Repository navigation
feat: MCP SDK tier improvements - #9
yurirocha15 wants to merge 167 commits into
Conversation
…on units OAuth, client runtime, protocol tools, memory transport, and HTTP types now compile as .cpp files; protocol models and typed handler templates remain header-based.
Fixtures, run script, and regression baseline for the official @modelcontextprotocol/conformance runner at spec revision 2025-11-25, plus a --conformance build flag.
…ults Order counterbalancing, environment and container capture, resource headroom validation, protocol verification, and the audited production run results.
ROADMAP (tier gates), MAINTENANCE (triage SLAs), VERSIONING (compatibility surface), DEPENDENCY_POLICY (runtime dependency floors); guides and examples refreshed for the compiled runtime split.
d3a06f5 to
852db94
Compare
There was a problem hiding this comment.
Copilot review overview
🔵 Needs a closer look
The change spans 164 commits across concurrency-sensitive transports, OAuth security, and teardown/close-race fixes, a surface too broad and high-risk to approve without final human review.
Review effort: Balanced
Findings: None
What changed in this PR
This PR is a broad "tier improvement" pass on the mcp-cpp-sdk, combining conformance test coverage, server-side OAuth challenge support, hardening of peer-input handling (treating explicit null optionals like absent members), tool-handler exception semantics, and a series of teardown / close()-race fixes across the OAuth, HTTP and WebSocket client transports. It also adds project policy docs, CI workflows, and cross-SDK benchmark tooling. The slice reviewed here focuses primarily on the supporting test infrastructure and a new versioning policy document.
Changes:
- Adds shared test helpers and Linux-only libc interposers (
socket_gate,resolve_gate,stalling_server) to deterministically park Asio connect/resolve/stall paths soclose()-race behavior can be tested without timeouts. - Updates server tests to send
notifications/initializedafterinitialize, replaces a racystd::ostringstreampoll with a mutex-guardedCollectingStreambuf, and aligns tool-result assertions with the newstructuredContentshape and the middleware-throws→JSON-RPC-error behavior. - Adds a
VERSIONING.mdcompatibility policy document.
| File | Description |
|---|---|
VERSIONING.md |
New SemVer / ABI / release-evidence compatibility policy. |
test/test_utils.hpp |
Adds shared make_initialized_notification() helper. |
test/support/stalling_server.hpp |
Test peer that accepts one connection and holds it open with no I/O. |
test/support/socket_gate.{hpp,cpp} |
Linux socket() interposer to park an Asio connect at socket-open time. |
test/support/resolve_gate.{hpp,cpp} |
Linux getaddrinfo() interposer to park an Asio resolve past its cancel check. |
test/server/server_subscriptions_test.cpp |
Sends initialized notification after initialize. |
test/server/server_progress_test.cpp |
Sends initialized notification after initialize. |
test/server/server_stdio_test.cpp |
Race-free CollectingStreambuf; structuredContent assertion; signal-shutdown test. |
test/server/server_middleware_test.cpp |
Middleware-throws now asserts a JSON-RPC error; structuredContent assertions. |
I verified the central correctness-sensitive areas: the has_json_value null-tolerance helper and its consistent application, the server.cpp dispatcher's tool-exception→isError handling (with middleware exceptions correctly surfacing as g_INTERNAL_ERROR), the SerializedTransportWriter strand serialization and lost-wakeup handling, the secure_random session-id length, the atomic CAS logic in the test gates, and that all newly referenced scripts (check_readme_snippets.py, check_json_matrix.py, test_check_json_matrix.py) and constants exist. I did not find concrete, objective defects in the reviewed slice, and the CI workflow is reported green at d3a06f5.
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Summary
Tier-gate work for the SDK: conformance coverage, server-side OAuth challenge support, hardening of peer-input handling, and a series of teardown and close-race fixes. 164 commits;
CHANGELOG.md(Unreleased) is the detailed record.Added
HttpServerTransport, withset_async_bearer_token_validator()andset_max_request_body_bytes().ClientOptions::on_protocol_errorfor messages the client discards.ROADMAP.md,MAINTENANCE.md), issue templates and a label manifest.Changed
nulloptionals from peers are read like absent members instead of being rejected.CallToolResulterror; undecodable incoming messages no longer end the client session.Servermay be destroyed while handlers are still in flight.close()from a thread that does not run theio_contextis no longer lost on the OAuth, HTTP and WebSocket client transports. An HTTP write cut short byclose()reportsoperation_abortedon every platform.Testing
CIworkflow green ond3a06f5(run 37270051655, 10/10 jobs): 869 tests on Linux (four configs plus sanitize), 861 on macOS, 857 on Windows.conformance.ymlandplan-guards.ymlhave not run on this branch before this PR.Known follow-ups
WebSocketClientTransporthas no handshake timeout.HttpClientTransportthrowsruntime_errorrather thanoperation_aborted.