Repository navigation
Deliver Mjolnir's MCP servers to Muse through muse-acp 0.8.1 - #1190
Merged
Merged
Conversation
Pin muse-acp 0.8.1 with Muse Code 1.4.1-R4503.1 for managed installs and the agent-dev image (runtime.json). muse-acp 0.8.0 forwards ACP MCP servers to Muse through its typed session MCP configuration, so Muse no longer needs to be excluded from Mjolnir's injected tools. Remove HarnessKind::supports_injected_mcp, which returned false only for Muse, and the worker's separate hard-coded Muse check in project_memory_mcp. The two answered the same question independently; with both gone, Muse sessions receive the mj-memory tools and a Muse profile can be a reviewer. Auto review still skips Muse, whose provider has no Auto policy. muse-acp drops every MCP server, with only a log line, when the Muse host does not grant session MCP, and it advertises mcpCapabilities.http exactly when the grant was given. The worker now fails a Muse session that would carry MCP servers without that advertisement instead of running without Mjolnir's tools. The check runs after the session opens, because a host that could not start also withholds the grant and the open's error carries its real diagnostic (for example, not logged in). Making Muse a reviewer exposed two reviewer launch gaps. The worker set the harness home variable directly to the role's profile copy, but Muse reads $XDG_CONFIG_HOME/muse and needs its own XDG_DATA_HOME, so the reviewer reported "Muse is not logged in" and would have written into the person's own Muse data. The reviewer now places and names its home through HarnessKind::home_from_environment and configure_home_environment, the helpers sessions use. Reviewer staging also did not write the enforced Muse permission profile into the staged settings.json the way session staging does; it now applies the same staged execution setting. Validation: cargo test (all crates; the only failures are three move_session::transfer tests that need rsync, which this host lacks), cargo clippy --all-targets -D warnings, the ignored real-adapter Muse scenario against the verified muse-acp 0.8.1 binary, new behavior tests for MCP delivery, the missing-grant failure, the host diagnostic, the reviewer's Muse home, and the staged reviewer permission profile. Live runs in an isolated instance: a managed local Muse session listed and called the mj-memory tools; a session on the published agent-dev image (muse-acp 0.5.0) failed with the new message; a session on an image built from this runtime.json used mj-memory and completed an automatic Muse turn review. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01XMubswjnr331JWDXctkFz5
Review of the Muse MCP change found an upgrade break and a privilege gap. A container keeps the muse-acp it was created with, and containers are not replaced on upgrade (#1139). The worker failed every Muse session whose adapter withheld MCP servers, so a running session in a container from an older agent-dev image stopped working after a daemon upgrade. Such a session now continues without Mjolnir's tools and reports a warning that names the remedy. A reviewer still fails, because it is told to inspect the change with its analyzer tools. Whether an adapter forwards offered servers only when it advertises HTTP MCP is now a HarnessKind property, and the check counts the servers the opening request actually carried. It no longer rebuilds the list on its own. Muse has no guardian mode and always runs unconstrained. A Muse reviewer could therefore run with auto-approval on an unsandboxed host while reviewing a session that runs with guardian approvals. Reviewer staging now refuses a reviewer that would run unconstrained for a session that does not. A reviewer role now replaces the whole directory its home variable names, so files an earlier reviewer on another harness left there do not remain in a Muse reviewer's XDG_CONFIG_HOME. The staged execution setting failure now names the profile. Validation: cargo test (all crates; the only failures are three move_session::transfer tests that need rsync, which this host lacks), cargo clippy --all-targets -D warnings, the ignored real-adapter Muse scenario against verified muse-acp 0.8.1, and new or updated tests for the withheld-grant warning, the reviewer refusal without tools, the reviewer privilege refusal, and the replaced reviewer home. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01XMubswjnr331JWDXctkFz5
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Muse sessions now receive Mjolnir's MCP servers, and a Muse profile can act as a turn reviewer.
mj-worker/assets/muse/runtime.json, which carries verified SHA-256s for all four platforms. muse-acp 0.8.0 forwards ACP MCP servers to Muse through typed session MCP.HarnessKind::supports_injected_mcp, which was false only for Muse, is removed.project_memory_mcp.mj-memorytools, and Muse can be selected as a reviewer. Auto review still skips it, because Muse has no Auto policy.sessionMcpgrant. It advertisesmcpCapabilities.httpexactly when the grant was given;HarnessKind::mcp_servers_need_advertised_httprecords that rule.$XDG_CONFIG_HOME/museand needs its ownXDG_DATA_HOME, so it reported "Muse is not logged in". Reviewers now usehome_from_environmentandconfigure_home_environment, as sessions do. Each refresh replaces the whole directory the home variable names.settings.json, as session staging already does.Sub-agent delegation tools remain Claude and Codex only (
supports_delegation_tools). This PR does not change that.Follow-up issues found during live testing: #1188 and #1189.
Test plan
cargo test: all crates pass. The only local failures are threemove_session::transfertests that needrsync, which the test host lacks.cargo clippy --all-targets -- -D warningsmj-memorytools.runtime.jsonusedmj-memoryand completed an automatic Muse turn review.After merge,
publish-agent-dev-image.ymlrepublishes the image with the new pin.🤖 Generated with Claude Code
https://claude.ai/code/session_01XMubswjnr331JWDXctkFz5