fix(core): use sessionId for MCP transport correlation - #19172

Merged
betegon merged 16 commits into
developfrom
bete/fix/mcp-wrapper-transport-correlation
Feb 10, 2026
Merged

fix(core): use sessionId for MCP transport correlation#19172
betegon merged 16 commits into
developfrom
bete/fix/mcp-wrapper-transport-correlation

Conversation

@betegon

Copy link
Copy Markdown
Member

Summary

Fixes MCP server instrumentation not recording events for wrapper transport patterns (like NodeStreamableHTTPServerTransport which wraps WebStandardStreamableHTTPServerTransport).

The root cause: wrapper transports proxy onmessage/send via getters/setters, causing different this values. The previous WeakMap<transport, ...> correlation couldn't match requests to responses. This changes to Map<sessionId, ...> correlation which works regardless of transport object reference.

Changes

  • Changed correlation.ts to use sessionId-based Maps instead of transport-based WeakMaps
  • Changed sessionManagement.ts to use sessionId-based session lookup
  • Added unit tests with mock wrapper transport utility
  • Added E2E tests for StreamableHTTP transport across node-express, node-express-v5, and tsx-express

Test Plan

  • Unit tests: cd packages/core && yarn test (2010 tests pass)
  • E2E tests: All pass
    • node-express: 14/14
    • node-express-v5: 12/12
    • tsx-express: 10/10

  • If you've added code that should be tested, please add tests.
  • Ensure your code lints and the test suite passes (yarn lint) & (yarn test).
  • Link an issue if there is one related to your pull request. If no issue is linked, one will be auto-generated and linked.

Closes#19233

Thanks @gotenxds for reporting and debugging this issue!

…n spans
This introduces `recordInputs` and `recordOutputs` options to the MCP server wrapper and related functions, allowing for more granular control over the data captured in spans.
Wrapper transports (like NodeStreamableHTTPServerTransport wrapping
WebStandardStreamableHTTPServerTransport) proxy onmessage/send via
getters/setters, causing different 'this' values in each callback.
This changes correlation from WeakMap<transport> to Map<sessionId>
to correctly correlate requests with responses regardless of which
transport object reference is used.
Reported-by: @gotenxds
Add mock wrapper transport utility and tests verifying that
instrumentation correctly handles transports that proxy onmessage/send
via getters/setters (common pattern with StreamableHTTP transports).
Add E2E tests for MCP StreamableHTTP transport across node-express,
node-express-v5, and tsx-express test applications. Tests verify that
transactions are recorded correctly for the wrapper transport pattern
used by NodeStreamableHTTPServerTransport.
@github-actions

github-actionsBot commented Feb 4, 2026

Copy link
Copy Markdown
Contributor

Codecov Results 📊


Generated by Codecov Action

@github-actions

Copy link
Copy Markdown
Contributor

Codecov Results 📊

23 passed | ⏭️ 7 skipped | Total: 30 | Pass Rate: 76.67% | Execution Time: 10.04s

All tests are passing successfully.


Generated by Codecov Action

@github-actions

github-actionsBot commented Feb 4, 2026

Copy link
Copy Markdown
Contributor

node-overhead report 🧳

Note: This is a synthetic benchmark with a minimal express app and does not necessarily reflect the real-world performance impact in an application.

ScenarioRequests/s% of BaselinePrev. Requests/sChange %
GET Baseline9,142-8,968+2%
GET With Sentry1,74319%1,736+0%
GET With Sentry (error only)6,17868%6,029+2%
POST Baseline1,201-1,202-0%
POST With Sentry58148%585-1%
POST With Sentry (error only)1,03586%1,062-3%
MYSQL Baseline3,308-3,277+1%
MYSQL With Sentry46214%500-8%
MYSQL With Sentry (error only)2,70782%2,659+2%

View base workflow run

@betegon
betegon marked this pull request as ready for review February 9, 2026 13:00

@cursorcursorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Bugbot Autofix is OFF. To automatically fix reported issues with Cloud Agents, enable Autofix in the Cursor dashboard.

* different transport objects share the same logical session
*/
const transportToSpanMap = new WeakMap<MCPTransport, Map<RequestId, RequestSpanMapValue>>();
const sessionToSpanMap = new Map<string, Map<RequestId, RequestSpanMapValue>>();

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Module-level Maps leak memory without transport close

Medium Severity

sessionToSpanMap and sessionToSessionData are module-level Map<string, ...> instances whose entries are only removed via explicit delete calls in cleanupPendingSpansForTransport / cleanupSessionDataForTransport, which are solely triggered by the transport's onclose handler. If a transport is abandoned without onclose firing (e.g., unclean disconnect), entries accumulate indefinitely. The previous WeakMap<MCPTransport, ...> approach provided automatic GC-based cleanup as a safety net, which this change loses for stateful transports.

Additional Locations (1)

Fix in CursorFix in Web

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

acknowledged, intentional.

So this would happen if somehow the mcp server skips onClose when closing a connection, and it shouldn't happen.

  1. the only way to skip onclose is a process crash (where memory is freed anyway) or a genuine bug in user code where they abandon a transport without closing it
  2. the MCP server.close() calls close() on all connected transports, which triggers onclose
  3. HTTP connection drops trigger onclose in the transport implementation
  4. SSE disconnects trigger onclose

This is a normal flow as per MCP docs:

1. Transport created (sessionId assigned)
2. server.connect(transport) → we wrap onmessage/send/onclose
3. Messages flow:
- onmessage: stores span in sessionToSpanMap[sessionId][requestId]
- send: looks up span in sessionToSpanMap[sessionId][requestId], ends it, deletes entry
4. Transport closes:
- onclose fires
- cleanupPendingSpansForTransport(): ends any orphan spans, calls sessionToSpanMap.delete(sessionId)
- cleanupSessionDataForTransport(): calls sessionToSessionData.delete(sessionId)
5. Maps are now clean for that sessionId

So everything is cleaned up.

@betegon
betegon requested a review from JPeer264February 9, 2026 13:21
@betegonbetegon self-assigned this Feb 9, 2026

@JPeer264JPeer264 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM.

@betegon
betegon merged commit 389ab1f into developFeb 10, 2026
219 checks passed
@betegon
betegon deleted the bete/fix/mcp-wrapper-transport-correlation branch February 10, 2026 12:36
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

MCP server aint recording events - req/res transport issue

2 participants

@betegon@JPeer264
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

fix(core): use sessionId for MCP transport correlation - #19172

Merged
betegon merged 16 commits into
developfrom
bete/fix/mcp-wrapper-transport-correlation
Feb 10, 2026
Merged

fix(core): use sessionId for MCP transport correlation#19172
betegon merged 16 commits into
developfrom
bete/fix/mcp-wrapper-transport-correlation

Conversation

@betegon

Copy link
Copy Markdown
Member

Summary

Fixes MCP server instrumentation not recording events for wrapper transport patterns (like NodeStreamableHTTPServerTransport which wraps WebStandardStreamableHTTPServerTransport).

The root cause: wrapper transports proxy onmessage/send via getters/setters, causing different this values. The previous WeakMap<transport, ...> correlation couldn't match requests to responses. This changes to Map<sessionId, ...> correlation which works regardless of transport object reference.

Changes

  • Changed correlation.ts to use sessionId-based Maps instead of transport-based WeakMaps
  • Changed sessionManagement.ts to use sessionId-based session lookup
  • Added unit tests with mock wrapper transport utility
  • Added E2E tests for StreamableHTTP transport across node-express, node-express-v5, and tsx-express

Test Plan

  • Unit tests: cd packages/core && yarn test (2010 tests pass)
  • E2E tests: All pass
    • node-express: 14/14
    • node-express-v5: 12/12
    • tsx-express: 10/10

  • If you've added code that should be tested, please add tests.
  • Ensure your code lints and the test suite passes (yarn lint) & (yarn test).
  • Link an issue if there is one related to your pull request. If no issue is linked, one will be auto-generated and linked.

Closes#19233

Thanks @gotenxds for reporting and debugging this issue!

…n spans
This introduces `recordInputs` and `recordOutputs` options to the MCP server wrapper and related functions, allowing for more granular control over the data captured in spans.
Wrapper transports (like NodeStreamableHTTPServerTransport wrapping
WebStandardStreamableHTTPServerTransport) proxy onmessage/send via
getters/setters, causing different 'this' values in each callback.
This changes correlation from WeakMap<transport> to Map<sessionId>
to correctly correlate requests with responses regardless of which
transport object reference is used.
Reported-by: @gotenxds
Add mock wrapper transport utility and tests verifying that
instrumentation correctly handles transports that proxy onmessage/send
via getters/setters (common pattern with StreamableHTTP transports).
Add E2E tests for MCP StreamableHTTP transport across node-express,
node-express-v5, and tsx-express test applications. Tests verify that
transactions are recorded correctly for the wrapper transport pattern
used by NodeStreamableHTTPServerTransport.
@github-actions

github-actionsBot commented Feb 4, 2026

Copy link
Copy Markdown
Contributor

Codecov Results 📊


Generated by Codecov Action

@github-actions

Copy link
Copy Markdown
Contributor

Codecov Results 📊

23 passed | ⏭️ 7 skipped | Total: 30 | Pass Rate: 76.67% | Execution Time: 10.04s

All tests are passing successfully.


Generated by Codecov Action

@github-actions

github-actionsBot commented Feb 4, 2026

Copy link
Copy Markdown
Contributor

node-overhead report 🧳

Note: This is a synthetic benchmark with a minimal express app and does not necessarily reflect the real-world performance impact in an application.

ScenarioRequests/s% of BaselinePrev. Requests/sChange %
GET Baseline9,142-8,968+2%
GET With Sentry1,74319%1,736+0%
GET With Sentry (error only)6,17868%6,029+2%
POST Baseline1,201-1,202-0%
POST With Sentry58148%585-1%
POST With Sentry (error only)1,03586%1,062-3%
MYSQL Baseline3,308-3,277+1%
MYSQL With Sentry46214%500-8%
MYSQL With Sentry (error only)2,70782%2,659+2%

View base workflow run

@betegon
betegon marked this pull request as ready for review February 9, 2026 13:00

@cursorcursorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Bugbot Autofix is OFF. To automatically fix reported issues with Cloud Agents, enable Autofix in the Cursor dashboard.

* different transport objects share the same logical session
*/
const transportToSpanMap = new WeakMap<MCPTransport, Map<RequestId, RequestSpanMapValue>>();
const sessionToSpanMap = new Map<string, Map<RequestId, RequestSpanMapValue>>();

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Module-level Maps leak memory without transport close

Medium Severity

sessionToSpanMap and sessionToSessionData are module-level Map<string, ...> instances whose entries are only removed via explicit delete calls in cleanupPendingSpansForTransport / cleanupSessionDataForTransport, which are solely triggered by the transport's onclose handler. If a transport is abandoned without onclose firing (e.g., unclean disconnect), entries accumulate indefinitely. The previous WeakMap<MCPTransport, ...> approach provided automatic GC-based cleanup as a safety net, which this change loses for stateful transports.

Additional Locations (1)

Fix in CursorFix in Web

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

acknowledged, intentional.

So this would happen if somehow the mcp server skips onClose when closing a connection, and it shouldn't happen.

  1. the only way to skip onclose is a process crash (where memory is freed anyway) or a genuine bug in user code where they abandon a transport without closing it
  2. the MCP server.close() calls close() on all connected transports, which triggers onclose
  3. HTTP connection drops trigger onclose in the transport implementation
  4. SSE disconnects trigger onclose

This is a normal flow as per MCP docs:

1. Transport created (sessionId assigned)
2. server.connect(transport) → we wrap onmessage/send/onclose
3. Messages flow:
- onmessage: stores span in sessionToSpanMap[sessionId][requestId]
- send: looks up span in sessionToSpanMap[sessionId][requestId], ends it, deletes entry
4. Transport closes:
- onclose fires
- cleanupPendingSpansForTransport(): ends any orphan spans, calls sessionToSpanMap.delete(sessionId)
- cleanupSessionDataForTransport(): calls sessionToSessionData.delete(sessionId)
5. Maps are now clean for that sessionId

So everything is cleaned up.

@betegon
betegon requested a review from JPeer264February 9, 2026 13:21
@betegonbetegon self-assigned this Feb 9, 2026

@JPeer264JPeer264 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM.

