Skip to content

fix(session): enforce --strict-mcp-config at the pane-spawn choke point - #32

Merged
Eyalm321 merged 5 commits into
mainfrom
fix/goal-agent-strict-mcp-config
Oct 5, 2026
Merged

Eyalm321 merged 5 commits into
mainfrom
fix/goal-agent-strict-mcp-config

Conversation

@Eyalm321

@Eyalm321 Eyalm321 commented Oct 5, 2026 •

Copy link
Copy Markdown
Owner

What this changes

Enforces --strict-mcp-config at the pane-spawn choke point (79264df, rs/crates/core/src/session/spawn.rs).

claude --mcp-config <file> does not restrict claude to that file. It merges every MCP server the rotated account dir registers. The code-index servers (tokensave, serena) then re-index the repo once per goal agent, at 6–10 GB each against a ~300 MB normal footprint.

2b58fd6 fixed the persona spawn templates, but agents spawn agents, so the guarantee shouldn't depend on an LLM following prose. resolve_spawn_with now inserts --strict-mcp-config into any claude launch that carries an explicit --mcp-config. It covers both the shell-wrapped string form and the direct argv form. The edit is byte-preserving: the inserted flag is the only change, quoting and prompt text come back verbatim, and every no-op path returns Cow::Borrowed.

Also on this branch

  • Version bump to 0.0.31 (0476f67). Main still reads 0.0.30, so merging this carries the bump.
  • cf16afa (model aliases): already on main as b014598. Same patch, so the merge resolves it with no conflict.
  • b0492de: rustfmt reflow of spawn.rs that 79264df left unformatted.
  • A merge of main (5d1781b) bringing in the goal-orchestrator restore fix and the script exec-bit fix.

Verification

On the merged tree:

core fmt clean, clippy -D warnings clean, 717 passed, incl. the 10 new strict_mcp_config_* / resolve_spawn_* tests
app fmt clean, 184 passed / 1 ignored, cargo build --locked clean
terminal-widget clippy clean

Not verified live. Running goal agents do carry --strict-mcp-config, but the installed build is cut from main, which does not contain this change. Those flags come from the launch line and the personas (2b58fd6), not from this choke point. The choke point is covered by unit tests only: the shell-string form, the argv form, --mcp-config= equals form, quoted values with spaces, idempotency, and the no-op cases (non-claude commands, no --mcp-config, a dangling flag).

A note on the counts: a first pass reported core at 707, because shared CARGO_TARGET_DIR across worktrees reused a spawn.rs artifact built from main. The numbers above are from a forced rebuild.

🤖 Generated with Claude Code

Eyalm321 and others added 5 commits September 23, 2026 00:37
2b58fd6 corrected the goal-persona spawn templates, but agents spawn agents
here, so the guarantee should not rest on an LLM following prose.
`resolve_spawn_with` now inserts `--strict-mcp-config` into any `claude`
launch carrying an explicit `--mcp-config`, for both the shell-wrapped
string shape and the direct argv shape.

Without the flag, `claude --mcp-config <file>` does not restrict claude to
that file: it MERGES every server the rotated account dir registers. The
code-index servers (tokensave, serena) then index the repo once per agent,
6-10GB each against a ~300MB normal footprint.

The edit is byte-preserving: the inserted flag is the only change, so
quoting, spacing and prompt text come back verbatim. Every no-op path
returns Cow::Borrowed.
…ation

The model pickers held dated ids — `claude-opus-5[1m]`, `claude-sonnet-5[1m]`,
`claude-fable-5[1m]`, `claude-haiku-4-5`. Those keep working after a model
launch, which is the problem: a long-running goal org stays pinned to the
previous generation indefinitely and nothing surfaces it. The only cure was
noticing and editing the array, then shipping a hyperpanes release.

`--model` takes an alias for the latest model in a family ("Provide an alias for
the latest model (e.g. 'fable', 'opus', or 'sonnet')"), so the picker now holds
`opus[1m]` / `sonnet[1m]` / `fable[1m]` / `haiku` and a new model reaches running
orgs with no release at all.

Verified against the 2.1.280 binary rather than assumed: its accepted set is
`["sonnet","opus","haiku","fable","best","sonnet[1m]","opus[1m]","fable[1m]",
"opusplan"]`, so `[1m]` is valid ON an alias — Claude Code builds `"opus[1m]"`
itself. `haiku` has no 1M entry there, which is why index 3 stays bare.

That makes `GOAL_MODELS` identical to `GOAL_MODEL_LABELS` today. They stay
separate: one is a wire value, the other UI text, and rewording a label must not
change what gets spawned.

Three tests guard it, because a regression here is invisible — a dated id still
spawns fine, it just quietly runs last generation. They assert every entry is in
Claude Code's alias set, that nothing starts with `claude-`, and that only
families with a 1M variant carry the suffix.

Personas updated to match (SKILL.md's model-choice guidance, SPEC.md's
`spawn_workers` command and its `HP_GOAL_IMPL_MODEL` default). Mirrored into
~/dev/agent-orchestration-skills, still uncommitted there.

App: 174 passed, rustfmt clean, `cargo build --locked` clean.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Picked up incidentally: `cargo fmt --all` run from rs/crates/app reaches core
through the workspace path dependency. Whitespace only — core stays rustfmt and
clippy clean, 717 tests passing.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
rpm.sh refuses when the requested version and crates/app/Cargo.toml disagree,
which is the guard that stops a package claiming a version its binary does not
report.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Brings in the goal-orchestrator restore fix (45023a3, f5146df), the model-alias
cherry-pick (b014598, a duplicate of this branch's cf16afa that git resolves
cleanly), and the script exec-bit fix (23c4cbc).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@Eyalm321
Eyalm321 merged commit 5b1775f into main Oct 5, 2026
20 checks passed
@Eyalm321
Eyalm321 deleted the fix/goal-agent-strict-mcp-config branch October 5, 2026 22:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant