Watch
0
0
Fork
You've already forked hyperhive
0
hyperhive/nix/module-eval/agent-runtime.nix
atlas d6f94e5247 swarm: show subagent terminals in the swarm UI
An agent's subagent daemon publishes each subagent's output as terminal
rows on `$SWARM.term.<agent>.sub.<subagent>`, as the agent, into a
per-agent stream it creates itself; swarm-controller lists an agent's
subagents from that stream's subjects and relays one subagent's rows as
SSE; the swarm UI lists them under the agent's terminal preview and
reuses AgentTermPreview, full-screen tab included, with no input.

- swarm-nats.nix: the agent token may also publish
  `$SWARM.term.{agent}.sub.>` and `$JS.API.STREAM.CREATE|INFO` on
  `term-sub-{agent}`, and nothing else of JetStream. A module-eval arm
  pins the agent-token grant as an exact list.
- mcp.nix: hive-subagent-daemon loads the agent's store identity
  (`hive-agent-bao-cert/-key/-server-ca`, the ones hive-agent loads)
  whenever the agent has a store, not only on the opencode preset. The
  agent's own queue secret lives in the store, so this is the credential
  the harness connects with.
- hive-subagent-mcp: `swarm_term` reads the agent's queue secret under
  that identity, connects with the agent token, opens or creates
  `term-sub-<agent>` (max_age 24h), and publishes classified rows from
  the sink every subagent line already passes through. The sink only
  queues (bounded, drop-and-count); a missing store, refused credential,
  failed stream create or failed publish is a log line.
- The stream-json classifier (`stream_enrich`) and the `TermMsg` row
  types plus `fit` move from the hive-agent binary into hive-sh4re, so
  the subagent daemon publishes the rows AgentTermPreview already
  renders. hive-agent keeps its LiveEvent classifier on top.
- swarm-controller: `GET /api/agents/{name}/subagents` and
  `GET /api/agents/{name}/subagents/{subagent}/term/stream`.
- docs/swarm: what the UI shows and what the queue carries.

Closes #4827
2026-10-03 01:34:01 +02:00

152 lines
4.7 KiB
Nix

# `checks.module-eval-agent-runtime` — see ./lib.nix for the shared
# rationale (why this suite exists, naming convention, "evaluates
# not executes").
{
pkgs,
lib,
self,
nixosSystem,
}:
let
inherit
(import ./lib.nix {
inherit
pkgs
lib
self
nixosSystem
;
})
agentWith
runGroup
;
backendEnv = "/agents/a1/harness/backend.env";
# Both arms carry a backend file, so the claude arm's lack of one on the
# subagent unit is the gate and not a missing input.
agentOn =
runtime:
agentWith {
services.hyperhive.agent = {
inherit runtime;
backendEnvironmentFile = backendEnv;
acp.command = "/bin/agent";
acp.args = [ "acp" ];
};
};
claude = agentOn "claude";
acp = agentOn "acp";
# The opencode preset, with and without a secret store.
opencodeWith =
extra:
agentWith {
services.hyperhive.agent = {
runtime = "acp";
acp.preset = "opencode";
acp.opencode.provider.baseUrl = "https://inference.t.local/v1";
acp.opencode.provider.apiKeyEnv = "T_PROVIDER_KEY";
acp.opencode.model = "m";
}
// extra;
};
opencode = opencodeWith { };
opencodeBao = opencodeWith { bao.addr = "https://bao.t.local:8200"; };
acpBao = agentWith {
services.hyperhive.agent = {
runtime = "acp";
acp.command = "/bin/agent";
bao.addr = "https://bao.t.local:8200";
};
};
subagent = machine: machine.systemd.services.hive-subagent-daemon;
harness = machine: machine.systemd.services.hive-agent;
runtimeVars = [
"HIVE_RUNTIME"
"HIVE_ACP_COMMAND"
"HIVE_ACP_ARGS"
"HIVE_ACP_ENV"
];
cases = [
{
# The daemon reads these with `hive_runtime::RuntimeSpec`, the same
# parser as the harness, so equal values mean the same runtime.
name = "an ACP agent's subagent daemon gets the harness's runtime selection";
ok = lib.all (
var: (subagent acp).environment.${var} or null == (harness acp).environment.${var}
) runtimeVars;
}
{
name = "an opencode agent's harness and subagent daemon are told its provider key variable";
ok =
(harness opencode).environment.HIVE_ACP_API_KEY_ENV == "T_PROVIDER_KEY"
&& (subagent opencode).environment.HIVE_ACP_API_KEY_ENV == "T_PROVIDER_KEY";
}
{
# Only the opencode preset has a provider key variable.
name = "an ACP agent off the opencode preset is told no provider key variable";
ok =
!((harness acpBao).environment ? HIVE_ACP_API_KEY_ENV)
&& (subagent acpBao).environment.HIVE_ACP_API_KEY_ENV or null == null;
}
{
# Every agent with a store, whatever its runtime: the daemon reads the
# agent's queue credential with it to publish subagent terminals.
name = "a subagent daemon gets the agent's store identity whenever the agent has a store";
ok =
lib.all
(
u:
u.serviceConfig.LoadCredential == [
"hive-agent-bao-cert"
"hive-agent-bao-key"
"hive-agent-bao-server-ca"
]
&& u.environment.HIVE_AGENT_NAME == "a1"
&& u.environment.BAO_ADDR == "https://bao.t.local:8200"
)
[
(subagent acpBao)
(subagent opencodeBao)
];
}
{
name = "an opencode agent's subagent daemon gets the agent's store identity";
ok =
let
u = subagent opencodeBao;
in
u.serviceConfig.LoadCredential == [
"hive-agent-bao-cert"
"hive-agent-bao-key"
"hive-agent-bao-server-ca"
]
&& u.environment.HIVE_AGENT_NAME == "a1"
&& u.environment.BAO_ADDR == "https://bao.t.local:8200"
&& u.environment.BAO_CLIENT_CERT == "%d/hive-agent-bao-cert"
&& u.environment.BAO_CLIENT_KEY == "%d/hive-agent-bao-key";
}
{
name = "an opencode agent with no store hands its subagent daemon no store identity";
ok =
!((subagent opencode).serviceConfig ? LoadCredential)
&& !((subagent opencode).environment ? BAO_ADDR);
}
{
name = "an ACP agent's subagent daemon loads the backend credentials";
ok = (subagent acp).serviceConfig.EnvironmentFile or null == "-${backendEnv}";
}
{
# Unset is what `RuntimeSpec` reads as claude, and a claude subagent
# is not handed the backend file.
name = "a claude agent's subagent daemon has no runtime selection and no backend file";
ok =
lib.all (var: (subagent claude).environment.${var} or null == null) runtimeVars
&& !((subagent claude).serviceConfig ? EnvironmentFile);
}
];
in
runGroup "agent-runtime" cases