Skip to content

fix(mcp): Go HTTP auth/body-limit + precision-default + shape guard + stderr surfacing (bug-hunt) - #1046

Merged
lusoris merged 1 commit into
masterfrom
fix/bughunt-mcp
Jun 27, 2026
Merged

lusoris merged 1 commit into
masterfrom
fix/bughunt-mcp

Conversation

@lusoris

@lusoris lusoris commented Jun 27, 2026

Copy link
Copy Markdown
Contributor

What

Confirmed, adversarially-verified fixes from the codebase bug-hunt sweep (cluster: mcp). See the commit body for the per-finding detail and verification evidence. Golden-safe: no Netflix assertAlmostEqual value modified.

Reproducer / smoke

See the commit body — each fix lists its build + test evidence (golden gate / parity / regression tests run locally per cluster).

Deliverables (ADR-0108)

  • Research digest — no digest needed: verified bug fixes, root cause in commit body + state.md row.
  • Decision matrix — no alternatives: only-one-way correctness fixes matching the CPU/upstream reference.
  • AGENTS.md invariant note — cmd/vmafx-mcp/AGENTS.md.
  • Reproducer / smoke-test command — see "Reproducer / smoke" + commit body.
  • CHANGELOG fragment — changelog.d/fixed/bughunt-mcp-go-python-parity-2026-06-27.md.
  • Rebase note — docs/rebase-notes.md entry.
  • state.md — T-BUGHUNT-MCP-2026-06-27 (Recently closed).

I did not modify any Netflix golden assertAlmostEqual value.

@lusoris
lusoris marked this pull request as ready for review June 27, 2026 17:11
@lusoris
lusoris enabled auto-merge (squash) June 27, 2026 17:11
…t + vmaf-tune stderr + eval shape guard (T-BUGHUNT-MCP-2026-06-27)

Bug-hunt sweep (mcp subsystem), 4 fixed / 2 already-fixed-and-skipped:

- mcp #1 (high): the Go cmd/vmafx-mcp streamable-HTTP transport had no auth,
  no body limit, and bound all interfaces — the Python ADR-0967 hardening was
  never ported. New cmd/vmafx-mcp/http_security.go adds a bearer-token
  middleware (VMAFX_MCP_HTTP_TOKEN, crypto/subtle constant-time compare,
  VMAFX_MCP_HTTP_NO_AUTH=1 opt-out, refuse-all 401 when neither is set), a
  4 MiB body limit (http.MaxBytesReader + Content-Length pre-flight -> 413),
  and a loopback-only default bind (VMAFX_MCP_HTTP_BIND, default 127.0.0.1,
  applied when mcp.http.addr has no host); wired into main.go runMCPTransport.
- mcp #3 (med): unify the score-precision default to "legacy" (%.6f, the
  C-CLI default per ADR-0119). The Python HTTP /v1/score path and the Go
  direct-cgo->subprocess fallback both defaulted to "17", diverging from the
  stdio path and the documented default.
- mcp #4 (low): add the pred/target shape-mismatch guard to the Go
  eval_model_on_split inline script (parity with Python _eval_model_on_split).
- mcp #5 (low): the three Go vmaf-tune wrappers now fold subprocess stderr
  into the error via a shared runVmafTune helper
  ("vmaf-tune <sub> exited <rc>: <stderr>"), instead of discarding it with
  exec.Output().

Skipped (already fixed in-tree): mcp #2 (subsample forwarding on
vmaf_score_encoded — scoreExtras.subsample) and mcp #6 (HTTP /v1/score strict
serializer — http_transport.py uses _dumps_strict).

Golden safety: no Netflix golden assertAlmostEqual value touched (MCP servers
only).

Reproducer:
  go test ./cmd/vmafx-mcp/        # TestSecurityMiddleware*, TestApplyBindHost,
                                  # TestRunVmafTune_*
  gosec ./cmd/vmafx-mcp/          # 0 issues
  PYTHONPATH=mcp-server/vmaf-mcp/src python -m pytest mcp-server/vmaf-mcp/tests -q
                                  # 451 passed, 2 skipped
                                  # (incl. test_score_precision_defaults_to_legacy)

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@lusoris
lusoris merged commit 6c7c3ce into master Jun 27, 2026
60 of 67 checks passed
@lusoris
lusoris deleted the fix/bughunt-mcp branch June 27, 2026 17:55
@lusoris lusoris added this to the 1.0.0 — First release milestone Sep 4, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant