Skip to content

fix(deps): bound mcp below 2 so the built-in MCP servers import - #276

Open
SproutSeeds wants to merge 1 commit into
psi-oss:mainfrom
SproutSeeds:cody/cap-mcp-below-2
Open

SproutSeeds wants to merge 1 commit into
psi-oss:mainfrom
SproutSeeds:cody/cap-mcp-below-2

Conversation

@SproutSeeds

@SproutSeeds SproutSeeds commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

What changed

  • pyproject.toml: mcp>=1.27.0 becomes mcp>=1.27.0,<2, with a comment giving the reason.
  • uv.lock: the matching requires-dist line. No locked versions change (relocked with uv 0.9.12, the CI version).
  • tests/test_release_consistency.py: the two curated dependency assertions now expect the bound.
  • CHANGELOG.md: a vNEXT entry.

Why

Fixes #273. mcp 2.x removed mcp.server.fastmcp. Since mcp 2.0.0 shipped on July 28, a fresh install without extras resolves mcp 2.x, and seven of the nine gpd-mcp-* entry points fail with ModuleNotFoundError. (The June date in the issue is 2.0.0a1, a prerelease that pip and uv skip by default.) This is the path npx -y get-physics-done takes: it runs pip install --upgrade get-physics-done==<version> in the managed environment.

Installs with the arxiv extra avoid the break only because arxiv-mcp-server 0.7.x declares mcp<2.0.0. The arxiv and Wolfram bridges use the low level Server API and still import under mcp 2.2.0.

This is option 1 from @sknob3l's report. Porting the servers to the 2.x MCPServer API (option 2) can lift the bound later; tighten_registered_tool_contracts reaches into FastMCP internals, so that port is more than a rename.

Testing done

At 8e1d10e, macOS arm64:

  • The two updated assertions fail against main's pyproject.toml and uv.lock and pass here.
  • uv run pytest tests/ -q on Python 3.11.13: 12945 passed, 7 skipped, 3 failed, with the same three failures on unmodified main. Two are Codex projection budget assertions that count the bridge command, which embeds the checkout path (mine is 2 characters longer than CI's); the third needs a TeX package my TinyTeX lacks.
  • ruff check ., uv lock --check and the four generated surface --check scripts pass.
  • Wheels built with uv build from this branch and from main, installed into fresh venvs with pip install --upgrade <wheel> and no extras, on Python 3.11.13 and 3.13.9:
    • this branch: mcp 1.30.0; all nine entry points load, and the seven FastMCP servers answer initialize and list_tools over stdio.
    • main: mcp 2.2.0; the seven FastMCP servers fail to import.
  • With the arxiv extra, gpd-mcp-arxiv also answers over stdio. gpd-mcp-wolfram needs GPD_WOLFRAM_MCP_API_KEY, so I did not exercise it.

Until a release

The bound reaches npx installs after the next PyPI release. Meanwhile, installing mcp<2 into the managed environment at ${GPD_HOME:-~/.gpd}/venv restores the servers:

~/.gpd/venv/bin/python -m pip install "mcp<2"

A plain rerun of the installer keeps it, but --reinstall resolves mcp 2.x again.

Checklist

  • Tests pass (full suite locally, with the three environment failures above also present on main)
  • Lint / pre-commit clean (uv run ruff check .)
  • No secrets or credentials in the diff
  • User-facing docs updated (not applicable; install flow unchanged, vNEXT note added)

Summary by CodeRabbit

  • Bug Fixes
    • Limited MCP support to versions below 2 to avoid import failures in built-in servers.

mcp 2.x removed mcp.server.fastmcp. The requirement mcp>=1.27.0 had no
upper bound, so a fresh install without the arxiv extra, which is the
path `npx -y get-physics-done` takes, resolved mcp 2.x and seven of the
nine gpd-mcp-* entry points failed with ModuleNotFoundError. Installs
with the arxiv extra avoided it only because arxiv-mcp-server 0.7.x
declares mcp<2.0.0.

Bound the requirement to mcp>=1.27.0,<2 until the servers move to the
2.x MCPServer API, and update the curated dependency assertions for
pyproject.toml and uv.lock. Locked versions are unchanged.

Refs psi-oss#273
@coderabbitai

coderabbitai Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 04db95dc-36c4-4c25-8d2b-d7b1c1aef525

📥 Commits

Reviewing files that changed from the base of the PR and between 0f41769 and 8e1d10e.

⛔ Files ignored due to path filters (1)
  • uv.lock is excluded by !**/*.lock
📒 Files selected for processing (3)
  • CHANGELOG.md
  • pyproject.toml
  • tests/test_release_consistency.py

Included review availability: This review used your included allowance. Your plan provides up to 4 included reviews per hour; 3 remain after this review.


📝 Walkthrough

Walkthrough

The project now requires mcp>=1.27.0,<2. Release consistency checks enforce the bound for the runtime dependency and lockfile metadata. The vNEXT changelog records the bound and reported import failures with MCP 2.x.

Changes

MCP dependency bound

Layer / File(s) Summary
Constrain MCP and update release checks
pyproject.toml, tests/test_release_consistency.py, CHANGELOG.md
The MCP requirement now excludes version 2 while retaining the 1.27.0 minimum. Tests check the dependency and lockfile metadata against the bounded range. The changelog records the bound and reported import failures with MCP 2.x.

Priority: ➖ Normal

Estimated code review effort: 2 (Simple) | ~5 minutes

Change: Bug fix · Severity of issue fixed: Medium

Suggested reviewers: physicalsuperintelligence

Merge Risk: ⚪ Minimal · up to 8e1d1

The MCP version limit prevents fresh installs from selecting the documented incompatible 2.x API, while the locked version supports the built-in servers. No actionable merge risk remains.

Security Architecture Review

Security architecture risk: 🔵 Low · up to 8e1d1

The new version bound addresses a documented server import incompatibility without changing the servers’ authority or exposing a new entry point. No PR-introduced security concern was established, though runtime compatibility has not been verified across every installation.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The changed requirement applies to the distributed package and can affect installations of its built-in MCP commands; the changed test functions do not expand attacker-controlled runtime reachability.

Trust Boundaries and Controls

  • inferred — The visible change constrains dependency selection rather than changing server authentication, identity, or tool authority; no new trust-boundary crossing is evidenced in the inspected changes.
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 2 functions across 1 files. (2 skipped: 2 … Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly and concisely states the primary change: constraining mcp below version 2 to keep the built-in MCP servers importable.
Description check ✅ Passed The description includes all required sections, explains the cause and selected fix, documents testing results and known baseline failures, and completes the checklist.
Linked Issues check ✅ Passed PR #276 satisfies the directly linked coding requirement in issue #273. pyproject.toml changes mcp>=1.27.0 to mcp>=1.27.0,<2, which keeps the seven built-in servers on the API they currently imp…
Out of Scope Changes check ✅ Passed The reviewed changes stay within issue #273. The dependency bound addresses the reported import failure. The consistency assertions verify the bound, and the vNEXT changelog documents the compatibil…
Full details: Docstring Coverage

Explanation

Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 2 functions across 1 files. (2 skipped: 2 unsupported.)

  • Fix all pre-merge checks with AI
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

All 7 built-in MCP servers fail to import on mcp>=2.0 (FastMCP renamed); mcp>=1.27.0 is unbounded

1 participant