Skip to content

fix(mcp): define the SSE port out-parameter in the transport-less build - #2643

Merged
lusoris merged 3 commits into
masterfrom
fix/tidy-mcp-server-const
Oct 9, 2026
Merged

lusoris merged 3 commits into
masterfrom
fix/tidy-mcp-server-const

Conversation

@lusoris

@lusoris lusoris commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

Summary

The cuda clang-tidy lane reported core/src/vmafx/mcp_server.c:204:43 readability-non-const-parameter on a clean master (8493fcd9d): the transport-less stub of vmafx_mcp_start_sse never wrote its port parameter. port is a documented output of the public function (core/include/vmafx/mcp.h, read by core/src/compat/libvmaf/mcp.c on success only), so it stays non-const; the stub now stores 0 (no bound port) when port is non-NULL, as the real implementation does when it binds. No baseline edit. Hosted Tidy Ratchet runs the cpu lane and was green on master; only the cuda lane (run locally) is affected.

Type

  • fix — bug fix

Checklist

  • Commits follow Conventional Commits (the commit-msg hook enforces this).
  • Every commit is signed off (git commit -s; fix a branch with git rebase --signoff origin/master). See DCO sign-off.
  • make format && make lint is green locally.
  • Unit tests pass: new test_vmafx_mcp_absent (suite fast): positive (sentinel *port becomes 0, NOTSUP, error names mcp), boundary (NULL port), NULL error pointer; skips with a reason in an MCP build. Against the unfixed stub it fails (port output defined (0), not left as the sentinel); with the fix 3 of 3 pass.
  • If I touched any SIMD/GPU code path — not applicable.
  • If this is a breaking change — not applicable: signature unchanged.

Bug-status hygiene (ADR-0165)

  • docs/state.md updated in this PR with a row in Recently closed.

Netflix golden-data gate (ADR-0024)

  • I did not modify any assertAlmostEqual(...) score in the Netflix golden Python tests.

Deep-dive deliverables (ADR-0108)

  • Research digest — no digest needed: trivial.
  • Decision matrix — no alternatives: only-one-way fix (a const pointee would break the documented output).
  • AGENTS.md invariant note — no rebase-sensitive invariants.
  • Reproducer / smoke-test command — pasted below under "Reproducer".
  • CHANGELOG fragment — no changelog needed: no user-visible change (the transport-less stub already failed with NOTSUP; it now also zeroes port).
  • Rebase note — no rebase impact: one stub in a file only this fork has.

Reproducer

scripts/dev/tidy-lane.sh --jobs 4 cuda

On master: exit 2/4 with mcp_server.c: warnings 0 -> 1 (and, until #2636 lands, core/src/hip/dispatch_strategy.c: not measured). On this head merged with #2636: 598 TUs, 0 warnings (baseline 0), ... baseline matches measurement, exit 0.

Known follow-ups

None.

@github-actions github-actions Bot added the type:bug Something isn't working label Oct 8, 2026
lusoris added a commit that referenced this pull request Oct 8, 2026
…ld (#2643)

* fix(mcp): define the SSE port out-parameter in the transport-less build

The stub of vmafx_mcp_start_sse never wrote its port out-parameter, so the cuda tidy lane reported readability-non-const-parameter at mcp_server.c:204. The parameter is a documented output in mcp.h, so it stays non-const and the stub now stores 0 (no bound port).

* docs(state): record the cuda lane mcp_server finding as closed

* test(mcp): pin the transport-less vmafx_mcp_start_sse refusal and its port output

Signed-off-by: Lusoris <lusoris@proton.me>
@lusoris
lusoris force-pushed the fix/tidy-mcp-server-const branch 2 times, most recently from 6104d99 to 8645fed Compare October 8, 2026 22:48
…026-6617 and the stdlib advisories (#2651)

* fix(deps): move golang.org/x/net to v0.60.0 for GO-2026-6617

The Go vulnerability database published GO-2026-6617 (HTTP/2 server crash from an HPACK encoder race, fixed in v0.60.0). govulncheck found it reachable from the controller, the tune executor, pkg/libvmaf and tools/obssmoke, so the pre-push security hook refused every push. go vet ./... and govulncheck ./... pass after the bump.

* fix(deps): move the Go toolchain to 1.27.2 for the standard-library advisories

The vulnerability database release that published GO-2026-6617 also published
twelve standard-library advisories (GO-2026-6599/6600/6603/6604/6605/6607/6608/
6609/6610/6611/6612/6613), and the standard library carries GO-2026-6617 in its
own HTTP/2 copy. With x/net v0.60.0 alone the CI go vet + go test job still
failed at the govulncheck gate on Go 1.27.1, and so did the local pre-push
security hook. Go 1.27.2 fixes all thirteen.

go.mod declares go 1.27.2. RELEASE_GO_BASE and DEV_GO_BASE move to the
golang:1.27-trixie digest that carries Go 1.27.2, and the Dockerfile and
compose copies are rewritten by check-base-image-single-source.sh --write.
The state row no longer claims govulncheck passed on 1.27.1.

* build(go): pin gosec to a commit built with x/tools v0.50.0 so it reads Go 1.27.2 export data

Go 1.27.2 writes export data version 5. gosec v2.29.0, the newest
release, builds with x/tools v0.49.0, which reads at most version 4, so
under Go 1.27.2 it reported "could not import" for every package and
checked nothing. Commit 9e8e5d91f2f3 of gosec's main branch builds with
x/tools v0.50.0; under Go 1.27.2 it type-checks the whole tree and reports
the same five findings v2.29.0 reports on master under Go 1.27.1.

Signed-off-by: Lusoris <lusoris@proton.me>
…2641)

* port(upstream): MSVC: install static library as vmaf.lib (3b4dd350e)

A static MSVC, clang-cl or icx-cl build names its installed libraries
vmaf.lib and vmafx.lib, the files the MSVC linker opens for -lvmaf and
-lvmafx, instead of Meson's libvmaf.a and libvmafx.a. The names are set
with explicit name_prefix / name_suffix keywords because Meson's
namingscheme option needs Meson 1.10 and this project's floor is 1.4.0
(ADR-2752). Every other build keeps its names.

scripts/ci/check_msvc_library_names.py checks the installed files and
pkg-config files; the MSVC CUDA, SYCL and ARM64 legs run it after
installing.

Signed-off-by: Lusoris <lusoris@proton.me>
…ld (#2643)

* fix(mcp): define the SSE port out-parameter in the transport-less build

The stub of vmafx_mcp_start_sse never wrote its port out-parameter, so the cuda tidy lane reported readability-non-const-parameter at mcp_server.c:204. The parameter is a documented output in mcp.h, so it stays non-const and the stub now stores 0 (no bound port).

* docs(state): record the cuda lane mcp_server finding as closed

* test(mcp): pin the transport-less vmafx_mcp_start_sse refusal and its port output

Signed-off-by: Lusoris <lusoris@proton.me>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

type:bug Something isn't working

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant