hyperhive/hive-host-sock
Repository files (latest commit first)
Filename Latest commit message Latest commit date
atlas d94bc2188d topology: drop the parent field and the hierarchy it fed
`topology.json` was a map of `name -> parent | null`, and that value fed
the whole agent hierarchy: `<parent>` / `<children>` recipient sentinels,
the reparenting API (CLI verb, wire verb, dashboard endpoints, DAG node),
the dashboard tree, the rebuild depth sort, and an unconditional
bind-mount grant giving every agent RW on its direct children's state.

Per the operator's ruling the field goes, and with it all of the above.
The file survives as what remains once the value is gone: the roster of
agent names, which is the set `ManageRootAgent` grants mounts over. It is
now a JSON array; `read` still accepts the old map shape and keeps its
keys, so a hive that upgrades across this does not blank its roster (and
so no capability holder loses its mounts for the length of that window).

Two sites kept their behaviour under a different recipient rather than
losing it. Both addressed `<parent>`, which the broker already resolved to
`operator` for a root agent, and every agent is now what that fallback
called a root:

- the harness's turn-failure / plugin-failure notification
  (`Surface::send_to_parent` -> `send_to_operator`), and
- the send allow-list's always-permitted escape hatch, so an agent with a
  restrictive allow-list still has a way to say it is stuck.

What is NOT preserved, deliberately: an agent with no capability no longer
sees any other agent's dirs. `ManageRootAgent`'s own grant is unchanged --
still every agent in the roster, still state RW + config RO, still no
`harness`.

The dashboard's reparenting control (the M0V3 picker) is deleted with its
CSS. The tree rendering that reads `ContainerView.parent` is left for the
frontend owner -- it degrades to a flat list with the field gone.
2026-09-21 22:08:47 +02:00
..
src topology: drop the parent field and the hierarchy it fed 2026-09-21 22:08:47 +02:00
Cargo.toml hivectl: migrate dag_progress to hive-jobq-wire's generic GraphNode 2026-08-03 20:35:24 +02:00
README.md docs: restructure into topic subdirectories, collapse duplicated index 2026-09-02 01:55:37 +02:00

hive-host-sock

Wire types for the host admin socket (/run/hyperhive/host.sock) — the host-control protocol spoken between the hivectl operator CLI and the hive-c0re daemon.

Why it's its own crate

Re-homed out of hive-sh4re so a standalone hivectl depends on just this protocol crate instead of the whole daemon-shared crate. hivectl drives the full hive (spawn / kill / destroy / rebuild / deploy) over this socket without linking hive-c0re; keeping the request/response shapes here is what makes that thin dependency possible.

Shape

Serde-derived request/response enums for the host admin protocol. The larger shared payload types some variants reference (Approval, AgentStatusRow) stay in hive-sh4re — this crate is only the protocol envelope, no server or client implementation.

Its own jobs module is the exception: the job-queue vocabulary hivectl needs (Source, State, PermPayload, NodeId) is protocol-local. The typed DagView/NodeView projection that used to live there is gone — the queue is served as a generic graph (hive-jobq-wire), not as a second hand-written view.

See docs/trust-boundary/boundary.md (host admin socket access) for the trust model around who may connect to the socket, and hive-priv-sock for the sibling split on the privileged-helper socket.