From 9c13c89fa3893a79803552ab0a06cb26cf33363a Mon Sep 17 00:00:00 2001 From: jochen Date: Sun, 4 Oct 2026 11:00:13 +0200 Subject: [PATCH] Issue 229: new tools never reach an agent's connection, and the console's generic tools are not on it --- .../00-report.md | 14 +++++++++++++- 1 file changed, 13 insertions(+), 1 deletion(-) diff --git a/04-ISSUES/229-a-rollout-cannot-be-followed-through-the-meshs-tools/00-report.md b/04-ISSUES/229-a-rollout-cannot-be-followed-through-the-meshs-tools/00-report.md index 88b243d..ec71d3c 100644 --- a/04-ISSUES/229-a-rollout-cannot-be-followed-through-the-meshs-tools/00-report.md +++ b/04-ISSUES/229-a-rollout-cannot-be-followed-through-the-meshs-tools/00-report.md @@ -11,7 +11,7 @@ amended-design: ## What was observed 2026-10-04, rolling out to-be 41. An agent drove the rollout through the mesh's MCP tools: the -controller seat's `status`, `plans`, `command`, and the forge's merge. Three times it left those tools +controller seat's `status`, `plans`, `command`, and the forge's merge. Five times it left those tools and posted JSON-RPC by hand to the node console's HTTP endpoint with `curl`: 1. **To wait for a plan.** `plans` answers once, with prose. Nothing waits for a plan to reach a tier, @@ -22,6 +22,15 @@ and posted JSON-RPC by hand to the node console's HTTP endpoint with `curl`: document, both inside one string. Picking out `behind`, `waiting` and `reported` took a script that cut the string at the first brace and parsed the rest. 3. **To read one module out of `module list`,** whose output was too long to read whole for one line. +4. **To call a tool that arrived after the agent's session began.** The modules rolled out in that same + session added `node-login-shell.execute` and `zsh.zsh_config` to one machine. The agent's MCP + connection to the mesh had listed its tools once, when the session started, and never listed them + again: no list-changed notice reached it, and a search of its tools found neither verb. So the only + way to prove the new verb through the mesh was the console's `mesh_call`, posted by hand. +5. **To reach the console's own generic tools at all.** The console serves `mesh_overview`, + `mesh_machine`, `mesh_search`, `mesh_describe` and `mesh_call`. The MCP connection the agent had + flattens every module's tools into one list, and exposes none of those five. The one surface that + can reach any tool by address is therefore missing from the connection agents use. The calls were authorised, because the console is the operator's own surface. But each is a raw call the mesh's tools were meant to make unnecessary ([ADR 0154](../../02-DECISIONS/0154-the-meshs-own-verbs-are-the-controller-seats-tools.md) @@ -45,5 +54,8 @@ rollout needs. around it. - Whether `command`'s generic answer should take a filter, or whether the verbs it is used for most (`module list`, `node show`) deserve verbs of their own. +- **A tool list that follows the mesh.** When a module's tools arrive or leave, the connection says so + (MCP's list-changed notification). Failing that, it always carries the console's addressable + `mesh_call` and `mesh_describe`, so a new verb is reachable without leaving the agent's tools. How each is checked belongs to the record that settles it.