Skip to content

[RUN-4807] Serve the 2026-07-28 MCP protocol revision over stdio - #88

Merged
fdevans merged 3 commits into
mainfrom
protocol-update-final
Aug 20, 2026
Merged

fdevans merged 3 commits into
mainfrom
protocol-update-final

Conversation

@smartinellibenedetti

@smartinellibenedetti smartinellibenedetti commented Aug 20, 2026 •

Copy link
Copy Markdown
Contributor

About this change

Jira Ticket: RUN-4807

Purpose of the Changes

Adds 2026-07-28 ("modern era") protocol support over stdio, alongside the existing 2025-era protocol, via serveStdio(() => server). Reworks destructive-action confirmation (api_call DELETE/credential-regen, acl_manage delete/update) off the deprecated Server.elicitInput (which throws on a 2026-07-28-era request) onto the MRTR inputRequired() pattern — written once for both eras, per the SDK's own migration guide: the SDK's built-in legacy shim fulfills it on 2025-era connections via a real elicitation/create request, verified both against the SDK's runtime source and a real unpinned client in a new integration test.

Also: cacheHints for the 2026-07-28 CacheableResult fields (optional tuning — the SDK fills safe defaults on its own), a resources/templates/list handler (was unregistered, causing a live "Method not found" via MCP Inspector), and an inspector.config.json + npm run inspect update to exercise Modern era.

Supersedes #85 (targets this same sdk-update base) — full rationale, SDK-internals evidence, and independent review findings (SDK-audit, changelog-completeness, update-protocol-branch comparison, official-guide cross-check) are in PROTOCOL_2026_07_28_MIGRATION_PLAN.md.

Kind of Change

  • Bug Fix
  • Enhancement/New Feature/Behavior
  • Maintenance/Refactor
  • Other... (FILL IN)

Development Checklist

  • npm run validate passes locally (build + test + integration validations)
  • Unit tests added/updated for modified code — confirmation.test.ts rewritten for the unified era-agnostic design; two new integration test files drive a real client against the built server on both eras
  • New/changed tools, resources, or prompts documented in CLAUDE.md if applicable — updated the Entry point section: serveStdio()/dual-era serving, the new resources/templates/list handler, and the MRTR-based confirmation rework
  • New environment variables documented in CLAUDE.md's Environment Variables table — N/A, none added
  • Docs download / RUNDECK_DOCS_PATH behavior unaffected, or changes called out below — unaffected

Testing

Testing setup:

npm install
npm run build
npm test
npm run validate

Acceptance Criteria:

  • npm run build succeeds with no TypeScript errors
  • npm test passes (390/390), including both 2025-era and 2026-07-28-pinned integration coverage
  • npm run validate passes
  • A client pinned to versionNegotiation: { mode: { pin: "2026-07-28" } } completes the full destructive-action MRTR round trip (input_required → retry → resolved outcome)
  • A plain default-negotiation (2025-era) client completes the identical round trip via the SDK's legacy shim, with byte-identical server-side log behavior to the modern-era path
  • Docker image (rundeck/mcp-ci:latest) rebuilt and smoke-tested clean, including a real MCP initialize round trip

Switches to serveStdio(() => server) so the server negotiates both the
2025-era protocol and 2026-07-28 from the same handler registrations, and
reworks destructive-action confirmation off the deprecated (and, on a
2026-07-28-era request, throwing) Server.elicitInput onto the MRTR
inputRequired() pattern, written once for both eras — the SDK's own legacy
shim fulfills it on 2025-era connections via a real elicitation/create
request, verified against both the SDK's runtime source and a real unpinned
client in a new integration test.

Also adds cacheHints for the 2026-07-28 CacheableResult fields (optional
tuning, not a compliance requirement — the SDK fills safe defaults), a
resources/templates/list handler (previously unregistered, causing a
"Method not found" observed live via MCP Inspector), and an
inspector.config.json + npm run inspect update to exercise Modern era.

Full rationale, SDK-internals evidence, and review findings in
PROTOCOL_2026_07_28_MIGRATION_PLAN.md.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
rolldown 1.2.5 (a transitive dev dependency: @modelcontextprotocol/inspector
-> vite -> rolldown) is caught by the internal registry's quarantine policy
for recently-published packages, breaking npm ci in CI. 1.2.4 is a week
older, still within vite's own declared ~1.2.1 range, and never touches
this repo's own code (rolldown is only vite's bundler for the Inspector's
web UI, not shipped or used at runtime).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@smartinellibenedetti smartinellibenedetti changed the title Serve the 2026-07-28 MCP protocol revision over stdio [RUN-4807] Serve the 2026-07-28 MCP protocol revision over stdio Aug 20, 2026
…n in CLAUDE.md

The Entry point section still said "all six MCP request types" and made
no mention of serving two protocol eras or the elicitInput->MRTR rework,
both introduced by the 2026-07-28 migration in this branch.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Base automatically changed from sdk-update to main August 20, 2026 14:16
@fdevans
fdevans merged commit bfe022d into main Aug 20, 2026
4 checks passed
@fdevans
fdevans deleted the protocol-update-final branch August 20, 2026 14:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants