Skip to content

Add the memnet-mcp product gateway (MN-REQ-06.12) - #203

Merged
chouswei merged 5 commits into
masterfrom
cursor/memnet-product-gateway-7e7e
Oct 8, 2026
Merged

chouswei merged 5 commits into
masterfrom
cursor/memnet-product-gateway-7e7e

Conversation

@chouswei

@chouswei chouswei commented Oct 8, 2026

Copy link
Copy Markdown
Owner

SysML first, then the memnet-mcp capability that follows it. No SemVer bump. Not merged. Not deployed.

Requirement

Today (unchanged by this cut)

Checked on tags v0.19.6 (droplet memnet-mcp-http) and v0.19.18 (Pi serve).

  1. One MCP, one serve. Neither tag can point one MCP at several serves. TCP uses MEMNET_SERVE_HOST / MEMNET_SERVE_PORT only (v0.19.6 client.py 105–139, config.py 90–95; v0.19.18 client.py 106–140, config.py 96–101).
  2. Auth in front. streamable-http optional exact MEMNET_MCP_HTTP_TOKEN (http_transport.py 70–76 and 230–264, both tags). stdio has none. caller is optional CapsPolicy when session ACL is on. Tip mn_tip_ exists only at v0.19.18 (portal SHA-256 + nginx), not per-product, and is not accepted as a product credential.
  3. Wire. A v0.19.6 MCP can talk to a v0.19.18 serve for the argv it sends. Envelope is {args, stdin?} → {exit_code, stdout, stderr}. v0.19.18 adds optional admin_token / admin_usage, --max-edges, --product, --token, admin usage-report, and session expire-status. The reverse breaks: a v0.19.18 MCP always sends --max-edges, which v0.19.6 CLI lacks.

This cut

memnet-mcp --transport gateway when MEMNET_GATEWAY_CONFIG is set:

  • backend registry (id → host:port; each product's backends, houses, pinned version)
  • route by product, house, or session; one owning serve; no silent move
  • hashed, scoped, rotatable, revocable per-product credentials
  • product namespace isolation for session open, load, save, close, and list
  • exact pass-through of GQL, stdin, and engine @ERR / @WRN / @STAT
  • @ERR: gateway_<code>|… refusals
  • health check; failover only for a new session with no house and no backend; otherwise gateway_backend_unreachable
  • version check against the pin
  • loopback or tailnet bind only unless MEMNET_GATEWAY_ALLOW_PUBLIC=1
  • per-product admin counts (no content, no session ids)
  • stdio and streamable-http ignore the registry

Contract: docs/operations/product-gateway-contract.md (implemented for this cut; not a draft).

Tests run two real memnet serve processes, including a 0.19.18-compatible wire.

Endleaf

Backend endleaf-rpi5-syson at tailnet 100.118.79.40:18795, product endleaf, house syson, pin 0.19.18. Sample JSON and the hash command are in the contract. The droplet's existing 0.19.6 memnet-mcp-http does not speak this contract.

Open

See the contract, decisions 1–12: agent MCP tools do not use the registry; owner file is one process; counts reset on stop; list keeps backend max; unknown and foreign sessions share gateway_forbidden_session; no automatic return and no SnapshotHandCarry; public bind is opt-in; MagicDNS is not resolved; mn_tip_ is not federated; version cache default 15s; empty-paren edge delete is an engine lower, not rewritten; sessions opened outside this gateway are not adopted.

Open in Web Open in Cursor 

cursoragent and others added 3 commits October 8, 2026 15:27
Route by product, house, or session to one owning serve, with hashed
per-product credentials and verbatim serve pass-through. Single-backend
stdio and streamable-http stay unchanged when no registry is set.
No SemVer bump.

Co-authored-by: chouswei <chouswei@users.noreply.github.com>
The pull request open event did not start the workflow.

Co-authored-by: chouswei <chouswei@users.noreply.github.com>
Pick up the snapshot, WHERE, and ACL who fix so the pull request can run CI.

Co-authored-by: chouswei <chouswei@users.noreply.github.com>
@chouswei
chouswei marked this pull request as ready for review October 8, 2026 15:44
Real-serve tests start serves from this tree, so pinned_version follows memnet.__version__ (0.19.19 after #204). No-bump guard follows 0.19.19.
@chouswei
chouswei merged commit f31eddd into master Oct 8, 2026
2 checks passed
chouswei added a commit that referenced this pull request Oct 8, 2026
Hatch, project.toml, changelog, and the version map name the memnet-mcp product gateway (#203, MN-REQ-06.12). Not 0.20.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants