Cross-version zod schemas crash tools/list in createSdkMcpServer
The bundled JSON-Schema walker prefers a schema node's own bound processor (e._zod.processJSONSchema), and builds the walker context itself. When a schema was constructed by a different zod build than the one bundled here, the bound processor is called with a foreign context and throws. Example: a z.record() built by zod 4.6.5 calls ctx.deferred.push(...), but this package's 4.4.3 context has no deferred field, so the walker raises TypeError: Cannot read properties of undefined (reading 'push'). Because the throw happens while serializing the tool list, the entire tools/list response fails and the server is reported connected with zero tools — a silent, hard-to-attribute failure for any host whose zod is newer than the bundled one.
Two asks:
- (a) do not invoke a schema's bound
_zod.processJSONSchema unless the schema was built by the bundled zod, or guard the context so a foreign processor cannot corrupt the walk;
- (b) when a tool list fails to serialize, surface it as a per-server error with the offending tool name rather than an empty, "healthy" server.
Cross-version zod schemas crash tools/list in createSdkMcpServer
The bundled JSON-Schema walker prefers a schema node's own bound processor (
e._zod.processJSONSchema), and builds the walker context itself. When a schema was constructed by a different zod build than the one bundled here, the bound processor is called with a foreign context and throws. Example: az.record()built by zod 4.6.5 callsctx.deferred.push(...), but this package's 4.4.3 context has nodeferredfield, so the walker raisesTypeError: Cannot read properties of undefined (reading 'push'). Because the throw happens while serializing the tool list, the entiretools/listresponse fails and the server is reportedconnectedwith zero tools — a silent, hard-to-attribute failure for any host whose zod is newer than the bundled one.Two asks:
_zod.processJSONSchemaunless the schema was built by the bundled zod, or guard the context so a foreign processor cannot corrupt the walk;