From ddde4332245eb32b2a21fe225cc4bbf488cb0f99 Mon Sep 17 00:00:00 2001 From: Mikei386 <44135113+Mikei386@users.noreply.github.com> Date: Sun, 23 Aug 2026 18:44:14 +0200 Subject: [PATCH] Pass GitHub PAT to MCP subprocess --- config/operator-system-prompt.txt | 6 ++++++ docs/GITHUB_MCP.md | 6 ++++++ docs/QWEN_OPERATOR_CONTEXT.md | 6 ++++++ platform/mcp/Dockerfile.github | 6 +++++- platform/mcp/README.md | 7 +++++++ platform/openwebui/install-models.sh | 5 +++++ 6 files changed, 35 insertions(+), 1 deletion(-) diff --git a/config/operator-system-prompt.txt b/config/operator-system-prompt.txt index 9264d9d..7779217 100644 --- a/config/operator-system-prompt.txt +++ b/config/operator-system-prompt.txt @@ -50,6 +50,12 @@ code search, use the official read-only GitHub Repository MCP. Use general web search for broader public research. Avoid repeated synonymous tool calls and keep tool output bounded. +If a specialist tool reports an authentication, authorization, connection or +configuration error, do not repeat the same call. State the exact bounded +failure. For public information make at most one focused fallback attempt with +the general web tool, then synthesize the available evidence or stop clearly. +Never enter a fallback or synonym-search loop. + For models and GPU services, introduce changes only through the experimental profile or an isolated container. Change one variable at a time, record source, license, revision, size and SHA256, account for weights, KV cache, projector, diff --git a/docs/GITHUB_MCP.md b/docs/GITHUB_MCP.md index 696b637..7b55cbe 100644 --- a/docs/GITHUB_MCP.md +++ b/docs/GITHUB_MCP.md @@ -72,6 +72,12 @@ WebUI fehlerhaft. Produktiv wird deshalb der offizielle GitHub MCP 1.10.1 über `mcp-proxy` 0.12.0 bereitgestellt. Der Pfad wurde mit Open WebUIs eigenem Python-MCP-Client und einer echten öffentlichen Repositorysuche geprüft. +Falls ein Werkzeug stattdessen einen Code für `github.com/login/device` +ausgibt, ist der PAT nicht im GitHub-stdio-Unterprozess angekommen. Der +produktive Proxy verwendet deshalb ausdrücklich `--pass-environment`. Der PAT +darf nicht in den Chat kopiert und die Geräteanmeldung nicht als Dauerlösung +verwendet werden. + Der Normalmodus ist Teil des Installationsskripts. Skript, Compose-Override und diese Anleitung liegen im Git-Repository und werden vom Recovery-Koffer mitgeführt. Das Platform Context MCP kann diese Anleitung lesen, erhält aber diff --git a/docs/QWEN_OPERATOR_CONTEXT.md b/docs/QWEN_OPERATOR_CONTEXT.md index 6744861..84b2880 100644 --- a/docs/QWEN_OPERATOR_CONTEXT.md +++ b/docs/QWEN_OPERATOR_CONTEXT.md @@ -249,6 +249,12 @@ WebUI, Git oder einem Prompt. Für Quellcode, README, API-Routen und Repositorystruktur ist GitHub das richtige Werkzeug; die allgemeine Websuche ist für breitere öffentliche Recherche zuständig. +Meldet ein Fachwerkzeug einen Authentifizierungs-, Autorisierungs-, Verbindungs- +oder Konfigurationsfehler, darf derselbe Aufruf nicht wiederholt werden. Für +öffentliche Informationen ist höchstens ein gezielter Wechsel zur allgemeinen +Websuche erlaubt. Danach muss das Modell die verfügbaren Belege auswerten oder +den Abbruch klar melden, statt weitere Synonyme und Fallbacks durchzuprobieren. + GitHub ist standardmäßig strikt lesend. Falls der Benutzer ausdrücklich einen beaufsichtigten Schreibtermin verlangt, gilt der Ablauf in `docs/GITHUB_MCP.md`: begrenzten Wartungsmodus aktivieren, ausschließlich auf diff --git a/platform/mcp/Dockerfile.github b/platform/mcp/Dockerfile.github index 5c77879..418adbf 100644 --- a/platform/mcp/Dockerfile.github +++ b/platform/mcp/Dockerfile.github @@ -17,5 +17,9 @@ EXPOSE 8000 # This is the same OpenWebUI-compatible stateless transport used by Athena's # other Python/stdio MCP adapters. The official GitHub binary remains the only # component implementing GitHub operations. -ENTRYPOINT ["mcp-proxy", "--host", "0.0.0.0", "--port", "8000", "--stateless", "--"] +# mcp-proxy intentionally starts stdio children with a minimal environment. +# Explicit pass-through is required so the GitHub subprocess receives the PAT +# already injected into this container by Docker. The value is never placed on +# the command line, image, logs or Open WebUI connection record. +ENTRYPOINT ["mcp-proxy", "--host", "0.0.0.0", "--port", "8000", "--stateless", "--pass-environment", "--"] CMD ["/usr/local/bin/github-mcp-server", "stdio", "--read-only", "--tools", "search_repositories,get_repository_tree,get_file_contents,search_code"] diff --git a/platform/mcp/README.md b/platform/mcp/README.md index e649e76..edf4a11 100644 --- a/platform/mcp/README.md +++ b/platform/mcp/README.md @@ -169,6 +169,13 @@ führte trotz gesundem GitHub-Server und gültigem Token zu ist derselbe Transport, der sich bereits beim Athena Platform Context MCP bewährt hat. +Die Brücke wird mit `--pass-environment` gestartet. Ohne diese ausdrückliche +Option sieht zwar der Proxy-Prozess den per Docker-Envfile injizierten PAT, der +von ihm gestartete GitHub-stdio-Unterprozess jedoch nicht; der offizielle +Server fällt dann irreführend auf die interaktive GitHub-Geräteanmeldung +zurück. Der Token bleibt dabei eine Umgebungsvariable und erscheint weder in +Kommandozeile noch Image, Log oder Open-WebUI-Konfiguration. + Dem Modell werden ausschließlich `search_repositories`, `get_repository_tree`, `get_file_contents` und `search_code` angeboten. Der offizielle Server wird zusätzlich explizit mit `--read-only` gestartet; die Umgebungsvariablen im diff --git a/platform/openwebui/install-models.sh b/platform/openwebui/install-models.sh index 253921f..44cbbe6 100644 --- a/platform/openwebui/install-models.sh +++ b/platform/openwebui/install-models.sh @@ -200,6 +200,11 @@ params = { "API routes, or code search, use the dedicated official GitHub repository " "tool instead of guessing from ordinary web results. Use general web search " "for wider public discussion and non-repository sources. " + "If a specialist tool returns an authentication, authorization, connection, " + "or configuration error, do not repeat the same call. Report the error. For " + "public information you may make at most one focused fallback attempt with " + "the general web tool, then synthesize the available evidence or stop clearly; " + "never enter a fallback or synonym-search loop. " "Never invent tool results, system state, files, measurements, or actions. " "For claims about current external or system state, you must successfully " "use the relevant domain tool during the current request before saying "