Skip to content

Cross-version zod schemas crash tools/list in createSdkMcpServer (connected but zero tools) #491

Description

@wzm2023

Cross-version zod schemas crash tools/list in createSdkMcpServer

The bundled JSON-Schema walker prefers a schema node's own bound processor (e._zod.processJSONSchema), and builds the walker context itself. When a schema was constructed by a different zod build than the one bundled here, the bound processor is called with a foreign context and throws. Example: a z.record() built by zod 4.6.5 calls ctx.deferred.push(...), but this package's 4.4.3 context has no deferred field, so the walker raises TypeError: Cannot read properties of undefined (reading 'push'). Because the throw happens while serializing the tool list, the entire tools/list response fails and the server is reported connected with zero tools — a silent, hard-to-attribute failure for any host whose zod is newer than the bundled one.

Two asks:

  • (a) do not invoke a schema's bound _zod.processJSONSchema unless the schema was built by the bundled zod, or guard the context so a foreign processor cannot corrupt the walk;
  • (b) when a tool list fails to serialize, surface it as a per-server error with the offending tool name rather than an empty, "healthy" server.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't workingduplicateThis issue or pull request already exists

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions