Pin bun config for MCP server processes (#1589)

This commit is contained in:
Ashwin Bhat 2026-08-04 10:03:43 -07:00 committed by GitHub
parent b2963b9127
commit 6fb6bb6858
No known key found for this signature in database
GPG Key ID: B5690EEEBB952194
2 changed files with 58 additions and 16 deletions

View File

@ -17,6 +17,20 @@ type PrepareConfigParams = {
context: GitHubContext; context: GitHubContext;
}; };
// Build the bun invocation for one of the action's own MCP servers. The
// flags mirror the entrypoint invocation in action.yml so the server process
// reads its runtime config from the action directory rather than from the
// process working directory.
function bunServerArgs(scriptPath: string): string[] {
const actionPath = process.env.GITHUB_ACTION_PATH;
return [
"--no-env-file",
`--config=${actionPath}/bunfig.toml`,
"run",
`${actionPath}/${scriptPath}`,
];
}
async function checkActionsReadPermission( async function checkActionsReadPermission(
token: string, token: string,
owner: string, owner: string,
@ -97,10 +111,7 @@ export async function prepareMcpConfig(
if (shouldIncludeCommentServer) { if (shouldIncludeCommentServer) {
baseMcpConfig.mcpServers.github_comment = { baseMcpConfig.mcpServers.github_comment = {
command: "bun", command: "bun",
args: [ args: bunServerArgs("src/mcp/github-comment-server.ts"),
"run",
`${process.env.GITHUB_ACTION_PATH}/src/mcp/github-comment-server.ts`,
],
env: { env: {
GITHUB_TOKEN: githubToken, GITHUB_TOKEN: githubToken,
REPO_OWNER: owner, REPO_OWNER: owner,
@ -116,10 +127,7 @@ export async function prepareMcpConfig(
if (context.inputs.useCommitSigning) { if (context.inputs.useCommitSigning) {
baseMcpConfig.mcpServers.github_file_ops = { baseMcpConfig.mcpServers.github_file_ops = {
command: "bun", command: "bun",
args: [ args: bunServerArgs("src/mcp/github-file-ops-server.ts"),
"run",
`${process.env.GITHUB_ACTION_PATH}/src/mcp/github-file-ops-server.ts`,
],
env: { env: {
GITHUB_TOKEN: githubToken, GITHUB_TOKEN: githubToken,
REPO_OWNER: owner, REPO_OWNER: owner,
@ -142,10 +150,7 @@ export async function prepareMcpConfig(
) { ) {
baseMcpConfig.mcpServers.github_inline_comment = { baseMcpConfig.mcpServers.github_inline_comment = {
command: "bun", command: "bun",
args: [ args: bunServerArgs("src/mcp/github-inline-comment-server.ts"),
"run",
`${process.env.GITHUB_ACTION_PATH}/src/mcp/github-inline-comment-server.ts`,
],
env: { env: {
GITHUB_TOKEN: githubToken, GITHUB_TOKEN: githubToken,
REPO_OWNER: owner, REPO_OWNER: owner,
@ -187,10 +192,7 @@ export async function prepareMcpConfig(
} else { } else {
baseMcpConfig.mcpServers.github_ci = { baseMcpConfig.mcpServers.github_ci = {
command: "bun", command: "bun",
args: [ args: bunServerArgs("src/mcp/github-actions-server.ts"),
"run",
`${process.env.GITHUB_ACTION_PATH}/src/mcp/github-actions-server.ts`,
],
env: { env: {
// Use workflow github token, not app token // Use workflow github token, not app token
GITHUB_TOKEN: process.env.DEFAULT_WORKFLOW_TOKEN, GITHUB_TOKEN: process.env.DEFAULT_WORKFLOW_TOKEN,

View File

@ -214,6 +214,46 @@ describe("prepareMcpConfig", () => {
); );
}); });
test("should pin bun config flags before run for every bun server", async () => {
process.env.GITHUB_ACTION_PATH = "/test/action/path";
process.env.DEFAULT_WORKFLOW_TOKEN = "workflow-token";
const result = await prepareMcpConfig({
githubToken: "test-token",
owner: "test-owner",
repo: "test-repo",
branch: "test-branch",
baseBranch: "main",
allowedTools: ["mcp__github_inline_comment__create_inline_comment"],
mode: "tag",
context: {
...mockPRContext,
inputs: { ...mockPRContext.inputs, useCommitSigning: true },
},
});
const parsed = JSON.parse(result);
const servers: Record<string, string> = {
github_comment: "src/mcp/github-comment-server.ts",
github_file_ops: "src/mcp/github-file-ops-server.ts",
github_inline_comment: "src/mcp/github-inline-comment-server.ts",
github_ci: "src/mcp/github-actions-server.ts",
};
for (const [name, script] of Object.entries(servers)) {
expect(parsed.mcpServers[name]).toBeDefined();
expect(parsed.mcpServers[name].command).toBe("bun");
expect(parsed.mcpServers[name].args).toEqual([
"--no-env-file",
"--config=/test/action/path/bunfig.toml",
"run",
`/test/action/path/${script}`,
]);
}
delete process.env.DEFAULT_WORKFLOW_TOKEN;
});
test("should use current working directory when GITHUB_WORKSPACE is not set", async () => { test("should use current working directory when GITHUB_WORKSPACE is not set", async () => {
delete process.env.GITHUB_WORKSPACE; delete process.env.GITHUB_WORKSPACE;