`goal_reached`/`need_help` took the session name as a tool argument, so identity was an assertion by the caller and the only guard on it was `occupancy()` — "does that name have a turn in flight", which two concurrently running siblings both satisfy for each other. A subagent could stop its sibling's run by naming it. Identity moves into the URL. Each spawned run is minted an unguessable token (`Uuid::new_v4`, the OS CSPRNG), the URL carrying it goes into that one subagent's own `--mcp-config`, and the route resolves it back to a session before dispatching to a handler bound to that session. Neither tool takes a `name` any more: a subagent has no field in which to name a sibling, and a sibling's name — which a brief may well mention — is not a token. One route with a path parameter, not a route per session: the `Router` is built once at startup and subagents come and go for the daemon's whole life. An unminted or revoked token gets a bare 404, the same answer either way, so nothing enumerates. A run's token is revoked when the run ends (`finish_turn`) or when a call never reached a spawn. Two things fall out of that: - the config file becomes one per session. A single shared path was already a race between two `start`s; with a per-session URL in it, the loser would read the winner's identity. - `occupancy()` stops being the identity guard and is gone from the signal path entirely rather than kept "just in case" — a revoked token can't reach it, and it never answered the question it was standing in for. It still backs `status`, which is what it was always actually for. Refs #4403 Refs #4413
45 lines
1.4 KiB
TOML
45 lines
1.4 KiB
TOML
[package]
|
|
name = "hive-subagent-mcp"
|
|
edition.workspace = true
|
|
version.workspace = true
|
|
readme = "README.md"
|
|
|
|
[lints]
|
|
workspace = true
|
|
|
|
[dependencies]
|
|
anyhow.workspace = true
|
|
axum.workspace = true
|
|
clap.workspace = true
|
|
hive-agent-sock.workspace = true
|
|
hive-claude.workspace = true
|
|
hive-sock-client.workspace = true
|
|
hive-types.workspace = true
|
|
libc.workspace = true
|
|
rmcp.workspace = true
|
|
schemars.workspace = true
|
|
serde.workspace = true
|
|
serde_json.workspace = true
|
|
tokio.workspace = true
|
|
tracing.workspace = true
|
|
tracing-subscriber.workspace = true
|
|
# Signal-route tokens. `Uuid::new_v4` draws from the OS CSPRNG (getrandom),
|
|
# which is the property the per-session URL rests on — see
|
|
# `session::State::mint_signal_url`.
|
|
uuid.workspace = true
|
|
|
|
# `test-util` for `#[tokio::test(start_paused = true)]`: the `continue`
|
|
# resume-grace tests assert what happens when the bound is actually reached,
|
|
# and paused time gets that answer without a five-second unit test.
|
|
[dev-dependencies]
|
|
tokio = { workspace = true, features = ["test-util"] }
|
|
|
|
# `hive-subagent-daemon` — long-running per-agent claude-subagent runner.
|
|
# Independent of `hive-bash-mcp` (own crate, own binary, own MCP server) —
|
|
# see lib.rs's module doc for why. Serves its MCP tools (`start`/
|
|
# `continue`/`status`/`interrupt`, plus the subagent-facing
|
|
# `goal_reached`/`need_help` route) directly over streamable-http — no
|
|
# stdio bridge.
|
|
[[bin]]
|
|
name = "hive-subagent-daemon"
|
|
path = "src/main.rs"
|