This is an automated email from the ASF dual-hosted git repository.
yuqi1129 pushed a commit to branch branch-1.3
in repository https://gitbox.apache.org/repos/asf/gravitino.git
The following commit(s) were added to refs/heads/branch-1.3 by this push:
new 5e4f55e8a9 [Cherry-pick to branch-1.3] [#13595] improvement(mcp): move
pylint/pytest/parameterized to a dev group (#13596) (#13602)
5e4f55e8a9 is described below
commit 5e4f55e8a91d56e846a55c97782b37c3316bdf5b
Author: geyanggang <[email protected]>
AuthorDate: Tue Sep 29 22:39:26 2026 +0800
[Cherry-pick to branch-1.3] [#13595] improvement(mcp): move
pylint/pytest/parameterized to a dev group (#13596) (#13602)
Cherry-pick Information:
Original commit:
https://github.com/apache/gravitino/commit/502bd5f3720d90fc75514a948063289a43d76348
Target branch: branch-1.3
Status: ✅ Clean cherry-pick (no conflicts)
---
dev/docker/mcp-server/Dockerfile | 7 ++++--
dev/docker/mcp-server/start-mcp-server.sh | 5 +++-
mcp-server/build.gradle.kts | 39 ++++++++++++++++++++++++++++++-
mcp-server/pyproject.toml | 13 ++++++++++-
mcp-server/uv.lock | 14 ++++++++---
5 files changed, 70 insertions(+), 8 deletions(-)
diff --git a/dev/docker/mcp-server/Dockerfile b/dev/docker/mcp-server/Dockerfile
index 3aab0cef36..27f2f0b0a4 100644
--- a/dev/docker/mcp-server/Dockerfile
+++ b/dev/docker/mcp-server/Dockerfile
@@ -22,7 +22,8 @@ LABEL maintainer="[email protected]"
WORKDIR /opt/mcp-server
-COPY --from=ghcr.io/astral-sh/uv:latest /uv /bin/uv
+# Pinned to an exact version so every build ships the same uv.
+COPY --from=ghcr.io/astral-sh/uv:0.12.14 /uv /bin/uv
COPY --chmod=775 packages/mcp-server /opt/mcp-server
@@ -33,7 +34,9 @@ ENV UV_CACHE_DIR=/opt/mcp-server/.cache/uv
RUN uv venv
-RUN uv sync
+# --no-dev excludes the [dependency-groups] dev tools (pylint/astroid, pytest,
+# parameterized) so GPL/LGPL and unused test tooling stay out of the shipped
image.
+RUN uv sync --no-dev
RUN uv pip install -e .
diff --git a/dev/docker/mcp-server/start-mcp-server.sh
b/dev/docker/mcp-server/start-mcp-server.sh
index 6947b34700..6e11b035dc 100644
--- a/dev/docker/mcp-server/start-mcp-server.sh
+++ b/dev/docker/mcp-server/start-mcp-server.sh
@@ -20,4 +20,7 @@
cd /opt/mcp-server
-uv run mcp_server $@
+# --no-dev: the container reads the shipped pyproject.toml at startup; without
it
+# uv run would reinstall the dev-group tools (pylint/astroid, pytest,
parameterized)
+# that the image was built to exclude.
+uv run --no-dev mcp_server $@
diff --git a/mcp-server/build.gradle.kts b/mcp-server/build.gradle.kts
index 9bc51ad8e6..892da89774 100644
--- a/mcp-server/build.gradle.kts
+++ b/mcp-server/build.gradle.kts
@@ -54,6 +54,18 @@ val venvPython = venvExecutable("python")
val blackRequirement = "black==26.5.1"
val isortRequirement = "isort==9.0.0"
+// Dev tooling used by the pylint and testPython tasks: pylint (and its
transitive
+// astroid) for linting, pytest and parameterized for the unit tests. These
live in
+// pyproject's [dependency-groups] dev, not the runtime dependencies, so
+// `uv pip install -e .` (installDependenciesWithUv) does not pull them in and
they
+// never reach the shipped image. Pinned so a new release cannot change the
lint/test
+// outcome in CI.
+val devToolRequirements = listOf(
+ "pylint==3.3.8",
+ "pytest==8.4.1",
+ "parameterized==0.9.0"
+)
+
tasks {
register<Exec>("installUv") {
group = "python"
@@ -178,6 +190,25 @@ tasks {
}
}
+ register<Exec>("installDevTools") {
+ group = "python"
+ description = "Install dev-group tooling (pylint, pytest, parameterized)
into the venv"
+ dependsOn("installDependenciesWithUv")
+ workingDir(pythonProjectDir)
+
+ doFirst {
+ commandLine(
+ listOf(getUvExecutable(), "pip", "install", "--python", venvPython) +
devToolRequirements
+ )
+ }
+
+ doLast {
+ if (executionResult.get().exitValue != 0) {
+ throw GradleException("Failed to install dev tools. Exit code:
${executionResult.get().exitValue}")
+ }
+ }
+ }
+
register("buildPython") {
group = "python"
description = "Build Python project"
@@ -190,7 +221,10 @@ tasks {
register<Exec>("testPython") {
group = "python"
description = "Run Python unit tests with unittest"
- dependsOn("buildPython")
+ // The tests import pytest/parameterized, which moved to pyproject's dev
group and
+ // are therefore not installed by installDependenciesWithUv;
installDevTools adds
+ // them to the venv.
+ dependsOn("buildPython", "installDevTools")
workingDir(pythonProjectDir)
commandLine(venvPython, "-m", "unittest", "discover", "-s", "tests", "-v")
@@ -268,6 +302,9 @@ tasks {
}
tasks.register<Exec>("pylint") {
+ // pylint moved to pyproject's dev group, so it is no longer installed by
+ // installDependenciesWithUv; installDevTools puts it into the venv for this
task.
+ dependsOn("installDevTools")
mustRunAfter("buildPython")
commandLine(venvPython, "-m", "pylint", "./tests", "./mcp_server")
}
diff --git a/mcp-server/pyproject.toml b/mcp-server/pyproject.toml
index e23762cd16..43b3969ec2 100644
--- a/mcp-server/pyproject.toml
+++ b/mcp-server/pyproject.toml
@@ -24,7 +24,10 @@ requires-python = ">=3.10"
dependencies = [
# Pin FastMCP so breaking API changes are handled explicitly during
dependency upgrades.
"fastmcp==3.2.0",
- # Function validation aliases require Pydantic 2.12 or newer.
+ # Function argument validation via
Field(validation_alias=AliasChoices(...)) — used to
+ # keep accepting legacy tool argument names — is only honored from
Pydantic 2.12.0
+ # (fix: https://github.com/pydantic/pydantic/pull/12340). Without this
floor the lock
+ # resolves an older Pydantic and the legacy-alias tests fail.
"pydantic>=2.12.0,<3",
# httpx.Auth plugin for hop-2 client_credentials fetch/cache.
"httpx-auth>=0.22,<0.24",
@@ -33,6 +36,14 @@ dependencies = [
# fakeredis.aioredis, which pydocket still uses. Pin fakeredis to <2.35.0
until the
# tracked pydocket/fakeredis compatibility issue is resolved.
"fakeredis<2.35.0",
+]
+
+# Development-only dependencies. These are NOT shipped in the MCP server image:
+# the Dockerfile runs `uv sync --no-dev` and start-mcp-server.sh runs `uv run
--no-dev`,
+# so pylint (GPL-2.0-or-later) and its transitive dep astroid (LGPL) stay out
of the
+# distributed runtime environment. Developers still get them via `uv sync`
locally.
+[dependency-groups]
+dev = [
"parameterized>=0.9.0",
"pytest>=8.4.1",
"pylint>=2.20.0",
diff --git a/mcp-server/uv.lock b/mcp-server/uv.lock
index 168c6b6708..69ec4fd1af 100644
--- a/mcp-server/uv.lock
+++ b/mcp-server/uv.lock
@@ -459,14 +459,18 @@ wheels = [
[[package]]
name = "gravitino-mcp-server"
-version = "1.3.1.dev0"
+version = "1.3.2.dev0"
source = { virtual = "." }
dependencies = [
{ name = "fakeredis" },
{ name = "fastmcp" },
{ name = "httpx-auth" },
- { name = "parameterized" },
{ name = "pydantic" },
+]
+
+[package.dev-dependencies]
+dev = [
+ { name = "parameterized" },
{ name = "pylint" },
{ name = "pytest" },
]
@@ -476,8 +480,12 @@ requires-dist = [
{ name = "fakeredis", specifier = "<2.35.0" },
{ name = "fastmcp", specifier = "==3.2.0" },
{ name = "httpx-auth", specifier = ">=0.22,<0.24" },
- { name = "parameterized", specifier = ">=0.9.0" },
{ name = "pydantic", specifier = ">=2.12.0,<3" },
+]
+
+[package.metadata.requires-dev]
+dev = [
+ { name = "parameterized", specifier = ">=0.9.0" },
{ name = "pylint", specifier = ">=2.20.0" },
{ name = "pytest", specifier = ">=8.4.1" },
]