fix: bound discovery time and response size - #16
Merged
TheGreatAxios merged 1 commit intoSep 27, 2026
Conversation
TheGreatAxios
added this pull request to stack #12
September 27, 2026 02:23
TheGreatAxios
force-pushed
the
cl-9452-mcp-bound-discovery-time-and-stream-size
branch
3 times, most recently
from
September 27, 2026 18:35
d47aa87 to
8cc585d
Compare
Discovery requests now time out after 30 seconds, covering the body read, and every client call takes an optional `timeoutMs` and `signal`. mcpTools and mcpServers bound initialize and tools/call at 60 seconds by default (their `timeoutMs` option) and honour the tool call's abort signal. A response body or SSE frame over 4 MiB is refused, and the reader is cancelled on overflow, on timeout and once the matching frame is read.
TheGreatAxios
force-pushed
the
cl-9452-mcp-bound-discovery-time-and-stream-size
branch
from
September 27, 2026 18:49
8cc585d to
56aec15
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
A tenant member could point discovery at a server that streams forever, so the route never returned, or sends one huge SSE frame (64 MB cost about 1.6 GB of RSS). The client also never cancelled the body after reading its frame. At run time,
mcpToolsand the sidecar bundle sentinitializeandtools/callwith no bound and ignored the tool call's abort signal, so a stalling server hung the agent's tool call.Changes
McpClientOptionsgainstimeoutMs. It covers the request and reading its body. Discovery (discoverMcpServer, and so the hub route) uses 30 seconds;discoverMcpServertakestimeoutMsto override it.McpClientOptionsalso gainssignal, which cancels the request and body read.mcpToolsandmcpServerstake atimeoutMsoption (60 seconds by default,DEFAULT_TIMEOUT_MS) forinitializeandtools/call, and pass each tool call's abort signal totools/call.McpError.discoverMcpServer, and a stallingtools/calltiming out and being cancelled through bothmcpToolsandmcpServers.timeoutMs,signal, the run-time default, the cap and the discovery timeout.Checks
bun run check,bun run buildand the Node pack smoke pass locally.Closes CL-9452