[ 
https://issues.apache.org/jira/browse/KUDU-3806?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18120099#comment-18120099
 ] 

ASF subversion and git services commented on KUDU-3806:
-------------------------------------------------------

Commit c813a7c233c8758be91ac38d31c0124ccb0880f7 in kudu's branch 
refs/heads/master from Marton Greber
[ https://gitbox.apache.org/repos/asf?p=kudu.git;h=c813a7c23 ]

KUDU-3806: add deadline-bounded WaitAndCollect()

Add Subprocess::WaitAndCollect(), which concurrently drains the child's
piped stdout and stderr while waiting for it to exit, up to a deadline.
Draining both pipes together means a large write on one cannot deadlock
against a full buffer on the other; if the deadline passes first the
child is killed (SIGKILL), '*timed_out' is set, and whatever output was
collected so far is still returned.

To support this, ReadFdsFully() gains a deadline: a one-shot libev timer
(DeadlineHelper) breaks the drain loop when it fires, and each fd watcher
now decrements a shared open-count so the loop ends deterministically at
EOF even with the timer armed. An uninitialized deadline preserves the
historical "drain to EOF" behavior, which is what Subprocess::Call()
continues to pass.

This is groundwork for running each MCP tools/call in a bounded child
'kudu' process.

Change-Id: I582ea89b0ada4f723695df8d98d7e5bc0bbc7f7f
Co-Authored-By: Claude Opus 4.8 <[email protected]>
Reviewed-on: http://gerrit.cloudera.org:8080/24905
Reviewed-by: Gabriella Lotz <[email protected]>
Reviewed-by: Alexey Serbin <[email protected]>
Tested-by: Marton Greber <[email protected]>


> Kudu MCP
> --------
>
>                 Key: KUDU-3806
>                 URL: https://issues.apache.org/jira/browse/KUDU-3806
>             Project: Kudu
>          Issue Type: New Feature
>            Reporter: Marton Greber
>            Assignee: Marton Greber
>            Priority: Major
>
>  Introduce kudu mcp serve, an MCP server that exposes existing kudu CLI 
> actions as MCP tools so operators can drive cluster diagnostics and 
> administration from an MCP-capable client (e.g. an LLM agent) without 
> hand-crafting command lines.
> Design highlights:
>  - Safety classification. Every action in the CLI action tree resolves to 
> exactly one Disposition:
>  -- SURFACE — read-only, always exposed (node-local reads are surfaced but 
> tagged as only meaningful on that node);
>  -- GATED — cluster-mutating, hidden unless --allow-writes is set;
>  -- REJECT — long-running/never-promptly-returning ops that would wedge the 
> single-threaded serve loop;
>  -- EXCLUDE — interactive or node-local mutating actions, never surfaced.
>  - Read-only by default. Mutating tools are only advertised with 
> --allow-writes.
>  - Process isolation. Each tools/call runs its action in a fresh child kudu 
> process bounded by --mcp_tool_timeout_sec (default 60s), so a hung action 
> cannot freeze the server.
>  - Credential hygiene. --master_addresses is registered once at serve time 
> and injected into each call, so it never has to appear in the conversation.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to