Watch
0
0
Fork
You've already forked hyperhive
0
hyperhive/hive-host-sock
Repository files (latest commit first)
Filename Latest commit message Latest commit date
atlas 5785c0024c Make agent creation swarm-only and refuse a name placed on another hive
swarm-controller's POST /api/agents now refuses (409) a name the swarm
has already placed on a different hive: a non-Destroyed declaration in
that hive's wanted state, or a SetAgentWanted node still queued for it.
The same name on the same hive is that agent being re-created and goes
through. A wanted state that cannot be read refuses (503/500) instead of
reading as "placed nowhere". Creations are serialised from that read to
the graph insert so two concurrent creations of one name cannot both
pass.

Hive-level creation is removed: hivectl `agent create` / `request-create`,
HostRequest::Spawn / RequestSpawn, the dashboard POST /api/request-spawn
route, and ApprovalKind::Spawn with its approve/resolve arms and the
approval-carrying `templates::spawn`. The swarm path (deploy request or
wanted-state sweep -> queue_first_deploy -> templates::first_deploy) used
none of them. Old `spawn` approval rows are skipped by collect_lenient,
as `init_config` rows were in a3b672d1.

policy.rs's comment on agent_object_name stated swarm-wide name
uniqueness as a fact; it now says where it is enforced and what that
check cannot see.

Refs #4396
2026-09-29 15:47:40 +02:00
..
src Make agent creation swarm-only and refuse a name placed on another hive 2026-09-29 15:47:40 +02:00
Cargo.toml hivectl: migrate dag_progress to hive-jobq-wire's generic GraphNode 2026-08-03 20:35:24 +02:00
README.md docs: restructure into topic subdirectories, collapse duplicated index 2026-09-02 01:55:37 +02:00

hive-host-sock

Wire types for the host admin socket (/run/hyperhive/host.sock) — the host-control protocol spoken between the hivectl operator CLI and the hive-c0re daemon.

Why it's its own crate

Re-homed out of hive-sh4re so a standalone hivectl depends on just this protocol crate instead of the whole daemon-shared crate. hivectl drives the full hive (spawn / kill / destroy / rebuild / deploy) over this socket without linking hive-c0re; keeping the request/response shapes here is what makes that thin dependency possible.

Shape

Serde-derived request/response enums for the host admin protocol. The larger shared payload types some variants reference (Approval, AgentStatusRow) stay in hive-sh4re — this crate is only the protocol envelope, no server or client implementation.

Its own jobs module is the exception: the job-queue vocabulary hivectl needs (Source, State, PermPayload, NodeId) is protocol-local. The typed DagView/NodeView projection that used to live there is gone — the queue is served as a generic graph (hive-jobq-wire), not as a second hand-written view.

See docs/trust-boundary/boundary.md (host admin socket access) for the trust model around who may connect to the socket, and hive-priv-sock for the sibling split on the privileged-helper socket.