github / github/github-mcp-server

Add read-only regression coverage for dynamic toolsets and deprecated aliases

Abierto
#2,192 0 comentarios 0 reacciones 0 asignados Ver en GitHub
Lenguaje dominante
Go
Estrellas
33k
Forks
5k
Merge medio
2 d 1 h
PR fusionados (30 d)
52

Descripción

Read-only guarantees currently depend on implicit inventory behavior that is not regression-tested across dynamic toolset enablement and deprecated alias resolution.

Current behavior is insufficient because the server's read-only contract spans multiple capability surfaces (`DynamicTools`, inventory filtering, and deprecated alias lookup), but there is no focused test that proves mutating canonical tools and deprecated aliases stay unavailable when read-only mode is active.

Why now: `--read-only` is a core governance boundary for this server, so the contract should be locked in with explicit regression coverage before toolset and alias work drifts further.

Claim-to-codepath map:
- Dynamic toolset registration in `pkg/github/dynamic_tools.go`
- Deprecated alias mapping in `pkg/github/deprecated_tool_aliases.go`
- Server inventory assembly in `internal/ghmcp/server.go`
- Request-level filtering tests in `pkg/http/handler_test.go`

Requested behavior:
- Read-only mode should continue to exclude mutating tools when a toolset is enabled dynamically.
- Deprecated aliases for mutating tools should not re-expose write capability under read-only filtering.
- The invariant should be covered by targeted tests.

## Evidence Packet
- Commit under test: `1da41fa6947f`
- Runtime environment:
- OS: Darwin 25.3.0 arm64
- Go: go1.25.7
- golangci-lint: 2.8.0
- Minimal repro:
1. Build inventory/server state with read-only mode enabled.
2. Exercise dynamic toolset enablement and deprecated alias lookup.
3. Verify whether any mutating capability becomes available.
- Expected behavior: no mutating canonical tool or deprecated alias becomes callable in read-only mode.
- Actual behavior: the code path is not covered by a focused regression test today.

## Acceptance Criteria
- Add targeted tests proving read-only behavior holds for dynamic toolsets and deprecated aliases.
- Keep the change scoped to regression coverage unless a concrete behavior bug is found.

Guía de contribución

Abrir la guía de contribución

Evaluación

Este issue todavía no se ha evaluado.

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.