| Filename | Latest commit message | Latest commit date |
|---|---|---|
mara ruled on #4849 (c88934): "remove create_repo tool". The tool ran in
hive-c0re with the hive's core token, so it only ever worked for agents
on the hive that runs the forge.
Removed:
- the create_repo MCP tool and CreateRepoArgs (hive-agent-mcp)
- wire variants Request::CreateRepo and Response::RepoCreated
(hive-core-agent-sock)
- hive-c0re's handle_create_repo, its valid_repo_name check and the
dispatch arm
- forge::create_agent_repo and apply_operator_branch_protection, which
had no other caller, plus AGENTS_ORG and OPERATORS_TEAM, whose only
users they were
- the tool's docs (docs/tools/forge.md repo management, docs/turn-loop/
mcp.md, the conventions tool-group table) and the doc comments that
named it (hive-sock-client's response timeout, ensure_repo_creation_
disabled, the security doc's merge-gate bullet)
ToolGroup::Forge is kept with no tools, the same way
|
||
| .. | ||
| src | ||
| Cargo.toml | ||
| README.md | ||
hive-core-agent-sock
Wire types for the per-agent + manager socket (/run/hive/mcp.sock) — the
unified Request / Response protocol spoken between an agent's in-container
harness (and the manager) and the hive-c0re daemon.
Why it's its own crate
Re-homed out of hive-sh4re so this one socket owns its protocol crate,
mirroring the hive-host-sock / hive-priv-sock splits. The shared payload
types it references (Message, LooseEnd, Approval, …) stay in hive-sh4re,
which this crate depends on — this crate is just the request/response envelope
for this socket.
Not to be confused with hive-agent-sock
This is the host-served protocol: the harness talks out to hive-c0re
over /run/hive/mcp.sock (broker sends, approvals, lifecycle).
hive-agent-sock is the separate in-container socket the harness serves to
its own local producers — that one never leaves the container. See
docs/trust-boundary/boundary.md for the socket topology.