Skip to content

fix(core): enforce MCP policy consistently at runtime - #29200

Closed
CoralGarden52 wants to merge 3 commits into
google-gemini:mainfrom
CoralGarden52:fix/mcp-runtime-policy
Closed

CoralGarden52 wants to merge 3 commits into
google-gemini:mainfrom
CoralGarden52:fix/mcp-runtime-policy

Conversation

@CoralGarden52

Copy link
Copy Markdown

Summary

  • Align MCP runtime policy checks with the CLI's case-insensitive, whitespace-trimmed server-name matching.
  • Treat an explicitly empty mcp.allowed list as fail-closed instead of allowing every configured server.
  • Preserve the distinction between an omitted allowlist and an explicit empty allowlist.

Details

McpClientManager previously used exact includes() checks and ignored empty policy arrays, so the runtime could disagree with the CLI policy path. This change normalizes server names at the runtime boundary and retains undefined for an omitted allowlist while using [] when MCP is globally disabled.

Related Issues

Fixes #29199

How to Validate

  1. Configure a server named probe and verify that allowed: [" PROBE "] starts it, while excluded: [" probe "] and allowed: [] prevent it from starting.
  2. Run npm test --workspace @google/gemini-cli-core -- src/tools/mcp-client-manager.test.ts (41 passing).
  3. Run npm test --workspace @google/gemini-cli-core -- src/config/config.test.ts (237 passing).
  4. Run GEMINI_CLI_TRUST_WORKSPACE=true npm test --workspace @google/gemini-cli -- src/gemini.test.tsx (43 passing, 1 skipped).
  5. Run npm run typecheck --workspace @google/gemini-cli-core.

I also ran npm run preflight. Its formatting, build, lint, and typecheck stages passed. The core sandbox integration tests cannot run in this container because Bubblewrap is not permitted to mount /proc (Operation not permitted).

Pre-Merge Checklist

  • Updated relevant documentation and README (if needed)
  • Added/updated tests (if needed)
  • Noted breaking changes (if any)
  • Validated on required platforms/methods:
    • MacOS
      • npm run
      • npx
      • Docker
      • Podman
      • Seatbelt
    • Windows
      • npm run
      • npx
      • Docker
    • Linux
      • npm run
      • npx
      • Docker

@CoralGarden52
CoralGarden52 requested review from a team as code owners September 4, 2026 04:25
@google-cla

google-cla Bot commented Sep 4, 2026

Copy link
Copy Markdown

Thanks for your pull request! It looks like this may be your first contribution to a Google open source project. Before we can look at your pull request, you'll need to sign a Contributor License Agreement (CLA).

View this failed invocation of the CLA check for more information.

For the most up to date status, view the checks section at the bottom of the pull request.

@gemini-code-assist

Copy link
Copy Markdown
Contributor

Summary of Changes

Hello, I'm Gemini Code Assist1! I'm currently reviewing this pull request and will post my feedback shortly. In the meantime, here's a summary to help you and other reviewers quickly get up to speed!

This pull request improves the consistency and security of the MCP (Model Context Protocol) server management. By normalizing server name matching and ensuring that explicit empty allowlists are treated as restrictive rather than permissive, the runtime now correctly adheres to the policies defined in the CLI configuration. These changes resolve inconsistencies between configuration settings and runtime execution behavior.

Highlights

  • Policy Consistency: Aligned MCP runtime policy checks with the CLI's case-insensitive and whitespace-trimmed server-name matching.
  • Fail-Closed Behavior: Updated the runtime to treat an explicitly empty allowlist as fail-closed, ensuring no servers are started when the list is defined but empty.
  • Allowlist Distinction: Preserved the semantic distinction between an omitted allowlist (undefined) and an explicitly empty allowlist ([]).
Using Gemini Code Assist

The full guide for Gemini Code Assist can be found on our documentation page, here are some quick tips.

Invoking Gemini

You can request assistance from Gemini at any point by creating a comment using either /gemini <command> or @gemini-code-assist <command>. Below is a summary of the supported commands on the current page.

Feature Command Description
Code Review /gemini review Performs a code review for the current pull request in its current state.
Pull Request Summary /gemini summary Provides a summary of the current pull request in its current state.
Comment @gemini-code-assist Responds in comments when explicitly tagged, both in pull request comments and review comments.
Help /gemini help Displays a list of available commands.

Customization

To customize the Gemini Code Assist for GitHub experience, repository maintainers can create a configuration file and/or provide a custom code review style guide (such as PEP-8 for Python) by creating and adding files to a .gemini/ folder in the base of the repository. Detailed instructions can be found here.

Limitations & Feedback

Gemini Code Assist may make mistakes. Please leave feedback on any instances where its feedback is incorrect or counterproductive. You can react with 👍 and 👎 on @gemini-code-assist comments. If you're interested in giving your feedback about your experience with Gemini Code Assist for GitHub and other Google products, sign up here.

Footnotes

  1. Review the Privacy Notices, Generative AI Prohibited Use Policy, Terms of Service, and learn how to configure Gemini Code Assist in GitHub here. Gemini can make mistakes, so double check it and use code with caution. ↩

@github-actions github-actions Bot added the size/m A medium sized PR label Sep 4, 2026
@github-actions

github-actions Bot commented Sep 4, 2026 •

Copy link
Copy Markdown

📊 PR Size: size/M

  • Lines changed: 175
  • Additions: +155
  • Deletions: -20
  • Files changed: 10

@github-actions

github-actions Bot commented Sep 4, 2026 •

Copy link
Copy Markdown

🛑 Action Required: Evaluation Approval

Steering changes have been detected in this PR. To prevent regressions, a maintainer must approve the evaluation run before this PR can be merged.

Maintainers:

  1. Go to the Workflow Run Summary.
  2. Click the yellow 'Review deployments' button.
  3. Select the 'eval-gate' environment and click 'Approve'.

Once approved, the evaluation results will be posted here automatically.

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request updates the configuration and client manager for Model Context Protocol (MCP) servers to properly handle and preserve an explicitly empty allowlist, and to normalize server names (by trimming and converting to lowercase) when evaluating allowlists and blocklists. Specifically, allowedMcpServers can now be undefined (meaning no allowlist is set), allowing an empty array [] to act as an explicit block-all list. Corresponding unit tests have been added to verify these behaviors. There are no review comments to address, so I have no additional feedback to provide.

@gemini-cli gemini-cli Bot added priority/p2 Important but can be addressed in a future release. area/enterprise Issues related to Telemetry, Policy, Quota / Licensing area/non-interactive Issues related to GitHub Actions, SDK, 3P Integrations, Shell Scripting, Command line automation labels Sep 4, 2026
@gemini-cli

gemini-cli Bot commented Sep 12, 2026

Copy link
Copy Markdown
Contributor

Hi there! Thank you for your interest in contributing to Gemini CLI.

To ensure we maintain high code quality and focus on our prioritized roadmap, we only guarantee review and consideration of pull requests for issues that are explicitly labeled as 'help wanted'.

This PR will be closed in 7 days if it remains without that designation. We encourage you to find and contribute to existing 'help wanted' issues in our backlog! Thank you for your understanding.

@gemini-cli

gemini-cli Bot commented Sep 19, 2026

Copy link
Copy Markdown
Contributor

This pull request is being closed as it has been open for 14 days without a 'help wanted' designation. We encourage you to find and contribute to existing 'help wanted' issues in our backlog! Thank you for your understanding.

This branch is waiting to be deployed

1 waiting deployment
eval-gate — f8a348bb Waiting Sep 10, 2026 by CoralGarden52 via Evaluate Steering & Regressions #1948
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/enterprise Issues related to Telemetry, Policy, Quota / Licensing area/non-interactive Issues related to GitHub Actions, SDK, 3P Integrations, Shell Scripting, Command line automation priority/p2 Important but can be addressed in a future release. size/m A medium sized PR status/pr-nudge-sent

Projects

None yet

Development

Successfully merging this pull request may close these issues.

MCP runtime policy does not normalize names or enforce an empty allowlist

1 participant