@betegon
betegon merged commit 389ab1f into developFeb 10, 2026
219 checks passed
@betegon
betegon deleted the bete/fix/mcp-wrapper-transport-correlation branch February 10, 2026 12:36
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

MCP server aint recording events - req/res transport issue

2 participants

@betegon@JPeer264
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(core): use sessionId for MCP transport correlation - #19172

Merged
betegon merged 16 commits into
developfrom
bete/fix/mcp-wrapper-transport-correlation
Feb 10, 2026
Merged

fix(core): use sessionId for MCP transport correlation#19172
betegon merged 16 commits into
developfrom
bete/fix/mcp-wrapper-transport-correlation

Conversation

@betegon

Copy link
Copy Markdown
Member

Summary

Fixes MCP server instrumentation not recording events for wrapper transport patterns (like NodeStreamableHTTPServerTransport which wraps WebStandardStreamableHTTPServerTransport).

The root cause: wrapper transports proxy onmessage/send via getters/setters, causing different this values. The previous WeakMap<transport, ...> correlation couldn't match requests to responses. This changes to Map<sessionId, ...> correlation which works regardless of transport object reference.

Changes

  • Changed correlation.ts to use sessionId-based Maps instead of transport-based WeakMaps
  • Changed sessionManagement.ts to use sessionId-based session lookup
  • Added unit tests with mock wrapper transport utility
  • Added E2E tests for StreamableHTTP transport across node-express, node-express-v5, and tsx-express

Test Plan

  • Unit tests: cd packages/core && yarn test (2010 tests pass)
  • E2E tests: All pass
    • node-express: 14/14
    • node-express-v5: 12/12
    • tsx-express: 10/10

  • If you've added code that should be tested, please add tests.
  • Ensure your code lints and the test suite passes (yarn lint) & (yarn test).
  • Link an issue if there is one related to your pull request. If no issue is linked, one will be auto-generated and linked.

Closes#19233

Thanks @gotenxds for reporting and debugging this issue!

…n spans
This introduces `recordInputs` and `recordOutputs` options to the MCP server wrapper and related functions, allowing for more granular control over the data captured in spans.
Wrapper transports (like NodeStreamableHTTPServerTransport wrapping
WebStandardStreamableHTTPServerTransport) proxy onmessage/send via
getters/setters, causing different 'this' values in each callback.
This changes correlation from WeakMap<transport> to Map<sessionId>
to correctly correlate requests with responses regardless of which
transport object reference is used.
Reported-by: @gotenxds
Add mock wrapper transport utility and tests verifying that
instrumentation correctly handles transports that proxy onmessage/send
via getters/setters (common pattern with StreamableHTTP transports).
Add E2E tests for MCP StreamableHTTP transport across node-express,
node-express-v5, and tsx-express test applications. Tests verify that
transactions are recorded correctly for the wrapper transport pattern
used by NodeStreamableHTTPServerTransport.
@github-actions

github-actionsBot commented Feb 4, 2026

Copy link
Copy Markdown
Contributor

Codecov Results 📊


Generated by Codecov Action

@github-actions

Copy link
Copy Markdown
Contributor

Codecov Results 📊

23 passed | ⏭️ 7 skipped | Total: 30 | Pass Rate: 76.67% | Execution Time: 10.04s

All tests are passing successfully.


Generated by Codecov Action

@github-actions

github-actionsBot commented Feb 4, 2026

Copy link
Copy Markdown
Contributor

node-overhead report 🧳

Note: This is a synthetic benchmark with a minimal express app and does not necessarily reflect the real-world performance impact in an application.

ScenarioRequests/s% of BaselinePrev. Requests/sChange %
GET Baseline9,142-8,968+2%
GET With Sentry1,74319%1,736+0%
GET With Sentry (error only)6,17868%6,029+2%
POST Baseline1,201-1,202-0%
POST With Sentry58148%585-1%
POST With Sentry (error only)1,03586%1,062-3%
MYSQL Baseline3,308-3,277+1%
MYSQL With Sentry46214%500-8%
MYSQL With Sentry (error only)2,70782%2,659+2%

View base workflow run

@betegon
betegon marked this pull request as ready for review February 9, 2026 13:00

@cursorcursorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Bugbot Autofix is OFF. To automatically fix reported issues with Cloud Agents, enable Autofix in the Cursor dashboard.

* different transport objects share the same logical session
*/
const transportToSpanMap = new WeakMap<MCPTransport, Map<RequestId, RequestSpanMapValue>>();
const sessionToSpanMap = new Map<string, Map<RequestId, RequestSpanMapValue>>();

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Module-level Maps leak memory without transport close

Medium Severity

sessionToSpanMap and sessionToSessionData are module-level Map<string, ...> instances whose entries are only removed via explicit delete calls in cleanupPendingSpansForTransport / cleanupSessionDataForTransport, which are solely triggered by the transport's onclose handler. If a transport is abandoned without onclose firing (e.g., unclean disconnect), entries accumulate indefinitely. The previous WeakMap<MCPTransport, ...> approach provided automatic GC-based cleanup as a safety net, which this change loses for stateful transports.

Additional Locations (1)

Fix in CursorFix in Web

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

acknowledged, intentional.

So this would happen if somehow the mcp server skips onClose when closing a connection, and it shouldn't happen.

  1. the only way to skip onclose is a process crash (where memory is freed anyway) or a genuine bug in user code where they abandon a transport without closing it
  2. the MCP server.close() calls close() on all connected transports, which triggers onclose
  3. HTTP connection drops trigger onclose in the transport implementation
  4. SSE disconnects trigger onclose

This is a normal flow as per MCP docs:

1. Transport created (sessionId assigned)
2. server.connect(transport) → we wrap onmessage/send/onclose
3. Messages flow:
- onmessage: stores span in sessionToSpanMap[sessionId][requestId]
- send: looks up span in sessionToSpanMap[sessionId][requestId], ends it, deletes entry
4. Transport closes:
- onclose fires
- cleanupPendingSpansForTransport(): ends any orphan spans, calls sessionToSpanMap.delete(sessionId)
- cleanupSessionDataForTransport(): calls sessionToSessionData.delete(sessionId)
5. Maps are now clean for that sessionId

So everything is cleaned up.

@betegon
betegon requested a review from JPeer264February 9, 2026 13:21
@betegonbetegon self-assigned this Feb 9, 2026

@JPeer264JPeer264 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM.

@betegon
betegon merged commit 389ab1f into developFeb 10, 2026
219 checks passed
@betegon
betegon deleted the bete/fix/mcp-wrapper-transport-correlation branch February 10, 2026 12:36
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

MCP server aint recording events - req/res transport issue

2 participants

@betegon@JPeer264
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(core): use sessionId for MCP transport correlation - #19172

Merged
betegon merged 16 commits into
developfrom
bete/fix/mcp-wrapper-transport-correlation
Feb 10, 2026
Merged

fix(core): use sessionId for MCP transport correlation#19172
betegon merged 16 commits into
developfrom
bete/fix/mcp-wrapper-transport-correlation

Conversation

@betegon

Copy link
Copy Markdown
Member

Summary

Fixes MCP server instrumentation not recording events for wrapper transport patterns (like NodeStreamableHTTPServerTransport which wraps WebStandardStreamableHTTPServerTransport).

The root cause: wrapper transports proxy onmessage/send via getters/setters, causing different this values. The previous WeakMap<transport, ...> correlation couldn't match requests to responses. This changes to Map<sessionId, ...> correlation which works regardless of transport object reference.

Changes

  • Changed correlation.ts to use sessionId-based Maps instead of transport-based WeakMaps
  • Changed sessionManagement.ts to use sessionId-based session lookup
  • Added unit tests with mock wrapper transport utility
  • Added E2E tests for StreamableHTTP transport across node-express, node-express-v5, and tsx-express

Test Plan

  • Unit tests: cd packages/core && yarn test (2010 tests pass)
  • E2E tests: All pass
    • node-express: 14/14
    • node-express-v5: 12/12
    • tsx-express: 10/10

  • If you've added code that should be tested, please add tests.
  • Ensure your code lints and the test suite passes (yarn lint) & (yarn test).
  • Link an issue if there is one related to your pull request. If no issue is linked, one will be auto-generated and linked.

Closes#19233

Thanks @gotenxds for reporting and debugging this issue!

…n spans
This introduces `recordInputs` and `recordOutputs` options to the MCP server wrapper and related functions, allowing for more granular control over the data captured in spans.
Wrapper transports (like NodeStreamableHTTPServerTransport wrapping
WebStandardStreamableHTTPServerTransport) proxy onmessage/send via
getters/setters, causing different 'this' values in each callback.
This changes correlation from WeakMap<transport> to Map<sessionId>
to correctly correlate requests with responses regardless of which
transport object reference is used.
Reported-by: @gotenxds
Add mock wrapper transport utility and tests verifying that
instrumentation correctly handles transports that proxy onmessage/send
via getters/setters (common pattern with StreamableHTTP transports).
Add E2E tests for MCP StreamableHTTP transport across node-express,
node-express-v5, and tsx-express test applications. Tests verify that
transactions are recorded correctly for the wrapper transport pattern
used by NodeStreamableHTTPServerTransport.
@github-actions

github-actionsBot commented Feb 4, 2026

Copy link
Copy Markdown
Contributor

Codecov Results 📊


Generated by Codecov Action

@github-actions

Copy link
Copy Markdown
Contributor

Codecov Results 📊

23 passed | ⏭️ 7 skipped | Total: 30 | Pass Rate: 76.67% | Execution Time: 10.04s

All tests are passing successfully.


Generated by Codecov Action

@github-actions

github-actionsBot commented Feb 4, 2026

Copy link
Copy Markdown
Contributor

node-overhead report 🧳

Note: This is a synthetic benchmark with a minimal express app and does not necessarily reflect the real-world performance impact in an application.

ScenarioRequests/s% of BaselinePrev. Requests/sChange %
GET Baseline9,142-8,968+2%
GET With Sentry1,74319%1,736+0%
GET With Sentry (error only)6,17868%6,029+2%
POST Baseline1,201-1,202-0%
POST With Sentry58148%585-1%
POST With Sentry (error only)1,03586%1,062-3%
MYSQL Baseline3,308-3,277+1%
MYSQL With Sentry46214%500-8%
MYSQL With Sentry (error only)2,70782%2,659+2%

View base workflow run

@betegon
betegon marked this pull request as ready for review February 9, 2026 13:00

@cursorcursorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Bugbot Autofix is OFF. To automatically fix reported issues with Cloud Agents, enable Autofix in the Cursor dashboard.

* different transport objects share the same logical session
*/
const transportToSpanMap = new WeakMap<MCPTransport, Map<RequestId, RequestSpanMapValue>>();
const sessionToSpanMap = new Map<string, Map<RequestId, RequestSpanMapValue>>();

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Module-level Maps leak memory without transport close

Medium Severity

sessionToSpanMap and sessionToSessionData are module-level Map<string, ...> instances whose entries are only removed via explicit delete calls in cleanupPendingSpansForTransport / cleanupSessionDataForTransport, which are solely triggered by the transport's onclose handler. If a transport is abandoned without onclose firing (e.g., unclean disconnect), entries accumulate indefinitely. The previous WeakMap<MCPTransport, ...> approach provided automatic GC-based cleanup as a safety net, which this change loses for stateful transports.

Additional Locations (1)

Fix in CursorFix in Web

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

acknowledged, intentional.

So this would happen if somehow the mcp server skips onClose when closing a connection, and it shouldn't happen.

  1. the only way to skip onclose is a process crash (where memory is freed anyway) or a genuine bug in user code where they abandon a transport without closing it
  2. the MCP server.close() calls close() on all connected transports, which triggers onclose
  3. HTTP connection drops trigger onclose in the transport implementation
  4. SSE disconnects trigger onclose

This is a normal flow as per MCP docs:

1. Transport created (sessionId assigned)
2. server.connect(transport) → we wrap onmessage/send/onclose
3. Messages flow:
- onmessage: stores span in sessionToSpanMap[sessionId][requestId]
- send: looks up span in sessionToSpanMap[sessionId][requestId], ends it, deletes entry
4. Transport closes:
- onclose fires
- cleanupPendingSpansForTransport(): ends any orphan spans, calls sessionToSpanMap.delete(sessionId)
- cleanupSessionDataForTransport(): calls sessionToSessionData.delete(sessionId)
5. Maps are now clean for that sessionId

So everything is cleaned up.

@betegon
betegon requested a review from JPeer264February 9, 2026 13:21
@betegonbetegon self-assigned this Feb 9, 2026

@JPeer264JPeer264 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM.

@betegon
betegon merged commit 389ab1f into developFeb 10, 2026
219 checks passed
@betegon
betegon deleted the bete/fix/mcp-wrapper-transport-correlation branch February 10, 2026 12:36
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

MCP server aint recording events - req/res transport issue

2 participants

@betegon@JPeer264
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

fix(core): use sessionId for MCP transport correlation - #19172

Merged
betegon merged 16 commits into
developfrom
bete/fix/mcp-wrapper-transport-correlation
Feb 10, 2026
Merged

fix(core): use sessionId for MCP transport correlation#19172
betegon merged 16 commits into
developfrom
bete/fix/mcp-wrapper-transport-correlation

Conversation

@betegon

Copy link
Copy Markdown
Member

Summary

Fixes MCP server instrumentation not recording events for wrapper transport patterns (like NodeStreamableHTTPServerTransport which wraps WebStandardStreamableHTTPServerTransport).

The root cause: wrapper transports proxy onmessage/send via getters/setters, causing different this values. The previous WeakMap<transport, ...> correlation couldn't match requests to responses. This changes to Map<sessionId, ...> correlation which works regardless of transport object reference.

Changes

  • Changed correlation.ts to use sessionId-based Maps instead of transport-based WeakMaps
  • Changed sessionManagement.ts to use sessionId-based session lookup
  • Added unit tests with mock wrapper transport utility
  • Added E2E tests for StreamableHTTP transport across node-express, node-express-v5, and tsx-express

Test Plan

  • Unit tests: cd packages/core && yarn test (2010 tests pass)
  • E2E tests: All pass
    • node-express: 14/14
    • node-express-v5: 12/12
    • tsx-express: 10/10

  • If you've added code that should be tested, please add tests.
  • Ensure your code lints and the test suite passes (yarn lint) & (yarn test).
  • Link an issue if there is one related to your pull request. If no issue is linked, one will be auto-generated and linked.

Closes#19233

Thanks @gotenxds for reporting and debugging this issue!

…n spans
This introduces `recordInputs` and `recordOutputs` options to the MCP server wrapper and related functions, allowing for more granular control over the data captured in spans.
Wrapper transports (like NodeStreamableHTTPServerTransport wrapping
WebStandardStreamableHTTPServerTransport) proxy onmessage/send via
getters/setters, causing different 'this' values in each callback.
This changes correlation from WeakMap<transport> to Map<sessionId>
to correctly correlate requests with responses regardless of which
transport object reference is used.
Reported-by: @gotenxds
Add mock wrapper transport utility and tests verifying that
instrumentation correctly handles transports that proxy onmessage/send
via getters/setters (common pattern with StreamableHTTP transports).
Add E2E tests for MCP StreamableHTTP transport across node-express,
node-express-v5, and tsx-express test applications. Tests verify that
transactions are recorded correctly for the wrapper transport pattern
used by NodeStreamableHTTPServerTransport.
@github-actions

github-actionsBot commented Feb 4, 2026

Copy link
Copy Markdown
Contributor

Codecov Results 📊


Generated by Codecov Action

@github-actions

Copy link
Copy Markdown
Contributor

Codecov Results 📊

23 passed | ⏭️ 7 skipped | Total: 30 | Pass Rate: 76.67% | Execution Time: 10.04s

All tests are passing successfully.


Generated by Codecov Action

@github-actions

github-actionsBot commented Feb 4, 2026

Copy link
Copy Markdown
Contributor

node-overhead report 🧳

Note: This is a synthetic benchmark with a minimal express app and does not necessarily reflect the real-world performance impact in an application.

ScenarioRequests/s% of BaselinePrev. Requests/sChange %
GET Baseline9,142-8,968+2%
GET With Sentry1,74319%1,736+0%
GET With Sentry (error only)6,17868%6,029+2%
POST Baseline1,201-1,202-0%
POST With Sentry58148%585-1%
POST With Sentry (error only)1,03586%1,062-3%
MYSQL Baseline3,308-3,277+1%
MYSQL With Sentry46214%500-8%
MYSQL With Sentry (error only)2,70782%2,659+2%

View base workflow run

@betegon
betegon marked this pull request as ready for review February 9, 2026 13:00

@cursorcursorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Bugbot Autofix is OFF. To automatically fix reported issues with Cloud Agents, enable Autofix in the Cursor dashboard.

* different transport objects share the same logical session
*/
const transportToSpanMap = new WeakMap<MCPTransport, Map<RequestId, RequestSpanMapValue>>();
const sessionToSpanMap = new Map<string, Map<RequestId, RequestSpanMapValue>>();

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Module-level Maps leak memory without transport close

Medium Severity

sessionToSpanMap and sessionToSessionData are module-level Map<string, ...> instances whose entries are only removed via explicit delete calls in cleanupPendingSpansForTransport / cleanupSessionDataForTransport, which are solely triggered by the transport's onclose handler. If a transport is abandoned without onclose firing (e.g., unclean disconnect), entries accumulate indefinitely. The previous WeakMap<MCPTransport, ...> approach provided automatic GC-based cleanup as a safety net, which this change loses for stateful transports.

Additional Locations (1)

Fix in CursorFix in Web

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

acknowledged, intentional.

So this would happen if somehow the mcp server skips onClose when closing a connection, and it shouldn't happen.

  1. the only way to skip onclose is a process crash (where memory is freed anyway) or a genuine bug in user code where they abandon a transport without closing it
  2. the MCP server.close() calls close() on all connected transports, which triggers onclose
  3. HTTP connection drops trigger onclose in the transport implementation
  4. SSE disconnects trigger onclose

This is a normal flow as per MCP docs:

1. Transport created (sessionId assigned)
2. server.connect(transport) → we wrap onmessage/send/onclose
3. Messages flow:
- onmessage: stores span in sessionToSpanMap[sessionId][requestId]
- send: looks up span in sessionToSpanMap[sessionId][requestId], ends it, deletes entry
4. Transport closes:
- onclose fires
- cleanupPendingSpansForTransport(): ends any orphan spans, calls sessionToSpanMap.delete(sessionId)
- cleanupSessionDataForTransport(): calls sessionToSessionData.delete(sessionId)
5. Maps are now clean for that sessionId

So everything is cleaned up.

@betegon
betegon requested a review from JPeer264February 9, 2026 13:21
@betegonbetegon self-assigned this Feb 9, 2026

@JPeer264JPeer264 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM.

@betegon
betegon merged commit 389ab1f into developFeb 10, 2026
219 checks passed
@betegon
betegon deleted the bete/fix/mcp-wrapper-transport-correlation branch February 10, 2026 12:36
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

MCP server aint recording events - req/res transport issue

2 participants

@betegon@JPeer264
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(core): use sessionId for MCP transport correlation - #19172

Merged
betegon merged 16 commits into
developfrom
bete/fix/mcp-wrapper-transport-correlation
Feb 10, 2026
Merged

fix(core): use sessionId for MCP transport correlation#19172
betegon merged 16 commits into
developfrom
bete/fix/mcp-wrapper-transport-correlation

Conversation

@betegon

Copy link
Copy Markdown
Member

Summary

Fixes MCP server instrumentation not recording events for wrapper transport patterns (like NodeStreamableHTTPServerTransport which wraps WebStandardStreamableHTTPServerTransport).

The root cause: wrapper transports proxy onmessage/send via getters/setters, causing different this values. The previous WeakMap<transport, ...> correlation couldn't match requests to responses. This changes to Map<sessionId, ...> correlation which works regardless of transport object reference.

Changes

  • Changed correlation.ts to use sessionId-based Maps instead of transport-based WeakMaps
  • Changed sessionManagement.ts to use sessionId-based session lookup
  • Added unit tests with mock wrapper transport utility
  • Added E2E tests for StreamableHTTP transport across node-express, node-express-v5, and tsx-express

Test Plan

  • Unit tests: cd packages/core && yarn test (2010 tests pass)
  • E2E tests: All pass
    • node-express: 14/14
    • node-express-v5: 12/12
    • tsx-express: 10/10

  • If you've added code that should be tested, please add tests.
  • Ensure your code lints and the test suite passes (yarn lint) & (yarn test).
  • Link an issue if there is one related to your pull request. If no issue is linked, one will be auto-generated and linked.

Closes#19233

Thanks @gotenxds for reporting and debugging this issue!

…n spans
This introduces `recordInputs` and `recordOutputs` options to the MCP server wrapper and related functions, allowing for more granular control over the data captured in spans.
Wrapper transports (like NodeStreamableHTTPServerTransport wrapping
WebStandardStreamableHTTPServerTransport) proxy onmessage/send via
getters/setters, causing different 'this' values in each callback.
This changes correlation from WeakMap<transport> to Map<sessionId>
to correctly correlate requests with responses regardless of which
transport object reference is used.
Reported-by: @gotenxds
Add mock wrapper transport utility and tests verifying that
instrumentation correctly handles transports that proxy onmessage/send
via getters/setters (common pattern with StreamableHTTP transports).
Add E2E tests for MCP StreamableHTTP transport across node-express,
node-express-v5, and tsx-express test applications. Tests verify that
transactions are recorded correctly for the wrapper transport pattern
used by NodeStreamableHTTPServerTransport.
@github-actions

github-actionsBot commented Feb 4, 2026

Copy link
Copy Markdown
Contributor

Codecov Results 📊


Generated by Codecov Action

@github-actions

Copy link
Copy Markdown
Contributor

Codecov Results 📊

23 passed | ⏭️ 7 skipped | Total: 30 | Pass Rate: 76.67% | Execution Time: 10.04s

All tests are passing successfully.


Generated by Codecov Action

@github-actions

github-actionsBot commented Feb 4, 2026

Copy link
Copy Markdown
Contributor

node-overhead report 🧳

Note: This is a synthetic benchmark with a minimal express app and does not necessarily reflect the real-world performance impact in an application.

ScenarioRequests/s% of BaselinePrev. Requests/sChange %
GET Baseline9,142-8,968+2%
GET With Sentry1,74319%1,736+0%
GET With Sentry (error only)6,17868%6,029+2%
POST Baseline1,201-1,202-0%
POST With Sentry58148%585-1%
POST With Sentry (error only)1,03586%1,062-3%
MYSQL Baseline3,308-3,277+1%
MYSQL With Sentry46214%500-8%
MYSQL With Sentry (error only)2,70782%2,659+2%

View base workflow run

@betegon
betegon marked this pull request as ready for review February 9, 2026 13:00

@cursorcursorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Bugbot Autofix is OFF. To automatically fix reported issues with Cloud Agents, enable Autofix in the Cursor dashboard.

* different transport objects share the same logical session
*/
const transportToSpanMap = new WeakMap<MCPTransport, Map<RequestId, RequestSpanMapValue>>();
const sessionToSpanMap = new Map<string, Map<RequestId, RequestSpanMapValue>>();

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Module-level Maps leak memory without transport close

Medium Severity

sessionToSpanMap and sessionToSessionData are module-level Map<string, ...> instances whose entries are only removed via explicit delete calls in cleanupPendingSpansForTransport / cleanupSessionDataForTransport, which are solely triggered by the transport's onclose handler. If a transport is abandoned without onclose firing (e.g., unclean disconnect), entries accumulate indefinitely. The previous WeakMap<MCPTransport, ...> approach provided automatic GC-based cleanup as a safety net, which this change loses for stateful transports.

Additional Locations (1)

Fix in CursorFix in Web

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

acknowledged, intentional.

So this would happen if somehow the mcp server skips onClose when closing a connection, and it shouldn't happen.

  1. the only way to skip onclose is a process crash (where memory is freed anyway) or a genuine bug in user code where they abandon a transport without closing it
  2. the MCP server.close() calls close() on all connected transports, which triggers onclose
  3. HTTP connection drops trigger onclose in the transport implementation
  4. SSE disconnects trigger onclose

This is a normal flow as per MCP docs:

1. Transport created (sessionId assigned)
2. server.connect(transport) → we wrap onmessage/send/onclose
3. Messages flow:
- onmessage: stores span in sessionToSpanMap[sessionId][requestId]
- send: looks up span in sessionToSpanMap[sessionId][requestId], ends it, deletes entry
4. Transport closes:
- onclose fires
- cleanupPendingSpansForTransport(): ends any orphan spans, calls sessionToSpanMap.delete(sessionId)
- cleanupSessionDataForTransport(): calls sessionToSessionData.delete(sessionId)
5. Maps are now clean for that sessionId

So everything is cleaned up.

@betegon
betegon requested a review from JPeer264February 9, 2026 13:21
@betegonbetegon self-assigned this Feb 9, 2026

@JPeer264JPeer264 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM.

