Discover PostgreSQL databases automatically with environment-first 0.3.1 setup - #17
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Final 0.3.1 hosted verification
At head
70bf2c7f9ee86c188754cd4baf94491481bb10ae, all 12 executed hosted checks passed: Linux integration and installed npm/NuGet verification, native npm/NuGet installation on macOS and Windows, SQL fuzzing, container/dependency/secret scans, four CodeQL baseline/candidate scans and the trusted raw-SARIF regression gate. The non-PRanalyzejob was skipped by design and is not counted as a pass.GitHub rendered README review was unavailable: both immutable-commit and branch browser URLs returned GitHub’s Unicorn error page. Local link/anchor/JSON review and exact documented command/runtime smoke passed; no successful hosted-page visual review is claimed.
Environment-first 0.3.1 patch follow-on
POSTGRES_CONNECTION_STRING; primary MCP JSON contains no credentials and requires no targets file. Existing protected multi-profile files remain optional..bashrc/.zshrcfunctions; login profiles,ZDOTDIR, explicit invocation and same-shell client launch are documented. PowerShell 7.1+ must run in an interactive terminal.Local verification
--version/--helpreport 0.3.1 and environment-first setup. Documentation audit: 38 local links/anchors and 11 JSON examples valid.Hosted checks for the follow-on head passed as recorded above; historical results below still apply only to their named earlier revision.
Prior discovery-head hosted verification
At head
d9e2b0eaf8467b7d6d0e472e7f7764cb2461f499, all 12 executed hosted checks passed: Linux integration/installed-package verification, native npm/NuGet installation on macOS and Windows, coverage-guided SQL fuzzing, container/dependency/secret scanning, all four CodeQL baseline/candidate scans and the trusted raw-SARIF regression gate. The non-PR analyze job was skipped by design, not counted as a pass.Native platform proof is installation/CLI/MCP/error/shutdown; live PostgreSQL discovery/query/write proof is provided by the Linux owned disposable fixture. PR remains unmerged; 0.3.0 is locally installed, not a published release.
Problem
Per-database alias registration prevented the agent from discovering and selecting newly accessible PostgreSQL tenant databases. The user requested server-catalog discovery modeled on their
codegiveness/mssql-mcprepository and unrestricted access when no mode is supplied.Behavior
list_databasesqueries livepg_catalog.pg_database, excludes templates/disabled connections and checks CONNECT, returns{target, databases: QueryPage, access_mode, limits}. New databases require no file edits/restart.targetchooses a configured profile. No shared USE/current-database state, host/credential substitution or failure fallback.POSTGRES_DATABASESremains an optional restrictive allowlist.read_only=trueremains the SQL-call default and writes still requireread_only=false. PostgreSQL roles/RLS remain the authority.256 / PoolSizedata sources, evict idle entries, retain in-flight leases, and include capacity waits in the original deadline.Observed verification
Using the existing .NET 10.0.401 SDK with locked restores:
dotnet run --project tools/PostgreSqlMcp.Verify -c Release -p:RestoreLockedMode=true -- integrationpassed all real MCP/PostgreSQL scenarios, including immutable single-seed configuration, concurrent physical switching, live creation/CONNECT revocation, punctuation names, explicit profiles/allowlists, permissions/RLS, default unrestricted DML/DDL commit and rollback, cache churn/busy capacity/deadline recovery and cleanup. Existing SQL/metadata/HypoPG/sanitization boundaries and 129 FsCheck PostgreSQL literal scenarios passed.dotnet run --project tools/PostgreSqlMcp.Build -c Release -p:RestoreLockedMode=true -- package --output artifacts/discovery-packagesbuilt npm/NuGet 0.3.0 artifacts and five RID apphosts.dotnet run --project tools/PostgreSqlMcp.Verify -c Release -p:RestoreLockedMode=true -- packages --artifacts artifacts/discovery-packagesinstalled both artifacts into isolated locations and exercised their actual entrypoints, including live discovery/new database selection without seed edits and explicit write commit/cleanup.-dvalues containing=as connection info; isolated CLI reproduced that parser error. Fixture now uses PGDATABASE, retaining the original boundary test; the full integration and package runs above passed afterward.All database runtime evidence uses owned disposable fixtures. No operator databases were queried. Earlier README rendering/setup evidence and hosted results at e31de7b remain historical, not proof for this new runtime head.
Compatibility and limits
This broadens database reach to the configured role's existing grants and changes the default mode and listing payload. Review PUBLIC CONNECT/object grants before deployment; aliases are not a tenant isolation boundary. Existing sessions are not terminated merely by REVOKE CONNECT. Database-agnostic means PostgreSQL database independence, not multi-engine SQL support.
The release is not published; the available 0.2.0 archive lacks these features. README identifies this version boundary and source/local artifact routes. No merge, new registry publication or repository-setting change is authorized/performed by this PR. Hosted checks at 2ac00b8: Linux integration/package verification, coverage-guided SQL fuzzing, container/dependency/secret scans, four baseline/candidate CodeQL scans and the raw-SARIF comparison passed. Both native installation jobs failed because the new default package verifier requires Docker (missing executable on macOS; rejected container on Windows). Repair adds explicit --installation-only for these platform jobs: both actual installed distributions still run CLI/MCP/unavailable-endpoint checks; Linux retains full live database scenarios. Subsequent head checks are pending.
Local installation: the saved MCP command now points to installed 0.3.0. Protected targets bytes and 0600 permissions, explicit restricted mode and other MCP entries are unchanged. The saved command was exercised with a substituted owned disposable seed: MCP initialization/nine tools, live discovery after CREATE DATABASE, physical selection in a read-only transaction and clean shutdown passed. No operator database was queried.
Scanner repair: exact
Password=writer-disposableis permitted only in the maintained Packages.cs disposable fixture. Different passwords at that path and the same password outside that path failed; corrected full reachable-history scan passed before push. Published rendered README version boundary checked visually.Native-runner repair locally verified with locked restore:
packages --artifacts artifacts/discovery-packages --installation-onlypassed actual npm/NuGet installation/CLI/MCP/error/shutdown checks; the defaultpackages --artifacts artifacts/discovery-packagesthen passed the full live fixture scenarios for both distributions again. Combining --installation-only with --targets-file is rejected before installation or target access.At b232fac, Windows native installation and all Linux/security checks passed; macOS reached MCP but rejected the unavailable-endpoint error code. The fixture had relied on an owned bound, non-listening socket. Repair owns a listening loopback socket, accepts and closes each handshake, and cancels/joins its accept task on disposal. The server error mapping and exact expected connection_error assertion are unchanged. Subsequent native checks will provide platform proof.