Repository navigation
feat(mcp): add bounded Gmail exports and scoped Calendar tools - #1181
salmonumbrella wants to merge 1 commit into
Conversation
|
🦞👀 Pull request received. I will update this pull request when review starts. ClawSweeper review completeClawSweeper finished reviewing this revision. The review result is being finalized. |
|
Codex review: needs real behavior proof before merge. Reviewed October 1, 2026, 6:26 AM ET / 10:26 UTC (Revision 4). ClawSweeper reviewWhat this changesThe PR adds bounded Gmail byte exports and paged metadata reads, typed Calendar and Gmail settings tools, separate sensitive-action grants, private snapshots, and mutation receipts. Merge readiness⛔ Blocked before merge - 6 items remain This PR remains useful and is not already implemented on main. The previous changelog finding is resolved; permission-expansion approval and production behavior proof remain outstanding. Priority: P2 Review scores
Verification
How this fits togethergog's MCP server exposes selected Google Workspace operations to agent clients over stdio. It applies account and capability policies before dispatching native commands or returning private export snapshots. flowchart TD
A[Agent tool request] --> B[MCP server]
C[Account and saved policy] --> B
B --> D[Permission and input checks]
D --> E[Native Google operations]
E --> F[Google Workspace APIs]
F --> G[Private snapshots or mutation receipts]
G --> H[Bounded client response]
Decision needed
Why: The expansion is intentional and documented, but accepting a broader persisted authorization surface requires maintainer intent. Before merge
Findings
Agent review detailsSecurityNeeds attention: The unresolved security question is expansion of existing persisted mutation authority; no concrete supply-chain regression was found. Review metrics
Merge-risk optionsMaintainer options:
Technical reviewBest possible solution: Preserve previously reviewed mutation permissions during upgrade unless operators explicitly enable the additions, with verified fresh-start and saved-policy behavior. Do we have a high-confidence way to reproduce the issue? Not applicable as a feature request; source and fixtures establish the proposed paths, but no real Google-account after-fix run is supplied. Is this the best way to solve the issue? Unclear. Reusing native commands behind typed bounded tools is sensible, but saved-policy authorization expansion needs an approved compatibility contract. AGENTS.md: found and applied where relevant. Codex review notes: model internal, reasoning medium; reviewed against 414e2ff8afa2. LabelsLabel changes: No label changes. Label justifications:
EvidenceSecurity concerns:
What I checked:
Likely related people:
Rank-up movesOptional improvements that raise the rating; they are not merge blockers.
Rating scale
Overall follows the weaker of proof and patch quality. Workflow
HistoryReview history (3 earlier review cycles)
|
ab06e95 to
8ba2104
Compare
8ba2104 to
3a6a5e0
Compare
What changed
Why
Large MIME messages and attachments need an exact byte path that can be reconstructed without truncated JSON or normalized content. Clients also need compact thread enumeration and typed Calendar/settings actions without a generic command runner or broader send/delete permission.
Usage
Exports are capped at 50 MiB decoded; snapshots expire 900 seconds after publication. New bounded tools require an output budget of at least 4096 bytes. The migration guide documents native envelope/schema changes and removal of overlapping sidecar registrations.
Validation:
make ci TEST_FLAGS=-timeout=60m: all Go packages, lint, generated docs/skills and 19 Node script tests pass at ab06e95. Subsequent revisions change only tests and release-note references; exact-head upstream CI is also green.Saved-policy upgrade evidence (
TestMCPSavedPolicyUpgrade):*+ writeThe same old-format JSON fixture ran against pinned upstream and this branch.
Broad selectors intentionally gain five ordinary writes: Calendar create/update/
move, label rename and filter creation. Narrow account policies replace the
global policy; new notification/delete grants remain absent, and existing Gmail
send/delete stays gated. The committed regression and its race run pass (1.430s).
Pin exact tool names to retain an existing reviewed write surface.
Maintainer review remains required for that broad-selector expansion. All
mutation proofs use isolated fixtures; live Google mutation/readback and
production rollout were outside this contribution task. The upstream review's
request for live provider proof remains a pre-merge decision for maintainers.
Both Unreleased entries now link to this PR.
Roborev passed the full original implementation and each subsequent correction with
zai/glm-5.3-flashatmax. Deferred follow-ups: a distinct typed-read overflow code, redacted debug events, and a bounded iterative budget for abandoned-fetch retries under hostile churn.Refs #1173. This adds an exact export path; it does not change the documented full-payload MIME projection or claim to fix that report.