BobSong-dev opened a new pull request, #7424: URL: https://github.com/apache/shenyu/pull/7424
## Background Agent Gateway currently establishes request context for LLM traffic. This change adds an explicitly matched MCP tools entry in the same plugin, without replacing the legacy MCP server or AI Proxy. This PR reuses the Agent Gateway foundation already merged into master in #7133. It does not include commits from, or require merging, another open PR. The entry implements the tools-only subset of the fixed 2026-07-28 protocol snapshot. It is not a complete MCP Gateway or an OAuth implementation. ## Changes - Add request-local `server/discover`, `tools/list` and `tools/call` dispatch, returning JSON or one final SSE message. - Validate UTF-8 JSON-RPC, mirrored headers, protocol metadata and Origin; bound request/encoded response sizes and execution deadlines. - Register tools explicitly and intersect rule permissions with verified server-side grants. Check required client capabilities after authorization and before argument validation or invocation. - Preserve immutable request/configuration snapshots and cancellation of the current reactive subscription, including concurrent calls using the same client RPC ID. - Add shared MCP rule configuration, strict Admin save validation and opt-in Starter assembly. Missing identity adapters deny access. - Provide a disabled-by-default loopback-only JWT/read-only order example and regression coverage. LLM forwarding and legacy MCP/AI Proxy source remain unchanged. ## Verification Current local verification uses the `81b2549d7` master baseline. The verified changes are committed as `91d508207`; committing did not change the tested source. - Core/Admin: 287 targeted tests across a 48-module reactor, including 25 upstream registration regressions; zero failures, errors or skips. Checkstyle and RAT passed. - Example: 28 targeted tests and Checkstyle passed; a separate explicit RAT check passed. - Real Bootstrap/Admin/H2/WebSocket verification: 39 entry checks and 12 legacy MCP/AI Proxy coexistence checks passed. The coexistence AI upstream is a controlled fixture. - Earlier verification at `7c94ab887`, not rerun this round: 23 HTTP Client regression tests passed; OpenCode 2.0.18 with a real DeepSeek V4 Flash model successfully called `order_status` through JSON, SSE and client-side CodeMode. - Earlier RISC-V/QEMU verification at `a12aa3e59`: 218 targeted tests and Checkstyle/RAT passed. The 45 feature files remain byte-identical; RISC-V was not rerun after updating the baseline. - `git diff --check` passed. Full-project tests, native RISC-V, complete OAuth verification and GitHub CI have not been run for this change. ## Protocol scope and remaining gaps The unmodified fixed conformance suite (`7169291ec`, requirements `2026-07-28`) failed at `7c94ab887` and was not rerun in this round. Each transport ran 50 scenarios and 184 actual checks: - JSON: 109 success, 63 failure, 4 warning, 7 skipped, 1 informational. - SSE: 110 success, 63 failure, 4 warning, 7 skipped. The remaining failures cover resources, prompts, completion, media, progress, MRTR, Tasks and custom parameter-header mirroring. These capabilities are planned as separate feature PRs; the failures are not waived. Complete protocol acceptance remains outstanding. This PR adds no session lifecycle, initialization handshake, progress stream, task store or remote-target aggregation. Cancellation propagates to the current reactive subscription; it does not guarantee interruption of blocking provider code or rollback of external side effects. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
