Problem/Motivation
In 1.6.0, the three schema tools in graphql_compose_codegen_mcp (SchemaDiffTool, SchemaInspectTool, SchemaPreviewTool) pass permission: to the #[Tool] attribute. Drupal\tool\Attribute\Tool accepts $permission only from Tool API 1.0.0-beta11 (#3583064); beta8, beta9 and beta10 have no such parameter. The submodule requires tool (>=1.0.0-beta8).
With the submodule enabled, Tool plugin discovery throws:
Error: Unknown named parameter $permission in ReflectionAttribute->newInstance() (line 16 of modules/contrib/graphql_compose_codegen/modules/graphql_compose_codegen_mcp/src/Plugin/tool/Tool/SchemaPreviewTool.php) #0 core/lib/Drupal/Component/Plugin/Discovery/AttributeClassDiscovery.php(237): ReflectionAttribute->newInstance() ... #7 mcp_sentinel/src/Service/McpGovernanceReadiness.php(278): DefaultPluginManager->hasDefinition()
Every caller of the Tool plugin manager fails, not only these tools. On a site running MCP Sentinel, its readiness check calls the Tool plugin manager on every governed request, so every agent JSON:API request returns HTTP 500. We hit this in production on Drupal 11.4 with tool 1.0.0-beta9 after updating from 1.5.0 to 1.6.0. CI resolved ^1.0.0-beta8 to beta11, so the floor was never tested.
The argument was added in 1.6.0 with #3623734. 1.5.0 is not affected.
Steps to reproduce
- Install tool 1.0.0-beta9 (or beta8/beta10) and graphql_compose_codegen 1.6.0, and enable
graphql_compose_codegen_mcp. - Clear caches, then call
\Drupal::service('plugin.manager.tool')->getDefinitions(). - The error above is thrown.
Proposed resolution
Remove permission: from the three #[Tool] attributes, and enforce the permission in the tool's access check instead (as 1.5.0 did). Add a kernel test that calls Tool plugin discovery with the submodule enabled against the lowest supported Tool API version, so CI catches an unsupported attribute argument.
Remaining tasks
- Fix and test.
- Release 1.6.1.
User interface changes
None.
API changes
None.
Data model changes
None.
Comments
Comment #2
jmcerdaCorrection to the summary: Tool API does accept
permissionon the#[Tool]attribute from 1.0.0-beta11 (#3583064). It is missing in beta8, beta9 and beta10. The site that broke had beta9, and this module declarestool (>=1.0.0-beta8). Our CI resolved^1.0.0-beta8to beta11 on every leg, so the floor was never tested.Reproduced on Drupal 11.4 with Tool API 1.0.0-beta9: the MCP kernel tests on 1.6.0 give
Tests: 5, Errors: 5, all "Unknown named parameter $permission".Fix on
1.x, for 1.6.1:permission:from the three tools. Access is unchanged:McpGovernedToolBasealready requires "access mcp sentinel context", andSchemaToolBase::checkGovernedAccess()requires "administer graphql_compose_codegen".With the fix on beta9, the MCP kernel tests give
Tests: 6, all passing. Module Unit (23) and Kernel (35) suites pass too.Comment #3
jmcerdaFixed in 1.6.1. The three schema tools no longer pass
permissionto#[Tool]; access is still enforced in code, including on direct execution. The MCP submodule now declares Tool API 1.0.0-beta9 as its floor, since it usesOutputDefinition, which beta8 lacks. CI pins beta9 on Drupal 10.6 and 11.3 and floats the newest beta on 11.