Rust-native rewrite: MCP server, CLI, and approvals GUI #2

Merged
xicv merged 20 commits from rewrite/rust-native into main 2026-08-23 07:46:23 +00:00
xicv commented 2026-08-23 01:16:44 +00:00 (Migrated from github.com)

Summary

Complete native Rust rewrite of sequel-mcp, replacing the TypeScript implementation: a single crate providing the policy-gated MCP stdio server, the sequel-mcp CLI (serve / doctor / approve / gui), and a native egui approvals companion window. 16 commits across 14 locally verified checkpoints; verification history covering sessions 1–16 lives in docs/rust-rewrite/VERIFICATION.md.

What it contains

  • 27-tool MCP surface with prompts (setup-connection, analyze-table) and the no-secrets connections resource
  • Two-layer policy engine (statement classifier + baseline & exact/wildcard table rules; strictest-wins, fail-closed), digest-bound single-use approvals, server-side opaque MRTR handles, DDL TOCTOU closing (preflight-approved DROP subsets only)
  • Three transports: direct TCP (TLS, private CA), SSH tunnels (russh, host-key fail-closed semantics, tunnel-lease generation pool keys, LRU retirement), Docker bridge over SSH exec (works under AllowTcpForwarding no)
  • Authenticated approval IPC: same-euid Unix socket (LOCAL_PEERCRED/SO_PEERCRED), id-bound fail-closed protocol, approve CLI + native GUI companion; elicitation remains first choice
  • Audit chain with epochs and retention; Sequel Ace importers; backup/restore with transactional replay
  • Fail-closed test isolation: SEQUEL_MCP_TEST_MODE binary gate, isolated test env shared by every test/bench child
  • CI: npm workflow replaced with SHA-pinned Rust gates (fmt/clippy/check on macOS+Ubuntu, tests on macOS)

Verification

Full evidence in docs/rust-rewrite/VERIFICATION.md. Gates at the final tree: 161 lib tests, 16 lifecycle/isolation binary tests, workspace gates green, SSH matrix 27/27, both-engine docker matrix green, clippy -D warnings 0, fmt clean, gitleaks clean, cargo package --locked + publish --dry-run green, install-from-package verified (incl. real GUI window smoke from the installed artifact).

Release/LTO benchmarks (Mac15,6 arm64, n=50, isolated config): cold initialize median 6.96 ms (p95 7.55), cold tools/list 7.57 ms, warm tools/list 0.18 ms, warm SQLite query 1.53 ms.

Status

Draft. CI-clean at the head SHA and awaiting independent review — no reviews recorded yet. Review focus requested on: permission resolution, approval replay resistance, Keychain/Touch ID, audit/backup transaction boundaries, SSH host-key verification, Docker command construction, same-euid approval IPC, MCP stdout purity, migration and rollback.

Independent review (four parallel code reviews) found and fixed 3 blockers — expression-context subqueries bypassing table read-denies, MRTR approvals replayable across databases, and audit-write failures swallowed after committed mutations — plus coupled fixes (session grants now persist via a process-shared approval engine; companion approvals show the SQL again) and a seven-item hardening batch (MySQL autocommit window closed for backed-up writes, execution-time multi-statement re-check, TOFU warnings emitted, relative knownHostsPath rejected, restore tunnel revision, table-rule bounds, v1 config backup). Evidence: docs/rust-rewrite/VERIFICATION.md sessions 19–20.

Known follow-ups (deliberately deferred, non-blocking, tracked post-merge): journal link_audit wiring for MySQL crash windows; chain-epoch handling so retention doesn't read as tampering; restore_backup per-statement policy resolution + audit rows; pooled-password lifetime.

## Summary Complete native Rust rewrite of sequel-mcp, replacing the TypeScript implementation: a single crate providing the policy-gated MCP stdio server, the `sequel-mcp` CLI (serve / doctor / approve / gui), and a native egui approvals companion window. 16 commits across 14 locally verified checkpoints; verification history covering sessions 1–16 lives in `docs/rust-rewrite/VERIFICATION.md`. ## What it contains - **27-tool MCP surface** with prompts (setup-connection, analyze-table) and the no-secrets connections resource - **Two-layer policy engine** (statement classifier + baseline & exact/wildcard table rules; strictest-wins, fail-closed), digest-bound single-use approvals, server-side opaque MRTR handles, DDL TOCTOU closing (preflight-approved DROP subsets only) - **Three transports**: direct TCP (TLS, private CA), SSH tunnels (russh, host-key fail-closed semantics, tunnel-lease generation pool keys, LRU retirement), Docker bridge over SSH exec (works under `AllowTcpForwarding no`) - **Authenticated approval IPC**: same-euid Unix socket (LOCAL_PEERCRED/SO_PEERCRED), id-bound fail-closed protocol, `approve` CLI + native GUI companion; elicitation remains first choice - **Audit chain** with epochs and retention; Sequel Ace importers; backup/restore with transactional replay - **Fail-closed test isolation**: `SEQUEL_MCP_TEST_MODE` binary gate, isolated test env shared by every test/bench child - **CI**: npm workflow replaced with SHA-pinned Rust gates (fmt/clippy/check on macOS+Ubuntu, tests on macOS) ## Verification Full evidence in `docs/rust-rewrite/VERIFICATION.md`. Gates at the final tree: 161 lib tests, 16 lifecycle/isolation binary tests, workspace gates green, SSH matrix 27/27, both-engine docker matrix green, clippy `-D warnings` 0, fmt clean, gitleaks clean, `cargo package --locked` + `publish --dry-run` green, install-from-package verified (incl. real GUI window smoke from the installed artifact). Release/LTO benchmarks (Mac15,6 arm64, n=50, isolated config): cold initialize median 6.96 ms (p95 7.55), cold tools/list 7.57 ms, warm tools/list 0.18 ms, warm SQLite query 1.53 ms. ## Status Draft. CI-clean at the head SHA and awaiting independent review — no reviews recorded yet. Review focus requested on: permission resolution, approval replay resistance, Keychain/Touch ID, audit/backup transaction boundaries, SSH host-key verification, Docker command construction, same-euid approval IPC, MCP stdout purity, migration and rollback. Independent review (four parallel code reviews) found and fixed 3 blockers — expression-context subqueries bypassing table read-denies, MRTR approvals replayable across databases, and audit-write failures swallowed after committed mutations — plus coupled fixes (session grants now persist via a process-shared approval engine; companion approvals show the SQL again) and a seven-item hardening batch (MySQL autocommit window closed for backed-up writes, execution-time multi-statement re-check, TOFU warnings emitted, relative knownHostsPath rejected, restore tunnel revision, table-rule bounds, v1 config backup). Evidence: docs/rust-rewrite/VERIFICATION.md sessions 19–20. Known follow-ups (deliberately deferred, non-blocking, tracked post-merge): journal link_audit wiring for MySQL crash windows; chain-epoch handling so retention doesn't read as tampering; restore_backup per-statement policy resolution + audit rows; pooled-password lifetime.
Sign in to join this conversation.
No description provided.