[Server][Streamable HTTP] Concurrent SSE streams on one session can consume each other's client responses
I maintainer di solito rispondono entro 1 giorno
Una pull request collegata è già stata integrata.
- #556 di @mglaman — integrata
Valutazione
- Difficoltà
- 4/5
- Tempo stimato
- 3-5 giorni
- Idoneità per principianti
- 25/100
- Tipo di issue
- Bug
- Chiarezza
- Specificata chiaramente
- Stato di attività
- Ferma
- Stack tecnologico
- php
- Ambito
- backend-api-design
Direzione di ricerca
Start with StreamableHttpTransport::createStreamedResponse() and the getPendingRequests() and checkForResponse() calls described in the issue; trace how yielded request IDs relate to each stream's fiber. Check linked pull request #556, which is already open. Done means concurrent streams on one session cannot consume or time out each other's responses.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Summary
On Streamable HTTP (handshake era, SSE), two tool calls on one session that both send a server-to-client request, such as elicitation/create, can each receive the other's answer.
Cause
Protocol keeps pending server-to-client requests in one session-wide list, _mcp.pending_requests. The SSE loop in StreamableHttpTransport::createStreamedResponse() walks that whole list, not only the requests its own fiber sent:
$pendingRequests = $this->getPendingRequests($this->sessionId);
// ...
foreach ($pendingRequests as $pending) {
$response = $this->checkForResponse($pending['request_id'], $this->sessionId);
if (null !== $response) {
$yielded = $this->sessionFiber->resume($response);
// ...
With tool calls A and B open on one session, each waiting in ClientGateway::elicit():
- The client answers B's elicitation.
- A's loop polls first, finds B's answer, consumes it, and resumes A's fiber with it. A's tool continues with B's answer.
- B's answer is gone from the session. B's tool waits until its 120-second timeout.
The timeout branch has the same problem: A's loop can resume A's fiber with a timeout error for B's request ID.
I found this by reading the source on main (a5ed85f) and 0.8.1. I have not reproduced it end to end. Running two streams on one session at the same time needs a server that doesn't serialize requests per session.
Suggested fix
Record which stream sent each pending request, and have each loop check only its own. For example, track the request IDs the fiber yielded in the transport instance, and filter getPendingRequests() by them.
Context
In Drupal's mcp_server we lock the session for the length of a stream. That lock made a second elicitation wait, which hid this bug. We're changing the lock to cover each session write instead of the whole stream, so elicitation answers don't wait on the lease (mcp_server!88). That makes this race reachable.
- Lingua principale
- PHP
- Stelle
- 1.6k
- Fork
- 177
- Merge medio
- 2g 16h
- PR unite (30g)
- 36
Preparare l'ambiente
- Nessun Dockerfile né file Docker Compose
- Nessun modello di pull request
- Leggi la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di modelcontextprotocol/php-sdk
-
[Server] Handler type uses bare Closure, hard to decorate RegistryInterface under strict PHPStanApertaServer
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 78/100
modelcontextprotocol/php-sdk#468 · 2 commenti ·
I maintainer di solito rispondono entro 1 giorno
-
Builder::build() silently skips configured file-based discovery when symfony/finder is missing — should fail loudlyForse già presa @ousamabenyounes l’ha presa 54 giorni fa. Apertaneeds confirmation needs maintainer action Server
Difficoltà 2/5 1-3 ore Idoneità per principianti 68/100
modelcontextprotocol/php-sdk#398 · 1 reazione ·
I maintainer di solito rispondono entro 1 giorno
-
enhancement
Difficoltà 2/5 1-3 ore Idoneità per principianti 68/100
modelcontextprotocol/php-sdk#370 ·
I maintainer di solito rispondono entro 1 giorno
-
enhancement
Difficoltà 4/5 3-5 giorni Idoneità per principianti 52/100
modelcontextprotocol/php-sdk#587 ·
I maintainer di solito rispondono entro 1 giorno
-
bug
Difficoltà 3/5 Mezza giornata Idoneità per principianti 60/100
modelcontextprotocol/php-sdk#586 · 2 commenti ·
I maintainer di solito rispondono entro 1 giorno
Tutte le issue di modelcontextprotocol/php-sdk
Issue simili
-
sync-en
Difficoltà 2/5 1-3 ore Idoneità per principianti 75/100
I maintainer di solito rispondono entro 1 giorno
-
sync-en
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
I maintainer di solito rispondono entro 4 giorni
-
Перевод устарел
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 85/100
-
bug
Difficoltà 2/5 Mezza giornata Idoneità per principianti 76/100
m3ue/m3u-editor#1604 ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 70/100
femiwiki/docker-mediawiki#1497 ·
I maintainer di solito rispondono entro 1 giorno