Repository navigation
fix(mcp): break Python transport import cycle - #1538
Merged
Merged
Conversation
lusoris
force-pushed
the
fix/mcp-cyclic-imports
branch
2 times, most recently
from
September 23, 2026 22:28
18302a1 to
7732441
Compare
lusoris
force-pushed
the
fix/mcp-cyclic-imports
branch
from
September 24, 2026 00:04
7732441 to
c22ba18
Compare
3 of 6 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Breaks the Python MCP
server -> http_transport -> servercycle reported by CodeQL alerts 917/918 without hiding an import behind dynamic loading. HTTP scoring now crosses a narrowHttpScoringRuntimeprotocol, and explicitly injected runtimes are bound to each aiohttp application so concurrent embedded servers cannot overwrite process-global policy. The default[dev]extra now includes Prometheus so the HTTP and concurrency regressions actually execute in CI instead of silently skipping at collection.This is stacked on #1536. Merge #1536 first; once it lands, this PR's one prerequisite commit/diff disappears against
master.Type
fix— bug fixrefactor— preserves scoring behavior while repairing dependency directionChecklist
make format && make lint— focused Ruff lint/format, changed-file pre-commit, markdownlint, semgrep, governance, HISS, and generated-doc checks passed.[dev]environment reports 533 passed, 19 skipped.Bug-status hygiene
docs/state.mdrecords alerts 917/918 as fixed in source, names the regression test, and leaves hosted closure pending the post-merge CodeQL run.Netflix golden-data gate
assertAlmostEqual(...)score or golden fixture was modified.Cross-backend numerical results
Not applicable: the scoring implementation and numerical output contract are unchanged; only HTTP dependency direction and runtime ownership changed.
Deep-dive deliverables
docs/research/2028-code-scanning-audit-2026-09-03.mdrecords the alert evidence and updated decision matrix;docs/research/2040-code-scanning-cleanup-1243.mdcarries the cleanup ledger.AGENTS.mdinvariant note —mcp-server/AGENTS.mdpins both the acyclic dependency direction and the default HTTP test dependencies.changelog.d/fixed/mcp-python-cyclic-imports.md.docs/rebase-notes.mdrecords the import-DAG and per-application ownership invariants.Reproducer
python3 -m venv /tmp/vmafx-mcp-cycle /tmp/vmafx-mcp-cycle/bin/pip install -e 'mcp-server/vmaf-mcp[dev]' VMAF_BIN=/path/to/vmaf /tmp/vmafx-mcp-cycle/bin/python -m pytest -q \ mcp-server/vmaf-mcp/testsLocal result on CPython 3.14.7 with aiohttp 3.14.3 and Prometheus 0.26.0: 533 passed, 19 skipped in 3.36s. The fresh editable install proves the corrected
[dev]dependency surface; all HTTP round-5 and import-graph regressions execute. Focused Ruff lint/format,make docs-fragments-check, changed-file pre-commit, andgit diff --checkpass.Known follow-ups
masterand the post-merge analysis reports them closed.server.pystill reports its existing optional AI import and MCP SDK alias debt; the newhttp_scoring.pyand changed transport are clean, and this repository's enforced mypy scope passes.