Files
Gitea-Tools/docs/mcp-tool-inventory.md
T
sysadminandClaude Opus 4.8 e3fa3b263d feat(mcp): gate Connected-but-unattached MCP namespaces (Closes #708)
The prior #708 slice added assess_connected_namespace_attachment() as a pure
decision function with no call site: nothing invoked it, so a session whose
role namespaces were Connected at the host but absent from the active session
tool surface still passed every mutation gate. Detection existed on paper only.

This makes it load-bearing.

Decision layer (mcp_namespace_health.py)
- assess_connected_namespace_attachment() gains secret-free telemetry
  (connected/attached/required/missing counts, discovery cache hit and age,
  reconnect_required, auto_attach_attempted, auto_recovered, error_type) and
  reports reconnect_required, auto_recovered and startup_ordering_race.
- Startup ordering: a namespace whose connect completed after the session tool
  snapshot cannot be in that snapshot, so parallel multi-role startup is
  identified as its own race with the affected namespaces listed.
- attachment_gate_from_session() is a fail-closed gate keyed by
  ATTACHMENT_GATED_TASKS. An unassessed namespace does not gate, matching #543
  semantics, so this never fabricates a block.
- SANCTIONED_ATTACH_RECOVERY_TOOL names gitea_request_mcp_reconnect (#678) as
  the only recovery.

Server wiring (gitea_mcp_server.py)
- New tool gitea_assess_mcp_namespace_attachment classifies the condition and
  records a per-namespace verdict in _LIVE_NAMESPACE_ATTACHMENT.
- gitea_submit_pr_review and gitea_merge_pr now consult
  _namespace_attachment_gate() alongside the existing #543 health gate, so both
  fail closed while a required namespace is unattached.
- Watchdog check-in emits status only, never namespace contents.

The typed condition mcp_connected_namespaces_missing stays distinct from config
drift (#672), transport-closed (#584) and resolver EOF (#685). Recovery never
routes through direct imports, CLI or raw API mutation, profile hopping,
session-state overrides, or process kills.

Docs
- docs/mcp-namespace-health.md documents the tool arguments, startup ordering,
  the fail-closed gate, and the telemetry contract.
- skills/llm-project-workflow/SKILL.md states Connected is not attached, and
  that preflight proof is live tool visibility plus gitea_whoami on the role
  namespace rather than host status alone.
- docs/mcp-tool-inventory.md lists the new tool.
- docs/remote-mcp/threat-model-anchors.json and threat-model.md: 21 #956 anchors
  restamped for the line shift these additions caused in gitea_mcp_server.py.
  Every anchor was re-derived from its recorded expect substring; none guessed.

Tests
- tests/test_issue_708_attachment_wiring.py (19 cases): typed detection, proof
  mapping, reconnect-only next action, auto-attach success and failure,
  reconnect rediscovery, multi-role startup ordering, telemetry including a
  no-secret-leak assertion, fail-closed gate per role, unassessed and unmapped
  tasks not gating, partial attachment gating only the affected role, and no
  healthy verdict without attachment proof.

Verification
- tests/test_issue_708_attachment_wiring.py + test_issue_708_mcp_namespace_attachment.py: 24 passed
- namespace/session/runtime/review sweep: 427 passed, 12 subtests
- full suite head: 31 failed, 5885 passed, 6 skipped, 1047 subtests
- full suite base 17ba1ff035: 30 failed, 5862 passed, 6 skipped, 1047 subtests
- failing identifier sets match, plus tests/test_mirror_refs.py DryRunBanner,
  which fails on the unmodified base in isolation and passes here: flaky, not a
  regression from this branch.
- Gate proven by execution, not inspection: registering the assessment blocks
  merge_pr and review_pr, and attaching the namespaces clears the block.

Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]>
2026-07-28 16:46:09 -04:00

6.2 KiB

Registered MCP tool inventory

This is the canonical list of tools the Gitea-Tools MCP server registers. It exists because documentation and the registered inventory drifted: the workflow documented a gitea_edit_issue tool that no namespace had ever registered, so a mutation could be planned against a tool that did not exist and only fail at execution time (#781).

The rule

Documentation must never name a tool an actor cannot reach.

Two guards enforce it, both in tests/test_issue_781_edit_issue_tool.py:

  1. The list below must equal the registered tool set exactly — sorted, no duplicates, nothing missing in either direction. Adding a tool without documenting it fails, and documenting a tool without registering it fails.
  2. Every backticked gitea_* / mcp_* identifier in skills/**/*.md must be a registered tool. Module and script names that share the prefix are listed explicitly in mcp_tool_inventory.NON_TOOL_IDENTIFIERS rather than being waved through by a looser pattern.

Updating this file

When you add or remove an @mcp.tool(), regenerate the block below:

PYTEST_CURRENT_TEST=1 venv/bin/python -c "
import mcp_server, mcp_tool_inventory
print(mcp_tool_inventory.render_inventory_block(
    mcp_server.mcp._tool_manager._tools))
"

Replace everything between the markers with that output. Do not hand-edit individual entries — the generator and the guard share one ordering rule.

Registered tools

Namespaces (gitea-tools, gitea-reviewer, gitea-merger, gitea-reconciler) register the same tool set; what differs per namespace is the execution profile that gates each call, not which tools exist.

  • gitea_abandon_workflow_lease
  • gitea_acquire_conflict_fix_lease
  • gitea_acquire_merger_pr_lease
  • gitea_acquire_reviewer_pr_lease
  • gitea_activate_profile
  • gitea_adopt_merger_pr_lease
  • gitea_adopt_workflow_lease
  • gitea_allocate_next_work
  • gitea_assess_already_landed_reconciliation
  • gitea_assess_conflict_fix_classification
  • gitea_assess_conflict_fix_push
  • gitea_assess_gitea_operation_path
  • gitea_assess_master_parity
  • gitea_assess_mcp_namespace_attachment
  • gitea_assess_mcp_namespace_health
  • gitea_assess_pr_sync_status
  • gitea_assess_review_merge_state_machine
  • gitea_assess_reviewer_pr_lease
  • gitea_assess_terminal_label_hygiene
  • gitea_assess_work_issue_duplicate
  • gitea_assess_worktree_cleanup_integrity
  • gitea_audit_config
  • gitea_audit_runtime_recovery_contamination
  • gitea_audit_stable_branch_contamination
  • gitea_audit_worktree_cleanup
  • gitea_authorize_reconciliation_cleanup_phase
  • gitea_authorize_review_correction
  • gitea_bootstrap_author_issue_worktree
  • gitea_capability_stop_terminal_report
  • gitea_capture_branches_worktree_snapshot
  • gitea_check_pr_eligibility
  • gitea_cleanup_merged_pr_branch
  • gitea_cleanup_obsolete_reviewer_comment_lease
  • gitea_cleanup_post_merge_moot_lease
  • gitea_cleanup_stale_claims
  • gitea_cleanup_stale_review_decision_lock
  • gitea_cleanup_terminal_pr_labels
  • gitea_close_issue
  • gitea_commit_files
  • gitea_consume_irrecoverable_decision_lock_provenance
  • gitea_create_issue
  • gitea_create_issue_comment
  • gitea_create_label
  • gitea_create_pr
  • gitea_delete_branch
  • gitea_diagnose_review_decision_lock
  • gitea_diagnose_reviewer_pr_lease_handoff
  • gitea_diagnose_terminal
  • gitea_dry_run_pr_review
  • gitea_edit_issue
  • gitea_edit_pr
  • gitea_expire_workflow_leases
  • gitea_get_authenticated_user
  • gitea_get_current_user
  • gitea_get_file
  • gitea_get_pr_review_feedback
  • gitea_get_profile
  • gitea_get_runtime_context
  • gitea_get_shell_health
  • gitea_heartbeat_issue_lock
  • gitea_heartbeat_reviewer_pr_lease
  • gitea_inspect_issue_lock_contract
  • gitea_inspect_workflow_lease
  • gitea_issue_irrecoverable_provenance_authorization
  • gitea_list_dependency_edges
  • gitea_list_issue_comments
  • gitea_list_issues
  • gitea_list_labels
  • gitea_list_profiles
  • gitea_list_prs
  • gitea_list_workflow_leases
  • gitea_load_review_workflow
  • gitea_lock_issue
  • gitea_mark_final_review_decision
  • gitea_mark_issue
  • gitea_merge_pr
  • gitea_mirror_refs
  • gitea_observability_link_issue
  • gitea_observability_list_projects
  • gitea_observability_reconcile_incident
  • gitea_post_heartbeat
  • gitea_publish_unpublished_issue_branch
  • gitea_quarantine_contaminated_review
  • gitea_reclaim_expired_workflow_lease
  • gitea_reconcile_already_landed_pr
  • gitea_reconcile_issue_claims
  • gitea_reconcile_merged_cleanups
  • gitea_reconcile_superseded_by_merged_pr
  • gitea_record_daemon_process_kill_attempt
  • gitea_record_irrecoverable_decision_lock_provenance
  • gitea_record_pre_review_command
  • gitea_record_shell_spawn_outcome
  • gitea_record_stable_branch_push_attempt
  • gitea_recover_incomplete_bootstrap_lock
  • gitea_release_merger_pr_lease
  • gitea_release_reviewer_pr_lease
  • gitea_release_workflow_lease
  • gitea_request_mcp_reconnect
  • gitea_request_mcp_restart
  • gitea_resolve_task_capability
  • gitea_resume_review_draft
  • gitea_review_pr
  • gitea_route_task_session
  • gitea_save_review_draft
  • gitea_scan_already_landed_open_prs
  • gitea_sentry_get_issue_events
  • gitea_sentry_link_gitea_issue
  • gitea_sentry_list_issues
  • gitea_sentry_reconcile_issue
  • gitea_sentry_watchdog
  • gitea_set_issue_labels
  • gitea_submit_pr_review
  • gitea_update_pr_branch_by_merge
  • gitea_validate_review_final_report
  • gitea_view_issue
  • gitea_view_pr
  • gitea_whoami
  • gitea_workflow_dashboard
  • mcp_check_workflow_skill_preflight
  • mcp_get_control_plane_guide
  • mcp_get_skill_guide
  • mcp_list_project_skills

Issue-content editing

gitea_edit_issue is the only path that changes an issue's title or body. It PATCHes the issue endpoint, refuses a pull-request number, sends only the fields the caller named, and proves the result by read-after-write — including that state, labels, assignees, and milestone did not move.

gitea_edit_pr remains pull-request-only. The two paths never merge: a single tool that accepted either kind would make the narrower capability reachable through the wider one.