fix(mac): Git en MCP werken op mac-prod #264

Merged
janpeter merged 3 commits from fix/mac-git-mcp into main 2026-09-28 15:58:41 +02:00
Owner

Fixes two gaps on mac-prod that were found while writing the manual (#263).

Git: /git showed "No repos configured", and git as _jpops refuses repos owned by the login user.

  • The launcher forces REPO_PATHS_FILE=/opt/jpvisser/config/repo-paths. The app (lib/repo-paths.ts) reads from that file when REPO_PATHS is empty: one path per line, # comments allowed. The file is root:_jpops 0640, read per request, and needs no deploy.
  • The whitelist git commands run with -c safe.directory=/Users/janpetervisser/Development/* and -c core.fsmonitor=false, both protected command-line config.
  • install now also installs the whitelist (ops-agent-commands.yml) from the verified staging, so the whitelist and the release move together.

MCP: /mcp gave 403 mcp_status is not in the whitelist, plus a restart button that did nothing.

  • If the agent doesn't offer mcp_status, the page shows the running scrum4me-mcp processes (from dev_processes) and explains that the MCP is session-bound. There's no restart button in that case.

Tests: repo-paths-and-mcp (new, base group), the launcher env (Go + harness), the whitelist, and the deploy test. tsc is clean.

After the deploy, a one-time root step is needed: create /opt/jpvisser/config/repo-paths (see the runbook).

🤖 Generated with Claude Code

Fixes two gaps on `mac-prod` that were found while writing the manual (#263). **Git**: `/git` showed "No repos configured", and git as `_jpops` refuses repos owned by the login user. - The launcher forces `REPO_PATHS_FILE=/opt/jpvisser/config/repo-paths`. The app (`lib/repo-paths.ts`) reads from that file when `REPO_PATHS` is empty: one path per line, `#` comments allowed. The file is root:_jpops 0640, read per request, and needs no deploy. - The whitelist git commands run with `-c safe.directory=/Users/janpetervisser/Development/*` and `-c core.fsmonitor=false`, both protected command-line config. - `install` now also installs the whitelist (`ops-agent-commands.yml`) from the verified staging, so the whitelist and the release move together. **MCP**: `/mcp` gave `403 mcp_status is not in the whitelist`, plus a restart button that did nothing. - If the agent doesn't offer `mcp_status`, the page shows the running `scrum4me-mcp` processes (from `dev_processes`) and explains that the MCP is session-bound. There's no restart button in that case. Tests: `repo-paths-and-mcp` (new, base group), the launcher env (Go + harness), the whitelist, and the deploy test. tsc is clean. After the deploy, a one-time root step is needed: create `/opt/jpvisser/config/repo-paths` (see the runbook). 🤖 Generated with [Claude Code](https://claude.com/claude-code)
fix(mac): Git en MCP werken op mac-prod
Some checks failed
CI / Select checks (pull_request) Successful in 25s
CI / Ops-agent checks (pull_request) Successful in 41s
CI / DB access operator (pull_request) Successful in 1m20s
CI / Deploy artifact checks (pull_request) Successful in 39s
CI / Docker image build (pull_request) Successful in 1m23s
CI / Root app checks (pull_request) Successful in 7m44s
CI / Mac foundation hermetic checks (pull_request) Successful in 2m14s
CI / Required checks (pull_request) Has been cancelled
CI / Publish post-merge release evidence (pull_request) Has been cancelled
CI / Mac foundation reproducible build (pull_request) Has been cancelled
405f788cd8
Git: de launcher forceert REPO_PATHS_FILE=/opt/jpvisser/config/repo-paths
en de app leest daaruit als REPO_PATHS leeg is; de git-commando's in de
whitelist draaien met -c safe.directory=~/Development/* en
core.fsmonitor=false, zodat git als _jpops de repos van de login-gebruiker
leest. install zet de whitelist voortaan mee vanuit de geverifieerde staging.

MCP: zonder mcp_status (sessiegebonden MCP) toont /mcp de draaiende
scrum4me-mcp-processen uit dev_processes en geen nutteloze herstartknop.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
s4m-codex-reviewer requested changes 2026-09-28 15:33:03 +02:00
Dismissed
s4m-codex-reviewer left a comment

REQUEST_CHANGES

  • P1 — deploy/mac-production/deploy-ops-release.sh:256: In de productievertakking van install_config wordt /opt/jpvisser/config/ops-agent-commands.yml geïnstalleerd zonder dat /opt/jpvisser/config wordt aangemaakt of gevalideerd. Alleen de HOST_ROOT-testvertakking maakt de bovenliggende map aan. Op een schone Mac breekt cmd_install daardoor vóór cmd_switch af. Maak de directory in de productievertakking met de bedoelde eigenaar/groep/mode en dek de schone-installatie af met een test.

Geen gekoppeld plan gevonden — beoordeeld op codekwaliteit + product-standaarden.

## REQUEST_CHANGES - **P1 — `deploy/mac-production/deploy-ops-release.sh:256`:** In de productievertakking van `install_config` wordt `/opt/jpvisser/config/ops-agent-commands.yml` geïnstalleerd zonder dat `/opt/jpvisser/config` wordt aangemaakt of gevalideerd. Alleen de `HOST_ROOT`-testvertakking maakt de bovenliggende map aan. Op een schone Mac breekt `cmd_install` daardoor vóór `cmd_switch` af. Maak de directory in de productievertakking met de bedoelde eigenaar/groep/mode en dek de schone-installatie af met een test. Geen gekoppeld plan gevonden — beoordeeld op codekwaliteit + product-standaarden.
docs(handleiding): Git en MCP op mac-prod na de fix
All checks were successful
CI / Select checks (pull_request) Successful in 33s
CI / Ops-agent checks (pull_request) Successful in 39s
CI / DB access operator (pull_request) Successful in 1m15s
CI / Deploy artifact checks (pull_request) Successful in 40s
CI / Docker image build (pull_request) Successful in 1m22s
CI / Root app checks (pull_request) Successful in 7m27s
CI / Mac foundation hermetic checks (pull_request) Successful in 2m13s
CI / Mac foundation reproducible build (pull_request) Successful in 3m32s
CI / Publish post-merge release evidence (pull_request) Has been skipped
CI / Required checks (pull_request) Successful in 13s
9f3991a9df
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
s4m-codex-reviewer left a comment

Verdict: APPROVED

Geen blokkerende findings.

Geen gekoppeld plan gevonden — beoordeeld op codekwaliteit + product-standaarden.

De wijziging centraliseert de repository-configuratie, behandelt de sessiegebonden MCP-variant expliciet, werkt de Mac-deployketen bij en voegt gerichte tests en documentatie toe.

## Verdict: APPROVED Geen blokkerende findings. Geen gekoppeld plan gevonden — beoordeeld op codekwaliteit + product-standaarden. De wijziging centraliseert de repository-configuratie, behandelt de sessiegebonden MCP-variant expliciet, werkt de Mac-deployketen bij en voegt gerichte tests en documentatie toe.
Sign in to join this conversation.
No reviewers
No milestone
No project
No assignees
2 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
janpeter/Ops-dashboard!264
No description provided.