ADVERSARIAL_API_ONLY setup omits MCP scoped passwords #654

Open
opened 2026-10-02 03:10:14 +00:00 by kayg · 4 comments
Owner

Run ADVERSARIAL_API_ONLY=1 ADVERSARIAL_SKIP_WEB_BUILD=1 tests/adversarial/run.sh. The API-only branch invokes mcp_probe.py, but setup.mjs writes mcp-passwords.json only when ADVERSARIAL_MCP_ONLY=1 or XUSER_MATRIX_WITH_MCP=1. In the API-only run, mcp_probe.py exits with FileNotFoundError for target/tmp/adversarial.*/mcp-passwords.json; the sidecar and API probes continue. Make the setup selection and API-only probe list agree. No expectations were changed.

Run `ADVERSARIAL_API_ONLY=1 ADVERSARIAL_SKIP_WEB_BUILD=1 tests/adversarial/run.sh`. The API-only branch invokes `mcp_probe.py`, but `setup.mjs` writes `mcp-passwords.json` only when `ADVERSARIAL_MCP_ONLY=1` or `XUSER_MATRIX_WITH_MCP=1`. In the API-only run, `mcp_probe.py` exits with `FileNotFoundError` for `target/tmp/adversarial.*/mcp-passwords.json`; the sidecar and API probes continue. Make the setup selection and API-only probe list agree. No expectations were changed.
Author
Owner

Starting #654 on branch job/advsetup-654, based on c4a61e8cf090170f35b1bed3350d9de20c83ecd5 (the current origin/dev SHA). The API-only branch runs mcp_probe.py, while setup.mjs provisions mcp-passwords.json only for MCP-only and xuser-with-MCP runs. I will extend the existing setup selection and verify the API-only run against its real local server.

Starting #654 on branch `job/advsetup-654`, based on `c4a61e8cf090170f35b1bed3350d9de20c83ecd5` (the current `origin/dev` SHA). The API-only branch runs `mcp_probe.py`, while `setup.mjs` provisions `mcp-passwords.json` only for MCP-only and xuser-with-MCP runs. I will extend the existing setup selection and verify the API-only run against its real local server.
Author
Owner

The requested runner currently stops before server startup in prepare-media-runtime.sh: too many local threads for the bounded media sandbox test: 5565. The standalone authz classification passes when rerun, so this is the shared-host thread cap, not an MCP result. I am continuing with the same setup.mjs and mcp_probe.py against a fresh local server, while preserving the full-run failure output for the report.

The requested runner currently stops before server startup in `prepare-media-runtime.sh`: `too many local threads for the bounded media sandbox test: 5565`. The standalone authz classification passes when rerun, so this is the shared-host thread cap, not an MCP result. I am continuing with the same `setup.mjs` and `mcp_probe.py` against a fresh local server, while preserving the full-run failure output for the report.
Author
Owner

Finished the harness change on job/advsetup-654 at 9d7c689e37fc135eace6e28ef469cae48752fa7a.

Change

tests/adversarial/setup.mjs now creates the existing MCP read, MCP full and API-only scoped App Password fixtures when ADVERSARIAL_API_ONLY=1. The existing credential code is reused. No test expectation or server behavior changed.

Verification

node --check tests/adversarial/setup.mjs exited 0 with no output. git diff --check HEAD^ HEAD exited 0 with no output.

The requested full runner stopped before server startup because the shared-host media sandbox preflight detected too many local threads. Its output was:

Cross-User classification gate: 335 operations classified
Generated entry point classification: 945 tools classified
Admin coverage: 39 reviewed operations; contract and Rust guards agree
too many local threads for the bounded media sandbox test: 5565

I then ran the existing setup.mjs and mcp_probe.py against a fresh local server. Setup created mcp-passwords.json, and the probe read it and reached MCP Inspector. The probe exited 1 because its existing expected list differs by one tool: listed=290 expected=289 extra=1 missing=0; the sole extra name is calternal_calendar. I did not change the expectation, as required. The server binary came from a worktree merged at the same origin/dev base; its extra changes were UI files only.

Cleanup

cargo clean output:

Removed 6231 files, 3.0GiB total

I removed apps/web/build and the temporary #654 logs and runner script. The branch is clean and one commit ahead of origin/dev. The requested MCP probe pass remains blocked by the host preflight and the one-tool MCP list mismatch above.

Finished the harness change on `job/advsetup-654` at `9d7c689e37fc135eace6e28ef469cae48752fa7a`. ## Change `tests/adversarial/setup.mjs` now creates the existing MCP read, MCP full and API-only scoped App Password fixtures when `ADVERSARIAL_API_ONLY=1`. The existing credential code is reused. No test expectation or server behavior changed. ## Verification `node --check tests/adversarial/setup.mjs` exited 0 with no output. `git diff --check HEAD^ HEAD` exited 0 with no output. The requested full runner stopped before server startup because the shared-host media sandbox preflight detected too many local threads. Its output was: ```text Cross-User classification gate: 335 operations classified Generated entry point classification: 945 tools classified Admin coverage: 39 reviewed operations; contract and Rust guards agree too many local threads for the bounded media sandbox test: 5565 ``` I then ran the existing `setup.mjs` and `mcp_probe.py` against a fresh local server. Setup created `mcp-passwords.json`, and the probe read it and reached MCP Inspector. The probe exited 1 because its existing expected list differs by one tool: `listed=290 expected=289 extra=1 missing=0`; the sole extra name is `calternal_calendar`. I did not change the expectation, as required. The server binary came from a worktree merged at the same `origin/dev` base; its extra changes were UI files only. ## Cleanup `cargo clean` output: ```text Removed 6231 files, 3.0GiB total ``` I removed `apps/web/build` and the temporary #654 logs and runner script. The branch is clean and one commit ahead of `origin/dev`. The requested MCP probe pass remains blocked by the host preflight and the one-tool MCP list mismatch above.
Author
Owner

Independent LIGHT review for #664: reviewed job/advfind-664 at 884cc8ba6e1d275d14844187ed16e65f4b20a354. The #654 fix is absent from this tree: tests/adversarial/setup.mjs:103 selects MCP-only or XUser-with-MCP, while tests/adversarial/run.sh:377–384 invokes mcp_probe.py for API-only. mcp_probe.py:28 reads the scoped password file before making requests. The merge round must include the reported #654 fix at 9d7c689e37fc135eace6e28ef469cae48752fa7a before it claims API-only MCP coverage. No build, test, or server ran in this review; no duplicate issue was filed.

Independent LIGHT review for #664: reviewed `job/advfind-664` at `884cc8ba6e1d275d14844187ed16e65f4b20a354`. The #654 fix is absent from this tree: `tests/adversarial/setup.mjs:103` selects MCP-only or XUser-with-MCP, while `tests/adversarial/run.sh:377–384` invokes mcp_probe.py for API-only. `mcp_probe.py:28` reads the scoped password file before making requests. The merge round must include the reported #654 fix at `9d7c689e37fc135eace6e28ef469cae48752fa7a` before it claims API-only MCP coverage. No build, test, or server ran in this review; no duplicate issue was filed.
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
kayg/calternal#654
No description provided.