remove the create_repo agent tool
mara ruled on #4849 (c88934): "remove create_repo tool". The tool ran in
hive-c0re with the hive's core token, so it only ever worked for agents
on the hive that runs the forge.
Removed:
- the create_repo MCP tool and CreateRepoArgs (hive-agent-mcp)
- wire variants Request::CreateRepo and Response::RepoCreated
(hive-core-agent-sock)
- hive-c0re's handle_create_repo, its valid_repo_name check and the
dispatch arm
- forge::create_agent_repo and apply_operator_branch_protection, which
had no other caller, plus AGENTS_ORG and OPERATORS_TEAM, whose only
users they were
- the tool's docs (docs/tools/forge.md repo management, docs/turn-loop/
mcp.md, the conventions tool-group table) and the doc comments that
named it (hive-sock-client's response timeout, ensure_repo_creation_
disabled, the security doc's merge-gate bullet)
ToolGroup::Forge is kept with no tools, the same way b88a5b24 kept
Lifecycle, so existing meta/capabilities.json grants still parse.
Forge state is untouched: existing agents/* repos keep their collaborators
and operators-team branch protection. The swarm-controller's own
create_repo (config-org repos) is a different path and is unchanged.
Closes #4849
This commit is contained in:
parent
bab15e2ba6
commit
7d217f8267
14 changed files with 43 additions and 230 deletions
|
|
@ -302,7 +302,7 @@ binary flavor.
|
|||
| `lifecycle` | none — `list_containers` no longer exists, with no replacement; the variant survives only so existing grants parse. |
|
||||
| `approvals` | none — `request_update_meta_inputs` no longer exists, with no replacement. Still a live server-side gate: `cancel_loose_end`'s approval-cancel arm requires it. |
|
||||
| `scheduling` | `request_schedule_prompt`, `fire_schedule_now`, `cancel_schedule`, `edit_schedule`, `list_schedules` *(privileged)* |
|
||||
| `forge` | `create_repo` — create git repos through hive-c0re (operator-gated merge) |
|
||||
| `forge` | none — `create_repo` no longer exists, with no replacement; the variant survives only so existing grants parse. |
|
||||
| `web_tools` | none (gates the Claude built-ins `WebFetch`/`WebSearch`, not an MCP tool) |
|
||||
|
||||
**Always-on tools** — `ToolGroup::ALWAYS_ON_TOOLS` exposes `set_status`,
|
||||
|
|
|
|||
|
|
@ -212,18 +212,11 @@ plain comment show under `last comment`, not `reviews`.
|
|||
|
||||
Agents **can't create repos directly via forge token** — Forgejo
|
||||
disables push-to-create and the agent token doesn't have the Create
|
||||
scope. Two paths exist depending on where the repo should live:
|
||||
scope.
|
||||
|
||||
**Agent repos (`agents/<name>`)** — Use the `mcp__hyperhive__create_repo`
|
||||
MCP tool (requires the `forge` tool group). hive-c0re creates the repo in
|
||||
the c0re-owned `agents/` org, adds you as a write collaborator (not
|
||||
owner), enables branch protection (operator-team merge approval
|
||||
required — you can't self-merge), and returns the clone URL immediately.
|
||||
This is the standard path for agents that need a working repo.
|
||||
|
||||
**Other repos** — Use the CLI verbs below (`repo-create` / `repo-add-collaborator`).
|
||||
These use the agent's own forge token so the repo lands under the agent's
|
||||
user account or an org the agent belongs to.
|
||||
The CLI verbs below (`repo-create` / `repo-add-collaborator`) use the
|
||||
agent's own forge token, so a repo lands under the agent's user account
|
||||
or an org the agent belongs to.
|
||||
|
||||
**`repo-create <name>`** — create a repo under the authenticated user
|
||||
and print its URL. Key flags:
|
||||
|
|
|
|||
|
|
@ -125,10 +125,10 @@ checkpoints**, not about sandboxing the agent from its own tools:
|
|||
**human (the operator) merges the PR**, keeping a person in the loop on the
|
||||
highest-value action. On the **internal forge this is technically enforced,
|
||||
not just convention**: agents can't create repos (`max_repo_creation = 0`),
|
||||
so every repo is `core`-created with branch protection **on by default** —
|
||||
merges restricted to the operators team + a required operators-team approval
|
||||
(`apply_operator_branch_protection` / the config-repo equivalent) — and an
|
||||
agent (a write collaborator, not a repo admin) can neither change those
|
||||
and `main` on an `agent-configs/<name>` repo carries swarm-controller's
|
||||
branch protection: merge allowlisted to the `operators` team, with one
|
||||
approval from it. Existing `agents/<repo>` repos carry the same merge gate.
|
||||
An agent (a write collaborator, not a repo admin) can neither change those
|
||||
settings nor merge its own PR. It's **not** set up for external VCS (GitHub
|
||||
etc.), though — there, operator-merge is process + accepted risk, not a
|
||||
technical control.
|
||||
|
|
|
|||
|
|
@ -137,13 +137,8 @@ hive_name?, swarm_name?, matrix_accounts? }`. `matrix_accounts` is a
|
|||
[`docs/agent-lifecycle/approvals.md`](../agent-lifecycle/approvals.md).
|
||||
- **Scheduling** (`scheduling`) — scheduled prompts. See
|
||||
[`docs/tools/scheduling.md`](../tools/scheduling.md).
|
||||
- **Forge repos** (`forge`) — `create_repo` — the only agent path to
|
||||
create a repo under the `agents/` org (direct forge token creation is
|
||||
disabled for agents). The repo lands in the c0re-owned `agents`
|
||||
org; the calling agent gets write collaborator access; the default
|
||||
branch is branch-protected (operator-team must approve merges, so the
|
||||
agent can't self-merge). Opt-in; not in any default preset.
|
||||
See [`docs/tools/forge.md — Repo management`](../tools/forge.md).
|
||||
- **Forge repos** (`forge`) — carries no MCP tool: `create_repo` no
|
||||
longer exists, with no replacement; `forge` gates nothing.
|
||||
- **Web egress** (`web_tools`) — enables Claude's built-in `WebFetch`
|
||||
and `WebSearch` tools (not MCP tools; added directly to the
|
||||
`--allowedTools` list). Off by default; add the group in the
|
||||
|
|
|
|||
Loading…
Reference in a new issue