[Server][Streamable HTTP] Concurrent SSE streams on one session can consume each other's client responses
Maintainer antworten meist innerhalb von 1 Tag
Bewertung
- Schwierigkeit
- 4/5
- Geschätzter Aufwand
- 3-5 Tage
- Anfängerfreundlichkeit
- 25/100
- Issue-Typ
- Bug
- Klarheit
- Klar beschrieben
- Aktivitätsstatus
- Veraltet
- Tech-Stack
- php
- Bereich
- backend-api-design
Rechercherichtung
Start with StreamableHttpTransport::createStreamedResponse() and the getPendingRequests() and checkForResponse() calls described in the issue; trace how yielded request IDs relate to each stream's fiber. Check linked pull request #556, which is already open. Done means concurrent streams on one session cannot consume or time out each other's responses.
Vom Indexierungsmodell aus dem Issue-Text verfasst.
Beschreibung
Summary
On Streamable HTTP (handshake era, SSE), two tool calls on one session that both send a server-to-client request, such as elicitation/create, can each receive the other's answer.
Cause
Protocol keeps pending server-to-client requests in one session-wide list, _mcp.pending_requests. The SSE loop in StreamableHttpTransport::createStreamedResponse() walks that whole list, not only the requests its own fiber sent:
$pendingRequests = $this->getPendingRequests($this->sessionId);
// ...
foreach ($pendingRequests as $pending) {
$response = $this->checkForResponse($pending['request_id'], $this->sessionId);
if (null !== $response) {
$yielded = $this->sessionFiber->resume($response);
// ...
With tool calls A and B open on one session, each waiting in ClientGateway::elicit():
- The client answers B's elicitation.
- A's loop polls first, finds B's answer, consumes it, and resumes A's fiber with it. A's tool continues with B's answer.
- B's answer is gone from the session. B's tool waits until its 120-second timeout.
The timeout branch has the same problem: A's loop can resume A's fiber with a timeout error for B's request ID.
I found this by reading the source on main (a5ed85f) and 0.8.1. I have not reproduced it end to end. Running two streams on one session at the same time needs a server that doesn't serialize requests per session.
Suggested fix
Record which stream sent each pending request, and have each loop check only its own. For example, track the request IDs the fiber yielded in the transport instance, and filter getPendingRequests() by them.
Context
In Drupal's mcp_server we lock the session for the length of a stream. That lock made a second elicitation wait, which hid this bug. We're changing the lock to cover each session write instead of the whole stream, so elicitation answers don't wait on the lease (mcp_server!88). That makes this race reachable.
- Vorherrschende Sprache
- PHP
- Sterne
- 1.6k
- Forks
- 177
- Ø Merge
- 3 T. 1 Std.
- Gemergte PRs (30 T.)
- 27
Entwicklungsumgebung
- Kein Dockerfile und keine Docker-Compose-Datei
- Keine Pull-Request-Vorlage
- Beitragsleitfaden lesen
Erste Schritte
- Lesen Sie das ganze Issue und danach den Beitragsleitfaden des Projekts.
- Schreiben Sie ins Issue, dass Sie es übernehmen — das erspart doppelte Arbeit.
- Forken Sie das Repository und arbeiten Sie in einem Branch.
- Öffnen Sie einen Pull Request, der die Issue-Nummer nennt.
Mehr aus modelcontextprotocol/php-sdk
-
[Server] Handler type uses bare Closure, hard to decorate RegistryInterface under strict PHPStanOffenServer
Schwierigkeit 1/5 Unter einer Stunde Anfängerfreundlichkeit 78/100
modelcontextprotocol/php-sdk#468 · 2 Kommentare ·
Maintainer antworten meist innerhalb von 1 Tag
-
Builder::build() silently skips configured file-based discovery when symfony/finder is missing — should fail loudlyEvtl. vergeben @ousamabenyounes hat das vor 51 Tagen übernommen. Offenneeds confirmation needs maintainer action Server
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 68/100
modelcontextprotocol/php-sdk#398 · 1 Reaktion ·
Maintainer antworten meist innerhalb von 1 Tag
-
enhancement
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 68/100
modelcontextprotocol/php-sdk#370 ·
Maintainer antworten meist innerhalb von 1 Tag
-
[Client] Expired HTTP sessions remain marked connected, including during cancellationEvtl. vergeben @ineersa hat das heute übernommen. Offenbug
Schwierigkeit 4/5 3-5 Tage Anfängerfreundlichkeit 25/100
modelcontextprotocol/php-sdk#559 ·
Maintainer antworten meist innerhalb von 1 Tag
-
Server
Schwierigkeit 4/5 3-5 Tage Anfängerfreundlichkeit 32/100
modelcontextprotocol/php-sdk#529 · 1 Kommentar ·
Maintainer antworten meist innerhalb von 1 Tag
Alle Issues in modelcontextprotocol/php-sdk
Ähnliche Issues
-
📚 Documentation: Placeholder link `link-to-realtime-docs` in Flutter SDK changelogEvtl. vergeben @ShyneChikwapulo hat das heute übernommen. Offenapi / realtime product / auth product / messaging product / vcs
Schwierigkeit 1/5 Unter einer Stunde Anfängerfreundlichkeit 82/100
appwrite/appwrite#14272 · 1 Kommentar ·
Maintainer antworten meist innerhalb von 1 Tag
-
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 82/100
-
Schwierigkeit 1/5 Unter einer Stunde Anfängerfreundlichkeit 75/100
Boavizta/boaviztapi#580 · 1 Kommentar ·
-
Add PrestashopOffenrequest
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 72/100
endoflife-date/endoflife.date#11303 ·
Maintainer antworten meist innerhalb von 1 Tag
-
0. to triage enhancement
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 65/100
Maintainer antworten meist innerhalb von 1 Tag