Skip to content
905 linesCodeBlameRaw
1//! The MCP server's tools: a few resource tools, each with an `action`.
2//!
3//! Every operation is one action of one tool. A call is dispatched to the
4//! operation it names, so permissions, the audit log, billing and outcomes
5//! are exactly those of the REST API. A token sees only the actions its
6//! scopes allow, and a tool none of whose actions it may use is not listed.
7//!
8//! The listed input schema is one flat object: `action`, then every field
9//! any of its actions takes. Which fields each action needs is in the
10//! `action` field's description and checked on every call. Claude's API,
11//! and so most MCP clients, refuse a tool whose input schema has `oneOf`
12//! at its top level, so the schema keyed by action, with each action's
13//! required fields, is [`discriminated`], published on the server's card
14//! and in the docs.
15
16use g1t_contracts::credentials::NEVER;
17use g1t_contracts::identity::AgentScope;
18use g1t_contracts::scopes::{Level, NO_SCOPE, TokenAccess, scope_for};
19use serde_json::{Map, Value, json};
20
21use crate::about::AboutOp;
22use crate::operations::Op;
23use crate::rules::RulesOp;
24use crate::security::SecurityOp;
25
26pub struct Action {
27 pub name: &'static str,
28 pub op: Op,
29 /// One line, for the `action` field's description.
30 pub summary: &'static str,
31}
32
33pub struct Tool {
34 pub name: &'static str,
35 pub title: &'static str,
36 /// What it is for, in a sentence or two.
37 pub description: &'static str,
38 pub actions: &'static [Action],
39 /// The action a call without one runs.
40 pub default_action: Option<&'static str>,
41}
42
43const fn a(name: &'static str, op: Op, summary: &'static str) -> Action {
44 Action { name, op, summary }
45}
46
47pub const TOOLS: &[Tool] = &[
48 Tool {
49 name: "search",
50 title: "Search",
51 description: "Find things. `code` (the default) searches all of g1t you can see: repositories, code, issues, pull requests and people, with qualifiers like repo:owner/name, language:rust, is:issue. `context` searches one workspace's catalog, docs, issues and memory by meaning.",
52 default_action: Some("code"),
53 actions: &[
54 a("code", Op::Search, "Search all of g1t: repositories, code, issues, pull requests, people"),
55 a("context", Op::SearchContext, "Search a workspace's context hub by meaning"),
56 a("entity", Op::GetEntity, "One catalog entry and its relations"),
57 a("ticket", Op::GetContext, "A Jira, Linear or Sentry item the work refers to, as it is now"),
58 ],
59 },
60 Tool {
61 name: "repository",
62 title: "Repositories",
63 description: "Repositories: find, read and create them, change their settings and rulesets (what may happen to branches and tags, and what a pull request needs to merge), check their CODEOWNERS file, manage their labels and milestones, see and dismiss their security alerts (secrets and vulnerable dependencies), read what their default branch says (languages, contributors, license), star them, and publish releases. Name one as \"owner/name\". Deleting, transferring and changing visibility need `confirm`.",
64 default_action: None,
65 actions: &[
66 a("list", Op::ListRepos, "Repositories you can see"),
67 a("get", Op::GetRepo, "One repository"),
68 a("create", Op::CreateRepo, "Create one, empty or copied from a public git URL"),
69 a("update", Op::UpdateRepo, "Change description, website, topics, default branch, protection"),
70 a("get_settings", Op::GetRepoSettings, "How pull requests merge, and the default branch's protection as its rules stack"),
71 a("update_settings", Op::UpdateRepoSettings, "Change how pull requests merge and the default branch protection ruleset"),
72 a("check_names", Op::ListCheckNames, "Check names reported lately, to require in a ruleset"),
73 a("list_rulesets", Op::Rules(RulesOp::ListRepoRulesets), "Its rulesets, and its workspace's that hold in it"),
74 a("get_ruleset", Op::Rules(RulesOp::GetRepoRuleset), "One ruleset"),
75 a("create_ruleset", Op::Rules(RulesOp::CreateRepoRuleset), "Create a ruleset for its branches or tags"),
76 a("update_ruleset", Op::Rules(RulesOp::UpdateRepoRuleset), "Change a ruleset"),
77 a("delete_ruleset", Op::Rules(RulesOp::DeleteRepoRuleset), "Delete a ruleset"),
78 a("branch_rules", Op::Rules(RulesOp::GetBranchRules), "Every rule that holds for a branch or tag, and where it comes from"),
79 a("rule_evaluations", Op::Rules(RulesOp::ListRuleEvaluations), "How its rules judged pushes and merges, with insights"),
80 a("codeowners", Op::GetCodeownersErrors, "Problems in its CODEOWNERS file, by line"),
81 a("list_labels", Op::ListLabels, "Labels, with colors and how many issues and pull requests carry each"),
82 a("create_label", Op::CreateLabel, "Create a label"),
83 a("update_label", Op::UpdateLabel, "Rename a label or change its color or description"),
84 a("delete_label", Op::DeleteLabel, "Delete a label, from everything that carries it"),
85 a("add_default_labels", Op::AddDefaultLabels, "Add the default labels it is missing"),
86 a("list_milestones", Op::ListMilestones, "Milestones, with progress and due dates"),
87 a("get_milestone", Op::GetMilestone, "One milestone with its issues and pull requests"),
88 a("create_milestone", Op::CreateMilestone, "Create a milestone"),
89 a("update_milestone", Op::UpdateMilestone, "Change a milestone's title, description, due date or state"),
90 a("delete_milestone", Op::DeleteMilestone, "Delete a milestone"),
91 a("list_events", Op::ListEvents, "Timeline: pushes, issues, pull requests, comments"),
92 a("languages", Op::About(AboutOp::GetLanguages), "Its languages by bytes, with colors and percentages"),
93 a("contributors", Op::About(AboutOp::ListContributors), "Who made it: commits per person, agent and author, by week"),
94 a("license", Op::About(AboutOp::GetLicense), "The license its LICENSE file holds"),
95 a("stargazers", Op::About(AboutOp::ListStargazers), "Who starred it"),
96 a("starred", Op::About(AboutOp::CheckStarred), "Whether you starred it, and how many have"),
97 a("star", Op::About(AboutOp::Star), "Star it"),
98 a("unstar", Op::About(AboutOp::Unstar), "Take your star back"),
99 a("list_starred", Op::About(AboutOp::ListStarred), "Repositories you starred"),
100 a("list_releases", Op::About(AboutOp::ListReleases), "Releases, newest first"),
101 a("latest_release", Op::About(AboutOp::GetLatestRelease), "The latest release"),
102 a("get_release", Op::About(AboutOp::GetRelease), "One release by id"),
103 a("get_release_by_tag", Op::About(AboutOp::GetReleaseByTag), "The release of a tag"),
104 a("create_release", Op::About(AboutOp::CreateRelease), "Publish a release of a tag, making the tag if needed"),
105 a("update_release", Op::About(AboutOp::UpdateRelease), "Change a release's title, notes, draft or prerelease"),
106 a("delete_release", Op::About(AboutOp::DeleteRelease), "Delete a release; its tag stays"),
107 a("rename_branch", Op::RenameBranch, "Rename a branch"),
108 a("rename", Op::RenameRepo, "Rename it; old addresses redirect"),
109 a("transfer", Op::TransferRepo, "Move it to another workspace you own"),
110 a("archive", Op::ArchiveRepo, "Make it read-only"),
111 a("unarchive", Op::UnarchiveRepo, "Make it writable again"),
112 a("set_visibility", Op::SetRepoVisibility, "Make it public or private"),
113 a("delete", Op::DeleteRepo, "Delete it; restorable for 30 days"),
114 a("list_deleted", Op::ListDeletedRepos, "A workspace's deleted repositories"),
115 a("restore", Op::RestoreRepo, "Restore a deleted one"),
116 a("purge", Op::PurgeRepo, "Remove a deleted one for good"),
117 a("security_alerts", Op::ListSecurityAlerts, "Secret and dependency alerts, filtered by state"),
118 a("dismiss_alert", Op::DismissSecurityAlert, "Dismiss an alert with a reason"),
119 a("reopen_alert", Op::ReopenSecurityAlert, "Reopen a dismissed alert"),
120 ],
121 },
122 Tool {
123 name: "issue",
124 title: "Issues",
125 description: "Issues: what should change. Read one before working on it to see the pull requests already made for it. Issues and pull requests share numbers; `comment` works on either.",
126 default_action: None,
127 actions: &[
128 a("list", Op::ListIssues, "Issues on a repository, newest first"),
129 a("get", Op::GetIssue, "One issue with comments and its pull requests"),
130 a("create", Op::CreateIssue, "Open an issue"),
131 a("update", Op::UpdateIssue, "Change title, body, labels, milestone or assignees"),
132 a("labels", Op::ListIssueLabels, "The labels an issue or pull request carries"),
133 a("add_labels", Op::AddIssueLabels, "Add labels to an issue or pull request"),
134 a("set_labels", Op::SetIssueLabels, "Replace the labels of an issue or pull request"),
135 a("remove_labels", Op::RemoveIssueLabels, "Take labels off an issue or pull request"),
136 a("close", Op::CloseIssue, "Close it without a pull request"),
137 a("reopen", Op::ReopenIssue, "Reopen it"),
138 a("comment", Op::AddComment, "Comment on an issue or pull request; path and line for one line of a change"),
139 a("import", Op::ImportIssue, "Open an issue from a Jira, Linear or Sentry item"),
140 ],
141 },
142 Tool {
143 name: "pull_request",
144 title: "Pull requests",
145 description: "Pull requests: start a change for an issue, record your session, mark it ready, ask people and teams to review, review and merge. Read `overlaps` and `behind` on `get` before going far, and `code_owners` for whose approval it needs.",
146 default_action: None,
147 actions: &[
148 a("list", Op::ListPullRequests, "Pull requests on a repository, newest first"),
149 a("get", Op::GetPullRequest, "Status, checks and required checks, reviews, overlaps, whether it is behind"),
150 a("changes", Op::GetPullRequestChanges, "Files and line-by-line diff"),
151 a("create", Op::CreatePullRequest, "Start a draft with its own fork to push to, or open one from a pushed branch"),
152 a("update", Op::UpdatePullRequest, "Change its base branch, labels, milestone, assignees or reviewers"),
153 a("record_session", Op::RecordSession, "Append prompt, reasoning and tool entries to its session"),
154 a("read_session", Op::ReadSession, "Its recorded session"),
155 a("ready", Op::MarkPullRequestReady, "Mark a draft ready, with a summary"),
156 a("request_reviewers", Op::RequestReviewers, "Ask people or teams to review it"),
157 a("remove_requested_reviewers", Op::RemoveRequestedReviewers, "Stop asking people or teams to review it"),
158 a("review", Op::ReviewPullRequest, "Approve or request changes"),
159 a("close", Op::ClosePullRequest, "Close without merging"),
160 a("merge", Op::MergePullRequest, "Land it, or join the merge queue"),
161 a("merge_queue", Op::GetMergeQueue, "The repository's merge queue"),
162 ],
163 },
164 Tool {
165 name: "agent",
166 title: "g1t agents",
167 description: "Put g1t's agent to work and talk to it. One agent per issue; to do more at once, use more issues. Starting an agent uses the workspace's money.",
168 default_action: None,
169 actions: &[
170 a("delegate", Op::Delegate, "Open an issue and put an agent on it in one step"),
171 a("assign", Op::AssignIssue, "Put an agent on an existing issue"),
172 a("message", Op::MessageAgent, "Tell the agent on a pull request something, or ask another agent"),
173 a("answer", Op::AnswerMessage, "Answer a question or handoff sent to you"),
174 a("take_messages", Op::TakeMessages, "For a g1t agent: messages not seen yet"),
175 ],
176 },
177 Tool {
178 name: "plan",
179 title: "Plans",
180 description: "Turn an outcome into issues: an agent proposes them with what done means and their dependencies; nothing opens until you apply the plan.",
181 default_action: None,
182 actions: &[
183 a("create", Op::PlanWork, "Ask an agent for a plan; read it with get until ready"),
184 a("get", Op::GetPlan, "A plan and the issues it proposes"),
185 a("apply", Op::ApplyPlan, "Open its issues; with assign, agents start in dependency order"),
186 ],
187 },
188 Tool {
189 name: "memory",
190 title: "Memory",
191 description: "What the project and its workspace remember for the next agent: how to build, conventions, decisions, traps. Recall before you start; remember one short fact at a time, never a secret.",
192 default_action: None,
193 actions: &[
194 a("recall", Op::Recall, "Search memory, or list it all"),
195 a("remember", Op::Remember, "Save one fact"),
196 ],
197 },
198 Tool {
199 name: "workflow",
200 title: "Workflows",
201 description: "GitHub Actions workflows from .g1t/workflows: their runs, jobs and logs, and running, cancelling or rerunning them. Also the self-hosted runners they run on: a workspace's (`workspace`) or a repository's own (`repo`), their groups, and where agent work runs.",
202 default_action: None,
203 actions: &[
204 a("list", Op::ListWorkflows, "Workflows on the default branch"),
205 a("list_runs", Op::ListWorkflowRuns, "Runs, newest first"),
206 a("get_run", Op::GetWorkflowRun, "One run with its jobs and steps"),
207 a("job_logs", Op::GetJobLogs, "A job's log after a sequence number"),
208 a("dispatch", Op::DispatchWorkflow, "Run a workflow_dispatch workflow"),
209 a("cancel", Op::CancelWorkflowRun, "Cancel a run"),
210 a("rerun", Op::RerunWorkflowRun, "Run a finished run again"),
211 a("update", Op::UpdateWorkflow, "Turn a workflow on or off"),
212 a("list_runners", Op::ListRunners, "Self-hosted runners, with status, labels and what each is doing"),
213 a("create_runner_token", Op::CreateRunnerRegistrationToken, "A one-hour token for g1t-runner register"),
214 a("remove_runner", Op::RemoveRunner, "Remove a self-hosted runner"),
215 a("list_runner_groups", Op::ListRunnerGroups, "A workspace's runner groups"),
216 a("create_runner_group", Op::CreateRunnerGroup, "Make a group, for some repositories"),
217 a("update_runner_group", Op::UpdateRunnerGroup, "Rename a group or change its repositories"),
218 a("delete_runner_group", Op::DeleteRunnerGroup, "Delete a group; its runners join the default"),
219 a("get_runner_settings", Op::GetRunnerSettings, "Where agent work runs; whether forks may use runners"),
220 a("update_runner_settings", Op::UpdateRunnerSettings, "Change them"),
221 ],
222 },
223 Tool {
224 name: "secret",
225 title: "Secrets and variables",
226 description: "A repository's or workspace's secrets and variables, read by workflows and deployments. Secret values are never returned.",
227 default_action: None,
228 actions: &[
229 a("list_secrets", Op::ListActionsSecrets, "Secrets, without values"),
230 a("set_secret", Op::SetActionsSecret, "Add or change a secret"),
231 a("delete_secret", Op::DeleteActionsSecret, "Remove a secret"),
232 a("list_variables", Op::ListActionsVariables, "Variables, with values"),
233 a("set_variable", Op::SetActionsVariable, "Add or change a variable"),
234 a("delete_variable", Op::DeleteActionsVariable, "Remove a variable"),
235 ],
236 },
237 Tool {
238 name: "webhook",
239 title: "Webhooks",
240 description: "HTTPS addresses sent signed events as they happen, for a repository or a whole workspace.",
241 default_action: None,
242 actions: &[
243 a("list", Op::ListWebhooks, "Webhooks, without secrets"),
244 a("create", Op::CreateWebhook, "Register one; a ping is sent"),
245 a("update", Op::UpdateWebhook, "Change address, events or active"),
246 a("delete", Op::DeleteWebhook, "Remove one"),
247 a("ping", Op::PingWebhook, "Send a ping"),
248 a("list_deliveries", Op::ListWebhookDeliveries, "Latest deliveries"),
249 a("redeliver", Op::RedeliverWebhook, "Send a delivery again"),
250 ],
251 },
252 Tool {
253 name: "access",
254 title: "Who has access",
255 description: "Who has access to a repository and with which role (read, triage, write, maintain, admin), outside collaborators, and a workspace's base permission.",
256 default_action: None,
257 actions: &[
258 a("list_collaborators", Op::ListCollaborators, "Everyone with a role, and pending invitations"),
259 a("get_permission", Op::GetCollaboratorPermission, "One person's role and capabilities"),
260 a("add_collaborator", Op::AddCollaborator, "Give someone a role, by username or email"),
261 a("update_collaborator", Op::UpdateCollaborator, "Change a direct role"),
262 a("remove_collaborator", Op::RemoveCollaborator, "Take away a direct role"),
263 a("list_invitations", Op::ListRepoInvitations, "Pending invitations to a repository"),
264 a("revoke_invitation", Op::RevokeRepoInvitation, "Withdraw one"),
265 a("set_base_permission", Op::SetBasePermission, "What every member gets on each repository"),
266 a("list_outside_collaborators", Op::ListOutsideCollaborators, "People with roles who are not members"),
267 ],
268 },
269 Tool {
270 name: "team",
271 title: "Teams",
272 description: "Teams: groups of a workspace's members, given roles on repositories together, mentioned as @workspace/team and asked to review together. Name one by `workspace` and its slug (`team`). Any member may create a team; the workspace's owners and the team's maintainers manage it. A secret team is seen only by its people and the owners.",
273 default_action: None,
274 actions: &[
275 a("list", Op::ListTeams, "A workspace's teams you can see"),
276 a("get", Op::GetTeam, "One team"),
277 a("create", Op::CreateTeam, "Create a team; you become its maintainer"),
278 a("update", Op::UpdateTeam, "Change its name, slug, description, visibility, parent or notifications"),
279 a("delete", Op::DeleteTeam, "Delete it; its child teams move up"),
280 a("list_members", Op::ListTeamMembers, "Its people and their roles, child teams' with include_child_teams"),
281 a("set_member", Op::SetTeamMember, "Add a member of the workspace, or change their role"),
282 a("remove_member", Op::RemoveTeamMember, "Take someone out of it"),
283 a("list_child_teams", Op::ListChildTeams, "The teams nested under it"),
284 a("list_repos", Op::ListTeamRepos, "The repositories it has a role on"),
285 a("set_repo", Op::SetTeamRepo, "Give it a role on a repository"),
286 a("remove_repo", Op::RemoveTeamRepo, "Take its role on a repository away"),
287 a("set_review_assignment", Op::SetTeamReviewAssignment, "Whom it picks when asked to review"),
288 a("list_user_teams", Op::ListUserTeams, "The teams someone is in"),
289 ],
290 },
291 Tool {
292 name: "workspace",
293 title: "Workspaces",
294 description: "Workspaces own repositories (g1t.sh/{workspace}/{repo}): create, update or delete one, invite members, connect integrations and model providers, set rulesets that hold across its repositories, and keep your own pinned projects at the top of its sidebar.",
295 default_action: None,
296 actions: &[
297 a("get", Op::GetWorkspace, "A workspace's details and settings"),
298 a("create", Op::CreateWorkspace, "Create a workspace"),
299 a("delete", Op::DeleteWorkspace, "Delete a workspace and everything in it (support can restore it for 30 days)"),
300 a("update", Op::UpdateWorkspace, "Change its name, description, base permission or who may create teams"),
301 a("list_invites", Op::ListWorkspaceInvites, "Its invites"),
302 a("invite_member", Op::InviteMember, "Invite an email address"),
303 a("revoke_invite", Op::RevokeWorkspaceInvite, "Revoke a pending invite"),
304 a("list_integrations", Op::ListIntegrations, "Model providers, alert sources, trackers"),
305 a("connect_integration", Op::ConnectIntegration, "Connect one"),
306 a("disconnect_integration", Op::DisconnectIntegration, "Remove one"),
307 a("test_integration", Op::TestIntegration, "Check its credentials"),
308 a("get_model_routes", Op::GetModelRoutes, "Where each kind of work's model requests go"),
309 a("set_model_routes", Op::SetModelRoutes, "Replace them"),
310 a("list_pinned_projects", Op::ListPinnedProjects, "Your pinned projects in it, in your order"),
311 a("pin_project", Op::PinProject, "Pin a project, at a position or the end"),
312 a("unpin_project", Op::UnpinProject, "Unpin a project"),
313 a("reorder_pinned_projects", Op::ReorderPinnedProjects, "Put your pins in a new order"),
314 a("list_rulesets", Op::Rules(RulesOp::ListWorkspaceRulesets), "Its rulesets, which hold across its repositories"),
315 a("get_ruleset", Op::Rules(RulesOp::GetWorkspaceRuleset), "One of its rulesets"),
316 a("create_ruleset", Op::Rules(RulesOp::CreateWorkspaceRuleset), "Create a ruleset for some or all of its repositories"),
317 a("update_ruleset", Op::Rules(RulesOp::UpdateWorkspaceRuleset), "Change one of its rulesets"),
318 a("delete_ruleset", Op::Rules(RulesOp::DeleteWorkspaceRuleset), "Delete one of its rulesets"),
319 a("rule_evaluations", Op::Rules(RulesOp::ListWorkspaceRuleEvaluations), "How rules judged changes across its repositories"),
320 ],
321 },
322 Tool {
323 name: "billing",
324 title: "Billing",
325 description: "A workspace's billing: its usage by product, project and day, its budget (the monthly spend limit, alerts and whether usage pauses at it), its AI credit, its invoices, and its AI Gateway requests. Amounts are whole millionths of a dollar (`_micros`), or cents (`_cents`) where named. Members read it; changing the budget and buying credit are for owners, as people, and never for g1t's agents.",
326 default_action: Some("usage"),
327 actions: &[
328 a("usage", Op::GetUsage, "Usage over a range of days, by product, meter, project and day, and what paid for it"),
329 a("budget", Op::GetBudget, "The monthly spend limit, what was spent, alerts and whether usage pauses at the limit"),
330 a("set_budget", Op::SetBudget, "Change the spend limit, alerts, pausing or the alert webhook"),
331 a("ai_credit", Op::GetAiCredit, "AI credit left, its grants, auto-reload and how to buy more"),
332 a("buy_ai_credit", Op::BuyAiCredit, "A payment page to buy AI credit, for a person to open"),
333 a("invoices", Op::ListInvoices, "Every invoice, the itemised usage invoices, and the next one so far"),
334 a("billing_details", Op::GetBillingDetails, "Who invoices are made out to and the payment method on file"),
335 a("gateway_requests", Op::ListGatewayRequests, "Recent AI Gateway requests: model, tokens, cost, status and token"),
336 ],
337 },
338 Tool {
339 name: "security",
340 title: "Security",
341 description: "A repository's security: secret scanning alerts and push protection bypasses, custom secret patterns, code scanning alerts and SARIF uploads, vulnerability alerts, the dependency graph and its SBOM, dependency review, settings, and a workspace's overview. Fix an alert with g1t. Findings are shown to those who can change the code only. Give `repo` (owner/name), or `workspace` for lists across one.",
342 default_action: Some("secret_alerts"),
343 actions: &[
344 a("secret_alerts", Op::Security(SecurityOp::ListSecretAlerts), "Secret scanning alerts; by state, secret_type, validity, bypassed"),
345 a("secret_alert", Op::Security(SecurityOp::GetSecretAlert), "One secret alert, with where it was found and its bypass requests"),
346 a("update_secret_alert", Op::Security(SecurityOp::UpdateSecretAlert), "Dismiss a secret alert with a reason, or reopen it"),
347 a("secret_locations", Op::Security(SecurityOp::ListSecretLocations), "Every file, line and commit a secret is in"),
348 a("bypass", Op::Security(SecurityOp::BypassPushProtection), "Push past push protection with a reason, or ask to"),
349 a("check_validity", Op::Security(SecurityOp::CheckSecretValidity), "Ask a secret's issuer whether it still works"),
350 a("bypass_requests", Op::Security(SecurityOp::ListBypassRequests), "A workspace's push protection bypass requests"),
351 a("review_bypass", Op::Security(SecurityOp::ReviewBypassRequest), "Approve, deny or cancel a bypass request"),
352 a("patterns", Op::Security(SecurityOp::ListCustomPatterns), "Custom secret patterns of a repository or workspace"),
353 a("create_pattern", Op::Security(SecurityOp::CreateCustomPattern), "Create a custom secret pattern, as a draft or published"),
354 a("update_pattern", Op::Security(SecurityOp::UpdateCustomPattern), "Change, publish or unpublish a custom pattern"),
355 a("delete_pattern", Op::Security(SecurityOp::DeleteCustomPattern), "Delete a custom pattern"),
356 a("dry_run_pattern", Op::Security(SecurityOp::DryRunCustomPattern), "Run a pattern over the default branch without saving it"),
357 a("code_alerts", Op::Security(SecurityOp::ListCodeAlerts), "Code scanning alerts; by state, severity, tool, rule_id"),
358 a("code_alert", Op::Security(SecurityOp::GetCodeAlert), "One code scanning alert by number"),
359 a("update_code_alert", Op::Security(SecurityOp::UpdateCodeAlert), "Dismiss a code scanning alert with a reason, or reopen it"),
360 a("analyses", Op::Security(SecurityOp::ListAnalyses), "Code scanning analyses, newest first"),
361 a("upload_sarif", Op::Security(SecurityOp::UploadSarif), "Upload a SARIF file, gzipped and base64-encoded"),
362 a("sarif_upload", Op::Security(SecurityOp::GetSarifUpload), "Whether a SARIF upload was read, and its analyses"),
363 a("vulnerability_alerts", Op::Security(SecurityOp::ListVulnerabilityAlerts), "Vulnerable dependencies; by state, severity, ecosystem, package"),
364 a("vulnerability_alert", Op::Security(SecurityOp::GetVulnerabilityAlert), "One vulnerability alert"),
365 a("update_vulnerability_alert", Op::Security(SecurityOp::UpdateVulnerabilityAlert), "Dismiss a vulnerability alert with a reason, or reopen it"),
366 a("fix", Op::Security(SecurityOp::FixAlert), "Put g1t on an issue to fix an alert"),
367 a("dependency_graph", Op::Security(SecurityOp::GetDependencyGraph), "Every package the lockfiles resolve, direct or transitive"),
368 a("sbom", Op::Security(SecurityOp::GetSbom), "The dependency graph as an SPDX 2.3 document"),
369 a("compare_dependencies", Op::Security(SecurityOp::CompareDependencies), "What changes in dependencies between base...head"),
370 a("settings", Op::Security(SecurityOp::GetSettings), "A repository's security settings"),
371 a("update_settings", Op::Security(SecurityOp::UpdateSettings), "Change when checks fail and dependency review's policy"),
372 a("workspace_settings", Op::Security(SecurityOp::GetWorkspaceSettings), "A workspace's delegated bypass and validity checks"),
373 a("update_workspace_settings", Op::Security(SecurityOp::UpdateWorkspaceSettings), "Turn delegated bypass or validity checks on or off"),
374 a("overview", Op::Security(SecurityOp::GetOverview), "A workspace's alerts, trends and coverage"),
375 ],
376 },
377 Tool {
378 name: "notifications",
379 title: "Notifications",
380 description: "Your inbox: what needs you, and what you follow. One thread per issue, pull request, workflow or deployment, with why you were told (`reason`): an agent waiting on you, a review asked of you, an assignment, a mention, your work's checks, or what you subscribe to and watch. Mark threads read or done once handled, and choose what you hear of with subscribe, unsubscribe and watch. Your own: a personal token.",
381 default_action: Some("list"),
382 actions: &[
383 a("list", Op::ListNotifications, "Unread threads, latest first; all, a view, a reason, a repository"),
384 a("get", Op::GetNotificationThread, "One thread with its recent activity and your subscription"),
385 a("mark_read", Op::MarkThreadRead, "Mark a thread read, or unread"),
386 a("mark_all_read", Op::MarkNotificationsRead, "Mark everything read up to a time, or one repository's"),
387 a("done", Op::MarkThreadDone, "Mark a thread done; new activity brings it back"),
388 a("save", Op::SaveThread, "Save a thread, or unsave it"),
389 a("snooze", Op::SnoozeThread, "Snooze a thread until a time, or bring it back"),
390 a("subscription", Op::GetThreadSubscription, "Your subscription to an issue or pull request"),
391 a("subscribe", Op::SetThreadSubscription, "Subscribe to an issue or pull request, or ignore it"),
392 a("unsubscribe", Op::DeleteThreadSubscription, "Unsubscribe until you comment or are mentioned"),
393 a("watching", Op::GetRepoSubscription, "How you watch a repository"),
394 a("watch", Op::SetRepoSubscription, "Watch a repository: participating, all, ignore or custom"),
395 a("unwatch", Op::DeleteRepoSubscription, "Stop watching a repository"),
396 a("watched", Op::ListWatchedRepos, "Repositories you watch other than the default way"),
397 ],
398 },
399 Tool {
400 name: "account",
401 title: "Your account",
402 description: "Who this token acts as and its workspaces (`whoami`), your email addresses, your invites, and invitations to repositories waiting for you.",
403 default_action: Some("whoami"),
404 actions: &[
405 a("whoami", Op::Whoami, "Who the token acts as, and its workspaces"),
406 a("list_emails", Op::ListEmails, "Your addresses"),
407 a("add_email", Op::AddEmail, "Add an address"),
408 a("remove_email", Op::RemoveEmail, "Remove an address"),
409 a("update_email_settings", Op::UpdateEmailSettings, "Primary, backup and privacy"),
410 a("list_invites", Op::ListInvites, "Your invites to g1t"),
411 a("create_invite", Op::CreateInvite, "Make an invite"),
412 a("revoke_invite", Op::RevokeInvite, "Revoke one"),
413 a("list_repository_invitations", Op::ListMyRepoInvitations, "Invitations to repositories for you"),
414 a("accept_repository_invitation", Op::AcceptRepoInvitation, "Accept one"),
415 a("decline_repository_invitation", Op::DeclineRepoInvitation, "Decline one"),
416 ],
417 },
418];
419
420/// Operations that cannot be undone, or reach beyond g1t's own records:
421/// clients ask before running a tool that has any of them.
422fn destructive(op: Op) -> bool {
423 matches!(
424 op,
425 Op::Security(SecurityOp::DeleteCustomPattern | SecurityOp::BypassPushProtection)
426 | Op::Rules(RulesOp::DeleteRepoRuleset | RulesOp::DeleteWorkspaceRuleset)
427 | Op::DeleteWorkspace
428 | Op::UpdateWorkspace
429 | Op::DeleteRepo
430 | Op::PurgeRepo
431 | Op::TransferRepo
432 | Op::SetRepoVisibility
433 | Op::RemoveEmail
434 | Op::RemoveCollaborator
435 | Op::DisconnectIntegration
436 | Op::DeleteWebhook
437 | Op::DeleteActionsSecret
438 | Op::DeleteActionsVariable
439 | Op::SetActionsSecret
440 | Op::SetActionsVariable
441 | Op::SetModelRoutes
442 | Op::SetBasePermission
443 | Op::DeleteTeam
444 | Op::RemoveTeamRepo
445 | Op::MergePullRequest
446 | Op::RemoveRunner
447 | Op::DeleteRunnerGroup
448 | Op::UpdateRunnerSettings
449 )
450}
451
452/// Whether an operation only reads.
453pub fn reads_only(op: Op) -> bool {
454 NO_SCOPE.contains(&op.name())
455 || scope_for(op.name()).is_some_and(|scope| scope.level() == Level::Read)
456}
457
458/// What decides which actions a caller sees.
459pub enum Gate<'a> {
460 /// No limit beyond the person's own role.
461 Everything,
462 /// A g1t agent's token: the operations its run lists.
463 Agent(&'a AgentScope),
464 /// An access token with scopes.
465 Token(&'a TokenAccess),
466}
467
468impl Gate<'_> {
469 pub fn allows(&self, op: Op) -> bool {
470 match self {
471 Gate::Everything => true,
472 Gate::Agent(scope) => op.allowed_by(scope) && !NEVER.contains(&op.name()),
473 Gate::Token(access) => {
474 if NO_SCOPE.contains(&op.name()) {
475 return true;
476 }
477 match scope_for(op.name()) {
478 Some(scope) => access.allows(scope),
479 None => access.scopes.is_none(),
480 }
481 }
482 }
483 }
484}
485
486impl Tool {
487 pub fn by_name(name: &str) -> Option<&'static Tool> {
488 TOOLS.iter().find(|tool| tool.name == name)
489 }
490
491 pub fn action(&self, name: &str) -> Option<&'static Action> {
492 // The tools are 'static; find through TOOLS to keep the lifetime.
493 TOOLS
494 .iter()
495 .find(|tool| tool.name == self.name)
496 .and_then(|tool| tool.actions.iter().find(|action| action.name == name))
497 }
498
499 pub fn visible(&self, gate: &Gate) -> Vec<&'static Action> {
500 TOOLS
501 .iter()
502 .find(|tool| tool.name == self.name)
503 .map(|tool| tool.actions.iter().filter(|action| gate.allows(action.op)).collect())
504 .unwrap_or_default()
505 }
506
507 /// The flat input schema of the actions given.
508 pub fn input_schema(&self, actions: &[&Action]) -> Value {
509 let mut properties = Map::new();
510 let lines: Vec<String> = actions
511 .iter()
512 .map(|action| {
513 let required: Vec<String> = action.op.required();
514 if required.is_empty() {
515 format!("{}: {}.", action.name, action.summary)
516 } else {
517 format!("{} ({}): {}.", action.name, required.join(", "), action.summary)
518 }
519 })
520 .collect();
521 let mut action_schema = json!({
522 "type": "string",
523 "enum": actions.iter().map(|action| action.name).collect::<Vec<_>>(),
524 "description": lines.join("\n"),
525 });
526 if let Some(default) = self.default_action.filter(|name| actions.iter().any(|action| action.name == *name)) {
527 action_schema["default"] = json!(default);
528 }
529 properties.insert("action".to_owned(), action_schema);
530 for action in actions {
531 for (name, schema) in action.op.properties() {
532 merge_property(&mut properties, name, schema);
533 }
534 }
535 let mut required = vec![];
536 if self.default_action.is_none() {
537 required.push("action");
538 }
539 let mut schema = json!({ "type": "object", "properties": properties });
540 if !required.is_empty() {
541 schema["required"] = json!(required);
542 }
543 schema
544 }
545
546 /// The input schema keyed by action: one `oneOf` branch per action,
547 /// each with its own fields and the ones it needs.
548 pub fn discriminated(&self, actions: &[&Action]) -> Value {
549 let branches: Vec<Value> = actions
550 .iter()
551 .map(|action| {
552 let mut properties = Map::new();
553 properties.insert("action".to_owned(), json!({ "const": action.name }));
554 properties.extend(action.op.properties());
555 let mut required = vec![Value::String("action".to_owned())];
556 // The default action may leave `action` out.
557 if self.default_action == Some(action.name) {
558 required.clear();
559 }
560 required.extend(action.op.required().into_iter().map(Value::String));
561 json!({
562 "title": action.name,
563 "description": action.summary,
564 "type": "object",
565 "properties": properties,
566 "required": required,
567 })
568 })
569 .collect();
570 json!({ "type": "object", "oneOf": branches })
571 }
572
573 /// MCP's hints about the actions given: whether the tool only reads,
574 /// whether it can destroy something, and whether calling it twice is
575 /// the same as once.
576 pub fn annotations(&self, actions: &[&Action]) -> Value {
577 let read_only = actions.iter().all(|action| reads_only(action.op));
578 json!({
579 "title": self.title,
580 "readOnlyHint": read_only,
581 "destructiveHint": !read_only && actions.iter().any(|action| destructive(action.op)),
582 "idempotentHint": read_only,
583 "openWorldHint": false,
584 })
585 }
586
587 /// The tool as `tools/list` gives it, for a caller behind `gate`, or
588 /// `None` when it may use none of its actions.
589 pub fn listed(&self, gate: &Gate) -> Option<Value> {
590 let actions = self.visible(gate);
591 if actions.is_empty() {
592 return None;
593 }
594 Some(json!({
595 "name": self.name,
596 "title": self.title,
597 "description": self.description,
598 "inputSchema": self.input_schema(&actions),
599 "annotations": self.annotations(&actions),
600 }))
601 }
602}
603
604/// Adds a property to a tool's flat schema. The first action to use a name
605/// describes it; a later one with other allowed values adds them.
606fn merge_property(properties: &mut Map<String, Value>, name: String, schema: Value) {
607 match properties.get_mut(&name) {
608 None => {
609 properties.insert(name, schema);
610 }
611 Some(existing) => {
612 if let (Some(Value::Array(had)), Some(Value::Array(more))) =
613 (existing.get("enum").cloned(), schema.get("enum"))
614 {
615 let mut merged = had;
616 for value in more {
617 if !merged.contains(value) {
618 merged.push(value.clone());
619 }
620 }
621 existing["enum"] = Value::Array(merged);
622 }
623 // Different kinds of value under one name: say less, accept both.
624 if existing.get("type") != schema.get("type")
625 && let Some(fields) = existing.as_object_mut()
626 {
627 fields.remove("type");
628 fields.remove("items");
629 }
630 }
631 }
632}
633
634/// What a call to a tool runs: the operation its action names, or why not.
635pub fn resolve(tool: &Tool, arguments: &Value) -> Result<Op, String> {
636 let names = || {
637 tool.actions
638 .iter()
639 .map(|action| action.name)
640 .collect::<Vec<_>>()
641 .join(", ")
642 };
643 let Some(name) = arguments["action"].as_str().or(tool.default_action) else {
644 return Err(format!("Give an action: one of {}.", names()));
645 };
646 let Some(action) = tool.action(name) else {
647 return Err(format!("{} has no action {name}. Its actions: {}.", tool.name, names()));
648 };
649 let missing: Vec<String> = action
650 .op
651 .required()
652 .into_iter()
653 .filter(|field| arguments.get(field).is_none_or(Value::is_null))
654 .collect();
655 if !missing.is_empty() {
656 return Err(format!("{}.{name} needs {}.", tool.name, missing.join(", ")));
657 }
658 Ok(action.op)
659}
660
661#[cfg(test)]
662mod tests {
663 use super::*;
664 use g1t_contracts::scopes::{Preset, Scope};
665
666 fn listed(gate: &Gate) -> Vec<Value> {
667 TOOLS.iter().filter_map(|tool| tool.listed(gate)).collect()
668 }
669
670 fn token(scopes: Option<Vec<Scope>>) -> TokenAccess {
671 TokenAccess {
672 token_id: "tok_1".to_owned(),
673 scopes: scopes.map(|scopes| scopes.iter().map(|scope| scope.as_str().to_owned()).collect()),
674 legacy: false,
675 name: None,
676 }
677 }
678
679 #[test]
680 fn every_operation_is_exactly_one_action_of_one_tool() {
681 for op in Op::ALL {
682 let count = TOOLS
683 .iter()
684 .flat_map(|tool| tool.actions.iter())
685 .filter(|action| action.op == op)
686 .count();
687 assert_eq!(count, 1, "{} is {count} actions", op.name());
688 }
689 for tool in TOOLS {
690 let mut names = std::collections::HashSet::new();
691 for action in tool.actions {
692 assert!(names.insert(action.name), "{}.{} twice", tool.name, action.name);
693 }
694 if let Some(default) = tool.default_action {
695 assert!(tool.action(default).is_some(), "{}", tool.name);
696 }
697 }
698 assert!(TOOLS.len() <= 17, "{} tools", TOOLS.len());
699 }
700
701 #[test]
702 fn every_operation_needs_exactly_one_scope_or_none() {
703 use g1t_contracts::scopes::OPERATIONS;
704 for op in Op::ALL {
705 let mapped = OPERATIONS.iter().filter(|(name, _)| *name == op.name()).count();
706 let free = NO_SCOPE.contains(&op.name());
707 assert_eq!(mapped + usize::from(free), 1, "{}", op.name());
708 }
709 for (name, _) in OPERATIONS {
710 assert!(Op::by_name(name).is_some(), "{name} is not an operation");
711 }
712 }
713
714 #[test]
715 fn each_tool_schema_is_valid_with_one_branch_per_action() {
716 for tool in TOOLS {
717 let actions: Vec<&Action> = tool.actions.iter().collect();
718 let flat = tool.input_schema(&actions);
719 assert_eq!(flat["type"], "object");
720 assert!(flat.get("oneOf").is_none(), "no oneOf at the top level");
721 let listed: Vec<&str> = flat["properties"]["action"]["enum"]
722 .as_array()
723 .unwrap()
724 .iter()
725 .map(|name| name.as_str().unwrap())
726 .collect();
727 assert_eq!(listed, tool.actions.iter().map(|action| action.name).collect::<Vec<_>>());
728 for action in tool.actions {
729 for field in action.op.required() {
730 assert!(flat["properties"].get(&field).is_some(), "{}.{}: {field}", tool.name, action.name);
731 }
732 }
733 let keyed = tool.discriminated(&actions);
734 let branches = keyed["oneOf"].as_array().unwrap();
735 assert_eq!(branches.len(), tool.actions.len());
736 for (branch, action) in branches.iter().zip(tool.actions) {
737 assert_eq!(branch["properties"]["action"]["const"], action.name);
738 for field in branch["required"].as_array().unwrap() {
739 assert!(branch["properties"].get(field.as_str().unwrap()).is_some(), "{}.{}: {field}", tool.name, action.name);
740 }
741 }
742 // A well-formed JSON Schema object throughout.
743 let text = serde_json::to_string(&flat).unwrap();
744 assert!(serde_json::from_str::<Value>(&text).is_ok());
745 }
746 }
747
748 #[test]
749 fn a_read_only_token_sees_read_actions_only() {
750 let access = token(Preset::ReadOnly.scopes());
751 let gate = Gate::Token(&access);
752 for tool in TOOLS {
753 for action in tool.visible(&gate) {
754 assert!(reads_only(action.op), "{}.{}", tool.name, action.name);
755 }
756 }
757 let tools = listed(&gate);
758 for tool in &tools {
759 assert_eq!(tool["annotations"]["readOnlyHint"], true, "{}", tool["name"]);
760 assert_eq!(tool["annotations"]["destructiveHint"], false);
761 }
762 let issue = tools.iter().find(|tool| tool["name"] == "issue").unwrap();
763 assert_eq!(issue["inputSchema"]["properties"]["action"]["enum"], json!(["list", "get", "labels"]));
764 // Nothing of the agent tool is a read.
765 assert!(!tools.iter().any(|tool| tool["name"] == "agent"));
766 }
767
768 #[test]
769 fn a_narrow_token_sees_only_its_tools() {
770 let access = token(Some(vec![Scope::IssuesWrite]));
771 let names: Vec<Value> = listed(&Gate::Token(&access)).into_iter().map(|tool| tool["name"].clone()).collect();
772 // Labels and milestones are the repository's, managed with issues:write.
773 assert_eq!(names, vec![json!("repository"), json!("issue"), json!("plan"), json!("account")]);
774 // Notifications are a resource of their own: reading them lists
775 // only what reads.
776 let reader = token(Some(vec![Scope::NotificationsRead]));
777 let tools = listed(&Gate::Token(&reader));
778 let notifications = tools.iter().find(|tool| tool["name"] == "notifications").unwrap();
779 assert_eq!(
780 notifications["inputSchema"]["properties"]["action"]["enum"],
781 json!(["list", "get", "subscription", "watching", "watched"])
782 );
783 assert_eq!(notifications["annotations"]["readOnlyHint"], true);
784 let full = token(None);
785 assert_eq!(listed(&Gate::Token(&full)).len(), TOOLS.len());
786 assert_eq!(listed(&Gate::Everything).len(), TOOLS.len());
787 }
788
789 #[test]
790 fn a_tool_that_can_destroy_says_so() {
791 let tools = listed(&Gate::Everything);
792 let repository = tools.iter().find(|tool| tool["name"] == "repository").unwrap();
793 assert_eq!(repository["annotations"]["destructiveHint"], true);
794 assert_eq!(repository["annotations"]["readOnlyHint"], false);
795 let memory = tools.iter().find(|tool| tool["name"] == "memory").unwrap();
796 assert_eq!(memory["annotations"]["destructiveHint"], false);
797 }
798
799 #[test]
800 fn calls_resolve_to_their_operation_or_say_what_is_missing() {
801 let issue = Tool::by_name("issue").unwrap();
802 assert_eq!(resolve(issue, &json!({ "action": "get", "repo": "a/b", "number": 1 })), Ok(Op::GetIssue));
803 assert_eq!(resolve(issue, &json!({ "action": "get", "repo": "a/b" })), Err("issue.get needs number.".to_owned()));
804 assert!(resolve(issue, &json!({})).unwrap_err().starts_with("Give an action"));
805 assert!(resolve(issue, &json!({ "action": "explode" })).unwrap_err().contains("no action explode"));
806 let search = Tool::by_name("search").unwrap();
807 assert_eq!(resolve(search, &json!({ "query": "x" })), Ok(Op::Search));
808 let account = Tool::by_name("account").unwrap();
809 assert_eq!(resolve(account, &json!({})), Ok(Op::Whoami));
810 }
811
812 #[test]
813 fn teams_are_one_tool_and_a_workspace_reader_sees_only_its_reads() {
814 let team = Tool::by_name("team").unwrap();
815 let names: Vec<&str> = team.actions.iter().map(|action| action.name).collect();
816 assert_eq!(
817 names,
818 [
819 "list",
820 "get",
821 "create",
822 "update",
823 "delete",
824 "list_members",
825 "set_member",
826 "remove_member",
827 "list_child_teams",
828 "list_repos",
829 "set_repo",
830 "remove_repo",
831 "set_review_assignment",
832 "list_user_teams",
833 ]
834 );
835 let reader = token(Some(vec![Scope::WorkspaceRead]));
836 let tools = listed(&Gate::Token(&reader));
837 let listed_team = tools.iter().find(|tool| tool["name"] == "team").unwrap();
838 assert_eq!(
839 listed_team["inputSchema"]["properties"]["action"]["enum"],
840 json!(["list", "get", "list_members", "list_child_teams", "list_repos", "list_user_teams"])
841 );
842 assert_eq!(listed_team["annotations"]["readOnlyHint"], true);
843 // A team's role on a repository is who has access.
844 let admin = token(Some(vec![Scope::WorkspaceAdmin]));
845 let tools = listed(&Gate::Token(&admin));
846 let listed_team = tools.iter().find(|tool| tool["name"] == "team").unwrap();
847 let actions = listed_team["inputSchema"]["properties"]["action"]["enum"].as_array().unwrap();
848 assert!(actions.contains(&json!("set_review_assignment")) && !actions.contains(&json!("set_repo")));
849 let access = token(Some(vec![Scope::AccessAdmin]));
850 let tools = listed(&Gate::Token(&access));
851 let listed_team = tools.iter().find(|tool| tool["name"] == "team").unwrap();
852 assert_eq!(listed_team["inputSchema"]["properties"]["action"]["enum"], json!(["set_repo", "remove_repo"]));
853 // Both kinds of role a schema names are offered.
854 let roles = &listed(&Gate::Everything).into_iter().find(|tool| tool["name"] == "team").unwrap()["inputSchema"]
855 ["properties"]["role"]["enum"];
856 for role in ["member", "maintainer", "read", "admin"] {
857 assert!(roles.as_array().unwrap().contains(&json!(role)), "{role}");
858 }
859 assert_eq!(
860 resolve(team, &json!({ "action": "set_repo", "workspace": "acme", "team": "backend", "repo": "rocket" })),
861 Err("team.set_repo needs role.".to_owned())
862 );
863 }
864
865 #[test]
866 fn reviewers_and_code_owners_are_actions_of_their_tools() {
867 let pull = Tool::by_name("pull_request").unwrap();
868 assert_eq!(
869 resolve(pull, &json!({ "action": "request_reviewers", "repo": "a/b", "number": 1, "team_reviewers": ["backend"] })),
870 Ok(Op::RequestReviewers)
871 );
872 assert_eq!(pull.action("remove_requested_reviewers").map(|action| action.op), Some(Op::RemoveRequestedReviewers));
873 let repository = Tool::by_name("repository").unwrap();
874 assert_eq!(resolve(repository, &json!({ "action": "codeowners", "repo": "a/b" })), Ok(Op::GetCodeownersErrors));
875 assert!(reads_only(Op::GetCodeownersErrors));
876 assert!(!reads_only(Op::RequestReviewers));
877 }
878
879 /// How much smaller `tools/list` is than one tool per operation. Run
880 /// with `--nocapture` to see the numbers.
881 #[test]
882 fn the_tool_list_is_much_smaller_than_one_tool_per_operation() {
883 let before: Vec<Value> = Op::ALL
884 .into_iter()
885 .map(|op| json!({ "name": op.name(), "description": op.description(), "inputSchema": op.input() }))
886 .collect();
887 let after = listed(&Gate::Everything);
888 let before_bytes = serde_json::to_string(&json!({ "tools": before })).unwrap().len();
889 let after_bytes = serde_json::to_string(&json!({ "tools": after })).unwrap().len();
890 let agent = token(Preset::Agent.scopes());
891 let agent_bytes = serde_json::to_string(&json!({ "tools": listed(&Gate::Token(&agent)) })).unwrap().len();
892 let read = token(Preset::ReadOnly.scopes());
893 let read_bytes = serde_json::to_string(&json!({ "tools": listed(&Gate::Token(&read)) })).unwrap().len();
894 println!(
895 "tools/list: before {} tools, {before_bytes} bytes (~{} tokens); after {} tools, {after_bytes} bytes (~{} tokens); agent preset {agent_bytes} bytes (~{} tokens); read only {read_bytes} bytes (~{} tokens)",
896 before.len(),
897 before_bytes / 4,
898 after.len(),
899 after_bytes / 4,
900 agent_bytes / 4,
901 read_bytes / 4,
902 );
903 assert!(after_bytes * 2 < before_bytes, "{after_bytes} vs {before_bytes}");
904 }
905}