Skip to content

Deliver Mjolnir's MCP servers to Muse through muse-acp 0.8.1 - #1190

Merged
foundev merged 2 commits into
masterfrom
claude/muse-acp-mcp
Sep 29, 2026
Merged

foundev merged 2 commits into
masterfrom
claude/muse-acp-mcp

Conversation

@foundev

@foundev foundev commented Sep 29, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

Muse sessions now receive Mjolnir's MCP servers, and a Muse profile can act as a turn reviewer.

  • Pin: muse-acp 0.8.1 with Muse Code 1.4.1-R4503.1, for managed installs and for the agent-dev image. Both install from mj-worker/assets/muse/runtime.json, which carries verified SHA-256s for all four platforms. muse-acp 0.8.0 forwards ACP MCP servers to Muse through typed session MCP.
  • One owner for MCP delivery:
    • HarnessKind::supports_injected_mcp, which was false only for Muse, is removed.
    • So is the worker's separate hard-coded Muse check in project_memory_mcp.
    • Muse sessions now get the mj-memory tools, and Muse can be selected as a reviewer. Auto review still skips it, because Muse has no Auto policy.
  • Withheld servers are visible: muse-acp drops MCP servers with only a log line when the Muse host withholds the sessionMcp grant. It advertises mcpCapabilities.http exactly when the grant was given; HarnessKind::mcp_servers_need_advertised_http records that rule.
    • A session whose runtime withholds the servers continues without them and shows a warning with the remedy. This is typically a container created from an older image, and containers are not replaced on upgrade (Version the agent-dev image per release, bake the worker into it, and replace containers on upgrade #1139).
    • A reviewer fails instead, because it needs its analyzer tools.
    • The check counts the servers the opening request actually carried. It runs after the open, so a host that could not start reports its own diagnostic.
  • Reviewer authority: Muse always runs unconstrained. Reviewer staging refuses a reviewer that would run unconstrained for a session that runs with approvals. A Muse reviewer can review sessions that already run unconstrained: container targets and Muse sessions.
  • Reviewer launch fixes: these surfaced once Muse could review.
    • The worker set the harness home variable straight to the role's profile copy. Muse reads $XDG_CONFIG_HOME/muse and needs its own XDG_DATA_HOME, so it reported "Muse is not logged in". Reviewers now use home_from_environment and configure_home_environment, as sessions do. Each refresh replaces the whole directory the home variable names.
    • Reviewer staging now also writes the enforced Muse permission profile into the staged settings.json, as session staging already does.

Sub-agent delegation tools remain Claude and Codex only (supports_delegation_tools). This PR does not change that.

Follow-up issues found during live testing: #1188 and #1189.

Test plan

  • cargo test: all crates pass. The only local failures are three move_session::transfer tests that need rsync, which the test host lacks.
  • cargo clippy --all-targets -- -D warnings
  • Ignored real-adapter Muse scenario against the checksum-verified muse-acp 0.8.1 binary
  • New behavior tests:
    • MCP delivery
    • warning when the grant is withheld
    • reviewer failure without its tools
    • host diagnostic not masked
    • the reviewer's Muse home, replaced as a whole
    • the reviewer authority refusal
    • the staged reviewer permission profile
  • Live runs in an isolated instance:
    • A managed local Muse session called the mj-memory tools.
    • The published agent-dev image (muse-acp 0.5.0) failed with the first revision's message. It now continues with a warning; the fake-adapter tests cover that path.
    • An image built from this runtime.json used mj-memory and completed an automatic Muse turn review.
  • Code review of the PR: the upgrade break, reviewer authority, the recomputed server list, the stale reviewer home, the message remedy, and the harness property are addressed in the second commit.

After merge, publish-agent-dev-image.yml republishes the image with the new pin.

🤖 Generated with Claude Code

https://claude.ai/code/session_01XMubswjnr331JWDXctkFz5

foundev and others added 2 commits September 29, 2026 15:38
Pin muse-acp 0.8.1 with Muse Code 1.4.1-R4503.1 for managed installs and
the agent-dev image (runtime.json). muse-acp 0.8.0 forwards ACP MCP
servers to Muse through its typed session MCP configuration, so Muse no
longer needs to be excluded from Mjolnir's injected tools.

Remove HarnessKind::supports_injected_mcp, which returned false only for
Muse, and the worker's separate hard-coded Muse check in
project_memory_mcp. The two answered the same question independently;
with both gone, Muse sessions receive the mj-memory tools and a Muse
profile can be a reviewer. Auto review still skips Muse, whose provider
has no Auto policy.

muse-acp drops every MCP server, with only a log line, when the Muse
host does not grant session MCP, and it advertises
mcpCapabilities.http exactly when the grant was given. The worker now
fails a Muse session that would carry MCP servers without that
advertisement instead of running without Mjolnir's tools. The check
runs after the session opens, because a host that could not start also
withholds the grant and the open's error carries its real diagnostic
(for example, not logged in).

Making Muse a reviewer exposed two reviewer launch gaps. The worker set
the harness home variable directly to the role's profile copy, but Muse
reads $XDG_CONFIG_HOME/muse and needs its own XDG_DATA_HOME, so the
reviewer reported "Muse is not logged in" and would have written into
the person's own Muse data. The reviewer now places and names its home
through HarnessKind::home_from_environment and
configure_home_environment, the helpers sessions use. Reviewer staging
also did not write the enforced Muse permission profile into the staged
settings.json the way session staging does; it now applies the same
staged execution setting.

Validation: cargo test (all crates; the only failures are three
move_session::transfer tests that need rsync, which this host lacks),
cargo clippy --all-targets -D warnings, the ignored real-adapter Muse
scenario against the verified muse-acp 0.8.1 binary, new behavior tests
for MCP delivery, the missing-grant failure, the host diagnostic, the
reviewer's Muse home, and the staged reviewer permission profile. Live
runs in an isolated instance: a managed local Muse session listed and
called the mj-memory tools; a session on the published agent-dev image
(muse-acp 0.5.0) failed with the new message; a session on an image
built from this runtime.json used mj-memory and completed an automatic
Muse turn review.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01XMubswjnr331JWDXctkFz5
Review of the Muse MCP change found an upgrade break and a privilege gap.

A container keeps the muse-acp it was created with, and containers are
not replaced on upgrade (#1139). The worker failed every Muse session
whose adapter withheld MCP servers, so a running session in a container
from an older agent-dev image stopped working after a daemon upgrade.
Such a session now continues without Mjolnir's tools and reports a
warning that names the remedy. A reviewer still fails, because it is
told to inspect the change with its analyzer tools.

Whether an adapter forwards offered servers only when it advertises HTTP
MCP is now a HarnessKind property, and the check counts the servers the
opening request actually carried. It no longer rebuilds the list on its
own.

Muse has no guardian mode and always runs unconstrained. A Muse reviewer
could therefore run with auto-approval on an unsandboxed host while
reviewing a session that runs with guardian approvals. Reviewer staging
now refuses a reviewer that would run unconstrained for a session that
does not.

A reviewer role now replaces the whole directory its home variable names,
so files an earlier reviewer on another harness left there do not remain
in a Muse reviewer's XDG_CONFIG_HOME. The staged execution setting
failure now names the profile.

Validation: cargo test (all crates; the only failures are three
move_session::transfer tests that need rsync, which this host lacks),
cargo clippy --all-targets -D warnings, the ignored real-adapter Muse
scenario against verified muse-acp 0.8.1, and new or updated tests for
the withheld-grant warning, the reviewer refusal without tools, the
reviewer privilege refusal, and the replaced reviewer home.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01XMubswjnr331JWDXctkFz5
@foundev
foundev merged commit 297b5f6 into master Sep 29, 2026
15 checks passed
@foundev
foundev deleted the claude/muse-acp-mcp branch September 30, 2026 10:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant