modelcontextprotocol / modelcontextprotocol/python-sdk
stdio_client crashes on malformed UTF-8 from child stdout instead of surfacing parse error
还没有人认领这个 Issue。
- 主要语言
- Python
- 星标
- 24.3k
- 派生
- 4k
- 平均合并
- 1 天 1 小时
- 30 天内合并 PR
- 31
描述
Summary
mcp.client.stdio.stdio_client() crashes when the spawned child process writes invalid UTF-8 bytes to stdout.
The transport currently decodes child stdout with encoding_error_handler="strict", so malformed bytes raise during TextReceiveStream(...) iteration. That exception escapes the decoding loop and brings down the transport task group instead of surfacing the bad line as an in-stream parse error.
Why this looks like a bug
The SDK already hardened the server side for the analogous case in PR #2302 (fix: handle non-UTF-8 bytes in stdio server stdin). That change explicitly preferred:
- replace invalid bytes with U+FFFD,
- let JSON validation fail on the malformed line, and
- keep the transport alive so subsequent valid messages can still be processed.
The client side still behaves asymmetrically today. A buggy or non-compliant child server can kill the Python client transport with a single malformed line even if the next line is valid JSON-RPC.
That seems inconsistent with the current stdio robustness direction.
Reproduction
A minimal child process that writes one malformed line and then one valid JSON-RPC line:
import sys
import time
sys.stdout.buffer.write(b"\xff\xfe\n")
sys.stdout.buffer.write(b'{"jsonrpc":"2.0","id":1,"method":"ping"}\n')
sys.stdout.buffer.flush()
time.sleep(0.2)
With current stdio_client(...) defaults, the transport raises ExceptionGroup instead of continuing.
Expected behavior
The malformed line should be surfaced as an in-stream parse / validation error, and the next valid JSON-RPC line should still be received.
Observed behavior
The transport task group fails before the valid follow-up message is delivered.
Proposed fix
Match the server-side approach from PR #2302:
- default
StdioServerParameters.encoding_error_handlerto"replace" - continue treating malformed decoded lines as JSON validation failures
- keep the background stdio tasks resilient during early subprocess shutdown / abrupt close
Validation
I reproduced this locally against current main and verified that a minimal patch plus a regression test fixes it.
A focused regression test in tests/client/test_stdio.py can assert:
- first item from the read stream is an
Exception - second item is the valid
SessionMessage
贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
调研方向
从 mcp.client.stdio.stdio_client() 和 tests/client/test_stdio.py 开始;检查 TextReceiveStream 解码和读取流迭代如何处理编码错误。添加 issue 中描述的 malformed-then-valid 回归测试,然后运行针对性测试,验证第一个项目是 Exception,第二个是有效的 SessionMessage,并且传输保持活动状态。
由索引模型根据 Issue 内容生成。
评估
- 技术栈
- python
- 领域
- backend, testing
- Issue 类型
- 缺陷
- 难度
- 3/5
- 预计耗时
- 1-2 天
- 活跃度
- 冷清
- 描述清晰度
- 描述清楚
- 新手友好度
- 78/100