hyperhive/hive-sh4re
Repository files (latest commit first)
Filename Latest commit message Latest commit date
atlas 5ce0a357b4 subagent: grant claude's Bash when the agent holds the execution group
A subagent inherited the parent's built-in tool list, which correctly has
no `Bash` -- the agent reaches a shell through the `bash` MCP server, not
the built-in. Subagents get no such server, so the intersection was empty
and they could not run a command at all: no commits, no pushes, no gates.

Add `subagent_builtin_tools_for`/`_arg`, which reuse the shared resolver
and append `Bash` only when `Execution` -- the group that gates the `bash`
MCP server -- is present. Only the subagent spawn path calls them, so the
harness's own `--tools`/`--allowedTools` are unchanged.

The capability transfers; the mechanism does not.

Refs #4422
2026-09-15 18:48:51 +02:00
..
src subagent: grant claude's Bash when the agent holds the execution group 2026-09-15 18:48:51 +02:00
Cargo.toml permissions: give the built-in tool list one home, next to ToolGroup 2026-09-15 17:40:27 +02:00
README.md treefmt: apply prettier 2026-09-02 15:25:07 +02:00

hive-sh4re

The shared payload vocabulary between hive-c0re and the in-container harness — the common types (Message, Approval, LooseEnd, HelperEvent, …) that the per-socket wire protocols are built from. The request/response envelopes themselves now live in the per-socket crates (below); this crate holds the payloads they carry.

Where it sits

This is the shared payload crate; the per-socket protocol envelopes have been split into their own smaller crates so specialised binaries don't have to pull in all of hive-sh4re:

  • hive-host-sock — host admin socket (hivectlhive-c0re)
  • hive-core-agent-sock — per-agent/manager socket (/run/hive/mcp.sock)
  • hive-priv-sock — the privileged-helper socket

Those crates re-export or reference the payload types that still live here (Approval, Message, LooseEnd, …).

Modules

  • wire_time — the timestamp convention: wire fields are chrono::DateTime<Utc> (serialized RFC 3339), while sqlite storage + input args stay unix-epoch i64; this module owns the two boundary conversions.
  • paths — well-known on-disk path helpers.
  • assets — resolves bundled runtime asset paths (branding, prompts) under HIVE_ASSETS_DIR.

Agent-name fields are typed as hive_types::Ident for serde-validated parsing at the socket boundary.