Repository navigation
feat(diff): name the env_vars entries that changed in an MCP row (Refs #795) - #1003
Merged
Merged
Conversation
…#795) An MCP server that passes variables through by name in an env_vars list changed only its list, and the row said the change was in a detail it did not show, pointing at the command's path. The grant now publishes the plain names (host-grants 0.9, extended in place, display-only) and the row names the ones gained and lost. No value is published; rows, direction, severity and check decisions do not move.
pengfei-threemoonslab
force-pushed
the
claude/795-mcp-env-field
branch
from
October 8, 2026 14:32
3a0ce4f to
8496ac0
Compare
Closed
8 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Refs #795
What
openai/codex-security#1281 added
CODEX_SECURITY_PLUGIN_ROOTto a server'senv_varsarray inplugins/codex-security/.mcp.jsonand changed nothing else. The row said the change was "in a detail this output does not show, such as the command's path or another setting". The grant published only the keys of theenvmap (env_keys), so a change to theenv_varslist was visible only throughconfig_sha256.An
mcp_servergrant now publishesenv_var_names: the plain names itsenv_varslist declares, in declared order (host-grants0.9, extended in place;0.9is not inv1.2.0, and no schema file present in that tag changes). The row names the ones gained and lost, beside the existingenv keysandheader keys.Before:
After:
Other shapes:
env keys +API_BASE -DEBUG; env_vars names +X -Y; the same names in another order readenv_vars names in a different order(the digest reads the list in order, so it is already a row); an added or removed server's cell lists the names.Display only
DISPLAY_ONLY_GRANT_FIELDS), likepackage/args_sha256/launch_source. No row, direction,expands, severity, expansion signal orcheckdecision moves; a test comparescheck's whole result for a named and an unnamed head.env_vars names), so the row claims no meaning for a name beyond that it is listed there.[A-Za-z_][A-Za-z0-9_]{0,79}and neither the digest input's redaction (_redact_secret_values) nor the label redaction rewrites it. ANAME=valueentry, an object, a token-shaped string and the entry after a credential word are not published, and a change confined to them still says it is not shown. The generic sentence namesenv_vars namesas compared only when both readings publish them and one lists a name; a saved-baseline side claims nothing.difftext and--json,verifytext/verifier.json/PR comment,checkby--base/--headand by--diff, all through the sharedreview.changes[].change.What this does not do
config_sha256's input redacts everyenvandheadersvalue whole, so a value-only change produces no digest change and no row today (pinned by a test). Naming the key would need a per-key value digest, which is a hashing oracle on secrets and would add a row class (acheckdecision change). Not done here.cwd,bearer_token_env_var,env_http_headersand header key names beyond the existingheader_keysare not published; the issue's evidence names onlyenv_vars.Tests
tests/test_mcp_env_var_names.py(new): the reproduction on every route; added, removed, both, reordered, repeated, credential-word names, more than five names;env+env_vars+headerstogether; added/removed server cells; Codexconfig.toml; display-only equivalence (named vs unnamed head); value rotation is no row and prints nothing;envmap reorder is no row; unpublished entries (NAME=valuewith a canary, object, token-shaped, spaced) never reach any output; a credential word before a name hides a change the digest never saw; grant/baseline/digest independence; a baseline side claims nothing.tests/test_distribution_surface_parity.py(claim comment),docs/distribution-surfaces.mdrow,tests/shard_seconds.json,STABILITY.mdmigration note,docs/host-boundary-support.md,CHANGELOG.md, regenerateddocs/host-grants-inventory-schema.v0.9.json.CI mirror (
-n auto -m "not perf" --ignore=tests/test_adapter_static_only.py): exit 1 on this loaded machine with only the known locallocal_settings_enabled_plugins-*failures plus load-sensitivetest_instruction_structure_hooks(2) andtest_workflow_label_redactionlinear-time (3), which pass when rerun alone.tests/test_adapter_static_only.pyalone passes;ruff check .passes.🤖 Generated with Claude Code