| Filename | Latest commit message | Latest commit date |
|---|---|---|
`deliver` read the value out of the secret store and wrote it itself, as the `hive-core` user, at 0600. The file lands in a directory owned by the agent, so it arrived owned by `hive-core` — the agent's matrix daemon woke on it appearing and could not read its own credential. `priv_client::write_agent_ matrix_token` already existed and already had two callers; this was the one path that did not use it. hive-priv now owns the filename too, so the name the daemon's path unit globs for is decided in one place instead of being built identically in two. That move exposed a disagreement worth fixing rather than routing around. The secret store accepts `[A-Za-z0-9_-]` for an account name; hive-priv's `validate_name_chars` accepts lowercase, digits and hyphen only. An account is an attribute name in `hyperhive.matrixAccounts`, typed `attrsOf` with no charset constraint, so `Ops_Relay9` is a key an operator can already have written — and it would have read out of the store and then failed to land. So hive-priv grows `validate_account_name` rather than widening the existing one: an agent name is an `Ident` and lowercase by design, an account name is an attrset key, and one validator serving two name domains is what let them drift. The test that caught this came from `credential.rs`, which used to build the path. It moves to hive-priv with both of its controls intact, because the controls are the point — they assert which names must be ACCEPTED, and a validator narrower than the store's passes every rejection case. A second moved test pins the `matrix-token` prefix where the name is now built; the old one would have kept passing while asserting a function that no longer decided anything. Refs #3726 |
||
| .. | ||
| src | ||
| Cargo.toml | ||
| README.md | ||
hive-c0re
The unprivileged host daemon (runs as hive-core). Owns the sqlite
broker, the approval/reminder/schedule queues, the generic job-DAG
queue, container lifecycle, gateway/forge/matrix provisioning,
per-container stats, and the axum operator dashboard. Largest crate in
the workspace — bin-only, no separate lib.
When to use it
Host-level, cross-container orchestration: spawning/rebuilding/
destroying agent containers, the approval flow, dashboard-visible
state, provisioning per-agent forge/matrix/gateway accounts. Agent-side
behavior (turn loop, MCP tools) lives in hive-agent/hive-agent-mcp
instead — this daemon only talks to agents over the socket wire types
in hive-sh4re.
Shape
Cohesive clusters live in directory submodules, each re-exported at
the crate root (crate::broker::… keeps resolving regardless of which
subdirectory a module actually lives in). One line each — read the
module's own //! doc-comment for real detail, don't expect this file
to track it:
dashboard/— the operator dashboard (containers, approvals, schedules, logs, topology).job_queue/— the job-DAG queue + desired-state reconciliation (docs/scheduler/coordinator.md).lifecycle/—nixos-containerlifecycle + per-agent config flake generation.stores/— sqlite-backed stores (broker, queues, audit, power).workers/— background sweeps (crash watch, scheduled prompts, auto-update, knowledge sync).agent_config/— per-agent registries (tool groups, capabilities, resource limits, topology).stats/— dashboard metrics aggregation + OTEL export.socket_server/— the unix-socket request server shared by per-agent + manager sockets.forge/— optional Forgejo wiring (docs/integrations/forge.md).coordinator.rs— top-level wiring forserve.meta.rs,migrate.rs— the meta flake + schema/state migrations.matrix.rs,gateway_nginx.rs,webhook_secret.rs,priv_client.rs— matrix provisioning, gateway vhosts, webhook secrets, and thehive-privclient respectively.
See the top-level CLAUDE.md/docs/ index for the full reading-path
map.