Repository navigation
Conversation
WithMCPParse unmarshaled the entire tools/call arguments payload into a map[string]any on every request just to extract owner and repo. Decode into a small typed struct with only those two fields instead, and drop the now-unused Arguments field from MCPMethodInfo (grep confirmed the only consumer was the middleware's own test). Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
There was a problem hiding this comment.
🟡 Changes recommended
It introduces a breaking exported API change (MCPMethodInfo field removal) and tightens argument decoding in a way that can drop valid repo extraction on partial type mismatches.
Once you've addressed the issues Copilot identified, you can request another Copilot review.
Pull request overview
This PR optimizes HTTP-mode MCP request parsing by avoiding full map[string]any argument decoding when handling tools/call, extracting only owner/repo to reduce per-request allocations and parsing work.
Changes:
- Updated
WithMCPParseto decodetools/callarguments into a small typed struct containing onlyowner/repo. - Removed
Arguments map[string]anyfromMCPMethodInfo. - Updated middleware tests to stop asserting full arguments and added coverage for large extra argument fields.
File summaries
| File | Description |
|---|---|
| pkg/http/middleware/mcp_parse.go | Switches argument parsing to decode only owner/repo for tools/call. |
| pkg/context/mcp_info.go | Removes Arguments from MCPMethodInfo. |
| pkg/http/middleware/mcp_parse_test.go | Adjusts assertions to match new parsing behavior and adds a “large extra field” case. |
Review details
- Files reviewed: 3/3 changed files
- Comments generated: 2
- Review effort level: Lite
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
…s field Address review feedback: decode owner/repo as json.RawMessage and unmarshal each individually so a wrongly typed field no longer blocks extraction of the other. Restore the MCPMethodInfo.Arguments field as deprecated (no longer populated) to avoid breaking external consumers of pkg/context. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Strip CRLF terminators from embedded icon data URIs so Windows checkouts match the existing tool snapshots. Cover both line endings and exercise tolerant argument extraction, large nested payloads, and body restoration. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Validate cached golangci-lint versions, align CI's exact pin, correct Go/build and workflow guidance, and add independent canonical icon URI and malformed-entry coverage. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Resolve parser conflicts using upstream RawArguments and DecodeArguments, retaining deprecated legacy fields for source compatibility. Preserve scope-policy inputs and fast paths, and add exact-key, malformed-input, body-preservation and lazy-allocation regression coverage. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
The two requested fixes from this review are already present on the branch in commit f9760d5: |
Summary
Keep MCP request parsing lazy and preserve source compatibility while covering argument-decoding regressions. Also fix Windows icon URI line endings and enforce the repository's lint-tool version.
Why
The original middleware materialized all tool arguments just to read owner/repo. During review, current main introduced a better lazy
RawArguments/DecodeArguments()design; this branch now integrates that design instead of retaining eager struct extraction, which also had case-insensitive key-matching regressions. No linked issue.What changed
mcp_parse.gonow matches main.Owner,Repo, andArgumentsfields for source compilation compatibility. The middleware does not populate them; consumers explicitly useDecodeArguments()instead. Decoded maps are not shared or cached.MCP impact
No tool names or wire schemas change relative to current main. Request metadata uses lazy decoding, with deprecated library fields retained solely for source compatibility; raw arguments remain available to policy middleware and tool validation.
Prompts tested (tool changes only)
N/A: no live GitHub tool prompts were executed. Automated request/argument tests cover the affected middleware behavior.
Security / limits
Preserves main's scope-challenge workflow/file-path inputs and maximum-scopes fast path. Request-size enforcement and downstream body contents remain intact. Case-varied keys stay distinct rather than overriding lowercase owner/repo keys.
Tool renaming
deprecated_tool_aliases.goNo tools are renamed.
Note: if you're renaming tools, you must add the tool aliases. For more information on how to do so, please refer to the official docs.
Lint & tests
./script/lint./script/testPost-integration validation uses Go 1.25.12, pinned golangci-lint v2.9.0, and MinGW GCC with
CGO_ENABLED=1: full lint (0 issues), full race suite,go build ./...,go mod tidy -diff, and generated-documentation consistency all pass. Windows scripts run through Git Bash withset -o igncr; module files were normalized to LF to match CI.Independent QA also passed 12 isolated linter-cache/install/error-path scenarios. On Windows amd64, the ~128 KiB nested-payload benchmark measured 139,856 B / 14 allocations for lazy envelope parsing versus 324,896 B / 1,058 allocations for envelope parsing plus eager map decoding. These exclude HTTP body reading and explicit lazy decoding by downstream consumers.
Docs
Updated installation and contributor/toolchain guidance. Generated documentation is unchanged relative to current main.