GitHub
10/05/2026, 2:09 PMosctrl-mcp sends its own User-Agent
The standalone MCP binary reused the API client's hardcoded osctrl-cli-http-client/<version>, so agent traffic was indistinguishable from osctrl-cli in osctrl-api logs.
• apiclient.OsctrlAPI gains an optional UserAgent field. Empty keeps the existing default, so osctrl-cli requests are unchanged.
• osctrl-mcp sets osctrl-mcp/<version>.
• Hosted MCP already forwards the calling client's User-Agent, so no change is needed there.
Result-log and query-result alerts report a stable detail
matchFields walked a Go map when evaluating match-any rules, so when several columns matched, the one visited first supplied the hit's Detail and varied from run to run. Status logs were fixed earlier; this applies the same fix to the other two paths.
• Keys are sorted once per log entry and reused across rules.
• For an empty pattern, the detail is the first non-empty value, since action is often blank and sorts early.
• Which entries match is unchanged; only the reported detail is now consistent.
• Cost: about 3% slower in the existing matcher benchmarks (20x500: 1.45 ms to 1.50 ms; 50x1000: 5.42 ms to 5.55 ms), plus one small allocation per entry for the sorted keys.
Lint
"testing" moved into the standard-library import group in pkg/queries/events_test.go. golangci-lint run ./... now reports 0 issues.
Validation
• go build ./... and go vet ./... are clean, and all 54 packages pass go test ./....
• New tests: User-Agent default and override; alert detail determinism over 50 runs. The determinism test fails against the previous matcher and passes now.
jmpsec/osctrlGitHub
10/05/2026, 2:31 PM