`build_config` spawned a subagent with `--dangerously-skip-permissions` and no `--tools` at all, so it got claude's entire built-in set — `SendMessage` and `ListAgents` (message peers, or the operator, as its parent), `Task*` including `TaskStop`, which takes an *agent* id and so reaches clean outside the run, `Cron*`, `RemoteTrigger` and `EnterWorktree`/`ExitWorktree`. None of that is part of "do this bounded task in this directory", and none of it is something the parent agent itself can do: the harness has always passed `--tools`. Pass the same one. The value comes from `hive_sh4re::permissions::builtin_tools_arg()` — literally the function the harness resolves its own session with — so the subagent's set is the parent's set, `HIVE_TOOL_GROUPS` and all. That inheritance is the requirement, not an implementation detail: a hardcoded subagent list would hand `WebFetch`/`WebSearch` to the subagent of an agent without the `web_tools` group, which is a privilege escalation, and would drift from the parent's list the first time anyone added a tool to either. `--tools` is the real gate: it holds under `--dangerously-skip-permissions`, unlike `--allowedTools`, which only auto-approves prompts. It does not filter MCP tools, so the `goal_reached`/`need_help` signal surface is deliberately unnamed in it and survives on `--strict-mcp-config` alone. `build_config`'s doc comment claimed `strict_mcp_config` was *the* safety property and that a subagent got "nothing implicit and nothing more". That was false for built-ins, and is what hid this gap for as long as it did; it now says which flag covers which half and that neither substitutes for the other. An empty `--tools` value parses as *unset* and grants more than omitting the flag, so an empty resolution can only be a bug — `build_config` asserts against it and a test pins the non-emptiness alongside the subset-of-parent property. Refs #4416
49 lines
1.7 KiB
TOML
49 lines
1.7 KiB
TOML
[package]
|
|
name = "hive-subagent-mcp"
|
|
edition.workspace = true
|
|
version.workspace = true
|
|
readme = "README.md"
|
|
|
|
[lints]
|
|
workspace = true
|
|
|
|
[dependencies]
|
|
anyhow.workspace = true
|
|
axum.workspace = true
|
|
clap.workspace = true
|
|
hive-agent-sock.workspace = true
|
|
hive-claude.workspace = true
|
|
# `permissions::builtin_tools_arg` — the same `--tools` resolution the parent
|
|
# harness spawns its own claude with, so a subagent's built-in surface is its
|
|
# parent's rather than a second list that drifts. See `session::build_config`.
|
|
hive-sh4re.workspace = true
|
|
hive-sock-client.workspace = true
|
|
hive-types.workspace = true
|
|
libc.workspace = true
|
|
rmcp.workspace = true
|
|
schemars.workspace = true
|
|
serde.workspace = true
|
|
serde_json.workspace = true
|
|
tokio.workspace = true
|
|
tracing.workspace = true
|
|
tracing-subscriber.workspace = true
|
|
# Signal-route tokens. `Uuid::new_v4` draws from the OS CSPRNG (getrandom),
|
|
# which is the property the per-session URL rests on — see
|
|
# `session::State::mint_signal_url`.
|
|
uuid.workspace = true
|
|
|
|
# `test-util` for `#[tokio::test(start_paused = true)]`: the `continue`
|
|
# resume-grace tests assert what happens when the bound is actually reached,
|
|
# and paused time gets that answer without a five-second unit test.
|
|
[dev-dependencies]
|
|
tokio = { workspace = true, features = ["test-util"] }
|
|
|
|
# `hive-subagent-daemon` — long-running per-agent claude-subagent runner.
|
|
# Independent of `hive-bash-mcp` (own crate, own binary, own MCP server) —
|
|
# see lib.rs's module doc for why. Serves its MCP tools (`start`/
|
|
# `continue`/`status`/`interrupt`, plus the subagent-facing
|
|
# `goal_reached`/`need_help` route) directly over streamable-http — no
|
|
# stdio bridge.
|
|
[[bin]]
|
|
name = "hive-subagent-daemon"
|
|
path = "src/main.rs"
|