Describe the bug
When a server scenario fails, its Streamable HTTP session is never terminated. #79 added the DELETE to the connection's close(), but most scenarios call close() as the last statement of their try block, so it only runs on the success path. When the scenario throws (for example on a -32601 for a method the server does not implement), the catch records the failure and the session, including its GET stream, stays open until the process exits.
For example, on main (7169291), every scenario in src/scenarios/server/prompts.ts and resources.ts follows this shape:
try {
const conn = await connectToServer(serverUrl);
// ... checks that can throw ...
await conn.close(); // skipped when anything above throws
} catch (error) {
checks.push({ /* FAILURE */ });
}
The same pattern is in 0.2.0-alpha.11: of about 50 close() calls in the bundle, 4 are in a finally.
Why it matters
A server that caps concurrent sessions per client (a reasonable defence for an authenticated HTTP server) fills up after a few failing scenarios, and every later scenario gets HTTP 503 at initialize. Their results then describe the harness, not the server. Running conformance server against a gateway with a cap of 4 sessions per client, the 2025-11-25 run gets 13 of these 503s, and scenarios later in the run cannot be scored. Because the open GET stream is also left in place, the server cannot tell those sessions apart from live, idle clients, so it has no safe way to reclaim them.
Expected behavior
Close the connection on every exit path, e.g.:
let conn: Connection | undefined;
try {
conn = await connectToServer(serverUrl);
// ... checks ...
} catch (error) {
checks.push({ /* FAILURE */ });
} finally {
await conn?.close().catch(() => {});
}
To Reproduce
- Run
npx @modelcontextprotocol/conformance server --url <server> against a server that does not implement prompts/list (so the prompts scenarios fail with -32601).
- Watch the server: sessions from the failed scenarios receive no DELETE, and their GET streams stay open until the suite exits.
Additional context
Found while running the suite against Fathomgate, an MCP proxy, through its HTTP listener. Happy to send a PR if that helps.
Describe the bug
When a server scenario fails, its Streamable HTTP session is never terminated. #79 added the DELETE to the connection's
close(), but most scenarios callclose()as the last statement of theirtryblock, so it only runs on the success path. When the scenario throws (for example on a-32601for a method the server does not implement), thecatchrecords the failure and the session, including its GET stream, stays open until the process exits.For example, on
main(7169291), every scenario insrc/scenarios/server/prompts.tsandresources.tsfollows this shape:The same pattern is in 0.2.0-alpha.11: of about 50
close()calls in the bundle, 4 are in afinally.Why it matters
A server that caps concurrent sessions per client (a reasonable defence for an authenticated HTTP server) fills up after a few failing scenarios, and every later scenario gets HTTP 503 at
initialize. Their results then describe the harness, not the server. Runningconformance serveragainst a gateway with a cap of 4 sessions per client, the 2025-11-25 run gets 13 of these 503s, and scenarios later in the run cannot be scored. Because the open GET stream is also left in place, the server cannot tell those sessions apart from live, idle clients, so it has no safe way to reclaim them.Expected behavior
Close the connection on every exit path, e.g.:
To Reproduce
npx @modelcontextprotocol/conformance server --url <server>against a server that does not implementprompts/list(so the prompts scenarios fail with-32601).Additional context
Found while running the suite against Fathomgate, an MCP proxy, through its HTTP listener. Happy to send a PR if that helps.