| Filename | Latest commit message | Latest commit date |
|---|---|---|
fifo_fairness_for_the_slot lived in hive-c0re and submitted three rebuilds, driving one to completion to watch the freed build slot go to the earlier waiter. The guarantee it was checking is this crate's: claim_one scans nodes in insertion order and takes the first satisfiable one. Nothing here tested it -- the property hive-jobq provides was asserted only downstream, through a host's templates. a_contended_resource_goes_to_the_oldest_waiter tests it directly. Mutation-checked: reversing the scan order fails it. What is hive-c0re's is which nodes contend for the slot at all, and that is a declaration, so its half is now a declared_resources table with nothing running. The measured shape corrected an assumption on the way: MetaSync takes the meta window only, and the agent lease starts at StopForUpdate -- the first node that touches the container -- not at the head of the chain. Prebuild deliberately holds no lease, which is what lets it overlap another DAG on the same agent while the container is still up. "Uniform hold across the chain" needs no test of its own: a resource is held for the acquirer's whole subtree, and the parent nesting is already asserted in rebuild_chain_is_declared_serial. |
||
| .. | ||
| src | ||
| Cargo.toml | ||
| README.md | ||
hive-c0re
The unprivileged host daemon (runs as hive-core). Owns the sqlite
broker, the approval/question/schedule queues, the generic job-DAG
queue, container lifecycle, gateway/forge/matrix provisioning,
per-container stats, and the axum operator dashboard. Largest crate in
the workspace — bin-only, no separate lib.
When to use it
Host-level, cross-container orchestration: spawning/rebuilding/
destroying agent containers, the approval flow, dashboard-visible
state, provisioning per-agent forge/matrix/gateway accounts. Agent-side
behavior (turn loop, MCP tools) lives in hive-agent/hive-agent-mcp
instead — this daemon only talks to agents over the socket wire types
in hive-sh4re.
Shape
Cohesive clusters live in directory submodules, each re-exported at
the crate root (crate::broker::… keeps resolving regardless of which
subdirectory a module actually lives in). One line each — read the
module's own //! doc-comment for real detail, don't expect this file
to track it:
dashboard/— the operator dashboard (containers, approvals, schedules, questions, logs, topology).job_queue/— the job-DAG queue + desired-state reconciliation (docs/coordinator.md).lifecycle/—nixos-containerlifecycle + per-agent config flake generation.stores/— sqlite-backed stores (broker, queues, audit, power).workers/— background sweeps (crash watch, scheduled prompts, auto-update, knowledge sync).agent_config/— per-agent registries (tool groups, capabilities, resource limits, topology).stats/— dashboard metrics aggregation + OTEL export.socket_server/— the unix-socket request server shared by per-agent + manager sockets.forge/— optional Forgejo wiring (docs/forge.md).coordinator.rs— top-level wiring forserve.meta.rs,migrate.rs— the meta flake + schema/state migrations.matrix.rs,gateway_nginx.rs,webhook_secret.rs,priv_client.rs— matrix provisioning, gateway vhosts, webhook secrets, and thehive-privclient respectively.
See the top-level CLAUDE.md/docs/ index for the full reading-path
map.