Hacktoberfest 2026:メンテナが10月に向けて印を付けた、オープンで初心者向けの issue。 Hacktoberfest の issue を見る

[Client] Expired HTTP sessions remain marked connected, including during cancellation

オープン
#559 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る

メンテナーはふだん 1 日以内に返信

@ineersa がすでに取り組んでいます。

2026年10月8日 から。

  • #560 @ineersa による — オープン

評価

難易度
4/5
見積もり時間
3〜5日
初心者へのやさしさ
25/100
issue の種類
バグ
明瞭さ
明確に書かれている
活発さ
停滞
技術スタック
php
領域
api

調査の方向性

Start with src/Client/Transport/HttpTransport.php at send() and trace how HTTP responses are handled, then read src/Client/Protocol.php at notifyCancellation() to understand why notification failures are caught. Done means a session-bound 404 invalidates the session even during cancellation, preserves the original cancellation or deadline exception, and allows a fresh connection without replaying the interrupted call.

索引モデルが issue の本文から書いたものです。

説明

bug

Describe the bug
Stateful Streamable HTTP session expiry is not correctly reflected in the PHP SDK’s connection state.

In the affected HttpTransport::send() implementation, HTTP status codes are not checked before processing or discarding the response body.

Consequently:

  • A session-bound HTTP 404 with an empty or plain-text body leaves the tool request waiting until timeout.
  • Client::isConnected() remains true, and subsequent requests continue using the expired session.
  • A 404 returned for notifications/cancelled is also discarded without invalidating the connection.

This concerns protocol revisions using Mcp-Session-Id, such as 2025-11-25.

To Reproduce

Ordinary tool request
  1. Initialize a connection to a stateful HTTP server and receive session ID S.
  2. Invalidate S on the server.
  3. Call a tool. The server returns HTTP 404 with an empty or plain-text body.
  4. Observe that the request waits until timeout and the client still reports itself connected.
  5. Make another call: it sends the same expired session ID.
Cancellation or deadline expiry
  1. Start a tool call using session S and leave its response pending.
  2. Invalidate the session, then cancel the call or let its deadline expire.
  3. The SDK sends notifications/cancelled with S; the server returns HTTP 404.
  4. The original call is interrupted, but the client remains marked connected despite its expired session.

Simply adding a ConnectionException for HTTP 404 is insufficient for the second case: Protocol::notifyCancellation() catches notification failures. Connection invalidation must persist independently of whether that exception reaches the caller.

Expected behavior

  • Recognize a 404 on a request carrying Mcp-Session-Id as session expiry.
  • Close the response body, clear the session ID, and mark the client uninitialized so isConnected() returns false.
  • Surface an ordinary request’s session expiry promptly as a connection failure.
  • Preserve the original cancellation/deadline exception when expiry is detected during the cancellation POST.
  • Allow a subsequent reconnect to initialize without the expired session ID.
  • Keep healthy connections reusable after cancellation or deadline expiry.

The 2025-11-25 specification, Session Management points 3–4, requires fresh initialization after a session-bound 404. It does not require automatically replaying the interrupted tool call.

Additional context

主要言語
PHP
スター
1.6k
フォーク
177
平均マージ
3日 1時間
マージ済み PR(30日)
27

環境構築

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

modelcontextprotocol/php-sdk のほかの issue

modelcontextprotocol/php-sdk の issue をすべて見る

似ている issue

PHP の issue をもっと見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。