Repository navigation
v0.2.0
Breaking
-
The connector CLI no longer falls back to no-op auth when no backend is configured. Starting without
authentication is now an explicit opt-in viaCONNECTOR_ALLOW_NOOP_AUTH=1; otherwise the connector exits with
a configuration error, so a missing or misspelledENTRA_CLIENT_IDfails the deployment instead of quietly
starting it unprotected. Setting only one ofENTRA_CLIENT_ID/ENTRA_TENANT_IDis likewise now an error
rather than silently selecting no-op auth
(#287).Who is affected: anyone starting
mcp-connector-serverwithout bothENTRA_CLIENT_IDand
ENTRA_TENANT_IDset — typically local development and CI. A connector that previously started with a
No ENTRA_CLIENT_ID/ENTRA_TENANT_ID setwarning now exits with status 1.To migrate: set
CONNECTOR_ALLOW_NOOP_AUTH=1to keep the old unauthenticated behaviour, or configure a
real backend (ENTRA_CLIENT_ID+ENTRA_TENANT_ID, orCONNECTOR_AUTH_FACTORY). Deployments using the
bundled Azure scripts are unaffected:_deploy-common.shalready requires both Entra variables.
Added
-
SessionConfig.data_manager_factoryfor supplying a customizedDataLakeDataManagerper session, and an
optionaldata_managerargument onSession. A deployment needing a different credential, a custom artifact
resolver, extra fetchers, or configuration derived from the session'suser_identity/user_tokenno longer
has to subclassSessionManagerand replacesession.data_managerafter the fact — a workaround that leaked a
temp cache directory per session, sinceDataLakeDataManagerallocates one eagerly in its constructor. The
factory receives aSessionContextand must return a fresh instance per session, because the session owns the
manager and cleans it up (#307). -
CONNECTOR_AUTH_FACTORYfor pointing the connector CLI at a"module.path:factory"that returns a custom
AuthConfig, and an optionalauth_config_factoryargument onconnector.cli.main()so a downstream package
can ship its own console script that reuses the CLI's environment parsing and server selection. Operators with
an identity provider other than Entra ID no longer have to fork the CLI to use
mcp-connector-server(#287). -
artifact_resolveronDataLakeDataManager, plus anArtifactResolverprotocol and the built-in
SearchIndexArtifactResolverit now delegates to.<blob>id</blob>tags previously required an Azure AI
Search index to resolve, so deployments cataloging assets in a manifest, a database, or a REST service could
not use them at all without overriding a private method. Omitting the argument builds the search-backed
resolver from the environment exactly as before. The asset-tag guidance shown to the agent now sources its
availability note from the resolver'sunavailable_reasoninstead of namingDATA_LAKE_SEARCH_ENDPOINT
unconditionally, so it stays accurate on other backends
(#306).
Fixed
- Kernel teardown now claims its target atomically and can be awaited, so a session's resources are actually
released when a caller says they are._shutdown_kernelremoved the session from the kernel registry after
its awaits and every caller scheduled it as a barecreate_task, which left four overlapping failures: a
concurrent execute could be handed a kernel that was already being destroyed; a second close scheduled a
duplicate teardown that died withKeyErroras an unretrieved task exception; a teardown that resumed late
could evict a replacement kernel andrmtreethe live session's outputs directory; and
_cleanup_parallel_batch_sessionsreported a batch cleaned up while still holding every child kernel — and
every child kernel's GPU memory. The kernel and all of its per-kernel state are now dropped in one synchronous
step before the first await, teardowns coalesce onto a single strongly-referenced task whose failures are
logged,_get_or_create_kernelwaits for a pending teardown before building a replacement, and the new
aclose_session()lets callers wait for the resources to be freed.close_session()keeps its synchronous
signature and now returns the teardown task; called with no running event loop it warns naming
aclose_session()rather than silently leaking the kernel through aget_event_loop()fallback that has been
dead since Python 3.12 (#314). - Kernel bootstrap state is now keyed to the kernel process rather than the session id, so a session whose
kernel is rebuilt gets its tool proxies andAGORA_OUTPUT_DIRpreamble re-injected. Previously a session id
outliving its kernel — after an idle-kernel cleanup, a request timeout, or an explicit close followed by reuse
of the same logical id — left the replacement kernel bootstrapped in name only: the injection latch still held
the session id, so no proxies were installed and every subsequent call to a tool helper raisedNameError,
while trace flushing tried to read aToolCallLogthat no longer existed.SessionManagernow stamps each
kernel with a unique, never-reused generation id and records bootstrap steps against it, so every teardown
path — including any added later — invalidates that state without having to know it exists
(#311). {name}_check_batchand{name}_cancel_batchfailed with404: Batch '<id>' not foundfor every valid batch,
leaving results from{name}_parallel_executeunreachable. Both tools resolve the owning session from the batch
status payload, which never carriedparent_session_id, so the ownership check always failed. Because that
payload is built before the check runs, a finished batch had its results computed and its child sessions and
batch state cleaned up, then discarded rather than returned — so a second call reported the batch as genuinely
missing (#304).{name}_check_batchand{name}_cancel_batchnow settle authorization before building a status payload.
Building one retires a terminal batch, so a caller who supplied a batch id they did not own could close its
child sessions and prune its state before being refused, destroying results the owner had not yet read
(#304).- Registered data access blob fetchers independently of Azure AI Search configuration, and allowed callers to
provide a storage credential directly, so fully qualified blob URLs can be fetched without configuring artifact
ID resolution (#305). - The expired-session sweep now emits the same leaked-kernel warning as
close_session()when it runs without a
running event loop, instead of dropping the kernel silently. Only the scheduling helper can distinguish having
nothing to tear down from having no loop to tear it down on, so the warning moved there and names the operation
that hit it. It is the background path where silence hurts most, since nothing is watching it
(#317).