Skip to content

chore(deps): update rust crate rmcp to v1.8.0 - #84

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/rmcp-1.x-lockfile
Open

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/rmcp-1.x-lockfile

Conversation

@renovate

@renovate renovate Bot commented Jun 23, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change
rmcp dependencies minor 1.7.0 → 1.8.0

Release Notes

modelcontextprotocol/rust-sdk (rmcp)

v1.8.0

Compare Source

[!WARNING]

⚠️ Breaking Changes

Despite being a minor version bump, this release contains a source-breaking API change (it should have been 2.0.0). If you depend on rmcp = "1.7", Cargo will resolve to 1.8.0 automatically and your build may fail. Pin to =1.7.x if you are not ready to migrate.

Peer::peer_info() return type changed (#​862):

- pub fn peer_info(&self) -> Option<&R::PeerInfo>
+ pub fn peer_info(&self) -> Option<Arc<R::PeerInfo>>

This was needed so peer info can be re-set on a duplicate initialize (it now lives behind an RwLock), which is why a borrow can no longer be returned.

Migration: field access still works through Arc's Deref. If you need the old &InitializeResult (e.g. you bound the type explicitly), use .as_deref():

// Before (1.7.x): info is &InitializeResult
let info: Option<&InitializeResult> = client.peer_info();

// After (1.8.0): info is Arc<InitializeResult>
let info: Option<Arc<InitializeResult>> = client.peer_info();

// To recover the old reference type:
let info: Option<&InitializeResult> = client.peer_info().as_deref();
Added
  • standardize resource-not-found error code (SEP-2164) (#​899)
  • validate OAuth authorization response issuer (#​896)
  • specify OIDC application_type during dynamic client registration (SEP-837) (#​883)
  • deprecate roots, sampling, and logging (SEP-2577) (#​884)
Fixed
  • (auth) preserve configured reqwest client (#​917)
  • (auth) align OAuth metadata discovery ordering (#​887)
  • align progress timeout token (#​909)
  • (elicitation) preserve enumNames through ElicitationSchema serde round-trip (#​905)
  • return tool errors for invalid arguments (#​894)
  • (auth) apply offline_access to reauth paths (#​897)
  • update peer info on duplicate initialize (#​862) — ⚠️ breaking: changes the Peer::peer_info() signature, see Breaking Changes above
  • strip and validate tool outputSchema and inputSchema (#​860)
  • remove unnecessary fields from tools' inputSchema (#​856)
  • reject init header/body version mismatch (#​853)
  • align protocol version negotiation (#​855)
  • accept 200 with empty body in response to notifications in addition to 202 (#​849)
Other
  • Allow custom HTTP clients for OAuth (#​908)
  • Add progress-aware request timeout reset (#​858)
  • (server) document Err vs Ok(CallToolResult::error) visibility contract on ServerHandler::call_tool (#​854)
  • refine mcpmate listing copy (#​885)
  • added jilebi-mcp to the list of built with rmcp (#​861)

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@claude

claude Bot commented Jun 23, 2026

Copy link
Copy Markdown
Contributor

Review: rmcp 1.7.0 → 1.8.0 (lockfile-only)

This is a Renovate-generated Cargo.lock-only bump: rmcp/rmcp-macros 1.7.0 → 1.8.0, plus transitive updates to windows-sys (0.52 → 0.61) and getrandom (0.3 → 0.4). No source code is modified. The 1.8.0 version is within the ^1.2.0 semver constraint in Cargo.toml.

Behavioral changes to be aware of (rmcp 1.8.0)

Tool error wrapping — #894: Invalid arguments now produce a CallToolResult { isError: true } (tool-layer error) instead of a protocol-layer error response. The project's tool handlers hit this path via the Parameters<T> extractor. Most MCP clients treat both error forms the same, but any integration test that checks for a specific error shape on bad-argument calls may see different behavior.

Schema stripping — #860, #856: The SDK now strips and validates inputSchema/outputSchema on tool registration. Schemas are generated via schemars and should remain valid, but it is worth running cargo test to confirm tool registration still succeeds end-to-end.

Protocol negotiation strictness — #853: The server now rejects initialize requests where the protocol version in the HTTP header differs from the body. This only affects non-conforming clients; compliant clients (including claude.ai) are unaffected.

Pre-existing gap surfaced by the bump

src/auth.rs:RegistrationRequest intentionally ignores unknown fields (// Accept and ignore additional fields from the MCP client). rmcp 1.8.0 clients now send application_type: "web" in registration requests (#883); RegistrationResponse does not echo it back. RFC 7591 §3.2.1 permits a server to omit fields it does not register, so this is spec-compliant. No action required for this PR, but worth tracking if a future rmcp version validates the echo.

Verdict

Safe to merge. The bump is within semver bounds, no compile-time breaks are expected, and the behavioral changes are correctness improvements rather than regressions.

@renovate
renovate Bot force-pushed the renovate/rmcp-1.x-lockfile branch from e54cb14 to 1f92454 Compare July 20, 2026 21:59
@claude

claude Bot commented Jul 20, 2026

Copy link
Copy Markdown
Contributor

Reviewed this PR. It's a Renovate-generated lockfile-only update (Cargo.lock), bumping rmcp 1.7.0 → 1.8.0 along with transitive deps (windows-sys, getrandom). No source files or Cargo.toml changed.

  • The rmcp 1.8.0 release notes call out a breaking change to Peer::peer_info() (return type changed from Option<&R::PeerInfo> to Option<Arc<R::PeerInfo>>). Checked the codebase — peer_info is not used anywhere, so this does not affect this project.
  • Cargo.toml already specifies rmcp = "1.2.0" (caret range, allows <2.0.0), so 1.8.0 was already a valid resolution target; this PR just updates the lockfile to it.
  • No security, logic, or CLAUDE.md guideline concerns found.

Note: I was unable to run cargo build/cargo test/cargo clippy in this environment (sandboxed, command execution wasn't approved), so compilation wasn't independently re-verified here — worth confirming CI is green before merging.

@renovate
renovate Bot force-pushed the renovate/rmcp-1.x-lockfile branch from 1f92454 to 7570be5 Compare July 29, 2026 01:09
@claude

claude Bot commented Jul 29, 2026

Copy link
Copy Markdown
Contributor

Review summary

This PR only touches Cargo.lock (auto-generated by Renovate) — no source files changed. Findings:

  • rmcp 1.7.0 → 1.8.0: The upstream release notes flag a source-breaking change (Peer::peer_info() now returns Option<Arc<R::PeerInfo>> instead of Option<&R::PeerInfo>). I checked and this codebase does not call peer_info() anywhere (src/mcp.rs, src/auth.rs, etc.), so this breaking change does not affect the build.
  • The Cargo.toml constraint (rmcp = { version = "1.2.0", ... }) already permits this via default caret semantics, consistent with the lockfile bump.
  • The windows-sys 0.61.2 → 0.52.0 changes for a few transitive deps (libc, rustix, getrandom) are just resolver churn from the rmcp update pulling in different transitive requirements — multiple windows-sys versions already coexisted in the lockfile before this change, so this isn't a new issue.

No bugs, security issues, CLAUDE.md violations, or performance concerns found — this is a safe, mechanical dependency update.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants