Files
Hao Guo 14b84f08a3 fix(mcp): bound the MCP shutdown phase (#1183)
Closing MCP clients in the review teardown was serial and unbounded: each
Close hit the SDK's three-stage escalation (wait after stdin close, wait
after SIGTERM, wait after SIGKILL) at the default 5s per stage, so one
unresponsive stdio server could hold shutdown for ~15s and N configured
servers multiplied that. The overruns defeated docker stop's 10s grace
period and the VS Code extension's 3s SIGKILL escalation, orphaning the
subprocesses the graceful path exists to reclaim (#1141).

- Set an explicit 800ms TerminateDuration on CommandTransport, keeping a
  single server's worst case at ~2.4s instead of ~15s.
- Add mcp.CloseAll: closes clients concurrently with per-server errors
  joined into one report, so the phase costs the slowest server rather
  than the sum of all servers.
- Cap the whole close phase with a 2.8s deadline in review_cmd, chosen on
  context.Background() so an already-cancelled run keeps its budget; on
  timeout the warning reports the servers still shutting down and keeps
  any errors already collected. The SDK still escalates to SIGKILL in the
  meantime; whatever outlives the process is left to the OS.

Tests cover an unresponsive stdio server (SIGTERM-ignoring child, full
stdin-close -> SIGTERM -> SIGKILL path, < 3s), unchanged fast error-free
close for responsive servers, joined per-server error messages, and the
deadline abandonment. Child fixtures run this test binary in three modes;
under -race the widened child shutdown latency is absorbed by a build-tag
budget so the suite stays deterministic.
2026-09-09 15:56:59 +08:00
..