Repository navigation
feat(mcp): admit user MCP tools in Plan and Goal - #1384
Open
chengzhi-c wants to merge 9 commits into
Open
chengzhi-c wants to merge 9 commits into
chengzhi-c wants to merge 9 commits into
Conversation
A user MCP server stays out of Plan and Goal unless its record names the raw tools. The launch path forwards each named tool as its own full name, and host-core admits an mcp_ call only when that list contains the exact tool name. An empty list, a wildcard, and a sibling tool stay denied. Agent mode is unchanged.
Use native path basenames in fork assertions so Windows checks retain their exact file-preservation contract. Bound SDK-heavy test workers to available CPUs and at most four to avoid resource starvation without increasing test timeouts.
Avoid forced handshakes for metadata edits. Isolate global MCP test storage so sync clearing is verified against an independent target.
Raw MCP identities must not change underneath admitted tools after a configuration update or reconnect. Unchanged editor arguments and local permission preferences must survive saves and portable configuration sync.
Authorization completion used the record captured when login started. A configuration change or disable during the wait could reconnect that old server. Look up the current record and refuse the handshake when it no longer matches.
# Conflicts: # apps/desktop/src/components/extensions/McpEditorSheet.tsx # apps/desktop/test/user-mcp.test.mjs # crates/host-core/src/mcp_servers.rs # crates/host-core/src/mcp_servers/tests.rs # crates/host-core/src/rpc/mod.rs # packages/shared/src/types/capabilities.ts
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
planSafeTools, or every active user MCP tool when the localallowMcpInPlanGoalswitch is on.tools/callsends.Rebased onto current
origin/main(831b66dfa). The per-server handshake timeout is preserved.Verification
Checked locally at
913e8b611.cargo fmt -p host-core --checkmcp_execution_forwards_the_admitted_raw_identitycargo test -p host-core --locked: 745 passed.data_relocationfails the same two tests on currentorigin/main, andtools_abort_during_execution_kills_bash_and_cleans_registrypasses on its ownapps/desktopnode --test: the MCP files pass. The package run also hits pre-existing Windows failures (POSIX shell, SSH, macOS signing, models.dev catalog) and one Vite server that hangs inselection-texaction_requiredFixes #1112