fa570ab32a
Resolve who is calling an MCP tool from the connection, not a spoofable argument (per docs/MCP-Contract.md). ConnectionIdentity ties the loopback peer PID (LsofPeerPidLookup) to a herdr pane (PaneLocator via pane.list/pane.process_info) → the caller's terminal_id; a caller owning no pane is the primary. bridge_reply now takes only content and resolves the worker from the connection (no sessionId). Live-verified: real PID→pane (contract test), and a non-pane MCP caller correctly gets a workers-only error. Single-host; the token path stays the split-host fallback. 58 tests green, IDE-clean.
14 lines
494 B
Java
14 lines
494 B
Java
package dev.ltms.bridged.mcp;
|
|
|
|
/**
|
|
* Resolves the OS PID that owns a loopback TCP source port — the OS half of connection-based MCP
|
|
* identity. Java exposes no peer PID for a TCP socket, so this shells out. Injectable so
|
|
* {@link ConnectionIdentity} is testable without a real connection.
|
|
*/
|
|
@FunctionalInterface
|
|
public interface PeerPidLookup {
|
|
|
|
/** The PID whose socket has local (source) {@code port} on loopback, or {@code -1} if unknown. */
|
|
long pidForLocalPort(int port);
|
|
}
|