fix(mcp): npm launcher falls back to api.github.com and honours proxies - #598
Merged
Merged
Conversation
On Windows the launcher always downloads the binary from GitHub Releases (no platform package exists there), and that download is the channel most often blocked or flaky on restricted networks. The MCP client then waits forever for initialize. - retry a failed github.com download through api.github.com release assets; a 404 is final, and SHA256SUMS verification is unchanged - route downloads through HTTPS_PROXY / HTTP_PROXY with a CONNECT tunnel - on failure, print the release URL and the exact cache path where the binary can be placed by hand ref #597
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
The npm launcher downloads the native binary from GitHub Releases whenever no platform package is installed. That is every Windows run, because the bare
crw-mcp-win32-*npm names are held by npm security. On restricted networks thegithub.comdownload host is often blocked whileapi.github.comstill works, and the MCP client then waits forever forinitialize.Changes
github.comdownload through theapi.github.comrelease asset endpoint. A 404 is final (the file is missing from the release), and SHA256SUMS verification is unchanged, so an unverified byte still never reaches disk.HTTPS_PROXY/HTTP_PROXYwith a CONNECT tunnel, no new dependency.NO_PROXYis not honoured.Verification
npm testinmcp/crw-mcp: 23/23, including new tests for the API fallback, a mismatched archive still being refused on the fallback path, 404 not falling back, and the proxy CONNECT target.github.comand allows everything else: the proxy log showsgithub.com:443blocked, thenapi.github.com:443andrelease-assets.githubusercontent.com:443. The binary downloaded, passed the checksum and ran.Not in this PR
The proper Windows fast path (scoped
@fastcrw/crw-mcp-win32-*platform packages) needs the npm org and a first publish, and will follow separately.ref #597