| Filename | Latest commit message | Latest commit date |
|---|---|---|
swarm-logs covers every host-tier unit this tool could reach, so the second, capability-gated path into host journald earns nothing and is removed outright rather than disabled behind a flag. Removed end to end: the MCP tool definition + handler, the GetHostJournal/HostJournal wire variants, hive-c0re's dispatch_host_journal handler, the ReadHostJournal capability, and the harness-side capability->--allowedTools gate. get_host_journal was the only capability that mapped to an MCP tool, so allowed_capability_tools could only ever return an empty vec; it goes too rather than linger as a function that provably does nothing. capabilities::has_cap/caps_for stay: #4624 gave ManageRootAgent's bind-mount enforcement (hive-c0re/src/lifecycle/host_config.rs) a second caller of has_cap, so they're no longer callerless once this lands on top of it. hive-sh4re's journal module (JournalPriority) had no consumer outside this tool and is deleted. An existing capabilities.json still naming read_host_journal does not error: capabilities::prune_unknown drops unrecognised names with a warn!, and an agent left with no capabilities has its entry removed. No migration step is needed. Untouched: hive-c0re/src/dashboard/journal.rs's read_host_journal_response, which matches the name but is the private helper behind the operator-only GET /api/journal-host dashboard route and carries no capability check. |
||
| .. | ||
| src | ||
| Cargo.toml | ||
| README.md | ||
hive-sh4re
The shared payload vocabulary between hive-c0re and the in-container
harness — the common types (Message, Approval, LooseEnd, HelperEvent, …)
that the per-socket wire protocols are built from. The request/response
envelopes themselves now live in the per-socket crates (below); this crate
holds the payloads they carry.
Where it sits
This is the shared payload crate; the per-socket protocol envelopes have been
split into their own smaller crates so specialised binaries don't have to pull
in all of hive-sh4re:
hive-host-sock— host admin socket (hivectl↔hive-c0re)hive-core-agent-sock— per-agent/manager socket (/run/hive/mcp.sock)hive-priv-sock— the privileged-helper socket
Those crates re-export or reference the payload types that still live here
(Approval, Message, LooseEnd, …).
Modules
wire_time— the timestamp convention: wire fields arechrono::DateTime<Utc>(serialized RFC 3339), while sqlite storage + input args stay unix-epochi64; this module owns the two boundary conversions.paths— well-known on-disk path helpers.assets— resolves bundled runtime asset paths (branding, prompts) underHIVE_ASSETS_DIR.
Agent-name fields are typed as hive_types::Ident for serde-validated parsing at
the socket boundary.