Context
StdioServerParameters (and the stdio_client context manager that spawns the server subprocess) expose no hook to control the spawned child process's resource limits or process-group assignment at fork time.
Problem
A client that spawns an untrusted or third-party MCP server via stdio cannot, from the SDK public API:
- set CPU / memory / FD / address-space
rlimits on the child,
- place the child in its own process group (so a runaway child can be killed as a group without orphaning grandchildren),
- set a
preexec_fn (POSIX) or equivalent to run arbitrary setup between fork and exec.
StdioServerParameters signature (command, args, env, cwd, encoding, encoding_error_handler) has no slot for any of these. stdio_client owns the subprocess spawn internally, so a caller cannot inject a custom Popen either.
Impact
Downstream hosts (e.g. inference servers spawning MCP tool servers) cannot enforce hard resource caps or reliable teardown on a hung/misbehaving MCP server subprocess from the client side. The only mitigation available today is a bounded connect timeout around __aenter__, which does not cover a server that accepts the connection then later runs away.
Request
Expose at least one of:
- an optional
preexec_fn / process_group / rlimit-style kwarg on StdioServerParameters (or stdio_client), passed through to the underlying subprocess.Popen, or
- an injection point for a custom
Popen factory / spawn callable.
(1) mirrors subprocess.Popen(..., preexec_fn=..., start_new_session=...) and would let hosts enforce resource limits + process-group isolation without forking the SDK.
Environment: mcp python-sdk, macOS / Linux. Filed from fusion-mlx (local MLX inference host) where we need to cap spawned MCP server subprocesses.
Context
StdioServerParameters(and thestdio_clientcontext manager that spawns the server subprocess) expose no hook to control the spawned child process's resource limits or process-group assignment at fork time.Problem
A client that spawns an untrusted or third-party MCP server via stdio cannot, from the SDK public API:
rlimits on the child,preexec_fn(POSIX) or equivalent to run arbitrary setup betweenforkandexec.StdioServerParameterssignature (command, args, env, cwd, encoding, encoding_error_handler) has no slot for any of these.stdio_clientowns thesubprocessspawn internally, so a caller cannot inject a customPopeneither.Impact
Downstream hosts (e.g. inference servers spawning MCP tool servers) cannot enforce hard resource caps or reliable teardown on a hung/misbehaving MCP server subprocess from the client side. The only mitigation available today is a bounded connect timeout around
__aenter__, which does not cover a server that accepts the connection then later runs away.Request
Expose at least one of:
preexec_fn/process_group/rlimit-style kwarg onStdioServerParameters(orstdio_client), passed through to the underlyingsubprocess.Popen, orPopenfactory / spawn callable.(1) mirrors
subprocess.Popen(..., preexec_fn=..., start_new_session=...)and would let hosts enforce resource limits + process-group isolation without forking the SDK.Environment: mcp python-sdk, macOS / Linux. Filed from fusion-mlx (local MLX inference host) where we need to cap spawned MCP server subprocesses.