fix(mcp): refuse the environment writes that resolve to a wrong or hidden entry - #660
Merged
Merged
Conversation
…dden entry A custom name a built-in stack ends in (monitor, for azure-monitor) is refused, and the effective entry only selects a prefixed key that parses back to the configured pair, so a hand-edited declaration never reads a built-in's entry. local is refused as an environment value and prefix, like unknown. An environment write while the stack is local is refused - switch the stack first, or in the same call - and a switch to local clears the stored environment, so nothing re-arms on the next remote switch. Closes #656 Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This was referenced Sep 26, 2026
Merged
Merged
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
The MCP server's configuration validation no longer lets three environment states through:
monitornext toazure-monitor) is refused, and the effective entry selects<environment>-<stack>only when that key parses back to the configured pair, so a pre-existingmonitordeclaration can no longer read the built-in's entry;environmentwrite while the resulting stack islocalis refused ("the local stack takes no environment - switch the stack first, or in the same call"), and a switch tolocalclears the stored environment, so nothing re-arms on the next remote switch;localis refused as an environment value and as a key prefix, likeunknown.The implementation choices that go beyond or narrow the proposal are recorded on the issue: #656 (comment)
Tests
tests/mcp-server/test_config.py/test_server.py(268 passed).integration-tests/mcp-server/test-config-surface.shcovers the refused writes, the remote-switch-with-environment acceptance and the clear-on-local-switch.apm install --target claude+apm audit(apm-cli 0.31.0) green.Review
A separate reviewer sub-agent checked the whole branch against the issue:
monitor) split the built-in, so every new custom declaration was refused with a message blaming the wrong name. Fixed in 2403386 (only the name being declared is blamed) with a regression test. It also asked for the decision record on the issue before the PR — posted.Harness measurement
Coarse non-regression check only (
test-plugin-harnessing, copilot /openai/gpt-5.6-luna/ medium,/odd-observedrive mission on the local llms-benchmark stack, ABBA). The runtime change lives in the MCP server, which the lab runs from PyPI 1.13.1 on both sides; the only measured difference is six lines ofbackend-configuration/SKILL.md.Main's spread today over six samples: turns 35–45, commands 30–51, tokens in 2.66–3.41 M, wall 310–431 s. Both branch samples sit inside it (1 premium request each, 0 authored scripts, 0 resets, 0
--help). No measurable change expected and none measured.Closes #656
🤖 Generated with Claude Code