register` endpoint returns `M_USER_IN_USE` (HTTP 400) /// on second call for the same localpart. Callers re-running this for /// a known-existing matrix user should expect a hard error from this diff --git a/hive-c0re/src/socket_server/lifecycle_handlers.rs b/hive-c0re/src/socket_server/lifecycle_handlers.rs index 0e3c9e11..8feda850 100644 --- a/hive-c0re/src/socket_server/lifecycle_handlers.rs +++ b/hive-c0re/src/socket_server/lifecycle_handlers.rs @@ -53,7 +53,7 @@ pub(super) async fn handle_restart(coord: &Arc, agent: &str, name: /// Restart a hive infrastructure container on behalf of an agent that /// holds the `infra_admin` capability. The `container` is already a valid -/// [`InfraContainer`] (the caller parsed it); this gates on the capability +/// [`hive_priv_sock::InfraContainer`] (the caller parsed it); this gates on the capability /// and routes the systemctl restart through hive-priv. Direct, not /// approval-gated. async fn handle_restart_infra( diff --git a/hive-c0re/src/stats/container_stats.rs b/hive-c0re/src/stats/container_stats.rs index db80f355..ed298561 100644 --- a/hive-c0re/src/stats/container_stats.rs +++ b/hive-c0re/src/stats/container_stats.rs @@ -158,7 +158,7 @@ pub fn spawn_disk_sampler() { /// **not** create a separate machined `machine-.scope` — the /// container's cgroup *is* the launching service unit, /// `container@.service`, placed under `machine.slice`. -/// systemd-machined still logs "New machine " (registration), but the +/// systemd-machined still logs "New machine ``" (registration), but the /// cgroup stays on the service unit. So the path is /// `machine.slice/container@.service`, and the service unit name is /// used verbatim — no `\x2d` escaping (that only applies when a string is diff --git a/hive-c0re/src/stats/hive_stats.rs b/hive-c0re/src/stats/hive_stats.rs index 94b1e8c9..93bf6615 100644 --- a/hive-c0re/src/stats/hive_stats.rs +++ b/hive-c0re/src/stats/hive_stats.rs @@ -212,8 +212,8 @@ pub struct HiveStats { pub bash_mix: Vec, /// Most-triggered skills (fully-qualified `plugin:skill-name`) across /// the whole swarm, busiest first, capped to 10. Sourced from each - /// agent's `tool_call_breakdown_json` — see [`read_skill_breakdown`]. - /// Empty until at least one agent has actually invoked a skill. + /// agent's `tool_call_breakdown_json`. Empty until at least one agent has + /// actually invoked a skill. pub skill_mix: Vec, } diff --git a/hive-c0re/src/stats/otel_metrics.rs b/hive-c0re/src/stats/otel_metrics.rs index 2ae9c24a..e9d3291d 100644 --- a/hive-c0re/src/stats/otel_metrics.rs +++ b/hive-c0re/src/stats/otel_metrics.rs @@ -47,7 +47,7 @@ static PROVIDER: OnceLock = OnceLock::new(); /// Spawn the container-resource OTEL exporter if OTEL is configured /// (`HYPERHIVE_OTEL_ENDPOINT` non-empty — the same enable signal -/// [`crate::meta::otel_config`] uses). No-op otherwise. Call once at startup. +/// `meta::otel_config` uses). No-op otherwise. Call once at startup. pub fn spawn_exporter(hyperhive_flake: &str) { let Some(endpoint) = endpoint() else { tracing::debug!("otel container-metrics: no endpoint configured, exporter disabled"); diff --git a/hive-c0re/src/stores/audit_log.rs b/hive-c0re/src/stores/audit_log.rs index e2928f2b..b1de06e4 100644 --- a/hive-c0re/src/stores/audit_log.rs +++ b/hive-c0re/src/stores/audit_log.rs @@ -14,8 +14,8 @@ //! signal the operator actually wants. //! //! Same process-singleton handle pattern as `build_logs`: installed once -//! at `Coordinator::open`, fetched via [`global`] so the recording sites -//! (e.g. `socket_server::handle_restart_infra`) don't have to thread an +//! at `Coordinator::open`, and fetched by recording sites (e.g. +//! `socket_server::handle_restart_infra`) so they don't have to thread an //! `Arc` through every call path. Recording is best-effort: a //! sqlite blip must never fail the underlying privileged action. diff --git a/hive-c0re/src/workers/agent_sockets.rs b/hive-c0re/src/workers/agent_sockets.rs index 8f2673bb..ac1c0cbd 100644 --- a/hive-c0re/src/workers/agent_sockets.rs +++ b/hive-c0re/src/workers/agent_sockets.rs @@ -56,7 +56,7 @@ pub fn agent_dir_for(name: &str) -> PathBuf { /// Compute the deterministic socket path for an agent. Pure function /// of the agent name so the value matches whatever -/// [`agent_sockets::write`] writes for that agent, and whatever the +/// [`write()`] writes for that agent, and whatever the /// harness binds via `HIVE_WEB_SOCKET`. #[must_use] pub fn socket_path_for(name: &str) -> PathBuf { diff --git a/hive-c0re/src/workers/knowledge.rs b/hive-c0re/src/workers/knowledge.rs index e8e2cdc5..999a1dbe 100644 --- a/hive-c0re/src/workers/knowledge.rs +++ b/hive-c0re/src/workers/knowledge.rs @@ -153,7 +153,7 @@ async fn seed_readme(core_token: &str) -> Result<()> { /// /// `webhook_secret` is the HMAC secret Forgejo will attach as /// `X-Hub-Signature-256` on each delivery; hive-c0re verifies this header -/// in [`crate::dashboard::webhook::post_webhook_knowledge`]. +/// in the dashboard webhook handler (`post_webhook_knowledge`). /// /// Called at startup alongside [`ensure_local_clone`]. No-op when the /// core token is absent (forge not yet provisioned).