The subagent daemon gets the agent's store identity on every agent with a store, whatever its runtime. The case pinned only the two ACP arms; it now covers the claude runtime too, and checks BAO_CLIENT_CERT/KEY as well.
161 lines
5 KiB
Nix
161 lines
5 KiB
Nix
# `checks.module-eval-agent-runtime` — see ./lib.nix for the shared
|
|
# rationale (why this suite exists, naming convention, "evaluates
|
|
# not executes").
|
|
{
|
|
pkgs,
|
|
lib,
|
|
self,
|
|
nixosSystem,
|
|
}:
|
|
let
|
|
inherit
|
|
(import ./lib.nix {
|
|
inherit
|
|
pkgs
|
|
lib
|
|
self
|
|
nixosSystem
|
|
;
|
|
})
|
|
agentWith
|
|
runGroup
|
|
;
|
|
|
|
backendEnv = "/agents/a1/harness/backend.env";
|
|
|
|
# Both arms carry a backend file, so the claude arm's lack of one on the
|
|
# subagent unit is the gate and not a missing input.
|
|
agentOn =
|
|
runtime:
|
|
agentWith {
|
|
services.hyperhive.agent = {
|
|
inherit runtime;
|
|
backendEnvironmentFile = backendEnv;
|
|
acp.command = "/bin/agent";
|
|
acp.args = [ "acp" ];
|
|
};
|
|
};
|
|
|
|
claude = agentOn "claude";
|
|
acp = agentOn "acp";
|
|
|
|
# The opencode preset, with and without a secret store.
|
|
opencodeWith =
|
|
extra:
|
|
agentWith {
|
|
services.hyperhive.agent = {
|
|
runtime = "acp";
|
|
acp.preset = "opencode";
|
|
acp.opencode.provider.baseUrl = "https://inference.t.local/v1";
|
|
acp.opencode.provider.apiKeyEnv = "T_PROVIDER_KEY";
|
|
acp.opencode.model = "m";
|
|
}
|
|
// extra;
|
|
};
|
|
opencode = opencodeWith { };
|
|
opencodeBao = opencodeWith { bao.addr = "https://bao.t.local:8200"; };
|
|
claudeBao = agentWith {
|
|
services.hyperhive.agent = {
|
|
runtime = "claude";
|
|
bao.addr = "https://bao.t.local:8200";
|
|
};
|
|
};
|
|
acpBao = agentWith {
|
|
services.hyperhive.agent = {
|
|
runtime = "acp";
|
|
acp.command = "/bin/agent";
|
|
bao.addr = "https://bao.t.local:8200";
|
|
};
|
|
};
|
|
|
|
subagent = machine: machine.systemd.services.hive-subagent-daemon;
|
|
harness = machine: machine.systemd.services.hive-agent;
|
|
runtimeVars = [
|
|
"HIVE_RUNTIME"
|
|
"HIVE_ACP_COMMAND"
|
|
"HIVE_ACP_ARGS"
|
|
"HIVE_ACP_ENV"
|
|
];
|
|
cases = [
|
|
{
|
|
# The daemon reads these with `hive_runtime::RuntimeSpec`, the same
|
|
# parser as the harness, so equal values mean the same runtime.
|
|
name = "an ACP agent's subagent daemon gets the harness's runtime selection";
|
|
ok = lib.all (
|
|
var: (subagent acp).environment.${var} or null == (harness acp).environment.${var}
|
|
) runtimeVars;
|
|
}
|
|
{
|
|
name = "an opencode agent's harness and subagent daemon are told its provider key variable";
|
|
ok =
|
|
(harness opencode).environment.HIVE_ACP_API_KEY_ENV == "T_PROVIDER_KEY"
|
|
&& (subagent opencode).environment.HIVE_ACP_API_KEY_ENV == "T_PROVIDER_KEY";
|
|
}
|
|
{
|
|
# Only the opencode preset has a provider key variable.
|
|
name = "an ACP agent off the opencode preset is told no provider key variable";
|
|
ok =
|
|
!((harness acpBao).environment ? HIVE_ACP_API_KEY_ENV)
|
|
&& (subagent acpBao).environment.HIVE_ACP_API_KEY_ENV or null == null;
|
|
}
|
|
{
|
|
# Every agent with a store, whatever its runtime: the daemon reads the
|
|
# agent's queue credential with it to publish subagent terminals.
|
|
name = "a subagent daemon gets the agent's store identity whenever the agent has a store";
|
|
ok =
|
|
lib.all
|
|
(
|
|
u:
|
|
u.serviceConfig.LoadCredential == [
|
|
"hive-agent-bao-cert"
|
|
"hive-agent-bao-key"
|
|
"hive-agent-bao-server-ca"
|
|
]
|
|
&& u.environment.HIVE_AGENT_NAME == "a1"
|
|
&& u.environment.BAO_ADDR == "https://bao.t.local:8200"
|
|
&& u.environment.BAO_CLIENT_CERT == "%d/hive-agent-bao-cert"
|
|
&& u.environment.BAO_CLIENT_KEY == "%d/hive-agent-bao-key"
|
|
)
|
|
[
|
|
(subagent claudeBao)
|
|
(subagent acpBao)
|
|
(subagent opencodeBao)
|
|
];
|
|
}
|
|
{
|
|
name = "an opencode agent's subagent daemon gets the agent's store identity";
|
|
ok =
|
|
let
|
|
u = subagent opencodeBao;
|
|
in
|
|
u.serviceConfig.LoadCredential == [
|
|
"hive-agent-bao-cert"
|
|
"hive-agent-bao-key"
|
|
"hive-agent-bao-server-ca"
|
|
]
|
|
&& u.environment.HIVE_AGENT_NAME == "a1"
|
|
&& u.environment.BAO_ADDR == "https://bao.t.local:8200"
|
|
&& u.environment.BAO_CLIENT_CERT == "%d/hive-agent-bao-cert"
|
|
&& u.environment.BAO_CLIENT_KEY == "%d/hive-agent-bao-key";
|
|
}
|
|
{
|
|
name = "an opencode agent with no store hands its subagent daemon no store identity";
|
|
ok =
|
|
!((subagent opencode).serviceConfig ? LoadCredential)
|
|
&& !((subagent opencode).environment ? BAO_ADDR);
|
|
}
|
|
{
|
|
name = "an ACP agent's subagent daemon loads the backend credentials";
|
|
ok = (subagent acp).serviceConfig.EnvironmentFile or null == "-${backendEnv}";
|
|
}
|
|
{
|
|
# Unset is what `RuntimeSpec` reads as claude, and a claude subagent
|
|
# is not handed the backend file.
|
|
name = "a claude agent's subagent daemon has no runtime selection and no backend file";
|
|
ok =
|
|
lib.all (var: (subagent claude).environment.${var} or null == null) runtimeVars
|
|
&& !((subagent claude).serviceConfig ? EnvironmentFile);
|
|
}
|
|
];
|
|
in
|
|
runGroup "agent-runtime" cases
|