feat(#2377): forge-webhook-triggered config-PR merge flow

Replace the request_merge_config_pr MCP tool with a Forgejo
pull_request webhook on the agent-configs org. Agents now open a
config PR normally; hive-c0re auto-queues the MergeConfigPr approval
from the webhook event — no extra tool call needed.

Changes:
- dashboard/webhook.rs: add POST /webhook/config-pr handler
  - parses Forgejo pull_request payload (opened/synchronize)
  - strips agent-configs/<agent> prefix to extract agent name
  - calls submit_merge_config_pr → queues dashboard approval card
  - always 200 to prevent Forgejo retries; errors logged at warn
- dashboard/mod.rs: wire /webhook/config-pr route
- forge/mod.rs: add ensure_config_pr_webhook() — idempotent org-level
  hook registration on agent-configs at startup; CONFIG_ORG now
  pub(crate) for webhook handler
- main.rs: call ensure_config_pr_webhook alongside knowledge webhook
- socket_server/config_approvals.rs: drop handle_request_merge_config_pr;
  make submit_merge_config_pr pub(crate) for webhook handler
- socket_server/mod.rs: re-export submit_merge_config_pr; drop dispatch arm
- hive-sh4re/src/lib.rs: remove AgentRequest::RequestMergeConfigPr
  wire type; drop from ToolGroup::Approvals tool list
- hive-ag3nt/src/mcp/: drop request_merge_config_pr tool + args struct
- docs: update approvals.md (webhook trigger), conventions.md (tool
  group), agent-hierarchy.md, tools/lifecycle.md

Hardening from #2375-merge-config-pr-hardening branch preserved:
- pr_is_open check at queue time (rejects closed/merged PRs)
- atomic fetched_sha INSERT via submit_kind(fetched_sha: Some(&sha))

Approve-handler machinery unchanged (run_merge_config_pr,
ff_push_to_main, fetch_pr_head_into_applied, mark_pr_merged).
This commit is contained in:
atlas 2026-07-11 10:50:24 +02:00 committed by mara
commit d5a81f9195
14 changed files with 255 additions and 163 deletions

View file

@ -64,24 +64,6 @@ pinned commit.
rejected — the approval pins the exact commit). `agent` must be a
direct child. Topology-enforced.
### `request_merge_config_pr(agent, pr_number, description?)`
Submit an open PR on the agent's `agent-configs/<agent>` forge repo for
operator review and merge. The PR-based config flow's counterpart to
`request_apply_commit`: instead of pinning a commit sha from the proposed
repo, the submitter references an already-open forge PR.
hive-c0re fetches the PR head sha at submission time (the "reviewed" sha);
on operator approval it re-checks for drift, eval-verifies the commit,
fast-forwards the forge repo's `main` to the reviewed sha, marks the PR
merged, and rebuilds the agent container. If the PR head moves between
submission and approval the approve handler aborts — the submitter must
re-submit.
`agent` must be in the caller's subtree. The agent must already be fully
provisioned (applied repo present); this tool is not for first-spawn.
Requires the `approvals` tool group.
### `request_update_meta_inputs(inputs?, description?)`
Queue an approval to run `nix flake update [inputs...]` on the meta
@ -100,7 +82,6 @@ agents after the approval resolves.
| `list_containers` | No | All descendants |
| `request_init_config` | Yes (InitConfig) | New direct child only |
| `request_apply_commit` | Yes (ApplyCommit) | Direct children |
| `request_merge_config_pr` | Yes (MergeConfigPr) | Descendants |
| `request_update_meta_inputs` | Yes (MetaUpdate) | Meta flake (global) |
## See also