Watch
0
0
Fork
You've already forked hyperhive
0
hyperhive/hive-agent
Repository files (latest commit first)
Filename Latest commit message Latest commit date
atlas 0f58cdbde2 swarm-queue-client: install aws-lc-rs as the process rustls provider
rustls is built with both `ring` (async-nats's `ring` feature) and
`aws-lc-rs` (reqwest's `rustls` feature), so it cannot pick a
process-level default by itself. Since the queue started requiring TLS
(1d261b3f), async-nats builds its config with `ClientConfig::builder()`,
which panics without an installed default. The panic kills the async-nats
connector task, and every queue client (swarm-controller, hive-c0re, all
hive-agents) has sat in `Pending` since the 2026-09-25 23:04Z deploy.

Add `swarm_queue_client::install_crypto_provider()`, which installs
aws-lc-rs and ignores the "already installed" error. It is called first in
`main` of every binary that links async-nats: hive-agent, hive-c0re,
swarm-controller, swarm-nats-auth. `connect()` also calls it, so a new
binary that dials through this crate is covered without remembering to.

aws-lc-rs because reqwest already falls back to it when no default is
installed, so HTTPS in these processes keeps its current provider. The
other rustls users in the tree reach it only through reqwest, which never
panics here.

Closes #4738
2026-09-27 04:17:24 +02:00
..
prompts remove the get_host_journal MCP tool and its capability 2026-09-21 19:31:45 +02:00
src swarm-queue-client: install aws-lc-rs as the process rustls provider 2026-09-27 04:17:24 +02:00
Cargo.toml log: send records natively to journald, keep stdout off-unit 2026-09-21 15:52:57 +02:00
README.md docs: give turn-loop/ a README.md landing page 2026-08-03 12:55:18 +02:00

hive-agent

The in-container harness serve-loop binary — one instance per agent. Long-polls the broker inbox and drives one claude --print turn per inbox message, over the hive-claude driver. There is one role here (agent); the Surface trait + AgentSurface zero-sized type tag keep the turn loop generic and testable for future roles without a parallel copy of the loop.

When to use it

You don't call into this crate from elsewhere — it's the top-level binary systemd starts per agent container. Look here when you need to understand or change: what happens between "a message lands in the inbox" and "claude produces a reply", how login/auth is bootstrapped, how the per-agent web UI is served, or how turn/event stats get recorded. Architecture detail lives in docs/turn-loop/; this README is just the map of the module tree.

Shape

  • turn.rs — the turn-loop policy layer: renders the system prompt + MCP config, invokes hive-claude, classifies the outcome, and feeds the event/turn-stats sinks.
  • client.rs — broker client (inbox poll, ack, send) speaking the hive-sh4re wire protocol.
  • login.rs / login_session.rs — first-run and session-resume auth flow for the claude CLI.
  • mcp_config.rs — renders the per-turn --mcp-config / --allowedTools blob from tool groups + capabilities.
  • todos.rs / reminders.rs / todo_server.rs — the harness-local loose-ends v2 stores (sqlite-backed) and the in-agent socket server extra MCP daemons + hive-agent-mcp dial into for todo/reminder ops.
  • vacuum.rs — periodic sqlite vacuum sweep for the harness-local stores.
  • events.rs / turn_stats.rs / stats.rs — append-only event sink and per-turn telemetry recording (context usage, cost, tool favorites) under harness/.
  • forge_notify.rs — subscribes to forge notifications and wakes the harness on new activity.
  • prompt.rs — system-prompt renderer (persona + tool docs + environment facts).
  • web_ui/ — the per-agent dashboard (terminal pane, status, schedules) served over the built-in hive-agent web port.
  • paths.rs — canonical path resolution for state/harness dirs and the harness-local sqlite files.

Sibling: hive-agent-mcp (the MCP server this loop points claude at every turn). Both are described together in docs/turn-loop/::Harness binary shape.