swarm-controller now creates `term-sub-<agent>` for every agent a hive is declared to run, at start and every minute after, with the config `swarm_queue_client::subagent_term::open_or_create` spells (subjects `$SWARM.term.<agent>.sub.>`, max_age 24h). An existing stream is opened as it is, as the controller does for its other streams and buckets, under the `$JS.API.STREAM.CREATE.*` grant it already holds. The agent no longer creates the stream: its token is granted publish on `$SWARM.term.<agent>.sub.>` and no `$JS.API.STREAM.CREATE|INFO` subject, and the subagent daemon only publishes. A `CREATE` carries the stream's config in its payload, which no subject grant narrows, so the agent could otherwise pick the stream's subjects and limits.
57 lines
2.1 KiB
TOML
57 lines
2.1 KiB
TOML
[package]
|
|
name = "hive-subagent-mcp"
|
|
edition.workspace = true
|
|
version.workspace = true
|
|
readme = "README.md"
|
|
|
|
[lints]
|
|
workspace = true
|
|
|
|
[dependencies]
|
|
anyhow.workspace = true
|
|
# The swarm-queue client for publishing subagent terminals (`swarm_term`).
|
|
async-nats.workspace = true
|
|
axum.workspace = true
|
|
clap.workspace = true
|
|
hive-agent-sock.workspace = true
|
|
hive-claude.workspace = true
|
|
hive-runtime.workspace = true
|
|
# `permissions::builtin_tools_arg` — the same `--tools` resolution the parent
|
|
# harness spawns its own claude with, so a subagent's built-in surface is its
|
|
# parent's rather than a second list that drifts. See `session::build_config`.
|
|
# Also `term_msg`/`stream_enrich`, the rows `swarm_term` publishes.
|
|
hive-sh4re.workspace = true
|
|
hive-sock-client.workspace = true
|
|
hive-types.workspace = true
|
|
libc.workspace = true
|
|
rmcp.workspace = true
|
|
schemars.workspace = true
|
|
serde.workspace = true
|
|
serde_json.workspace = true
|
|
# `subagent_term`: the subject each subagent's rows are published on.
|
|
swarm-queue-client.workspace = true
|
|
# The agent's own queue credential, read under its store identity.
|
|
swarm-secret-client.workspace = true
|
|
tokio.workspace = true
|
|
tracing.workspace = true
|
|
tracing-subscriber.workspace = true
|
|
# Signal-route tokens. `Uuid::new_v4` draws from the OS CSPRNG (getrandom),
|
|
# which is the property the per-session URL rests on — see
|
|
# `session::State::mint_signal_url`.
|
|
uuid.workspace = true
|
|
|
|
# `test-util` for `#[tokio::test(start_paused = true)]`: the `continue`
|
|
# resume-grace tests assert what happens when the bound is actually reached,
|
|
# and paused time gets that answer without a five-second unit test.
|
|
[dev-dependencies]
|
|
tokio = { workspace = true, features = ["test-util"] }
|
|
|
|
# `hive-subagent-daemon` — long-running per-agent claude-subagent runner.
|
|
# Independent of `hive-bash-mcp` (own crate, own binary, own MCP server) —
|
|
# see lib.rs's module doc for why. Serves its MCP tools (`start`/
|
|
# `continue`/`status`/`interrupt`, plus the subagent-facing
|
|
# `goal_reached`/`need_help` route) directly over streamable-http — no
|
|
# stdio bridge.
|
|
[[bin]]
|
|
name = "hive-subagent-daemon"
|
|
path = "src/main.rs"
|