Problem/Motivation

In 1.6.0, the three schema tools in graphql_compose_codegen_mcp (SchemaDiffTool, SchemaInspectTool, SchemaPreviewTool) pass permission: to the #[Tool] attribute. Drupal\tool\Attribute\Tool accepts $permission only from Tool API 1.0.0-beta11 (#3583064); beta8, beta9 and beta10 have no such parameter. The submodule requires tool (>=1.0.0-beta8).

With the submodule enabled, Tool plugin discovery throws:

Error: Unknown named parameter $permission in ReflectionAttribute->newInstance() (line 16 of modules/contrib/graphql_compose_codegen/modules/graphql_compose_codegen_mcp/src/Plugin/tool/Tool/SchemaPreviewTool.php)
#0 core/lib/Drupal/Component/Plugin/Discovery/AttributeClassDiscovery.php(237): ReflectionAttribute->newInstance()
...
#7 mcp_sentinel/src/Service/McpGovernanceReadiness.php(278): DefaultPluginManager->hasDefinition()

Every caller of the Tool plugin manager fails, not only these tools. On a site running MCP Sentinel, its readiness check calls the Tool plugin manager on every governed request, so every agent JSON:API request returns HTTP 500. We hit this in production on Drupal 11.4 with tool 1.0.0-beta9 after updating from 1.5.0 to 1.6.0. CI resolved ^1.0.0-beta8 to beta11, so the floor was never tested.

The argument was added in 1.6.0 with #3623734. 1.5.0 is not affected.

Steps to reproduce

  1. Install tool 1.0.0-beta9 (or beta8/beta10) and graphql_compose_codegen 1.6.0, and enable graphql_compose_codegen_mcp.
  2. Clear caches, then call \Drupal::service('plugin.manager.tool')->getDefinitions().
  3. The error above is thrown.

Proposed resolution

Remove permission: from the three #[Tool] attributes, and enforce the permission in the tool's access check instead (as 1.5.0 did). Add a kernel test that calls Tool plugin discovery with the submodule enabled against the lowest supported Tool API version, so CI catches an unsupported attribute argument.

Remaining tasks

  • Fix and test.
  • Release 1.6.1.

User interface changes

None.

API changes

None.

Data model changes

None.

Comments

jmcerda created an issue. See original summary.

jmcerda’s picture

Title: Tool plugin discovery fails: Tool attribute has no permission parameter » 1.6.0 breaks Tool plugin discovery on Tool API beta8–beta10 (permission attribute argument)
Issue summary: View changes

Correction to the summary: Tool API does accept permission on the #[Tool] attribute from 1.0.0-beta11 (#3583064). It is missing in beta8, beta9 and beta10. The site that broke had beta9, and this module declares tool (>=1.0.0-beta8). Our CI resolved ^1.0.0-beta8 to beta11 on every leg, so the floor was never tested.

Reproduced on Drupal 11.4 with Tool API 1.0.0-beta9: the MCP kernel tests on 1.6.0 give Tests: 5, Errors: 5, all "Unknown named parameter $permission".

Fix on 1.x, for 1.6.1:

  • Remove permission: from the three tools. Access is unchanged: McpGovernedToolBase already requires "access mcp sentinel context", and SchemaToolBase::checkGovernedAccess() requires "administer graphql_compose_codegen".
  • A new kernel test refuses an account that has only "administer graphql_compose_codegen".
  • The CI floor legs now pin Tool API 1.0.0-beta8 and assert the resolved version.

With the fix on beta9, the MCP kernel tests give Tests: 6, all passing. Module Unit (23) and Kernel (35) suites pass too.

jmcerda’s picture

Status: Active » Fixed

Fixed in 1.6.1. The three schema tools no longer pass permission to #[Tool]; access is still enforced in code, including on direct execution. The MCP submodule now declares Tool API 1.0.0-beta9 as its floor, since it uses OutputDefinition, which beta8 lacks. CI pins beta9 on Drupal 10.6 and 11.3 and floats the newest beta on 11.

Now that this issue is closed, review the contribution record.

As a contributor, attribute any organization that helped you, or if you volunteered your own time.

Maintainers, credit people who helped resolve this issue.