| Filename | Latest commit message | Latest commit date |
|---|---|---|
Review finding from argus. The new endpoint test carried a SAFETY comment claiming no other test in its module asserts on the variables it perturbs — the wrong boundary. The module is not the unit that shares the environment, the process is: meta.rs's render_flake_injects_otel_when_signalled mutates the same HYPERHIVE_OTEL_ENDPOINT, both land in the one hive-c0re test binary, and cargo runs it at default parallelism with no serialisation anywhere in the crate. Each test independently claimed exclusive ownership of shared global state, which is the instrument-that-looks-solid class the endpoint change's own gate reasoning warns about. Adds test_env with a single ENV_LOCK, taken by both. No new dependency: this is the pattern hive-bash-mcp and hive-agent already use, and hive-bash-mcp's helper records why it has to be crate-wide rather than per-module — two per-module mutexes serialise nothing against each other, which produced a CI-only flake there. The asymmetry that makes this hard to see locally is worth stating: an agent container has the hyperhive variables ambient-set, so a losing race still finds a plausible value and the test passes; the nix sandbox strips them, so only there can one thread delete a variable out from under another. Verified in that shape with `env -u HYPERHIVE_OTEL_ENDPOINT -u OTEL_EXPORTER_OTLP_ENDPOINT`, five consecutive runs green — a sanity check, not a proof, since a race cannot be shown absent by running. What makes it correct is structural: both tests take the same lock. Deliberately scoped to the pair that overlaps. meta.rs has three further env-mutating tests (HIVE_FORGE_URL twice, the TLS CA pair) that race with each other, untouched here and tracked separately, because the fix is not the mechanical one it looks like: std::sync::Mutex is not reentrant, so adding a lock to a test whose helpers also lock deadlocks. That needs reading per test rather than a sweep. |
||
| .. | ||
| src | ||
| Cargo.toml | ||
| README.md | ||
hive-c0re
The unprivileged host daemon (runs as hive-core). Owns the sqlite
broker, the approval/question/schedule queues, the generic job-DAG
queue, container lifecycle, gateway/forge/matrix provisioning,
per-container stats, and the axum operator dashboard. Largest crate in
the workspace — bin-only, no separate lib.
When to use it
Host-level, cross-container orchestration: spawning/rebuilding/
destroying agent containers, the approval flow, dashboard-visible
state, provisioning per-agent forge/matrix/gateway accounts. Agent-side
behavior (turn loop, MCP tools) lives in hive-agent/hive-agent-mcp
instead — this daemon only talks to agents over the socket wire types
in hive-sh4re.
Shape
Cohesive clusters live in directory submodules, each re-exported at
the crate root (crate::broker::… keeps resolving regardless of which
subdirectory a module actually lives in). One line each — read the
module's own //! doc-comment for real detail, don't expect this file
to track it:
dashboard/— the operator dashboard (containers, approvals, schedules, questions, logs, topology).job_queue/— the job-DAG queue + desired-state reconciliation (docs/coordinator.md).lifecycle/—nixos-containerlifecycle + per-agent config flake generation.stores/— sqlite-backed stores (broker, queues, audit, power).workers/— background sweeps (crash watch, scheduled prompts, auto-update, knowledge sync).agent_config/— per-agent registries (tool groups, capabilities, resource limits, topology).stats/— dashboard metrics aggregation + OTEL export.socket_server/— the unix-socket request server shared by per-agent + manager sockets.forge/— optional Forgejo wiring (docs/forge.md).coordinator.rs— top-level wiring forserve.meta.rs,migrate.rs— the meta flake + schema/state migrations.matrix.rs,gateway_nginx.rs,webhook_secret.rs,priv_client.rs— matrix provisioning, gateway vhosts, webhook secrets, and thehive-privclient respectively.
See the top-level CLAUDE.md/docs/ index for the full reading-path
map.