Skip to content

[REQ-131][CODE] MCP 工具别名碰撞时禁止静默覆盖 #726

Description

@jinjunnn

Parent

Problem

MCP 工具模型别名不是一一映射:当前 McpCatalog.toolName 会把不允许的字符统一替换为下划线,因此同一或不同 server 中的远端名称可能归一化为同一个模型工具名。例如 foo.bar 与 foo_bar 会碰撞;普通 MCP materialization 和 Code Mode 都会写入以该别名为 key 的 Record,后写入者静默覆盖先写入者。

这会让模型看到的工具、用户策略命中的稳定 identity 和最终执行对象发生错位,属于 fail-open 的能力路由缺陷。

Covers

  • REQ-131 AC1、AC2、AC3、AC6。

Ground-truth evidence

  • packages/opencode/src/mcp/catalog.ts:117-119:非法字符归一化为下划线。
  • packages/opencode/src/mcp/index.ts:666-685:按模型别名写入普通 MCP tool record。
  • packages/opencode/src/tool/code-mode.ts:120:Code Mode 存在相同的 key 覆盖形态。

Required behavior

  • 模型可见别名与 source/server/remote-tool 稳定 identity 保持可验证的一一映射。
  • 在批准可逆唯一别名方案前,任何碰撞必须在工具提供给模型或执行前 fail closed;禁止静默覆盖。
  • 普通 MCP、V1/V2 registry materialization 与 Code Mode 使用同一碰撞不变量。
  • permission、用户三态策略、计费/风险元数据和最终执行均绑定稳定 identity,不能因别名碰撞指向另一工具。

Verification

  • 同 server:foo.bar 与 foo_bar。
  • 跨 server:不同 canonical server identity 产生相同模型别名。
  • server rename/rebind、动态删除/重加及缓存 catalog。
  • 普通 MCP 与 Code Mode 均证明无静默覆盖;恢复旧 overwrite 行为时命名测试变红。
  • 未能唯一反解的模型别名必须响亮拒绝,且不会触发网络、副作用或费用。

Boundary

MCP catalog/identity、模型工具 materialization、Code Mode 适配与确定性测试;同步更新受影响的 canonical contract/design 文档。

Out of scope

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:contractsContracts, schemas, or compatibilityarea:integrationRepository, API, or external integrationarea:runtimeServices, jobs, infrastructure, or operationsarea:securitySecurity or access controlsource:skill-auditOriginated from a skill or repository audittype:bugSomething is incorrect or regressed

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions