Repository navigation
feat: every agent runtime gets the work's MCP servers in the file it reads - #664
Merged
Merged
Conversation
…reads Gemini CLI, OpenCode, GitHub Copilot CLI and Cursor runs had their connections' credentials and notes but no tools, since only Claude Code reads .mcp.json. Each now gets the same servers in its own file and shape, established from the versions the agent image installs: Gemini's user settings.json in a GEMINI_CLI_HOME of the run's own, an OPENCODE_CONFIG file, Copilot's --additional-mcp-config @<file>, and Cursor's project .cursor/mcp.json with --approve-mcps. The per-run files live in one run home, /home/agent/optio/runs/<run id>, named after the task, Job run or agent turn and removed when the run's script exits and with the task's worktree; Codex's per-run CODEX_HOME moves there too (it was a random, never-removed directory). The setup-file writer merges a runtime's project config into the repo's own file and marks a tracked file it wrote over skip-worktree, so Optio's servers and their credentials can never be committed.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
Connections' tools and MCP servers reached only Claude Code (
.mcp.json) and Codex (config.toml). A Job on Gemini, a persistent agent on Copilot, or a Task on OpenCode or Cursor got the connections' credentials and notes but no tools. Each runtime now gets the same servers in the file it reads, established from the versions the agent image installs by reading their installed code and docs (sources inutils/harness-config.ts):<run home>/codex/config.toml([mcp_servers.*])CODEX_HOME(as before, now under the run home)<run home>/gemini/.gemini/settings.json— the adapter's settings +mcpServers, eachtrust: trueGEMINI_CLI_HOME<run home>/opencode/opencode.json—mcp: { name: { type: "local", command: [cmd, ...args], environment } }OPENCODE_CONFIG(merged after the global, before the project file)<run home>/copilot/mcp-config.json—type: "local",tools: ["*"]--additional-mcp-config @<file>.cursor/mcp.jsonin the working directory, merged into the repo's own--approve-mcpsOpenClaw manages MCP servers through its own
openclaw mcpconfig (mcp.servers); its entry schema and the launch Optio uses were not verified, so it is left out.The run home
Per-run files live in
/home/agent/optio/runs/<run id>(OPTIO_RUN_HOME), named after the task, Job run, or agent turn — a retry lands in the same place — and removed when the run's script exits (an EXIT trap in both exec scripts) and again with the task's worktree (repo-pool-service, repo-cleanup-worker). Codex's per-run home moves there too; it used to be a random directory that was never removed from the repo pod's home volume.Writer
WRITE_SETUP_FILESmerges amerge: "json"file into the JSON object already at its path (a repo's own.cursor/mcp.json) and marks a tracked file it wrote overskip-worktree, so an agent'sgit add -Acan never commit Optio's servers and their credentials. The image entrypoint maps/opt/optio/…into the agent's home like the exec scripts do. Connections can no longer setGEMINI_CLI_HOME,OPENCODE_CONFIG*,COPILOT_HOME,CURSOR_CONFIG_DIR.Tests
agent-environment-service.int.test.ts— each runtime's file and env from the real service; sensitive only when a server carries credentials; the untrusted pod's copy has none.harness-mcp.e2e.test.ts— a Cursor Job with a Pylon connection:.cursor/mcp.jsoncontent,--approve-mcps, the cleanup line in the script (new fake directives[[mock:file:*suffix]],[[mock:script:TEXT]]).Live
Rebuilt + redeployed the API on the local cluster. An OpenCode Job with an HTTP API connection pointed at a mock OpenAI server (host.docker.internal:4999): the model's tool list carried
Probe_API_describe/Probe_API_requestfrom the per-runopencode.json, the model calledProbe_API_request, the REST bridge reached the mock with the connection's Bearer token, and the result came back in the run's logs. After the run,/home/agent/optio/runs/on the Job pod was empty.