Skip to content

fix(tools/bigquery): keep the provider error classification in bigquery-execute-sql - #3738

Merged
Yuan325 merged 3 commits into
googleapis:mainfrom
he-yufeng:fix/bq-execute-sql-error-classification
Jul 29, 2026
Merged

fix(tools/bigquery): keep the provider error classification in bigquery-execute-sql#3738
Yuan325 merged 3 commits into
googleapis:mainfrom
he-yufeng:fix/bq-execute-sql-error-classification

Conversation

@he-yufeng

Copy link
Copy Markdown
Contributor

What

Fixes #3716. On the actual query run, bigquery-execute-sql wrapped every provider failure in a blanket NewClientServerError("error running sql", 500, err), so a BigQuery 403 from an impersonated service account missing dataViewer surfaced as HTTP 500 and connectors showed an opaque bad-gateway instead of anything recoverable. The dry-run path in the same tool already routed through util.ProcessGcpError, which made the two stages inconsistent with each other.

The actual-run error path now goes through util.ProcessGcpError too, the same classification the other GCP tools use (bigtable, firestore, datalineage, and this tool's dry run): 401/403 keep their status with the provider cause attached, and everything else becomes a readable AgentError so the model sees the real message (invalid SQL, missing table) instead of a generic 500.

How

One-line swap at the RunSQL error site, plus TestInvokeRunSqlErrorClassification: a 403 from the provider must come back as ClientServerError with code 403 and the Access Denied cause visible, and a 400 must come back as an AgentError with the cause visible. Existing tests (TestInvokeDatasetRestrictions and the rest of the package) still pass.

Verification

  • go test ./internal/tools/bigquery/bigqueryexecutesql/ - all pass, including the two new classification subtests
  • go vet ./internal/tools/bigquery/bigqueryexecutesql/ - clean

@he-yufeng
he-yufeng requested review from a team as code owners July 28, 2026 21:19

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request updates the BigQuery execute SQL tool to use util.ProcessGcpError for handling SQL execution errors, ensuring that GCP-specific errors (such as 403 Access Denied) retain their correct classification rather than being collapsed into generic 500 internal server errors. It also adds a comprehensive unit test, TestInvokeRunSqlErrorClassification, to verify this error classification behavior. There are no review comments, and I have no additional feedback to provide.

@Yuan325 Yuan325 added the release candidate Use label to signal PR should be included in the next release. label Jul 29, 2026
@Yuan325

Yuan325 commented Jul 29, 2026

Copy link
Copy Markdown
Contributor

Thank you for your contributions! @he-yufeng :)

@Yuan325

Yuan325 commented Jul 29, 2026

Copy link
Copy Markdown
Contributor

/gcbrun

@Yuan325
Yuan325 enabled auto-merge (squash) July 29, 2026 18:07
@Yuan325
Yuan325 merged commit 42570b8 into googleapis:main Jul 29, 2026
20 checks passed
Yuan325 added a commit that referenced this pull request Aug 14, 2026
🤖 I have created a release *beep* *boop*
---


##
[1.9.0](v1.8.0...v1.9.0)
(2026-08-14)


### Features

* **groups:** Add ttlMs and cacheScope customization to config
([#3805](#3805))
([a5d4947](a5d4947))
* **migrate:** Convert toolset to group kind during migration
([#3704](#3704))
([0adeaa5](0adeaa5))
* **server/mcp:** Introduce generic client extension registry
([#3723](#3723))
([016245c](016245c))
* **skill:** Add review-prs skill for mcp-toolbox
([#3743](#3743))
([5b7bacc](5b7bacc))
* **source/bigquery:** Add apiEndpoint field to override BigQuery API
host ([#3437](#3437))
([4da1600](4da1600))
* **source/databaseinsights:** Add databaseinsights source
([#3461](#3461))
([3b9615d](3b9615d))
* **sources/spanner:** Rename execute_sql_dql to execute_sql_readonly
([#3776](#3776))
([cf5a0c8](cf5a0c8))
* **tools/bigtable:** Add admin lifecycle and listing tools
([#3596](#3596))
([801d589](801d589))
* **tools/bigtable:** Bigtable-list-schemas MCP tool
([#3683](#3683))
([9228c61](9228c61))
* **tools/databaseinsights:** Add Advanced Query Insights tools for
AlloyDB ([#3722](#3722))
([74d18ae](74d18ae))
* **tools/looker:** Add additional tools to allow dashboards to be
modified, and their layouts altered.
([#3597](#3597))
([b2b80fb](b2b80fb))
* **tools:** Add cloud-sql-connect-gce for pg, mysql, mssql
([#3740](#3740))
([ca58fa4](ca58fa4))


### Bug Fixes

* **auth/mcp:** Derive PRM URL from Toolbox URL
([#3765](#3765))
([aa30842](aa30842))
* **config:** Ignore environment variables in YAML comments
([#3807](#3807))
([79aa732](79aa732)),
refs [#3793](#3793)
* **mcp:** Return Tool execution error for invalid input param
([#3799](#3799))
([8120197](8120197))
* **prebuilt/cloud-storage:** Declare tool collections as groups
([#3764](#3764))
([7d468be](7d468be))
* **server/mcp:** Disallow client overriding URL bound parameters
([#3798](#3798))
([f15a9c7](f15a9c7))
* **server:** Avoid a nil-flusher panic in the SSE handler
([#3520](#3520))
([947f42f](947f42f))
* **tools/bigquery:** Keep the provider error classification in
bigquery-execute-sql
([#3738](#3738))
([42570b8](42570b8))
* **tools/looker:** Scope the filters quoting rule to values in query
description
([#3788](#3788))
([78eb0b8](78eb0b8))
* **util:** Convert exponent-form JSON numbers in ConvertNumbers
([#3730](#3730))
([e9713ee](e9713ee))

---
This PR was generated with [Release
Please](https://github.com/googleapis/release-please). See
[documentation](https://github.com/googleapis/release-please#release-please).

---------

Co-authored-by: release-please[bot] <55107282+release-please[bot]@users.noreply.github.com>
Co-authored-by: Yuan Teoh <45984206+Yuan325@users.noreply.github.com>
github-actions Bot pushed a commit that referenced this pull request Aug 14, 2026
🤖 I have created a release *beep* *boop*
---

##
[1.9.0](v1.8.0...v1.9.0)
(2026-08-14)

### Features

* **groups:** Add ttlMs and cacheScope customization to config
([#3805](#3805))
([a5d4947](a5d4947))
* **migrate:** Convert toolset to group kind during migration
([#3704](#3704))
([0adeaa5](0adeaa5))
* **server/mcp:** Introduce generic client extension registry
([#3723](#3723))
([016245c](016245c))
* **skill:** Add review-prs skill for mcp-toolbox
([#3743](#3743))
([5b7bacc](5b7bacc))
* **source/bigquery:** Add apiEndpoint field to override BigQuery API
host ([#3437](#3437))
([4da1600](4da1600))
* **source/databaseinsights:** Add databaseinsights source
([#3461](#3461))
([3b9615d](3b9615d))
* **sources/spanner:** Rename execute_sql_dql to execute_sql_readonly
([#3776](#3776))
([cf5a0c8](cf5a0c8))
* **tools/bigtable:** Add admin lifecycle and listing tools
([#3596](#3596))
([801d589](801d589))
* **tools/bigtable:** Bigtable-list-schemas MCP tool
([#3683](#3683))
([9228c61](9228c61))
* **tools/databaseinsights:** Add Advanced Query Insights tools for
AlloyDB ([#3722](#3722))
([74d18ae](74d18ae))
* **tools/looker:** Add additional tools to allow dashboards to be
modified, and their layouts altered.
([#3597](#3597))
([b2b80fb](b2b80fb))
* **tools:** Add cloud-sql-connect-gce for pg, mysql, mssql
([#3740](#3740))
([ca58fa4](ca58fa4))

### Bug Fixes

* **auth/mcp:** Derive PRM URL from Toolbox URL
([#3765](#3765))
([aa30842](aa30842))
* **config:** Ignore environment variables in YAML comments
([#3807](#3807))
([79aa732](79aa732)),
refs [#3793](#3793)
* **mcp:** Return Tool execution error for invalid input param
([#3799](#3799))
([8120197](8120197))
* **prebuilt/cloud-storage:** Declare tool collections as groups
([#3764](#3764))
([7d468be](7d468be))
* **server/mcp:** Disallow client overriding URL bound parameters
([#3798](#3798))
([f15a9c7](f15a9c7))
* **server:** Avoid a nil-flusher panic in the SSE handler
([#3520](#3520))
([947f42f](947f42f))
* **tools/bigquery:** Keep the provider error classification in
bigquery-execute-sql
([#3738](#3738))
([42570b8](42570b8))
* **tools/looker:** Scope the filters quoting rule to values in query
description
([#3788](#3788))
([78eb0b8](78eb0b8))
* **util:** Convert exponent-form JSON numbers in ConvertNumbers
([#3730](#3730))
([e9713ee](e9713ee))

---
This PR was generated with [Release
Please](https://github.com/googleapis/release-please). See
[documentation](https://github.com/googleapis/release-please#release-please).

---------

Co-authored-by: release-please[bot] <55107282+release-please[bot]@users.noreply.github.com>
Co-authored-by: Yuan Teoh <45984206+Yuan325@users.noreply.github.com> 5de8f13
github-actions Bot pushed a commit to rodineyw/mcp-toolbox that referenced this pull request Aug 14, 2026
🤖 I have created a release *beep* *boop*
---

##
[1.9.0](googleapis/mcp-toolbox@v1.8.0...v1.9.0)
(2026-08-14)

### Features

* **groups:** Add ttlMs and cacheScope customization to config
([googleapis#3805](googleapis#3805))
([a5d4947](googleapis@a5d4947))
* **migrate:** Convert toolset to group kind during migration
([googleapis#3704](googleapis#3704))
([0adeaa5](googleapis@0adeaa5))
* **server/mcp:** Introduce generic client extension registry
([googleapis#3723](googleapis#3723))
([016245c](googleapis@016245c))
* **skill:** Add review-prs skill for mcp-toolbox
([googleapis#3743](googleapis#3743))
([5b7bacc](googleapis@5b7bacc))
* **source/bigquery:** Add apiEndpoint field to override BigQuery API
host ([googleapis#3437](googleapis#3437))
([4da1600](googleapis@4da1600))
* **source/databaseinsights:** Add databaseinsights source
([googleapis#3461](googleapis#3461))
([3b9615d](googleapis@3b9615d))
* **sources/spanner:** Rename execute_sql_dql to execute_sql_readonly
([googleapis#3776](googleapis#3776))
([cf5a0c8](googleapis@cf5a0c8))
* **tools/bigtable:** Add admin lifecycle and listing tools
([googleapis#3596](googleapis#3596))
([801d589](googleapis@801d589))
* **tools/bigtable:** Bigtable-list-schemas MCP tool
([googleapis#3683](googleapis#3683))
([9228c61](googleapis@9228c61))
* **tools/databaseinsights:** Add Advanced Query Insights tools for
AlloyDB ([googleapis#3722](googleapis#3722))
([74d18ae](googleapis@74d18ae))
* **tools/looker:** Add additional tools to allow dashboards to be
modified, and their layouts altered.
([googleapis#3597](googleapis#3597))
([b2b80fb](googleapis@b2b80fb))
* **tools:** Add cloud-sql-connect-gce for pg, mysql, mssql
([googleapis#3740](googleapis#3740))
([ca58fa4](googleapis@ca58fa4))

### Bug Fixes

* **auth/mcp:** Derive PRM URL from Toolbox URL
([googleapis#3765](googleapis#3765))
([aa30842](googleapis@aa30842))
* **config:** Ignore environment variables in YAML comments
([googleapis#3807](googleapis#3807))
([79aa732](googleapis@79aa732)),
refs [googleapis#3793](googleapis#3793)
* **mcp:** Return Tool execution error for invalid input param
([googleapis#3799](googleapis#3799))
([8120197](googleapis@8120197))
* **prebuilt/cloud-storage:** Declare tool collections as groups
([googleapis#3764](googleapis#3764))
([7d468be](googleapis@7d468be))
* **server/mcp:** Disallow client overriding URL bound parameters
([googleapis#3798](googleapis#3798))
([f15a9c7](googleapis@f15a9c7))
* **server:** Avoid a nil-flusher panic in the SSE handler
([googleapis#3520](googleapis#3520))
([947f42f](googleapis@947f42f))
* **tools/bigquery:** Keep the provider error classification in
bigquery-execute-sql
([googleapis#3738](googleapis#3738))
([42570b8](googleapis@42570b8))
* **tools/looker:** Scope the filters quoting rule to values in query
description
([googleapis#3788](googleapis#3788))
([78eb0b8](googleapis@78eb0b8))
* **util:** Convert exponent-form JSON numbers in ConvertNumbers
([googleapis#3730](googleapis#3730))
([e9713ee](googleapis@e9713ee))

---
This PR was generated with [Release
Please](https://github.com/googleapis/release-please). See
[documentation](https://github.com/googleapis/release-please#release-please).

---------

Co-authored-by: release-please[bot] <55107282+release-please[bot]@users.noreply.github.com>
Co-authored-by: Yuan Teoh <45984206+Yuan325@users.noreply.github.com> 5de8f13
github-actions Bot pushed a commit to Jaleel-zhu/genai-toolbox that referenced this pull request Aug 14, 2026
🤖 I have created a release *beep* *boop*
---

##
[1.9.0](googleapis/mcp-toolbox@v1.8.0...v1.9.0)
(2026-08-14)

### Features

* **groups:** Add ttlMs and cacheScope customization to config
([googleapis#3805](googleapis#3805))
([a5d4947](googleapis@a5d4947))
* **migrate:** Convert toolset to group kind during migration
([googleapis#3704](googleapis#3704))
([0adeaa5](googleapis@0adeaa5))
* **server/mcp:** Introduce generic client extension registry
([googleapis#3723](googleapis#3723))
([016245c](googleapis@016245c))
* **skill:** Add review-prs skill for mcp-toolbox
([googleapis#3743](googleapis#3743))
([5b7bacc](googleapis@5b7bacc))
* **source/bigquery:** Add apiEndpoint field to override BigQuery API
host ([googleapis#3437](googleapis#3437))
([4da1600](googleapis@4da1600))
* **source/databaseinsights:** Add databaseinsights source
([googleapis#3461](googleapis#3461))
([3b9615d](googleapis@3b9615d))
* **sources/spanner:** Rename execute_sql_dql to execute_sql_readonly
([googleapis#3776](googleapis#3776))
([cf5a0c8](googleapis@cf5a0c8))
* **tools/bigtable:** Add admin lifecycle and listing tools
([googleapis#3596](googleapis#3596))
([801d589](googleapis@801d589))
* **tools/bigtable:** Bigtable-list-schemas MCP tool
([googleapis#3683](googleapis#3683))
([9228c61](googleapis@9228c61))
* **tools/databaseinsights:** Add Advanced Query Insights tools for
AlloyDB ([googleapis#3722](googleapis#3722))
([74d18ae](googleapis@74d18ae))
* **tools/looker:** Add additional tools to allow dashboards to be
modified, and their layouts altered.
([googleapis#3597](googleapis#3597))
([b2b80fb](googleapis@b2b80fb))
* **tools:** Add cloud-sql-connect-gce for pg, mysql, mssql
([googleapis#3740](googleapis#3740))
([ca58fa4](googleapis@ca58fa4))

### Bug Fixes

* **auth/mcp:** Derive PRM URL from Toolbox URL
([googleapis#3765](googleapis#3765))
([aa30842](googleapis@aa30842))
* **config:** Ignore environment variables in YAML comments
([googleapis#3807](googleapis#3807))
([79aa732](googleapis@79aa732)),
refs [googleapis#3793](googleapis#3793)
* **mcp:** Return Tool execution error for invalid input param
([googleapis#3799](googleapis#3799))
([8120197](googleapis@8120197))
* **prebuilt/cloud-storage:** Declare tool collections as groups
([googleapis#3764](googleapis#3764))
([7d468be](googleapis@7d468be))
* **server/mcp:** Disallow client overriding URL bound parameters
([googleapis#3798](googleapis#3798))
([f15a9c7](googleapis@f15a9c7))
* **server:** Avoid a nil-flusher panic in the SSE handler
([googleapis#3520](googleapis#3520))
([947f42f](googleapis@947f42f))
* **tools/bigquery:** Keep the provider error classification in
bigquery-execute-sql
([googleapis#3738](googleapis#3738))
([42570b8](googleapis@42570b8))
* **tools/looker:** Scope the filters quoting rule to values in query
description
([googleapis#3788](googleapis#3788))
([78eb0b8](googleapis@78eb0b8))
* **util:** Convert exponent-form JSON numbers in ConvertNumbers
([googleapis#3730](googleapis#3730))
([e9713ee](googleapis@e9713ee))

---
This PR was generated with [Release
Please](https://github.com/googleapis/release-please). See
[documentation](https://github.com/googleapis/release-please#release-please).

---------

Co-authored-by: release-please[bot] <55107282+release-please[bot]@users.noreply.github.com>
Co-authored-by: Yuan Teoh <45984206+Yuan325@users.noreply.github.com> 5de8f13
github-actions Bot pushed a commit to pepe57/genai-toolbox that referenced this pull request Aug 14, 2026
🤖 I have created a release *beep* *boop*
---

##
[1.9.0](googleapis/mcp-toolbox@v1.8.0...v1.9.0)
(2026-08-14)

### Features

* **groups:** Add ttlMs and cacheScope customization to config
([googleapis#3805](googleapis#3805))
([a5d4947](googleapis@a5d4947))
* **migrate:** Convert toolset to group kind during migration
([googleapis#3704](googleapis#3704))
([0adeaa5](googleapis@0adeaa5))
* **server/mcp:** Introduce generic client extension registry
([googleapis#3723](googleapis#3723))
([016245c](googleapis@016245c))
* **skill:** Add review-prs skill for mcp-toolbox
([googleapis#3743](googleapis#3743))
([5b7bacc](googleapis@5b7bacc))
* **source/bigquery:** Add apiEndpoint field to override BigQuery API
host ([googleapis#3437](googleapis#3437))
([4da1600](googleapis@4da1600))
* **source/databaseinsights:** Add databaseinsights source
([googleapis#3461](googleapis#3461))
([3b9615d](googleapis@3b9615d))
* **sources/spanner:** Rename execute_sql_dql to execute_sql_readonly
([googleapis#3776](googleapis#3776))
([cf5a0c8](googleapis@cf5a0c8))
* **tools/bigtable:** Add admin lifecycle and listing tools
([googleapis#3596](googleapis#3596))
([801d589](googleapis@801d589))
* **tools/bigtable:** Bigtable-list-schemas MCP tool
([googleapis#3683](googleapis#3683))
([9228c61](googleapis@9228c61))
* **tools/databaseinsights:** Add Advanced Query Insights tools for
AlloyDB ([googleapis#3722](googleapis#3722))
([74d18ae](googleapis@74d18ae))
* **tools/looker:** Add additional tools to allow dashboards to be
modified, and their layouts altered.
([googleapis#3597](googleapis#3597))
([b2b80fb](googleapis@b2b80fb))
* **tools:** Add cloud-sql-connect-gce for pg, mysql, mssql
([googleapis#3740](googleapis#3740))
([ca58fa4](googleapis@ca58fa4))

### Bug Fixes

* **auth/mcp:** Derive PRM URL from Toolbox URL
([googleapis#3765](googleapis#3765))
([aa30842](googleapis@aa30842))
* **config:** Ignore environment variables in YAML comments
([googleapis#3807](googleapis#3807))
([79aa732](googleapis@79aa732)),
refs [googleapis#3793](googleapis#3793)
* **mcp:** Return Tool execution error for invalid input param
([googleapis#3799](googleapis#3799))
([8120197](googleapis@8120197))
* **prebuilt/cloud-storage:** Declare tool collections as groups
([googleapis#3764](googleapis#3764))
([7d468be](googleapis@7d468be))
* **server/mcp:** Disallow client overriding URL bound parameters
([googleapis#3798](googleapis#3798))
([f15a9c7](googleapis@f15a9c7))
* **server:** Avoid a nil-flusher panic in the SSE handler
([googleapis#3520](googleapis#3520))
([947f42f](googleapis@947f42f))
* **tools/bigquery:** Keep the provider error classification in
bigquery-execute-sql
([googleapis#3738](googleapis#3738))
([42570b8](googleapis@42570b8))
* **tools/looker:** Scope the filters quoting rule to values in query
description
([googleapis#3788](googleapis#3788))
([78eb0b8](googleapis@78eb0b8))
* **util:** Convert exponent-form JSON numbers in ConvertNumbers
([googleapis#3730](googleapis#3730))
([e9713ee](googleapis@e9713ee))

---
This PR was generated with [Release
Please](https://github.com/googleapis/release-please). See
[documentation](https://github.com/googleapis/release-please#release-please).

---------

Co-authored-by: release-please[bot] <55107282+release-please[bot]@users.noreply.github.com>
Co-authored-by: Yuan Teoh <45984206+Yuan325@users.noreply.github.com> 5de8f13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

release candidate Use label to signal PR should be included in the next release.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

BigQuery 403 from impersonated SA should be AgentError, not HTTP 500 / Cloudflare 502

2 participants