Fix hosted MCP egress target propagation - #7240
serrrfirat wants to merge 1 commit into
Conversation
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: ASSERTIVE Plan: Pro Plus Run ID: 📒 Files selected for processing (1)
📝 WalkthroughSummary by CodeRabbit
WalkthroughHosted MCP discovery now derives a ChangesHosted MCP network targeting
Estimated code review effort: 2 (Simple) | ~10 minutes Possibly related issues
Suggested reviewers: 🚥 Pre-merge checks | ✅ 4✅ Passed checks (4 passed)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
🔎 Review · PR #7240
Submitted review →Reviewed the complete trusted base-to-head comparison. The change correctly propagates the validated hosted-MCP HTTPS endpoint into discovered capabilities, enabling credential-free calls without broadening access beyond the endpoint host and optional port. No actionable findings identified. Automatic · PR opened · attempt 1 of 3 · completed in 1m 53s Run details
|
There was a problem hiding this comment.
🔍 Review complete · PR #7240
✅ No actionable findings
Reviewed the complete trusted base-to-head comparison. The change correctly propagates the validated hosted-MCP HTTPS endpoint into discovered capabilities, enabling credential-free calls without broadening access beyond the endpoint host and optional port. No actionable findings identified.
Validation and technical details
- Compared refs/ironloop/base (b1da072) through refs/ironloop/head (66ef225).
- Inspected the changed discovery code and traced endpoint admission, capability projection, extension network-policy construction, authorization obligations, runtime obligation validation, and network target matching.
- Inspected the added unit regression and the credential-free hosted-MCP lifecycle integration scenario.
- git diff --check completed successfully.
- The codebase graph was unavailable, so targeted live-code searches were used as required by repository guidance.
- Cargo tests could not be run because cargo is unavailable in the review environment.
- Base:
main - Head:
codex/fix-hosted-mcp-egress-targetat66ef225 - Run:
cbcbc535-55d6-4ebb-946d-52bc2f5f0925
|
Superseded by #7241, recreated from an upstream nearai/ironclaw branch so Railway preview checks can run. |
Summary
ApplyNetworkPolicyobligation and failing before dispatch.Change Type
Linked Issue
None.
Validation
cargo fmt --all -- --checkcargo clippy --all --benches --tests --examples --all-features -- -D warnings— scoped owning-crate clippy was run instead.cargo build— covered by the owning-crate and integration test builds.cargo test -p ironclaw_extensions; credential-free hosted-MCP lifecycle integration test.cargo test --features integration— no database-backed behavior changed.review-prorpr-shepherd --fixwas run before requesting review — final diff was audited locally; no automated PR review was run.Test Strategy
User behavior: A registered credential-free hosted MCP tool can reach its registered server instead of failing locally with
network_deniedduring obligation preparation.Risk areas:
Tests added or updated:
discovered_public_mcp_tool_keeps_endpoint_as_network_targetinironclaw_extensions.no_auth_registration_story_replays_streamable_http_mrc_trace_through_real_lifecycleproduction-path test.What the tests prove: Credential-free discovered tools retain the exact HTTPS host and optional port from the validated registration endpoint, authorization receives a non-empty egress allowlist, and the real hosted-MCP runtime path completes against a hermetic server.
Commands run:
Security Impact
Corrects fail-closed hosted-MCP egress authorization. The change does not introduce wildcard access: each discovered tool receives only the HTTPS host and optional port from the already validated registered MCP endpoint. Paths, queries, private-IP denial, and host-runtime mediation remain unchanged.
Reborn Trust-Boundary Checklist
extension_network_policyand obligation validation.serde(default)fields fail closed or have migration tests. Not affected.Transient,Permanent,Misconfigured,PolicyDeniedor equivalent). No error taxonomy changed.Database Impact
None. No migrations, schemas, or persistence behavior changed.
Blast Radius
Hosted HTTP MCP capability metadata generated after tool discovery. Credentialed providers may now carry the endpoint both explicitly and through credential audiences; the existing policy projection deduplicates identical targets. Other extension runtimes and network policies are unchanged.
Rollback Plan
Revert this commit. That restores the previous fail-closed behavior where credential-free hosted-MCP invocations are rejected during network-obligation preparation.
Review Follow-Through
Please verify that retaining the registered endpoint on discovered capabilities is the preferred ownership boundary. No known follow-up is required.
Review track: C (network authorization)