Files
DottaandPaperclip 7b35de65aa feat(mcp) [split 1/8]: add fixture demo servers (#9556)
## Thinking Path

> - Paperclip is the open source app people use to manage AI agents for
work
> - Governed MCP access spans contracts, runtime enforcement, adapters,
UI surfaces, and operator verification
> - The parity reference PR #9534 is too large for effective automated
or human review
> - The feature therefore needs a linear stack whose individual diffs
stay below the 100-file review limit
> - This pull request is split 1/8 and focuses on fixture and demo MCP
servers
> - The benefit is a standalone, testable review boundary while
preserving byte-for-byte parity at the top of the stack

## Linked Issues or Issue Description

- Related parity reference: #9534
- Problem: Developers need deterministic local MCP fixtures and visible
demo servers without pulling in the governed production runtime.
- Proposed solution: Adds the Google Sheets and KV demo MCP packages,
fixture catalog/servers, smoke harness, guide, and the root
smoke/typecheck registration hunks.
- Alternatives considered: keeping #9534 as one 403-file review, or
rewriting the feature to manufacture seams; both were rejected in favor
of path extraction plus compile-driven boundary moves.
- Roadmap alignment: this advances the existing governed MCP/tool-access
work already represented by #9534; it does not introduce a separate
roadmap initiative.
- Stack position: base branch is `master`.
- Merge policy: merge bottom-up, in order, only after the complete
eight-PR stack has been reviewed and the top-of-stack parity gate
remains empty.
- Requested review: QA for fixture and smoke coverage; Greptile on every
PR.

## What Changed

- Adds the Google Sheets and KV demo MCP packages, fixture
catalog/servers, smoke harness, guide, and the root smoke/typecheck
registration hunks.
- Keeps this PR below 100 changed files and independently typecheckable.
- Preserves the final tree from #9534 when combined with the other seven
stack levels.

## Verification

- `pnpm typecheck`
- `pnpm --filter @paperclipai/google-sheets-mcp-server test` — 27 tests
passed
- `pnpm --filter @paperclipai/kv-demo-mcp-server test` — 12 tests passed

## Risks

- The new packages add dependencies that are intentionally not committed
to `pnpm-lock.yaml`, per repository policy.
- Stack risk: merging out of order can expose incomplete layers;
mitigate by following the documented bottom-up merge policy.
- Parity risk: later edits to an intermediate branch can drift from
#9534; mitigate by re-running the empty top-of-stack diff before merge.

> For core feature work, check [`ROADMAP.md`](ROADMAP.md) first and
discuss it in `#dev` before opening the PR. Feature PRs that overlap
with planned core work may need to be redirected — check the roadmap
first. See `CONTRIBUTING.md`.

## Model Used

- OpenAI Codex, exact model ID `gpt-5.4`; runtime-managed context
window; medium reasoning with repository, shell, Git, GitHub CLI, and
code-execution tools enabled.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] Internal references are omitted except the execution-plan link
explicitly required for this coordinated split stack
- [x] My branch name describes the change and contains no internal
Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [ ] All Paperclip CI gates are green
- [ ] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge


## Stack Coordination

- Internal execution plan:
[PAP-13874](/PAP/issues/PAP-13874#document-plan)
- Parity reference: #9534
- Stack: #9556 → #9557 → #9558 → #9559 → #9560 → #9561 → #9562 → #9563
- Merge bottom-up only after full-stack review and an empty parity diff
at #9563.

---------

Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-07-14 12:56:21 -05:00

169 lines
4.6 KiB
JavaScript

#!/usr/bin/env node
import { spawn } from "node:child_process";
import { randomUUID } from "node:crypto";
import { createInterface } from "node:readline";
const sessions = new Map();
const childProcesses = new Set();
function writeMessage(message) {
process.stdout.write(`${JSON.stringify(message)}\n`);
}
function withTimeout(promise, label, timeoutMs = 5_000) {
return Promise.race([
promise,
new Promise((_, reject) => {
const timer = setTimeout(() => reject(new Error(`${label} timed out`)), timeoutMs);
timer.unref();
}),
]);
}
async function inspectStdioServer(server) {
if (!server || typeof server !== "object" || "type" in server) {
throw new Error("ACP isolation fixture only supports stdio MCP servers");
}
const serverEnv = Object.fromEntries(
(server.env ?? []).map((entry) => [entry.name, entry.value]),
);
const child = spawn(server.command, server.args ?? [], {
env: { ...process.env, ...serverEnv },
stdio: ["pipe", "pipe", "pipe"],
});
childProcesses.add(child);
let nextId = 1;
const pending = new Map();
const lines = createInterface({ input: child.stdout });
lines.on("line", (line) => {
let message;
try {
message = JSON.parse(line);
} catch {
return;
}
const waiter = pending.get(message.id);
if (!waiter) return;
pending.delete(message.id);
if (message.error) waiter.reject(new Error(message.error.message));
else waiter.resolve(message.result);
});
const request = (method, params = {}) =>
withTimeout(
new Promise((resolve, reject) => {
const id = nextId++;
pending.set(id, { resolve, reject });
child.stdin.write(`${JSON.stringify({ jsonrpc: "2.0", id, method, params })}\n`);
}),
`MCP ${method}`,
);
await request("initialize", {
protocolVersion: "2024-11-05",
capabilities: {},
clientInfo: { name: "paperclip-acp-isolation-fixture", version: "1.0.0" },
});
child.stdin.write(`${JSON.stringify({ jsonrpc: "2.0", method: "notifications/initialized" })}\n`);
const toolsResult = await request("tools/list");
return {
child,
observation: {
name: server.name,
tools: toolsResult.tools.map((tool) => tool.name),
},
};
}
async function handleRequest(request) {
if (request.method === "initialize") {
return {
protocolVersion: 1,
agentCapabilities: {
loadSession: false,
mcpCapabilities: { http: false, sse: false },
sessionCapabilities: { close: {} },
},
agentInfo: { name: "paperclip-acp-isolation-fixture", version: "1.0.0" },
};
}
if (request.method === "session/new") {
const sessionId = randomUUID();
const inspected = await Promise.all(
(request.params?.mcpServers ?? []).map(inspectStdioServer),
);
sessions.set(sessionId, inspected);
return { sessionId };
}
if (request.method === "session/prompt") {
const sessionId = request.params.sessionId;
const observations = (sessions.get(sessionId) ?? []).map((entry) => entry.observation);
writeMessage({
jsonrpc: "2.0",
method: "session/update",
params: {
sessionId,
update: {
sessionUpdate: "agent_message_chunk",
content: { type: "text", text: JSON.stringify(observations) },
},
},
});
return { stopReason: "end_turn" };
}
if (request.method === "session/close") {
const inspected = sessions.get(request.params.sessionId) ?? [];
sessions.delete(request.params.sessionId);
for (const entry of inspected) entry.child.kill("SIGTERM");
return {};
}
if (request.method === "session/cancel") return null;
if (request.method === "session/set_mode" || request.method === "session/set_config_option") {
return {};
}
throw new Error(`Unsupported ACP method: ${request.method}`);
}
const lines = createInterface({ input: process.stdin });
lines.on("line", async (line) => {
let request;
try {
request = JSON.parse(line);
const result = await handleRequest(request);
if (request.id !== undefined && result !== null) {
writeMessage({ jsonrpc: "2.0", id: request.id, result });
}
} catch (error) {
if (request?.id !== undefined) {
writeMessage({
jsonrpc: "2.0",
id: request.id,
error: { code: -32603, message: String(error?.message ?? error) },
});
}
}
});
function cleanup() {
for (const child of childProcesses) child.kill("SIGTERM");
}
process.on("exit", cleanup);
process.on("SIGINT", () => {
cleanup();
process.exit(0);
});
process.on("SIGTERM", () => {
cleanup();
process.exit(0);
});