| Filename | Latest commit message | Latest commit date |
|---|---|---|
The hive had two spellings of "this agent may act on agents that aren't its children": the `ManageRootAgent` capability, which nothing checked, and a `can_manage_top_level_agents` role in a third meta store, `roles.json`, which owned the real grant — the bind mounts that put another agent's state (rw) and config (ro) inside the holder's container. The two drifted independently, and with the parent/child hierarchy removed the role's set (`parent.is_none()`) silently became every agent while nothing said so. Collapse them. The mount grant now hangs off `Capability::ManageRootAgent`, looked up through the one capability path that already exists (`capabilities::has_cap` over `capabilities.json`) rather than a second mechanism. `roles.json` and everything that read, wrote or reconciled it is gone, along with its `meta.rs` staging and commit-label wiring; nothing in the tree reads that file any more. The enum variant keeps its name deliberately. Renaming it would turn every `manage_root_agent` already stored in `capabilities.json` into an unrecognised name that `prune_unknown` drops without asking. Its meaning, not its spelling, is what changed: "may manage any agent". The doc comment and the description string now say that. `top_level_agents()`/`top_level_agents_in()` are replaced by `all_agents()`/`all_agents_in()`. Under "manage any agent" the mounted set is every agent by definition, so the code states it instead of deriving it from a predicate that no longer discriminates — and the call-site comment explains that, because it otherwise reads as a widening. The holder is no longer bound as its own virtual child: that reproduced the own-state and own-config mounts exactly, so dropping it loses nothing. |
||
| .. | ||
| prompts | ||
| src | ||
| Cargo.toml | ||
| README.md | ||
hive-agent
The in-container harness serve-loop binary — one instance per agent.
Long-polls the broker inbox and drives one claude --print turn per
inbox message, over the hive-claude driver. There is one role here
(agent); the Surface trait + AgentSurface zero-sized type tag keep
the turn loop generic and testable for future roles without a
parallel copy of the loop.
When to use it
You don't call into this crate from elsewhere — it's the top-level
binary systemd starts per agent container. Look here when you need to
understand or change: what happens between "a message lands in the
inbox" and "claude produces a reply", how login/auth is bootstrapped,
how the per-agent web UI is served, or how turn/event stats get
recorded. Architecture detail lives in
docs/turn-loop/; this README is just the
map of the module tree.
Shape
turn.rs— the turn-loop policy layer: renders the system prompt + MCP config, invokeshive-claude, classifies the outcome, and feeds the event/turn-stats sinks.client.rs— broker client (inbox poll, ack, send) speaking thehive-sh4rewire protocol.login.rs/login_session.rs— first-run and session-resume auth flow for theclaudeCLI.mcp_config.rs— renders the per-turn--mcp-config/--allowedToolsblob from tool groups + capabilities.todos.rs/reminders.rs/todo_server.rs— the harness-local loose-ends v2 stores (sqlite-backed) and the in-agent socket server extra MCP daemons +hive-agent-mcpdial into for todo/reminder ops.vacuum.rs— periodic sqlite vacuum sweep for the harness-local stores.events.rs/turn_stats.rs/stats.rs— append-only event sink and per-turn telemetry recording (context usage, cost, tool favorites) underharness/.forge_notify.rs— subscribes to forge notifications and wakes the harness on new activity.prompt.rs— system-prompt renderer (persona + tool docs + environment facts).web_ui/— the per-agent dashboard (terminal pane, status, schedules) served over the built-inhive-agentweb port.paths.rs— canonical path resolution for state/harness dirs and the harness-local sqlite files.
Sibling: hive-agent-mcp (the MCP server this loop points claude
at every turn). Both are described together in
docs/turn-loop/::Harness binary shape.