Conversation
Deploying mcpproxy-docs with
|
| Latest commit: |
4542b0a
|
| Status: | ✅ Deploy successful! |
| Preview URL: | https://060a3f4a.mcpproxy-docs.pages.dev |
| Branch Preview URL: | https://claude-spec-gardener.mcpproxy-docs.pages.dev |
|
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
📦 Build ArtifactsWorkflow Run: View Run Available Artifacts
How to DownloadOption 1: GitHub Web UI (easiest)
Option 2: GitHub CLI gh run download 36454891166 --repo smart-mcp-proxy/mcpproxy-go
|
# Conflicts: # ROADMAP.md
# Conflicts: # ROADMAP.md
|
CI failure on this run: Build Binaries (macos-15, darwin, arm64) — the "Run tests (skip binary E2E tests...)" step failed (exit code 1) after a This is not this PR's failure: the PR's only diff is two markdown files ( Re-running the failed jobs once to confirm. Generated by Claude Code Generated by Claude Code |
|
Re-run attempt failed: Generated by Claude Code Generated by Claude Code |
# Conflicts: # ROADMAP.md # specs/108-profiles-v3/tasks.md
# Conflicts: # ROADMAP.md
# Conflicts: # ROADMAP.md
# Conflicts: # ROADMAP.md
40 ticks applied, 1 un-tick proposed (not applied), ~300 candidates examined and dropped as false alarms/unbuilt, run date 2026-09-28.
Scope of this run:
scripts/check-spec-evidence.pyflagged 264possibly_builttick candidates and 74 currently-ticked tasks with unresolved evidence (67UNRESOLVED+ 7REMOVED) across 77 specs, plus 36RELOCATEDinformational findings. Every candidate was hand-verified against current code — 7 parallel review passes read the cited files, traced wiring, and (wherever runnable) re-ran the cited tests live — before any checkbox changed. Two specs (108-profiles-v3,109-ux-navigation-consistency) were newly added tomainsince the last gardener run and account for the bulk of both the candidates and the applied ticks.Cap note: verification produced 55 genuinely-earned ticks (1 in
006-oauth-extra-params, 11 in108-profiles-v3, 43 in109-ux-navigation-consistency), but the 40-tick cap means 15 verified109-ux-navigation-consistencycandidates were deferred rather than applied — see "Deferred (verified, not applied)" below. They do not need re-verification next run.Applied ticks
006-oauth-extra-paramsT045cmd/mcpproxy/auth_cmd.go:680-699(printDaemonOAuthLoginResult)cmd/mcpproxy/auth_cmd_test.go:272-315(TestPrintDaemonOAuthLoginResult_*)108-profiles-v3T002internal/server/profiles_v3_fixture_test.go:76-100newProfilesV3Fixturebuilds a real proxy+runtime with the 3 fixture profiles/upstreams; non-stub108-profiles-v3T004internal/config/profiles_v3_test.goIsLegacy,switchable_toround-trip, FR-009 field-set reflection (default +-tags server),Effective*defaults108-profiles-v3T005internal/profile/policy_test.goTestCompiledPolicy_Decide_EnforcementMatrix+ 5 more pass (deny-beats-allow, allow-cannot-add-server, stale classification,EffectiveUnannotated/EffectiveCodeExecutiondefaults)108-profiles-v3T005ainternal/profile/intrinsic_tier_contract_test.goTestIntrinsicTier_OneTierMappingAcrossSpecs,TestIntrinsicTier_OutOfRangeFailsClosed,TestNoSecondAnnotationMappingpass108-profiles-v3T006internal/profile/glob_test.goTestGlobMatcher(17 subtests) +TestCanonicalIdentitypass108-profiles-v3T007internal/profile/contract_test.goTestContractFixtures_Decode(6 fixtures) +TestCompiledPolicy_Fingerprint(14 subtests) pass108-profiles-v3T008internal/server/profile_index_policy_test.goTestProfileIndex_CompiledPolicy(6 subtests) passes108-profiles-v3T010internal/profile/policy.goTier/CompiledPolicy/Compile/Decide/Fingerprintimplemented, exercised by