[Server][Streamable HTTP] Concurrent SSE streams on one session can consume each other's client responses
Los mantenedores suelen responder en 1 día
Evaluación
- Dificultad
- 4/5
- Tiempo estimado
- 3-5 días
- Aptitud para principiantes
- 25/100
- Tipo de issue
- Error
- Claridad
- Bien especificado
- Estado de actividad
- Estancado
- Stack tecnológico
- php
- Área
- backend-api-design
Línea de trabajo
Start with StreamableHttpTransport::createStreamedResponse() and the getPendingRequests() and checkForResponse() calls described in the issue; trace how yielded request IDs relate to each stream's fiber. Check linked pull request #556, which is already open. Done means concurrent streams on one session cannot consume or time out each other's responses.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
Summary
On Streamable HTTP (handshake era, SSE), two tool calls on one session that both send a server-to-client request, such as elicitation/create, can each receive the other's answer.
Cause
Protocol keeps pending server-to-client requests in one session-wide list, _mcp.pending_requests. The SSE loop in StreamableHttpTransport::createStreamedResponse() walks that whole list, not only the requests its own fiber sent:
$pendingRequests = $this->getPendingRequests($this->sessionId);
// ...
foreach ($pendingRequests as $pending) {
$response = $this->checkForResponse($pending['request_id'], $this->sessionId);
if (null !== $response) {
$yielded = $this->sessionFiber->resume($response);
// ...
With tool calls A and B open on one session, each waiting in ClientGateway::elicit():
- The client answers B's elicitation.
- A's loop polls first, finds B's answer, consumes it, and resumes A's fiber with it. A's tool continues with B's answer.
- B's answer is gone from the session. B's tool waits until its 120-second timeout.
The timeout branch has the same problem: A's loop can resume A's fiber with a timeout error for B's request ID.
I found this by reading the source on main (a5ed85f) and 0.8.1. I have not reproduced it end to end. Running two streams on one session at the same time needs a server that doesn't serialize requests per session.
Suggested fix
Record which stream sent each pending request, and have each loop check only its own. For example, track the request IDs the fiber yielded in the transport instance, and filter getPendingRequests() by them.
Context
In Drupal's mcp_server we lock the session for the length of a stream. That lock made a second elicitation wait, which hid this bug. We're changing the lock to cover each session write instead of the whole stream, so elicitation answers don't wait on the lease (mcp_server!88). That makes this race reachable.
- Lenguaje dominante
- PHP
- Estrellas
- 1.6k
- Forks
- 177
- Merge medio
- 3 d 1 h
- PR fusionados (30 d)
- 27
Preparar el entorno
- Sin Dockerfile ni archivo de Docker Compose
- Sin plantilla de pull request
- Leer la guía de contribución
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de modelcontextprotocol/php-sdk
-
[Server] Handler type uses bare Closure, hard to decorate RegistryInterface under strict PHPStanAbiertoServer
Dificultad 1/5 Menos de una hora Aptitud para principiantes 78/100
modelcontextprotocol/php-sdk#468 · 2 comentarios ·
Los mantenedores suelen responder en 1 día
-
Builder::build() silently skips configured file-based discovery when symfony/finder is missing — should fail loudlyPosiblemente ocupada @ousamabenyounes la tomó hace 52 días. Abiertoneeds confirmation needs maintainer action Server
Dificultad 2/5 1-3 horas Aptitud para principiantes 68/100
modelcontextprotocol/php-sdk#398 · 1 reacción ·
Los mantenedores suelen responder en 1 día
-
enhancement
Dificultad 2/5 1-3 horas Aptitud para principiantes 68/100
modelcontextprotocol/php-sdk#370 ·
Los mantenedores suelen responder en 1 día
-
[Client] Expired HTTP sessions remain marked connected, including during cancellationPosiblemente ocupada @ineersa la tomó hoy. Abiertobug
Dificultad 4/5 3-5 días Aptitud para principiantes 25/100
modelcontextprotocol/php-sdk#559 ·
Los mantenedores suelen responder en 1 día
-
Server
Dificultad 4/5 3-5 días Aptitud para principiantes 32/100
modelcontextprotocol/php-sdk#529 · 1 comentario ·
Los mantenedores suelen responder en 1 día
Todos los issues de modelcontextprotocol/php-sdk
Issues similares
-
📚 Documentation: Placeholder link `link-to-realtime-docs` in Flutter SDK changelogPosiblemente ocupada @ShyneChikwapulo la tomó hoy. Abiertoapi / realtime product / auth product / messaging product / vcs
Dificultad 1/5 Menos de una hora Aptitud para principiantes 82/100
appwrite/appwrite#14272 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 82/100
-
Dificultad 1/5 Menos de una hora Aptitud para principiantes 75/100
Boavizta/boaviztapi#580 · 1 comentario ·
-
Add PrestashopAbiertorequest
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
endoflife-date/endoflife.date#11303 ·
Los mantenedores suelen responder en 1 día
-
0. to triage enhancement
Dificultad 2/5 1-3 horas Aptitud para principiantes 65/100
Los mantenedores suelen responder en 1 día