[ENG-1118] Prepare public CI for header-based plugin promotion - #277
Conversation
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 205d81ad0a
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| if server.get("url") != canonical_url: | ||
| errors.append(f"MCP URL must stay {canonical_url!r} across releases; " | ||
| "query parameters change the registered OAuth identity") | ||
| reported = [value for name, value in server.get("headers", {}).items() | ||
| if name.lower() == "x-memhub-plugin-version"] | ||
| if reported != [version]: | ||
| errors.append(f"loaded MCP connection must send one version header " |
There was a problem hiding this comment.
Update the release guide to use the version header
When preparing the next release, docs/plugin-operations-upgrade.md lines 4–6 still instruct maintainers to carry the version in the MCP URL and update that URL with the manifest. Following that documented process now produces a configuration this new guard rejects because it requires the canonical URL plus X-MemHub-Plugin-Version; since promotion copies only plugins/memhub/, it cannot correct the repository-level guide later. Update the release documentation alongside this contract change.
Useful? React with 👍 / 👎.
🧠 Session context1 session behind this pull request. Team rules that fired while building this
Effort Sessions
|
Prepare public CI for the internal port of #272 (ENG-1118): https://github.com/XTraceAI/agent-plugins-internal/pull/42. The new promotion export reports its package version in
X-MemHub-Plugin-Versionwhile preserving the canonical MCP URL, which Codex hashes for OAuth. Today's public parity guard requires the broken query format and would reject that generated release.Require the exact production URL and one matching version header for new releases. Grandfather only the already-shipped 0.76.1 config with its exact existing query and no headers so this CI-only PR can land before promotion. Remove that exception after the first header-based promotion.
Only tests and the repository-level upgrade guide change; this PR does not edit plugin bytes, versions, tags, or marketplace pins. The fix itself is developed and exported from
XTraceAI/agent-plugins-internal; promotion copies onlyplugins/memhub/, which is why the public CI prerequisite must land separately.Validation (all exit 0):
python3 tests/version_parity_test.pyagainst the unchanged public 0.76.1 packagepython3 tests/mcp_oauth_identity_test.py— 4 tests covering the registered identity, the exact legacy exception, rejected query parameters on new versions, and missing/stale/ambiguous headerspython3 tests/registration_test.pygit diff --checkThe required real-agent production-fixture workflow has been dispatched on the final head: https://github.com/XTraceAI/agent-plugins/actions/runs/35811206090. Its result and all automatic release gates are required before merge.