Skip to content

Fix hosted MCP egress target propagation - #7240

Closed
serrrfirat wants to merge 1 commit into
nearai:mainfrom
serrrfirat:codex/fix-hosted-mcp-egress-target
Closed

serrrfirat wants to merge 1 commit into
nearai:mainfrom
serrrfirat:codex/fix-hosted-mcp-egress-target

Conversation

@serrrfirat

Copy link
Copy Markdown
Collaborator

Summary

  • Preserve the validated hosted-MCP endpoint as an explicit network target on every discovered tool.
  • Prevent credential-free hosted-MCP calls from producing an empty ApplyNetworkPolicy obligation and failing before dispatch.
  • Add a regression test for the credential-free discovery path.

Change Type

  • Bug fix
  • New feature
  • Refactor
  • Documentation
  • CI/Infrastructure
  • Security
  • Dependencies

Linked Issue

None.

Validation

  • cargo fmt --all -- --check
  • cargo clippy --all --benches --tests --examples --all-features -- -D warnings — scoped owning-crate clippy was run instead.
  • cargo build — covered by the owning-crate and integration test builds.
  • Relevant tests pass: cargo test -p ironclaw_extensions; credential-free hosted-MCP lifecycle integration test.
  • cargo test --features integration — no database-backed behavior changed.
  • Manual testing — deterministic production-path integration coverage was used instead.
  • If a coding agent was used and supports it, review-pr or pr-shepherd --fix was run before requesting review — final diff was audited locally; no automated PR review was run.

Test Strategy

User behavior: A registered credential-free hosted MCP tool can reach its registered server instead of failing locally with network_denied during obligation preparation.

Risk areas:

  • Model behavior
  • Browser
  • Side effect
  • Persistence
  • Security or permissions
  • External provider
  • Cross-component behavior

Tests added or updated:

  • Unit or contract: Added discovered_public_mcp_tool_keeps_endpoint_as_network_target in ironclaw_extensions.
  • Reborn integration: Reused the existing no_auth_registration_story_replays_streamable_http_mrc_trace_through_real_lifecycle production-path test.
  • Recorded fixture: Not applicable: model selection and request arguments are unchanged.
  • Browser E2E: Not applicable: no browser behavior changed.
  • Backend or runtime: The existing hermetic hosted-MCP lifecycle integration test exercises registration, discovery, activation, authorization, mediated HTTP, and completion.
  • Live canary: Not applicable: the behavior is deterministic and covered without a real provider.

What the tests prove: Credential-free discovered tools retain the exact HTTPS host and optional port from the validated registration endpoint, authorization receives a non-empty egress allowlist, and the real hosted-MCP runtime path completes against a hermetic server.

Commands run:

cargo test -p ironclaw_extensions discovered_public_mcp_tool_keeps_endpoint_as_network_target
cargo test -p ironclaw_extensions
cargo clippy -p ironclaw_extensions --all-targets --all-features -- -D warnings
cargo test -p ironclaw_reborn_integration_tests --test reborn_integration_hosted_mcp_registration no_auth_registration_story_replays_streamable_http_mrc_trace_through_real_lifecycle -- --exact
cargo fmt --all -- --check
git diff --check

Security Impact

Corrects fail-closed hosted-MCP egress authorization. The change does not introduce wildcard access: each discovered tool receives only the HTTPS host and optional port from the already validated registered MCP endpoint. Paths, queries, private-IP denial, and host-runtime mediation remain unchanged.

Reborn Trust-Boundary Checklist

  • Public policy/evidence/trust-bearing types: construction remains inside validated hosted-MCP package discovery; extensions cannot supply arbitrary discovered-tool targets.
  • Untrusted content enters prompts only through an envelope/escaping primitive. Not affected.
  • Hashes declare purpose; trust/binding/authenticity uses SHA-256/BLAKE3 or separate authenticity check. Not affected.
  • New/changed status, exit, policy, runtime, or error variants: none added; downstream policy construction was audited through extension_network_policy and obligation validation.
  • Security/durability serde(default) fields fail closed or have migration tests. Not affected.
  • Queues/maps/buffers/counters have bounds and overflow-safe arithmetic. Not affected.
  • Driver/operator-visible errors have stable class semantics (Transient, Permanent, Misconfigured, PolicyDenied or equivalent). No error taxonomy changed.
  • Sandbox/native/host names accurately describe trust boundary. Not affected.

Database Impact

None. No migrations, schemas, or persistence behavior changed.

Blast Radius

Hosted HTTP MCP capability metadata generated after tool discovery. Credentialed providers may now carry the endpoint both explicitly and through credential audiences; the existing policy projection deduplicates identical targets. Other extension runtimes and network policies are unchanged.

Rollback Plan

Revert this commit. That restores the previous fail-closed behavior where credential-free hosted-MCP invocations are rejected during network-obligation preparation.

