Skip to main content

af-filesystem-mcp v0.1.1

An MCP server that gives an AF (Analysis Facility) user browse/read access to their own files on the AF's shared NFS home (/home/<unixname>) and Ceph data area (/data/<unixname>) — nothing more. Designed to sit behind af-mcp-platform's credential broker so an LLM session can look at a user's own analysis outputs, condor logs, and scratch files without a human copying paths around.

What it does

  • List a directory (fs_list)
  • Read a file, by byte range or line range, including head/tail (fs_read)
  • Stat a path — size, mtime, type, permissions (fs_stat)
  • Grep for a pattern across files under a directory, capped in files scanned and matches returned (fs_grep)

That is the entire v1 tool surface. There is deliberately no write tool, no delete, no chmod, no arbitrary command execution, and no full-tree walk (directory-size, duplicate-finder). See CLAUDE.md for the design rationale and phase-2 (write) plan.

Security model

Every filesystem operation for user alice runs in a short-lived helper subprocess impersonating alice's real uid/gid — the server process itself (running as root, holding only CAP_SETUID/CAP_SETGID) never reads or writes a byte of user data directly. This means the kernel (and, for the NFS-mounted homes, the NFS server) enforces every permission check against the real identity: even a bug in this server's own path-pinning logic can only let alice reach what alice's real uid could already reach. See CLAUDE.md § "Security model" and src/af_filesystem_mcp/paths.py for the full design rationale, and maniaclab/af-mcp-platform#188 for the workplan and the (rejected) alternatives this design was chosen over.

Installation

pip install af-filesystem-mcp

Or with pixi:

pixi add af-filesystem-mcp

Requirements

  • Python 3.10+
  • Linux (the impersonation mechanism is POSIX setuid/setgid; there is no Windows/macOS deployment target — local stdio mode runs fine on any OS for development, since it never impersonates)

Quick start (local development, stdio)

In stdio mode there is exactly one caller (you), so no impersonation happens — the server operates directly as your own uid/gid, confined to your own $HOME and a configurable data root:

af-filesystem-mcp serve --data-root /data

Broker mode (production, HTTP)

af-filesystem-mcp serve --transport http \
  --broker-url https://mcp.af.uchicago.edu \
  --broker-audience af-filesystem-mcp \
  --home-root /home --data-root /data

Bearers are broker-issued identity JWTs (aud=af-filesystem-mcp) carrying uid/gid/unixname POSIX claims (af-mcp-platform's identityProviders[].targetOptions.af-filesystem-mcp.includePosix: true). Requires the broker extra: pip install af-filesystem-mcp[broker].

Development

pixi install
pixi run test
pixi run lint

See CLAUDE.md for architecture, the impersonation/path-confinement design, and conventions for adding a new tool.

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

af_filesystem_mcp-0.1.1.tar.gz (107.9 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

af_filesystem_mcp-0.1.1-py3-none-any.whl (38.6 kB view details)

Uploaded Python 3

File details

Details for the file af_filesystem_mcp-0.1.1.tar.gz.

File metadata

  • Download URL: af_filesystem_mcp-0.1.1.tar.gz
  • Upload date:
  • Size: 107.9 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for af_filesystem_mcp-0.1.1.tar.gz
Algorithm Hash digest
SHA256 7380e03d658c5a7a974a2108e575adf3cef98d8028244f485d95db28e15b59e0
MD5 643d5a8f2ad0244dcd2b18e5a243743e
BLAKE2b-256 1f0dae02604c2a0b1000ab1f22b5fd841b1c4f009584681bd2785b7836eb00ae

See more details on using hashes here.

Provenance

The following attestation bundles were made for af_filesystem_mcp-0.1.1.tar.gz:

Publisher: cd.yml on maniaclab/af-filesystem-mcp

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file af_filesystem_mcp-0.1.1-py3-none-any.whl.

File metadata

File hashes

Hashes for af_filesystem_mcp-0.1.1-py3-none-any.whl
Algorithm Hash digest
SHA256 50d2a4b2f9129d2c0f743b14a76a40acd77a0019eab29f6ffb7a441a32927e33
MD5 c9c9fd928b1e2a38b9671407ca67a442
BLAKE2b-256 74847387ae4b12d8ee6b5294c1f765740956162258de5e31499c4548982956b7

See more details on using hashes here.

Provenance

The following attestation bundles were made for af_filesystem_mcp-0.1.1-py3-none-any.whl:

Publisher: cd.yml on maniaclab/af-filesystem-mcp

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Release history Release notifications | RSS feed

0.1.3

2 files

0.1.2

2 files

This release

0.1.1 This release

2 files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page