feat(nvim-core): make nvim_execute_lua read-only to enforce specialized tool usage

This commit is contained in:
Riz Ashraf committed 2026-10-08 23:19:47 +01:00
1 parent 9d9e959744
commit 5485b40d14
1 file changed
+9 -19
+9 -19
View File
@@ -1868,27 +1868,17 @@ pub async fn run_mcp_loop(app_name: &str, app_version: &str) {
"nvim_execute_lua" => { "nvim_execute_lua" => {
if let Some(code) = args.get("code").and_then(|v| v.as_str()) { if let Some(code) = args.get("code").and_then(|v| v.as_str()) {
// BAKE IN: Block interactive prompts that cause server deadlocks // READ-ONLY ENFORCEMENT: Block any Lua code that attempts to mutate state.
let lower_code = code.to_lowercase(); let lower_code = code.to_lowercase();
if lower_code.contains("vim.fn.input") if lower_code.contains("vim.cmd")
|| lower_code.contains("vim.ui.select") || lower_code.contains("nvim_buf_set_lines")
|| lower_code.contains("vim.fn.confirm") || lower_code.contains("nvim_buf_set_text")
|| lower_code.contains("vim.ui.input") || lower_code.contains("nvim_command")
|| lower_code.contains("nvim_set_current")
|| lower_code.contains("nvim_win_set")
|| lower_code.contains("nvim_buf_set_name")
{ {
send_error(id, -32600, "CRITICAL ERROR: Interactive Lua functions (input, select, confirm) are strictly forbidden via MCP as they will hang the headless server.").await; send_error(id, -32600, "CRITICAL ERROR: nvim_execute_lua is restricted to READ-ONLY queries to prevent agents from bypassing the specialized visual tools (nvim_buffer, nvim_visual). Use the designated tools to mutate editor state.").await;
return;
}
// Block the 'c' confirm flag in vim.cmd substitutions
if (code.contains("vim.cmd")
|| code.contains("vim.api.nvim_command"))
&& code.contains("%s")
&& (code.contains("gc'")
|| code.contains("gc\"")
|| code.contains("gc\n")
|| code.contains("c'")
|| code.contains("c\""))
{
send_error(id, -32600, "CRITICAL ERROR: The 'c' (confirm) flag in Neovim substitutions is strictly forbidden via MCP as it triggers an interactive prompt that hangs the headless server. Use '/g' or '/ge' instead.").await;
return; return;
} }