# Reported issues for Runner MCP

Pod holds 18 of 18 GitHub reports that passed its relevance review. This can include external user reports, maintainer-confirmed bugs, and concrete feature gaps. Treat them as evidence to inspect, not a count of distinct defects.

Back to [Runner MCP](/mcp/runner-mcp).

## Most discussed

### Harden source installer against resolver stalls and ambiguous Python crashes

## Summary

A clean Linux lab installation exposed an installer/runtime hardening gap in `install.sh`.

During the normal source-install path, the isolated venv was created successfully, but:

1. `python -m pip install "$ROOT_DIR"` first terminated with a real Python `SIGSEGV` while resolving/installing dependencies.
2. A later disposable reproduction of the combined dependency install did not crash, but entered a single-threaded ~100% CPU resolver spin with no log progress for multiple…

[Read the thread](https://github.com/Blacksp1d3r/runner-mcp/issues/194) · 2026-09-30 · closed · 31 comments

### Qualify aifordable-lab host/guest after reproducible Python SIGSEGV

## Incident

`aifordable-lab` still produces intermittent native Python `SIGSEGV` / `rc=139` during fresh-process imports of the MCP server stack.

This issue tracks the remaining private host/guest qualification after installer hardening #194 and host-integrity feature #195 were completed.

## Reproducible crash boundary

Known lab runtime:
- Ubuntu 24.04
- Python 3.12.3
- mcp 2.2.0
- mcp-types 2.2.0
- pydantic 2.13.5
- pydantic-core 2.46.5
- starlette 0.52.1
- httpx2 2.13.1
- cryptography…

[Read the thread](https://github.com/Blacksp1d3r/runner-mcp/issues/198) · 2026-09-30 · closed · 9 comments

### Replace GitHub mailbox as primary runtime control transport

Architectural requirement: Runner MCP must not depend on GitHub for normal runtime control.

GitHub remains acceptable for source control, CI, release distribution, audit export and an optional degraded-mode mailbox fallback, but the primary command/result path must continue to operate when GitHub is unavailable or rate-limited.

Target architecture:
- Runner establishes an outbound-only authenticated connection to an AIfordable-owned control relay; no inbound listener on the private host.
-…

[Read the thread](https://github.com/Blacksp1d3r/runner-mcp/issues/125) · 2026-09-28 · open · 9 comments

### Extend host-integrity gate with hardware and storage fault evidence

## Context

Lab qualification for Runner MCP is currently blocked by intermittent native Python SIGSEGVs. The existing Linux host-integrity adapter correctly detects recent fatal Python process evidence, but it does not classify likely underlying host faults.

Current evidence makes hardware/runtime instability a serious hypothesis:
- Python/pip and MCP imports have crashed at different points;
- pure source compile stress can remain stable;
- source and installed files were byte-identical in…

[Read the thread](https://github.com/Blacksp1d3r/runner-mcp/issues/195) · 2026-09-30 · closed · 7 comments

### Harden replacement-host qualification for service-user runtimes and stale installed CLIs

Context from live qualification on `aifordable-lab` after replacing the unstable i9-14900KS with a temporary i5-12400F.

Observed operator/runtime mismatches:
- The canonical Runner MCP runtime is private under `/home/aifordable-runner/.local/share/runner-mcp/venv`.
- Running the #198 userspace probe as operator `gerard` reported `Python executable not found or not executable` even though the runtime existed; the service-user home permissions prevented traversal. The safe invocation had to run…

[Read the thread](https://github.com/Blacksp1d3r/runner-mcp/issues/225) · 2026-10-02 · closed · 6 comments

### Activate and prove Runner Fabric coarse work-unit bridge end to end

Transport foundation is already merged through Runner MCP PR #111 as main commit `3ebd39981c358c307fa66afa32ad2f5fc32731cf`; issue #109 is complete. Do **not** rebuild or widen that bridge.

## Remaining goal

Activate and prove the existing coarse Runner Fabric boundary end to end only after the upstream Fabric authority/durability prerequisites are ready.

Target:
`agent -> Runner MCP fabric_run_work_unit -> private loopback Runner Fabric agent MCP -> trusted Fabric work-unit service`

Runner…

[Read the thread](https://github.com/Blacksp1d3r/runner-mcp/issues/110) · 2026-09-27 · open · 6 comments

### Prove recovery-capable self-update on the private host

Track the remaining live proof from Phase 3.8.11 without widening Runner MCP authority.

## Preconditions
- Use the merged recovery-capable baseline from current `main`; reconcile live GitHub first.
- Do not expose hostnames, addresses, usernames, paths, tokens, service names or other private infrastructure in GitHub.
- Use only the existing bounded Runner MCP/operator interfaces. Do not add a general remote shell or package-manager control as a workaround.
- Keep the operator emergency-stop…

[Read the thread](https://github.com/Blacksp1d3r/runner-mcp/issues/108) · 2026-09-27 · open · 5 comments

### Mailbox bridge: liveness heartbeat and stale-request recovery contract

Add a generic, infrastructure-neutral resilience contract for private GitHub mailbox watchers.

Goals:
- expose a sanitized liveness heartbeat without host/path/service details
- detect requests that remain unprocessed beyond a configurable age
- resume backlog processing after watcher restart without replaying completed request IDs
- preserve the existing replay ledger and fail-closed protocol
- define bounded retry/backoff for transport errors only; never retry arbitrary Runner MCP actions…

[Read the thread](https://github.com/Blacksp1d3r/runner-mcp/issues/7) · 2026-09-20 · closed · 4 comments

## Most recent

### Expose bounded Agent Bus durable-result convergence status

Context: AF-22.6 / Fabric #479 live qualification needs to verify that a replayed terminal result was acknowledged and removed from the private outbox without inspecting private filesystem paths or payloads.

## Goal
Add a read-only local status surface for the Runner MCP-owned Agent Bus state directory.

## Contract
- `runner-mcp agent-bus convergence`;
- report only bounded category + pending durable-result count;
- categories: `not_initialized`, `clear`, `pending`, `invalid`;
- never print…

[Read the thread](https://github.com/Blacksp1d3r/runner-mcp/issues/228) · 2026-10-02 · closed · 0 comments

### Add bounded async Runner Fabric bootstrap job

Required to activate the GitHub-independent Agent Bus on an existing private Runner MCP host without adding generic remote shell/package authority.

Scope:
- bootstrap only canonical `Blacksp1d3r/Runner-Fabric` at one full lowercase commit;
- asynchronous durable job with start/status actions so mailbox/MCP request timeout cannot leave ambiguous state;
- source fetched into a private temporary root;
- build wheel with the installed Runner MCP Python using `--no-deps --no-build-isolation`;
-…

[Read the thread](https://github.com/Blacksp1d3r/runner-mcp/issues/146) · 2026-09-29 · closed · 0 comments

### Make offline wheel staging test respect test-runtime packaging capability

Live self-update diagnosis: target lint passes, but target unit suite fails only at `test_real_project_wheel_can_stage_without_index`.

The live custom unit profile runs in the project test venv, while real self-update wheel staging runs in the installed Runner MCP service venv. The project test venv is not guaranteed to contain the package build backend.

Fix:
- keep the real offline wheel staging test active when the test interpreter has the required packaging backend;
- skip that…

[Read the thread](https://github.com/Blacksp1d3r/runner-mcp/issues/143) · 2026-09-29 · closed · 1 comment

### Fix self-update runtime status distribution identity

Live pre-bootstrap runtime_status still reports `version: development` although the installed distribution is `aifordable-runner-mcp`.

The self-update runtime status path still queries the legacy distribution name `runner-mcp`.

Fix that read-only status path to use the canonical installed distribution identity and add a regression test. No update/install authority changes.

[Read the thread](https://github.com/Blacksp1d3r/runner-mcp/issues/137) · 2026-09-29 · closed · 0 comments

### Add local-only self-update baseline bootstrap

The first self-update on an already-installed Runner MCP host currently fails safely with `bootstrap_required` because no compatibility/install baseline has been recorded yet.

Add one local-only bootstrap command for existing trusted installations.

Required behavior:
- command is CLI-only; no MCP, mailbox, Agent Bus or Fabric mapping;
- requires canonical `runner-mcp` project configuration and non-production staging environment;
- requires a clean checkout at an explicit full lowercase commit…

[Read the thread](https://github.com/Blacksp1d3r/runner-mcp/issues/135) · 2026-09-29 · closed · 0 comments

### Add local private Agent Bus configuration commands

Follow-up to #130.

Add local-only Agent Bus configure/status/remove commands.

Requirements:
- relay origin + runner subject validated before persistence;
- relay credential entered through hidden prompt or stdin only, never CLI argv;
- private env update remains atomic/locked and preserves unrelated secrets;
- status returns configured/not-configured only;
- remove deletes only Agent Bus relay values;
- no MCP or GitHub-mailbox mapping for configure/remove;
- no arbitrary local endpoint,…

[Read the thread](https://github.com/Blacksp1d3r/runner-mcp/issues/133) · 2026-09-29 · closed · 0 comments

### Add managed Agent Bus worker lifecycle and make GitHub watcher fallback-only

Parent: #125.

Operationalize the new AIfordable-owned control channel on the private runner.

Required:
- add a managed `agent-bus-worker` lifecycle beside server/github-watcher/completion-watcher;
- worker starts from private config only;
- worker runs outbound-only; no inbound port;
- expose bounded status: installed/enabled/active/primary-connected/fallback-only/degraded;
- do not print relay credential or private endpoint details;
- keep GitHub watcher independently enable/disable-able;
-…

[Read the thread](https://github.com/Blacksp1d3r/runner-mcp/issues/130) · 2026-09-29 · closed · 2 comments

### Respect GitHub REST reset windows and reduce watcher polling pressure

A live private-host mailbox watcher exhausted the authenticated GitHub REST primary rate limit (5000/hour).

Observed behavior:
- GitHub returned HTTP 403 with `X-RateLimit-Remaining: 0` and an explicit reset timestamp.
- The mailbox watcher continued retrying through the generic 2s/5s transport retry path and then polled again every 5 seconds.
- With a backlog, the watcher performs both request-head and compare calls per cycle, so a 5-second default can consume ~1440 REST calls/hour before…

[Read the thread](https://github.com/Blacksp1d3r/runner-mcp/issues/122) · 2026-09-28 · closed · 0 comments

### Fix CLI package-version lookup after aifordable-runner-mcp rename

Live private-host upgrade from the legacy 0.1.0 install to exact current main exposed a packaging identity mismatch: the new `aifordable-runner-mcp==0.1.2` distribution installed successfully and new runtime checks were present, but `runner-mcp --version` and `status` still reported 0.1.0 because `package_version()` queries `importlib.metadata.version("runner-mcp")`. The old distribution metadata remains in the reused venv.

Acceptance:
- query the canonical distribution name…

[Read the thread](https://github.com/Blacksp1d3r/runner-mcp/issues/119) · 2026-09-28 · closed · 0 comments

### Bridge Runner Fabric coarse work-units into Runner MCP

## Goal

Reduce agent dependence on many direct GitHub/Git/test tool calls by exposing Runner Fabric's
coarse work-unit boundary through Runner MCP.

Product boundary remains unchanged:
- Runner Fabric owns orchestration, GitHub Gateway, work-unit state/policy and durable execution;
- Runner MCP is transport/safety only and must not absorb Fabric orchestration logic.

## Tool surface

When a private Fabric endpoint is configured, expose only:
- `fabric_run_work_unit`
- `fabric_get_work_unit`
-…

[Read the thread](https://github.com/Blacksp1d3r/runner-mcp/issues/109) · 2026-09-27 · closed · 0 comments

The remaining reports are on [the project's issue tracker](https://github.com/Blacksp1d3r/runner-mcp/issues).
