Skip to content
900 linesCodeBlameRaw
1//! The MCP server's tools: a few resource tools, each with an `action`.
2//!
3//! Every operation is one action of one tool. A call is dispatched to the
4//! operation it names, so permissions, the audit log, billing and outcomes
5//! are exactly those of the REST API. A token sees only the actions its
6//! scopes allow, and a tool none of whose actions it may use is not listed.
7//!
8//! The listed input schema is one flat object: `action`, then every field
9//! any of its actions takes. Which fields each action needs is in the
10//! `action` field's description and checked on every call. Claude's API,
11//! and so most MCP clients, refuse a tool whose input schema has `oneOf`
12//! at its top level, so the schema keyed by action, with each action's
13//! required fields, is [`discriminated`], published on the server's card
14//! and in the docs.
15
16use g1t_contracts::credentials::NEVER;
17use g1t_contracts::identity::AgentScope;
18use g1t_contracts::scopes::{Level, NO_SCOPE, TokenAccess, scope_for};
19use serde_json::{Map, Value, json};
20
21use crate::deployments::DeploymentsOp;
22use crate::operations::Op;
23use crate::rules::RulesOp;
24use crate::security::SecurityOp;
25
26pub struct Action {
27 pub name: &'static str,
28 pub op: Op,
29 /// One line, for the `action` field's description.
30 pub summary: &'static str,
31}
32
33pub struct Tool {
34 pub name: &'static str,
35 pub title: &'static str,
36 /// What it is for, in a sentence or two.
37 pub description: &'static str,
38 pub actions: &'static [Action],
39 /// The action a call without one runs.
40 pub default_action: Option<&'static str>,
41}
42
43const fn a(name: &'static str, op: Op, summary: &'static str) -> Action {
44 Action { name, op, summary }
45}
46
47pub const TOOLS: &[Tool] = &[
48 Tool {
49 name: "search",
50 title: "Search",
51 description: "Find things. `code` (the default) searches all of g1t you can see: repositories, code, issues, pull requests and people, with qualifiers like repo:owner/name, language:rust, is:issue. `context` searches one workspace's catalog, docs, issues and memory by meaning.",
52 default_action: Some("code"),
53 actions: &[
54 a("code", Op::Search, "Search all of g1t: repositories, code, issues, pull requests, people"),
55 a("context", Op::SearchContext, "Search a workspace's context hub by meaning"),
56 a("entity", Op::GetEntity, "One catalog entry and its relations"),
57 a("ticket", Op::GetContext, "A Jira, Linear or Sentry item the work refers to, as it is now"),
58 ],
59 },
60 Tool {
61 name: "repository",
62 title: "Repositories",
63 description: "Repositories: find, read and create them, change their settings and rulesets (what may happen to branches and tags, and what a pull request needs to merge), check their CODEOWNERS file, manage their labels and milestones, and see and dismiss their security alerts (secrets and vulnerable dependencies). Name one as \"owner/name\". Deleting, transferring and changing visibility need `confirm`.",
64 default_action: None,
65 actions: &[
66 a("list", Op::ListRepos, "Repositories you can see"),
67 a("get", Op::GetRepo, "One repository"),
68 a("create", Op::CreateRepo, "Create one, empty or copied from a public git URL"),
69 a("update", Op::UpdateRepo, "Change description, website, topics, default branch, protection"),
70 a("get_settings", Op::GetRepoSettings, "How pull requests merge, and the default branch's protection as its rules stack"),
71 a("update_settings", Op::UpdateRepoSettings, "Change how pull requests merge and the default branch protection ruleset"),
72 a("check_names", Op::ListCheckNames, "Check names reported lately, to require in a ruleset"),
73 a("list_rulesets", Op::Rules(RulesOp::ListRepoRulesets), "Its rulesets, and its workspace's that hold in it"),
74 a("get_ruleset", Op::Rules(RulesOp::GetRepoRuleset), "One ruleset"),
75 a("create_ruleset", Op::Rules(RulesOp::CreateRepoRuleset), "Create a ruleset for its branches or tags"),
76 a("update_ruleset", Op::Rules(RulesOp::UpdateRepoRuleset), "Change a ruleset"),
77 a("delete_ruleset", Op::Rules(RulesOp::DeleteRepoRuleset), "Delete a ruleset"),
78 a("branch_rules", Op::Rules(RulesOp::GetBranchRules), "Every rule that holds for a branch or tag, and where it comes from"),
79 a("rule_evaluations", Op::Rules(RulesOp::ListRuleEvaluations), "How its rules judged pushes and merges, with insights"),
80 a("codeowners", Op::GetCodeownersErrors, "Problems in its CODEOWNERS file, by line"),
81 a("list_labels", Op::ListLabels, "Labels, with colors and how many issues and pull requests carry each"),
82 a("create_label", Op::CreateLabel, "Create a label"),
83 a("update_label", Op::UpdateLabel, "Rename a label or change its color or description"),
84 a("delete_label", Op::DeleteLabel, "Delete a label, from everything that carries it"),
85 a("add_default_labels", Op::AddDefaultLabels, "Add the default labels it is missing"),
86 a("list_milestones", Op::ListMilestones, "Milestones, with progress and due dates"),
87 a("get_milestone", Op::GetMilestone, "One milestone with its issues and pull requests"),
88 a("create_milestone", Op::CreateMilestone, "Create a milestone"),
89 a("update_milestone", Op::UpdateMilestone, "Change a milestone's title, description, due date or state"),
90 a("delete_milestone", Op::DeleteMilestone, "Delete a milestone"),
91 a("list_events", Op::ListEvents, "Timeline: pushes, issues, pull requests, comments"),
92 a("rename_branch", Op::RenameBranch, "Rename a branch"),
93 a("rename", Op::RenameRepo, "Rename it; old addresses redirect"),
94 a("transfer", Op::TransferRepo, "Move it to another workspace you own"),
95 a("archive", Op::ArchiveRepo, "Make it read-only"),
96 a("unarchive", Op::UnarchiveRepo, "Make it writable again"),
97 a("set_visibility", Op::SetRepoVisibility, "Make it public or private"),
98 a("delete", Op::DeleteRepo, "Delete it; restorable for 30 days"),
99 a("list_deleted", Op::ListDeletedRepos, "A workspace's deleted repositories"),
100 a("restore", Op::RestoreRepo, "Restore a deleted one"),
101 a("purge", Op::PurgeRepo, "Remove a deleted one for good"),
102 a("security_alerts", Op::ListSecurityAlerts, "Secret and dependency alerts, filtered by state"),
103 a("dismiss_alert", Op::DismissSecurityAlert, "Dismiss an alert with a reason"),
104 a("reopen_alert", Op::ReopenSecurityAlert, "Reopen a dismissed alert"),
105 ],
106 },
107 Tool {
108 name: "issue",
109 title: "Issues",
110 description: "Issues: what should change. Read one before working on it to see the pull requests already made for it. Issues and pull requests share numbers; `comment` works on either.",
111 default_action: None,
112 actions: &[
113 a("list", Op::ListIssues, "Issues on a repository, newest first"),
114 a("get", Op::GetIssue, "One issue with comments and its pull requests"),
115 a("create", Op::CreateIssue, "Open an issue"),
116 a("update", Op::UpdateIssue, "Change title, body, labels, milestone or assignees"),
117 a("labels", Op::ListIssueLabels, "The labels an issue or pull request carries"),
118 a("add_labels", Op::AddIssueLabels, "Add labels to an issue or pull request"),
119 a("set_labels", Op::SetIssueLabels, "Replace the labels of an issue or pull request"),
120 a("remove_labels", Op::RemoveIssueLabels, "Take labels off an issue or pull request"),
121 a("close", Op::CloseIssue, "Close it without a pull request"),
122 a("reopen", Op::ReopenIssue, "Reopen it"),
123 a("comment", Op::AddComment, "Comment on an issue or pull request; path and line for one line of a change"),
124 a("import", Op::ImportIssue, "Open an issue from a Jira, Linear or Sentry item"),
125 ],
126 },
127 Tool {
128 name: "pull_request",
129 title: "Pull requests",
130 description: "Pull requests: start a change for an issue, record your session, mark it ready, ask people and teams to review, review and merge. Read `overlaps` and `behind` on `get` before going far, and `code_owners` for whose approval it needs.",
131 default_action: None,
132 actions: &[
133 a("list", Op::ListPullRequests, "Pull requests on a repository, newest first"),
134 a("get", Op::GetPullRequest, "Status, checks and required checks, reviews, overlaps, whether it is behind"),
135 a("changes", Op::GetPullRequestChanges, "Files and line-by-line diff"),
136 a("create", Op::CreatePullRequest, "Start a draft with its own fork to push to, or open one from a pushed branch"),
137 a("update", Op::UpdatePullRequest, "Change its base branch, labels, milestone, assignees or reviewers"),
138 a("record_session", Op::RecordSession, "Append prompt, reasoning and tool entries to its session"),
139 a("read_session", Op::ReadSession, "Its recorded session"),
140 a("ready", Op::MarkPullRequestReady, "Mark a draft ready, with a summary"),
141 a("request_reviewers", Op::RequestReviewers, "Ask people or teams to review it"),
142 a("remove_requested_reviewers", Op::RemoveRequestedReviewers, "Stop asking people or teams to review it"),
143 a("review", Op::ReviewPullRequest, "Approve or request changes"),
144 a("close", Op::ClosePullRequest, "Close without merging"),
145 a("merge", Op::MergePullRequest, "Land it, or join the merge queue"),
146 a("merge_queue", Op::GetMergeQueue, "The repository's merge queue"),
147 ],
148 },
149 Tool {
150 name: "agent",
151 title: "g1t agents",
152 description: "Put g1t's agent to work and talk to it. One agent per issue; to do more at once, use more issues. Starting an agent uses the workspace's money.",
153 default_action: None,
154 actions: &[
155 a("delegate", Op::Delegate, "Open an issue and put an agent on it in one step"),
156 a("assign", Op::AssignIssue, "Put an agent on an existing issue"),
157 a("message", Op::MessageAgent, "Tell the agent on a pull request something, or ask another agent"),
158 a("answer", Op::AnswerMessage, "Answer a question or handoff sent to you"),
159 a("take_messages", Op::TakeMessages, "For a g1t agent: messages not seen yet"),
160 ],
161 },
162 Tool {
163 name: "plan",
164 title: "Plans",
165 description: "Turn an outcome into issues: an agent proposes them with what done means and their dependencies; nothing opens until you apply the plan.",
166 default_action: None,
167 actions: &[
168 a("create", Op::PlanWork, "Ask an agent for a plan; read it with get until ready"),
169 a("get", Op::GetPlan, "A plan and the issues it proposes"),
170 a("apply", Op::ApplyPlan, "Open its issues; with assign, agents start in dependency order"),
171 ],
172 },
173 Tool {
174 name: "memory",
175 title: "Memory",
176 description: "What the project and its workspace remember for the next agent: how to build, conventions, decisions, traps. Recall before you start; remember one short fact at a time, never a secret.",
177 default_action: None,
178 actions: &[
179 a("recall", Op::Recall, "Search memory, or list it all"),
180 a("remember", Op::Remember, "Save one fact"),
181 ],
182 },
183 Tool {
184 name: "workflow",
185 title: "Workflows",
186 description: "GitHub Actions workflows from .g1t/workflows: their runs, jobs and logs, and running, cancelling or rerunning them. Deployments wherever they run (reported from any CI, made by jobs with an `environment:`, or built on g1t.page), their statuses and environments, and reporting your own. Also the self-hosted runners they run on: a workspace's (`workspace`) or a repository's own (`repo`), their groups, and where agent work runs.",
187 default_action: None,
188 actions: &[
189 a("list", Op::ListWorkflows, "Workflows on the default branch"),
190 a("list_runs", Op::ListWorkflowRuns, "Runs, newest first"),
191 a("get_run", Op::GetWorkflowRun, "One run with its jobs and steps"),
192 a("job_logs", Op::GetJobLogs, "A job's log after a sequence number"),
193 a("dispatch", Op::DispatchWorkflow, "Run a workflow_dispatch workflow"),
194 a("cancel", Op::CancelWorkflowRun, "Cancel a run"),
195 a("rerun", Op::RerunWorkflowRun, "Run a finished run again"),
196 a("update", Op::UpdateWorkflow, "Turn a workflow on or off"),
197 a("list_deployments", Op::Deployments(DeploymentsOp::ListDeployments), "Deployments wherever they run, newest first, filtered"),
198 a("get_deployment", Op::Deployments(DeploymentsOp::GetDeployment), "One deployment with every status it has had"),
199 a("create_deployment", Op::Deployments(DeploymentsOp::CreateDeployment), "Report a deployment of a ref to an environment"),
200 a("deployment_statuses", Op::Deployments(DeploymentsOp::ListDeploymentStatuses), "A deployment's statuses, newest first"),
201 a("create_deployment_status", Op::Deployments(DeploymentsOp::CreateDeploymentStatus), "Report where a deployment is: in_progress, success, failure"),
202 a("list_environments", Op::Deployments(DeploymentsOp::ListEnvironments), "Environments with their current and latest deployments"),
203 a("get_environment", Op::Deployments(DeploymentsOp::GetEnvironment), "One environment by name"),
204 a("list_runners", Op::ListRunners, "Self-hosted runners, with status, labels and what each is doing"),
205 a("create_runner_token", Op::CreateRunnerRegistrationToken, "A one-hour token for g1t-runner register"),
206 a("remove_runner", Op::RemoveRunner, "Remove a self-hosted runner"),
207 a("list_runner_groups", Op::ListRunnerGroups, "A workspace's runner groups"),
208 a("create_runner_group", Op::CreateRunnerGroup, "Make a group, for some repositories"),
209 a("update_runner_group", Op::UpdateRunnerGroup, "Rename a group or change its repositories"),
210 a("delete_runner_group", Op::DeleteRunnerGroup, "Delete a group; its runners join the default"),
211 a("get_runner_settings", Op::GetRunnerSettings, "Where agent work runs; whether forks may use runners"),
212 a("update_runner_settings", Op::UpdateRunnerSettings, "Change them"),
213 ],
214 },
215 Tool {
216 name: "secret",
217 title: "Secrets and variables",
218 description: "A repository's or workspace's secrets and variables, read by workflows and deployments. Secret values are never returned.",
219 default_action: None,
220 actions: &[
221 a("list_secrets", Op::ListActionsSecrets, "Secrets, without values"),
222 a("set_secret", Op::SetActionsSecret, "Add or change a secret"),
223 a("delete_secret", Op::DeleteActionsSecret, "Remove a secret"),
224 a("list_variables", Op::ListActionsVariables, "Variables, with values"),
225 a("set_variable", Op::SetActionsVariable, "Add or change a variable"),
226 a("delete_variable", Op::DeleteActionsVariable, "Remove a variable"),
227 ],
228 },
229 Tool {
230 name: "webhook",
231 title: "Webhooks",
232 description: "HTTPS addresses sent signed events as they happen, for a repository or a whole workspace.",
233 default_action: None,
234 actions: &[
235 a("list", Op::ListWebhooks, "Webhooks, without secrets"),
236 a("create", Op::CreateWebhook, "Register one; a ping is sent"),
237 a("update", Op::UpdateWebhook, "Change address, events or active"),
238 a("delete", Op::DeleteWebhook, "Remove one"),
239 a("ping", Op::PingWebhook, "Send a ping"),
240 a("list_deliveries", Op::ListWebhookDeliveries, "Latest deliveries"),
241 a("redeliver", Op::RedeliverWebhook, "Send a delivery again"),
242 ],
243 },
244 Tool {
245 name: "access",
246 title: "Who has access",
247 description: "Who has access to a repository and with which role (read, triage, write, maintain, admin), outside collaborators, and a workspace's base permission.",
248 default_action: None,
249 actions: &[
250 a("list_collaborators", Op::ListCollaborators, "Everyone with a role, and pending invitations"),
251 a("get_permission", Op::GetCollaboratorPermission, "One person's role and capabilities"),
252 a("add_collaborator", Op::AddCollaborator, "Give someone a role, by username or email"),
253 a("update_collaborator", Op::UpdateCollaborator, "Change a direct role"),
254 a("remove_collaborator", Op::RemoveCollaborator, "Take away a direct role"),
255 a("list_invitations", Op::ListRepoInvitations, "Pending invitations to a repository"),
256 a("revoke_invitation", Op::RevokeRepoInvitation, "Withdraw one"),
257 a("set_base_permission", Op::SetBasePermission, "What every member gets on each repository"),
258 a("list_outside_collaborators", Op::ListOutsideCollaborators, "People with roles who are not members"),
259 ],
260 },
261 Tool {
262 name: "team",
263 title: "Teams",
264 description: "Teams: groups of a workspace's members, given roles on repositories together, mentioned as @workspace/team and asked to review together. Name one by `workspace` and its slug (`team`). Any member may create a team; the workspace's owners and the team's maintainers manage it. A secret team is seen only by its people and the owners.",
265 default_action: None,
266 actions: &[
267 a("list", Op::ListTeams, "A workspace's teams you can see"),
268 a("get", Op::GetTeam, "One team"),
269 a("create", Op::CreateTeam, "Create a team; you become its maintainer"),
270 a("update", Op::UpdateTeam, "Change its name, slug, description, visibility, parent or notifications"),
271 a("delete", Op::DeleteTeam, "Delete it; its child teams move up"),
272 a("list_members", Op::ListTeamMembers, "Its people and their roles, child teams' with include_child_teams"),
273 a("set_member", Op::SetTeamMember, "Add a member of the workspace, or change their role"),
274 a("remove_member", Op::RemoveTeamMember, "Take someone out of it"),
275 a("list_child_teams", Op::ListChildTeams, "The teams nested under it"),
276 a("list_repos", Op::ListTeamRepos, "The repositories it has a role on"),
277 a("set_repo", Op::SetTeamRepo, "Give it a role on a repository"),
278 a("remove_repo", Op::RemoveTeamRepo, "Take its role on a repository away"),
279 a("set_review_assignment", Op::SetTeamReviewAssignment, "Whom it picks when asked to review"),
280 a("list_user_teams", Op::ListUserTeams, "The teams someone is in"),
281 ],
282 },
283 Tool {
284 name: "workspace",
285 title: "Workspaces",
286 description: "Workspaces own repositories (g1t.sh/{workspace}/{repo}): create, update or delete one, invite members, connect integrations and model providers, set rulesets that hold across its repositories, read and change its projects (what each is, where it runs, its links), and keep your own pinned projects at the top of its sidebar.",
