feat: compose authenticated stdio MCP with explicit runtime tool mapping
Some checks failed
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / pytest-smoke (push) Failing after 3s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e747-8f27-7242-8df8-8bc44f88c929
This commit is contained in:
tegwick 2026-09-28 12:38:04 +02:00
parent 1ece969f59
commit 3c5cbfbafe
14 changed files with 465 additions and 81 deletions

View file

@ -19,6 +19,8 @@ def discover(root):
from hub_core.runtime.inbox_projection import create_inbox_projection_router
from hub_core.security.browser import create_browser_router
from hub_core.mcp import RUNTIME_TOOL_NAMES
rows = []
def routes(router):
@ -100,7 +102,8 @@ def discover(root):
calls.append(dict(method=call.func.attr[1:].upper(), path_expression=ast.unparse(call.args[0])))
rows.append(dict(id=f'mcp:{name}', kind='mcp', tool=name, profile='mcp-client',
source=str(path.relative_to(root)), line=node.lineno,
target_calls=calls, current_gate='per-invocation token provider available; host adoption required'))
target_calls=calls, backend_profiles=['embedded', 'runtime'] if name in RUNTIME_TOOL_NAMES else ['embedded'],
current_gate='per-invocation credential provider available; enforced runtime requires stdio credential file; embedded host admission required'))
assert expected == {r['tool'] for r in rows if r['kind'] == 'mcp'}
assert len(rows) == len({r['id'] for r in rows}), 'Duplicate surface identity'
return sorted(rows, key=lambda r:r['id'])

View file

@ -1,7 +1,7 @@
#!/usr/bin/env python3
"""Check an installed wheel outside the checkout's import path (use python -I).
Run via: uv run --no-project --with dist/<wheel> python -I tools/check_installed_package.py
Run via: uv run --no-project --isolated --refresh-package hub-core --with dist/<wheel> python -I tools/check_installed_package.py
No startup, owner requests, credentials or database connection are needed.
"""
import json
@ -9,6 +9,7 @@ from importlib.resources import files
from pathlib import Path
import hub_core
from hub_core.mcp.credentials import StdioTokenFile
from hub_core.conformance import ConformanceHarness
from hub_core.runtime.app import create_app
from hub_core.runtime.config import RuntimeSettings
@ -22,6 +23,7 @@ def main():
installed = Path(hub_core.__file__).resolve()
if installed.is_relative_to(checkout):
raise RuntimeError('package smoke imported checkout instead of installed wheel')
StdioTokenFile(Path("/not-read-by-package-check"))
catalog = json.loads(files('hub_core.security').joinpath('routes.json').read_text())['routes']
app = create_app(settings=RuntimeSettings(environment='test', access_mode='enforce'))
routes = [*iter_routes(app), *iter_routes(create_inbox_projection_router())]