rdmpw3275m-changelog-20260825-1455-remove-atlassian-rovo-and-verify-gitlab
Removed the remaining host-local Atlassian Rovo integration state on
rdmpw3275m, verified GitLab was already absent, and traced
localhost:5598/oauth/callback to Antigravity's former
mcp-remote Atlassian SSE configuration.
Scope
- Host:
rdmpw3275monly. - Requested targets: Atlassian/Rovo MCP and GitLab MCP.
- Canonical development repositories: unchanged.
- Network/public state: unchanged; no fleet-wide removal is claimed.
Root cause and attribution
- The local callback was produced by
mcp-remote, launched under Antigravity'slanguage_serverwhen it loaded the former server URLhttps://mcp.atlassian.com/v1/sse. - Local
mcp-remotesource computes its default OAuth callback port as3335 + (parseInt(first four hex characters of MD5(server URL), 16) % 45816)and uses the callback path/oauth/callback. - The Atlassian SSE URL hashes to
bbcf3c111998d8af66c1b0d7523c9a05; therefore3335 + (0xbbcf % 45816) = 5598. - Antigravity history in
/Users/richh/Library/Logs/Antigravity/language_server.logcontained the former Atlassian SSE configuration. - Before this task's cleanup phase, two local fleet messages reported
that another agent had already removed Atlassian/Rovo and
gitlab-orbitfrom/Users/richh/.gemini/config/mcp_config.jsonat 13:48 and 13:53 EDT. This task independently re-read and verified the file; it did not rewrite it. Its observed SHA-256 is4b5ad0d6f5c2cdd6cccc625b747e40781cb57720ad77dad9bf4b63718307d4f0, with mtime2026-08-25 13:53:09 EDT.
Changes made in this task
- Uninstalled the Codex Atlassian Rovo plugin through Codex Plugin
Management. The active cache at
/Users/richh/.codex/plugins/cache/openai-curated-remote/atlassian-rovowas removed by the uninstall synchronization. - Requested GitLab removal through the same manager. It returned
not_installed; no Codex GitLab plugin cache was present. - Before uninstall synchronization completed, copied the seven-file
Atlassian Rovo plugin package and install metadata to
/Users/richh/.codex/backups/plugin-removal-20260825-1441/atlassian-rovo. This backup contains plugin package metadata/assets, not OAuth credentials. - Deleted exactly 28 Atlassian-specific
mcp-remoteOAuth/PKCE cache files totaling 3,864 bytes under/Users/richh/.mcp-auth, restricted to the endpoint hashesbbcf3c111998d8af66c1b0d7523c9a05and01910c24c5f2edcaf999bd1eaaeaeee8. - The expected GitLab endpoint hash
252ab552f8636c5b82dfd2622f4486b1had zero cache files, so no GitLab auth file was deleted. - OAuth/PKCE material was intentionally not backed up because restoring it would reverse the requested disconnect and would unnecessarily preserve credential-bearing state.
- Created and released coordination check-in
/Users/richh/.agent-coordination/checkins/codex-rdmpw3275m-remove-atlassian-rovo-gitlab-20260825.json. - Sent completion evidence to the canonical fleet lead in message
20260825-145331-1E6DCA7C. - Sent a separate sanitized security notice in message
20260825-145331-A3AC136Eafter observing an unrelated active MCP process expose a credential in its argv. The process and credential were not changed or copied into this record.
Files and state touched
- Removed by uninstall:
/Users/richh/.codex/plugins/cache/openai-curated-remote/atlassian-rovo - Removed selectively: 28 matching files below
/Users/richh/.mcp-auth - Created backup:
/Users/richh/.codex/backups/plugin-removal-20260825-1441/atlassian-rovo - Created/updated check-in:
/Users/richh/.agent-coordination/checkins/codex-rdmpw3275m-remove-atlassian-rovo-gitlab-20260825.json - Created fleet messages:
/Users/richh/.agent-coordination/mail/20260825-145331-1E6DCA7C__from-codex-rdmpw3275m__to-claude-rdmsm4x__local-mcp-removal-verified.mdand/Users/richh/.agent-coordination/mail/20260825-145331-A3AC136E__from-codex-rdmpw3275m__to-claude-rdmsm4x__unrelated-argv-credential-exposure.md - Created this changelog:
/Users/richh/dev/LLM/Claude/changelogs/rdmpw3275m-changelog-20260825-1455-remove-atlassian-rovo-and-verify-gitlab.md - Read-only verification:
/Users/richh/.gemini/config/mcp_config.json,/Users/richh/Library/Logs/Antigravity/language_server.log, and localmcp-remotepackage source under/Users/richh/.npm/_npx/705d23756ff7dacc/node_modules/mcp-remote
Commands and operations
- Resolved the host with
scutil --get ComputerNameand confirmed an Aqua GUI session withlaunchctl managername. - Inspected Codex MCP state with
codex mcp list; inspected Claude MCP state read-only withclaude mcp list. - Inspected launcher ownership with
ps,pgrep, and Antigravity logs without stopping unrelated processes. - Inspected configuration with
jq,rg,stat, andshasum. - Calculated endpoint hashes and the
mcp-remotedefault callback port from the locally installed package source. - Backed up the plugin package before invoking Codex Plugin Management uninstall.
- Removed only target-prefixed OAuth cache files using a bounded
findexpression. - Validated listener state using
lsof -nP -iTCP:5598 -sTCP:LISTEN. - Re-ran removal idempotently; both Atlassian Rovo and GitLab returned
not_installedafter completion.
Verification evidence
- Matching Atlassian/Rovo/GitLab entries in
/Users/richh/.gemini/config/mcp_config.json:0. - Matching target files under
/Users/richh/.mcp-auth:0. - TCP listener on local port 5598: absent at final check.
- Processes whose command line matched
mcp.atlassian.comorgitlab-orbit:0at final check. - Active Codex Atlassian plugin cache: absent.
- Codex Plugin Management final idempotency result: Atlassian Rovo
not_installed; GitLabnot_installed. codex mcp list: onlycodex_app,computer-use, andnode_repl; no Atlassian/Rovo or GitLab entry.- Coordination check-in verification object records the same bounded final state and is released.
Rollback / undo
- Reinstall Atlassian Rovo through the Codex Plugins interface or Plugin Management, then complete OAuth again. The package backup can support inspection but deliberately does not restore authentication.
- To re-enable Atlassian in Antigravity, deliberately add the desired
current endpoint back to
/Users/richh/.gemini/config/mcp_config.jsonand reauthenticate; do not restore stale PKCE/token cache files. - No GitLab rollback is available or needed because no GitLab Codex plugin or GitLab OAuth cache was present in this task.
Outstanding owner actions and boundaries
- Start a new Codex task or restart Codex if the current task's already-materialized plugin tool list still shows Atlassian tools; installed state is removed, but an in-flight task's tool inventory can be static.
- A separate account-scoped
claude.aiAtlassian Rovo connector still appeared inclaude mcp list. It was not the local Antigravity launcher and was not changed because removing it would affect the Claude account rather than just this host-local source. - The unrelated argv credential exposure was routed to the canonical fleet lead for separate verification and remediation.