Skip to content

fix: read-only mode misses checkpoint and delete_by_source in _MUTATING_TOOLS - #1930

Merged
igorls merged 1 commit into
MemPalace:developfrom
yusefhaddad:fix/read-only-missing-mutating-tools
Jul 6, 2026
Merged

fix: read-only mode misses checkpoint and delete_by_source in _MUTATING_TOOLS#1930
igorls merged 1 commit into
MemPalace:developfrom
yusefhaddad:fix/read-only-missing-mutating-tools

Conversation

@yusefhaddad

Copy link
Copy Markdown
Contributor

Summary

mempalace_checkpoint and mempalace_delete_by_source (both added in 3.5.0) are missing from _MUTATING_TOOLS in mcp_server.py. As a result, a server started with --read-only / MEMPALACE_MCP_READ_ONLY=1 still allows writing drawers (checkpoint) and bulk-deleting them (delete_by_source with dry_run=false). The peer-writer lock gate uses the same frozenset, so it is affected as well.

Fix

Add both tool names to the _MUTATING_TOOLS frozenset (2 lines, no behavior change outside read-only/peer-writer gating).

Context

Found during a security review of the codebase before adopting MemPalace as a hardened read-only recall layer for a personal memory system. Thanks for the project, the defensive engineering elsewhere (restricted unpickler, sanitizers, loopback-anchored HTTP) is genuinely impressive.

🤖 Generated with Claude Code

mempalace_checkpoint and mempalace_delete_by_source (added in 3.5.0) were
missing from _MUTATING_TOOLS, so a server started with --read-only /
MEMPALACE_MCP_READ_ONLY=1 still allowed writing drawers and bulk-deleting
by source. The same gap affected the peer-writer lock gate, which uses
the same frozenset.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request updates the _parse_args function in mempalace/mcp_server.py to include two new commands: mempalace_checkpoint and mempalace_delete_by_source. There are no review comments, and I have no additional feedback to provide.

Important

The consumer version of Gemini Code Assist on GitHub is being sunset. Starting June 18, 2026, new organization installations will be blocked, and all code review activity will officially cease on July 17, 2026.
For more details on the timeline and next steps, please review the Help Documentation.

@igorls
igorls merged commit 39bec19 into MemPalace:develop Jul 6, 2026
8 checks passed
@igorls igorls mentioned this pull request Jul 14, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants