Skip to content

feat: migrate to the official MCP Go SDK with 2026-07-28 protocol support - #44

Merged
wu-sheng merged 4 commits into
apache:mainfrom
CodePrometheus:feat/migrate-official-go-sdk
Aug 14, 2026
Merged

wu-sheng merged 4 commits into
apache:mainfrom
CodePrometheus:feat/migrate-official-go-sdk

Conversation

@CodePrometheus

Copy link
Copy Markdown
Contributor

When skywalking-mcp was created a year ago there was no official MCP Go SDK, so it was built on the relatively mature mark3labs/mcp-go.
The official modelcontextprotocol/go-sdk has since matured and implements the latest protocol revision, 2026-07-28: https://modelcontextprotocol.io/specification/2026-07-28

This PR migrates the server to the official SDK. Main changes:

  • MCP protocol 2026-07-28 support, staying backward compatible with clients on earlier protocol revisions.
  • Tool input schemas are now inferred from the Go request structs and can no longer drift from the code; required parameters are enforced.
  • Removed the MQE documentation resources: they were rarely read by clients, and the metrics list they exposed remains available through the list_mqe_metrics tool.
  • --log-command now uses the SDK's JSON-RPC message log, in a different output format; sensitive-field redaction is preserved.
  • Requires Go 1.26; golangci-lint upgraded to v2.

…port

Signed-off-by: Zixin Zhou <zhouzixin@apache.org>
@CodePrometheus CodePrometheus added this to the 0.3.0 milestone Aug 12, 2026
@CodePrometheus
CodePrometheus requested a balanced review from Copilot August 12, 2026 12:01
@CodePrometheus CodePrometheus added the enhancement New feature or request label Aug 12, 2026

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Migrates SkyWalking MCP to the official Go SDK with MCP 2026-07-28 support, inferred tool schemas, updated transports, and Go 1.26.

Changes:

  • Replaces mark3labs/mcp-go with the official SDK.
  • Migrates tools, prompts, transports, schemas, and logging.
  • Removes MQE resources and updates dependencies, CI, documentation, and licenses.

Reviewed changes

Copilot reviewed 37 out of 48 changed files in this pull request and generated 1 comment.

Show a summary per file
File Description
.github/workflows/CI.yaml Uses Go 1.26 in CI.
.github/workflows/publish-binaries.yaml Builds releases with Go 1.26.
.golangci.yml Migrates lint configuration to v2.
CHANGES.md Documents the 0.3.0 migration.
CLAUDE.md Updates architecture and development guidance.
Dockerfile Uses the Go 1.26 builder image.
Makefile Upgrades golangci-lint to v2.
dist/LICENSE Updates dependency license inventory.
dist/licenses/license-github.com-google-jsonschema-go.txt Adds the current JSON Schema license.
dist/licenses/license-github.com-mailru-easyjson.txt Removes an obsolete dependency license.
dist/licenses/license-github.com-modelcontextprotocol-go-sdk.txt Updates official SDK licensing.
dist/licenses/license-github.com-segmentio-asm.txt Corrects dependency attribution.
dist/licenses/license-github.com-segmentio-encoding.txt Corrects dependency attribution.
dist/licenses/license-golang.org-x-oauth2.txt Updates dependency license text.
dist/licenses/license-golang.org-x-sync.txt Updates dependency license text.
dist/licenses/license-golang.org-x-time.txt Adds the dependency license.
dist/licenses/license-gopkg.in-yaml.v3.txt Removes an obsolete dependency license.
go.mod Adopts Go 1.26 and the official SDK.
go.sum Refreshes dependency checksums.
internal/prompts/analysis.go Migrates analysis prompt handlers.
internal/prompts/registry.go Migrates prompt registration.
internal/prompts/trace.go Migrates trace prompt handlers.
internal/prompts/utility.go Migrates utility prompt handlers.
internal/resources/mqe_ai_prompt.md Removes the MQE guide resource.
internal/resources/mqe_detailed_syntax.md Removes the MQE syntax resource.
internal/resources/mqe_docs.go Removes MQE resource registration.
internal/resources/mqe_examples.json Removes embedded MQE examples.
internal/swmcp/server.go Creates and configures the official SDK server.
internal/swmcp/server_registry_test.go Tests registration through MCP sessions.
internal/swmcp/server_test.go Tests shared context middleware.
internal/swmcp/sse.go Migrates the legacy SSE transport.
internal/swmcp/stdio.go Migrates stdio and redacted logging.
internal/swmcp/stdio_test.go Tests command-log redaction.
internal/swmcp/streamable.go Migrates streamable HTTP transport.
internal/tools/alarm.go Migrates alarm tool and schema.
internal/tools/alarm_test.go Tests the inferred alarm schema.
internal/tools/event.go Migrates event tool and schema.
internal/tools/io.go Removes the former I/O logger.
internal/tools/log.go Migrates log tool and schema.
internal/tools/metadata.go Migrates metadata tools and schemas.
internal/tools/mqe.go Migrates MQE tools and schemas.
internal/tools/mqe_test.go Updates MQE tool and schema tests.
internal/tools/result.go Adds result and schema helpers.
internal/tools/result_test.go Tests lenient inferred schemas.
internal/tools/tools.go Removes the former generic tool wrapper.
internal/tools/topology.go Migrates topology tools and schemas.
internal/tools/trace.go Migrates trace tool and result handling.
internal/tools/trace_test.go Updates trace tests for the official SDK.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread internal/swmcp/streamable.go Outdated
Signed-off-by: Zixin Zhou <zhouzixin@apache.org>

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 39 out of 50 changed files in this pull request and generated 1 comment.

Suppressed comments (1)

internal/swmcp/streamable.go:75

  • The compatibility-critical HTTP path is untested: current tests exercise registry and CORS separately, but never send either a legacy initialize flow or a 2026-07-28 request through this stateless handler and the configured endpoint path. Add transport-level tests for both protocol generations so the PR's backward-compatibility guarantee cannot regress while all existing tests still pass.

Comment thread Makefile Outdated
Signed-off-by: Zixin Zhou <zhouzixin@apache.org>

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 39 out of 50 changed files in this pull request and generated no new comments.

@wu-sheng

Copy link
Copy Markdown
Member

Confirmed against the exact pre-PR main base: with the backend listening on 127.0.0.1, an allowed external Origin, and a preserved public Host, the previous server returned 200 OK, while this PR returns 403 Forbidden: invalid Host header.

This is limited to same-host reverse proxies that preserve the public Host; proxies that rewrite Host to localhost, or connect to a non-loopback backend, are unaffected.

Overall, this PR looks good. The SDK migration is solid, the unit and race tests pass, and CI is green. This proxy edge case is my only concern and could be addressed through configuration or documentation.

Signed-off-by: Zixin Zhou <zhouzixin@apache.org>
@CodePrometheus
CodePrometheus requested a lite review from Copilot August 13, 2026 09:26

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 45 out of 56 changed files in this pull request and generated no new comments.

Suppressed comments (2)

internal/swmcp/server_registry_test.go:1

  • reflect is imported but no longer used after switching the registry tests to run over a real in-memory client session. This will fail go test with an unused import; remove reflect from the import list.
    internal/swmcp/stdio.go:1
  • log/slog is imported but (in the shown diff) there are no remaining references in this file. If it’s not used elsewhere in stdio.go, this will fail compilation with an unused import; remove it or reintroduce the intended usage.

@CodePrometheus

Copy link
Copy Markdown
Contributor Author

Confirmed against the exact pre-PR main base: with the backend listening on 127.0.0.1, an allowed external Origin, and a preserved public Host, the previous server returned 200 OK, while this PR returns 403 Forbidden: invalid Host header.

This is limited to same-host reverse proxies that preserve the public Host; proxies that rewrite Host to localhost, or connect to a non-loopback backend, are unaffected.

Overall, this PR looks good. The SDK migration is solid, the unit and race tests pass, and CI is green. This proxy edge case is my only concern and could be addressed through configuration or documentation.

Fixed, added --disable-localhost-protection for proxied deployments, defaulting to off so the protection stays on everywhere else.

@wu-sheng
wu-sheng merged commit ea491e1 into apache:main Aug 14, 2026
3 checks passed
@CodePrometheus
CodePrometheus deleted the feat/migrate-official-go-sdk branch August 14, 2026 02:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants