Skip to content

fix: preserve MCP request IDs in success and error responses - #7

Merged
veronica-agent merged 1 commit into
mainfrom
fix-mcp-request-ids
Oct 5, 2026
Merged

veronica-agent merged 1 commit into
mainfrom
fix-mcp-request-ids

Conversation

@veronica-agent

Copy link
Copy Markdown
Member

MCP clients could not correlate responses when a request ID exceeded 63 bytes or contained escaped characters: long IDs produced invalid JSON, while Unicode, controls, and large numeric IDs were changed. Both successful replies and JSON-RPC errors now echo the complete original ID token.

The parser retains an owned string lexeme for response IDs, validates escape and number syntax before echoing it, and accepts exponent-form numeric IDs. Error responses allocate space for the complete ID instead of truncating at 1024 bytes.

Validation: GAZE_DEV=ffff:ffff just test-protocol passed (5 protocol tests and 14 plugin tests, including 30 ID round trips and 9 malformed-token cases). The new round-trip regression failed on the original code with 12 mismatches and 3 malformed responses before the fix. No camera movement or capture was performed; hardware tests were not run.

Work item: WI-211b78.

@obey-agent obey-agent left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed head b488299afbdc79a8f8521eb8bc427974742d28ce. No actionable findings.

Traced JSON token validation, raw string ownership, ID lifetime through synchronous replies, and success/error buffer sizing. The Linux build passed with warnings treated as errors, and all five camera-free protocol tests passed, including long, escaped, Unicode, control, and numeric IDs and malformed-token recovery. Did not exercise macOS builds or camera hardware. The existing general string-decoding behavior and string length limit are outside this change.

@veronica-agent
veronica-agent merged commit dbb040d into main Oct 5, 2026
4 checks passed
@veronica-agent
veronica-agent deleted the fix-mcp-request-ids branch October 5, 2026 04:20
lancekrogers added a commit that referenced this pull request Oct 6, 2026
## Summary

The `linux` workflow on `main` (`dbb040d`, run 37263099985) failed in
`deps` before any gaze test ran. `sudo apt-get update` exited 100
because the Ubuntu runner image preinstalls `packages.microsoft.com`,
and that repo returned `403 Forbidden` (`noble InRelease` is no longer
signed). The same step is in `release-linux.yml`, so the next tag push
would fail the same way.

Gaze installs `gcc`, `libjpeg-dev`, and `just` from Ubuntu. Both
workflows now remove `microsoft-prod.list` and `microsoft-prod.sources`
before `apt-get update`.

The `protocol` workflow on that commit passed. The same `linux` job
passed on PR #7 about ten minutes earlier, which matches the known
intermittent Microsoft apt failure on hosted runners.

## Test plan

- [ ] `linux` workflow `deps` completes `apt-get update` and
`test-protocol` runs
- [ ] `protocol` workflow still passes
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants