Skip to content

fix: bound discovery time and response size - #16

Merged
TheGreatAxios merged 1 commit into
cl-9051-mcp-import-pinned-fetch-from-corbitscredential-httpfrom
cl-9452-mcp-bound-discovery-time-and-stream-size
Sep 27, 2026
Merged

TheGreatAxios merged 1 commit into
cl-9051-mcp-import-pinned-fetch-from-corbitscredential-httpfrom
cl-9452-mcp-bound-discovery-time-and-stream-size

Conversation

@TheGreatAxios

@TheGreatAxios TheGreatAxios commented Sep 27, 2026 •

Copy link
Copy Markdown
Contributor

A tenant member could point discovery at a server that streams forever, so the route never returned, or sends one huge SSE frame (64 MB cost about 1.6 GB of RSS). The client also never cancelled the body after reading its frame. At run time, mcpTools and the sidecar bundle sent initialize and tools/call with no bound and ignored the tool call's abort signal, so a stalling server hung the agent's tool call.

Changes

  • McpClientOptions gains timeoutMs. It covers the request and reading its body. Discovery (discoverMcpServer, and so the hub route) uses 30 seconds; discoverMcpServer takes timeoutMs to override it.
  • McpClientOptions also gains signal, which cancels the request and body read.
  • mcpTools and mcpServers take a timeoutMs option (60 seconds by default, DEFAULT_TIMEOUT_MS) for initialize and tools/call, and pass each tool call's abort signal to tools/call.
  • A JSON body or SSE frame (and the pending SSE buffer) over 4 MiB is refused with an McpError.
  • The body reader is cancelled on overflow, on timeout, on a non-2xx and once the matching frame is read.
  • Tests (each fails before the fix): an endless keep-alive stream, a stalled server, an oversized frame, an oversized JSON body, cancellation after the matching frame, a stalled server through discoverMcpServer, and a stalling tools/call timing out and being cancelled through both mcpTools and mcpServers.
  • README documents timeoutMs, signal, the run-time default, the cap and the discovery timeout.

Checks

bun run check, bun run build and the Node pack smoke pass locally.

Closes CL-9452

@TheGreatAxios
TheGreatAxios added this pull request to stack #12 September 27, 2026 02:23
@TheGreatAxios
TheGreatAxios force-pushed the cl-9452-mcp-bound-discovery-time-and-stream-size branch 3 times, most recently from d47aa87 to 8cc585d Compare September 27, 2026 18:35
Discovery requests now time out after 30 seconds, covering the body read,
and every client call takes an optional `timeoutMs` and `signal`. mcpTools
and mcpServers bound initialize and tools/call at 60 seconds by default
(their `timeoutMs` option) and honour the tool call's abort signal. A
response body or SSE frame over 4 MiB is refused, and the reader is
cancelled on overflow, on timeout and once the matching frame is read.
@TheGreatAxios
TheGreatAxios force-pushed the cl-9452-mcp-bound-discovery-time-and-stream-size branch from 8cc585d to 56aec15 Compare September 27, 2026 18:49
@TheGreatAxios
TheGreatAxios merged commit c40aa06 into main Sep 27, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant