hyperhive/hive-sh4re
Repository files (latest commit first)
Filename Latest commit message Latest commit date
atlas 5202e5c5ba types: reserve the protocol names an agent must not be called
An agent's name was checked for shape and never for meaning:
`Ident::parse` is 1-63 chars of [a-z0-9-] and there was no reserved-name
list anywhere in the tree. So an agent could be called `operator`,
`forge` or `todo` -- names the message layer already produces as a
sender -- and a wake from that component became indistinguishable, at the
broker, from a message sent by the agent.

Adds `RESERVED_NAMES` + `is_reserved_name` to `hive-types`, the zero-dep
leaf both `hive-c0re` and `swarm-controller` already depend on, so
neither grows a dependency to use it.

Every entry is a value some component actually produces as a message
`from`/`to`, taken from `hive-sh4re`'s own sentinel constants rather than
guessed: operator, system, reminder, forge, scheduled, todo, compact,
graceful-stop. Two sentinels are deliberately absent -- `<parent>` and
`<children>` are unreachable as agent names because the charset rejects
them, and `ruth` is a real agent, so wanting that name is a name being
*taken*, which the roster answers.

Deliberately not enforced inside `Ident::parse`: parsing runs on every
read of an already-created name, so rejecting there would make existing
agents unreadable rather than un-creatable -- and it would be a refusal,
which is a stronger action than the warning this is used for today.

`create_agent` now warns on both halves -- a reserved name, and a name
that is also a hive in the roster -- and does not refuse. The warnings
ride on `CreateAgentResponse` rather than only the daemon's log, because
the person who can still fix the name in one keystroke is holding the
response, not reading the journal. `skip_serializing_if` keeps the
no-warning JSON byte-identical to before, so this is a non-breaking first
step toward refusing later.

`hive-sh4re` gains a drift test tying its sentinel constants to the list:
two crates that cannot import each other's intent now fail loudly if a
sentinel is added without being reserved. Mutation-verified -- forcing
the predicate false, forcing it true, and dropping a single entry each
turn a different test red.
2026-08-27 16:36:42 +02:00
..
src types: reserve the protocol names an agent must not be called 2026-08-27 16:36:42 +02:00
Cargo.toml fix(#2733): write the agent pause marker via hive-priv 2026-07-27 09:42:31 +02:00
README.md docs: stop asserting DagView/NodeView after their deletion 2026-08-03 21:47:58 +02:00

hive-sh4re

The shared payload vocabulary between hive-c0re and the in-container harness — the common types (Message, Approval, LooseEnd, HelperEvent, …) that the per-socket wire protocols are built from. The request/response envelopes themselves now live in the per-socket crates (below); this crate holds the payloads they carry.

Where it sits

This is the shared payload crate; the per-socket protocol envelopes have been split into their own smaller crates so specialised binaries don't have to pull in all of hive-sh4re:

  • hive-host-sock — host admin socket (hivectlhive-c0re)
  • hive-core-agent-sock — per-agent/manager socket (/run/hive/mcp.sock)
  • hive-priv-sock — the privileged-helper socket

Those crates re-export or reference the payload types that still live here (Approval, Message, LooseEnd, …).

Modules

  • wire_time — the timestamp convention: wire fields are chrono::DateTime<Utc> (serialized RFC 3339), while sqlite storage + input args stay unix-epoch i64; this module owns the two boundary conversions.
  • paths — well-known on-disk path helpers.
  • assets — resolves bundled runtime asset paths (branding, prompts) under HIVE_ASSETS_DIR.

Agent-name fields are typed as hive_types::Ident for serde-validated parsing at the socket boundary.