refactor(mcp): serve admin sync through the project owner - #2343
Merged
Merged
Conversation
|
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
This was referenced Sep 27, 2026
Closed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
tracedecay_admin_syncis now an operation the project's graph-tool owner serves, with a typed request and result.tracedecay initandtracedecay syncread that typed result through the daemon invocation path; they no longer send an MCPtools/calland pullstatusout of its text. This is the first of the four internal admin tools still on the compat path (admin_sync,admin_project,hook_runtime,admin_cli). The compat layer itself is deleted in a later PR.Internal owner operations (
tracedecay-tool-catalog)ApplicationSurfaceOperation::AdminSyncis a graph-tool operation, and it is listed in the newINTERNAL_OPERATIONS. Internal operations are served by name for first-party CLI commands and host hooks. They never appear intools/list, the format-capable list (and so the generated Hermes plugin), or the HTTP mount: the MCP definition projection filters them out.EffectClass::SchedulesWorkis a new owner-side-effect class for "queue work on a daemon scheduler and answer with its admission". The operation's entry is{ SchedulesWork, LONG_RUNNING_CEILING_MILLIS, RunEach }. The ten-minute ceiling is the one it already dispatched under (it was inLONG_RUNNING_DISPATCH_TOOLS); the budget is unchanged. Its catalog capability is not cancellable, and it has nocancelledterminal.MCP_TOOL_NAMESconstant is deleted.Typed contract (
owner_effect_surface.rs)AdminSyncSurfaceRequestV1 {}(deny_unknown_fields) andAdminSyncResultV1 { reconcile_scope, status: queued | not_applicable, project_root }serialize to the JSON the tool already emitted. Before this change, any argument was silently ignored. Now it is refused.Deleted
dispatch_info_toolsMcpToolDispatchGroup::Infogroup and its binding row. Its other names (port_status,port_order,todos) were already owner operations, so the rows were dead.INTERNAL_DAEMON_TOOL_NAMESand long-running-ceiling entries for admin syncadmin_sync_statustext parser in the CLIbrokered_init_*tests, which spoke the oldtools/callwire. Replacements:core_cli_suiteinit journeys against a real daemon (tool_daemon_test,cli_non_interactive_test, which assertdaemon code-index reconciliation requested).a_parked_admin_sync_refusal_prints_as_fields. It converts the owner's refusal through the newApplicationRefusal::into_error, which keeps the typed detail. The code across the owner boundary is the canonicalapplication.code-index.parked, the same code every other owner read uses for a park (seecode_index_park_test), rather than the pre-owner reason code.Fail-before / pass-after (production MCP
tools/call,harness.call_tool)New test:
mcp_handler_test::info_health_request_test::admin_sync_answers_the_scheduler_admission_and_refuses_arguments. It asserts the literal result{"reconcile_scope":"authoritative_project","status":"queued","project_root":<root>}, paired with the literal refusalinvalid arguments for tracedecay_admin_sync: unknown fieldproject_root, there are no fields.On
origin/mastersource with only this test file added:With this change:
ok.Runtime journey
Setup: debug
tracedecaybuilt from this branch, isolated HOME/profile, and one daemon undersystemd-run --user --scope -p MemoryMax=6G -p MemorySwapMax=1G, stopped afterwards.Checks (local, on f3f7e04; merged with the 1.0.0-beta.58 version bump)
tracedecay-mcp387, daemon-protocol 65, daemon-service 322 (theadoption_observationcensus includes the newcapability.application.primitive.admin-sync), api 53.mcp_suitefiltered toinfo_health_request_test branch_search_test multi_mcp_coordination_test schema_test protocol_test admin_test: 53 passed.mcp:: daemon::: 736 passed, 1 failed. The failure isruntime_identity::concurrent_same_identity_worktrees_keep_exact_server_and_scheduler_bindings. It expects a JSON-RPC error for atracedecay_filesrefusal but gets theisErrorresult that fix(mcp): render parked refusals and graph-tool errors as typed fields #2340 introduced. That test does not reach admin sync.ignored_dependency_admission…expects a JSON-RPC error fromfind_exact_symbol(the fix(mcp): render parked refusals and graph-tool errors as typed fields #2340isErrorshape).status_wait_for_returns_reached…is a save/wait freshness assertion.core_cli_suite: 145 passed, 1 failed. The failure istool_diagnostics_reads_the_typescript_producer_publication, where the host TypeScript diagnostics producer is unavailable.cargo clippy -D warningsover tracedecay, mcp, contracts, daemon-protocol, api, mcp-catalog, tool-catalog, cli, and daemon-service,--all-targets, with and withouttracedecay/test-transport,test-helpers: clean.cargo fmt --all -- --check: clean.pnpm run contracts:generate, thencontracts:check: up to date. The dashboardEffectClassand the SDK are regenerated.