Skip to content

feat(server): migrate to MCP SDK v2 MCPServer API - #17

Open
zxkjack123 wants to merge 9 commits into
SecurityRonin:mainfrom
zxkjack123:feat/migrate-mcp-sdk-v2
Open

zxkjack123 wants to merge 9 commits into
SecurityRonin:mainfrom
zxkjack123:feat/migrate-mcp-sdk-v2

Conversation

@zxkjack123

Copy link
Copy Markdown
Contributor

Summary

Migrates docx-mcp from MCP SDK v1 (mcp.server.fastmcp.FastMCP) to v2 (mcp.server.MCPServer). This supersedes the mcp>=1.28,<2 pin from PR #16.

Migration surface (audited, not estimated)

Change Location
from mcp.server import MCPServer server.py:19
FastMCP( → MCPServer( (args unchanged) server.py:23
219 @mcp.tool() decorators unchanged — v2-compatible per migration guide
mcp>=2,<3 pyproject.toml

Verified zero hits for the migration guide's high-risk items: mcp.types imports, camelCase fields, get_context(), McpError, .root access, constructor transport params, MCP_* env vars, httpx dependency.

Thread safety

v2 runs sync handlers on worker threads (v1 ran them on the event loop, which accidentally serialized them). docx-mcp has 225 sync tools sharing the global _docs dict, so this PR adds a threading.RLock guarding all _docs access points (_resolve, _store, close_document, the _Module._doc compat property). Filesystem cleanup (doc.close()) runs outside the lock.

Known limitation (documented): same-handle concurrent edits are not serialized. This matches the existing instructions ("unsafe for parallel ones") and LLM clients' serialized tool-call pattern. Per-document serialization can be a follow-up if real usage shows a need.

Test results

1108 passed, 3 skipped, 0 failures   (uv run pytest, mcp 2.0.0)

Smoke test with the v2 official Client (in-process):

SMOKE OK: 219 tools registered
  server_info: name='docx-mcp'
  protocol_version: 2026-07-28

Real tool call returns a clean tool error (not a crash) when no document is open.

Notes

Closes #14

…resolve()

When para_id is explicitly provided, _resolve() no longer rejects
the operation because the same text appears in other paragraphs.
The paragraph-level dedup (multiple matches within one paragraph
without context) is preserved.

Closes SecurityRonin#6
This merges the fix for SecurityRonin#6 (remove document-global uniqueness guard
from _resolve()) into our local main so we can use the patched version
immediately. The feature branch remains available for the upstream PR.

PR: SecurityRonin#11
When tracked=True, wraps existing w:r elements in w:del and appends
new text in w:ins, producing proper revision markup.
tracked=False preserves the existing silent-update behavior.

Closes SecurityRonin#9
Adds tracked=True support to update_paragraph (Closes SecurityRonin#9).
Branch retained for upstream PR.
…e_image

Both tools now accept document_handle: str = '' for concurrent
session isolation. Empty string continues to use __default__ slot.

Closes SecurityRonin#8
Adds document_handle to copy_document and update_image (Closes SecurityRonin#8).
Branch retained for upstream PR.
MCP SDK 2.0.0 removed mcp.server.fastmcp (FastMCP renamed to MCPServer).
Unpinned mcp>=1.0.0 lets fresh installs resolve to 2.0.0 and die on
import. Pin to the v1 maintenance line until migration to MCPServer
API is done (see issue SecurityRonin#14).

Closes SecurityRonin#14
Pins mcp>=1.28,<2 (Closes SecurityRonin#14). Branch retained for upstream PR.
- FastMCP -> MCPServer (from mcp.server import MCPServer)
- 219 @mcp.tool() decorators unchanged (v2-compatible per migration guide)
- Add threading.RLock around _docs dict (v2 runs sync handlers on worker threads)
- Pin mcp>=2,<3

Supersedes the mcp>=1.28,<2 pin from PR SecurityRonin#16.
Known limitation: same-handle concurrent edits are not serialized (documented).
@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedmcp@​1.26.0 ⏵ 2.0.099 +1100 +31100100100

View full report

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Unpinned mcp>=1.0.0 breaks all fresh installs since MCP SDK 2.0.0 removed mcp.server.fastmcp

1 participant