# `checks.module-eval-agent-runtime` — see ./lib.nix for the shared # rationale (why this suite exists, naming convention, "evaluates # not executes"). { pkgs, lib, self, nixosSystem, }: let inherit (import ./lib.nix { inherit pkgs lib self nixosSystem ; }) agentWith runGroup ; backendEnv = "/agents/a1/harness/backend.env"; # Both arms carry a backend file, so the claude arm's lack of one on the # subagent unit is the gate and not a missing input. agentOn = runtime: agentWith { services.hyperhive.agent = { inherit runtime; backendEnvironmentFile = backendEnv; acp.command = "/bin/agent"; acp.args = [ "acp" ]; }; }; claude = agentOn "claude"; acp = agentOn "acp"; # The opencode preset, with and without a secret store. opencodeWith = extra: agentWith { services.hyperhive.agent = { runtime = "acp"; acp.preset = "opencode"; acp.opencode.provider.baseUrl = "https://inference.t.local/v1"; acp.opencode.provider.apiKeyEnv = "T_PROVIDER_KEY"; acp.opencode.model = "m"; } // extra; }; opencode = opencodeWith { }; opencodeBao = opencodeWith { bao.addr = "https://bao.t.local:8200"; }; acpBao = agentWith { services.hyperhive.agent = { runtime = "acp"; acp.command = "/bin/agent"; bao.addr = "https://bao.t.local:8200"; }; }; subagent = machine: machine.systemd.services.hive-subagent-daemon; harness = machine: machine.systemd.services.hive-agent; runtimeVars = [ "HIVE_RUNTIME" "HIVE_ACP_COMMAND" "HIVE_ACP_ARGS" "HIVE_ACP_ENV" ]; cases = [ { # The daemon reads these with `hive_runtime::RuntimeSpec`, the same # parser as the harness, so equal values mean the same runtime. name = "an ACP agent's subagent daemon gets the harness's runtime selection"; ok = lib.all ( var: (subagent acp).environment.${var} or null == (harness acp).environment.${var} ) runtimeVars; } { name = "an opencode agent's harness and subagent daemon are told its provider key variable"; ok = (harness opencode).environment.HIVE_ACP_API_KEY_ENV == "T_PROVIDER_KEY" && (subagent opencode).environment.HIVE_ACP_API_KEY_ENV == "T_PROVIDER_KEY"; } { # Only the opencode preset has a provider key variable; any other ACP # command reads nothing from the store. name = "an ACP agent off the opencode preset is told no provider key variable"; ok = !((harness acpBao).environment ? HIVE_ACP_API_KEY_ENV) && (subagent acpBao).environment.HIVE_ACP_API_KEY_ENV or null == null && !((subagent acpBao).serviceConfig ? LoadCredential); } { name = "an opencode agent's subagent daemon gets the agent's store identity"; ok = let u = subagent opencodeBao; in u.serviceConfig.LoadCredential == [ "hive-agent-bao-cert" "hive-agent-bao-key" "hive-agent-bao-server-ca" ] && u.environment.HIVE_AGENT_NAME == "a1" && u.environment.BAO_ADDR == "https://bao.t.local:8200" && u.environment.BAO_CLIENT_CERT == "%d/hive-agent-bao-cert" && u.environment.BAO_CLIENT_KEY == "%d/hive-agent-bao-key"; } { name = "an opencode agent with no store hands its subagent daemon no store identity"; ok = !((subagent opencode).serviceConfig ? LoadCredential) && !((subagent opencode).environment ? BAO_ADDR); } { name = "an ACP agent's subagent daemon loads the backend credentials"; ok = (subagent acp).serviceConfig.EnvironmentFile or null == "-${backendEnv}"; } { # Unset is what `RuntimeSpec` reads as claude, and a claude subagent # is not handed the backend file. name = "a claude agent's subagent daemon has no runtime selection and no backend file"; ok = lib.all (var: (subagent claude).environment.${var} or null == null) runtimeVars && !((subagent claude).serviceConfig ? EnvironmentFile); } ]; in runGroup "agent-runtime" cases