Support public environment-origin MCP through shared Harness bindings - #251
Merged
Merged
Conversation
…ings-20260930 # Conflicts: # apps/docs/content/guide-sources.json
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Change
Public HTTP MCP with explicit connection_origin=environment now reaches the existing Runtime bindings and native Harness adapters in managed and self-hosted workspaces. Previously the public entrypoint rejected this origin even though installed Plugin MCP already used that execution path.
Core validates each Harness's declared MCP origins and keeps frozen Project/Vault credential selection. Codex and Claude preserve null/empty/named allowlists and required initialization. MiniMax accepts null/omitted allowlists and required=false, rejecting unsupported policies. Native observations include public MiniMax calls, tool errors and cancellation. Credentials remain transient.
Service-origin stays on service execution hosts with environment:none. There is no network proxy, model-loop fallback, new framework or compatibility layer. The private Runtime wire is 0.10.0 and requires an exact match.
Validation
Qualification evidence records revisions, Sessions, test conditions and limits. One blind-review documentation finding was corrected in the authored guides and regenerated; the second review covers the complete 70-file diff.
Local make check was run: an initial database naming error was corrected; the later run passed Go/database/adapter checks but encountered an occupied browser fixture port. A separate browser run passed 83/86 with three UI timeouts/assertion failures on the shared host. These runs are not reported as full passes; the subsequent clean final-head CI full gate passed. No tests were removed or weakened.
Limits
Real macOS/Windows model runs and E2B/microsandbox are not qualified here; native CI is separate from live model evidence. Public stdio, literal headers/metadata, service-origin workspace forwarding, public functions and Subagent/MCP combinations remain outside scope. MiniMax allowlists and required initialization remain explicitly unsupported.
Only isolated acceptance infrastructure was changed; histories and data are retained. No production deployment, tag or Release.
Final-head CI: make check, official client, native platforms.