Skip to content

Keep MCP execution on the selected binding - #954

Draft
Y1fe1Zh0u wants to merge 2 commits into
dataelement:002-tool-runtime-contractfrom
Y1fe1Zh0u:fix/tool-execution-binding
Draft

Keep MCP execution on the selected binding#954
Y1fe1Zh0u wants to merge 2 commits into
dataelement:002-tool-runtime-contractfrom
Y1fe1Zh0u:fix/tool-execution-binding

Conversation

@Y1fe1Zh0u

Copy link
Copy Markdown
Collaborator

Summary

  • freeze a secret-free MCP tool/assignment route in the Model Step workset
  • strip Runtime-only binding metadata before sending Tool schemas to providers
  • dispatch Tool Step execution through the frozen binding and reject route drift
  • resolve MCP readiness and binding identity in one database query

Validation

  • 969 related Tool, Model Step, and agent_tools tests passed
  • scoped Ruff passed
  • Python compilation passed
  • git diff --check passed

Boundaries

  • live enablement, authorization, and credential values are still checked at execution time
  • no Tool Registry redesign and no database migration
  • no live MCP provider E2E was run

Set the existing protocol repair, safe-read replay, and model-visible Tool episode limits to ten while preserving their current independent state and execution semantics. Update focused tests and planning artifacts to make the off-by-one behavior explicit.

Constraint: Tool-related retry and repair limits must be ten without restructuring the existing counters

Rejected: Unify protocol, Receipt, and model-visible repair state now | counter redesign is intentionally deferred

Confidence: high

Scope-risk: moderate

Directive: Keep the independent counters until the planned repair-control refactor; do not infer identical attempt semantics from the shared numeric limit

Tested: 911 Runtime and Tool pytest cases; scoped Ruff; fatal-level caller Ruff; py_compile; git diff --check

Not-tested: Live Provider credentials
A model-visible MCP definition now carries a secret-free execution binding into the durable Tool context. The Tool step dispatches through that binding, resolves the exact assignment, and rejects route changes instead of re-selecting an endpoint by name. Readiness and binding creation share one database query, while provider payloads remain standard Tool schemas.

Constraint: Live authorization, enablement, and credential values must still be checked at execution time.

Rejected: Freeze decrypted credentials in the checkpoint | would persist secrets and prevent revocation or rotation.

Rejected: Refactor the complete Tool registry | unnecessary for closing the execution-route correctness gap.

Confidence: high

Scope-risk: moderate

Directive: Do not send _runtime_binding to model providers or replace exact assignment checks with name lookup.

Tested: 969 Tool, Model Step, and agent_tools pytest cases; scoped Ruff; py_compile; git diff --check.

Not-tested: Live MCP provider call and production database process restart.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant