Pin mcp below the release that masks validator refusals - #9
Merged
Merged
Conversation
Every refusal this server words for itself is raised from a Pydantic WrapValidator: the bounds, the enum listings, the whole-number distinction. mcp 2.1.0 stopped propagating anything raised during argument validation, so all of it reaches the caller as the bare "Error executing tool <name>". The SDK's own docstring for the wrapper says nothing from the original reaches the client. Bisected against a minimal probe rather than assumed: 2.0.0 and 2.0.1 keep the message, 2.1.0, 2.1.1 and 2.2.0 mask it. The declared range was >=2.0.0,<3, so a fresh install from PyPI has been resolving to a masked build since 2.1.0 shipped, while ovh2 stayed correct only because it happened to install 2.0.0. This restores the suite to 1970 passing. Lifting the pin needs the refusals moved out of validators into the tool bodies, where a ToolError message still survives on every version tested.
|
Reviewed against the read-only MCP client's usual concerns (corpus text escaping into live Markdown/HTML, derived judgment/scores, PoC token leakage, unbounded output, host-validation/transport weakening, scope creep). This diff is a single-line dependency pin in Sanity-checked the surrounding claims:
No findings. The follow-up mentioned in the description (moving refusals from validators into tool bodies so the pin can eventually be lifted) is correctly scoped out of this PR. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Restores
mainto green and, more importantly, stops shipping a degraded package to PyPI.What broke
Every refusal this server words for itself is raised from a Pydantic
WrapValidator- the bounds, the enum listings, the whole-number distinction.server.py:195-205calls that wording deliberate: "What stays ours is the wording."mcp2.1.0 stopped propagating anything raised during argument validation. The SDK docstring for its wrapper is explicit: "nothing from the original reaches the client."Proved with a minimal probe rather than inferred:
Exception type is irrelevant; the raise site is what matters.
Which versions
Bisected, not guessed:
So the break is 2.1.0. A
<2.2pin would have looked right and still shipped the bug.Exposure
The declared range was
mcp>=2.0.0,<3, so a freshpip install eip-mcphas been resolving to a masked build since 2.1.0 shipped. Production on ovh2 is unaffected only by luck: it installed 2.0.0, and a live call still returnslimit must be between 1 and 100.Result
1970 passed, 232 skipped, 0 failed.
Lifting this
The pin is a stopgap. The durable fix is moving the refusals out of validators into the tool bodies, where a
ToolErrormessage survives on every version tested, and that is a deliberate change rather than something to fold in here.