@betegon
betegon merged commit 389ab1f into developFeb 10, 2026
219 checks passed
@betegon
betegon deleted the bete/fix/mcp-wrapper-transport-correlation branch February 10, 2026 12:36
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

MCP server aint recording events - req/res transport issue

2 participants

@betegon@JPeer264
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(core): use sessionId for MCP transport correlation - #19172

Merged
betegon merged 16 commits into
developfrom
bete/fix/mcp-wrapper-transport-correlation
Feb 10, 2026
Merged

fix(core): use sessionId for MCP transport correlation#19172
betegon merged 16 commits into
developfrom
bete/fix/mcp-wrapper-transport-correlation

Conversation

@betegon

Copy link
Copy Markdown
Member

Summary

Fixes MCP server instrumentation not recording events for wrapper transport patterns (like NodeStreamableHTTPServerTransport which wraps WebStandardStreamableHTTPServerTransport).

The root cause: wrapper transports proxy onmessage/send via getters/setters, causing different this values. The previous WeakMap<transport, ...> correlation couldn't match requests to responses. This changes to Map<sessionId, ...> correlation which works regardless of transport object reference.

Changes

  • Changed correlation.ts to use sessionId-based Maps instead of transport-based WeakMaps
  • Changed sessionManagement.ts to use sessionId-based session lookup
  • Added unit tests with mock wrapper transport utility
  • Added E2E tests for StreamableHTTP transport across node-express, node-express-v5, and tsx-express

Test Plan

  • Unit tests: cd packages/core && yarn test (2010 tests pass)
  • E2E tests: All pass
    • node-express: 14/14
    • node-express-v5: 12/12
    • tsx-express: 10/10

  • If you've added code that should be tested, please add tests.
  • Ensure your code lints and the test suite passes (yarn lint) & (yarn test).
  • Link an issue if there is one related to your pull request. If no issue is linked, one will be auto-generated and linked.

Closes#19233

Thanks @gotenxds for reporting and debugging this issue!

…n spans
This introduces `recordInputs` and `recordOutputs` options to the MCP server wrapper and related functions, allowing for more granular control over the data captured in spans.
Wrapper transports (like NodeStreamableHTTPServerTransport wrapping
WebStandardStreamableHTTPServerTransport) proxy onmessage/send via
getters/setters, causing different 'this' values in each callback.
This changes correlation from WeakMap<transport> to Map<sessionId>
to correctly correlate requests with responses regardless of which
transport object reference is used.
Reported-by: @gotenxds
Add mock wrapper transport utility and tests verifying that
instrumentation correctly handles transports that proxy onmessage/send
via getters/setters (common pattern with StreamableHTTP transports).
Add E2E tests for MCP StreamableHTTP transport across node-express,
node-express-v5, and tsx-express test applications. Tests verify that
transactions are recorded correctly for the wrapper transport pattern
used by NodeStreamableHTTPServerTransport.
@github-actions

github-actionsBot commented Feb 4, 2026

Copy link
Copy Markdown
Contributor

Codecov Results 📊


Generated by Codecov Action

@github-actions

Copy link
Copy Markdown
Contributor

Codecov Results 📊

23 passed | ⏭️ 7 skipped | Total: 30 | Pass Rate: 76.67% | Execution Time: 10.04s

All tests are passing successfully.


Generated by Codecov Action

@github-actions

github-actionsBot commented Feb 4, 2026

Copy link
Copy Markdown
Contributor

node-overhead report 🧳

Note: This is a synthetic benchmark with a minimal express app and does not necessarily reflect the real-world performance impact in an application.

ScenarioRequests/s% of BaselinePrev. Requests/sChange %
GET Baseline9,142-8,968+2%
GET With Sentry1,74319%1,736+0%
GET With Sentry (error only)6,17868%6,029+2%
POST Baseline1,201-1,202-0%
POST With Sentry58148%585-1%
POST With Sentry (error only)1,03586%1,062-3%
MYSQL Baseline3,308-3,277+1%
MYSQL With Sentry46214%500-8%
MYSQL With Sentry (error only)2,70782%2,659+2%

View base workflow run

@betegon
betegon marked this pull request as ready for review February 9, 2026 13:00

@cursorcursorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Bugbot Autofix is OFF. To automatically fix reported issues with Cloud Agents, enable Autofix in the Cursor dashboard.

* different transport objects share the same logical session
*/
const transportToSpanMap = new WeakMap<MCPTransport, Map<RequestId, RequestSpanMapValue>>();
const sessionToSpanMap = new Map<string, Map<RequestId, RequestSpanMapValue>>();

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Module-level Maps leak memory without transport close

Medium Severity

sessionToSpanMap and sessionToSessionData are module-level Map<string, ...> instances whose entries are only removed via explicit delete calls in cleanupPendingSpansForTransport / cleanupSessionDataForTransport, which are solely triggered by the transport's onclose handler. If a transport is abandoned without onclose firing (e.g., unclean disconnect), entries accumulate indefinitely. The previous WeakMap<MCPTransport, ...> approach provided automatic GC-based cleanup as a safety net, which this change loses for stateful transports.

Additional Locations (1)

Fix in CursorFix in Web

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

acknowledged, intentional.

So this would happen if somehow the mcp server skips onClose when closing a connection, and it shouldn't happen.

  1. the only way to skip onclose is a process crash (where memory is freed anyway) or a genuine bug in user code where they abandon a transport without closing it
  2. the MCP server.close() calls close() on all connected transports, which triggers onclose
  3. HTTP connection drops trigger onclose in the transport implementation
  4. SSE disconnects trigger onclose

This is a normal flow as per MCP docs:

1. Transport created (sessionId assigned)
2. server.connect(transport) → we wrap onmessage/send/onclose
3. Messages flow:
- onmessage: stores span in sessionToSpanMap[sessionId][requestId]
- send: looks up span in sessionToSpanMap[sessionId][requestId], ends it, deletes entry
4. Transport closes:
- onclose fires
- cleanupPendingSpansForTransport(): ends any orphan spans, calls sessionToSpanMap.delete(sessionId)
- cleanupSessionDataForTransport(): calls sessionToSessionData.delete(sessionId)
5. Maps are now clean for that sessionId

So everything is cleaned up.

@betegon
betegon requested a review from JPeer264February 9, 2026 13:21
@betegonbetegon self-assigned this Feb 9, 2026

@JPeer264JPeer264 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM.

@betegon
betegon merged commit 389ab1f into developFeb 10, 2026
219 checks passed
@betegon
betegon deleted the bete/fix/mcp-wrapper-transport-correlation branch February 10, 2026 12:36
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

MCP server aint recording events - req/res transport issue

2 participants

@betegon@JPeer264
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

fix(core): use sessionId for MCP transport correlation - #19172

Merged
betegon merged 16 commits into
developfrom
bete/fix/mcp-wrapper-transport-correlation
Feb 10, 2026
Merged

fix(core): use sessionId for MCP transport correlation#19172
betegon merged 16 commits into
developfrom
bete/fix/mcp-wrapper-transport-correlation

Conversation

@betegon

Copy link
Copy Markdown
Member

Summary

Fixes MCP server instrumentation not recording events for wrapper transport patterns (like NodeStreamableHTTPServerTransport which wraps WebStandardStreamableHTTPServerTransport).

The root cause: wrapper transports proxy onmessage/send via getters/setters, causing different this values. The previous WeakMap<transport, ...> correlation couldn't match requests to responses. This changes to Map<sessionId, ...> correlation which works regardless of transport object reference.

Changes

  • Changed correlation.ts to use sessionId-based Maps instead of transport-based WeakMaps
  • Changed sessionManagement.ts to use sessionId-based session lookup
  • Added unit tests with mock wrapper transport utility
  • Added E2E tests for StreamableHTTP transport across node-express, node-express-v5, and tsx-express

Test Plan

  • Unit tests: cd packages/core && yarn test (2010 tests pass)
  • E2E tests: All pass
    • node-express: 14/14
    • node-express-v5: 12/12
    • tsx-express: 10/10

  • If you've added code that should be tested, please add tests.
  • Ensure your code lints and the test suite passes (yarn lint) & (yarn test).
  • Link an issue if there is one related to your pull request. If no issue is linked, one will be auto-generated and linked.

Closes#19233

Thanks @gotenxds for reporting and debugging this issue!

…n spans
This introduces `recordInputs` and `recordOutputs` options to the MCP server wrapper and related functions, allowing for more granular control over the data captured in spans.
Wrapper transports (like NodeStreamableHTTPServerTransport wrapping
WebStandardStreamableHTTPServerTransport) proxy onmessage/send via
getters/setters, causing different 'this' values in each callback.
This changes correlation from WeakMap<transport> to Map<sessionId>
to correctly correlate requests with responses regardless of which
transport object reference is used.
Reported-by: @gotenxds
Add mock wrapper transport utility and tests verifying that
instrumentation correctly handles transports that proxy onmessage/send
via getters/setters (common pattern with StreamableHTTP transports).
Add E2E tests for MCP StreamableHTTP transport across node-express,
node-express-v5, and tsx-express test applications. Tests verify that
transactions are recorded correctly for the wrapper transport pattern
used by NodeStreamableHTTPServerTransport.
@github-actions

github-actionsBot commented Feb 4, 2026

Copy link
Copy Markdown
Contributor

Codecov Results 📊


Generated by Codecov Action

@github-actions

Copy link
Copy Markdown
Contributor

Codecov Results 📊

23 passed | ⏭️ 7 skipped | Total: 30 | Pass Rate: 76.67% | Execution Time: 10.04s

All tests are passing successfully.


Generated by Codecov Action

@github-actions

github-actionsBot commented Feb 4, 2026

Copy link
Copy Markdown
Contributor

node-overhead report 🧳

Note: This is a synthetic benchmark with a minimal express app and does not necessarily reflect the real-world performance impact in an application.

ScenarioRequests/s% of BaselinePrev. Requests/sChange %
GET Baseline9,142-8,968+2%
GET With Sentry1,74319%1,736+0%
GET With Sentry (error only)6,17868%6,029+2%
POST Baseline1,201-1,202-0%
POST With Sentry58148%585-1%
POST With Sentry (error only)1,03586%1,062-3%
MYSQL Baseline3,308-3,277+1%
MYSQL With Sentry46214%500-8%
MYSQL With Sentry (error only)2,70782%2,659+2%

View base workflow run

@betegon
betegon marked this pull request as ready for review February 9, 2026 13:00

@cursorcursorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Bugbot Autofix is OFF. To automatically fix reported issues with Cloud Agents, enable Autofix in the Cursor dashboard.

* different transport objects share the same logical session
*/
const transportToSpanMap = new WeakMap<MCPTransport, Map<RequestId, RequestSpanMapValue>>();
const sessionToSpanMap = new Map<string, Map<RequestId, RequestSpanMapValue>>();

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Module-level Maps leak memory without transport close

Medium Severity

sessionToSpanMap and sessionToSessionData are module-level Map<string, ...> instances whose entries are only removed via explicit delete calls in cleanupPendingSpansForTransport / cleanupSessionDataForTransport, which are solely triggered by the transport's onclose handler. If a transport is abandoned without onclose firing (e.g., unclean disconnect), entries accumulate indefinitely. The previous WeakMap<MCPTransport, ...> approach provided automatic GC-based cleanup as a safety net, which this change loses for stateful transports.

Additional Locations (1)

Fix in CursorFix in Web

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

acknowledged, intentional.

So this would happen if somehow the mcp server skips onClose when closing a connection, and it shouldn't happen.

  1. the only way to skip onclose is a process crash (where memory is freed anyway) or a genuine bug in user code where they abandon a transport without closing it
  2. the MCP server.close() calls close() on all connected transports, which triggers onclose
  3. HTTP connection drops trigger onclose in the transport implementation
  4. SSE disconnects trigger onclose

This is a normal flow as per MCP docs:

1. Transport created (sessionId assigned)
2. server.connect(transport) → we wrap onmessage/send/onclose
3. Messages flow:
- onmessage: stores span in sessionToSpanMap[sessionId][requestId]
- send: looks up span in sessionToSpanMap[sessionId][requestId], ends it, deletes entry
4. Transport closes:
- onclose fires
- cleanupPendingSpansForTransport(): ends any orphan spans, calls sessionToSpanMap.delete(sessionId)
- cleanupSessionDataForTransport(): calls sessionToSessionData.delete(sessionId)
5. Maps are now clean for that sessionId

So everything is cleaned up.

@betegon
betegon requested a review from JPeer264February 9, 2026 13:21
@betegonbetegon self-assigned this Feb 9, 2026

@JPeer264JPeer264 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM.

@betegon
betegon merged commit 389ab1f into developFeb 10, 2026
219 checks passed
@betegon
betegon deleted the bete/fix/mcp-wrapper-transport-correlation branch February 10, 2026 12:36
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

MCP server aint recording events - req/res transport issue

2 participants

@betegon@JPeer264