Skip to content

Releases: dolibali/mcp-dev-runtime

v1.2.0

Choose a tag to compare

@github-actions github-actions released this 21 Sep 02:55

MCP Dev Runtime v1.2.0

Native Windows support with isolated platform backends, self-contained x64 and ARM64 ZIPs, and unchanged macOS/Linux tool contracts.

Downloads / 下载

Choose the architecture of the computer where MDR will run:

Archive Native release acceptance baseline
mcp-dev-runtime-1.2.0-darwin-arm64.tar.gz Apple Silicon; macOS 14
mcp-dev-runtime-1.2.0-darwin-x64.tar.gz Intel Mac; macOS 15
mcp-dev-runtime-1.2.0-linux-x64-gnu.tar.gz Ubuntu 22.04 x64; glibc and GCC 12 libstdc++
mcp-dev-runtime-1.2.0-linux-arm64-gnu.tar.gz Ubuntu 22.04 ARM64; glibc and GCC 12 libstdc++
mcp-dev-runtime-1.2.0-win32-x64.zip Windows Server 2025 x64; additional local Windows 11 testing
mcp-dev-runtime-1.2.0-win32-arm64.zip Windows 11 ARM64; native runner required

Every package includes Node.js 24.21.0, production dependencies and the runtime-only Tunnel from commit 70bb5a7e1305596f0216d7b18d0b7765d58576d5. Windows packages additionally contain the native mdr-windows-host.exe adapter and the matching image-processing prebuild. End users do not need to install Node, npm, Go, MSVC, Git Bash or WSL to run MDR. Development tools used by your own tasks remain your responsibility.

SHA256SUMS covers all six archives. VERIFICATION.json records the exact source commit and per-platform acceptance. GitHub build provenance is generated independently for each package. Publishing requires all six native builds and package checks to succeed; ARM64 cross-compilation alone is not sufficient.

Publisher code signing and Apple notarization remain intentionally skipped. Build provenance is not an OS publisher signature. Installers do not bypass execution policy, antivirus, Gatekeeper or other system protections.

Windows features

  • Use the same six stable MCP tools over HTTP or stdio. PowerShell 7 is preferred when installed; otherwise Windows PowerShell 5.1 is used. No second agent or model is invoked.
  • Native pipe execution and ConPTY interaction preserve UTF-8, real exit codes, output continuation and session history. Each task starts suspended, is assigned to an owned Job Object, and is resumed only after containment succeeds.
  • Parent disconnection, cancellation and normal task completion clean owned descendants. Blocked terminal input cannot prevent the control channel from handling EOF or termination. Windows termination is not represented as a fabricated Unix signal.
  • Private Windows DACLs, authenticated named-pipe control and orderly MCP shutdown protect configuration/state and flush history. Patches preserve destination access rules and CRLF; case-alias conflicts are rejected before writing.
  • Preserve exact destination DACL inheritance flags even when Windows normalizes legacy ACLs during replacement. A metadata error after content replacement is reported as a partial change; it is not hidden as an untouched file.
  • install.ps1 / uninstall.ps1 operate per user. Native command wrappers preserve arguments without CMD reparsing. Atomic current.json version pointers allow upgrades and rollback without junction privileges or overwriting loaded executables.
  • Complete removal requires explicit y / Y, uses a temporary runtime to avoid Windows executable locks, and preserves source checkouts, external custom data paths and shared Skills.

Compatibility and reliability

The tool contract remains 3.1, the six stable defaults and existing schemas remain unchanged, and local Skill tools remain opt-in. Existing unified and legacy split configurations are preserved. macOS/Linux retain their POSIX process backends and do not load the Windows native adapter.

Lifecycle relative deadlines now use monotonic time. This corrects premature or prolonged timeouts caused by wall-clock adjustments, reproduced during repeated Linux/WSL startup checks; normal recorded timestamps are unchanged.

PowerShell is not Bash: Windows PowerShell 5.1 does not support && / ||. CMD/batch commands can be called inside PowerShell but cmd.exe is not a direct MDR shell backend in this release. Long-lived tasks must retain their active session: completing a command also cleans its detached descendants. Older programs emitting non-UTF-8 OEM output need their own encoding configuration; MDR does not guess.

Install and upgrade

Download the matching archive and SHA256SUMS, compare the full hash, then extract it.

Windows, from PowerShell in the extracted directory:

.\install.ps1

macOS/Linux:

./install.sh

Fill the private runtime.env locally with your own Tunnel ID and API key. Then use mdr start --bg, mdr doctor and mdr smoke. Set tunnel.enabled=false in unified configuration for local-only MCP without Tunnel credentials. Installation never starts or migrates a live service automatically.

If the command directory is not on PATH, follow the installer's instructions for your user PATH; no system PATH is changed. Windows defaults to %LOCALAPPDATA%\Programs\mcp-dev-runtime\bin, with private data under %LOCALAPPDATA%\mcp-dev-runtime.

Before upgrading or rolling back, review active tasks and stop the selected managed instance. Run the trusted package's installer with the same prefix/bin selection. Previous program versions and existing configuration are retained; published v1.0.0, v1.0.1 and v1.1.0 assets are not replaced.

Windows guide · Windows 中文指南 · macOS/Linux installation

Validation and limits

The development checkpoint passed 253 source tests on macOS ARM64 and Linux x64 (Ubuntu 24.04 under existing WSL2), 35 Windows x64 source tests, two native Go tests, 18 Mac package groups and 15 Windows package groups. Release CI independently rebuilds and tests the exact clean commit on all six native targets; the attached VERIFICATION.json is the release-specific record.

Local tests use isolated homes, workspaces and synthetic credentials. Mock/local Tunnel lifecycle or SDK success does not establish a real ChatGPT/WAN round trip on every OS. Model Skill selection, standard-user versus administrator environments, old Windows versions, sleep/wake and multi-day reliability remain separate acceptance scopes. No sandbox, multi-user isolation, Windows boot service or automatic dependency installation is added.

中文摘要

v1.2.0 新增 Windows x64 和 ARM64 原生运行包,支持 PowerShell、ConPTY、真实退出码和 UTF-8 输出、自有进程树管理、命名管道生命周期、私人 DACL、完整安装卸载及版本回退。运行包内置 Node、Tunnel 和对应架构依赖,不需要用户安装 Go、MSVC、Git Bash 或 WSL。

现有 macOS/Linux 后端、六个稳定工具及契约 3.1 保持兼容,Skill 仍需主动启用。另修复系统校时导致生命周期等待错误的问题。正式发布要求六个平台分别完成原生构建和最终安装包验收,ARM64 不以交叉编译代替运行证明。发布者签名及 Apple 公证继续跳过,现有发行版附件保持不变。

v1.1.0

Choose a tag to compare

@github-actions github-actions released this 20 Sep 17:07

MCP Dev Runtime v1.1.0

Optional local Skill discovery and reading, with unchanged six-tool defaults and no additional agent/model calls. This is a regular release; the two new Skill tools are explicitly experimental and disabled by default.

Downloads / 下载

Archive Native acceptance baseline
mcp-dev-runtime-1.1.0-darwin-arm64.tar.gz Apple Silicon, macOS 14
mcp-dev-runtime-1.1.0-darwin-x64.tar.gz Intel Mac, macOS 15
mcp-dev-runtime-1.1.0-linux-x64-gnu.tar.gz Ubuntu 22.04 x64, glibc + GCC 12 libstdc++
mcp-dev-runtime-1.1.0-linux-arm64-gnu.tar.gz Ubuntu 22.04 ARM64, glibc + GCC 12 libstdc++

Each archive includes Node.js 24.21.0, compiled MDR, production native dependencies, the pinned YAML parser 2.9.1, and tunnel-client-runtime from 70bb5a7e1305596f0216d7b18d0b7765d58576d5. No system Node/npm/Go/compiler is needed to install or run MDR. Development tools required by your projects remain your responsibility.

SHA256SUMS covers the four final archives. VERIFICATION.json contains per-platform acceptance records. Each archive includes a file-hash manifest, component licenses and SPDX inventory; GitHub build provenance is generated separately.

Publisher code signing and Apple notarization remain deliberately skipped. The existing signing integration boundary is preserved. The installer does not disable or bypass operating-system protections.

What's new

  • Add two read-only, opt-in experimental MCP tools: discover_skills finds relevant metadata, and read_skill reads complete SKILL.md instructions and selected UTF-8 reference files. Neither tool executes scripts, installs dependencies, starts another agent or calls a model API.
  • Discover user roots ~/.agents/skills, $CODEX_HOME/skills (normally ~/.codex/skills) and existing .system skills. Discover project .agents/skills and compatibility .codex/skills roots within the current Git/worktree boundary. Explicit additional roots and disabled paths are supported.
  • Add bounded metadata search using weighted BM25/Han matching, canonical-path deduplication, explicit same-name disambiguation, lazy shared caches and scoped/versioned continuation cursors. Resource traversal, escaping links, special files, invalid text and over-budget reads fail explicitly.
  • Respect implicit-invocation policy from agents/openai.yaml; malformed policy is conservative. Skill dependencies are informational, never automatic authorization or installation instructions.
  • Add short task-level MCP guidance only when the Skill tools are enabled. New substantive tasks should discover once; explicitly named skills may be read directly; selected instructions must be read completely. Simple checks, output polling and unchanged-task continuations avoid repeated discovery.
  • Ship service-style start, stop, safe restart, and the --bg shorthand. Existing up, down and --background remain supported.
  • Add bilingual Skill guidance, lazy-loading/scope/resource-safety tests, HTTP/stdio and extracted-package checks, plus an interleaved Skill benchmark.

Compatibility and opt-in behavior

The original six tools retain their names and input/output schemas. Their default instructions are unchanged when Skills are disabled. The existing stable tool contract remains 3.1; two additional experimental tool definitions are advertised only when explicitly included in tools.allow.

Existing unified and legacy split configuration remains supported. Installation and upgrade preserve configuration: they do not enable Skills, move existing data, change Tunnel IDs or restart the user's active deployment automatically. Review active tasks and stop the selected managed service before upgrading.

To enable Skills after upgrading, merge the two additional names into the existing allowlist; do not replace unrelated settings:

{
  "tools": {
    "allow": [
      "exec_command",
      "write_stdin",
      "apply_patch",
      "view_image",
      "list_exec_sessions",
      "terminate_exec_session",
      "discover_skills",
      "read_skill"
    ]
  }
}

No separate skills configuration is needed for default roots. Optional skills.extra_roots and skills.disabled_paths can be configured in the same JSON file. Inspect the effective policy with mdr tools and non-secret settings with mdr config.

After a deliberate restart, refresh tools in the MCP client and test in a new conversation. No native ChatGPT Skill-upload interface is required. Skill file changes are picked up by an explicit refresh or the next request after cache expiry; no permanent filesystem watcher or periodic background scanner is added.

Installation and uninstall

Verify the full archive hash against SHA256SUMS, extract the archive for your platform, and run ./install.sh without sudo. The runtime package includes its own Node and pinned Tunnel. ./uninstall.sh requires interactive y confirmation for complete MDR-owned removal; shared user Skill roots are not owned or deleted by MDR.

English installation · 中文安装 · Local Skills · 本机 Skill

Verification scope and limitations

Every published platform archive must pass the full source regression, CLI/static checks and native extracted-package verification. Package acceptance includes the existing 20 real-tool checks, isolated opt-in Skill discovery/reading/pagination using bundled dependencies, and install/upgrade/rollback/uninstall behavior. VERIFICATION.json is the record for the final published artifacts.

Hosted-client automatic Skill selection is not certified by SDK tests: prompting, refresh behavior, actual trigger/selection accuracy, model-context costs and Tunnel WAN latency require separate ChatGPT acceptance. Benchmarks are local measurements, not an identical-to-Codex success-rate or latency guarantee. The service does not intercept user messages or force Skill discovery before ordinary tool execution.

Skill text reaches the connected client/model. Skill policies and the tool allowlist do not replace an OS sandbox or expand user authorization. Windows, Alpine/musl, automatic boot services and multi-user isolation remain outside this release. CI uses explicit mock/isolated Tunnel lifecycle tests, not private credentials or real cloud round trips on every platform.

中文摘要

v1.1.0 新增需要主动启用的 discover_skills、read_skill,支持全局与项目目录发现、相关候选搜索、完整指令和引用文件读取,以及有界缓存与 UTF-8 分页。默认仍只有原来的六个工具,原 schema 不变;不调用 Codex、其他 Agent 或模型,也不自动安装或执行 Skill 中的脚本。

本版同时包含 start、stop、安全 restart 和 --bg;旧命令继续兼容。新旧配置均保留,升级不会自动开启 Skill 或重启现有实例。需要启用时,把两个工具名加入已有 tools.allow,检查活动任务后主动重启,再刷新 ChatGPT 工具。

四个平台分别原生构建并验收,附校验文件和验证记录;签名和 Apple 公证仍跳过。网页版模型是否自然地主动选择 Skill,需要单独验证,不能由本地 SDK 或安装包测试代替。

v1.0.1

Choose a tag to compare

@github-actions github-actions released this 20 Sep 14:50

MCP Dev Runtime v1.0.1

Patch release focused on safer installation lifecycle, simpler configuration, and fail-closed tool exposure while preserving the existing six-tool contract.

Downloads / 下载

Choose the archive matching the computer where commands will run:

Package Native verification baseline
mcp-dev-runtime-1.0.1-darwin-arm64.tar.gz Apple Silicon, macOS 14
mcp-dev-runtime-1.0.1-darwin-x64.tar.gz Intel Mac, macOS 15
mcp-dev-runtime-1.0.1-linux-x64-gnu.tar.gz Ubuntu 22.04 x64, glibc + GCC 12 libstdc++
mcp-dev-runtime-1.0.1-linux-arm64-gnu.tar.gz Ubuntu 22.04 ARM64, glibc + GCC 12 libstdc++

Each archive contains Node.js 24.21.0, the compiled application, production native dependencies, and tunnel-client-runtime from commit 70bb5a7e1305596f0216d7b18d0b7765d58576d5. SHA256SUMS covers the final archives, VERIFICATION.json records per-platform package checks, and GitHub build provenance is generated for each archive.

Publisher code signing and Apple notarization are deliberately skipped in v1.0.1. The release workflow keeps the signing boundary fail-closed for future integration; the installer does not bypass Gatekeeper or other OS security controls.

What's new

  • Add a complete interactive ./uninstall.sh. It requires an explicit y, safely stops the owned managed instance, removes MDR-owned program versions, commands, configuration/credentials, state/history, logs and cache, and never deletes a source Git checkout itself.
  • New installations use one non-secret config.json plus private runtime.env. Existing v1.0.0-style launcher.config.json + config.json installations remain supported as legacy-split and are not migrated automatically.
  • Add fail-closed tools.allow. The same six stable MCP tools remain enabled by default; disabled tools are absent from MCP discovery and rejected again by Runtime before side effects. Unknown, duplicate and wildcard tool names are rejected.
  • Add tunnel.enabled. When false, managed startup runs only the local MCP service without Tunnel credentials, Tunnel binary resolution or a Tunnel health listener.
  • Add mdr config [--json] and mdr tools [--json] for read-only effective configuration/tool-policy inspection without exposing runtime.env contents.
  • Preserve the existing tool contract at 3.1 and keep all six established tool schemas unchanged.

Compatibility

v1.0.1 is designed as a compatible patch upgrade from v1.0.0. Existing split configuration is honored without automatic rewriting. New unified configuration is used only for new installs or when explicitly selected. The pinned upstream Tunnel commit and tool contract are unchanged.

Stop the selected managed instance and review active tasks before switching versions. The versioned installer preserves existing configuration and previous installed versions so rollback remains available.

Installation

Download the matching archive and SHA256SUMS, verify the full hash, extract the archive, then run:

./install.sh

Fill your own Tunnel ID/API key in the generated private runtime.env, then use mdr up --background, mdr doctor and mdr smoke. For local-only operation, set tunnel.enabled to false in the unified config.

English installation guide · 中文安装指南

Validation summary

Release preparation passed the full source regression suite, CLI verification, static release checks, local benchmark, secret scan, and an Apple Silicon package acceptance run. The native release workflow independently rebuilds and verifies all four platform archives before the draft can be published. Package verification includes real execution of all six MCP tools, HTTP/stdio, PTY, images, patching, history, upgrade/rollback and complete uninstall behavior.

Windows, Alpine/musl, publisher signing/notarization, automatic OS boot services and multi-user isolation remain outside this release. CI uses mock/isolated Tunnel lifecycle checks and does not claim a real ChatGPT/WAN round trip on every platform.

中文摘要

v1.0.1 重点完善安装与配置体验:新增完整 uninstall.sh;新安装统一为一份非敏感 config.json 加私有 runtime.env;加入 fail-closed 的 tools.allow,默认仍只暴露现有 6 个稳定工具;支持 tunnel.enabled=false 的纯本地 MCP 模式;新增 mdr config / mdr tools 查看实际配置与工具策略。v1.0.0 的旧 split 配置继续兼容,不会自动迁移。

本版工具契约仍为 3.1,固定 Tunnel commit 不变。发布者签名和 Apple 公证仍按计划暂时跳过。正式发布附件由四个平台原生 Runner 分别构建和验收后汇总。

v1.0.0

Choose a tag to compare

@github-actions github-actions released this 20 Sep 12:18

MCP Dev Runtime v1.0.0

First stable release, distributed as platform-specific, self-contained runtime packages.

Downloads / 下载

Choose the archive matching the computer where commands will run:

Package Native verification baseline
mcp-dev-runtime-1.0.0-darwin-arm64.tar.gz Apple Silicon, macOS 14
mcp-dev-runtime-1.0.0-darwin-x64.tar.gz Intel Mac, macOS 15
mcp-dev-runtime-1.0.0-linux-x64-gnu.tar.gz Ubuntu 22.04 x64, glibc + GCC 12 libstdc++
mcp-dev-runtime-1.0.0-linux-arm64-gnu.tar.gz Ubuntu 22.04 ARM64, glibc + GCC 12 libstdc++

Each archive contains Node.js 24.21.0, the compiled application, production native dependencies, and tunnel-client-runtime from commit 70bb5a7e1305596f0216d7b18d0b7765d58576d5. No system Node/npm/Go/compiler is required to install or run MDR. SHA256SUMS covers the final archives; each archive includes BUILD-MANIFEST.json, SBOM.spdx.json and third-party notices/licenses. VERIFICATION.json records the per-platform package checks. GitHub build provenance is attached separately.

Publisher code signing and Apple notarization are deliberately skipped in v1.0.0. These are unsigned distributions, not OpenAI official binaries. A signing boundary is reserved in the build pipeline. macOS may require user approval; the installer does not bypass OS security.

What's included

  • Six direct MCP tools for shell commands, interactive PTYs, file patches, images, session queries and owned-process termination; HTTP and stdio transports, with optional ChatGPT Secure MCP Tunnel.
  • Bounded execution history, opt-in output capture, archived tail/search, retry deduplication and truthful exit/partial-change reporting. Tool contract remains 3.1.
  • User-level installer: private configuration and logs outside the program tree, versioned installation with atomic current switching, idempotent configuration preservation, and active-instance upgrade protection. mdr is auto-registered only when conflict-free; the canonical command remains mcp-dev-runtime.
  • Concise status, detailed status --verbose, full status --json, paths reporting only effective locations, and uptime including seconds.
  • English and Simplified Chinese installation, ChatGPT onboarding and troubleshooting documentation.

Installation

Download the correct archive and SHA256SUMS, compare its SHA-256, extract it, then run the included ./install.sh without sudo. Follow the printed PATH instruction when needed, fill your own Tunnel ID/API key in the generated private runtime.env, then use mdr up --background, mdr doctor and mdr smoke.

English installation guide · 中文安装指南

Upgrade and limitations

Stop the selected instance and review active work before changing installed versions. Existing configuration and previous versions are preserved. Source checkouts remain project-local and are not automatically migrated or re-registered; an existing source command is never overwritten. No npm publication is part of this release.

Windows, Alpine/musl, older untested OS versions, publisher signing/notarization, automatic OS boot services and multi-user isolation are not included. The runtime executes with the current user's permissions; it is not a sandbox or an approval layer. Keep the MCP listener on loopback and connect trusted clients only. Test evidence distinguishes the actual bundled Tunnel identity from mocked lifecycle tests: CI does not use real user Tunnel credentials and does not claim a real ChatGPT/WAN round trip on every platform.

中文摘要

首个稳定发行版提供四种平台预编译运行包,内置 Node、原生依赖和固定 commit 的 Tunnel,不再要求普通用户安装编译工具。安装器按用户目录分离配置、日志和程序版本;无冲突时自动注册 mdr,升级和重复安装保留配置,活动服务未停止时拒绝切换。

本版按要求暂不进行发布者签名和 Apple 公证,但保留以后接入的流水线步骤。下载后先核对 SHA256SUMS;解压执行 ./install.sh,填写自己的凭据后再启动。源码版不会自动迁移,npm 和 Windows 暂不发布。具体构建与验收记录见附件 VERIFICATION.json;CI 的模拟 Tunnel 测试不冒充各平台真实 ChatGPT 连接验证。