Skip to content

chore(mcp): drop three unused settings/autonomy imports from server.ts#8423

Merged
loopover-orb[bot] merged 1 commit into
JSONbored:mainfrom
RealDiligent:fix/critical-issue-unused-imports-8339
Jul 24, 2026
Merged

chore(mcp): drop three unused settings/autonomy imports from server.ts#8423
loopover-orb[bot] merged 1 commit into
JSONbored:mainfrom
RealDiligent:fix/critical-issue-unused-imports-8339

Conversation

@RealDiligent

Copy link
Copy Markdown
Contributor

Summary

  • src/mcp/server.ts:175 imported four names from ../settings/autonomy but referenced only one. AGENT_ACTION_CLASSES, isActingAutonomyLevel, and resolveAutonomy appear nowhere else in the file (exact-identifier grep returns only the import line for each, and there is no re-export); AUTONOMY_LEVELS is genuinely used, e.g. z.enum(AUTONOMY_LEVELS) in the setActionAutonomyShape tool-input schema.
  • Narrows the import to AUTONOMY_LEVELS only.
  • This slipped past both static-analysis layers, which is why it accumulated: src/** has no ESLint config (only apps/loopover-miner-ui and apps/loopover-ui ship an eslint.config.js), and the root tsconfig.json sets neither noUnusedLocals nor noUnusedParameters.
  • packages/loopover-engine/src/settings/autonomy.ts is untouched — those exports stay exported and are used elsewhere (e.g. packages/loopover-mcp/bin/loopover-mcp.ts).
  • MAINTAIN_AUTONOMY_ACTION_CLASSES (src/mcp/server.ts:623) is deliberately not touched: it is the documented intentional divergence from AGENT_ACTION_CLASSES ("do not sync it to the engine list", packages/loopover-mcp/bin/loopover-mcp.ts:149-152), unrelated to this cleanup.

Closes #8339

Scope

  • The PR title follows type(scope): short summary Conventional Commit format, for example fix(api): restore profile access checks.
  • This PR is focused and does not mix unrelated backend, UI, MCP, docs, dependency, and deploy changes.
  • This follows CONTRIBUTING.md and does not reintroduce GitHub Pages, VitePress, site/, or CNAME.
  • I linked a currently open issue this PR resolves (e.g. Closes #123) — a linked open issue is required for every contributor PR.

Validation

  • git diff --check
  • npm run actionlint
  • npm run typecheck
  • npm run test:coverage locally; codecov/patch requires ≥99% coverage of the lines AND branches you changed (aim for 100% on your diff so CI variance does not fail near the threshold). Global coverage is a non-blocking trend with a loose 90% backstop, not the gate.
  • npm run test:workers
  • npm run build:mcp
  • npm run test:mcp-pack
  • npm run ui:openapi:check
  • npm run ui:lint
  • npm run ui:typecheck
  • npm run ui:build
  • npm audit --audit-level=moderate
  • New or changed behavior has unit/integration tests for new branches, fallback paths, and sanitizer boundaries

If any required check was skipped, explain why:

  • One-line import narrowing in src/mcp/server.ts with no behavior change, so actionlint (no workflow change), build:mcp/test:mcp-pack (this is the in-repo MCP server module, not the published packages/loopover-mcp package or its tarball), ui:* (no UI/OpenAPI change), test:workers (no worker change), and npm audit (no dependency change) are not exercised by it.
  • No new behavior to test, hence no new test: this removes references, it does not add a code path. Verified instead that nothing regressed — root tsc --noEmit is clean (the strongest signal here: an actually-used import would fail to compile once removed), and all three suites that import src/mcp/server.ts pass in full (change-guardrail, issue-plan-decomposition, issue-watch — 43 tests).
  • Codecov: the single changed line is an import statement, which is not an instrumented (DA) line, so the patch contains no coverable lines and nothing can be reported uncovered. src/mcp/server.ts still appears in the scoped run's coverage/lcov.info, so the "Verify coverage report exists" step is satisfied.

Safety

  • No secrets, wallet details, hotkeys, coldkeys, user PATs, private keys, raw trust scores, private rankings, or private maintainer evidence are exposed.
  • Public GitHub text stays sanitized, low-noise, and does not imply compensation guarantees or optimization tactics.
  • Auth, cookie, CORS, GitHub App, Cloudflare, or session changes include negative-path tests.
  • API/OpenAPI/MCP behavior is updated and tested where needed.
  • UI changes use live API data or real empty/error/loading states, not production mock/demo fallbacks.
  • Visible UI changes include a UI Evidence section below with JPG/JPEG or PNG screenshots arranged as organized, captioned, clickable thumbnails. SVG screenshots are not used as review evidence. Review-only screenshots or recordings are not committed to the repository.
  • Public docs/changelogs are updated where needed; changelogs are only edited for release-prep PRs.

UI Evidence

Not applicable — a single import-line cleanup in src/mcp/server.ts; no visible UI, frontend, docs, or extension change.

Notes

  • No MCP tool surface, schema, or runtime behavior changes: the removed names were never referenced, so the compiled module is behaviorally identical.

@RealDiligent
RealDiligent requested a review from JSONbored as a code owner July 24, 2026 12:43
AGENT_ACTION_CLASSES, isActingAutonomyLevel, and resolveAutonomy were imported
into src/mcp/server.ts but referenced nowhere in it; only AUTONOMY_LEVELS is
used. src/** has no ESLint config and the root tsconfig sets neither
noUnusedLocals nor noUnusedParameters, so neither static-analysis layer flags
this. The autonomy module's exports are unchanged (other callers use them), and
MAINTAIN_AUTONOMY_ACTION_CLASSES is deliberately left alone as the documented
intentional divergence it is.

Closes JSONbored#8339
@superagent-security

Copy link
Copy Markdown
Contributor

Superagent didn't find any vulnerabilities or security issues in this PR.

@codecov

codecov Bot commented Jul 24, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 89.92%. Comparing base (ca066b2) to head (bb0b3e2).
⚠️ Report is 5 commits behind head on main.

Additional details and impacted files
@@            Coverage Diff             @@
##             main    #8423      +/-   ##
==========================================
+ Coverage   80.15%   89.92%   +9.77%     
==========================================
  Files         791       98     -693     
  Lines       79290    23855   -55435     
  Branches    23950     4091   -19859     
==========================================
- Hits        63551    21451   -42100     
+ Misses      12382     2200   -10182     
+ Partials     3357      204    -3153     
Flag Coverage Δ
shard-1 45.86% <ø> (-7.46%) ⬇️
shard-2 40.81% <ø> (-11.65%) ⬇️
shard-3 75.71% <ø> (?)

Flags with carried forward coverage won't be shown. Click here to find out more.

Files with missing lines Coverage Δ
src/mcp/server.ts 96.60% <ø> (+22.62%) ⬆️

... and 693 files with indirect coverage changes

@loopover-orb loopover-orb Bot added the gittensor:bug Gittensor-scored bug fix — scores a 0.05x multiplier. label Jul 24, 2026
@loopover-orb

loopover-orb Bot commented Jul 24, 2026

Copy link
Copy Markdown
Contributor

Tip

✅ LoopOver review result - approve/merge recommended

Review updated: 2026-07-24 13:03:11 UTC

1 file · 1 AI reviewer · no blockers · readiness 93/100 · CI green · clean

✅ Suggested Action - Approve/Merge

  • safe to merge

Review summary
This is a minimal, single-line import cleanup in src/mcp/server.ts that narrows the import from ../settings/autonomy to only the identifier actually used (AUTONOMY_LEVELS, referenced via z.enum(AUTONOMY_LEVELS)). The PR description shows diligent grep verification that the three removed names (AGENT_ACTION_CLASSES, isActingAutonomyLevel, resolveAutonomy) are unused elsewhere in the file, and correctly distinguishes the untouched MAINTAIN_AUTONOMY_ACTION_CLASSES as an intentional divergence rather than an oversight. The change is closely tied to its linked issue and carries essentially zero behavioral risk since removed named imports with no other references are a no-op at runtime.

