Discovery is half-built and unwired. hive_advertise fires on every peer hello, but hive_discover has zero production call sites — so humd can announce its bees to the mesh and then never hears about anyone else's.
Current state (verified on f968e39)
| Piece |
State |
Ensemble::hive_advertise |
called on peer hello — humd/src/lib.rs:882 |
Ensemble::hive_discover |
never called outside ensemble/tests/hives_integration.rs |
manifests: RwLock<HashMap<client_id, HiveManifest>> |
keyed by local thrum client_id |
| every worker dispatch |
thrum.thrum_to(&client_id, ..) → local socket only |
inbound client_id == "ensemble" |
forwards replies by sid only — humd/src/lib.rs:745 |
pick_overflow_peer |
already selects cross-machine by caps + free_slots — humd/src/lib.rs:1345 |
So explicit addressing works today (to: <hid> routes at humd/src/lib.rs:733, proven by sim/tests/eggs_on_the_hum.rs). What's missing is automatic discovery and selection.
Why hive_discover alone won't close this
- Remote manifests have nowhere to live.
manifests is keyed by local thrum client_id. A remote bee has no client_id — it exists only as a Hid. Needs a parallel HashMap<Hid, HiveManifest>.
- Dispatch has to branch. Local hit →
thrum_to(client_id). Remote hit → ensemble.route() with to: <hid>. One lookup, two transports.
- The receiver can't answer a request. Inbound ensemble tones only forward replies by
sid (:745). Worse, a prompt arriving with client_id == "ensemble" currently falls through to local session handling at :895 as though a local bee sent it. Needs an explicit decision: reject, or resolve Hid → local worker via the hid field already in HiveManifest.
- Two selection mechanisms already exist — manifest-by-discovery and caps-by-
pick_overflow_peer. Pick one source of truth instead of letting them drift.
Requirements
Acceptance
Two humds in sim: B's worker discovered over gossip by A, A prompts it without knowing B in advance, reply returns to A's session by sid. Follows the existing integration-test shape (eggs_on_the_hum.rs), runs in CI.
Local-only dispatch must be observably unchanged — no regression in the current 209-test suite.
Non-goals
DHT bootstrap for workers (Kademlia already routes peers), NAT traversal (iroh already handles it), any central registry.
Discovery is half-built and unwired.
hive_advertisefires on every peer hello, buthive_discoverhas zero production call sites — so humd can announce its bees to the mesh and then never hears about anyone else's.Current state (verified on
f968e39)Ensemble::hive_advertisehumd/src/lib.rs:882Ensemble::hive_discoverensemble/tests/hives_integration.rsmanifests: RwLock<HashMap<client_id, HiveManifest>>thrum.thrum_to(&client_id, ..)→ local socket onlyclient_id == "ensemble"sidonly —humd/src/lib.rs:745pick_overflow_peerfree_slots—humd/src/lib.rs:1345So explicit addressing works today (
to: <hid>routes athumd/src/lib.rs:733, proven bysim/tests/eggs_on_the_hum.rs). What's missing is automatic discovery and selection.Why
hive_discoveralone won't close thismanifestsis keyed by local thrum client_id. A remote bee has no client_id — it exists only as aHid. Needs a parallelHashMap<Hid, HiveManifest>.thrum_to(client_id). Remote hit →ensemble.route()withto: <hid>. One lookup, two transports.sid(:745). Worse, apromptarriving withclient_id == "ensemble"currently falls through to local session handling at:895as though a local bee sent it. Needs an explicit decision: reject, or resolveHid→ local worker via thehidfield already inHiveManifest.pick_overflow_peer. Pick one source of truth instead of letting them drift.Requirements
remote: RwLock<HashMap<Hid, HiveManifest>>fed byhive_discover, keyed by hive namemanifestsandremote, preferring localthrum_toorensemble.routeon localitypromptresolved to a local worker, or explicitly refused — never silently treated as localremote(reuse the lease/evict_expiredmachinery from ensemble: bound every send, order the opening frame, prune dead routes #62), otherwise we dispatch into a black hole foreverfree_slotspreference where the manifest carries itAcceptance
Two humds in sim: B's worker discovered over gossip by A, A prompts it without knowing
Bin advance, reply returns to A's session bysid. Follows the existing integration-test shape (eggs_on_the_hum.rs), runs in CI.Local-only dispatch must be observably unchanged — no regression in the current 209-test suite.
Non-goals
DHT bootstrap for workers (Kademlia already routes peers), NAT traversal (iroh already handles it), any central registry.