Summary
Three MCP server configs — neural-link, github-workflow, gitlab-workflow — did not load the Tier-1 realm root, so their provider chain had no resolvable parent. Any read of an inherited Tier-1 leaf on them (auth.mode in the boot freshness guard; AuthService / TransportService under sse transport) threw Cannot read properties of undefined (reading 'mode') — the live NL-bridge boot crash behind #14499. This makes all five server configs participate uniformly (memory-core + knowledge-base already do) and adds a contract test so a new server config cannot ship standalone.
This is the §2.1 (hierarchy participation) half of the #14499 remediation. @neo-opus-ada's #14524 is the §3 crash-fix + AGENTS.md read-gate, and her §2/§3 Option B (own-config validateRequiredEnv) builds on this participation. Fix-forward, not a revert.
Resolves #14521
Refs #14523
The fix
Each of the three config.template.mjs gains one side-effect import of the Tier-1 root (import '../../../config.template.mjs', materialized to import '../../../config.mjs') — the memory-core form. These configs consume Tier-1 leaves via shared services but do not bind AiConfig themselves, so a named import (the knowledge-base form) would be an unused binding.
Test Evidence
New contract test test/playwright/unit/ai/mcp/server/config-participation.spec.mjs asserts every ai/mcp/server/*/config.template.mjs loads the Tier-1 root (accepts both side-effect and named-import forms).
Evidence: proven as a true falsifier (red-before / green-after), not asserted —
- RED on dev (pre-fix): failed listing exactly
["github-workflow", "gitlab-workflow", "neural-link"] (MC + KB correctly absent).
- GREEN post-fix:
1 passed (30.7s).
- Functional: force-regenerated the three
config.mjs from the fixed templates and loaded each in a Neo boot context — all three resolve auth.mode = "oidc" via the chain, no crash.
Deltas
ai/mcp/server/neural-link/config.template.mjs: + Tier-1 root import + behavior comment.
ai/mcp/server/github-workflow/config.template.mjs: + Tier-1 root import + behavior comment.
ai/mcp/server/gitlab-workflow/config.template.mjs: + Tier-1 root import + behavior comment.
test/playwright/unit/ai/mcp/server/config-participation.spec.mjs: new contract test (the standalone-config falsifier).
Post-Merge Validation
Authored by Grace (Claude Opus 4.8, Claude Code).
Summary
Three MCP server configs —
neural-link,github-workflow,gitlab-workflow— did not load the Tier-1 realm root, so their provider chain had no resolvable parent. Any read of an inherited Tier-1 leaf on them (auth.modein the boot freshness guard;AuthService/TransportServiceunder sse transport) threwCannot read properties of undefined (reading 'mode')— the live NL-bridge boot crash behind #14499. This makes all five server configs participate uniformly (memory-core+knowledge-basealready do) and adds a contract test so a new server config cannot ship standalone.This is the §2.1 (hierarchy participation) half of the #14499 remediation. @neo-opus-ada's #14524 is the §3 crash-fix + AGENTS.md read-gate, and her §2/§3 Option B (own-config
validateRequiredEnv) builds on this participation. Fix-forward, not a revert.Resolves #14521 Refs #14523
The fix
Each of the three
config.template.mjsgains one side-effect import of the Tier-1 root (import '../../../config.template.mjs', materialized toimport '../../../config.mjs') — thememory-coreform. These configs consume Tier-1 leaves via shared services but do not bindAiConfigthemselves, so a named import (theknowledge-baseform) would be an unused binding.Test Evidence
New contract test
test/playwright/unit/ai/mcp/server/config-participation.spec.mjsasserts everyai/mcp/server/*/config.template.mjsloads the Tier-1 root (accepts both side-effect and named-import forms).Evidence: proven as a true falsifier (red-before / green-after), not asserted —
["github-workflow", "gitlab-workflow", "neural-link"](MC + KB correctly absent).1 passed (30.7s).config.mjsfrom the fixed templates and loaded each in a Neo boot context — all three resolveauth.mode = "oidc"via the chain, no crash.Deltas
ai/mcp/server/neural-link/config.template.mjs: + Tier-1 root import + behavior comment.ai/mcp/server/github-workflow/config.template.mjs: + Tier-1 root import + behavior comment.ai/mcp/server/gitlab-workflow/config.template.mjs: + Tier-1 root import + behavior comment.test/playwright/unit/ai/mcp/server/config-participation.spec.mjs: new contract test (the standalone-config falsifier).Post-Merge Validation
initServerConfigsregeneratesconfig.mjsfrom templates) — the three servers boot withauth.*resolving under sse + gitlab-pat.config-participation.spec.mjsgreen in the CI unit suite.npm run prepare --migrate-configdoes not propagate a newly-added side-effect import to an existingconfig.mjs(the drift-detector doesn't flag it); fresh materialization (cloud build /rm+ regenerate) does. Non-urgent — NL/gh/gitlab are stdio locally with no auth path — but it belongs in the ADR-19 lint convergence (#14500).Authored by Grace (Claude Opus 4.8, Claude Code).