Skip to content

fix(security): don't re-quarantine servers added while running (rc.3 release gate) - #1488

Merged
github-actions[bot] merged 1 commit into
mainfrom
claude/fix-gate-runtime-adds
Oct 3, 2026
Merged

github-actions[bot] merged 1 commit into
mainfrom
claude/fix-gate-runtime-adds

Conversation

@Dumbris

@Dumbris Dumbris commented Oct 3, 2026

Copy link
Copy Markdown
Member

Pull Request

Description

Fixes the v0.70.0-rc.3 release-gate failure (matrix/oauth: server not ready, connected=true tools=0). That failure was a regression from #1485 (RC-UPG-001).

Cause

  • fix(security): don't admit a server v0.69 held in quarantine on upgrade (RC-UPG-001) #1485 re-quarantines a server that is known to config.db but has no approved tool baseline.
  • Server.AddServer saves a new server to config.db before it publishes the config, and the admission gate runs on every publish.
  • So a server added at runtime looked "known but never approved" and was held before its tools could be discovered.
  • An OAuth server added with quarantined: false has no tools until sign-in, which is exactly the gate's oauth cell.

Fix

  • The no-baseline rule now applies only to servers that config.db held the first time the gate read it in this process (Runtime.bootKnownServers). Those are the only records an older release could have left behind.
  • A quarantined value stated at add time is now recorded as an operator statement (MarkQuarantineExplicitlySet). It is written to mcp_config.json and obeyed after a restart. This covers:
    • REST add;
    • the upstream_servers MCP add;
    • CLI upstream add --no-quarantine without a running daemon;
    • imports with skip_quarantine (REST and CLI).

The last two were found by an add-path completeness sweep during review. The CLI direct-file case is pre-existing.

Testing

  • I have tested these changes locally
  • I have added/updated tests that prove my fix is effective or my feature works
  • All existing tests pass
Check rc.3 (dc851c8f5) this branch
release-gate matrix --cells oauth (real gate driver, run locally) fail, same error as CI pass
release-gate matrix --cells stdio,http,sse — pass
v0.69 → upgrade replay (keyless server restarted under v0.69) — keyless server held, vetted server live
  • New tests:
    • TestConfigLoadAdmissionGate_ServerAddedWhileRunningIsNotRequarantined;
    • an explicit-bit assertion in TestImport_SkipQuarantine.
  • Suites: the race suite with -tags server passes for runtime, httpapi, server and config. configimport and cmd/mcpproxy tests pass.
  • Lint: clean on the changed files.
  • Review: zcode (GLM) found nothing on the diff. The add-path sweep's two confirmed gaps are fixed here; a third, theoretical bootKnown edge was refuted on verification.

After merge, the next RC will be v0.70.0-rc.4.

🤖 Generated with Claude Code

…release gate)

The RC-UPG-001 rule (#1485) re-holds a server known to config.db with no
approved tool baseline. Server.AddServer saves a new server to config.db
before publishing its config, and the admission gate runs on every
publish, so a server added at runtime was read as known-but-never-
approved and quarantined before its tools could be discovered. An OAuth
server added with quarantined:false has no tools until sign-in, which
failed the v0.70.0-rc.3 release gate (matrix/oauth).

- The no-baseline rule now applies only to servers config.db held the
  first time the gate read it in this process (Runtime.bootKnownServers):
  the only records an older release can have left behind.
- A stated quarantine value on add is recorded as an operator statement
  (MarkQuarantineExplicitlySet) so it is written to mcp_config.json and
  obeyed after a restart: REST add, the upstream_servers MCP add, the CLI
  direct-file add, and imports with skip_quarantine.

Verified with the real release-gate matrix (stdio/http/sse/oauth pass;
oauth fails on dc851c8) and the v0.69 upgrade replay (keyless server
still held, vetted server live).
@cloudflare-workers-and-pages

Copy link
Copy Markdown

Deploying mcpproxy-docs with  Cloudflare Pages  Cloudflare Pages

Latest commit: ab0bf7d
Status: ✅  Deploy successful!
Preview URL: https://2c9be38f.mcpproxy-docs.pages.dev
Branch Preview URL: https://claude-fix-gate-runtime-adds.mcpproxy-docs.pages.dev

View logs

@github-actions

github-actions Bot commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

📦 Build Artifacts

Workflow Run: View Run
Branch: claude/fix-gate-runtime-adds

Available Artifacts

  • archive-darwin-amd64 (31 MB)
  • archive-darwin-arm64 (28 MB)
  • archive-linux-amd64 (19 MB)
  • archive-linux-arm64 (17 MB)
  • archive-windows-amd64 (31 MB)
  • archive-windows-arm64 (27 MB)
  • frontend-dist-pr (0 MB)
  • installer-dmg-darwin-amd64 (27 MB)
  • installer-dmg-darwin-arm64 (24 MB)
  • smart-mcp-proxymcpproxy-goBU52YY.dockerbuild (0 MB)

How to Download

Option 1: GitHub Web UI (easiest)

  1. Go to the workflow run page linked above
  2. Scroll to the bottom "Artifacts" section
  3. Click on the artifact you want to download

Option 2: GitHub CLI

gh run download 37134683826 --repo smart-mcp-proxy/mcpproxy-go

Note: Artifacts expire in 14 days.

@codecov-commenter

codecov-commenter commented Oct 3, 2026 •

Copy link
Copy Markdown

⚠️ Please install the 'codecov app svg image' to ensure uploads and comments are reliably processed by Codecov.

Codecov Report

❌ Patch coverage is 85.71429% with 2 lines in your changes missing coverage. Please review.

Files with missing lines Patch % Lines
internal/httpapi/server.go 0.00% 1 Missing and 1 partial ⚠️

📢 Thoughts on this report? Let us know!

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved (Model B): Paperclip review verdicts = ACCEPT and qa-gate green at this head SHA. Arming auto-merge; GitHub merges when all required checks pass.

@github-actions
github-actions Bot merged commit 13b7158 into main Oct 3, 2026
46 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants