 sysadminandClaude Opus 4.8
|
3428fb4190
|
feat(mcp-health): inventory and guard MCP restart/reload/kill paths (#657)
Enumerate every code/script/host path that can restart, reload, reconnect,
kill, or force-recreate an MCP process, classify each, and link it to the
guard that constrains it.
- mcp_restart_paths.py: machine-readable registry (single source of truth)
with classifications (sanctioned_narrow / guarded_fail_closed / forbidden /
removed / host_residual) plus fail-closed guards:
* assert_restart_attempt_registered() -- unknown restart attempts fail closed
* assert_no_daemon_self_replacement() -- daemon never os.execv/os.kill/os._exit
itself (source-tree scan; comment/docstring mentions ignored)
* assert_auto_restart_helper_absent() -- keeps the #685-removed
_trigger_mcp_auto_restart from returning
* assert_registry_wellformed() -- every path classified, guarded, referenced
- docs/mcp-restart-path-inventory.md: complete inventory table linked from
#655; documents residual host behaviors (/mcp reconnect) and rollout.
- tests/test_mcp_restart_paths.py: 17 tests -- registry well-formedness,
unknown-attempt fail-closed, daemon-self-replacement scan (with injected
violation + comment/docstring negative case), legacy-helper-removed
regression, pkill-stays-contamination (#630), and doc/module lock-step.
No behavior change to existing modules; regression assertions codify invariants
that already hold (per #657 flag-free-before-hard-block rollout). Links
#652 #653 #655 #656.
Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]>
|
2026-07-24 00:57:33 -04:00 |
|