Repository navigation
fix(hive): make the HOP_CAP loop guard real - harness owns hops and increments per bounce - #563
Merged
Conversation
…ncrements per bounce The routeMessage() hop-cap check compared msg.hops against HOP_CAP with a "loop guard - drop a runaway message" comment, but nothing ever incremented hops: normalize copied the agent-supplied value verbatim and all four harness bounce paths spread ...msg unchanged, so a god<->hookless-worker relay loop delivered a duplicate bounce (plus a log line and a git commit) every 1.5s router tick forever, while an outbox JSON echoing hops: 13 - a field PROTOCOL.md says the HARNESS fills in - had its first delivery silently dropped. normalize() now clamps the agent-carried hops into [0, HOP_CAP] (a carried relay count keeps climbing toward the fuse; a poison or negative value can neither fake nor evade it), and the four bounce paths go through a new bounceToGod() helper - the only place the counter moves, +1 per harness bounce - where the cap fuse actually fires and drops with reason 'hop-cap'. The dead check at the top of routeMessage() is removed: with clamped input it could never fire, and that inoperative "loop guard" was the bug.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What & why
The relay-loop guard (HOP_CAP) existed as a check but the harness never owned or incremented the hops counter, so a god↔hookless-worker relay loop was unbounded. The fix makes the harness own the hops field and increment it on every bounce, so the fuse actually trips.
Type of change
Evidence
Before
After
How I tested it
node --test test/hive-hop-cap.test.cjsagainst unfixedmain— regression tests fail (red).npm run typecheckclean.Credit (optional)
Discord: ttawdtt
X:
Checklist
npm run typecheckpasses.npm run test:focusedpasses (except pre-existing Windows-env failures unrelated to this change, identical on clean main).npm run buildsucceeds.DESIGN.md/tokens.ts— no ad-hoc colors, spacing, or fonts.ATTRIBUTION.md.