Skip to content

fix(mcp): enforce transport lifecycle contracts and document oracle workflows - #650

Merged
jmagar merged 14 commits into
mainfrom
codex/conformance-final-recovery
Sep 15, 2026
Merged

jmagar merged 14 commits into
mainfrom
codex/conformance-final-recovery

Conversation

@jmagar

@jmagar jmagar commented Sep 14, 2026 •

Copy link
Copy Markdown
Collaborator

Problem and behavior

Labby's stateless HTTP endpoint advertised historical MCP protocols whose session lifecycle it does not implement. This change limits HTTP discovery to 2026-07-28, preserves historical initialization on direct stdio, and removes unusable legacy resource-subscription capabilities. It also pins Labby and standalone labby-auth to the reviewed rmcp 3.3 fork follow-up revision in SDK PR #4, building on the previously merged upgrade.

Stacked on #635 so this PR contains only the lifecycle, oracle, and operator-workflow follow-up.

Verification and operator workflow

  • Add four executable HTTP requirement mappings, bringing the registry to nine oracles against the 2,223-row pinned inventory.
  • Provide documented Just recipes for source preparation, intent checks, oracle execution, reports, authorization checks, and C1/T2/T3 verification.
  • Keep source preparation immutable and custom specification checkouts read-only during validation.

Review and fixes

Lavra and Vibin apply-fixes review completed through parallel scoped reviewers, root synthesis, reproduced failures, fixes, and independent re-review. No actionable review finding remains unaddressed in this patch.

  • Correct HTTP-083 applicability and cover both JSON and actual POST SSE behavior, fresh subscription acknowledgements without event IDs, and rejected GET resumption.
  • Bind the literal historical-version rejection matrix to the SDK-known version set.
  • Fix virgin no-checkout source preparation and keep custom-checkout validation independent of the default checkout.
  • Add recipe regressions to CI with the repository-pinned Just installation.
  • Preserve process-group cleanup for timeout, Ctrl-C, and SIGTERM without masking cancellation.
  • Label overridden conformance pins as diagnostic and record their effective values.
  • Correct legacy-transport documentation and replace a stale technology-guide SDK SHA with a canonical link.
  • Fix strict stateless initialize status/header validation and malformed-header JSON-RPC envelopes in the narrow SDK follow-up: fix(rmcp): enforce strict stateless initialization errors rust-sdk#4, immutable commit a30965679d27ba4f7d17e9d8efa7c95742eb6b42. Only two SDK files changed. Relaxed/stateful legacy behavior remains compatible.

A refresh attempt encountered setup-stage ledger timeouts before protocol assertions. Live tracing also disproved an experimental catalog-polling readiness fix: root tools/list is intentionally cached-only and does not start lazy upstreams. That polling was removed, all original deadlines were retained, and a literal cold-list regression now covers the real contract. Failed/intermediate attempts are not counted as passing evidence.

Validation

  • All nine registered product-wire oracles passed twice consecutively on unchanged final source, with source/dependency-bound receipt and coverage report.
  • Standalone labby-auth: 613 checks passed (598 unit, 14 integration, and one compile-fail doctest), with two intentionally ignored checks. Real Authelia container acceptance and the ignored configuration-builder doctest were not executed.
  • Eleven exact HTTP lifecycle, discovery, direct-stdio, and bridge checks passed on the portable SDK pin.
  • The additional literal cold tools/list regression passed.
  • 61 focused SDK tests passed, including demonstrated red/green malformed-header regression; SDK PR feat: UniFi dispatch, API bearer auth, rmcp docs, linkding/paperless/prowlarr onboarding #4 GitHub checks are green.
  • 71 focused extraction, reporter, selector, recipe, and conformance-script tests passed; workflow-policy checks also passed.
  • Documentation checks passed: 594 local links and 113 canonical documents.

Coverage boundary

The retained report credits nine requirements and explicitly leaves 2,214 unresolved. The registered-oracle gate passes; the denominator-wide compliance gate remains incomplete by design. This is not full MCP compliance or a claim that the entire Labby suite was executed. The stack remains based on #635, and neither this PR nor the SDK follow-up has been merged or deployed.

@github-actions github-actions Bot added documentation Improvements or additions to documentation dependencies Pull requests that update a dependency file labels Sep 14, 2026
@jmagar
jmagar marked this pull request as ready for review September 14, 2026 06:44
Base automatically changed from codex/verification-conformance-integration to main September 14, 2026 11:38
@jmagar
jmagar force-pushed the codex/conformance-final-recovery branch from 7dc1b11 to 5a61c37 Compare September 14, 2026 11:40
@jmagar
jmagar enabled auto-merge (squash) September 14, 2026 11:40
@jmagar
jmagar merged commit 53305c3 into main Sep 15, 2026
38 of 39 checks passed
@jmagar
jmagar deleted the codex/conformance-final-recovery branch September 15, 2026 23:45
jmagar added a commit that referenced this pull request Sep 16, 2026
…oracle workflows (#650)" (#667)

This reverts commit 53305c3.

Co-authored-by: Jake Magar <jmagar@users.noreply.github.com>
@jmagar jmagar mentioned this pull request Oct 2, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file documentation Improvements or additions to documentation

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant