Repository navigation
Conversation
Per-platform MCP scoping: 1. A user migrating a global server writes 2. The guard is wired into toolset resolution only; the connection path never consults it (please confirm).
|
…tforms Servers scoped to other platforms are excluded from _get_platform_tools resolution even when explicitly listed (server-side scope wins); absent platforms = all (compat). '*'/'all'/'any' mean every platform, and a scope naming no known platform is warned about once instead of silently disabling the server everywhere. Cron's per-job MCP merge now follows the same cron-platform rules, so a server scoped away from cron cannot reach a job by being named there either. Closes NousResearch#110916
07c1464 to
94666df
Compare
|
Both points addressed at head 1. 2. Connection path — confirmed, traced, and one real leak closed. The MCP client pool is process-wide and shared across platforms/profiles by design (a multiplexed gateway connects a server once and serves several platforms from one connection), so the connection layer cannot be the per-platform gate without breaking that sharing. The enforcement point is toolset assembly: every runtime building an agent's toolset routes through Tests: focused → 10 passed; full neighbor files ( |
Closes #110916
Adds an optional server-side allowlist: mcp_servers..platforms (e.g. [discord]). Servers scoped to other platforms are excluded from _get_platform_tools resolution for that platform, even when explicitly listed in its platform_toolsets (server-side scope wins). Absent/null platforms means every platform (backward compatible); unparseable values fail open with a warning.
Enforcement point: enabled_mcp_server_names(config, platform) (new optional param, default keeps legacy set) threaded through _merge_mcp_servers from _get_platform_tools, so CLI/gateway/api_server/ACP/discord all resolve through the one chokepoint. MCP tool definitions and dispatch both derive from enabled_toolsets, so the scope holds at both seams.
Verification:
Known ceiling: portable plugin servers (in-memory, no config entry) cannot be scoped. The remaining direct enabled_mcp_server_names callers without a platform are diagnostics/membership checks (cron preflight; the ACP membership intersection, which intersects the already-filtered set and cannot re-admit). The MCP connection pool is process-wide by design (a multiplexed gateway shares one connection across platforms), so per-platform exposure is enforced where toolsets are assembled: _get_platform_tools(<platform_key>), which gateway/CLI/TUI/ACP/api_server/cron all route through. Cron's per-job MCP merge now threads platform=cron too, so a scoped-away server cannot reach a job by name.