Skip to content

fix: prevent streamable HTTP session leak - #934

Merged
DaleSeo merged 1 commit into
mainfrom
fix/streamable-http-session-leak
Jun 27, 2026
Merged

fix: prevent streamable HTTP session leak#934
DaleSeo merged 1 commit into
mainfrom
fix/streamable-http-session-leak

Conversation

@DaleSeo

Copy link
Copy Markdown
Member

Motivation and Context

The stateful Streamable HTTP server could allocate a local session before rejecting an invalid initial POST. This change validates that an initial stateful POST is an initialize request, checks the MCP-Protocol-Version header against the initialize body, and only creates a session after those checks pass. That keeps rejected pre-initialize requests from leaving entries behind in LocalSessionManager.

How Has This Been Tested?

Added tests

Breaking Changes

None.

Types of changes

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to change)
  • Documentation update

Checklist

  • I have read the MCP Documentation
  • My code follows the repository's style guidelines
  • New and existing tests pass locally
  • I have added appropriate error handling
  • I have added or updated documentation as needed

@github-actionsgithub-actionsBot added T-test Testing related changes T-core Core library changes T-transport Transport layer changes labels Jun 26, 2026
@DaleSeo
DaleSeo marked this pull request as ready for review June 26, 2026 21:37
@DaleSeo
DaleSeo requested a review from a team as a code ownerJune 26, 2026 21:37
@DaleSeoDaleSeo self-assigned this Jun 27, 2026
@DaleSeo
DaleSeo merged commit dfa7fd6 into mainJun 27, 2026
19 checks passed
@DaleSeo
DaleSeo deleted the fix/streamable-http-session-leak branch June 27, 2026 01:09
@github-actionsgithub-actionsBot mentioned this pull request Jun 26, 2026
alphabet-h added a commit to alphabet-h/grooveseek that referenced this pull request Aug 14, 2026
…2) (#149)
Reported against 1.4.0 as modelcontextprotocol/rust-sdk#808 and fixed by modelcontextprotocol/rust-sdk#934, released in rmcp 2.0.0, which also added SessionConfig::init_timeout. Verified against the published crates: 1.4.0-1.8.0 create the session before the initialize check, 2.0.0 onward do not. kb-mcp still pins 1.4.0, and no rmcp release bounds the number of sessions.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

T-coreCore library changesT-testTesting related changesT-transportTransport layer changes

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@DaleSeo@jokemanfire
, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
fix: prevent streamable HTTP session leak by DaleSeo · Pull Request #934 · modelcontextprotocol/rust-sdk · GitHub
Skip to content

fix: prevent streamable HTTP session leak - #934

Merged
DaleSeo merged 1 commit into
mainfrom
fix/streamable-http-session-leak
Jun 27, 2026
Merged

fix: prevent streamable HTTP session leak#934
DaleSeo merged 1 commit into
mainfrom
fix/streamable-http-session-leak

Conversation

@DaleSeo

Copy link
Copy Markdown
Member

Motivation and Context

The stateful Streamable HTTP server could allocate a local session before rejecting an invalid initial POST. This change validates that an initial stateful POST is an initialize request, checks the MCP-Protocol-Version header against the initialize body, and only creates a session after those checks pass. That keeps rejected pre-initialize requests from leaving entries behind in LocalSessionManager.

How Has This Been Tested?

Added tests

Breaking Changes

None.

Types of changes

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to change)
  • Documentation update

Checklist

  • I have read the MCP Documentation
  • My code follows the repository's style guidelines
  • New and existing tests pass locally
  • I have added appropriate error handling
  • I have added or updated documentation as needed

@github-actionsgithub-actionsBot added T-test Testing related changes T-core Core library changes T-transport Transport layer changes labels Jun 26, 2026
@DaleSeo
DaleSeo marked this pull request as ready for review June 26, 2026 21:37
@DaleSeo
DaleSeo requested a review from a team as a code ownerJune 26, 2026 21:37
@DaleSeoDaleSeo self-assigned this Jun 27, 2026
@DaleSeo
DaleSeo merged commit dfa7fd6 into mainJun 27, 2026
19 checks passed
@DaleSeo
DaleSeo deleted the fix/streamable-http-session-leak branch June 27, 2026 01:09
@github-actionsgithub-actionsBot mentioned this pull request Jun 26, 2026
alphabet-h added a commit to alphabet-h/grooveseek that referenced this pull request Aug 14, 2026
…2) (#149)
Reported against 1.4.0 as modelcontextprotocol/rust-sdk#808 and fixed by modelcontextprotocol/rust-sdk#934, released in rmcp 2.0.0, which also added SessionConfig::init_timeout. Verified against the published crates: 1.4.0-1.8.0 create the session before the initialize check, 2.0.0 onward do not. kb-mcp still pins 1.4.0, and no rmcp release bounds the number of sessions.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

T-coreCore library changesT-testTesting related changesT-transportTransport layer changes

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@DaleSeo@jokemanfire
, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' fix: prevent streamable HTTP session leak by DaleSeo · Pull Request #934 · modelcontextprotocol/rust-sdk · GitHub
Skip to content

fix: prevent streamable HTTP session leak - #934

Merged
DaleSeo merged 1 commit into
mainfrom
fix/streamable-http-session-leak
Jun 27, 2026
Merged

fix: prevent streamable HTTP session leak#934
DaleSeo merged 1 commit into
mainfrom
fix/streamable-http-session-leak

Conversation

@DaleSeo

Copy link
Copy Markdown
Member

Motivation and Context

The stateful Streamable HTTP server could allocate a local session before rejecting an invalid initial POST. This change validates that an initial stateful POST is an initialize request, checks the MCP-Protocol-Version header against the initialize body, and only creates a session after those checks pass. That keeps rejected pre-initialize requests from leaving entries behind in LocalSessionManager.

How Has This Been Tested?

Added tests

Breaking Changes

None.

Types of changes

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to change)
  • Documentation update

Checklist

  • I have read the MCP Documentation
  • My code follows the repository's style guidelines
  • New and existing tests pass locally
  • I have added appropriate error handling
  • I have added or updated documentation as needed

@github-actionsgithub-actionsBot added T-test Testing related changes T-core Core library changes T-transport Transport layer changes labels Jun 26, 2026
@DaleSeo
DaleSeo marked this pull request as ready for review June 26, 2026 21:37
@DaleSeo
DaleSeo requested a review from a team as a code ownerJune 26, 2026 21:37
@DaleSeoDaleSeo self-assigned this Jun 27, 2026
@DaleSeo
DaleSeo merged commit dfa7fd6 into mainJun 27, 2026
19 checks passed
@DaleSeo
DaleSeo deleted the fix/streamable-http-session-leak branch June 27, 2026 01:09
@github-actionsgithub-actionsBot mentioned this pull request Jun 26, 2026
alphabet-h added a commit to alphabet-h/grooveseek that referenced this pull request Aug 14, 2026
…2) (#149)
Reported against 1.4.0 as modelcontextprotocol/rust-sdk#808 and fixed by modelcontextprotocol/rust-sdk#934, released in rmcp 2.0.0, which also added SessionConfig::init_timeout. Verified against the published crates: 1.4.0-1.8.0 create the session before the initialize check, 2.0.0 onward do not. kb-mcp still pins 1.4.0, and no rmcp release bounds the number of sessions.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

T-coreCore library changesT-testTesting related changesT-transportTransport layer changes

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@DaleSeo@jokemanfire
, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' fix: prevent streamable HTTP session leak by DaleSeo · Pull Request #934 · modelcontextprotocol/rust-sdk · GitHub
Skip to content

fix: prevent streamable HTTP session leak - #934

Merged
DaleSeo merged 1 commit into
mainfrom
fix/streamable-http-session-leak
Jun 27, 2026
Merged

fix: prevent streamable HTTP session leak#934
DaleSeo merged 1 commit into
mainfrom
fix/streamable-http-session-leak

Conversation

@DaleSeo

Copy link
Copy Markdown
Member

Motivation and Context

The stateful Streamable HTTP server could allocate a local session before rejecting an invalid initial POST. This change validates that an initial stateful POST is an initialize request, checks the MCP-Protocol-Version header against the initialize body, and only creates a session after those checks pass. That keeps rejected pre-initialize requests from leaving entries behind in LocalSessionManager.

How Has This Been Tested?

Added tests

Breaking Changes

None.

Types of changes

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to change)
  • Documentation update

Checklist

  • I have read the MCP Documentation
  • My code follows the repository's style guidelines
  • New and existing tests pass locally
  • I have added appropriate error handling
  • I have added or updated documentation as needed

@github-actionsgithub-actionsBot added T-test Testing related changes T-core Core library changes T-transport Transport layer changes labels Jun 26, 2026
@DaleSeo
DaleSeo marked this pull request as ready for review June 26, 2026 21:37
@DaleSeo
DaleSeo requested a review from a team as a code ownerJune 26, 2026 21:37
@DaleSeoDaleSeo self-assigned this Jun 27, 2026
@DaleSeo
DaleSeo merged commit dfa7fd6 into mainJun 27, 2026
19 checks passed
@DaleSeo
DaleSeo deleted the fix/streamable-http-session-leak branch June 27, 2026 01:09
@github-actionsgithub-actionsBot mentioned this pull request Jun 26, 2026
alphabet-h added a commit to alphabet-h/grooveseek that referenced this pull request Aug 14, 2026
…2) (#149)
Reported against 1.4.0 as modelcontextprotocol/rust-sdk#808 and fixed by modelcontextprotocol/rust-sdk#934, released in rmcp 2.0.0, which also added SessionConfig::init_timeout. Verified against the published crates: 1.4.0-1.8.0 create the session before the initialize check, 2.0.0 onward do not. kb-mcp still pins 1.4.0, and no rmcp release bounds the number of sessions.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

T-coreCore library changesT-testTesting related changesT-transportTransport layer changes

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@DaleSeo@jokemanfire
, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' fix: prevent streamable HTTP session leak by DaleSeo · Pull Request #934 · modelcontextprotocol/rust-sdk · GitHub
Skip to content

fix: prevent streamable HTTP session leak - #934

Merged
DaleSeo merged 1 commit into
mainfrom
fix/streamable-http-session-leak
Jun 27, 2026
Merged

fix: prevent streamable HTTP session leak#934
DaleSeo merged 1 commit into
mainfrom
fix/streamable-http-session-leak

Conversation

@DaleSeo

Copy link
Copy Markdown
Member

Motivation and Context

The stateful Streamable HTTP server could allocate a local session before rejecting an invalid initial POST. This change validates that an initial stateful POST is an initialize request, checks the MCP-Protocol-Version header against the initialize body, and only creates a session after those checks pass. That keeps rejected pre-initialize requests from leaving entries behind in LocalSessionManager.

How Has This Been Tested?

Added tests

Breaking Changes

None.

Types of changes

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to change)
  • Documentation update

Checklist

  • I have read the MCP Documentation
  • My code follows the repository's style guidelines
  • New and existing tests pass locally
  • I have added appropriate error handling
  • I have added or updated documentation as needed

@github-actionsgithub-actionsBot added T-test Testing related changes T-core Core library changes T-transport Transport layer changes labels Jun 26, 2026
@DaleSeo
DaleSeo marked this pull request as ready for review June 26, 2026 21:37
@DaleSeo
DaleSeo requested a review from a team as a code ownerJune 26, 2026 21:37
@DaleSeoDaleSeo self-assigned this Jun 27, 2026
@DaleSeo
DaleSeo merged commit dfa7fd6 into mainJun 27, 2026
19 checks passed
@DaleSeo
DaleSeo deleted the fix/streamable-http-session-leak branch June 27, 2026 01:09
@github-actionsgithub-actionsBot mentioned this pull request Jun 26, 2026
alphabet-h added a commit to alphabet-h/grooveseek that referenced this pull request Aug 14, 2026
…2) (#149)
Reported against 1.4.0 as modelcontextprotocol/rust-sdk#808 and fixed by modelcontextprotocol/rust-sdk#934, released in rmcp 2.0.0, which also added SessionConfig::init_timeout. Verified against the published crates: 1.4.0-1.8.0 create the session before the initialize check, 2.0.0 onward do not. kb-mcp still pins 1.4.0, and no rmcp release bounds the number of sessions.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

T-coreCore library changesT-testTesting related changesT-transportTransport layer changes

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@DaleSeo@jokemanfire
, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' fix: prevent streamable HTTP session leak by DaleSeo · Pull Request #934 · modelcontextprotocol/rust-sdk · GitHub
Skip to content

fix: prevent streamable HTTP session leak - #934

Merged
DaleSeo merged 1 commit into
mainfrom
fix/streamable-http-session-leak
Jun 27, 2026
Merged

fix: prevent streamable HTTP session leak#934
DaleSeo merged 1 commit into
mainfrom
fix/streamable-http-session-leak

Conversation

@DaleSeo

Copy link
Copy Markdown
Member

Motivation and Context

The stateful Streamable HTTP server could allocate a local session before rejecting an invalid initial POST. This change validates that an initial stateful POST is an initialize request, checks the MCP-Protocol-Version header against the initialize body, and only creates a session after those checks pass. That keeps rejected pre-initialize requests from leaving entries behind in LocalSessionManager.

How Has This Been Tested?

Added tests

Breaking Changes

None.

Types of changes

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to change)
  • Documentation update

Checklist

  • I have read the MCP Documentation
  • My code follows the repository's style guidelines
  • New and existing tests pass locally
  • I have added appropriate error handling
  • I have added or updated documentation as needed

@github-actionsgithub-actionsBot added T-test Testing related changes T-core Core library changes T-transport Transport layer changes labels Jun 26, 2026
@DaleSeo
DaleSeo marked this pull request as ready for review June 26, 2026 21:37
@DaleSeo
DaleSeo requested a review from a team as a code ownerJune 26, 2026 21:37
@DaleSeoDaleSeo self-assigned this Jun 27, 2026
@DaleSeo
DaleSeo merged commit dfa7fd6 into mainJun 27, 2026
19 checks passed
@DaleSeo
DaleSeo deleted the fix/streamable-http-session-leak branch June 27, 2026 01:09
@github-actionsgithub-actionsBot mentioned this pull request Jun 26, 2026
alphabet-h added a commit to alphabet-h/grooveseek that referenced this pull request Aug 14, 2026
…2) (#149)
Reported against 1.4.0 as modelcontextprotocol/rust-sdk#808 and fixed by modelcontextprotocol/rust-sdk#934, released in rmcp 2.0.0, which also added SessionConfig::init_timeout. Verified against the published crates: 1.4.0-1.8.0 create the session before the initialize check, 2.0.0 onward do not. kb-mcp still pins 1.4.0, and no rmcp release bounds the number of sessions.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

T-coreCore library changesT-testTesting related changesT-transportTransport layer changes

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@DaleSeo@jokemanfire
, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); })(); fix: prevent streamable HTTP session leak by DaleSeo · Pull Request #934 · modelcontextprotocol/rust-sdk · GitHub
Skip to content

fix: prevent streamable HTTP session leak - #934

Merged
DaleSeo merged 1 commit into
mainfrom
fix/streamable-http-session-leak
Jun 27, 2026
Merged

fix: prevent streamable HTTP session leak#934
DaleSeo merged 1 commit into
mainfrom
fix/streamable-http-session-leak

Conversation

@DaleSeo

Copy link
Copy Markdown
Member

Motivation and Context

The stateful Streamable HTTP server could allocate a local session before rejecting an invalid initial POST. This change validates that an initial stateful POST is an initialize request, checks the MCP-Protocol-Version header against the initialize body, and only creates a session after those checks pass. That keeps rejected pre-initialize requests from leaving entries behind in LocalSessionManager.

How Has This Been Tested?

Added tests

Breaking Changes

None.

Types of changes

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to change)
  • Documentation update

Checklist

  • I have read the MCP Documentation
  • My code follows the repository's style guidelines
  • New and existing tests pass locally
  • I have added appropriate error handling
  • I have added or updated documentation as needed

@github-actionsgithub-actionsBot added T-test Testing related changes T-core Core library changes T-transport Transport layer changes labels Jun 26, 2026
@DaleSeo
DaleSeo marked this pull request as ready for review June 26, 2026 21:37
@DaleSeo
DaleSeo requested a review from a team as a code ownerJune 26, 2026 21:37
@DaleSeoDaleSeo self-assigned this Jun 27, 2026
@DaleSeo
DaleSeo merged commit dfa7fd6 into mainJun 27, 2026
19 checks passed
@DaleSeo
DaleSeo deleted the fix/streamable-http-session-leak branch June 27, 2026 01:09
@github-actionsgithub-actionsBot mentioned this pull request Jun 26, 2026
alphabet-h added a commit to alphabet-h/grooveseek that referenced this pull request Aug 14, 2026
…2) (#149)
Reported against 1.4.0 as modelcontextprotocol/rust-sdk#808 and fixed by modelcontextprotocol/rust-sdk#934, released in rmcp 2.0.0, which also added SessionConfig::init_timeout. Verified against the published crates: 1.4.0-1.8.0 create the session before the initialize check, 2.0.0 onward do not. kb-mcp still pins 1.4.0, and no rmcp release bounds the number of sessions.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

T-coreCore library changesT-testTesting related changesT-transportTransport layer changes

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@DaleSeo@jokemanfire