Skip to content

chore(specs): gardener checkbox sync - #1333

Draft
Dumbris wants to merge 11 commits into
mainfrom
claude/spec-gardener
Draft

Dumbris wants to merge 11 commits into
mainfrom
claude/spec-gardener

Conversation

@Dumbris

@Dumbris Dumbris commented Sep 21, 2026 •

Copy link
Copy Markdown
Member

40 ticks applied, 1 un-tick proposed (not applied), ~300 candidates examined and dropped as false alarms/unbuilt, run date 2026-09-28.

Scope of this run: scripts/check-spec-evidence.py flagged 264 possibly_built tick candidates and 74 currently-ticked tasks with unresolved evidence (67 UNRESOLVED + 7 REMOVED) across 77 specs, plus 36 RELOCATED informational findings. Every candidate was hand-verified against current code — 7 parallel review passes read the cited files, traced wiring, and (wherever runnable) re-ran the cited tests live — before any checkbox changed. Two specs (108-profiles-v3, 109-ux-navigation-consistency) were newly added to main since the last gardener run and account for the bulk of both the candidates and the applied ticks.

Cap note: verification produced 55 genuinely-earned ticks (1 in 006-oauth-extra-params, 11 in 108-profiles-v3, 43 in 109-ux-navigation-consistency), but the 40-tick cap means 15 verified 109-ux-navigation-consistency candidates were deferred rather than applied — see "Deferred (verified, not applied)" below. They do not need re-verification next run.

Applied ticks

Task file:line Decisive evidence
006-oauth-extra-params T045 cmd/mcpproxy/auth_cmd.go:680-699 (printDaemonOAuthLoginResult) Prints the full constructed authorization URL with all params visible (client_id/scope/redirect_uri/code_challenge/extra_params/resource); covered by cmd/mcpproxy/auth_cmd_test.go:272-315 (TestPrintDaemonOAuthLoginResult_*)
108-profiles-v3 T002 internal/server/profiles_v3_fixture_test.go:76-100 newProfilesV3Fixture builds a real proxy+runtime with the 3 fixture profiles/upstreams; non-stub
108-profiles-v3 T004 internal/config/profiles_v3_test.go 9 test funcs pass: legacy round-trip, v3 field parse, IsLegacy, switchable_to round-trip, FR-009 field-set reflection (default + -tags server), Effective* defaults
108-profiles-v3 T005 internal/profile/policy_test.go TestCompiledPolicy_Decide_EnforcementMatrix + 5 more pass (deny-beats-allow, allow-cannot-add-server, stale classification, EffectiveUnannotated/EffectiveCodeExecution defaults)
108-profiles-v3 T005a internal/profile/intrinsic_tier_contract_test.go TestIntrinsicTier_OneTierMappingAcrossSpecs, TestIntrinsicTier_OutOfRangeFailsClosed, TestNoSecondAnnotationMapping pass
108-profiles-v3 T006 internal/profile/glob_test.go TestGlobMatcher (17 subtests) + TestCanonicalIdentity pass
108-profiles-v3 T007 internal/profile/contract_test.go TestContractFixtures_Decode (6 fixtures) + TestCompiledPolicy_Fingerprint (14 subtests) pass
108-profiles-v3 T008 internal/server/profile_index_policy_test.go TestProfileIndex_CompiledPolicy (6 subtests) passes
108-profiles-v3 T010 internal/profile/policy.go Tier/CompiledPolicy/Compile/Decide/Fingerprint implemented, exercised by T005/T005a/T008
108-profiles-v3 T011 internal/profile/contract.go Enums implemented, decoded by T007's TestContractFixtures_Decode
108-profiles-v3 T014 frontend/src/types/contracts.ts:632-700 Profiles v3 enums present; go run ./cmd/generate-types regenerates byte-identical (verified, git status clean after)
108-profiles-v3 T036 internal/server/profile_resolver_v3.go:106 + profile_tool.go:682 ResolveProfileV3/selectable real, substantial, covered by T029/T033 tests; correctly staged (enforcement lands in 108-d per plan.md)
109-ux-navigation-consistency T006 frontend/tests/unit/router-home-default.spec.ts:11-13 Asserts / → dashboardView: 'overview', /usage → 'usage'. vitest: PASS
109-ux-navigation-consistency T007 frontend/tests/unit/z-index-scale.spec.ts:41-54 Stacking-order assertion + no :open-bound dialogs remain. vitest: PASS
109-ux-navigation-consistency T008 frontend/tests/unit/settings-naming.spec.ts:59-98 "Settings" naming, no emoji, Server Edition tab gated on edition==='server'. vitest: PASS
109-ux-navigation-consistency T009 frontend/tests/unit/server-detail-tab-url.spec.ts:97-163 Tab click → router.replace with ?tab=, other params kept. vitest: PASS
109-ux-navigation-consistency T010 frontend/tests/unit/tools-approval-filter.spec.ts:47-90 Exact approval values ['', 'approved', 'pending', 'changed'], /review resolves. vitest: PASS
109-ux-navigation-consistency T011 frontend/tests/unit/profile-switcher-hidden.spec.ts:54-59 ProfileSwitcher hidden when hasProfiles false. vitest: PASS
109-ux-navigation-consistency T013 frontend/tests/unit/usage-chart-ticks.spec.ts:29-56 Integer tick precision + "Calls to unknown tools" title. vitest: PASS
109-ux-navigation-consistency T014 internal/contracts/tier_test.go + internal/httpapi/tools_tier_test.go Every tools row carries tier (FR-028). go test: PASS
109-ux-navigation-consistency T015 cmd/mcpproxy/tools_tier_test.go:37-107 Pins the X11 --risk read regression + --tier/--risk/TIER column. go test: PASS
109-ux-navigation-consistency T016 frontend/tests/unit/tools-tier.spec.ts:42-58 "Tier" label; unannotated tool shows "Unannotated". vitest: PASS
109-ux-navigation-consistency T017 native/macos/MCPProxy/MCPProxyTests/ToolLabelsTests.swift:10-76 Real XCTest assertions against ToolLabels/ServerTool production types (not a stub; not executable in this Linux sandbox)
109-ux-navigation-consistency T018 frontend/src/router/index.ts:29,38 dashboardView: 'overview'/'usage' on / and /usage, verified live by T006
109-ux-navigation-consistency T022 frontend/src/views/Tools.vue:150-152 + cmd/mcpproxy/tools_cmd.go:48 Approval option labels + --approval pending help text
109-ux-navigation-consistency T023 internal/contracts/tier.go AnnotationTier + 5 exported constants, consumed by server.go/tools_cmd.go (confirmed by T014/T015)
109-ux-navigation-consistency T025 cmd/mcpproxy/registry_cmd.go:488-490 + frontend/src/components/CatalogSearch.vue:107,321 + native/.../CatalogView.swift:164,173,236 "Added ✓ · Open"/"Add to MCPProxy" labels (explicitly commented "Spec 109 FR-063") + CLI quarantine message; relocated from the deleted Repositories.vue/ServerBrowseView.swift — independently confirmed on all 3 surfaces before ticking
109-ux-navigation-consistency T026 frontend/tests/unit/review-interim-redirect.spec.ts:21-37 /review* redirects to real routes, never the 404 catch-all. vitest: PASS
109-ux-navigation-consistency T028 internal/connect/reload_hint_test.go Every ClientDef has ReloadHint/ClientInfoNames; DisplayPath collapses home to ~. go test: PASS (9 clients)
109-ux-navigation-consistency T030 internal/configimport/preview_summary_test.go:12-41 summary/tags per import-preview row. go test: PASS
109-ux-navigation-consistency T032 cmd/mcpproxy/connect_hint_test.go:40-48 Config: ~/… / Next: <hint>, --list CONFIG PATH column golden. go test: PASS
109-ux-navigation-consistency T034 internal/connect/clients.go:60-156 Per-client ReloadHint text, verified live by T028
109-ux-navigation-consistency T035 internal/httpapi/onboarding.go:82-87 + internal/storage/models.go:124 + bbolt.go:999 HasUsableServer/UsableServers/ClientConnectedAt/UpdateOnboardingState
109-ux-navigation-consistency T036 internal/httpapi/import.go:89-108 Summary/Tags/SecretLike DTO fields on preview response
109-ux-navigation-consistency T038 cmd/mcpproxy/connect_cmd.go:174 DisplayPath feeds the CONFIG PATH column, verified live by T032
109-ux-navigation-consistency T041 internal/health/status_test.go TestCalculateHealth_StatusVocabulary: 30/30 subtests PASS incl. RetryStopped/pending-auth/call-time-OAuth branches
109-ux-navigation-consistency T042 frontend/tests/unit/health-status-labels.spec.ts:160-201 SC-003 forbidden-word sweep over 7 usable=false fixtures. vitest: PASS
109-ux-navigation-consistency T043 cmd/mcpproxy/upstream_list_status_test.go STATUS/ACTION goldens, repeatable --status union filter. go test: PASS
109-ux-navigation-consistency T045 internal/server/upstream_servers_health_status_test.go:84 MCP upstream_servers list carries the new health fields. go test: PASS
109-ux-navigation-consistency T046 internal/health/constants.go:44-81 Status* constants + label maps, confirmed live by T041/T042

Deferred (verified valid, NOT applied — 40-tick cap only)

These 15 109-ux-navigation-consistency tasks passed the same verification (tests read and run, all passing) but exceeded this run's cap. They can be applied directly next run without re-verification: T047 (cmd/generate-types + contracts.ts HealthStatusValue/label maps), T097 (internal/registries/rank_test.go), T098 (internal/configimport/detect_url_command_test.go), T099 (internal/httpapi/catalog_test.go), T100 (cmd/mcpproxy/catalog_cmd_test.go), T101 (internal/server/search_servers_all_sources_test.go), T104 (internal/registries/catalog.go SearchAll/Rank), T105 (internal/secret/refname.go RefName), T107 (internal/server/mcp.go optional-registry search), T109a (internal/registries/catalog_bench_test.go), T114 (internal/httpapi/token_metrics_estimate_test.go), T115 (cmd/mcpproxy/activity_view_test.go), T116 (internal/httpapi/scope_filters_gate_test.go), T117 (frontend/src/composables/useScopeQuery.ts), T121 (internal/httpapi/scope_filters.go rejectUnsupportedScopeFilters).

Also deferred for the same reason, at the individual-task level rather than the cap: 109-ux-navigation-consistency T011a (scripts/test-api-e2e.sh cleanup-trap fix + test-api-e2e-cleanup-check.sh) — verified real (the blanket pkill lines are gone, replaced by identity-checked reap logic) but not executed end-to-end (requires a built binary + npx fixtures), so left for a run that can execute it, and to keep this run's total at exactly 40.

Proposed un-ticks (NOT applied)

Task Claim Why it looks false
102-schema-deferred T026 Regression test for R14 (a servers.changed published immediately after NewServer returns still reaches the direct rebuild) in internal/server/server_test.go That file doesn't exist. The production fix (T027) is real — internal/server/server.go:382-395 hoists SubscribeEvents() ahead of StartBackgroundInitialization() with an explicit R14 comment — but no test anywhere constructs a Server and races a servers.changed publish immediately after construction. The only R14-tagged test (mcp_direct_init_test.go, T024) asserts something different. Repeat finding: this exact candidate was already flagged (not applied) in the previous gardener PR #1333 and still hasn't been fixed.

Worth a human glance (not proposed as an un-tick)

107-server-edition-sso-hardening T101: the caller-kind-derivation half (GetConnectionSource, stdioAuthContext, CredentialKind) is real and tested (internal/server/audit_caller_test.go). But the task's second required file, a full surfaces × caller-kinds × situations combinatorial matrix test (~2,000 calls / 1,500-allow scale, named audit_dispatch_matrix_test.go), could not be found anywhere at that scale — audit_funnel_test.go covers similar situations but at 40-50x smaller scale. This looks similar to T026 above (user_token_cap_test.go) where a test was demonstrably added-then-deleted within the same PR — possibly the same pattern here. Not un-ticking because the security-relevant derivation logic is genuinely tested; flagging for a maintainer to confirm the large matrix test wasn't silently dropped during review.

Dropped by verification

Every other candidate the deterministic checker surfaced was examined and dropped. Grouped by why:

Tick candidates rejected — real code exists but the specific promised behavior (masking, a named test, a UI element, a doc section) does not, or is only partially built:

  • 006-oauth-extra-params (7 of 8 rejected): masking, redirect-URI display, last-refresh display, login preview/summary, post-success verification, example config snippets — all still missing from auth_cmd.go/doctor_cmd.go.
  • 007-oauth-e2e-testing (4 of 4): masking (same gap), provider-URL+grant_type logging, discovery-endpoint reachability check, auth-status-format tests — all absent.
  • 008-oauth-token-refresh (6 of 6): correlation-ID propagation was extended to exactly 2 functions (T024/T025, already ticked) but not to CreateOAuthConfig, handleCallback, discovery.go, persistent_token_store.go, connection_oauth.go's handleOAuthAuthorization, or managed/client.go — zero "correlation" matches in any of the 6.
  • 009-proactive-oauth-refresh (21 of 21): ServerCard.vue has Login/Logout buttons but none of the 9 tasks' specific UI (expiry badges, EXPIRED text, confirmation dialog on logout, FormatRelativeTime) exist; logout unit tests, --all flag, and 400/404 contract tests are all absent.
  • 001-oas-endpoint-documentation (6 of 6): zero swagger annotations/paths for secrets-refs, secrets-config, secrets-migrate, code/exec, and /events — doc-only task genuinely undone.
  • 003-tool-annotations-webui (3 of 3): no SessionsTable wired into Dashboard.vue, no sessionId param on getToolCalls, no session-lifecycle SSE events.
  • 004-management-health-refactor (9 of 9): no restart-related E2E test, no logHTTPRequest/redactToken/sanitizeAuthHeader functions, Docker log streaming is intentionally disabled (task wanted stderr-only streaming), no CLI→REST mapping doc table, no architecture diagram in plan.md.
  • 016-activity-log-backend (1 of 1): JSON-format activity export is tested, CSV format is not (task promises both).
  • 017-activity-cli-commands (8 of 8): no ID-format validation, no output-format assertions, no dedicated GetActivitySummary storage method, no export file-path validation test, plus 2 unverifiable "ran the gate" process claims.
  • 019-activity-webui (1 of 1): no ActivityWidget wired into Dashboard.vue.
  • 026-pii-detection (3 of 3): no PII-specific E2E test in e2e_test.go, no sensitive_data keyword in test-api-e2e.sh.
  • 058-mcp-2026-upgrade (all remaining ~36): Phase 3+ protocol-era-aware work (session statelessness, -32022, input_required detection, correlation propagation beyond T024/25) confirmed still entirely unbuilt; two real pre-existing bugs found in passing (T034/T076: the doc-comment claim about background session cleanup calling RemoveSession is false, the actual caller is a storage-layer method — flagged for whoever picks up this phase, not a checkbox issue).
  • 108-profiles-v3 (22 of 33 assigned): everything downstream of the foundational policy/contract layer — discovery/execution enforcement (SearchToolsAdmitted, PolicyFingerprint), client-credential wiring (CredentialMinter, mcp_cli_), session→server fan-out, activity attribution (block_reason, profile/client/token fields), REST/CLI/UI/macOS surfaces, and docs — confirmed absent. Consistent with the spec's 7/153 → 18/153 net progress this run.
  • 109-ux-navigation-consistency (8 of 51 assigned): the review-backend PR (Phase 7: previous_annotations, review-composer fields) and clients-hub (Clients.vue) are confirmed entirely unbuilt (T068, T079, T083, T084, T095, T133, T142, T149).
  • 001-update-version-display, 011-resource-auto-detect, 014-cli-output-formatting, 021-request-id-logging, 040-server-ux, 044-retention-telemetry-v3, 056-output-schema-validation, 057-in-proxy-profiles, 073-activity-size-retention, 028-agent-tokens, 029-mcpproxy-teams: same pattern — real underlying feature code with the specific test/doc/UI element the task names still missing (e.g. 040-server-ux T016-19: the whole AddServerView.swift Import flow was rewritten for the catalog-first refactor and never got the old preview/checkbox/NSOpenPanel UX; 028 T023: token list/create tested, revoke/regenerate/JSON-format are not).
  • A recurring category, same as last run: tasks whose only cited evidence is the repo-wide .github/.golangci.yml (076, 077 T041, 083, 096, 097, 098) or an unrecorded manual walkthrough (044-retention-telemetry-v3 T069, 077 T040) — treated as unverifiable process claims, left unticked.

Un-tick candidates dropped (all but 1) — ticked correctly, artifact just relocated/renamed/consolidated, or deliberately removed as a security fix, not missing:

  • The dominant pattern, same as last run: per-domain files consolidated into internal/contracts/types.go (001-oas T003/T005/T006/T007/T008, 004 T006-T011), internal/management/service.go (005 T013/T014/T015/T037), or renamed test files (016 T017/T026 → activity_handlers_test.go/sse_activity_test.go; 026-pii-detection's 24 findings → internal/security/entropy*.go, paths.go, cmd/mcpproxy/activity_cmd*.go, frontend/src/views/Activity.vue; 028-agent-tokens T011/T028/T034/T036 → mcp_auth_scope_test.go, mcp_activity_agent_test.go, api.ts, inlined into AgentTokens.vue; 040-server-ux T002 → patch_server_test.go; 044-retention-telemetry-v3's 6 findings, 058 T013, 102-schema-deferred T010/T067/T069, 047-cpu-hotpath-fix T012/T029, 074-discovery-intervals, 090-tray-glance-v2 T024/T032, 107-server-edition-sso-hardening T036/T047/T058/T101/T110, 009-proactive-oauth-refresh T005, 022-oauth-redirect-uri-persistence T007).
  • Deliberate, documented security-motivated deletions, not regressions: 107-server-edition-sso-hardening T015/T016 (removed an IdP-token-storage leak surface that was never wired to any consumer, per docs/features/idp-token-storage.md) and T026 (test consolidated into user_token_mutation_test.go within the same PR).
  • Genuine feature replacements, not regressions: 070-registry-easy-upstream-add T002/T016 (Repositories.vue deleted, replaced by CatalogSearch.vue in the catalog-first refactor — same data-test hooks, same behavior) and 029-mcpproxy-teams T009 (teams_register.go renamed to serveredition_register.go, same mechanism, feature alive under a new name — only the CI-wiring task T020 is genuinely still open).
  • 012-docusaurus-docs-site T021 (renamed .md→.mdx in the same commit that "deleted" it) and T067 (the cited path was a literal template example quoted from the task's own text, not a real file citation).

Notes

  • Verification was performed by 7 parallel code-reading passes (clustered by spec-domain: OAuth; contracts/activity/webui; 108-profiles-v3; 109-ux-navigation-consistency; PII/protocol-era/misc; SSO-hardening/scope-hardening/server-ux/tokens; remaining small specs), each independently applying the tick test (behavior over keyword-matching, real vs. stub/unwired, adversarial "argue the opposite" pass, re-running cited tests wherever the toolchain allowed) before ticking anything.
  • The orchestrating pass additionally independently re-verified one subagent's tick (109 T025) before accepting it, since its cited evidence covered only 1 of the task's 3 required surfaces (CLI) — confirmed the other two (Vue, macOS) hold at their relocated file paths before ticking.
  • The claude/spec-gardener branch's history had diverged unrelatedly from main (an old, pre-rewrite commit chain reachable only from this branch caused git rebase origin/main to fail catastrophically trying to replay repo-prehistory commits). Resolved with git merge origin/main instead of rebase — content-wise the branch was already cleanly mergeable (GitHub reported mergeable_state: clean), so a merge commit was the correct, non-destructive fix; no gardener-owned content was altered by it.
  • ROADMAP.md was regenerated (python3 scripts/gen-roadmap.py) in a separate commit after the checkbox commit, per the pre-commit hook requirement — 108-profiles-v3 moved from 7/153 (5%) to 18/153 (12%), 109-ux-navigation-consistency from 2/179 (1%) to 30/179 (17%), 006-oauth-extra-params from 43/65 (66%) to 44/65 (68%). ROADMAP.md and roadmap.yaml were not hand-edited.
  • Cap: 40 of 40 allowed applied ticks used this run (15 additional verified 109-ux-navigation-consistency candidates deferred, see above — safe to apply next run without re-verification).

@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Sep 21, 2026 •

Copy link
Copy Markdown

Deploying mcpproxy-docs with  Cloudflare Pages  Cloudflare Pages

Latest commit: 4542b0a
Status: ✅  Deploy successful!
Preview URL: https://060a3f4a.mcpproxy-docs.pages.dev
Branch Preview URL: https://claude-spec-gardener.mcpproxy-docs.pages.dev

View logs

@codecov-commenter

Copy link
Copy Markdown

⚠️ Please install the 'codecov app svg image' to ensure uploads and comments are reliably processed by Codecov.

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

@github-actions

github-actions Bot commented Sep 21, 2026 •

Copy link
Copy Markdown
Contributor

📦 Build Artifacts

Workflow Run: View Run
Branch: claude/spec-gardener

Available Artifacts

  • archive-darwin-amd64 (30 MB)
  • archive-darwin-arm64 (27 MB)
  • archive-linux-amd64 (18 MB)
  • archive-linux-arm64 (16 MB)
  • archive-windows-amd64 (30 MB)
  • archive-windows-arm64 (27 MB)
  • frontend-dist-pr (0 MB)
  • installer-dmg-darwin-amd64 (24 MB)
  • installer-dmg-darwin-arm64 (22 MB)
  • smart-mcp-proxymcpproxy-goURTD4P.dockerbuild (0 MB)

How to Download

Option 1: GitHub Web UI (easiest)

  1. Go to the workflow run page linked above
  2. Scroll to the bottom "Artifacts" section
  3. Click on the artifact you want to download

Option 2: GitHub CLI

gh run download 36454891166 --repo smart-mcp-proxy/mcpproxy-go

Note: Artifacts expire in 14 days.

Dumbris commented Sep 28, 2026

Copy link
Copy Markdown
Member Author

CI failure on this run: Build Binaries (macos-15, darwin, arm64) — the "Run tests (skip binary E2E tests...)" step failed (exit code 1) after a git merge origin/main fast-forwarded this branch's diff base.

This is not this PR's failure: the PR's only diff is two markdown files (specs/105-agent-scope-hardening/tasks.md checkbox flips + a regenerated ROADMAP.md), which cannot affect Go test behavior on any platform. The equivalent Linux and Windows "Build Binaries" jobs on this same commit passed, and every other recent PR Build run against current main succeeded, so this isn't a pre-existing base-branch break either. I couldn't pull the specific failing test name from the job log (the log-retrieval tool truncates before reaching the earlier failure in a ~7-minute, very verbose go test ./... run), but given the diff shape this is most consistent with a flaky/platform-specific test on the macOS arm64 runner.

Re-running the failed jobs once to confirm.


Generated by Claude Code


Generated by Claude Code

Dumbris commented Sep 28, 2026

Copy link
Copy Markdown
Member Author

Re-run attempt failed: rerun-failed-jobs returned 403 (resource not accessible by this integration) — I don't have permission to re-run CI jobs on this repo. Since the failing test is unrelated to this PR's markdown-only diff, there's no in-scope fix to push. Keeping this PR watched; will re-check on the next scheduled check-in and act on anything that changes (a maintainer re-run, a new push, or a genuine regression surfacing elsewhere).


Generated by Claude Code


Generated by Claude Code

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants