feat(mcp): release checkpointed read-only ID pagination (0.2.22) #42
No reviewers
Labels
No labels
waiting-on-julian
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
jlxq0/jmap-mcp!42
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "release/query-email-ids-0.2.22"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Scope
Add the reviewed read-only
query_email_idstool for checkpointed bounded historical ID enumeration; retain all 47 legacy tools and OAuth. Includes the separate minimal rustls 0.23.45 security repair for RUSTSEC-2026-0285. No mail mutation, auth or workflow changes.Exact source/review chain
5cbd0df823.6c5ed2d72e; verified bundle and all 51 payload hashes.07e591ff20; tree3e23b8e952. The only delta above reviewed parent is the package version 0.2.21 -> 0.2.22 in Cargo.toml and Cargo.lock. Independent version-delta review APPROVE; unchanged application/dependency/workflow objects.Verification
Owner and fresh bundle clone each passed 236 tests, fmt/clippy, RustSec, OSV, cargo-deny and source Trivy on the combined parent; five real-router probes and unchanged legacy tool schemas. Existing chacha20 yanked warning is permitted by unchanged CI invocation, not newly waived. No local Rust toolchain is present in Clark runtime: this exact versioned head requires the fresh real Forge cargo and source/image build gates before merge/release; prior results are not a substitute.
Release gates
Do not merge with failing checks. After protected merge, verify exact tree/ancestry and passing current main checks, push NEW matching annotated v0.2.22 tag, require actual tag cargo/tag-ancestry/docker success including final image scan and verified index/OCI provenance. Promote through existing Renovate platform PR with deliberate protected merge; verify every running container digest and health. No hand-edited deployment substitute. Ari owns separate live bounded mailbox acceptance; no live mail acceptance claimed here.
Deployment verified at 2026-09-15T06:26:38.919834+00:00: v0.2.22 is live at https://jmap-mcp.kampong.social/mcp. Reviewed source/release revision
07e591ff20; new annotated tag v0.2.22. Actual tag CI run 143 cargo, ancestry and docker tasks all passed (including mandatory source/dependency and post-publish final-image scans). OCI index/amd64 manifest/config hashes, revision/version and SBOM/provenance statement subjects verified.Existing Renovate generated platform PR oddie-apps/platform#804; protected test run 2872 task 21082 passed at e2a6b75378c23f800b0a3513d5f7b36432f4e4d3. Independently reviewed only the tag+digest image replacement, preserving all auth/env/callbacks; protected fast-forward merge without force. Promotion/main/Argo completed-sync revision e2a6b75378c23f800b0a3513d5f7b36432f4e4d3; Argo reconciled naturally without manual refresh or resource edits.
All serving endpoint pods and ready app containers match immutable index sha256:0f029e3c99c15027689890b950972b7d6ebcb89f0207c9ea7d0dfa5e715f9450; deployment generation/observedGeneration 34, ready/updated/available replicas 1, app restarts 0.
kubectl --context=admin@fondue -n jmap-mcp rollout status deployment/jmap-mcp --timeout=30sreturneddeployment "jmap-mcp" successfully rolled out. Public /health HTTP 200: healthy, version 0.2.22; protected /mcp remains expected unauthenticated HTTP 401. Verified twice after rollout; Argo green was never substituted for container identity.Live authenticated tools/list and personal pagination acceptance are explicitly NOT claimed: Clark has no own configured JMAP MCP connection and accessed no peer credentials. Synthetic real-handler captures contain 48 tools, all original 47 unchanged plus read-only query_email_ids. Ari owns fresh live schema discovery and only two bounded ID pages via existing credentials, tracked in t_5225e419; no full history, message bodies, Email/get or mail writes occurred here.
Rollback reference is the still-available immutable v0.2.21@sha256:196ee90a46a3594fe8c91bdec5cdf95b5bd00ae86b32f5e012129175b438d020. Reviewed reversal of image-only promotion commit e2a6b75378c23f800b0a3513d5f7b36432f4e4d3 through platform protected CI/PR, preserving later config; no tag move, kubectl undo/set-image or disabling self-heal. Rollback not executed. No exceptions, credential/protection changes, auth-flow changes, gateway restarts or unrelated infra changes.