| Filename | Latest commit message | Latest commit date |
|---|---|---|
The hive had two spellings of "this agent may act on agents that aren't its children": the `ManageRootAgent` capability, which nothing checked, and a `can_manage_top_level_agents` role in a third meta store, `roles.json`, which owned the real grant — the bind mounts that put another agent's state (rw) and config (ro) inside the holder's container. The two drifted independently, and with the parent/child hierarchy removed the role's set (`parent.is_none()`) silently became every agent while nothing said so. Collapse them. The mount grant now hangs off `Capability::ManageRootAgent`, looked up through the one capability path that already exists (`capabilities::has_cap` over `capabilities.json`) rather than a second mechanism. `roles.json` and everything that read, wrote or reconciled it is gone, along with its `meta.rs` staging and commit-label wiring; nothing in the tree reads that file any more. The enum variant keeps its name deliberately. Renaming it would turn every `manage_root_agent` already stored in `capabilities.json` into an unrecognised name that `prune_unknown` drops without asking. Its meaning, not its spelling, is what changed: "may manage any agent". The doc comment and the description string now say that. `top_level_agents()`/`top_level_agents_in()` are replaced by `all_agents()`/`all_agents_in()`. Under "manage any agent" the mounted set is every agent by definition, so the code states it instead of deriving it from a predicate that no longer discriminates — and the call-site comment explains that, because it otherwise reads as a widening. The holder is no longer bound as its own virtual child: that reproduced the own-state and own-config mounts exactly, so dropping it loses nothing. |
||
| .. | ||
| src | ||
| Cargo.toml | ||
| README.md | ||
hive-sh4re
The shared payload vocabulary between hive-c0re and the in-container
harness — the common types (Message, Approval, LooseEnd, HelperEvent, …)
that the per-socket wire protocols are built from. The request/response
envelopes themselves now live in the per-socket crates (below); this crate
holds the payloads they carry.
Where it sits
This is the shared payload crate; the per-socket protocol envelopes have been
split into their own smaller crates so specialised binaries don't have to pull
in all of hive-sh4re:
hive-host-sock— host admin socket (hivectl↔hive-c0re)hive-core-agent-sock— per-agent/manager socket (/run/hive/mcp.sock)hive-priv-sock— the privileged-helper socket
Those crates re-export or reference the payload types that still live here
(Approval, Message, LooseEnd, …).
Modules
wire_time— the timestamp convention: wire fields arechrono::DateTime<Utc>(serialized RFC 3339), while sqlite storage + input args stay unix-epochi64; this module owns the two boundary conversions.paths— well-known on-disk path helpers.assets— resolves bundled runtime asset paths (branding, prompts) underHIVE_ASSETS_DIR.
Agent-name fields are typed as hive_types::Ident for serde-validated parsing at
the socket boundary.