Skip to content

feat(mcp): UIState recipe bridge, evidence matrix, KB PR, feedback - #130

Merged
tonythethompson merged 15 commits into
mainfrom
feature/mcp-validation-kb-feedback
Aug 7, 2026
Merged

tonythethompson merged 15 commits into
mainfrom
feature/mcp-validation-kb-feedback

Conversation

@tonythethompson

@tonythethompson tonythethompson commented Aug 6, 2026 •

Copy link
Copy Markdown
Owner

Summary

Implements docs/mcp-validation-kb-feedback.plan.md:

  1. UIState ↔ Recipe bridge — createDefaultPipelineState, projectUiStateToRecipeEvaluation, studioRecipeBridge, loopback-only POST /api/mcp/studio-recipe + rate limit
  2. Python MCP tools — validate_ui_state_recipe, get_recipe_for_ui_state (fixed OLIVE_STUDIO_API_URL loopback only)
  3. Evidence-backed compatibility matrix — schema requires olive_pass + provenance; expanded matrix; test_compatibility_matrix.py; CI olive-pass-availability job (enumerate only, no optimization)
  4. Reviewable KB refresh — deterministic generator metadata; kb-update.yml runs generators+tests and opens labeled kb-refresh PR (no auto-merge)
  5. Local troubleshooting feedback — record_troubleshoot_feedback, bounded ranking in hybrid scorer, thumbs UI on MCPDiagnosticCard wired through ExecutionWorkspace + BatchProcessingPanel

Test plan

  • pnpm exec vitest run --config vitest.config.ts src/lib/__tests__/recipePipeline.test.ts
  • pnpm exec vitest run --config vitest.integration.config.ts src/server/__tests__/routes.integration.test.ts
  • pnpm exec vitest run --config vitest.component.config.ts (MCPDiagnosticCard / EW / Batch)
  • cd olive-mcp-server && python -m pytest tests/test_studio_recipe.py tests/test_compatibility_matrix.py tests/test_feedback.py tests/test_troubleshooting_hybrid.py tests/test_integration.py -q
  • CI green (lint, unit, server, integration, component, python-tests, olive-pass-availability)

Notes

  • Isolated worktree branch feature/mcp-validation-kb-feedback (original dirty branch preserved)
  • No real Olive optimization in tests/CI
  • Feedback is local aggregate-only (no log/traceback storage)

Review in cubic

@vercel

vercel Bot commented Aug 6, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
olive-studio Ready Ready Preview Aug 7, 2026 8:51am

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sorry @tonythethompson, your pull request is larger than the review limit of 150000 diff characters

@coderabbitai

coderabbitai Bot commented Aug 6, 2026 •

Copy link
Copy Markdown
Contributor

Review Change Stack

Warning

Review limit reached

@cursor[bot], you've reached your PR review limit, so we couldn't start this review.

Next review available in: 9 minutes

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 34506ab0-99aa-43d3-ba99-a0bd419c9958

📥 Commits

Reviewing files that changed from the base of the PR and between dd15075 and 3023b5c.

📒 Files selected for processing (37)
  • .github/workflows/ci.yml
  • .github/workflows/kb-update.yml
  • README.md
  • olive-mcp-server/README.md
  • olive-mcp-server/olive_mcp_server/knowledge_base/compatibility_matrix.json
  • olive-mcp-server/olive_mcp_server/mcp_server.py
  • olive-mcp-server/olive_mcp_server/tools/__init__.py
  • olive-mcp-server/olive_mcp_server/tools/feedback.py
  • olive-mcp-server/olive_mcp_server/tools/studio_recipe.py
  • olive-mcp-server/olive_mcp_server/tools/troubleshooting.py
  • olive-mcp-server/schemas/compatibility-v1.json
  • olive-mcp-server/scripts/check_olive_pass_availability.py
  • olive-mcp-server/scripts/expand_kb.py
  • olive-mcp-server/scripts/update_kb.py
  • olive-mcp-server/tests/test_compatibility_matrix.py
  • olive-mcp-server/tests/test_feedback.py
  • olive-mcp-server/tests/test_integration.py
  • olive-mcp-server/tests/test_studio_recipe.py
  • olive-mcp-server/tests/test_troubleshooting_hybrid.py
  • src/components/features/BatchProcessingPanel.test.tsx
  • src/components/features/BatchProcessingPanel.tsx
  • src/components/features/ExecutionWorkspace.test.tsx
  • src/components/features/ExecutionWorkspace.tsx
  • src/components/features/MCPDiagnosticCard.test.tsx
  • src/components/features/MCPDiagnosticCard.tsx
  • src/lib/__tests__/recipePipeline.test.ts
  • src/lib/hooks.ts
  • src/lib/pipelineValidation.ts
  • src/lib/recipePipeline.ts
  • src/lib/stores/pipelineStore.ts
  • src/server/__tests__/routes.integration.test.ts
  • src/server/middleware/rateLimit.ts
  • src/server/routes/mcp.ts
  • src/server/services/mcp/allowedTools.ts
  • src/server/services/mcp/client.ts
  • src/server/services/mcp/studioRecipeBridge.ts
  • src/types.ts
📝 Walkthrough

Walkthrough

The change adds loopback Studio recipe tools, aggregate troubleshooting feedback, evidence-backed Olive compatibility validation, deterministic knowledge-base refresh automation, related server and UI integrations, tests, workflows, and documentation.

Changes

MCP platform expansion

Layer / File(s) Summary
Compatibility contracts and pass validation
olive-mcp-server/olive_mcp_server/knowledge_base/compatibility_matrix.json, olive-mcp-server/schemas/*, olive-mcp-server/scripts/check_olive_pass_availability.py, olive-mcp-server/tests/test_compatibility_matrix.py, .github/workflows/ci.yml
The compatibility matrix now records Olive pass names and provenance evidence. Tests and CI validate matrix claims against installed Olive passes.
Studio recipe evaluation path
src/lib/*, src/server/services/mcp/*, src/server/routes/mcp.ts, src/server/middleware/rateLimit.ts, olive-mcp-server/olive_mcp_server/tools/studio_recipe.py, olive-mcp-server/tests/test_studio_recipe.py, src/server/__tests__/routes.integration.test.ts
The bridge sanitizes UI state, evaluates recipes without Olive execution, enforces loopback access, applies rate limits, and exposes structured results through MCP and HTTP routes.
Diagnostic feedback and ranking loop
olive-mcp-server/olive_mcp_server/tools/feedback.py, olive-mcp-server/olive_mcp_server/tools/troubleshooting.py, src/lib/hooks.ts, src/components/features/MCPDiagnosticCard.tsx, src/components/features/ExecutionWorkspace.tsx, src/components/features/BatchProcessingPanel.tsx, related tests
The server stores capped aggregate feedback and applies bounded ranking adjustments. The client validates feedback payloads and renders feedback controls for matched diagnostics.
Execution and diagnostic state integration
src/components/features/BatchProcessingPanel.tsx, src/components/features/ExecutionWorkspace.tsx, related tests
Batch execution uses reusable lifecycle helpers. The workspace supports historical diagnostics, keyed fixes, and feedback callbacks.
Deterministic KB refresh automation
olive-mcp-server/scripts/update_kb.py, olive-mcp-server/scripts/expand_kb.py, .github/workflows/kb-update.yml
KB generation now writes stable outputs and refresh metadata. The workflow validates changes, preserves human-edited branches, and creates or updates one labeled refresh PR.

Estimated code review effort: 5 (Critical) | ~120 minutes

Possibly related PRs

🚥 Pre-merge checks | ✅ 8
✅ Passed checks (8 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly summarizes the main changes: the UIState recipe bridge, compatibility evidence matrix, knowledge-base refresh PR, and feedback support.
Description check ✅ Passed The description directly explains the implemented features, workflow changes, feedback behavior, and planned test coverage.
Docstring Coverage ✅ Passed Docstring coverage is 63.48% which is sufficient. The required threshold is 60.00%.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Pipeline Stage Enum Ordering ✅ Passed The repository contains no SessionWorkflowStage enum, required stage members, or references, so this ordering and comparison check is not applicable to the pull request.
Gpu/Cpu Runtime Boundary ✅ Passed The PR-wide diff contains no inference/, managed requirements, main.py, or C# files; olive_requirements.txt is unchanged, so the GPU/CPU boundary conditions are not triggered.
Managed Host Restart Safety ✅ Passed The PR diff does not modify any managed-host component, and repository searches found no named host, lease, restart, or health/live symbols requiring this check.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch feature/mcp-validation-kb-feedback
✨ Simplify code
  • Create PR with simplified code
  • Commit simplified code in branch feature/mcp-validation-kb-feedback

Warning

Review ran into problems

🔥 Problems

Linked repositories: Public OSS repositories can only analyze public repositories installed in this organization. Analyzed tonythethompson/QuickShell, tonythethompson/numan, tonythethompson/dependency-chain-substrate, skipped Trackdubllc/Trackdub.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@greptile-apps

greptile-apps Bot commented Aug 6, 2026 •

Copy link
Copy Markdown
Contributor

Greptile Summary

This PR adds the Studio UIState-to-recipe bridge, MCP validation and feedback tools, evidence-backed compatibility data, and an automated reviewable knowledge-base refresh process.

  • Adds loopback-only Studio recipe evaluation and corresponding Python MCP tools.
  • Introduces aggregate local troubleshooting feedback and bounded ranking adjustments.
  • Expands compatibility evidence, validation tests, and CI pass-registry checks.
  • Adds UI feedback controls and propagates their handlers through execution and batch views.
  • Updates the scheduled knowledge-base workflow to generate, test, and propose refresh changes.

Confidence Score: 4/5

The PR does not yet appear safe to merge because the KB refresh workflow can still miss older human commits before replacing its refresh branch.

The workflow starts from a shallow checkout, fetches the refresh branch without explicitly obtaining its complete ancestry, and only deepens the default branch. Its author scan can therefore omit older refresh-branch commits and proceed to rebuild and force-update a branch containing human work.

Files Needing Attention: .github/workflows/kb-update.yml

Important Files Changed

Filename Overview
.github/workflows/kb-update.yml Adds generation, validation, artifact upload, and refresh-PR branch management; the previously reported human-edit preservation issue remains outstanding.
src/server/routes/mcp.ts Adds the loopback Studio recipe endpoint and integrates request rate limiting.
src/server/services/mcp/studioRecipeBridge.ts Bridges partial UI state into the shared recipe evaluation pipeline.
olive-mcp-server/olive_mcp_server/tools/studio_recipe.py Adds MCP clients for validating UI state and retrieving Studio-built recipes through a fixed loopback endpoint.
olive-mcp-server/olive_mcp_server/tools/feedback.py Implements bounded local aggregate feedback persistence for troubleshooting entries.
olive-mcp-server/olive_mcp_server/tools/troubleshooting.py Incorporates aggregate feedback as a capped adjustment to hybrid troubleshooting ranking.
olive-mcp-server/olive_mcp_server/knowledge_base/compatibility_matrix.json Expands model and hardware compatibility records with Olive pass identifiers and provenance.
src/components/features/MCPDiagnosticCard.tsx Adds optional thumbs feedback controls for diagnostics with stable matched entries.

