Skip to content

feat: MCP SDK tier improvements - #9

Draft
yurirocha15 wants to merge 167 commits into
mainfrom
feat/mcp-sdk-tier-improvements
Draft

yurirocha15 wants to merge 167 commits into
mainfrom
feat/mcp-sdk-tier-improvements

Conversation

@yurirocha15

Copy link
Copy Markdown
Owner

Summary

Tier-gate work for the SDK: conformance coverage, server-side OAuth challenge support, hardening of peer-input handling, and a series of teardown and close-race fixes. 164 commits; CHANGELOG.md (Unreleased) is the detailed record.

Added

  • Fixtures and a pinned harness for the official MCP conformance runner.
  • Server-side OAuth challenge support on HttpServerTransport, with set_async_bearer_token_validator() and set_max_request_body_bytes().
  • ClientOptions::on_protocol_error for messages the client discards.
  • Secure random generation and serialized transport-write helpers.
  • Project policy documents (ROADMAP.md, MAINTENANCE.md), issue templates and a label manifest.
  • Reproducible cross-SDK benchmark tooling.

Changed

  • Implementation moved out of oversized headers into compiled translation units.
  • Explicit null optionals from peers are read like absent members instead of being rejected.
  • Tool handler exceptions are reported as a CallToolResult error; undecodable incoming messages no longer end the client session.
  • A Server may be destroyed while handlers are still in flight.
  • Stricter OAuth metadata and fetch-policy validation.
  • close() from a thread that does not run the io_context is no longer lost on the OAuth, HTTP and WebSocket client transports. An HTTP write cut short by close() reports operation_aborted on every platform.

Testing

CI workflow green on d3a06f5 (run 37270051655, 10/10 jobs): 869 tests on Linux (four configs plus sanitize), 861 on macOS, 857 on Windows.

conformance.yml and plan-guards.yml have not run on this branch before this PR.

Known follow-ups

  • WebSocketClientTransport has no handshake timeout.
  • A write that never started on a closed HttpClientTransport throws runtime_error rather than operation_aborted.
  • No TSan job in CI.

…on units

OAuth, client runtime, protocol tools, memory transport, and HTTP types
now compile as .cpp files; protocol models and typed handler templates
remain header-based.
Fixtures, run script, and regression baseline for the official
@modelcontextprotocol/conformance runner at spec revision 2025-11-25,
plus a --conformance build flag.
…ults

Order counterbalancing, environment and container capture, resource
headroom validation, protocol verification, and the audited production
run results.
ROADMAP (tier gates), MAINTENANCE (triage SLAs), VERSIONING
(compatibility surface), DEPENDENCY_POLICY (runtime dependency floors);
guides and examples refreshed for the compiled runtime split.
@yurirocha15
yurirocha15 force-pushed the feat/mcp-sdk-tier-improvements branch from d3a06f5 to 852db94 Compare October 5, 2026 07:50
@yurirocha15
yurirocha15 requested a balanced review from Copilot October 5, 2026 08:15

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

The change spans 164 commits across concurrency-sensitive transports, OAuth security, and teardown/close-race fixes, a surface too broad and high-risk to approve without final human review.

Review effort: Balanced
Findings: None

What changed in this PR

This PR is a broad "tier improvement" pass on the mcp-cpp-sdk, combining conformance test coverage, server-side OAuth challenge support, hardening of peer-input handling (treating explicit null optionals like absent members), tool-handler exception semantics, and a series of teardown / close()-race fixes across the OAuth, HTTP and WebSocket client transports. It also adds project policy docs, CI workflows, and cross-SDK benchmark tooling. The slice reviewed here focuses primarily on the supporting test infrastructure and a new versioning policy document.

Changes:

  • Adds shared test helpers and Linux-only libc interposers (socket_gate, resolve_gate, stalling_server) to deterministically park Asio connect/resolve/stall paths so close()-race behavior can be tested without timeouts.
  • Updates server tests to send notifications/initialized after initialize, replaces a racy std::ostringstream poll with a mutex-guarded CollectingStreambuf, and aligns tool-result assertions with the new structuredContent shape and the middleware-throws→JSON-RPC-error behavior.
  • Adds a VERSIONING.md compatibility policy document.
File Description
VERSIONING.md New SemVer / ABI / release-evidence compatibility policy.
test/​test_utils.hpp Adds shared make_initialized_notification() helper.
test/​support/​stalling_server.hpp Test peer that accepts one connection and holds it open with no I/O.
test/​support/​socket_gate.{hpp,cpp} Linux socket() interposer to park an Asio connect at socket-open time.
test/​support/​resolve_gate.{hpp,cpp} Linux getaddrinfo() interposer to park an Asio resolve past its cancel check.
test/​server/​server_subscriptions_test.cpp Sends initialized notification after initialize.
test/​server/​server_progress_test.cpp Sends initialized notification after initialize.
test/​server/​server_stdio_test.cpp Race-free CollectingStreambuf; structuredContent assertion; signal-shutdown test.
test/​server/​server_middleware_test.cpp Middleware-throws now asserts a JSON-RPC error; structuredContent assertions.

I verified the central correctness-sensitive areas: the has_json_value null-tolerance helper and its consistent application, the server.cpp dispatcher's tool-exception→isError handling (with middleware exceptions correctly surfacing as g_INTERNAL_ERROR), the SerializedTransportWriter strand serialization and lost-wakeup handling, the secure_random session-id length, the atomic CAS logic in the test gates, and that all newly referenced scripts (check_readme_snippets.py, check_json_matrix.py, test_check_json_matrix.py) and constants exist. I did not find concrete, objective defects in the reviewed slice, and the CI workflow is reported green at d3a06f5.


💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants