Skip to content

fix(mcp): keep companion capability token out of process args - #827

Open
dawNotPoi wants to merge 3 commits into
xintaofei:mainfrom
dawNotPoi:fix/mcp-capability-token-env
Open

dawNotPoi wants to merge 3 commits into
xintaofei:mainfrom
dawNotPoi:fix/mcp-capability-token-env

Conversation

@dawNotPoi

@dawNotPoi dawNotPoi commented Sep 24, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Pass the per-launch codeg-mcp broker capability token through the companion's dedicated ACP stdio server environment instead of its process arguments.
  • Require a nonempty CODEG_MCP_TOKEN in the companion; reject the old --token argument. Keep token registration, broker validation, revocation, feature flags, and other startup arguments intact.
  • Cover the injected MCP configuration and companion parsing with regression tests.

Fixes #156. The exposed value is CodeG's per-launch broker capability token, not a model provider API key.

Verification

  • cargo test --no-default-features --lib injected_companion_keeps_capability_token_out_of_process_args --config profile.test.package.codeg.debug=0 — passed (1 test).
  • cargo test --no-default-features --bin codeg-mcp capability_token_must_come_from_nonempty_environment --config profile.test.package.codeg.debug=0 — passed (1 test).
  • cargo clippy --no-default-features --bin codeg-mcp -- -D warnings — passed.
  • Built the Linux codeg-mcp binary and launched it as a real subprocess: MCP initialize succeeded, the synthetic token was absent from ps and /proc/<pid>/cmdline, and it was present in the child environment. Unset and empty token values exited with code 2.
  • Checked the pinned Claude ACP v0.81.1 and Codex ACP v1.1.8 adapter sources: both forward a stdio MCP server's per-server env into the MCP configuration.

Scope and limits

This removes the token from ordinary process listings on Linux. It does not prevent a process with the same user identity from reading the companion's environment. Token authentication remains necessary for the broker, including the Windows named-pipe path. The main program and codeg-mcp companion must be upgraded together; a CODEG_MCP_BIN override must point to the matching version because older companions require --token. I did not run a full CodeG-to-Claude live session or Windows end-to-end test from this WSL checkout.

@dawNotPoi
dawNotPoi marked this pull request as ready for review September 24, 2026 04:52
@dawNotPoi

Copy link
Copy Markdown
Contributor Author

@xintaofei Ready for review: this removes the per-launch CodeG MCP broker capability token from process arguments and passes it through CODEG_MCP_TOKEN in the companion environment. A Linux subprocess check confirmed that the token is absent from ps and /proc/PID/cmdline; all seven CI checks passed. The change does not protect against same-user environment inspection, and the main app and companion must be upgraded together. Would appreciate your review.

@dawNotPoi
dawNotPoi force-pushed the fix/mcp-capability-token-env branch from 644e847 to 822025b Compare September 28, 2026 07:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

关于codeg进程会暴露mcp的api-key

1 participant