modelcontextprotocol / modelcontextprotocol/python-sdk

RequestResponder.__exit__ leaks CancelledError on cancelled request, killing the stdio receive loop

Aberta
#2,610 3 comentários 0 reações 0 responsáveis Ver no GitHub

Ninguém assumiu esta issue ainda.

bug needs confirmation P2 potentially close
Linguagem predominante
Python
Estrelas
24.3k
Forks
4k
Merge médio
1d 1h
PRs com merge (30d)
31

Descrição

Summary

When a client sends notifications/cancelled for an in-flight request handled over stdio, the server's receive loop task group dies. The process stays alive but stops reading stdin, so every subsequent request hangs and the client eventually reports MCP error -32000: Connection closed. The bug is racy — it reproduces in roughly 40–80% of attempts depending on platform timing.

Affects: mcp 1.26.0 and 1.27.1 (latest at time of writing). Confirmed with FastMCP 3.1.x and the in-tree stdio server.

Reproduction

A standalone subprocess test is in mlorentedev/hive tests/test_transport_recovery.py. The relevant flow:

  1. initialize → ack
  2. notifications/initialized
  3. tools/call id=2
  4. notifications/cancelled for requestId=2 (within a few ms of step 3)
  5. Receive: {"id": 2, "error": {"code": 0, "message": "Request cancelled"}} ← OK
  6. tools/call id=3
  7. No response. Server is alive but proc.stdout.readline() hangs.

Root cause

mcp.shared.session.RequestResponder.__exit__:

def __exit__(self, exc_type, exc_val, exc_tb):
    try:
        if self._completed:
            self._on_complete(self)
    finally:
        self._entered = False
        ...
        self._cancel_scope.__exit__(exc_type, exc_val, exc_tb)  # ← (A)

When notifications/cancelled arrives, RequestResponder.cancel() calls self._cancel_scope.cancel() and sends the error response. The handler task catches the CancelledError in mcp/server/lowlevel/server.py (around line 766) and returns. The with responder: block then exits with exc_type=None while the cancel scope is still in cancelled state — at line (A), anyio's CancelScope.__exit__ re-raises CancelledError.

That exception bubbles up to:

async with anyio.create_task_group() as tg:
    async for message in session.incoming_messages:
        tg.start_soon(self._handle_message, ...)

…in Server._run. anyio task groups cancel all sibling tasks and propagate the cancellation. The receive loop is one of those sibling tasks, so it dies.

Suggested fix

Swallow the spurious cancellation when the responder has already sent its response:

def __exit__(self, exc_type, exc_val, exc_tb):
    try:
        if self._completed:
            self._on_complete(self)
    finally:
        self._entered = False
        if not self._cancel_scope:
            raise RuntimeError("No active cancel scope")
        try:
            self._cancel_scope.__exit__(exc_type, exc_val, exc_tb)
        except BaseException as exc:
            if self._completed and isinstance(exc, anyio.get_cancelled_exc_class()):
                # cancel() already sent the error response — the scope's
                # re-raised cancellation is spurious.
                return
            raise

Mirrors what we ship in hive src/hive/_compat.py.

Workaround used downstream

We monkey-patch RequestResponder.__exit__ at import time. The patch is self-gated (only fires when _completed=True AND the leaking exception is anyio.get_cancelled_exc_class()), so it stays inert once a fix lands upstream.

Environment

  • Reproduced on Windows 11 (mcp 1.26.0, 1.27.1) and via Claude Code as the host.
  • Tracked downstream in mlorentedev/hive#75.
  • Regression test passes 5/5 with the patch applied on Python 3.12; fails 2/5 — 4/5 without it.
  • Python 3.13 appears to have additional uncancel semantics that the patch does not yet fully cover — verification in progress.

Guia de contribuição

Abrir o guia de contribuição

Primeiros passos

  1. Leia a issue inteira e depois o guia de contribuição do projeto.
  2. Comente na issue dizendo que vai assumir — evita que duas pessoas façam o mesmo trabalho.
  3. Faça um fork do repositório e trabalhe em uma branch.
  4. Abra um pull request que referencie o número da issue.

Direção de pesquisa

Comece em mcp.shared.session.RequestResponder.exit e inspecione o tratamento de cancelamento em torno de mcp/server/lowlevel/server.py, próximo à linha 766. Reproduza com tests/test_transport_recovery.py e, em seguida, verifique se cancelar uma solicitação stdio ainda produz sua resposta de erro e se uma solicitação subsequente recebe uma resposta sem que o loop de recebimento pare.

Escrita pelo modelo de indexação a partir do texto da issue.

Avaliação

Stack de tecnologia
python
Domínio
api, backend
Tipo de issue
Bug
Dificuldade
3/5
Tempo estimado
1-2 dias
Status de atividade
Pouca atividade
Clareza
Claramente especificada
Facilidade para iniciantes
68/100

Receba novas issues na sua caixa de entrada

Um resumo curto de issues do GitHub para quem está começando.