| Filename | Latest commit message | Latest commit date |
|---|---|---|
`build_config` spawned a subagent with `--dangerously-skip-permissions` and no `--tools` at all, so it got claude's entire built-in set — `SendMessage` and `ListAgents` (message peers, or the operator, as its parent), `Task*` including `TaskStop`, which takes an *agent* id and so reaches clean outside the run, `Cron*`, `RemoteTrigger` and `EnterWorktree`/`ExitWorktree`. None of that is part of "do this bounded task in this directory", and none of it is something the parent agent itself can do: the harness has always passed `--tools`. Pass the same one. The value comes from `hive_sh4re::permissions::builtin_tools_arg()` — literally the function the harness resolves its own session with — so the subagent's set is the parent's set, `HIVE_TOOL_GROUPS` and all. That inheritance is the requirement, not an implementation detail: a hardcoded subagent list would hand `WebFetch`/`WebSearch` to the subagent of an agent without the `web_tools` group, which is a privilege escalation, and would drift from the parent's list the first time anyone added a tool to either. `--tools` is the real gate: it holds under `--dangerously-skip-permissions`, unlike `--allowedTools`, which only auto-approves prompts. It does not filter MCP tools, so the `goal_reached`/`need_help` signal surface is deliberately unnamed in it and survives on `--strict-mcp-config` alone. `build_config`'s doc comment claimed `strict_mcp_config` was *the* safety property and that a subagent got "nothing implicit and nothing more". That was false for built-ins, and is what hid this gap for as long as it did; it now says which flag covers which half and that neither substitutes for the other. An empty `--tools` value parses as *unset* and grants more than omitting the flag, so an empty resolution can only be a bug — `build_config` asserts against it and a test pins the non-emptiness alongside the subset-of-parent property. Refs #4416 |
||
| .. | ||
| agent-lifecycle | ||
| crates | ||
| getting-started | ||
| integrations | ||
| networking | ||
| process | ||
| scheduler | ||
| swarm | ||
| tools | ||
| trust-boundary | ||
| turn-loop | ||
| web-ui | ||
| README.md | ||
hyperhive docs
Depth reference for hyperhive — the substrate, not the pitch (that's the
top-level README / website).
Every page here stands alone; pick the one matching your task rather than
reading top to bottom. For the autogenerated NixOS options reference
(every services.hyperhive.* / hyperhive.* option, host and agent), see
the options site instead —
this tree is prose, that one's generated straight from the module
declarations.
Getting started
- Bringing a fresh hive online? →
getting-started/setup.md(first-runhivectlbootstrap). - What does the dashboard look like, and how do I use it? →
web-ui/— the operator-facing starting point; its own sub-pages (shape,dashboard,agent,css-vars,terminal-rendering) go deeper into implementation. - What tools does an agent (or the operator) have available? →
tools/—hivectl(yours) plus every agent's MCP tool surface (bash, forge, lifecycle, matrix, scheduling).
Agent lifecycle
- How do config changes flow from manager to operator to container? →
agent-lifecycle/approvals.md(approval kinds, approval state machine,flake.lockvalidation). - What state survives destroy / purge / restart? →
agent-lifecycle/persistence.md. - Who can do what to whom — agent hierarchy and privilege? →
agent-lifecycle/agent-hierarchy.md. - How does claude get its prompt, and what tools does it have? →
turn-loop/— the loop, binary shape, turn outcomes; sub-pages:claude-invocation,config,mcp.
Trust boundary & security
- What's the operator/agent trust boundary? What's a capability? →
trust-boundary/boundary.md. - Agent trust model, prompt-injection threat model, credential
isolation? →
trust-boundary/security.md.
Accounts & integrations
- How do per-agent forge accounts work? What does
forge_notifypoll, and how does it format wake messages? →integrations/forge.md(the hive's own Forgejo);tools/forge.mdfor thehive-forgeCLI verbs agents actually call. - How does the matrix-tuwunel container work? Multiple accounts per
agent? →
integrations/matrix.md(the homeserver);tools/matrix.mdfor the MCP tool surface andhyperhive.matrixAccounts. - How do I give an agent a GitHub account (
gh+git push)? how's the PAT injected? →integrations/github.md(operator content up top; thegh/git-push + notification-poller mechanics are in a collapsed "Implementation" section at the bottom). - What's
/knowledge? How does the hive-wide knowledge repo sync, and how do I contribute a document? →integrations/knowledge.md. - What does
hivectldo? Provisioning, gateway users, container shells? →tools/hivectl.md(the curated guide);tools/hivectl-cli.mdfor the exhaustive, autogenerated flag reference.
Networking & swarms
- What nginx vhosts does the gateway serve? How does matrix
discovery work? →
networking/gateway.md. - How does DNS resolution work in agent containers? What's the
bridge network for? →
networking/network.md. - How do I connect two hives into a swarm? →
swarm/(peer hives, TLS trust). - Where do agent snapshots go? How does the swarm's
btrfs receiveendpoint authenticate a pushing hive? →networking/snapshot-store.md.
Scheduler, CI, observability
- what's the job queue, as a general idea (not hive-c0re specifics)? →
scheduler/jobq.md— operator-facing, no implementation detail. - How does the rebuild queue work? What are the concrete step kinds,
queue sources, scheduler internals? →
scheduler/coordinator.md. - How does the CI runner work? What's the autoregistration flow? →
scheduler/ci.md. - How do I export Claude Code metrics (tokens, cost, tool calls) to
Prometheus/Grafana? →
scheduler/observability.md.
Crate reference
- What does a specific Rust crate do, on its own terms? →
crates/— every workspace crate's ownREADME.md, one level up from source; the crate itself is still the source of truth, this is just a walkable mirror.
Process & conventions
- Naming, commit style, wire protocol, the
data-asyncpattern? →process/conventions.md. - Why does the nspawn flag look like that? →
process/gotchas.md(bind mounts, conf flags, other NixOS/nspawn quirks). - What does a PR review verdict actually gate? →
process/pr-review-gate.md.