Remove broken post_duo_code_review tool from AI Catalog, add MR review tools
What does this MR do and why?
Issue: https://gitlab.com/gitlab-org/gitlab/-/work_items/604613
The post_duo_code_review tool (id 87) is listed in the AI Catalog for custom agents, but it can never work there. The endpoint it calls is locked to the foundational Code Review flow by a security fix (#578840 (closed)), so custom agents always get a 403. It got added by accident in an old bulk tool-addition commit. This MR removes it from the catalog.
To give custom agents a real way to do code-review-style work on merge requests, this MR also adds 9 tools that already exist in the Duo Workflow Service but were missing from the catalog: add_merge_request_reviewers, create_branch, get_downstream_pipelines, get_failing_bridge_jobs, get_repository_files, list_mr_discussions, reply_to_discussion, set_discussion_resolved, submit_mr_review. All of them were checked to call endpoints that accept ai_workflows-scoped tokens, so they actually work for custom agents.
- Id 87 is retired for good with a new
RETIRED_TOOLSconstant, backed by specs that fail if the id or name is ever reused. - No migration needed: agents that already have 87 stored keep working as before, the id just gets dropped silently everywhere (display, save, flow run, audit) and cleans itself up on the next save.
- Also added: tool privilege mappings in the governance registry, "MR" added to the display-name acronyms so the new tools render as "Submit MR Review" etc., and the docs tool table updated.
References
https://gitlab.com/gitlab-org/gitlab/-/work_items/604613
How to set up and validate locally
Validation steps
- Go to AI Catalog and create or edit a custom agent.
- Open the tools picker.
post_duo_code_reviewis gone. - Search for the new tools. All 9 appear, with
submit_mr_reviewandlist_mr_discussionstitled "Submit MR Review" and "List MR Discussions". - Select a few new tools and save. The agent saves without errors.
Backwards compatibility with a stale tool id (rails console)
# Unknown ids are dropped silently, no errors:
Ai::Catalog::BuiltInTool.where(id: [87, 9]).map(&:name)
# => ["create_merge_request_note"]
Ai::Catalog::BuiltInTool.find_by(id: 87)
# => nil
Ai::Catalog::BuiltInTool.count
# => 101Then open that agent's edit page: it loads cleanly, the removed tool is not shown, and re-saving drops 87 from the stored tools without any error.
MR acceptance checklist
Evaluate this MR against the MR acceptance checklist. It helps you analyze changes to reduce risks in quality, performance, reliability, security, and maintainability.
Related to #604613