Reviews (14): Last reviewed commit: "fix(codefactor): split BatchProcessingPa..." | Re-trigger Greptile

Comment thread .github/workflows/kb-update.yml Outdated
@qodo-code-review

Copy link
Copy Markdown
Contributor

PR Summary by Qodo

feat(mcp): UIState↔recipe bridge, evidence-backed KB, feedback loop

✨ Enhancement 🧪 Tests ⚙️ Configuration changes 🕐 40+ Minutes

Grey Divider

AI Description

• Adds a loopback-only POST /api/mcp/studio-recipe bridge plus
 createDefaultPipelineState/projectUiStateToRecipeEvaluation to project untrusted UIState into a
 JSON-safe recipe/validation payload for new Python MCP tools validate_ui_state_recipe and
 get_recipe_for_ui_state.
• Requires olive_pass + provenance evidence on every compatibility-matrix claim, expands the
 matrix, and adds test_compatibility_matrix.py plus a CI olive-pass-availability job that
 enumerates the installed Olive pass registry (no optimization).
• Reworks kb-update.yml to run KB generators + tests and open a single labeled, human-reviewed
 kb-refresh PR (never auto-merged) instead of just uploading reports.
• Adds local-only aggregate record_troubleshoot_feedback (thumbs up/down + bounded reason codes)
 with a bounded ranking nudge in the hybrid scorer, wired to new thumbs UI on MCPDiagnosticCard via
 ExecutionWorkspace and BatchProcessingPanel.
• Refactors oliveRecipeBuilder.ts quantization/conversion/pruning branches into per-pass builder
 maps (structural, byte-compatible), and converts local-engine CLI discovery
 (findLmsCli/findOllamaCli) to async single-flight probing with abortable, capped-backoff
 readiness polling.
Diagram

graph TD
  UI["Studio UI"] --> Bridge["POST /api/mcp/studio-recipe"] --> Pipeline["recipePipeline.ts projection"] --> Recipe["Olive recipe JSON"]
  PyTool["validate_ui_state_recipe / get_recipe_for_ui_state"] -->|loopback HTTP only| Bridge
  Card["MCPDiagnosticCard thumbs"] --> FeedbackTool["record_troubleshoot_feedback"] --> Store[(Feedback JSON store)]
  Store --> Scorer["Hybrid troubleshooting scorer"]
  CI["olive-pass-availability CI job"] --> Matrix[(compatibility_matrix.json)]
  KBWorkflow["kb-update.yml"] --> Matrix
  KBWorkflow --> PR["kb-refresh PR (human review)"]
  subgraph Legend
    direction LR
    _svc([Service/Route]) ~~~ _db[(Data store)] ~~~ _ext{{External/CI}}
  end
Loading
High-Level Assessment

The PR's approach is sound: a loopback-only HTTP bridge with strict SSRF guards (no caller-supplied URL, host/scheme/credential validation, redirect refusal) is the standard safe pattern for a local Python process calling into a local Node server, and reusing the existing TypeScript recipe pipeline as the single source of truth avoids duplicating validation logic in Python. Evidence-requiring schema plus a CI enumeration job (rather than full Olive execution) is a pragmatic way to keep the compatibility matrix honest without incurring heavy CI cost. Aggregate-only, capped feedback storage with a small clamped ranking nudge is an appropriately conservative choice to avoid feedback loops overpowering keyword/semantic matching or leaking sensitive log data.

Files changed (42) +9994 / -2262

Enhancement (17) +4672 / -1116
studioRecipeBridge.tsNew loopback bridge core: allowlist-merge UIState and project recipe +192/-0

New loopback bridge core: allowlist-merge UIState and project recipe

• Adds evaluateStudioRecipeBridge and mergeBridgeUiState which allowlist-merge an untrusted partial UIState onto defaults, reject dangerous keys (batchJobs, activeJobId, etc.), and run a single pure projection into a JSON-safe evaluation payload.

src/server/services/mcp/studioRecipeBridge.ts

mcp.tsAdd loopback-only POST /api/mcp/studio-recipe route +61/-4

Add loopback-only POST /api/mcp/studio-recipe route

• Registers a new route gated by a strict loopback check (rejecting reverse-proxy hops) and a dedicated rate limiter, delegating to evaluateStudioRecipeBridge.

src/server/routes/mcp.ts

recipePipeline.tsAdd projectUiStateToRecipeEvaluation and UiStateRecipeEvaluation type +67/-0

Add projectUiStateToRecipeEvaluation and UiStateRecipeEvaluation type

• New pure wrapper around buildRecipeFromState returning a stable, JSON-safe evaluation shape (effectiveState, recipe, issues, counts, runnability) for the MCP bridge contract.

src/lib/recipePipeline.ts

types.tsAdd MCP feedback and diagnostic frequency types +94/-1

Add MCP feedback and diagnostic frequency types

• Adds McpDiagnosticFrequency, feedback rating/reason-code types and allowlists, and request/result/error shapes for record_troubleshoot_feedback; documents matched_entry as the stable feedback key.

src/types.ts

hooks.tsExtract parseMcpDiagnosticPayload and add feedback request helper +292/-53

Extract parseMcpDiagnosticPayload and add feedback request helper

• Factors diagnostic payload parsing into a reusable, testable function with frequency support and adds hasMcpFeedbackTarget plus requestMcpTroubleshootFeedback (implementation continues beyond shown diff) for submitting thumbs feedback via the MCP proxy.

src/lib/hooks.ts

MCPDiagnosticCard.tsxAdd thumbs up/down feedback controls to diagnostic card +387/-223

Add thumbs up/down feedback controls to diagnostic card

• Introduces DiagnosticFeedbackButtons, shown only when a diagnosis has a stable non-empty matched_entry, submitting via requestMcpTroubleshootFeedback with per-target reset, single-submission guard, and retry-on-error UX.

src/components/features/MCPDiagnosticCard.tsx

ExecutionWorkspace.tsxWire feedback callback and historical diagnosis display +46/-7

Wire feedback callback and historical diagnosis display

• Adds handleFeedbackSubmitted passthrough to MCPDiagnosticCard and displays the active history entry's diagnostic/fixApplied state alongside live MCP results.

src/components/features/ExecutionWorkspace.tsx

BatchProcessingPanel.tsxWire feedback callback into batch job diagnostics card +18/-2

Wire feedback callback into batch job diagnostics card

• Adds handleFeedbackSubmitted passthrough so batch-job MCPDiagnosticCard instances support thumbs feedback.

src/components/features/BatchProcessingPanel.tsx

studio_recipe.pyNew validate_ui_state_recipe / get_recipe_for_ui_state MCP tools +329/-0

New validate_ui_state_recipe / get_recipe_for_ui_state MCP tools

• Implements a loopback-only, SSRF-guarded HTTP client (no redirects, host/scheme/credential validation) that POSTs UIState to the Studio bridge and normalizes camelCase/snake_case fields into structured tool responses.

olive-mcp-server/olive_mcp_server/tools/studio_recipe.py

feedback.pyNew record_troubleshoot_feedback aggregate feedback store +413/-0

New record_troubleshoot_feedback aggregate feedback store

• Implements an atomically-written, capped, sanitized JSON store for thumbs-up/down and allowlisted reason codes keyed by KB entry id, with path resolution via override/env/XDG defaults and no free-form content persistence.

olive-mcp-server/olive_mcp_server/tools/feedback.py

troubleshooting.pyApply bounded feedback adjustment to hybrid ranking score +20/-0

Apply bounded feedback adjustment to hybrid ranking score

• Integrates feedback_score_delta into _best_match, clamping the adjustment to FEEDBACK_MAX_ADJUSTMENT and only applying it when the base hybrid score is already positive.

olive-mcp-server/olive_mcp_server/tools/troubleshooting.py

mcp_server.pyRegister new studio-recipe and feedback tools +12/-0

Register new studio-recipe and feedback tools

• Adds validate_ui_state_recipe, get_recipe_for_ui_state, and record_troubleshoot_feedback to the tool dispatch table.

olive-mcp-server/olive_mcp_server/mcp_server.py

__init__.pyExpose new tools in package lazy-import map +6/-0

Expose new tools in package lazy-import map

• Adds the three new tool names to the lazy module map and __all__ export list.

olive-mcp-server/olive_mcp_server/tools/init.py

compatibility-v1.jsonRequire olive_pass and provenance evidence on compatibility claims +40/-2

Require olive_pass and provenance evidence on compatibility claims

• Adds required olive_pass and evidence fields to pass_compat entries and defines a new pass_evidence schema with reference/type/version fields.

olive-mcp-server/schemas/compatibility-v1.json

compatibility_matrix.jsonExpand and annotate compatibility matrix with evidence +1609/-134

Expand and annotate compatibility matrix with evidence

• Substantially expands model/pass entries and adds olive_pass and evidence provenance fields to satisfy the updated schema.

olive-mcp-server/olive_mcp_server/knowledge_base/compatibility_matrix.json

expand_kb.pyRework KB expansion generator content and structure +890/-682

Rework KB expansion generator content and structure

• Large rewrite of the pass/matrix expansion generator to produce evidence-backed entries consistent with the new schema requirements.

olive-mcp-server/scripts/expand_kb.py

update_kb.pyMake KB update output deterministic with refresh metadata +196/-8

Make KB update output deterministic with refresh metadata

• Adds content-addressed fingerprinting, deterministic source timestamps, conditional file writes, and a merged refresh_metadata.json to support diff-stable, reviewable automated PRs.

olive-mcp-server/scripts/update_kb.py

Bug fix (3) +14 / -8
lmStudioRoutes.tsAwait async findLmsCli and pass abort signal to ensureLmsReady +5/-3

Await async findLmsCli and pass abort signal to ensureLmsReady

• Updates call sites for the now-async CLI discovery and forwards guard.signal so a disconnecting client aborts the shared ensure operation.

src/server/routes/ai/lmStudioRoutes.ts

ollamaRoutes.tsPass abort signal to ensureOllamaReady +3/-2

Pass abort signal to ensureOllamaReady

• Forwards guard.signal into ensureOllamaReady so the first disconnecting caller can cancel the shared operation.

src/server/routes/ai/ollamaRoutes.ts

installEngineRoutes.tsPass abort signal to ensure* readiness calls +6/-3

Pass abort signal to ensure* readiness calls

• Updates install-engine route to forward guard.signal into ensureOllamaReady/ensureLmsReady for proper cancellation.

src/server/routes/ai/installEngineRoutes.ts

Refactor (4) +548 / -376
pipelineStore.tsExtract createDefaultPipelineState factory +25/-19

Extract createDefaultPipelineState factory

• Replaces the shared mutable defaultState singleton with a pure factory function returning a fresh UIState object per call, used by both the store and the new bridge.

src/lib/stores/pipelineStore.ts

oliveRecipeBuilder.tsRefactor pass builders into typed per-pass builder maps +334/-266

Refactor pass builders into typed per-pass builder maps

• Replaces long if/else quantization/conversion/pruning chains with PASS_BUILDERS/QUANT_METHOD_BUILDERS/CONVERSION_BUILDERS registries and a shared withCalibrationData helper; structural refactor with byte-compatible output.

src/lib/oliveRecipeBuilder.ts

localEngines.tsConvert CLI probing to async single-flight with abortable backoff polling +187/-89

Convert CLI probing to async single-flight with abortable backoff polling

• Replaces execSync-based findLmsCli/findOllamaCli with async execFileAsync probing guarded by single-flight promises, and rewrites ensure*ReadyImpl loops to use a shared pollUntil helper with AbortSignal support and capped exponential backoff.

src/server/routes/ai/localEngines.ts

localEngineState.tsMinor state adjustments supporting async CLI probing +2/-2

Minor state adjustments supporting async CLI probing

• Small updates to shared local-engine runtime state to support the new single-flight/async probing model.

src/server/services/ai/localEngineState.ts

Tests (12) +4040 / -694
MCPDiagnosticCard.test.tsxNew tests for diagnostic feedback UI +381/-0

New tests for diagnostic feedback UI

• Covers rendering, conditional visibility of thumbs controls based on matched_entry, and submit/disable/retry flows.

src/components/features/MCPDiagnosticCard.test.tsx

ExecutionWorkspace.test.tsxAdd tests for MCP feedback wiring and failure diagnosis flow +197/-20

Add tests for MCP feedback wiring and failure diagnosis flow

• Adds runnable-state helpers, a no-Olive fetch mock, and tests exercising the diagnostic card feedback path after a simulated Execute Live failure.

src/components/features/ExecutionWorkspace.test.tsx

BatchProcessingPanel.test.tsxRewrite batch panel tests for feedback and diagnostics +410/-290

Rewrite batch panel tests for feedback and diagnostics

• Substantially reworks existing test suite to cover new feedback wiring alongside prior job validation behavior.

src/components/features/BatchProcessingPanel.test.tsx

recipePipeline.test.tsAdd tests for projectUiStateToRecipeEvaluation +180/-0

Add tests for projectUiStateToRecipeEvaluation

• Verifies the stable evaluation payload shape, parity with buildRecipeFromState, JSON-serializability, and sanitized effectiveState behavior.

src/lib/tests/recipePipeline.test.ts

routes.integration.test.tsAdd integration tests for studio-recipe bridge route +263/-2

Add integration tests for studio-recipe bridge route

• Covers 200 responses for valid/partial/empty/blocked UIState inputs, confirms no Olive job side effects, and asserts loopback access is not rejected.

src/server/tests/routes.integration.test.ts

setup.integration.tsUpdate comment for async CLI discovery mocking +4/-3

Update comment for async CLI discovery mocking

• Documents that findLmsCli is now async and resolves through mocked execFile rather than execSync.

src/server/tests/setup.integration.ts

localEngines.test.tsAdd unit tests for async CLI probing and abortable polling +230/-0

Add unit tests for async CLI probing and abortable polling

• New test suite mocking child_process to validate caching, single-flight probing, and abort-aware readiness polling.

src/server/routes/ai/localEngines.test.ts

test_compatibility_matrix.pyNew schema/provenance validation test suite for compatibility matrix +702/-0

New schema/provenance validation test suite for compatibility matrix

• Validates the real matrix against passes.json and the JSON schema, checking evidence types, version windows, and uniqueness constraints; includes negative fixtures.

olive-mcp-server/tests/test_compatibility_matrix.py

test_feedback.pyNew tests for feedback persistence, validation, and privacy +522/-0

New tests for feedback persistence, validation, and privacy

• Covers atomic writes, corrupt-store recovery, input validation, capped counters/reasons, and asserts no free-form/log content is ever persisted.

olive-mcp-server/tests/test_feedback.py

test_studio_recipe.pyNew tests for studio-recipe bridge tools and SSRF guards +648/-0

New tests for studio-recipe bridge tools and SSRF guards

• Covers loopback/scheme/credential validation, successful forwarding and field normalization, and error handling for unreachable/malformed bridge responses.

olive-mcp-server/tests/test_studio_recipe.py

test_troubleshooting_hybrid.pyUpdate hybrid scorer tests for bounded feedback adjustment +500/-379

Update hybrid scorer tests for bounded feedback adjustment

• Reworks existing hybrid-ranking tests to account for the new feedback-based score delta and its clamping behavior.

olive-mcp-server/tests/test_troubleshooting_hybrid.py

test_integration.pyMinor integration test update +3/-0

Minor integration test update

• Small adjustment to integration test setup accompanying the new tools.

olive-mcp-server/tests/test_integration.py

Documentation (2) +198 / -17
README.mdDocument studio-recipe bridge, feedback privacy, and KB refresh PRs +16/-4

Document studio-recipe bridge, feedback privacy, and KB refresh PRs

• Expands the MCP integration section to cover the loopback bridge, local-only feedback privacy guarantees, and the new kb-refresh PR workflow.

README.md

README.mdDocument new bridge tools, feedback env vars, and setup pin +182/-13

Document new bridge tools, feedback env vars, and setup pin

• Adds setup instructions for the studio-recipe bridge precondition, OLIVE_STUDIO_API_URL/OLIVE_MCP_FEEDBACK_PATH env vars, tool tables, and example request/response payloads; pins mcp<2.

olive-mcp-server/README.md

Other (4) +522 / -51
rateLimit.tsAdd studioRecipeRateLimit limiter +9/-0

Add studioRecipeRateLimit limiter

• New 30 req/min rate limiter dedicated to the studio-recipe bridge endpoint.

src/server/middleware/rateLimit.ts

check_olive_pass_availability.pyNew CI helper enumerating installed Olive pass registry +262/-0

New CI helper enumerating installed Olive pass registry

• Compares compatibility_matrix.json claimed passes against the installed Olive package's pass registry via several fallback discovery strategies, exiting non-zero on missing claims.

olive-mcp-server/scripts/check_olive_pass_availability.py

ci.ymlAdd olive-pass-availability CI job +40/-0

Add olive-pass-availability CI job

• New job installs a pinned olive-ai CPU-only build and runs check_olive_pass_availability.py to enumerate the pass registry against the compatibility matrix, with no model download or optimization.

.github/workflows/ci.yml

kb-update.ymlRework KB auto-update workflow to open a reviewable refresh PR +211/-51

Rework KB auto-update workflow to open a reviewable refresh PR

• Adds least-privilege permissions, runs generators plus compatibility/unit tests, detects KB output changes, and creates/updates a single labeled kb-refresh PR while preserving branches with human commits; never auto-merges.

.github/workflows/kb-update.yml

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 139ec59e8a

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment on lines +57 to +60
"record_troubleshoot_feedback": (
"olive_mcp_server.tools.feedback",
"record_troubleshoot_feedback",
),

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Restrict the persistent feedback tool to loopback callers

Registering record_troubleshoot_feedback here exposes a filesystem-writing, ranking-changing tool through the existing unauthenticated POST /api/mcp/tool proxy. Since server.ts binds Express to 0.0.0.0 and that proxy has no local-only middleware, any reachable LAN client can repeatedly increment the capped counters and persistently influence later troubleshooting matches, contrary to the tool's local-only contract. Gate this tool at the proxy or otherwise authenticate/restrict its callers.

Useful? React with 👍 / 👎.

Comment on lines +350 to +352
path = get_feedback_path()
with _lock:
store = _load_store_unlocked(path)

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Use an inter-process lock for feedback increments

When two feedback submissions overlap, this lock does not protect the read-modify-write cycle because the HTTP MCP proxy launches a fresh Python process for every request. Both processes can load the same counters, increment independently, and atomically replace the file, causing one acknowledged vote to be lost; use a cross-process file lock or another atomic persistence mechanism around the load and replace.

Useful? React with 👍 / 👎.

Comment thread .github/workflows/kb-update.yml Outdated
Comment on lines +126 to +127
git fetch origin "${BRANCH}" --depth=50
git fetch origin "${DEFAULT_BRANCH}" --depth=50

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Fetch enough history before checking for human commits

In the inspected kb-update.yml refresh workflow, both branch tips are fetched with depth 50 before evaluating origin/${DEFAULT_BRANCH}..origin/${BRANCH}. If the default branch advances beyond that shallow window between refreshes, the histories have no common ancestor and git log includes older human-authored commits from the refresh branch, so the workflow falsely reports human edits and permanently skips bot updates. Fetch full history or deepen until a merge base is available before applying the author filter.

Useful? React with 👍 / 👎.

Expose loopback-only Studio recipe validation for MCP tools, evidence-backed
compatibility matrix with CI pass enumeration, reviewable KB refresh PRs,
and local aggregate troubleshooting feedback with UI thumbs controls.
@tonythethompson
tonythethompson force-pushed the feature/mcp-validation-kb-feedback branch from 139ec59 to c391d6c Compare August 6, 2026 01:45
@qodo-code-review

qodo-code-review Bot commented Aug 6, 2026 •

Copy link
Copy Markdown
Contributor

Code Review by Qodo

🐞 Bugs (0) 📘 Rule violations (0) 📜 Skill insights (0)

Grey Divider


Action required

1. Feedback errors lose message ✓ Resolved 🐞 Bug ≡ Correctness
Description
record_troubleshoot_feedback returns structured error payloads containing an error field, but the
MCP proxy client treats any tool result with inner.error as a transport failure and the HTTP route
converts it to a 500 {error: <code>} response, dropping message and other fields. This breaks
the new thumbs UI’s ability to display actionable failure details (e.g. unknown_matched_entry,
persist_failed) and makes normal validation failures indistinguishable from invocation failures.
Code

olive-mcp-server/olive_mcp_server/tools/feedback.py[R314-317]

+        return {
+            "status": "error",
+            "error": "invalid_matched_entry",
+            "message": "matched_entry must be a non-empty string entry id.",
Relevance

●●● Strong

They commonly preserve actionable error details and return 4xx for validation failures instead of
generic 500s.

PR-#117
PR-#111

ⓘ Recommendations generated based on similar findings in past PRs

Evidence
The tool returns {status:"error", error:<code>, message:<text>}; the MCP client converts any
row.result.error into out.error; and the /api/mcp/tool route maps out.error to HTTP 500 with
only {error: out.error}. The new UI feedback request path expects structured payloads and will
lose the message/detail through this flattening.

olive-mcp-server/olive_mcp_server/tools/feedback.py[291-347]
olive-mcp-server/olive_mcp_server/tools/feedback.py[387-395]
src/server/services/mcp/client.ts[127-135]
src/server/routes/mcp.ts[229-243]
src/lib/hooks.ts[316-416]

Agent prompt
The issue below was found during a code review. Follow the provided context and guidance below and implement a solution

## Issue description
The new `record_troubleshoot_feedback` tool returns structured error objects with `{status: "error", error: <code>, message: <text>}`. The Node MCP bridge (`callOliveMcpTools`) currently treats any `row.result.error` as an invocation failure and converts it into `out.error`, causing `/api/mcp/tool` to respond HTTP 500 with only `{error: ...}` and discard the message/details.

## Issue Context
- `record_troubleshoot_feedback` intentionally returns a structured error payload (not an exception) to preserve a user-facing message.
- The MCP proxy uses `inner.error` as a sentinel for invocation failures, which collides with the tool’s error schema.

## Fix Focus Areas
- src/server/services/mcp/client.ts[127-135]
- src/server/routes/mcp.ts[231-243]
- olive-mcp-server/olive_mcp_server/tools/feedback.py[313-346]

### Suggested implementation direction
- Update `callOliveMcpTools` parsing: only treat `row.result.error` as an invocation error when the payload is a “proxy error envelope” (e.g., lacks `status`), and **pass through** structured results where `status === "error"`.
- With the above, `/api/mcp/tool` will return 200 with the structured `{status:"error", error, message}` payload for feedback failures, enabling the UI to show `message`.
- Alternatively (less preferred), rename the tool’s field from `error` to `code` to avoid colliding with the proxy’s sentinel, but this won’t help other future tools unless the proxy behavior is clarified.

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools



Remediation recommended

2. Tool proxy enables disk writes ✓ Resolved 🐞 Bug ⛨ Security
Description
This PR adds the record_troubleshoot_feedback MCP tool which persists a local JSON file, but the
existing /api/mcp/tool route is neither loopback-restricted nor rate-limited and will invoke
whatever toolName is provided. Since the server listens on 0.0.0.0, any client that can reach
the Studio HTTP server can trigger feedback-store writes via /api/mcp/tool.
Code

olive-mcp-server/olive_mcp_server/mcp_server.py[R57-60]

+    "record_troubleshoot_feedback": (
+        "olive_mcp_server.tools.feedback",
+        "record_troubleshoot_feedback",
+    ),
Relevance

●●● Strong

Team has accepted adding rate limits/loopback protections on unauthenticated, side-effecting routes.

PR-#108
PR-#93

ⓘ Recommendations generated based on similar findings in past PRs

Evidence
The PR registers record_troubleshoot_feedback as a callable MCP tool; that tool writes a JSON
store to disk; /api/mcp/tool executes arbitrary tool names via the MCP Python bridge without a
loopback gate/rate limit; and the server listens on 0.0.0.0, making the endpoint reachable beyond
localhost when network exposed.

olive-mcp-server/olive_mcp_server/mcp_server.py[49-60]
olive-mcp-server/olive_mcp_server/tools/feedback.py[77-88]
olive-mcp-server/olive_mcp_server/tools/feedback.py[200-219]
src/server/routes/mcp.ts[229-247]
server.ts[215-219]
src/server/services/mcp/client.ts[91-112]

Agent prompt
The issue below was found during a code review. Follow the provided context and guidance below and implement a solution

## Issue description
The new feedback tool writes to disk (`_atomic_write_unlocked`), and it is callable through the general-purpose MCP tool proxy endpoint `/api/mcp/tool`. That endpoint is currently open (no loopback gate, no rate limit) and the server binds to `0.0.0.0`, so network-reachable clients can trigger repeated disk writes.

## Issue Context
Even if the intended threat model is local-first, binding to `0.0.0.0` means LAN exposure is easy to do unintentionally. Adding a state-mutating tool increases the impact of this existing surface.

## Fix Focus Areas
- src/server/routes/mcp.ts[229-247]
- src/server/middleware/rateLimit.ts[81-89]
- server.ts[215-219]
- olive-mcp-server/olive_mcp_server/tools/feedback.py[200-219]

### Suggested implementation direction
- Apply a loopback-only middleware to `/api/mcp/tool` similar to the new studio-recipe bridge gate (or at minimum gate `record_troubleshoot_feedback`).
- Add a rate limiter for `/api/mcp/tool` (or a dedicated limiter for feedback submissions).
- Consider splitting write-capable tools onto dedicated endpoints with stricter guards, or introducing a server-side allowlist of tool names that are safe to expose via HTTP.

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools


3. Trivial handleFeedbackSubmitted useCallback ✓ Resolved 📜 Skill insight ➹ Performance
Description
handleFeedbackSubmitted is memoized with useCallback but performs no meaningful work, adding
unnecessary complexity and cognitive overhead without benefit. This violates the guidance to avoid
memoizing trivial values.
Code

src/components/features/ExecutionWorkspace.tsx[R214-217]

+  const handleFeedbackSubmitted = useCallback(
+    (payload: { matched_entry: string; rating: McpTroubleshootFeedbackRating }) => {
+      // No UI mutation — diagnosis display and history stay as-is after thumbs.
+      void payload.matched_entry;
Relevance

●● Moderate

Removing trivial useCallback is subjective; team accepts some hook-simplification, but no close
precedent on useCallback triviality.

PR-#98
PR-#107

ⓘ Recommendations generated based on similar findings in past PRs

Evidence
PR Compliance ID 2450421 disallows memoizing trivial values with useCallback. In the cited code,
handleFeedbackSubmitted is wrapped in useCallback yet only executes `void
payload.matched_entry;`, demonstrating it does not perform meaningful work and therefore constitutes
a trivial, unnecessary memoization.

src/components/features/ExecutionWorkspace.tsx[213-220]
src/components/features/BatchProcessingPanel.tsx[78-85]
Skill: vite-react-best-practices

Agent prompt
The issue below was found during a code review. Follow the provided context and guidance below and implement a solution

## Issue description
`handleFeedbackSubmitted` is wrapped in `useCallback` but only does `void payload.matched_entry;`, making the memoization unnecessary.

## Issue Context
The compliance rule discourages `useCallback` for trivial handlers unless needed for referential stability (e.g., React.memo children or dependency arrays).

## Fix Focus Areas
- src/components/features/ExecutionWorkspace.tsx[213-220]
- src/components/features/BatchProcessingPanel.tsx[78-85]

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools


Grey Divider

Context used
✅ Compliance rules (platform): 86 rules
✅ REVIEW.md

To customize comments, go to the Qodo configuration screen, or learn more in the docs.

Qodo Logo

Comment thread src/components/features/ExecutionWorkspace.tsx Outdated
Comment thread olive-mcp-server/olive_mcp_server/tools/feedback.py
Comment thread olive-mcp-server/olive_mcp_server/mcp_server.py
@qodo-code-review

Copy link
Copy Markdown
Contributor

Qodo Fixer

✅ Committed (3) · ☑ Fixed (3)

Grey Divider

Commits pushed directly to this PR — no separate fix PR opened.

Process — 3 fixed
  • ☑ Fixed: Feedback errors lose message
  • ☑ Fixed: Tool proxy enables disk writes
  • ☑ Fixed: Trivial handleFeedbackSubmitted useCallback

Add UiStatePatch so bridge partial passes type-check, enumerate Olive passes from installed olive_config.json without importing olive, require keyword evidence for explicit studio/olive troubleshoot domains, and fix MCPDiagnosticCard ref sync plus fetch mock typing.

Co-authored-by: Cursor <cursoragent@cursor.com>
Compare matrix olive_pass claims to Olive 0.12.x registry keys case-insensitively, and allow duplicate diagnostic titles in ExecutionWorkspace history test.

Co-authored-by: Cursor <cursoragent@cursor.com>
Treat QNNQuantization, OnnxModelOptimizer, and AzureMLQuantization as aliases or cloud-only claims so olive-pass-availability matches the pinned olive-ai 0.12.1 config.

Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Resolve MCP conflicts by keeping the studio-recipe bridge and loopback
gates from #130 while adopting main's bodyGuard, tool allowlist, circuit
breaker, and 503 unavailable handling. Preserve validation-error payloads
that use status: "error" so they are not unwrapped as proxy failures.

Co-authored-by: Anthony Thompson <github@trackdub.com>
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
@greptile-apps
greptile-apps Bot dismissed their stale review August 7, 2026 07:05

Dismissed because a newer commit was pushed; Greptile will re-review the current head.

greptile-apps[bot]
greptile-apps Bot previously approved these changes Aug 7, 2026
Merge duplicate @/types imports, replace bare except/pass with logged
fallbacks, remount MCP feedback controls via key instead of setState in
effects, and split high-complexity helpers flagged by CodeFactor.

Co-authored-by: Anthony Thompson <github@trackdub.com>
@greptile-apps
greptile-apps Bot dismissed their stale review August 7, 2026 07:47

Dismissed because a newer commit was pushed; Greptile will re-review the current head.

greptile-apps[bot]
greptile-apps Bot previously approved these changes Aug 7, 2026
@codefactor-io

codefactor-io Bot commented Aug 7, 2026 •

Copy link
Copy Markdown

Extract batch queue/SSE helpers, feedback UI/button class helpers,
MCP diagnostic/feedback parsers, bridge enum/pass assigners, and
compatibility-matrix claim validators so CodeFactor complex-method
findings stay under threshold.

Co-authored-by: Anthony Thompson <github@trackdub.com>
@greptile-apps
greptile-apps Bot dismissed their stale review August 7, 2026 08:00

Dismissed because a newer commit was pushed; Greptile will re-review the current head.

@codefactor-io

codefactor-io Bot commented Aug 7, 2026

Copy link
Copy Markdown

CodeFactor found an issue: Complex Method

It's currently on:
src\components\features\BatchProcessingPanel.tsx:401-502
Commit 920b511

greptile-apps[bot]
greptile-apps Bot previously approved these changes Aug 7, 2026
@tonythethompson

Copy link
Copy Markdown
Owner Author

@coderabbitai full review

@coderabbitai

coderabbitai Bot commented Aug 7, 2026 •

Copy link
Copy Markdown
Contributor
❌ Action failed

Review failed.

Extract queue-job helpers so CodeFactor no longer flags
handleStartQueue as a complex method on PR 130.

Co-authored-by: Anthony Thompson <github@trackdub.com>
@greptile-apps
greptile-apps Bot dismissed their stale review August 7, 2026 08:51

Dismissed because a newer commit was pushed; Greptile will re-review the current head.

@tonythethompson
tonythethompson merged commit 3291f6f into main Aug 7, 2026
14 checks passed
@tonythethompson
tonythethompson deleted the feature/mcp-validation-kb-feedback branch August 7, 2026 08:59
@linear-code

linear-code Bot commented Aug 7, 2026

Copy link
Copy Markdown
Contributor

OLI-60

This branch was successfully deployed

1 active deployment
Preview — 3023b5ca Deployed Aug 7, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants