Skip to content

feat: lock complete tool annotations and output schemas (v4) - #110

Merged
ernestprovo23 merged 8 commits into
mainfrom
codex/dse1539-tool-integrity
Oct 2, 2026
Merged

ernestprovo23 merged 8 commits into
mainfrom
codex/dse1539-tool-integrity

Conversation

@ernestprovo23

@ernestprovo23 ernestprovo23 commented Oct 2, 2026 •

Copy link
Copy Markdown
Member

What & why

MCP tool annotations and output schemas could change without invalidating an approved lock. This adds schema level 4 commitments to their complete objects, so a hint flip, schema removal, or output constraint relaxation triggers drift. Python and TypeScript share 111 conformance vectors, and the existing notification-triggered runtime tools/list gate compares the new fields for v4 locks.

DSE-1539. Existing v1–v3 locks remain readable and self-consistent; a v4 re-pin requires review rather than silently inheriting approval. SDK capture validates each tool while preserving raw fields that SDK models would discard, including extensions and explicit nested nulls. Annotation hints never grant authority; raw annotations are excluded from reports.

Type of change

  • Breaking change (intentional lock digest/schema change)
  • New integrity coverage
  • Docs / specs

Validation

  • Ruff and the complete base-to-head diff check pass.
  • Real clean fixture exits 0; mutated fixture exits 1. One flipped vector digest fails both language harnesses.
  • All three public pinned examples re-check clean at v4; their prior fields showed only format-migration drift before re-pinning.
  • Hash-verified dependency install, lock regeneration consistency, and pip-audit==2.9.0 --skip-editable pass without exclusions.
  • 123 TypeScript tests and 112 Python vector tests pass.
  • SDK 1.x and 2.x each pass 47 focused capture/metadata/runtime tests, including malformed later-page rejection and real stdio metadata mutation.
  • Final GitHub CI: 1218 passed, 2 skipped; coverage 88.59% (floor 80%). Deterministic fuzz rerun: 47 passed. All checks pass at exact final head; GitHub reports CLEAN. Pages deployment is correctly skipped for this PR.
  • Independent security review APPROVED the feature at 2e7c3aa7bbca44230a306125b682ad2d83311910 after closing both findings. Release-only delta review also APPROVED final head 8eb8393f12ef968d660e8e0c68c3f89d7ff1a29d (read-only / git clean; 23 example tool digests independently reproduced; PyJWT hashes match PyPI).

Release validation repairs

The existing CI audit rejected PyJWT 2.13.0. Both dev/CI and Action locks now pin 2.15.1 with regenerated artifact hashes; other package pins stay unchanged. Primary source: PyJWT advisory and patched versions. The three example locks were re-captured from unchanged pinned server versions at v4; their synthetic example approvals are explicitly documented. No CI gates were disabled.

Notes for reviewers

Review capture.py, drift_tool_metadata.py, the v4 strict reader, and the Python/TypeScript migration paths first. Fixture lock and generated vector changes are intentional. Historical v3 bytes are frozen in a separate fixture.

The protocol-neutral Warden/human-checkpoint design in docs/plans/2026-10-02-tool-integrity-upgrade.md is proposal-only. This PR adds no signing keys, new protocol adapters, kernel runtime wiring, fleet service, or changed guard fail-open/block defaults. Hashes/signatures establish commitments and provenance; they do not certify safe behavior or malicious-content freedom.

Security-specific release classification: merge remains subject to the existing exact-head human receipt for 6237658374ed41b335e2f6e92b0e177d9f2f2538. No package version bump or publication is included.

@ernestprovo23
ernestprovo23 marked this pull request as ready for review October 2, 2026 03:04
@ernestprovo23
ernestprovo23 merged commit 1de0d88 into main Oct 2, 2026
17 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant