Sidecar config detection + precedence + verified per-platform paths (P0 — silently breaks working setups) #91

Closed
opened 2026-08-12 02:34:10 -04:00 by the_og · 0 comments
Owner

Why (P0 — correctness)

ssh-mcp v2 reads a TOML sidecar and only falls back to CLI args if that file is absent. So BCC's carefully-managed --host/--user args can be completely inert while the real config lives in a file BCC never looks at. Worse: writing that TOML for the first time silently disables every arg-configured host at once. No other config tool catches this.

Two linked traps:

  1. Precedence: args are inert when a sidecar exists. BCC must detect the sidecar and say so: "These arguments are currently inert — this server reads …/ssh-mcp/config.toml. Edit that instead."
  2. Verified paths, not doc paths: ssh-mcp's README says ~/.config/ssh-mcp/config.toml, but the code resolves ~/Library/Application Support/ssh-mcp/config.toml on macOS and %APPDATA%\ssh-mcp on Windows. A user following the README writes a file that's never read, with no error. Encode verified per-platform paths in ServerSpec, ideally derived from reading the package.

Also covers the field-notes credential-scoping trap (#11): ssh-mcp's unprefixed SSH_MCP_PASSWORD is offered to every profile in multi-profile TOML mode — detect multiple profiles + an unscoped credential and offer per-profile names. (Our #89 fix already sidesteps this for the single-server Claude Desktop case.)

Non-reversing constraint

Editing a sidecar is a new write target. Do not route it through apply_servers (cardinal rule: it only writes mcpServers/_disabledMcpServers). Give the sidecar its own writer that reuses write_config's atomic-rename + _make_backup so #5's safety carries over.

Scope for a first PR

Read-only truth-telling first: detect sidecar presence + precedence, warn in the editor/lint. Sidecar editing is a follow-up. Depends on the ServerSpec spine.

Acceptance

Pure-core detectors + verified path table, unit-tested (fixture: npx -y ssh-mcp + existing config.toml → args-inert warning; TOML at ~/.config on macOS → wrong-path flag). Minimal advisory GUI, no new editor yet.

Part of the ssh-mcp field-notes epic.

## Why (P0 — correctness) `ssh-mcp` v2 reads a TOML sidecar and **only falls back to CLI args if that file is absent**. So BCC's carefully-managed `--host`/`--user` args can be completely **inert** while the real config lives in a file BCC never looks at. Worse: writing that TOML for the first time silently disables every arg-configured host at once. No other config tool catches this. Two linked traps: 1. **Precedence**: args are inert when a sidecar exists. BCC must detect the sidecar and say so: *"These arguments are currently inert — this server reads `…/ssh-mcp/config.toml`. Edit that instead."* 2. **Verified paths, not doc paths**: ssh-mcp's README says `~/.config/ssh-mcp/config.toml`, but the code resolves `~/Library/Application Support/ssh-mcp/config.toml` on macOS and `%APPDATA%\ssh-mcp` on Windows. A user following the README writes a file that's never read, with no error. Encode **verified** per-platform paths in `ServerSpec`, ideally derived from reading the package. Also covers the field-notes credential-scoping trap (#11): ssh-mcp's unprefixed `SSH_MCP_PASSWORD` is offered to every profile in multi-profile TOML mode — detect multiple profiles + an unscoped credential and offer per-profile names. (Our #89 fix already sidesteps this for the single-server Claude Desktop case.) ## Non-reversing constraint Editing a sidecar is a **new write target**. Do **not** route it through `apply_servers` (cardinal rule: it only writes `mcpServers`/`_disabledMcpServers`). Give the sidecar its own writer that **reuses** `write_config`'s atomic-rename + `_make_backup` so #5's safety carries over. ## Scope for a first PR Read-only truth-telling first: detect sidecar presence + precedence, warn in the editor/lint. Sidecar *editing* is a follow-up. Depends on the ServerSpec spine. ## Acceptance Pure-core detectors + verified path table, unit-tested (fixture: `npx -y ssh-mcp` + existing `config.toml` → args-inert warning; TOML at `~/.config` on macOS → wrong-path flag). Minimal advisory GUI, no new editor yet. Part of the ssh-mcp field-notes epic.
the_og added the P0 label 2026-08-12 02:34:10 -04:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: the_og/better-claude-config#91