Skip to content

v0.2.0

Choose a tag to compare

@jsmith13 jsmith13 released this 18 Aug 17:49
· 48 commits to main since this release
Immutable release. Only release title and notes can be modified.
30b3d34

Breaking

  • The connector CLI no longer falls back to no-op auth when no backend is configured. Starting without
    authentication is now an explicit opt-in via CONNECTOR_ALLOW_NOOP_AUTH=1; otherwise the connector exits with
    a configuration error, so a missing or misspelled ENTRA_CLIENT_ID fails the deployment instead of quietly
    starting it unprotected. Setting only one of ENTRA_CLIENT_ID / ENTRA_TENANT_ID is likewise now an error
    rather than silently selecting no-op auth
    (#287).

    Who is affected: anyone starting mcp-connector-server without both ENTRA_CLIENT_ID and
    ENTRA_TENANT_ID set — typically local development and CI. A connector that previously started with a
    No ENTRA_CLIENT_ID/ENTRA_TENANT_ID set warning now exits with status 1.

    To migrate: set CONNECTOR_ALLOW_NOOP_AUTH=1 to keep the old unauthenticated behaviour, or configure a
    real backend (ENTRA_CLIENT_ID + ENTRA_TENANT_ID, or CONNECTOR_AUTH_FACTORY). Deployments using the
    bundled Azure scripts are unaffected: _deploy-common.sh already requires both Entra variables.

Added

  • SessionConfig.data_manager_factory for supplying a customized DataLakeDataManager per session, and an
    optional data_manager argument on Session. A deployment needing a different credential, a custom artifact
    resolver, extra fetchers, or configuration derived from the session's user_identity / user_token no longer
    has to subclass SessionManager and replace session.data_manager after the fact — a workaround that leaked a
    temp cache directory per session, since DataLakeDataManager allocates one eagerly in its constructor. The
    factory receives a SessionContext and must return a fresh instance per session, because the session owns the
    manager and cleans it up (#307).

  • CONNECTOR_AUTH_FACTORY for pointing the connector CLI at a "module.path:factory" that returns a custom
    AuthConfig, and an optional auth_config_factory argument on connector.cli.main() so a downstream package
    can ship its own console script that reuses the CLI's environment parsing and server selection. Operators with
    an identity provider other than Entra ID no longer have to fork the CLI to use
    mcp-connector-server (#287).

  • artifact_resolver on DataLakeDataManager, plus an ArtifactResolver protocol and the built-in
    SearchIndexArtifactResolver it now delegates to. <blob>id</blob> tags previously required an Azure AI
    Search index to resolve, so deployments cataloging assets in a manifest, a database, or a REST service could
    not use them at all without overriding a private method. Omitting the argument builds the search-backed
    resolver from the environment exactly as before. The asset-tag guidance shown to the agent now sources its
    availability note from the resolver's unavailable_reason instead of naming DATA_LAKE_SEARCH_ENDPOINT
    unconditionally, so it stays accurate on other backends
    (#306).

Fixed

  • Kernel teardown now claims its target atomically and can be awaited, so a session's resources are actually
    released when a caller says they are. _shutdown_kernel removed the session from the kernel registry after
    its awaits and every caller scheduled it as a bare create_task, which left four overlapping failures: a
    concurrent execute could be handed a kernel that was already being destroyed; a second close scheduled a
    duplicate teardown that died with KeyError as an unretrieved task exception; a teardown that resumed late
    could evict a replacement kernel and rmtree the live session's outputs directory; and
    _cleanup_parallel_batch_sessions reported a batch cleaned up while still holding every child kernel — and
    every child kernel's GPU memory. The kernel and all of its per-kernel state are now dropped in one synchronous
    step before the first await, teardowns coalesce onto a single strongly-referenced task whose failures are
    logged, _get_or_create_kernel waits for a pending teardown before building a replacement, and the new
    aclose_session() lets callers wait for the resources to be freed. close_session() keeps its synchronous
    signature and now returns the teardown task; called with no running event loop it warns naming
    aclose_session() rather than silently leaking the kernel through a get_event_loop() fallback that has been
    dead since Python 3.12 (#314).
  • Kernel bootstrap state is now keyed to the kernel process rather than the session id, so a session whose
    kernel is rebuilt gets its tool proxies and AGORA_OUTPUT_DIR preamble re-injected. Previously a session id
    outliving its kernel — after an idle-kernel cleanup, a request timeout, or an explicit close followed by reuse
    of the same logical id — left the replacement kernel bootstrapped in name only: the injection latch still held
    the session id, so no proxies were installed and every subsequent call to a tool helper raised NameError,
    while trace flushing tried to read a ToolCallLog that no longer existed. SessionManager now stamps each
    kernel with a unique, never-reused generation id and records bootstrap steps against it, so every teardown
    path — including any added later — invalidates that state without having to know it exists
    (#311).
  • {name}_check_batch and {name}_cancel_batch failed with 404: Batch '<id>' not found for every valid batch,
    leaving results from {name}_parallel_execute unreachable. Both tools resolve the owning session from the batch
    status payload, which never carried parent_session_id, so the ownership check always failed. Because that
    payload is built before the check runs, a finished batch had its results computed and its child sessions and
    batch state cleaned up, then discarded rather than returned — so a second call reported the batch as genuinely
    missing (#304).
  • {name}_check_batch and {name}_cancel_batch now settle authorization before building a status payload.
    Building one retires a terminal batch, so a caller who supplied a batch id they did not own could close its
    child sessions and prune its state before being refused, destroying results the owner had not yet read
    (#304).
  • Registered data access blob fetchers independently of Azure AI Search configuration, and allowed callers to
    provide a storage credential directly, so fully qualified blob URLs can be fetched without configuring artifact
    ID resolution (#305).
  • The expired-session sweep now emits the same leaked-kernel warning as close_session() when it runs without a
    running event loop, instead of dropping the kernel silently. Only the scheduling helper can distinguish having
    nothing to tear down from having no loop to tear it down on, so the warning moved there and names the operation
    that hit it. It is the background path where silence hurts most, since nothing is watching it
    (#317).