feat(guard): read the Zerto task, and ask before guarding unknown tools (#6)

This commit was merged in pull request #6.
This commit is contained in:
2026-09-21 15:07:43 -04:00
parent 5039f7378d
commit 1d53029038
10 changed files with 359 additions and 22 deletions
+23 -6
View File
@@ -11,16 +11,33 @@ You talk to **one** MCP: `zerto_rewind_mcp`. Do not also require official ZVM MC
## Loop (mandatory)
Before **every** guest-mutating tool call:
Before **every** tool call that might touch a guest:
1. Take the hostname / VM name / Zerto `vmIdentifier` from the tool args.
2. Call `zerto_guard_before_mutate` with `change_id` and `action` (or `zerto_find_protection` then `zerto_create_tagged_checkpoint`).
3. If `ok` is not true: **stop**. Do not mutate.
4. Then run the mutating call.
2. Call `zerto_check_tool(server, tool, vm)`. Act on the verdict:
Reads skip the guard.
| verdict | what you do |
|---|---|
| `read_only` | Run the tool. No checkpoint. |
| `mutating` | Guard first. Do not ask — it is already known to change the guest. |
| `unknown` | **Ask the human.** Do not assume it is safe, and do not silently guard. |
Unlisted MCP tools pass through. If you are about to change a protected VM with a tool that is not in the catalog, call `zerto_add_mutating_tool` (server, tool, `vm_arg`) and then guard.
3. For `mutating`, or for `unknown` where the human said yes: call
`zerto_guard_before_mutate` with `change_id` and `action`.
4. If `ok` is not true: **stop**. Do not mutate.
5. Then run the call.
`unknown` is the normal case, not an edge case. The catalogs are short and the
world of tools is not, so most tools are unclassified. Unknown means *nobody has
said this is read-only* — it does not mean safe. Put the decision to the human:
> `winrm/run_ps` is not a known read-only command. It may change `web01`.
> Insert a Zerto tagged checkpoint first so this is reversible?
If they say yes, guard, then run. If they say no, run it and tell them plainly
that it is not reversible through Zerto. If they want it remembered, call
`zerto_add_mutating_tool` (server, tool, `vm_arg`) so it is guarded
automatically next time instead of asking again.
## find_protection outcomes