T005/T005a/T008108-profiles-v3T011internal/profile/contract.goTestContractFixtures_Decode108-profiles-v3T014frontend/src/types/contracts.ts:632-700go run ./cmd/generate-typesregenerates byte-identical (verified,git statusclean after)108-profiles-v3T036internal/server/profile_resolver_v3.go:106+profile_tool.go:682ResolveProfileV3/selectablereal, substantial, covered by T029/T033 tests; correctly staged (enforcement lands in 108-d per plan.md)109-ux-navigation-consistencyT006frontend/tests/unit/router-home-default.spec.ts:11-13/→dashboardView: 'overview',/usage→'usage'. vitest: PASS109-ux-navigation-consistencyT007frontend/tests/unit/z-index-scale.spec.ts:41-54:open-bound dialogs remain. vitest: PASS109-ux-navigation-consistencyT008frontend/tests/unit/settings-naming.spec.ts:59-98edition==='server'. vitest: PASS109-ux-navigation-consistencyT009frontend/tests/unit/server-detail-tab-url.spec.ts:97-163router.replacewith?tab=, other params kept. vitest: PASS109-ux-navigation-consistencyT010frontend/tests/unit/tools-approval-filter.spec.ts:47-90['', 'approved', 'pending', 'changed'],/reviewresolves. vitest: PASS109-ux-navigation-consistencyT011frontend/tests/unit/profile-switcher-hidden.spec.ts:54-59hasProfilesfalse. vitest: PASS109-ux-navigation-consistencyT013frontend/tests/unit/usage-chart-ticks.spec.ts:29-56109-ux-navigation-consistencyT014internal/contracts/tier_test.go+internal/httpapi/tools_tier_test.gotier(FR-028).go test: PASS109-ux-navigation-consistencyT015cmd/mcpproxy/tools_tier_test.go:37-107--risk readregression +--tier/--risk/TIER column.go test: PASS109-ux-navigation-consistencyT016frontend/tests/unit/tools-tier.spec.ts:42-58109-ux-navigation-consistencyT017native/macos/MCPProxy/MCPProxyTests/ToolLabelsTests.swift:10-76ToolLabels/ServerToolproduction types (not a stub; not executable in this Linux sandbox)109-ux-navigation-consistencyT018frontend/src/router/index.ts:29,38dashboardView: 'overview'/'usage'on/and/usage, verified live by T006109-ux-navigation-consistencyT022frontend/src/views/Tools.vue:150-152+cmd/mcpproxy/tools_cmd.go:48--approval pendinghelp text109-ux-navigation-consistencyT023internal/contracts/tier.goAnnotationTier+ 5 exported constants, consumed byserver.go/tools_cmd.go(confirmed by T014/T015)109-ux-navigation-consistencyT025cmd/mcpproxy/registry_cmd.go:488-490+frontend/src/components/CatalogSearch.vue:107,321+native/.../CatalogView.swift:164,173,236Repositories.vue/ServerBrowseView.swift— independently confirmed on all 3 surfaces before ticking109-ux-navigation-consistencyT026frontend/tests/unit/review-interim-redirect.spec.ts:21-37/review*redirects to real routes, never the 404 catch-all. vitest: PASS109-ux-navigation-consistencyT028internal/connect/reload_hint_test.goClientDefhasReloadHint/ClientInfoNames;DisplayPathcollapses home to~.go test: PASS (9 clients)109-ux-navigation-consistencyT030internal/configimport/preview_summary_test.go:12-41summary/tagsper import-preview row.go test: PASS109-ux-navigation-consistencyT032cmd/mcpproxy/connect_hint_test.go:40-48Config: ~/…/Next: <hint>,--listCONFIG PATH column golden.go test: PASS109-ux-navigation-consistencyT034internal/connect/clients.go:60-156ReloadHinttext, verified live by T028109-ux-navigation-consistencyT035internal/httpapi/onboarding.go:82-87+internal/storage/models.go:124+bbolt.go:999HasUsableServer/UsableServers/ClientConnectedAt/UpdateOnboardingState109-ux-navigation-consistencyT036internal/httpapi/import.go:89-108Summary/Tags/SecretLikeDTO fields on preview response109-ux-navigation-consistencyT038cmd/mcpproxy/connect_cmd.go:174DisplayPathfeeds the CONFIG PATH column, verified live by T032109-ux-navigation-consistencyT041internal/health/status_test.goTestCalculateHealth_StatusVocabulary: 30/30 subtests PASS incl.RetryStopped/pending-auth/call-time-OAuth branches109-ux-navigation-consistencyT042frontend/tests/unit/health-status-labels.spec.ts:160-201usable=falsefixtures. vitest: PASS109-ux-navigation-consistencyT043cmd/mcpproxy/upstream_list_status_test.go--statusunion filter.go test: PASS109-ux-navigation-consistencyT045internal/server/upstream_servers_health_status_test.go:84upstream_servers listcarries the new health fields.go test: PASS109-ux-navigation-consistencyT046internal/health/constants.go:44-81Status*constants + label maps, confirmed live by T041/T042Deferred (verified valid, NOT applied — 40-tick cap only)
These 15
109-ux-navigation-consistencytasks passed the same verification (tests read and run, all passing) but exceeded this run's cap. They can be applied directly next run without re-verification: T047 (cmd/generate-types+contracts.tsHealthStatusValue/label maps), T097 (internal/registries/rank_test.go), T098 (internal/configimport/detect_url_command_test.go), T099 (internal/httpapi/catalog_test.go), T100 (cmd/mcpproxy/catalog_cmd_test.go), T101 (internal/server/search_servers_all_sources_test.go), T104 (internal/registries/catalog.goSearchAll/Rank), T105 (internal/secret/refname.goRefName), T107 (internal/server/mcp.gooptional-registry search), T109a (internal/registries/catalog_bench_test.go), T114 (internal/httpapi/token_metrics_estimate_test.go), T115 (cmd/mcpproxy/activity_view_test.go), T116 (internal/httpapi/scope_filters_gate_test.go), T117 (frontend/src/composables/useScopeQuery.ts), T121 (internal/httpapi/scope_filters.gorejectUnsupportedScopeFilters).Also deferred for the same reason, at the individual-task level rather than the cap:
109-ux-navigation-consistencyT011a (scripts/test-api-e2e.shcleanup-trap fix +test-api-e2e-cleanup-check.sh) — verified real (the blanketpkilllines are gone, replaced by identity-checked reap logic) but not executed end-to-end (requires a built binary + npx fixtures), so left for a run that can execute it, and to keep this run's total at exactly 40.Proposed un-ticks (NOT applied)
102-schema-deferredT026servers.changedpublished immediately afterNewServerreturns still reaches the direct rebuild) ininternal/server/server_test.gointernal/server/server.go:382-395hoistsSubscribeEvents()ahead ofStartBackgroundInitialization()with an explicit R14 comment — but no test anywhere constructs aServerand races aservers.changedpublish immediately after construction. The only R14-tagged test (mcp_direct_init_test.go, T024) asserts something different. Repeat finding: this exact candidate was already flagged (not applied) in the previous gardener PR #1333 and still hasn't been fixed.Worth a human glance (not proposed as an un-tick)
107-server-edition-sso-hardeningT101: the caller-kind-derivation half (GetConnectionSource,stdioAuthContext,CredentialKind) is real and tested (internal/server/audit_caller_test.go). But the task's second required file, a full surfaces × caller-kinds × situations combinatorial matrix test (~2,000 calls / 1,500-allow scale, namedaudit_dispatch_matrix_test.go), could not be found anywhere at that scale —audit_funnel_test.gocovers similar situations but at 40-50x smaller scale. This looks similar to T026 above (user_token_cap_test.go) where a test was demonstrably added-then-deleted within the same PR — possibly the same pattern here. Not un-ticking because the security-relevant derivation logic is genuinely tested; flagging for a maintainer to confirm the large matrix test wasn't silently dropped during review.Dropped by verification
Every other candidate the deterministic checker surfaced was examined and dropped. Grouped by why:
Tick candidates rejected — real code exists but the specific promised behavior (masking, a named test, a UI element, a doc section) does not, or is only partially built:
006-oauth-extra-params(7 of 8 rejected): masking, redirect-URI display, last-refresh display, login preview/summary, post-success verification, example config snippets — all still missing fromauth_cmd.go/doctor_cmd.go.007-oauth-e2e-testing(4 of 4): masking (same gap), provider-URL+grant_type logging, discovery-endpoint reachability check, auth-status-format tests — all absent.008-oauth-token-refresh(6 of 6): correlation-ID propagation was extended to exactly 2 functions (T024/T025, already ticked) but not toCreateOAuthConfig,handleCallback,discovery.go,persistent_token_store.go,connection_oauth.go'shandleOAuthAuthorization, ormanaged/client.go— zero "correlation" matches in any of the 6.009-proactive-oauth-refresh(21 of 21):ServerCard.vuehas Login/Logout buttons but none of the 9 tasks' specific UI (expiry badges, EXPIRED text, confirmation dialog on logout,FormatRelativeTime) exist; logout unit tests,--allflag, and 400/404 contract tests are all absent.001-oas-endpoint-documentation(6 of 6): zero swagger annotations/paths for secrets-refs, secrets-config, secrets-migrate, code/exec, and/events— doc-only task genuinely undone.003-tool-annotations-webui(3 of 3): noSessionsTablewired intoDashboard.vue, nosessionIdparam ongetToolCalls, no session-lifecycle SSE events.004-management-health-refactor(9 of 9): norestart-related E2E test, nologHTTPRequest/redactToken/sanitizeAuthHeaderfunctions, Docker log streaming is intentionally disabled (task wanted stderr-only streaming), no CLI→REST mapping doc table, no architecture diagram in plan.md.016-activity-log-backend(1 of 1): JSON-format activity export is tested, CSV format is not (task promises both).017-activity-cli-commands(8 of 8): no ID-format validation, no output-format assertions, no dedicatedGetActivitySummarystorage method, no export file-path validation test, plus 2 unverifiable "ran the gate" process claims.019-activity-webui(1 of 1): noActivityWidgetwired intoDashboard.vue.026-pii-detection(3 of 3): no PII-specific E2E test ine2e_test.go, nosensitive_datakeyword intest-api-e2e.sh.058-mcp-2026-upgrade(all remaining ~36): Phase 3+ protocol-era-aware work (session statelessness,-32022,input_requireddetection, correlation propagation beyond T024/25) confirmed still entirely unbuilt; two real pre-existing bugs found in passing (T034/T076: the doc-comment claim about background session cleanup callingRemoveSessionis false, the actual caller is a storage-layer method — flagged for whoever picks up this phase, not a checkbox issue).108-profiles-v3(22 of 33 assigned): everything downstream of the foundational policy/contract layer — discovery/execution enforcement (SearchToolsAdmitted,PolicyFingerprint), client-credential wiring (CredentialMinter,mcp_cli_), session→server fan-out, activity attribution (block_reason, profile/client/token fields), REST/CLI/UI/macOS surfaces, and docs — confirmed absent. Consistent with the spec's 7/153 → 18/153 net progress this run.109-ux-navigation-consistency(8 of 51 assigned): the review-backend PR (Phase 7:previous_annotations, review-composer fields) and clients-hub (Clients.vue) are confirmed entirely unbuilt (T068, T079, T083, T084, T095, T133, T142, T149).001-update-version-display,011-resource-auto-detect,014-cli-output-formatting,021-request-id-logging,040-server-ux,044-retention-telemetry-v3,056-output-schema-validation,057-in-proxy-profiles,073-activity-size-retention,028-agent-tokens,029-mcpproxy-teams: same pattern — real underlying feature code with the specific test/doc/UI element the task names still missing (e.g.040-server-uxT016-19: the wholeAddServerView.swiftImport flow was rewritten for the catalog-first refactor and never got the old preview/checkbox/NSOpenPanel UX;028T023: token list/create tested, revoke/regenerate/JSON-format are not)..github/.golangci.yml(076,077T041,083,096,097,098) or an unrecorded manual walkthrough (044-retention-telemetry-v3T069,077T040) — treated as unverifiable process claims, left unticked.Un-tick candidates dropped (all but 1) — ticked correctly, artifact just relocated/renamed/consolidated, or deliberately removed as a security fix, not missing:
internal/contracts/types.go(001-oasT003/T005/T006/T007/T008,004T006-T011),internal/management/service.go(005T013/T014/T015/T037), or renamed test files (016T017/T026 →activity_handlers_test.go/sse_activity_test.go;026-pii-detection's 24 findings →internal/security/entropy*.go,paths.go,cmd/mcpproxy/activity_cmd*.go,frontend/src/views/Activity.vue;028-agent-tokensT011/T028/T034/T036 →mcp_auth_scope_test.go,mcp_activity_agent_test.go,api.ts, inlined intoAgentTokens.vue;040-server-uxT002 →patch_server_test.go;044-retention-telemetry-v3's 6 findings,058T013,102-schema-deferredT010/T067/T069,047-cpu-hotpath-fixT012/T029,074-discovery-intervals,090-tray-glance-v2T024/T032,107-server-edition-sso-hardeningT036/T047/T058/T101/T110,009-proactive-oauth-refreshT005,022-oauth-redirect-uri-persistenceT007).107-server-edition-sso-hardeningT015/T016 (removed an IdP-token-storage leak surface that was never wired to any consumer, perdocs/features/idp-token-storage.md) and T026 (test consolidated intouser_token_mutation_test.gowithin the same PR).070-registry-easy-upstream-addT002/T016 (Repositories.vuedeleted, replaced byCatalogSearch.vuein the catalog-first refactor — samedata-testhooks, same behavior) and029-mcpproxy-teamsT009 (teams_register.gorenamed toserveredition_register.go, same mechanism, feature alive under a new name — only the CI-wiring task T020 is genuinely still open).012-docusaurus-docs-siteT021 (renamed.md→.mdxin the same commit that "deleted" it) and T067 (the cited path was a literal template example quoted from the task's own text, not a real file citation).Notes
109T025) before accepting it, since its cited evidence covered only 1 of the task's 3 required surfaces (CLI) — confirmed the other two (Vue, macOS) hold at their relocated file paths before ticking.claude/spec-gardenerbranch's history had diverged unrelatedly frommain(an old, pre-rewrite commit chain reachable only from this branch causedgit rebase origin/mainto fail catastrophically trying to replay repo-prehistory commits). Resolved withgit merge origin/maininstead of rebase — content-wise the branch was already cleanly mergeable (GitHub reportedmergeable_state: clean), so a merge commit was the correct, non-destructive fix; no gardener-owned content was altered by it.python3 scripts/gen-roadmap.py) in a separate commit after the checkbox commit, per the pre-commit hook requirement —108-profiles-v3moved from 7/153 (5%) to 18/153 (12%),109-ux-navigation-consistencyfrom 2/179 (1%) to 30/179 (17%),006-oauth-extra-paramsfrom 43/65 (66%) to 44/65 (68%). ROADMAP.md and roadmap.yaml were not hand-edited.109-ux-navigation-consistencycandidates deferred, see above — safe to apply next run without re-verification).