remove the create_repo agent tool
mara ruled on #4849 (c88934): "remove create_repo tool". The tool ran in
hive-c0re with the hive's core token, so it only ever worked for agents
on the hive that runs the forge.
Removed:
- the create_repo MCP tool and CreateRepoArgs (hive-agent-mcp)
- wire variants Request::CreateRepo and Response::RepoCreated
(hive-core-agent-sock)
- hive-c0re's handle_create_repo, its valid_repo_name check and the
dispatch arm
- forge::create_agent_repo and apply_operator_branch_protection, which
had no other caller, plus AGENTS_ORG and OPERATORS_TEAM, whose only
users they were
- the tool's docs (docs/tools/forge.md repo management, docs/turn-loop/
mcp.md, the conventions tool-group table) and the doc comments that
named it (hive-sock-client's response timeout, ensure_repo_creation_
disabled, the security doc's merge-gate bullet)
ToolGroup::Forge is kept with no tools, the same way b88a5b24 kept
Lifecycle, so existing meta/capabilities.json grants still parse.
Forge state is untouched: existing agents/* repos keep their collaborators
and operators-team branch protection. The swarm-controller's own
create_repo (config-org repos) is a different path and is unchanged.
Closes #4849
This commit is contained in:
parent
bab15e2ba6
commit
7d217f8267
14 changed files with 43 additions and 230 deletions
|
|
@ -267,12 +267,11 @@ impl Client {
|
|||
/// default branch — only [`OPERATORS_TEAM`] members can merge, and
|
||||
/// an approving review from that team is required, so the agent (a
|
||||
/// write-level collaborator, not in the team) cannot merge its own
|
||||
/// PR. Mirrors `hive-c0re::forge::repos::apply_operator_branch_protection`
|
||||
/// exactly (same policy, same verify-don't-trust shape): a create
|
||||
/// failure is ambiguous (already-exists vs. a silent reject that
|
||||
/// created no rule), so on any error this GETs the `main` rule and
|
||||
/// only treats it as success if the rule is actually present — a
|
||||
/// fail-open merge gate is a security bug, not a shrug.
|
||||
/// PR. A create failure is ambiguous (already-exists vs. a silent
|
||||
/// reject that created no rule), so on any error this GETs the
|
||||
/// `main` rule and only treats it as success if the rule is
|
||||
/// actually present — a fail-open merge gate is a security bug,
|
||||
/// not a shrug.
|
||||
///
|
||||
/// Also push-whitelists [`SWARM_CONTROLLER_FORGE_USER`] alone —
|
||||
/// [`Client::seed_agent_config`]'s initial commit is a direct push to
|
||||
|
|
|
|||
Loading…
Reference in a new issue