| Filename | Latest commit message | Latest commit date |
|---|---|---|
`build_config` spawned a subagent with `--dangerously-skip-permissions` and no `--tools` at all, so it got claude's entire built-in set — `SendMessage` and `ListAgents` (message peers, or the operator, as its parent), `Task*` including `TaskStop`, which takes an *agent* id and so reaches clean outside the run, `Cron*`, `RemoteTrigger` and `EnterWorktree`/`ExitWorktree`. None of that is part of "do this bounded task in this directory", and none of it is something the parent agent itself can do: the harness has always passed `--tools`. Pass the same one. The value comes from `hive_sh4re::permissions::builtin_tools_arg()` — literally the function the harness resolves its own session with — so the subagent's set is the parent's set, `HIVE_TOOL_GROUPS` and all. That inheritance is the requirement, not an implementation detail: a hardcoded subagent list would hand `WebFetch`/`WebSearch` to the subagent of an agent without the `web_tools` group, which is a privilege escalation, and would drift from the parent's list the first time anyone added a tool to either. `--tools` is the real gate: it holds under `--dangerously-skip-permissions`, unlike `--allowedTools`, which only auto-approves prompts. It does not filter MCP tools, so the `goal_reached`/`need_help` signal surface is deliberately unnamed in it and survives on `--strict-mcp-config` alone. `build_config`'s doc comment claimed `strict_mcp_config` was *the* safety property and that a subagent got "nothing implicit and nothing more". That was false for built-ins, and is what hid this gap for as long as it did; it now says which flag covers which half and that neither substitutes for the other. An empty `--tools` value parses as *unset* and grants more than omitting the flag, so an empty resolution can only be a bug — `build_config` asserts against it and a test pins the non-emptiness alongside the subset-of-parent property. Refs #4416 |
||
| .. | ||
| src | ||
| Cargo.toml | ||
| README.md | ||
hive-subagent-mcp
Per-agent daemon (hive-subagent-daemon) that spawns nested headless
claude sessions on request and serves the tool surface
(start/continue/status/interrupt, plus a separate
subagent-facing goal_reached/need_help route, one per-session URL)
directly over streamable-http. No stdio bridge, no per-turn respawn — an
agent's claude reconnects to the same stable URL every turn.
Independent of hive-bash-mcp — a subagent spawns a full nested
claude session, a much heavier capability than a bash command, worth
its own deployable/restartable unit.
Shape
One bin (hive-subagent-daemon, src/main.rs) built from the crate's
own lib (src/lib.rs):
session.rs— the actual claude-facing logic:Claude::spawn+RunningClaude::wait/cancel_handle(notInfiniteSession::run, which has no cancel handle to reach in — see the module doc for the v1 scope this trades away), the turn-continuation loop agoalswitches on, and the in-memory maps that are the only state this daemon keeps (no task files — a restart stops whatever's running; the actual claude session is the durable store, found again by name viahive_claude::SessionStore).mcp.rs— thermcptool routers (the parent'sstart/continue/status/interrupton/mcp, the subagent'sgoal_reached/need_helpon/signal/mcp/<token>) +serve_http. Neither signal tool takes a session name: the token in the path is minted per run and resolved to a session before dispatch, so a subagent has no way to name — and therefore no way to signal — a sibling. One route with a path parameter, because theRouteris built once at startup and sessions come and go for the daemon's whole life.paths.rs— the in-agent todo-socket path.