Skip to content

fix(engine): use a gateway-supported MCP protocol version + wire gateway list/gw-call - #15

Merged
Miyamura80 merged 5 commits into
mainfrom
claude/sealg-gateway-wire
Aug 28, 2026
Merged

Miyamura80 merged 5 commits into
mainfrom
claude/sealg-gateway-wire

Conversation

@Miyamura80

@Miyamura80 Miyamura80 commented Aug 28, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Two things, discovered by verifying sealg end-to-end against a live local SealGate gateway:

  1. Bug fix (the important one): the gateway transport merged in feat(engine): gateway transport (config + hand-rolled MCP client) #14 advertised MCP protocol version 2026-07-28 in the initialize handshake, which the deployed gateway (FastMCP, sealgate 0.10.0) rejects with HTTP 400 / JSON-RPC -32600 (Unsupported protocol version … Supported: 2024-11-05, 2025-03-26, 2025-06-18, 2025-11-25). Every gateway call failed at connect. Fixed to 2025-06-18. So main is currently broken against a real gateway; this un-breaks it.
  2. Minimal wiring: adds gateway-backed sealg list and sealg gw-call so the transport is reachable from the CLI (until now nothing in the binary called it). This is a slim slice of the "thin-engine" re-scope; the fuller cleanup (repoint sealg call, delete the demo commands, discovery/--help) is a follow-up.

Design context: dev-docs/architecture/multi-interface-design.md in edison-watch/edison-watch (wire decision + protocol-version note).

Changes

  • crates/engine/src/gateway/client.rs — PROTOCOL_VERSION 2026-07-28 → 2025-06-18 (a version the gateway's FastMCP server lists), with a comment on why it must match the server. Module doc updated.
  • crates/cli/src/gateway_cmd.rs (new) — cmd_list / cmd_call: resolve GatewayConfig::from_env, GatewayClient::connect, forward tools/list / tools/call, print results (errors → stderr, exit 1).
  • crates/cli/src/main.rs — List and GwCall subcommands.

Testing

Verified end-to-end against a live gateway stood up locally (cloud-sandbox runbook: dockerd + GoTrue/Postgres, host backend TEST_AUTH_MODE=local, gateway on :3000):

  • sealg list returns the user's 13 tools (10 builtins + 3 from the connected demo-trifecta server) — proves initialize + tools/list round-trip.
  • sealg gw-call builtin_obtain_session_token → {"session_token":"eds_…"}; builtin_whoami and builtin_get_security_status also round-trip (tools/call).
  • Reproduced the original failure first (2026-07-28 → HTTP 400) and confirmed 2025-06-18 → 200 via direct curl.
  • cargo test -p engine (10 gateway unit tests) pass; cargo fmt --check + cargo clippy clean.

Follow-up noted in the design doc: negotiate the protocol version from the server's initialize result instead of a hardcoded constant.

Related Issues

None — tracked by the multi-interface design doc.


Generated by Claude Code


Summary by cubic

Fixes the gateway MCP handshake so it advertises a protocol version the SealGate gateway accepts, and adds sealg list and sealg gw-call subcommands so the gateway transport is reachable from the CLI. Every gateway call previously failed at connect with HTTP 400 because the client advertised 2026-07-28, which the gateway's FastMCP server rejects; it now uses 2025-06-18, a version the server lists as supported.

  • sealg list [--json] runs initialize and tools/list against the live gateway and prints the user's tools.
  • sealg gw-call <tool> [--args '<json>'] runs tools/call, prints the pretty JSON result, and exits with code 6 when the tool reports an error (1 on transport/connect failures).
  • Gateway error messages redact the API key from the endpoint URL — including the URL the HTTP client re-embeds in its own errors — so the key never reaches stderr.
  • Protocol version is still hardcoded; negotiating it from the server's initialize result is tracked as follow-up.

Written for commit 33e0646. Summary will update on new commits.

Review in cubic

claude added 2 commits August 28, 2026 14:03
Add a small `gateway_cmd` module to the `sealg` binary that drives the
merged `engine::gateway` transport:

- `sealg list [--json]` runs initialize + tools/list against the live
  gateway and prints `name  —  description` (or a JSON array).
- `sealg gw-call <tool> [--args '<json>'] [--json]` runs tools/call and
  prints the pretty JSON result.

Both resolve coordinates via `GatewayConfig::from_env()` and exit
non-zero with `error: <e>` on failure. Existing demo commands and
diagnostics.rs are untouched.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EpwFmgQPfugKFF9zugay6Y
The gateway client hardcoded protocolVersion "2026-07-28", which the
SealGate gateway's FastMCP server rejects with JSON-RPC -32600
("Unsupported protocol version ... Supported versions: 2024-11-05,
2025-03-26, 2025-06-18, 2025-11-25"). This made every `sealg list` /
`sealg gw-call` fail at initialize with an HTTP 400.

Switch to "2025-06-18", the current stable MCP spec the gateway accepts.
Verified end-to-end against a live local gateway: initialize, tools/list
(13 tools), and tools/call (builtin_whoami, builtin_get_security_status)
all round-trip successfully.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EpwFmgQPfugKFF9zugay6Y
@qodo-code-review

Copy link
Copy Markdown

ⓘ Qodo reviews are paused because the subscription is no longer active. Ask your workspace admin to reactivate the subscription to resume reviews. Manage billing

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 3 files

Reply with feedback, questions, or to request a fix.

Re-trigger cubic

Comment thread crates/cli/src/gateway_cmd.rs
Comment thread crates/cli/src/gateway_cmd.rs
Comment thread crates/cli/src/gateway_cmd.rs
Comment thread crates/engine/src/gateway/client.rs Outdated
Comment thread crates/cli/src/gateway_cmd.rs Outdated
Address cubic review on #15:
- P1 (security): gateway error messages embedded the request URL, which
  carries the API key in the /mcp/{key}/ path, leaking it to stderr. Redact
  the key via a pure redact_url() before logging; unit-tested.
- P1 (correctness): sealg gw-call printed an MCP isError:true result and exited
  0. Now prints the error content and exits nonzero (6), mirroring the MCP
  tool-call response.
- P3: reword the PROTOCOL_VERSION comment (drop the inaccurate 'current stable
  MCP spec' claim; it is the latest version the gateway's FastMCP accepts).
- Cleanup: drop the no-op --json flag on gw-call.

fmt + clippy clean; 11 engine unit tests pass.

Co-Authored-By: Claude <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EpwFmgQPfugKFF9zugay6Y

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 3 files (changes from recent commits).

Reply with feedback, questions, or to request a fix.

Re-trigger cubic

Comment thread crates/engine/src/gateway/client.rs Outdated
Comment thread crates/cli/src/gateway_cmd.rs
Comment thread crates/cli/src/gateway_cmd.rs Outdated
Comment thread crates/engine/src/gateway/client.rs Outdated
…t-code const

Address cubic re-review on #15:
- P1 (security): reqwest::Error's Display re-embeds the request URL (with the
  API key) even after we redact self.url; strip it with without_url().
- P3: redact_url now replaces the delimited /{key}/ path segment instead of a
  blanket replace-all, so a host/path containing the key text isn't corrupted;
  added a test case for that.
- P3: drop the stale [--json] from cmd_call's doc comment.
- P3: replace the magic exit 6 with a named EXIT_TOOL_ERROR constant documented
  against the design doc's exit-code taxonomy.

fmt + clippy clean; 11 engine unit tests pass.

Co-Authored-By: Claude <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EpwFmgQPfugKFF9zugay6Y

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 2 files (changes from recent commits).

Tip: Review your code locally with the cubic CLI to iterate faster.

Re-trigger cubic

Comment thread crates/cli/src/gateway_cmd.rs Outdated
…path

cubic re-review on #15: the comment cited the design doc by a path that lives
in the gateway repo, not this one. State the intent directly instead.

Co-Authored-By: Claude <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EpwFmgQPfugKFF9zugay6Y
@Miyamura80
Miyamura80 merged commit 242acca into main Aug 28, 2026
9 checks passed
@github-actions
github-actions Bot deleted the claude/sealg-gateway-wire branch August 28, 2026 15:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants