Repository navigation
fix(security): don't re-quarantine servers added while running (rc.3 release gate) - #1488
Merged
Merged
Conversation
…release gate) The RC-UPG-001 rule (#1485) re-holds a server known to config.db with no approved tool baseline. Server.AddServer saves a new server to config.db before publishing its config, and the admission gate runs on every publish, so a server added at runtime was read as known-but-never- approved and quarantined before its tools could be discovered. An OAuth server added with quarantined:false has no tools until sign-in, which failed the v0.70.0-rc.3 release gate (matrix/oauth). - The no-baseline rule now applies only to servers config.db held the first time the gate read it in this process (Runtime.bootKnownServers): the only records an older release can have left behind. - A stated quarantine value on add is recorded as an operator statement (MarkQuarantineExplicitlySet) so it is written to mcp_config.json and obeyed after a restart: REST add, the upstream_servers MCP add, the CLI direct-file add, and imports with skip_quarantine. Verified with the real release-gate matrix (stdio/http/sse/oauth pass; oauth fails on dc851c8) and the v0.69 upgrade replay (keyless server still held, vetted server live).
Deploying mcpproxy-docs with
|
| Latest commit: |
ab0bf7d
|
| Status: | ✅ Deploy successful! |
| Preview URL: | https://2c9be38f.mcpproxy-docs.pages.dev |
| Branch Preview URL: | https://claude-fix-gate-runtime-adds.mcpproxy-docs.pages.dev |
Contributor
📦 Build ArtifactsWorkflow Run: View Run Available Artifacts
How to DownloadOption 1: GitHub Web UI (easiest)
Option 2: GitHub CLI gh run download 37134683826 --repo smart-mcp-proxy/mcpproxy-go
|
|
Codecov Report❌ Patch coverage is
📢 Thoughts on this report? Let us know! |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Pull Request
Description
Fixes the
v0.70.0-rc.3release-gate failure (matrix/oauth: server not ready, connected=true tools=0). That failure was a regression from #1485 (RC-UPG-001).Cause
Server.AddServersaves a new server to config.db before it publishes the config, and the admission gate runs on every publish.quarantined: falsehas no tools until sign-in, which is exactly the gate's oauth cell.Fix
Runtime.bootKnownServers). Those are the only records an older release could have left behind.quarantinedvalue stated at add time is now recorded as an operator statement (MarkQuarantineExplicitlySet). It is written tomcp_config.jsonand obeyed after a restart. This covers:upstream_serversMCP add;upstream add --no-quarantinewithout a running daemon;skip_quarantine(REST and CLI).The last two were found by an add-path completeness sweep during review. The CLI direct-file case is pre-existing.
Testing
dc851c8f5)release-gate matrix --cells oauth(real gate driver, run locally)release-gate matrix --cells stdio,http,sseTestConfigLoadAdmissionGate_ServerAddedWhileRunningIsNotRequarantined;TestImport_SkipQuarantine.-tags serverpasses for runtime, httpapi, server and config.configimportandcmd/mcpproxytests pass.After merge, the next RC will be
v0.70.0-rc.4.🤖 Generated with Claude Code