Review Follow-Through

Please verify that retaining the registered endpoint on discovered capabilities is the preferred ownership boundary. No known follow-up is required.


Review track: C (network authorization)

@github-actions github-actions Bot added the size: M 50-199 changed lines label Aug 5, 2026
@coderabbitai

coderabbitai Bot commented Aug 5, 2026 •

Copy link
Copy Markdown

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: b3cb0f31-0f9e-4c41-b91f-345d5eb33c9a

📥 Commits

Reviewing files that changed from the base of the PR and between b1da072 and 66ef225.

📒 Files selected for processing (1)
  • crates/ironclaw_extensions/src/hosted_mcp_discovery.rs

📝 Walkthrough

Summary by CodeRabbit

  • Bug Fixes
    • Hosted MCP capabilities now correctly retain and use their provider’s secure endpoint.
    • Public, credential-free MCP tools now receive the appropriate network access target.
    • Invalid or missing hosted MCP endpoints are rejected during setup.

Walkthrough

Hosted MCP discovery now derives a NetworkTargetPattern from each provider HTTPS endpoint. Template construction rejects invalid or missing endpoints. Discovered capabilities retain the endpoint in their network allowlist, including credential-free providers.

Changes

Hosted MCP network targeting

Layer / File(s) Summary
Derive and validate hosted endpoints
crates/ironclaw_extensions/src/hosted_mcp_discovery.rs
The code parses hosted HTTPS URLs into a scheme, lowercase host, and optional port. Template construction stores the target and rejects invalid or missing endpoints.
Apply endpoint targets to discovered capabilities
crates/ironclaw_extensions/src/hosted_mcp_discovery.rs
Discovered capabilities now use the registered MCP endpoint as their explicit network target. A regression test covers credential-free providers.

Estimated code review effort: 2 (Simple) | ~10 minutes

Possibly related issues

  • nearai/ironclaw#6312 — Both changes connect MCP capability discovery with NetworkTargetPattern outbound allowlisting.

Suggested reviewers: benkurrek

🚥 Pre-merge checks | ✅ 4
✅ Passed checks (4 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly describes the hosted MCP egress target propagation fix; Conventional Commits style is preferred but not required.
Description check ✅ Passed The description covers all required sections, explains the security impact, documents validation, and identifies the review track and rollback plan.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions github-actions Bot added risk: low Changes to docs, tests, or low-risk modules contributor: core 20+ merged PRs labels Aug 5, 2026
@ironloopai

ironloopai Bot commented Aug 5, 2026 •

Copy link
Copy Markdown
Contributor

🔎 Review · PR #7240

🟢 Completed · Review submitted

Submitted review →

Reviewed the complete trusted base-to-head comparison. The change correctly propagates the validated hosted-MCP HTTPS endpoint into discovered capabilities, enabling credential-free calls without broadening access beyond the endpoint host and optional port. No actionable findings identified.

Automatic · PR opened · attempt 1 of 3 · completed in 1m 53s

Run details
  • Repository: nearai/ironclaw
  • Base: main at b1da072
  • Head: codex/fix-hosted-mcp-egress-target at 66ef225
  • Created: Aug 5, 2026, 12:37 PM UTC
  • Updated: Aug 5, 2026, 12:38 PM UTC
  • Run: cbcbc535-55d6-4ebb-946d-52bc2f5f0925
  • Latest attempt: 1 · Completed · 7e3433e7-965e-4f0a-b5b5-1fcb7a561255

@ironloopai ironloopai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔍 Review complete · PR #7240

✅ No actionable findings

Reviewed the complete trusted base-to-head comparison. The change correctly propagates the validated hosted-MCP HTTPS endpoint into discovered capabilities, enabling credential-free calls without broadening access beyond the endpoint host and optional port. No actionable findings identified.

Validation and technical details
  • Compared refs/ironloop/base (b1da072) through refs/ironloop/head (66ef225).
  • Inspected the changed discovery code and traced endpoint admission, capability projection, extension network-policy construction, authorization obligations, runtime obligation validation, and network target matching.
  • Inspected the added unit regression and the credential-free hosted-MCP lifecycle integration scenario.
  • git diff --check completed successfully.
  • The codebase graph was unavailable, so targeted live-code searches were used as required by repository guidance.
  • Cargo tests could not be run because cargo is unavailable in the review environment.
  • Base: main
  • Head: codex/fix-hosted-mcp-egress-target at 66ef225
  • Run: cbcbc535-55d6-4ebb-946d-52bc2f5f0925

@serrrfirat

Copy link
Copy Markdown
Collaborator Author

Superseded by #7241, recreated from an upstream nearai/ironclaw branch so Railway preview checks can run.

This branch was successfully deployed

No deployments
ironclaw-ci-preview / ironclaw-pr-7241 — 66ef225a Deployed Aug 5, 2026 by railway-app[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

contributor: core 20+ merged PRs risk: low Changes to docs, tests, or low-risk modules size: M 50-199 changed lines

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant