MCP session DELETE differs from its retained status contract #1023

Open
opened 2026-10-03 16:25:09 +00:00 by kayg · 1 comment
Owner

MCP owner session DELETE returns 202 where its contract test requires 200

Found in #867 round 2, job/merge-round-7b2. After fixing the fixture to decode finite SSE JSON-RPC replies (#836), the controlled principal/session regression reaches its final owner DELETE check. All earlier disabled-Plugin and principal checks finish before this failure.

Run the built server test binary with the production worker stack:

RUST_MIN_STACK=4194304 "$CARGO_TARGET_DIR/debug/deps/calternal_server-e059158dbb89b57f" wire::tests::mcp_session_owner_is_checked_at_the_http_boundary --exact --ignored --test-threads=4

Verbatim output:

assertion `left == right` failed: the original owner could not delete their session
  left: 202
 right: 200
test result: FAILED. 0 passed; 1 failed; 0 ignored; 0 measured; 213 filtered out; finished in 17.42s

The existing 200 expectation is retained under the owner rule. No brief explicitly changes the DELETE status contract. Decide whether the server must keep 200 or a protocol change requires an explicit issue; do not change the assertion merely to pass. The normal full server gate is still red until this is resolved and rerun.

Evidence: artifacts/round2-mcp-direct-worker-stack.log in the worktree. A Cargo invocation at the same worker stack is queued. A standalone invocation on the default 2 MiB test thread overflows; the full live-app child harness already selects the production 4 MiB worker stack. This report does not claim an origin/dev baseline result or production readiness.

MCP owner session DELETE returns 202 where its contract test requires 200 Found in #867 round 2, job/merge-round-7b2. After fixing the fixture to decode finite SSE JSON-RPC replies (#836), the controlled principal/session regression reaches its final owner DELETE check. All earlier disabled-Plugin and principal checks finish before this failure. Run the built server test binary with the production worker stack: ``` RUST_MIN_STACK=4194304 "$CARGO_TARGET_DIR/debug/deps/calternal_server-e059158dbb89b57f" wire::tests::mcp_session_owner_is_checked_at_the_http_boundary --exact --ignored --test-threads=4 ``` Verbatim output: ``` assertion `left == right` failed: the original owner could not delete their session left: 202 right: 200 test result: FAILED. 0 passed; 1 failed; 0 ignored; 0 measured; 213 filtered out; finished in 17.42s ``` The existing 200 expectation is retained under the owner rule. No brief explicitly changes the DELETE status contract. Decide whether the server must keep 200 or a protocol change requires an explicit issue; do not change the assertion merely to pass. The normal full server gate is still red until this is resolved and rerun. Evidence: artifacts/round2-mcp-direct-worker-stack.log in the worktree. A Cargo invocation at the same worker stack is queued. A standalone invocation on the default 2 MiB test thread overflows; the full live-app child harness already selects the production 4 MiB worker stack. This report does not claim an origin/dev baseline result or production readiness.
Author
Owner

Fixed in job/merge-round-7b2. The MCP boundary now normalizes rmcp's completed-session DELETE 202 response to the server's established 200 contract. The existing owner-delete status assertion remains unchanged; I extended it to verify GET after deletion returns 404. Focused live-app regression passed: 1 passed, 0 failed (13.39s). Server clippy is running.

Fixed in job/merge-round-7b2. The MCP boundary now normalizes rmcp's completed-session DELETE 202 response to the server's established 200 contract. The existing owner-delete status assertion remains unchanged; I extended it to verify GET after deletion returns 404. Focused live-app regression passed: 1 passed, 0 failed (13.39s). Server clippy is running.
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
kayg/calternal#1023
No description provided.