From 1d95e3f0ee00296be0f1642a9d30fea0d4a9dc69 Mon Sep 17 00:00:00 2001 From: Dai Ha Date: Sun, 16 Aug 2026 09:46:31 +0200 Subject: [PATCH] CB-593: the portable block no longer claims a member mounts only the bridge Measured on live members: a Claude Code member also inherits the operator's user-scope MCP servers from ~/.claude.json (gitea, context7), because --mcp-config adds to that scope rather than replacing it. An opencode member gets the bridge only. The old sentence was false for one backend and true for the other. The forge tools that appear are mounted but cannot authenticate: CB-592 shadows GITEA_ACCESS_TOKEN with a blocked sentinel, so every call fails with 'invalid username, password or token'. --- 7-Use-Cases.md | 16 ++++++++++------ 1 file changed, 10 insertions(+), 6 deletions(-) diff --git a/7-Use-Cases.md b/7-Use-Cases.md index bb87fa6..10b0694 100644 --- a/7-Use-Cases.md +++ b/7-Use-Cases.md @@ -369,9 +369,9 @@ below are the procedure — run them in order, every task, not only the big ones 5. **Collect** — `bridge_poll{ticket}` → `bridge_ack{ticket, msgId}`. Answer a worker's `bridge_ask` with `bridge_send{turnId, content}` — **not** `sessionId`. A worker gone quiet is diagnosed with `bridge_status`, never by reading its terminal. -6. **Verify yourself.** Re-run the build and the checks. A worker mounts only the bridge MCP and - cannot run your other tooling, and a piped command (`… | tail`) hides failures behind a zero - exit — never promote a worker's "clean" to a fact. +6. **Verify yourself.** Re-run the build and the checks. A worker cannot run your IDE tooling, any + forge tools it appears to have hold a blocked credential and fail, and a piped command + (`… | tail`) hides failures behind a zero exit — never promote a worker's "clean" to a fact. 7. **Review — fan out.** Spawn reviewers against the diff, one per dimension or per file, with `wait:false`. Never the implementer of the scope it reviews, and brief them from the diff — not from the implementer's rationale, which carries its own blind spot. Dispatch each PR's reviewers @@ -443,9 +443,13 @@ you. without replying, the bridge scrapes your pane, and it can return only the last 4000 characters. A clipped scrape is marked as partial, but the missing text is gone — your report reaches the lead with its end cut off. -5. **Report honestly.** State only what you actually ran and its real output, including failures. - You mount **only** the bridge MCP — the primary's other servers (IDE, forge, docs) are not yours, - so never claim the result of a check you had no way to run. +5. **Report honestly.** State only what you actually ran and its real output, including failures, + and never claim the result of a check you had no way to run. **Measure your own tools; do not + assume them.** What you mount depends on your backend: an opencode member gets the bridge and + nothing else, while a Claude Code member also inherits the operator's user-scope MCP servers, + which the bridge never chose for you. Two rules follow. The primary's IDE tooling is still not + yours, whatever you see. And **a mounted tool is not a working tool** — the forge server you may + find there holds a deliberately blocked credential and fails every call, by design. 6. **Never merge.** Stage files explicitly — never `git add -A` — and leave alone anything the project marks as not-yours-to-commit.