Skip to content

fix(clients): harden connect credential commit/abort ordering and offline reconcile - #1494

Merged
Dumbris merged 1 commit into
mainfrom
fix/issues-b4-backend-runtime
Oct 5, 2026
Merged

Dumbris merged 1 commit into
mainfrom
fix/issues-b4-backend-runtime

Conversation

@Dumbris

@Dumbris Dumbris commented Oct 5, 2026

Copy link
Copy Markdown
Member

Summary

Hardened the connect credential commit/abort ordering to prevent partial state transitions during binding reconciliation, and improved offline reconcile recovery through best-effort binding restoration.

Fixed Items

  • Follow-ups from post-merge Sol 6.1 review of Spec 108/109 PRs #1451 (connect credentials): Commit binding changes atomically before finalizing upstream connections; restore bindings on failed finalize with best-effort store row revert; add token-scoped claim constraints to prevent cross-agent credential pollution.
    • Tests: TestConnectCredentialAtomicity, TestOfflineBindingReconcile, TestTokenClaimScope

Review Status

Clean after 1 round(s). One open finding (low priority, deferred):

  • glm:1.1 (low-deferred): The best-effort binding restore after a failed finalize reverts only the store row. It writes no compensating audit record, publishes no event and sends no notification, even though the forward binding change was already recorded and announced.

Refs #1451

…aims, offline reconcile (refs #1451)

- Commit applies the requested binding before finalizing the rotated secret and restores the previous binding if finalize fails (1451-1).
- The in-flight connect claim carries a per-connect token; Release/Abort act only for the owning connect, and Abort refuses when the pending secret is no longer the one it issued (1451-16).
- The offline connect backend wires the config reader and reconciles the client before issuing (1451-2).
@cloudflare-workers-and-pages

Copy link
Copy Markdown

Deploying mcpproxy-docs with  Cloudflare Pages  Cloudflare Pages

Latest commit: 7d4940b
Status: ✅  Deploy successful!
Preview URL: https://39143dd9.mcpproxy-docs.pages.dev
Branch Preview URL: https://fix-issues-b4-backend-runtim.mcpproxy-docs.pages.dev

View logs

@github-actions

github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

📦 Build Artifacts

Workflow Run: View Run
Branch: fix/issues-b4-backend-runtime

Available Artifacts

  • archive-darwin-amd64 (31 MB)
  • archive-darwin-arm64 (28 MB)
  • archive-linux-amd64 (19 MB)
  • archive-linux-arm64 (17 MB)
  • archive-windows-amd64 (31 MB)
  • archive-windows-arm64 (27 MB)
  • frontend-dist-pr (0 MB)
  • installer-dmg-darwin-amd64 (27 MB)
  • installer-dmg-darwin-arm64 (24 MB)
  • smart-mcp-proxymcpproxy-goQXGDB5.dockerbuild (0 MB)

How to Download

Option 1: GitHub Web UI (easiest)

  1. Go to the workflow run page linked above
  2. Scroll to the bottom "Artifacts" section
  3. Click on the artifact you want to download

Option 2: GitHub CLI

gh run download 37301100323 --repo smart-mcp-proxy/mcpproxy-go

Note: Artifacts expire in 14 days.

@codecov-commenter

Copy link
Copy Markdown

⚠️ Please install the 'codecov app svg image' to ensure uploads and comments are reliably processed by Codecov.

Codecov Report

❌ Patch coverage is 80.00000% with 8 lines in your changes missing coverage. Please review.

Files with missing lines Patch % Lines
internal/runtime/clients_service_connect.go 78.37% 5 Missing and 3 partials ⚠️

📢 Thoughts on this report? Let us know!

@Dumbris
Dumbris merged commit bcc6380 into main Oct 5, 2026
44 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants