Skip to content

fix(mcp): npm launcher falls back to api.github.com and honours proxies - #598

Merged
us merged 2 commits into
mainfrom
fix/npm-launcher-windows-download
Sep 30, 2026
Merged

us merged 2 commits into
mainfrom
fix/npm-launcher-windows-download

Conversation

@us

@us us commented Sep 30, 2026

Copy link
Copy Markdown
Member

What

The npm launcher downloads the native binary from GitHub Releases whenever no platform package is installed. That is every Windows run, because the bare crw-mcp-win32-* npm names are held by npm security. On restricted networks the github.com download host is often blocked while api.github.com still works, and the MCP client then waits forever for initialize.

Changes

  • Retry a failed github.com download through the api.github.com release asset endpoint. A 404 is final (the file is missing from the release), and SHA256SUMS verification is unchanged, so an unverified byte still never reaches disk.
  • Route downloads through HTTPS_PROXY / HTTP_PROXY with a CONNECT tunnel, no new dependency. NO_PROXY is not honoured.
  • On failure, print the release URL and the exact cache path where the binary can be placed by hand.

Verification

  • npm test in mcp/crw-mcp: 23/23, including new tests for the API fallback, a mismatched archive still being refused on the fallback path, 404 not falling back, and the proxy CONNECT target.
  • Real run on a cold cache through a local proxy that blocks github.com and allows everything else: the proxy log shows github.com:443 blocked, then api.github.com:443 and release-assets.githubusercontent.com:443. The binary downloaded, passed the checksum and ran.
  • Ran on macOS only; the code path is platform independent.

Not in this PR

The proper Windows fast path (scoped @fastcrw/crw-mcp-win32-* platform packages) needs the npm org and a first publish, and will follow separately.

ref #597

On Windows the launcher always downloads the binary from GitHub Releases
(no platform package exists there), and that download is the channel most
often blocked or flaky on restricted networks. The MCP client then waits
forever for initialize.

- retry a failed github.com download through api.github.com release
  assets; a 404 is final, and SHA256SUMS verification is unchanged
- route downloads through HTTPS_PROXY / HTTP_PROXY with a CONNECT tunnel
- on failure, print the release URL and the exact cache path where the
  binary can be placed by hand

ref #597
Comment thread mcp/crw-mcp/test/download.test.js Fixed
@us
us merged commit 0bcd2dc into main Sep 30, 2026
9 checks passed
@github-actions github-actions Bot locked and limited conversation to collaborators Sep 30, 2026
@us
us deleted the fix/npm-launcher-windows-download branch September 30, 2026 21:14
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants