Files
Kigi-CLI/crates/codegen/kigi-shell/src/session/acp_mcp.rs
T
ZacharyZhang-NY 6f31415ed6 §9 acceptance: grep-zero sweep — every internal x.ai/grok identifier renamed
The PRD's first acceptance gate now holds: grep -RinE '\bx\.ai\b|grok'
crates/ --include='*.rs' → 0 matches (exempt: NOTICE and third-party
license archives, README provenance, and the required 'Based on Grok
Build Open Source' attribution, now sourced from version_attribution.txt).

Wire-visible renames (both sides in this repo, changed in lockstep):
- Auth method id 'grok.com' → 'kimi-code' (AuthMethodKind::KimiCode).
- Every x.ai/* and _x.ai/* ACP ext method and meta key → kigi/* /
  _kigi/* (~200 names; grokShell → kigiShell). Session-file replay keeps
  a read-side alias for the legacy '_x.ai/session/update' method so
  existing updates.jsonl histories load; writes emit only the new name
  (both directions test-pinned).
- Agent types grok-build* → kigi* with a documented legacy-prefix alias
  at resolution time so persisted sessions keep resolving.
- ToolNamespace/BuiltinAgentName GrokBuild* → Kigi* (wire snake_case
  kigi/kigi_concise/kigi_hashline; schema regenerated); grok_build
  implementation dirs renamed to kigi*.
- x-grok-* headers → x-kigi-*, __GROK_* sentinels → __KIGI_*, themes
  grokday/groknight → kigiday/kiginight (old persisted values fall back
  to the default theme), web_fetch allowlist xAI hosts → kimi.com +
  moonshot platforms, changelog CDN → this repo, grok-build changelog
  archives deleted.
- BYOK default endpoint removed: [endpoints] api_base_url is now truly
  optional with NO default — consumers fail fast with the flag name when
  unset (no silent x.ai egress). Mock harnesses inject it explicitly.
- System-prompt identity fixed: 'released by xAI' → 'an unofficial
  community CLI for Kimi' (template + regenerated encrypted form).

Also repaired pre-existing grok-era test debt found by the sweep: the
stale trace_classify default-model pin, the grok-pager UA label test,
pty-harness stale-binary reuse and non-hermetic moonshot routing (a PTY
test could previously reach the real api.moonshot.cn), and the outdated
oauth fixture scope key.

Gates: §9 grep 0; fmt clean; workspace check/clippy 0/0 (-D warnings);
FULL cargo test --workspace: 234 suites, 21,961 passed, 0 failed;
deny advisories ok.
2026-07-18 02:48:46 -04:00

145 lines
5.6 KiB
Rust

//! In-process SDK MCP servers over the ACP reverse channel (`kigi/mcp/sdk_call`).
//!
//! The official `kigi-agent-sdk` lets a host define in-process tools (`@tool` /
//! `create_sdk_mcp_server`). When `transport="acp"`, the SDK registers them in
//! `session/new` `_meta["kigi/mcp/servers"] = [{ "name", "serverId" }]` and the agent
//! invokes their tools by sending each MCP JSON-RPC message back to the client as a
//! reverse `kigi/mcp/sdk_call` request — handled here by [`GatewayAcpInvoker`].
//!
//! NOTE: the *reverse* route (agent -> client, `kigi/mcp/sdk_call`) invokes a tool that
//! lives in the SDK's process. It is the zero-IPC mirror of the *forward* route (client
//! -> agent, `kigi/mcp/call` in `extensions::mcp`), which invokes a tool on a server the
//! AGENT is connected to. They use distinct method strings and sit on opposite request
//! handlers, so they never collide.
use std::time::Duration;
use agent_client_protocol as acp;
use kigi_acp_lib::AcpAgentGatewaySender;
use kigi_mcp::acp_transport::AcpReverseInvoker;
use kigi_mcp::servers::AcpServerEntry;
use kigi_mcp::wire;
/// Parse `_meta["kigi/mcp/servers"]` into [`AcpServerEntry`] registrations. Each entry
/// is deserialized directly into the canonical type (so the `serverId` wire field is
/// serde-checked, not hand-read); entries missing `name`/`serverId` are skipped with a
/// warning. A name seen twice keeps the first (server names are the tool namespace, so a
/// duplicate would otherwise silently shadow). Absent meta yields none.
pub fn parse_acp_mcp_servers(meta: Option<&acp::Meta>) -> Vec<AcpServerEntry> {
let Some(array) = meta
.and_then(|m| m.get(wire::MCP_SERVERS))
.and_then(|v| v.as_array())
else {
return Vec::new();
};
let mut seen = std::collections::HashSet::new();
let mut servers = Vec::new();
for entry in array {
let server: AcpServerEntry = match serde_json::from_value(entry.clone()) {
Ok(server) => server,
Err(err) => {
tracing::warn!(entry = %entry, %err, "ignoring malformed kigi/mcp/servers entry");
continue;
}
};
if !seen.insert(server.name.clone()) {
tracing::warn!(name = %server.name, "ignoring duplicate kigi/mcp/servers entry");
continue;
}
servers.push(server);
}
servers
}
/// Reverse-RPC invoker for in-process SDK MCP servers.
///
/// Each [`invoke`](AcpReverseInvoker::invoke) sends one `kigi/mcp/sdk_call` reverse request
/// straight through the gateway. `AcpAgentGatewaySender::send` returns a `Send` future
/// (unlike the `?Send` `acp::Client::ext_method` trait method), so the rmcp transport's
/// `Send` invoker bound is satisfied with no relay task. Calls are independent and may
/// run concurrently — the gateway serializes them onto the session's message channel.
pub struct GatewayAcpInvoker {
gateway: AcpAgentGatewaySender,
}
impl GatewayAcpInvoker {
pub fn new(gateway: AcpAgentGatewaySender) -> Self {
Self { gateway }
}
}
/// Reverse `kigi/mcp/sdk_call` params. Declares the on-wire field names once (mirrors
/// the forward side's typed `McpCallRequest`) so the `serverId` literal isn't hand-spelled.
#[derive(serde::Serialize)]
struct SdkCallParams<'a> {
#[serde(rename = "serverId")]
server_id: &'a str,
message: serde_json::Value,
}
#[async_trait::async_trait]
impl AcpReverseInvoker for GatewayAcpInvoker {
async fn invoke(
&self,
server_id: &str,
message: serde_json::Value,
timeout: Duration,
) -> Result<serde_json::Value, String> {
let params = serde_json::value::to_raw_value(&SdkCallParams { server_id, message })
.map_err(|err| err.to_string())?;
let request = acp::ExtRequest::new(wire::MCP_SDK_CALL, params.into());
// Bound the round trip so a missing or hung client fails this reverse call at
// the configured per-server tool timeout rather than stalling the tool loop.
let response = tokio::time::timeout(timeout, self.gateway.send(request))
.await
.map_err(|_| {
format!(
"{} to server {server_id} timed out after {}ms",
wire::MCP_SDK_CALL,
timeout.as_millis()
)
})?
.map_err(|err| err.to_string())?;
serde_json::from_str(response.0.get()).map_err(|err| err.to_string())
}
}
#[cfg(test)]
mod tests {
use super::*;
#[test]
fn parses_valid_entries_and_skips_malformed() {
let meta = serde_json::json!({
"kigi/mcp/servers": [
{ "name": "harness-tools", "serverId": "srv_0" },
{ "name": "missing-id" },
{ "serverId": "no_name" },
]
});
let servers = parse_acp_mcp_servers(meta.as_object());
assert_eq!(servers.len(), 1);
assert_eq!(servers[0].name, "harness-tools");
assert_eq!(servers[0].server_id, "srv_0");
}
#[test]
fn duplicate_names_keep_the_first() {
let meta = serde_json::json!({
"kigi/mcp/servers": [
{ "name": "tools", "serverId": "srv_0" },
{ "name": "tools", "serverId": "srv_1" },
]
});
let servers = parse_acp_mcp_servers(meta.as_object());
assert_eq!(servers.len(), 1);
assert_eq!(servers[0].server_id, "srv_0");
}
#[test]
fn absent_meta_yields_none() {
assert!(parse_acp_mcp_servers(None).is_empty());
assert!(parse_acp_mcp_servers(serde_json::json!({}).as_object()).is_empty());
}
}