Skip to content

MCP operability: spawnable stdio servers, live config reloads, and actionable failures - #952

Merged
alcholiclg merged 59 commits into
modelscope:mainfrom
alcholiclg:fix/runtime-robustness
Aug 28, 2026
Merged

MCP operability: spawnable stdio servers, live config reloads, and actionable failures#952
alcholiclg merged 59 commits into
modelscope:mainfrom
alcholiclg:fix/runtime-robustness

Conversation

@alcholiclg

Copy link
Copy Markdown
Collaborator

Change Summary

  • stdio servers spawn reliably: bare commands (uvx, npx) resolve beyond the backend's PATH (~/.local/bin, Homebrew, /usr/local/bin), and the child process gets a networked environment (proxy/TLS/index vars; ALL_PROXY deliberately excluded — a socks5 value breaks children whose httpx lacks the socksio extra)
  • Calls to a disconnected server fail with an actionable message instead of a bare KeyError (found by from-scratch testing: a remote server that timed out once left its tools poisoned)
  • Prompt surface: one layout-aware "workspace records" section for all project layouts (managed and mounted), decided by where the session log actually writes; adds a credentials-discipline rule to the base prompt; normalizes heading levels (TEMPLATE_VERSION 2 upgrades untouched SOUL.md files silently)
  • Stale docs pointing at the pre-consolidation .ms_agent_artifacts spill directory corrected
  • Tests: 3 new stdio-env guards + prompting guards updated; suite baseline unchanged

Related issue number

Checklist

  • The pull request title is a good summary of the changes - it will be used in the changelog
  • Unit tests for the changes exist
  • Run pre-commit install and pre-commit run --all-files before git commit, and passed lint check.
  • Documentation reflects the changes where applicable

The orchestrator now owns the write discipline around a backend:
- schedule_add() runs the extraction-LLM + embedding cost (seconds) in a
  background task; flush_pending() is the teardown barrier so the last
  write is never dropped, and an inline fallback keeps writes when no
  loop is running.
- retrieval/ingestion/flush serialize on one per-store asyncio lock
  (embedded qdrant underneath is lock-free single-client code).
- a content-hash delta ledger (<base_dir>/ingest_state.json) makes each
  ingest send only messages the store has not seen; hashes are recorded
  only after a confirmed write, so a failed ingest retries naturally.
- ingest_status reports the last outcome (state/count/error/pending) so
  a UI can show memory working instead of silence.

Mem0Backend: per-turn retrieval cache (rounds 2..N of a tool-calling
turn reuse round 1's search instead of paying an embedding round-trip
each), on_messages returns the event count and propagates failures --
the orchestrator is the swallow-and-report layer now and needs the
exception to keep failed messages un-marked for retry.
…-side close

- add_memory(add_after_step) now fires only when a round closes the turn
  (assistant reply with no tool calls) and dispatches through the
  backend's schedule_add when available: tool rounds are intermediate
  state, and ingesting every round cost O(rounds x history) extraction
  calls where the closing ingest covers the whole turn.
- an interrupted round advances the ingest ledger WITHOUT ingesting
  (mark_ingested): a half-finished answer is not durable conversational
  truth and must not be swept into the next turn's delta.
- cleanup_tools drains scheduled ingestion (flush only -- memory
  instances are shared across agents of one store, so closing here would
  yank the store from a sibling agent); the new
  SharedMemoryManager.close_matching(base_dir) is the owner-of-last-
  resort that actually closes instances and releases the embedded
  store's exclusive file lock.
The number of recalled memories injected per turn was hardcoded twice
(search default 20, then a [:10] formatting slice). MemoryConfig gains
recall_top_k (default 10, read from the unified_memory node) and the
mem0 adapter threads it through search and formatting — consumers can
now size recall to their context budget.
…E) instead of scattered config fields, gated by personalization.enabled.

When those files change mid-conversation the next user turn carries a durable <system-reminder> naming them, so the model can tell a changed file from its own faulty memory.
…end's MEMORY.md snapshot in step with edits made outside the agent.

Also translates the memory tool descriptions and prompt headings to English.
# Conflicts:
#	.gitignore
#	ms_agent/memory/unified/backends/mem0_adapter.py
#	ms_agent/memory/unified/orchestrator.py
#	setup.py
…ts last entry deleted, instead of leaving the previous round's block in place.
- an interrupt marks only its own round, and never messages a scheduled
  ingest still owns (both lost the write silently)
- one shared instance per store, not per model, reconfigured in place
- close() is terminal: a straggler can no longer reopen a released store
- the store lock is per (loop, path), and search() takes it too
- search() honours its limit; injected memories carry their date
- memories are written in the language the user used
# Conflicts:
#	ms_agent/memory/unified/backends/mem0_adapter.py
…ters

Thinking support is per-model with no naming rule, and an unsupported model may
reject the whole request (DashScope returns 400) instead of ignoring the flag.
So we ask, and on a refusal retry once with it off, remembering the model.
…orwards, and read OpenRouter's reasoning field
…o a vision-disabled model neither claims nor disowns them
…x/runtime-robustness

# Conflicts:
#	ms_agent/agent/llm_agent.py
#	ms_agent/memory/unified/backends/mem0_adapter.py
#	ms_agent/memory/unified/orchestrator.py
…hat arrive mid-stream

- images go out only when the model's own switch says so; a provider's declared
  vision capability no longer implies it
- a 400 delivered on the first streamed chunk is repaired like an eager one
- thinking refusals are repaired on the Anthropic and Responses paths too
- a tool call the model is still writing is reported instead of nothing at all
- an unreadable managed MCP config is logged instead of silently yielding none
… tell the agent why a search failed instead of reporting no results
…ps cutting structured results into invalid JSON
… and gate interpreter execution and credential reads behind mode-aware asks
… unique tool-name prefixes, and return content instead of a stub on unchanged re-reads
…io startup timeouts and per-server failure isolation
…ranscript matches are not mistaken for user content
…tworked child environment, and turn calls to a disconnected server into an actionable error
…d a credentials rule, and normalize prompt heading levels
…x/runtime-robustness

# Conflicts:
#	ms_agent/agent/llm_agent.py
#	ms_agent/tools/code/local_code_executor.py
#	ms_agent/tools/mcp_client.py
#	tests/prompting/test_workspace_internals_hint.py
@alcholiclg
alcholiclg merged commit 6d1e078 into modelscope:main Aug 28, 2026
1 check failed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants