Commit 26a8395
committed
feat(mcp): OAB MCP Facade MVP — shared openab-mcp crate + broker loopback HTTP server
Implements the OAB MCP Adapter ADR (#1446) MVP:
- New workspace crate crates/openab-mcp: the MCP runtime extracted from
openab-agent (client runtime, OAuth/PKCE + auth.json store, layered
mcp.json config, tool cache, circuit breaker, jsonschema validation,
redaction) plus the new OAB MCP Facade — an inbound MCP server
exposing exactly search_capabilities / execute_capability.
- Facade transport: loopback-only Streamable HTTP (http://127.0.0.1:
<port>/mcp). Non-loopback binds are refused. Any MCP-capable coding
CLI on the host can connect.
- Broker activation: presence of [mcp] in config.toml starts the
listener in-process (absent = no listener, backward compatible).
openab-agent re-exports the crate (crate::{mcp,auth} shims + llm type
layer + HostBridge) — one runtime, two hosts, zero duplication.
- tool_filter enforcement (accepted MCP ADR §5.6, previously parsed but
unenforced): glob include/exclude applied at discovery (pre-cache)
and execution (pre-connect), for the meta-tool and facade alike.
- openab-agent mcp-facade --listen: standalone facade server.
- acp.rs env-mutating tests moved to temp_env (single global lock
domain; a private ENV_LOCK raced with temp_env-based tests once the
moved tests changed binary scheduling); session_new_missing_key now
sandboxes HOME instead of deleting the developer's real auth.json.
- Dockerfile.unified + ci-openab-agent.yml updated for the new member.1 parent 5ed03f4 commit 26a8395
28 files changed
Lines changed: 3988 additions & 2817 deletions
File tree
- .github/workflows
- crates
- openab-core/src
- openab-mcp
- src
- mcp
- openab-agent
- src
- src
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
4 | 4 | | |
5 | 5 | | |
6 | 6 | | |
| 7 | + | |
| 8 | + | |
7 | 9 | | |
8 | 10 | | |
9 | 11 | | |
10 | 12 | | |
| 13 | + | |
11 | 14 | | |
12 | 15 | | |
13 | 16 | | |
| |||
0 commit comments