287 default_action: None,
288 actions: &[
289 a("get", Op::GetWorkspace, "A workspace's details and settings"),
290 a("create", Op::CreateWorkspace, "Create a workspace"),
291 a("delete", Op::DeleteWorkspace, "Delete a workspace and everything in it (support can restore it for 30 days)"),
292 a("update", Op::UpdateWorkspace, "Change its name, description, base permission or who may create teams"),
293 a("list_invites", Op::ListWorkspaceInvites, "Its invites"),
294 a("invite_member", Op::InviteMember, "Invite an email address"),
295 a("revoke_invite", Op::RevokeWorkspaceInvite, "Revoke a pending invite"),
296 a("list_integrations", Op::ListIntegrations, "Model providers, alert sources, trackers"),
297 a("connect_integration", Op::ConnectIntegration, "Connect one"),
298 a("disconnect_integration", Op::DisconnectIntegration, "Remove one"),
299 a("test_integration", Op::TestIntegration, "Check its credentials"),
300 a("get_model_routes", Op::GetModelRoutes, "Where each kind of work's model requests go"),
301 a("set_model_routes", Op::SetModelRoutes, "Replace them"),
302 a("list_projects", Op::ListProjects, "Its projects you can see: what each is, where it runs, its links"),
303 a("get_project", Op::GetProject, "One project"),
304 a("update_project", Op::UpdateProject, "Change a project's name, description, kind, where it runs or its links"),
305 a("list_pinned_projects", Op::ListPinnedProjects, "Your pinned projects in it, in your order"),
306 a("pin_project", Op::PinProject, "Pin a project, at a position or the end"),
307 a("unpin_project", Op::UnpinProject, "Unpin a project"),
308 a("reorder_pinned_projects", Op::ReorderPinnedProjects, "Put your pins in a new order"),
309 a("list_rulesets", Op::Rules(RulesOp::ListWorkspaceRulesets), "Its rulesets, which hold across its repositories"),
310 a("get_ruleset", Op::Rules(RulesOp::GetWorkspaceRuleset), "One of its rulesets"),
311 a("create_ruleset", Op::Rules(RulesOp::CreateWorkspaceRuleset), "Create a ruleset for some or all of its repositories"),
312 a("update_ruleset", Op::Rules(RulesOp::UpdateWorkspaceRuleset), "Change one of its rulesets"),
313 a("delete_ruleset", Op::Rules(RulesOp::DeleteWorkspaceRuleset), "Delete one of its rulesets"),
314 a("rule_evaluations", Op::Rules(RulesOp::ListWorkspaceRuleEvaluations), "How rules judged changes across its repositories"),
315 ],
316 },
317 Tool {
318 name: "billing",
319 title: "Billing",
320 description: "A workspace's billing: its usage by product, project and day, its budget (the monthly spend limit, alerts and whether usage pauses at it), its AI credit, its invoices, and its AI Gateway requests. Amounts are whole millionths of a dollar (`_micros`), or cents (`_cents`) where named. Members read it; changing the budget and buying credit are for owners, as people, and never for g1t's agents.",
321 default_action: Some("usage"),
322 actions: &[
323 a("usage", Op::GetUsage, "Usage over a range of days, by product, meter, project and day, and what paid for it"),
324 a("budget", Op::GetBudget, "The monthly spend limit, what was spent, alerts and whether usage pauses at the limit"),
325 a("set_budget", Op::SetBudget, "Change the spend limit, alerts, pausing or the alert webhook"),
326 a("ai_credit", Op::GetAiCredit, "AI credit left, its grants, auto-reload and how to buy more"),
327 a("buy_ai_credit", Op::BuyAiCredit, "A payment page to buy AI credit, for a person to open"),
328 a("invoices", Op::ListInvoices, "Every invoice, the itemised usage invoices, and the next one so far"),
329 a("billing_details", Op::GetBillingDetails, "Who invoices are made out to and the payment method on file"),
330 a("gateway_requests", Op::ListGatewayRequests, "Recent AI Gateway requests: model, tokens, cost, status and token"),
331 ],
332 },
333 Tool {
334 name: "security",
335 title: "Security",
336 description: "A repository's security: secret scanning alerts and push protection bypasses, custom secret patterns, code scanning alerts and SARIF uploads, vulnerability alerts, the dependency graph and its SBOM, dependency review, settings, and a workspace's overview. Fix an alert with g1t. Findings are shown to those who can change the code only. Give `repo` (owner/name), or `workspace` for lists across one.",
337 default_action: Some("secret_alerts"),
338 actions: &[
339 a("secret_alerts", Op::Security(SecurityOp::ListSecretAlerts), "Secret scanning alerts; by state, secret_type, validity, bypassed"),
340 a("secret_alert", Op::Security(SecurityOp::GetSecretAlert), "One secret alert, with where it was found and its bypass requests"),
341 a("update_secret_alert", Op::Security(SecurityOp::UpdateSecretAlert), "Dismiss a secret alert with a reason, or reopen it"),
342 a("secret_locations", Op::Security(SecurityOp::ListSecretLocations), "Every file, line and commit a secret is in"),
343 a("bypass", Op::Security(SecurityOp::BypassPushProtection), "Push past push protection with a reason, or ask to"),
344 a("check_validity", Op::Security(SecurityOp::CheckSecretValidity), "Ask a secret's issuer whether it still works"),
345 a("bypass_requests", Op::Security(SecurityOp::ListBypassRequests), "A workspace's push protection bypass requests"),
346 a("review_bypass", Op::Security(SecurityOp::ReviewBypassRequest), "Approve, deny or cancel a bypass request"),
347 a("patterns", Op::Security(SecurityOp::ListCustomPatterns), "Custom secret patterns of a repository or workspace"),
348 a("create_pattern", Op::Security(SecurityOp::CreateCustomPattern), "Create a custom secret pattern, as a draft or published"),
349 a("update_pattern", Op::Security(SecurityOp::UpdateCustomPattern), "Change, publish or unpublish a custom pattern"),
350 a("delete_pattern", Op::Security(SecurityOp::DeleteCustomPattern), "Delete a custom pattern"),
351 a("dry_run_pattern", Op::Security(SecurityOp::DryRunCustomPattern), "Run a pattern over the default branch without saving it"),
352 a("code_alerts", Op::Security(SecurityOp::ListCodeAlerts), "Code scanning alerts; by state, severity, tool, rule_id"),
353 a("code_alert", Op::Security(SecurityOp::GetCodeAlert), "One code scanning alert by number"),
354 a("update_code_alert", Op::Security(SecurityOp::UpdateCodeAlert), "Dismiss a code scanning alert with a reason, or reopen it"),
355 a("analyses", Op::Security(SecurityOp::ListAnalyses), "Code scanning analyses, newest first"),
356 a("upload_sarif", Op::Security(SecurityOp::UploadSarif), "Upload a SARIF file, gzipped and base64-encoded"),
357 a("sarif_upload", Op::Security(SecurityOp::GetSarifUpload), "Whether a SARIF upload was read, and its analyses"),
358 a("vulnerability_alerts", Op::Security(SecurityOp::ListVulnerabilityAlerts), "Vulnerable dependencies; by state, severity, ecosystem, package"),
359 a("vulnerability_alert", Op::Security(SecurityOp::GetVulnerabilityAlert), "One vulnerability alert"),
360 a("update_vulnerability_alert", Op::Security(SecurityOp::UpdateVulnerabilityAlert), "Dismiss a vulnerability alert with a reason, or reopen it"),
361 a("fix", Op::Security(SecurityOp::FixAlert), "Put g1t on an issue to fix an alert"),
362 a("dependency_graph", Op::Security(SecurityOp::GetDependencyGraph), "Every package the lockfiles resolve, direct or transitive"),
363 a("sbom", Op::Security(SecurityOp::GetSbom), "The dependency graph as an SPDX 2.3 document"),
364 a("compare_dependencies", Op::Security(SecurityOp::CompareDependencies), "What changes in dependencies between base...head"),
365 a("settings", Op::Security(SecurityOp::GetSettings), "A repository's security settings"),
366 a("update_settings", Op::Security(SecurityOp::UpdateSettings), "Change when checks fail and dependency review's policy"),
367 a("workspace_settings", Op::Security(SecurityOp::GetWorkspaceSettings), "A workspace's delegated bypass and validity checks"),
368 a("update_workspace_settings", Op::Security(SecurityOp::UpdateWorkspaceSettings), "Turn delegated bypass or validity checks on or off"),
369 a("overview", Op::Security(SecurityOp::GetOverview), "A workspace's alerts, trends and coverage"),
370 ],
371 },
372 Tool {
373 name: "notifications",
374 title: "Notifications",
375 description: "Your inbox: what needs you, and what you follow. One thread per issue, pull request, workflow or deployment, with why you were told (`reason`): an agent waiting on you, a review asked of you, an assignment, a mention, your work's checks, or what you subscribe to and watch. Mark threads read or done once handled, and choose what you hear of with subscribe, unsubscribe and watch. Your own: a personal token.",
376 default_action: Some("list"),
377 actions: &[
378 a("list", Op::ListNotifications, "Unread threads, latest first; all, a view, a reason, a repository"),
379 a("get", Op::GetNotificationThread, "One thread with its recent activity and your subscription"),
380 a("mark_read", Op::MarkThreadRead, "Mark a thread read, or unread"),
381 a("mark_all_read", Op::MarkNotificationsRead, "Mark everything read up to a time, or one repository's"),
382 a("done", Op::MarkThreadDone, "Mark a thread done; new activity brings it back"),
383 a("save", Op::SaveThread, "Save a thread, or unsave it"),
384 a("snooze", Op::SnoozeThread, "Snooze a thread until a time, or bring it back"),
385 a("subscription", Op::GetThreadSubscription, "Your subscription to an issue or pull request"),
386 a("subscribe", Op::SetThreadSubscription, "Subscribe to an issue or pull request, or ignore it"),
387 a("unsubscribe", Op::DeleteThreadSubscription, "Unsubscribe until you comment or are mentioned"),
388 a("watching", Op::GetRepoSubscription, "How you watch a repository"),
389 a("watch", Op::SetRepoSubscription, "Watch a repository: participating, all, ignore or custom"),
390 a("unwatch", Op::DeleteRepoSubscription, "Stop watching a repository"),
391 a("watched", Op::ListWatchedRepos, "Repositories you watch other than the default way"),
392 ],
393 },
394 Tool {
395 name: "account",
396 title: "Your account",
397 description: "Who this token acts as and its workspaces (`whoami`), your email addresses, your invites, and invitations to repositories waiting for you.",
398 default_action: Some("whoami"),
399 actions: &[
400 a("whoami", Op::Whoami, "Who the token acts as, and its workspaces"),
401 a("list_emails", Op::ListEmails, "Your addresses"),
402 a("add_email", Op::AddEmail, "Add an address"),
403 a("remove_email", Op::RemoveEmail, "Remove an address"),
404 a("update_email_settings", Op::UpdateEmailSettings, "Primary, backup and privacy"),
405 a("list_invites", Op::ListInvites, "Your invites to g1t"),
406 a("create_invite", Op::CreateInvite, "Make an invite"),
407 a("revoke_invite", Op::RevokeInvite, "Revoke one"),
408 a("list_repository_invitations", Op::ListMyRepoInvitations, "Invitations to repositories for you"),
409 a("accept_repository_invitation", Op::AcceptRepoInvitation, "Accept one"),
410 a("decline_repository_invitation", Op::DeclineRepoInvitation, "Decline one"),
411 ],
412 },
413];
414
415/// Operations that cannot be undone, or reach beyond g1t's own records:
416/// clients ask before running a tool that has any of them.
417fn destructive(op: Op) -> bool {
418 matches!(
419 op,
420 Op::Security(SecurityOp::DeleteCustomPattern | SecurityOp::BypassPushProtection)
421 | Op::Rules(RulesOp::DeleteRepoRuleset | RulesOp::DeleteWorkspaceRuleset)
422 | Op::DeleteWorkspace
423 | Op::UpdateWorkspace
424 | Op::DeleteRepo
425 | Op::PurgeRepo
426 | Op::TransferRepo
427 | Op::SetRepoVisibility
428 | Op::RemoveEmail
429 | Op::RemoveCollaborator
430 | Op::DisconnectIntegration
431 | Op::DeleteWebhook
432 | Op::DeleteActionsSecret
433 | Op::DeleteActionsVariable
434 | Op::SetActionsSecret
435 | Op::SetActionsVariable
436 | Op::SetModelRoutes
437 | Op::SetBasePermission
438 | Op::DeleteTeam
439 | Op::RemoveTeamRepo
440 | Op::MergePullRequest
441 | Op::RemoveRunner
442 | Op::DeleteRunnerGroup
443 | Op::UpdateRunnerSettings
444 )
445}
446
447/// Whether an operation only reads.
448pub fn reads_only(op: Op) -> bool {
449 NO_SCOPE.contains(&op.name())
450 || scope_for(op.name()).is_some_and(|scope| scope.level() == Level::Read)
451}
452
453/// What decides which actions a caller sees.
454pub enum Gate<'a> {
455 /// No limit beyond the person's own role.
456 Everything,
457 /// A g1t agent's token: the operations its run lists.
458 Agent(&'a AgentScope),
459 /// An access token with scopes.
460 Token(&'a TokenAccess),
461}
462
463impl Gate<'_> {
464 pub fn allows(&self, op: Op) -> bool {
465 match self {
466 Gate::Everything => true,
467 Gate::Agent(scope) => op.allowed_by(scope) && !NEVER.contains(&op.name()),
468 Gate::Token(access) => {
469 if NO_SCOPE.contains(&op.name()) {
470 return true;
471 }
472 match scope_for(op.name()) {
473 Some(scope) => access.allows(scope),
474 None => access.scopes.is_none(),
475 }
476 }
477 }
478 }
479}
480
481impl Tool {
482 pub fn by_name(name: &str) -> Option<&'static Tool> {
483 TOOLS.iter().find(|tool| tool.name == name)
484 }
485
486 pub fn action(&self, name: &str) -> Option<&'static Action> {
487 // The tools are 'static; find through TOOLS to keep the lifetime.
488 TOOLS
489 .iter()
490 .find(|tool| tool.name == self.name)
491 .and_then(|tool| tool.actions.iter().find(|action| action.name == name))
492 }
493
494 pub fn visible(&self, gate: &Gate) -> Vec<&'static Action> {
495 TOOLS
496 .iter()
497 .find(|tool| tool.name == self.name)
498 .map(|tool| tool.actions.iter().filter(|action| gate.allows(action.op)).collect())
499 .unwrap_or_default()
500 }
501
502 /// The flat input schema of the actions given.
503 pub fn input_schema(&self, actions: &[&Action]) -> Value {
504 let mut properties = Map::new();
505 let lines: Vec<String> = actions
506 .iter()
507 .map(|action| {
508 let required: Vec<String> = action.op.required();
509 if required.is_empty() {
510 format!("{}: {}.", action.name, action.summary)
511 } else {
512 format!("{} ({}): {}.", action.name, required.join(", "), action.summary)
513 }
514 })
515 .collect();
516 let mut action_schema = json!({
517 "type": "string",
518 "enum": actions.iter().map(|action| action.name).collect::<Vec<_>>(),
519 "description": lines.join("\n"),
520 });
521 if let Some(default) = self.default_action.filter(|name| actions.iter().any(|action| action.name == *name)) {
522 action_schema["default"] = json!(default);
523 }
524 properties.insert("action".to_owned(), action_schema);
525 for action in actions {
526 for (name, schema) in action.op.properties() {
527 merge_property(&mut properties, name, schema);
528 }
529 }
530 let mut required = vec![];
531 if self.default_action.is_none() {
532 required.push("action");
533 }
534 let mut schema = json!({ "type": "object", "properties": properties });
535 if !required.is_empty() {
536 schema["required"] = json!(required);
537 }
538 schema
539 }
540
541 /// The input schema keyed by action: one `oneOf` branch per action,
542 /// each with its own fields and the ones it needs.
543 pub fn discriminated(&self, actions: &[&Action]) -> Value {
544 let branches: Vec<Value> = actions
545 .iter()
546 .map(|action| {
547 let mut properties = Map::new();
548 properties.insert("action".to_owned(), json!({ "const": action.name }));
549 properties.extend(action.op.properties());
550 let mut required = vec![Value::String("action".to_owned())];
551 // The default action may leave `action` out.
552 if self.default_action == Some(action.name) {
553 required.clear();
554 }
555 required.extend(action.op.required().into_iter().map(Value::String));
556 json!({
557 "title": action.name,
558 "description": action.summary,
559 "type": "object",
560 "properties": properties,
561 "required": required,
562 })
563 })
564 .collect();
565 json!({ "type": "object", "oneOf": branches })
566 }
567
568 /// MCP's hints about the actions given: whether the tool only reads,
569 /// whether it can destroy something, and whether calling it twice is
570 /// the same as once.
571 pub fn annotations(&self, actions: &[&Action]) -> Value {
572 let read_only = actions.iter().all(|action| reads_only(action.op));
573 json!({
574 "title": self.title,
575 "readOnlyHint": read_only,
576 "destructiveHint": !read_only && actions.iter().any(|action| destructive(action.op)),
577 "idempotentHint": read_only,
578 "openWorldHint": false,
579 })
580 }
581
582 /// The tool as `tools/list` gives it, for a caller behind `gate`, or
583 /// `None` when it may use none of its actions.
584 pub fn listed(&self, gate: &Gate) -> Option<Value> {
585 let actions = self.visible(gate);
586 if actions.is_empty() {
587 return None;
588 }
589 Some(json!({
590 "name": self.name,
591 "title": self.title,
592 "description": self.description,
593 "inputSchema": self.input_schema(&actions),
594 "annotations": self.annotations(&actions),
595 }))
596 }
597}
598
599/// Adds a property to a tool's flat schema. The first action to use a name
600/// describes it; a later one with other allowed values adds them.
601fn merge_property(properties: &mut Map<String, Value>, name: String, schema: Value) {
602 match properties.get_mut(&name) {
603 None => {
604 properties.insert(name, schema);
605 }
606 Some(existing) => {
607 if let (Some(Value::Array(had)), Some(Value::Array(more))) =
608 (existing.get("enum").cloned(), schema.get("enum"))
609 {
610 let mut merged = had;
611 for value in more {
612 if !merged.contains(value) {
613 merged.push(value.clone());
614 }
615 }
616 existing["enum"] = Value::Array(merged);
617 }
618 // Different kinds of value under one name: say less, accept both.
619 if existing.get("type") != schema.get("type")
620 && let Some(fields) = existing.as_object_mut()
621 {
622 fields.remove("type");
623 fields.remove("items");
624 }
625 }
626 }
627}
628
629/// What a call to a tool runs: the operation its action names, or why not.
630pub fn resolve(tool: &Tool, arguments: &Value) -> Result<Op, String> {
631 let names = || {
632 tool.actions
633 .iter()
634 .map(|action| action.name)
635 .collect::<Vec<_>>()
636 .join(", ")
637 };
638 let Some(name) = arguments["action"].as_str().or(tool.default_action) else {
639 return Err(format!("Give an action: one of {}.", names()));
640 };
641 let Some(action) = tool.action(name) else {
642 return Err(format!("{} has no action {name}. Its actions: {}.", tool.name, names()));
643 };
644 let missing: Vec<String> = action
645 .op
646 .required()
647 .into_iter()
648 .filter(|field| arguments.get(field).is_none_or(Value::is_null))
649 .collect();
650 if !missing.is_empty() {
651 return Err(format!("{}.{name} needs {}.", tool.name, missing.join(", ")));
652 }
653 Ok(action.op)
654}
655
656#[cfg(test)]
657mod tests {
658 use super::*;
659 use g1t_contracts::scopes::{Preset, Scope};
660
661 fn listed(gate: &Gate) -> Vec<Value> {
662 TOOLS.iter().filter_map(|tool| tool.listed(gate)).collect()
663 }
664
665 fn token(scopes: Option<Vec<Scope>>) -> TokenAccess {
666 TokenAccess {
667 token_id: "tok_1".to_owned(),
668 scopes: scopes.map(|scopes| scopes.iter().map(|scope| scope.as_str().to_owned()).collect()),
669 legacy: false,
670 name: None,
671 }
672 }
673
674 #[test]
675 fn every_operation_is_exactly_one_action_of_one_tool() {
676 for op in Op::ALL {
677 let count = TOOLS
678 .iter()
679 .flat_map(|tool| tool.actions.iter())
680 .filter(|action| action.op == op)
681 .count();
682 assert_eq!(count, 1, "{} is {count} actions", op.name());
683 }
684 for tool in TOOLS {
685 let mut names = std::collections::HashSet::new();
686 for action in tool.actions {
687 assert!(names.insert(action.name), "{}.{} twice", tool.name, action.name);
688 }
689 if let Some(default) = tool.default_action {
690 assert!(tool.action(default).is_some(), "{}", tool.name);
691 }
692 }
693 assert!(TOOLS.len() <= 17, "{} tools", TOOLS.len());
694 }
695
696 #[test]
697 fn every_operation_needs_exactly_one_scope_or_none() {
698 use g1t_contracts::scopes::OPERATIONS;
699 for op in Op::ALL {
700 let mapped = OPERATIONS.iter().filter(|(name, _)| *name == op.name()).count();
701 let free = NO_SCOPE.contains(&op.name());
702 assert_eq!(mapped + usize::from(free), 1, "{}", op.name());
703 }
704 for (name, _) in OPERATIONS {
705 assert!(Op::by_name(name).is_some(), "{name} is not an operation");
706 }
707 }
708
709 #[test]
710 fn each_tool_schema_is_valid_with_one_branch_per_action() {
711 for tool in TOOLS {
712 let actions: Vec<&Action> = tool.actions.iter().collect();
713 let flat = tool.input_schema(&actions);
714 assert_eq!(flat["type"], "object");
715 assert!(flat.get("oneOf").is_none(), "no oneOf at the top level");
716 let listed: Vec<&str> = flat["properties"]["action"]["enum"]
717 .as_array()
718 .unwrap()
719 .iter()
720 .map(|name| name.as_str().unwrap())
721 .collect();
722 assert_eq!(listed, tool.actions.iter().map(|action| action.name).collect::<Vec<_>>());
723 for action in tool.actions {
724 for field in action.op.required() {
725 assert!(flat["properties"].get(&field).is_some(), "{}.{}: {field}", tool.name, action.name);
726 }
727 }
728 let keyed = tool.discriminated(&actions);
729 let branches = keyed["oneOf"].as_array().unwrap();
730 assert_eq!(branches.len(), tool.actions.len());
731 for (branch, action) in branches.iter().zip(tool.actions) {
732 assert_eq!(branch["properties"]["action"]["const"], action.name);
733 for field in branch["required"].as_array().unwrap() {
734 assert!(branch["properties"].get(field.as_str().unwrap()).is_some(), "{}.{}: {field}", tool.name, action.name);
735 }
736 }
737 // A well-formed JSON Schema object throughout.
738 let text = serde_json::to_string(&flat).unwrap();
739 assert!(serde_json::from_str::<Value>(&text).is_ok());
740 }
741 }
742
743 #[test]
744 fn a_read_only_token_sees_read_actions_only() {
745 let access = token(Preset::ReadOnly.scopes());
746 let gate = Gate::Token(&access);
747 for tool in TOOLS {
748 for action in tool.visible(&gate) {
749 assert!(reads_only(action.op), "{}.{}", tool.name, action.name);
750 }
751 }
752 let tools = listed(&gate);
753 for tool in &tools {
754 assert_eq!(tool["annotations"]["readOnlyHint"], true, "{}", tool["name"]);
755 assert_eq!(tool["annotations"]["destructiveHint"], false);
756 }
757 let issue = tools.iter().find(|tool| tool["name"] == "issue").unwrap();
758 assert_eq!(issue["inputSchema"]["properties"]["action"]["enum"], json!(["list", "get", "labels"]));
759 // Nothing of the agent tool is a read.
760 assert!(!tools.iter().any(|tool| tool["name"] == "agent"));
761 }
762
763 #[test]
764 fn a_narrow_token_sees_only_its_tools() {
765 let access = token(Some(vec![Scope::IssuesWrite]));
766 let names: Vec<Value> = listed(&Gate::Token(&access)).into_iter().map(|tool| tool["name"].clone()).collect();
767 // Labels and milestones are the repository's, managed with issues:write.
768 assert_eq!(names, vec![json!("repository"), json!("issue"), json!("plan"), json!("account")]);
769 // Notifications are a resource of their own: reading them lists
770 // only what reads.
771 let reader = token(Some(vec![Scope::NotificationsRead]));
772 let tools = listed(&Gate::Token(&reader));
773 let notifications = tools.iter().find(|tool| tool["name"] == "notifications").unwrap();
774 assert_eq!(
775 notifications["inputSchema"]["properties"]["action"]["enum"],
776 json!(["list", "get", "subscription", "watching", "watched"])
777 );
778 assert_eq!(notifications["annotations"]["readOnlyHint"], true);
779 let full = token(None);
780 assert_eq!(listed(&Gate::Token(&full)).len(), TOOLS.len());
781 assert_eq!(listed(&Gate::Everything).len(), TOOLS.len());
782 }
783
784 #[test]
785 fn a_tool_that_can_destroy_says_so() {
786 let tools = listed(&Gate::Everything);
787 let repository = tools.iter().find(|tool| tool["name"] == "repository").unwrap();
788 assert_eq!(repository["annotations"]["destructiveHint"], true);
789 assert_eq!(repository["annotations"]["readOnlyHint"], false);
790 let memory = tools.iter().find(|tool| tool["name"] == "memory").unwrap();
791 assert_eq!(memory["annotations"]["destructiveHint"], false);
792 }
793
794 #[test]
795 fn calls_resolve_to_their_operation_or_say_what_is_missing() {
796 let issue = Tool::by_name("issue").unwrap();
797 assert_eq!(resolve(issue, &json!({ "action": "get", "repo": "a/b", "number": 1 })), Ok(Op::GetIssue));
798 assert_eq!(resolve(issue, &json!({ "action": "get", "repo": "a/b" })), Err("issue.get needs number.".to_owned()));
799 assert!(resolve(issue, &json!({})).unwrap_err().starts_with("Give an action"));
800 assert!(resolve(issue, &json!({ "action": "explode" })).unwrap_err().contains("no action explode"));
801 let search = Tool::by_name("search").unwrap();
802 assert_eq!(resolve(search, &json!({ "query": "x" })), Ok(Op::Search));
803 let account = Tool::by_name("account").unwrap();
804 assert_eq!(resolve(account, &json!({})), Ok(Op::Whoami));
805 }
806
807 #[test]
808 fn teams_are_one_tool_and_a_workspace_reader_sees_only_its_reads() {
809 let team = Tool::by_name("team").unwrap();
810 let names: Vec<&str> = team.actions.iter().map(|action| action.name).collect();
811 assert_eq!(
812 names,
813 [
814 "list",
815 "get",
816 "create",
817 "update",
818 "delete",
819 "list_members",
820 "set_member",
821 "remove_member",
822 "list_child_teams",
823 "list_repos",
824 "set_repo",
825 "remove_repo",
826 "set_review_assignment",
827 "list_user_teams",
828 ]
829 );
830 let reader = token(Some(vec![Scope::WorkspaceRead]));
831 let tools = listed(&Gate::Token(&reader));
832 let listed_team = tools.iter().find(|tool| tool["name"] == "team").unwrap();
833 assert_eq!(
834 listed_team["inputSchema"]["properties"]["action"]["enum"],
835 json!(["list", "get", "list_members", "list_child_teams", "list_repos", "list_user_teams"])
836 );
837 assert_eq!(listed_team["annotations"]["readOnlyHint"], true);
838 // A team's role on a repository is who has access.
839 let admin = token(Some(vec![Scope::WorkspaceAdmin]));
840 let tools = listed(&Gate::Token(&admin));
841 let listed_team = tools.iter().find(|tool| tool["name"] == "team").unwrap();
842 let actions = listed_team["inputSchema"]["properties"]["action"]["enum"].as_array().unwrap();
843 assert!(actions.contains(&json!("set_review_assignment")) && !actions.contains(&json!("set_repo")));
844 let access = token(Some(vec![Scope::AccessAdmin]));
845 let tools = listed(&Gate::Token(&access));
846 let listed_team = tools.iter().find(|tool| tool["name"] == "team").unwrap();
847 assert_eq!(listed_team["inputSchema"]["properties"]["action"]["enum"], json!(["set_repo", "remove_repo"]));
848 // Both kinds of role a schema names are offered.
849 let roles = &listed(&Gate::Everything).into_iter().find(|tool| tool["name"] == "team").unwrap()["inputSchema"]
850 ["properties"]["role"]["enum"];
851 for role in ["member", "maintainer", "read", "admin"] {
852 assert!(roles.as_array().unwrap().contains(&json!(role)), "{role}");
853 }
854 assert_eq!(
855 resolve(team, &json!({ "action": "set_repo", "workspace": "acme", "team": "backend", "repo": "rocket" })),
856 Err("team.set_repo needs role.".to_owned())
857 );
858 }
859
860 #[test]
861 fn reviewers_and_code_owners_are_actions_of_their_tools() {
862 let pull = Tool::by_name("pull_request").unwrap();
863 assert_eq!(
864 resolve(pull, &json!({ "action": "request_reviewers", "repo": "a/b", "number": 1, "team_reviewers": ["backend"] })),
865 Ok(Op::RequestReviewers)
866 );
867 assert_eq!(pull.action("remove_requested_reviewers").map(|action| action.op), Some(Op::RemoveRequestedReviewers));
868 let repository = Tool::by_name("repository").unwrap();
869 assert_eq!(resolve(repository, &json!({ "action": "codeowners", "repo": "a/b" })), Ok(Op::GetCodeownersErrors));
870 assert!(reads_only(Op::GetCodeownersErrors));
871 assert!(!reads_only(Op::RequestReviewers));
872 }
873
874 /// How much smaller `tools/list` is than one tool per operation. Run
875 /// with `--nocapture` to see the numbers.
876 #[test]
877 fn the_tool_list_is_much_smaller_than_one_tool_per_operation() {
878 let before: Vec<Value> = Op::ALL
879 .into_iter()
880 .map(|op| json!({ "name": op.name(), "description": op.description(), "inputSchema": op.input() }))
881 .collect();
882 let after = listed(&Gate::Everything);
883 let before_bytes = serde_json::to_string(&json!({ "tools": before })).unwrap().len();
884 let after_bytes = serde_json::to_string(&json!({ "tools": after })).unwrap().len();
885 let agent = token(Preset::Agent.scopes());
886 let agent_bytes = serde_json::to_string(&json!({ "tools": listed(&Gate::Token(&agent)) })).unwrap().len();
887 let read = token(Preset::ReadOnly.scopes());
888 let read_bytes = serde_json::to_string(&json!({ "tools": listed(&Gate::Token(&read)) })).unwrap().len();
889 println!(
890 "tools/list: before {} tools, {before_bytes} bytes (~{} tokens); after {} tools, {after_bytes} bytes (~{} tokens); agent preset {agent_bytes} bytes (~{} tokens); read only {read_bytes} bytes (~{} tokens)",
891 before.len(),
892 before_bytes / 4,
893 after.len(),
894 after_bytes / 4,
895 agent_bytes / 4,
896 read_bytes / 4,
897 );
898 assert!(after_bytes * 2 < before_bytes, "{after_bytes} vs {before_bytes}");
899 }
900}