Nits — 3 non-blocking
  • No test coverage is added or expected for a pure dead-import removal, but this is a src/** change with zero test-path evidence — confirm the ~97% patch-coverage gate treats an unused-import deletion as untestable/excluded rather than failing the diff.
  • src/mcp/server.ts:175 — the fix is correctly scoped to the single line; no further action needed here.
  • Code changes lack test evidence — Add focused regression tests or explain why existing coverage is sufficient.

Decision drivers

  • ✅ Code review — No blockers (1 reviewer)
  • ✅ Gate result — Passing (No configured blocker found.)
Context & advisory signals — never blocks the verdict
Signal Result Evidence
Linked issue ✅ Linked #8339
Related work ✅ No active overlap found No same-issue or scoped active PR overlap found.
Change scope ✅ 20/20 Low review scope from cached public metadata (1 linked issue).
Validation posture ✅ 25/25 PR body includes validation/test evidence.
Contributor workload ✅ 10/10 Author activity: 354 registered-repo PR(s), 137 merged, 37 issue(s).
Contributor context ✅ Confirmed Gittensor contributor RealDiligent; Gittensor profile; 354 PR(s), 37 issue(s).
Improvement ℹ️ None detected risk: low · value: none · LLM: minor
Linked issue satisfaction

Addressed
The diff trims the import at server.ts:175 to only AUTONOMY_LEVELS, exactly matching the issue's requested change, and leaves the autonomy.ts module and MAINTAIN_AUTONOMY_ACTION_CLASSES untouched as required.

Review context
  • Author: RealDiligent
  • Role context: outside_contributor
  • Public audience mode: oss maintainer
  • Lane context: Repository is configured for direct PR review.
  • Public profile languages: not available
  • Official Gittensor activity: 354 PR(s), 37 issue(s).
  • PR-specific overlap: none found.
Contributor next steps
  • Start here: Triage stale or unlinked PRs.
Signal definitions
  • Related work = same linked issue, overlapping active PRs, or title/path similarity.
  • Change scope = cached public metadata such as size labels, draft state, and review-burden hints.
  • Validation posture = whether the PR provides enough public validation/test evidence for maintainer review.
  • Contributor workload = public contributor activity and cleanup pressure, not a repo-wide quality failure.
  • Contributor context = public GitHub/Gittensor identity context; non-Gittensor status is not a blocker.
🧪 Chat with LoopOver

Ask LoopOver a question about this PR directly in a comment — grounded only in the same cached, public-safe facts shown above, never a new claim.

  • @loopover ask &lt;question&gt; answers contribution-quality Q&A with source citations and freshness.
  • @loopover chat &lt;question&gt; answers in natural prose from cached decision-pack facts via local inference (maintainer/collaborator; read-only).
  • A plain-language @loopover mention with a real question is routed to the closest matching read-only command automatically — no exact syntax required.

Full command reference: https://loopover.ai/docs/loopover-commands

🧪 Experimental — new and may change.

🟩 Safe / merged · 🟦 Advisory · 🟨 Held for review · 🟥 Blocked / closed


💰 Earn for open-source contributions like this. Gittensor lets GitHub contributors earn for the work they already do — register to start earning →.

Checked by LoopOver, a quiet PR intelligence layer for OSS maintainers.

  • Re-run LoopOver review

@loopover-orb loopover-orb Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LoopOver approves — the gate is satisfied and CI is green.

@loopover-orb
loopover-orb Bot merged commit bf2270e into JSONbored:main Jul 24, 2026
12 checks passed
@github-actions github-actions Bot mentioned this pull request Jul 24, 2026
12 tasks
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

gittensor:bug Gittensor-scored bug fix — scores a 0.05x multiplier.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

src/mcp/server.ts imports 3 unused identifiers from settings/autonomy

1 participant