Skip to content

fix(core): terminate legacy MCP sessions on close - #52414

Merged
rekram1-node merged 3 commits into
v2from
mcp-session-delete
Oct 1, 2026
Merged

rekram1-node merged 3 commits into
v2from
mcp-session-delete

Conversation

@rekram1-node

@rekram1-node rekram1-node commented Oct 1, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

Closing a remote MCP connection called client.close(), which only aborts the transport's HTTP streams. The SDK sends the MCP session DELETE only from the separate terminateSession(), so legacy Streamable HTTP sessions stayed alive on the server until its own expiry.

The connection finalizer now terminates the session before closing:

  • Runs only for legacy connections that hold an Mcp-Session-Id; stdio and modern connections are unchanged.
  • Skips sessions the server already reported as expired (404 / not initialized).
  • Is bounded to 1 second. A 405 is accepted; other failures and timeouts are logged as warnings and never prevent close(). It runs before close() because the DELETE shares the transport's abort signal; a timed-out request is aborted by the following close().
  • Uses the stored access token without OAuth refresh or 401 retry, so teardown cannot start a token refresh.

Unresponsive servers can add up to 1 second each to MCP teardown.

Verification

bun test test/mcp.test.ts test/mcp-oauth.test.ts and bun run check pass.

@rekram1-node
rekram1-node merged commit 155bc7d into v2 Oct 1, 2026
10 checks passed
@rekram1-node
rekram1-node deleted the mcp-session-delete branch October 1, 2026 03:17
Ichinose-Kazuki pushed a commit to Ichinose-Kazuki/opencode that referenced this pull request Oct 7, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant