diff --git a/mcp_server.md b/mcp_server.md index f5c3df8..d4cfeca 100644 --- a/mcp_server.md +++ b/mcp_server.md @@ -178,9 +178,33 @@ judged by where it points. Two arguments are deliberately **not** confined: `binary` (the `qelectrotech` executable) and `elements_dir` (the element collection). -Those are configuration, chosen once by whoever runs the server, and both -normally live in `/usr` or a build tree — outside any sensible workspace. -Confining them would reject the ordinary case while stopping nothing. +**This changes with the PR below.** + +#### The program the server runs + +> **Status: pending.** This section describes +> [PR #1129](https://github.com/qelectrotech/qelectrotech-source-mirror/pull/1129), +> not yet merged. Nothing here works until that lands — check the PR +> before trying any of this against your own build. This section will drop +> this notice once it does. + +Before this change, `binary` was taken from each tool call and whatever +executable file it named was run, with the call's own paths as arguments. +Text inside a project from someone else could therefore steer an assistant +into starting another program. Now the server finds QElectroTech itself +and a call cannot choose: + +| Variable | Effect | +|---|---| +| `QET_BINARY` | the QElectroTech the tools launch. Without it: `qelectrotech` on `PATH`, else the installation the server sits in (`/share/qelectrotech/mcp/qet_mcp.py`) | +| `QET_MCP_BINARIES` | other executables a call may name as `binary`, separated like `QET_MCP_WORKSPACE` — for comparing two builds | +| `QET_MCP_ALLOW_ANY_BINARY=1` | turns the check off: a call can then run any program | +| `QET_MCP_ELEMENTS` | element collections a call may name as `elements_dir`, besides the workspace and the installed one | + +`binary` can be left out of every call. When given, it must be the same file +(after following symlinks) or one listed in `QET_MCP_BINARIES`; anything else +is refused, even a file inside the workspace. A setup that relied on passing +a program that is not on `PATH` needs `QET_BINARY` in its `env` block. **Nothing is overwritten unasked.** `qet_export`, `qet_edit`, `qet_project_new` and `qet_element_build` refuse an `output` that already