Rust-native rewrite: MCP server, CLI, and approvals GUI #2
No reviewers
Labels
No labels
bug
documentation
duplicate
enhancement
good first issue
help wanted
invalid
question
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
x/sequel-mcp!2
Loading…
Reference in a new issue
No description provided.
Delete branch "rewrite/rust-native"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Summary
Complete native Rust rewrite of sequel-mcp, replacing the TypeScript implementation: a single crate providing the policy-gated MCP stdio server, the
sequel-mcpCLI (serve / doctor / approve / gui), and a native egui approvals companion window. 16 commits across 14 locally verified checkpoints; verification history covering sessions 1–16 lives indocs/rust-rewrite/VERIFICATION.md.What it contains
AllowTcpForwarding no)approveCLI + native GUI companion; elicitation remains first choiceSEQUEL_MCP_TEST_MODEbinary gate, isolated test env shared by every test/bench childVerification
Full evidence in
docs/rust-rewrite/VERIFICATION.md. Gates at the final tree: 161 lib tests, 16 lifecycle/isolation binary tests, workspace gates green, SSH matrix 27/27, both-engine docker matrix green, clippy-D warnings0, fmt clean, gitleaks clean,cargo package --locked+publish --dry-rungreen, install-from-package verified (incl. real GUI window smoke from the installed artifact).Release/LTO benchmarks (Mac15,6 arm64, n=50, isolated config): cold initialize median 6.96 ms (p95 7.55), cold tools/list 7.57 ms, warm tools/list 0.18 ms, warm SQLite query 1.53 ms.
Status
Draft. CI-clean at the head SHA and awaiting independent review — no reviews recorded yet. Review focus requested on: permission resolution, approval replay resistance, Keychain/Touch ID, audit/backup transaction boundaries, SSH host-key verification, Docker command construction, same-euid approval IPC, MCP stdout purity, migration and rollback.
Independent review (four parallel code reviews) found and fixed 3 blockers — expression-context subqueries bypassing table read-denies, MRTR approvals replayable across databases, and audit-write failures swallowed after committed mutations — plus coupled fixes (session grants now persist via a process-shared approval engine; companion approvals show the SQL again) and a seven-item hardening batch (MySQL autocommit window closed for backed-up writes, execution-time multi-statement re-check, TOFU warnings emitted, relative knownHostsPath rejected, restore tunnel revision, table-rule bounds, v1 config backup). Evidence: docs/rust-rewrite/VERIFICATION.md sessions 19–20.
Known follow-ups (deliberately deferred, non-blocking, tracked post-merge): journal link_audit wiring for MySQL crash windows; chain-epoch handling so retention doesn't read as tampering; restore_backup per-statement policy resolution + audit rows; pooled-password lifetime.