Repository navigation
fix: restore MCP compatibility and confine type-map reads - #47
Coding-Dev-Tools wants to merge 4 commits into
Conversation
Automated Code ReviewRuff lint: 0 issue(s)Ruff format: CleanSecret detection: 1 potential secret(s)Review incomplete or critical issues found: secrets, Potential secrets detected Verdict: FAIL Automated by Coding-Dev-Tools/.github reusable workflow. |
|
Review follow-up for the automated review, verified at head The 31 formatting findings are fixed in a separate mechanical commit. Ruff 0.16.10 now reports all 57 Python files formatted and zero lint findings. AST comparisons across every changed file are identical, including all 686 assertions in those files. All 14 MCP tests and the custom-revision fixture are unchanged. The remaining
The fixture is therefore a reproducible false positive for credential detection. Its expected semantics and assertions have been preserved; no exclusions, allowlists, security/lint settings, or check policies changed. The current automated check still reports FAIL for that result and requires maintainer disposition; this evidence does not claim the gate is cleared. Current-head CI passed independently. PR47 remains a draft and is not merged. |
Use the supported FastMCP constructor options for SSE host and port. Add offline signature-enforced transport regressions while preserving stdio defaults and optional MCP use.
Validate both optional MCP type-map paths against the existing allowed root after canonical link resolution. Add synthetic escape and valid-map regressions while preserving standalone CLI behavior and all prior MCP tests.
Schemaforge's MCP integration had three independent defects: optional extras allowed SDK 2.x despite importing the v1
FastMCPAPI; SSE passed unsupported address arguments torun(); and both optional MCP type-map paths reachedTypeConfig.from_filewithout the existing root validation.Both MCP declarations now require
mcp>=1.0,<2. SSE configures host/port through the supported constructor and retains the stdio behavior. Bothconvert.type_map_pathandcheck.type_map_pathnow use the same allowed-root contract ascheck.directory:SCHEMAFORGE_MCP_ROOT, or the current working directory when unset. Canonical resolution follows links before validation, and the validated canonical path is passed to loading. Outside-root maps are rejected before any loader call. Standalone CLI map loading is unchanged.Four separate commits cover the dependency cap, the 31 mechanical formatting corrections requested by review, the two-file SSE repair, and the two-file path repair. The formatting commit preserved all affected ASTs and 686 assertions. The path commit preserves all prior 20 MCP test cases, all 17 test-function ASTs and their 35 assertions, transport wiring, optional dependency behavior, and other three tools. It adds 34 synthetic regression cases.
Current head:
f26a119a678034b67688cf824be6594ecbc597d6Current tree:
50d24e28036e20b2b1fa22dccfc5565fb6354cdaValidation:
TypeError, while both stdio cases passed. Tests enforce the installed SDK's real signature with transport execution stubbed.c35332cc52d7403f026ab50c421933f2197cb989: 12 failing escape cases / 6 passing omitted-map and directory-guard cases. The failures observe mocked loader calls for absolute, traversal and linked escapes in both tools, under both root modes. No outside map contents are read by rejection probes.Fresh automated review run 37974036399 reports zero lint findings and clean formatting. Its remaining FAIL is the unchanged intentional Alembic revision fixture at
tests/test_new_formats.py:713. The unchanged offline scanner reproduces exactly that one finding. The review response documents its synthetic generator input/output assertion. Maintainer disposition is still required; the gate remains unresolved. No human reviews or inline review comments are submitted.PR47 remains a draft. Merge is held for unresolved review requirements and separate approval of the existing master-push GitHub Pages effect. Expected-head publication and remote commit/tree/file readback passed. No provider calls, real/private test-file reads, security-setting/permission changes, merge, release, deployment, or PR44–46 updates occurred.