Skip to content

fix(server): avoid a nil-flusher panic in the SSE handler - #3520

Merged
duwenxin99 merged 17 commits into
googleapis:mainfrom
he-yufeng:fix/sse-handler-nil-flusher
Aug 13, 2026
Merged

fix(server): avoid a nil-flusher panic in the SSE handler#3520
duwenxin99 merged 17 commits into
googleapis:mainfrom
he-yufeng:fix/sse-handler-nil-flusher

Conversation

@he-yufeng

Copy link
Copy Markdown
Contributor

What

In sseHandler, when the http.ResponseWriter does not implement http.Flusher, the code renders a 500 error response but then falls through instead of returning:

flusher, ok := w.(http.Flusher)
if !ok {
    err = fmt.Errorf("unable to retrieve flusher for sse")
    s.logger.DebugContext(ctx, err.Error())
    _ = render.Render(w, r, newErrResponse(err, http.StatusInternalServerError))
}
session := &sseSession{
    writer:  w,
    flusher: flusher, // nil here
    ...
}

flusher is the nil interface, so the first flusher.Flush() (right after the endpoint event is written) panics with invalid memory address or nil pointer dereference. The error response the branch just rendered never takes effect.

Fix

Return after rendering the error, which is what the branch was already trying to do.

Why it matters

The !ok branch exists specifically to handle a writer without a flusher, but the missing return turns that intended 500 into a panic. A wrapped or non-standard ResponseWriter that doesn't forward Flush (some middleware, custom transports) would hit this. The fix makes the handler return the 500 it already builds instead of crashing the request.

How to verify

go test ./internal/server/ -run TestSseHandlerWriterWithoutFlusher

The added test drives sseHandler with a ResponseWriter that intentionally does not implement http.Flusher and asserts a 500 is returned. On main it panics at flusher.Flush() (mcp.go); with the fix it returns the 500 cleanly. The full internal/server package, gofmt, and go vet all pass.

@he-yufeng
he-yufeng requested a review from a team as a code owner June 24, 2026 22:53

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request fixes a potential nil pointer dereference in sseHandler by adding a missing return statement when the response writer does not implement http.Flusher. It also introduces a new unit test TestSseHandlerWriterWithoutFlusher with a custom nonFlusherResponseWriter to verify this behavior. The feedback suggests using io.Discard instead of os.Stderr for the test logger to prevent cluttering the test output during execution.

Comment thread internal/server/mcp_test.go
@he-yufeng
he-yufeng force-pushed the fix/sse-handler-nil-flusher branch from 08dc854 to c085522 Compare June 25, 2026 04:50
@averikitsch averikitsch added the blunderbuss: assign Instruct blunderbuss to assign someone label Jun 25, 2026
@blunderbuss-gcf blunderbuss-gcf Bot removed the blunderbuss: assign Instruct blunderbuss to assign someone label Jun 25, 2026
@he-yufeng

Copy link
Copy Markdown
Contributor Author

Gentle nudge on this one. It's a small guard for the SSE handler: when the ResponseWriter doesn't implement http.Flusher the code currently keeps going instead of returning, which can panic on the nil flusher. The change just returns early in that case. It's been green with only the automated review since late June, so if a maintainer has a minute to look I'd appreciate it, and I'm happy to rebase if it has drifted.

@duwenxin99 duwenxin99 added the priority: p2 Moderately-important priority. Fix may not be included in next release. label Aug 3, 2026
@duwenxin99
duwenxin99 enabled auto-merge (squash) August 3, 2026 15:32
@duwenxin99 duwenxin99 added the type: bug Error or flaw in code with unintended results or allowing sub-optimal usage patterns. label Aug 3, 2026
@duwenxin99

Copy link
Copy Markdown
Contributor

Hi @he-yufeng, thanks for opening the PR! The changes LGTM. Could you rebase on the latest main to resolve the lint failure? Thank you!

@duwenxin99 duwenxin99 added the release candidate Use label to signal PR should be included in the next release. label Aug 3, 2026
@Yuan325

Yuan325 commented Aug 12, 2026

Copy link
Copy Markdown
Contributor

/gcbrun

1 similar comment
@Yuan325

Yuan325 commented Aug 12, 2026

Copy link
Copy Markdown
Contributor

/gcbrun

@Yuan325

Yuan325 commented Aug 13, 2026

Copy link
Copy Markdown
Contributor

/gcbrun

@Yuan325

Yuan325 commented Aug 13, 2026

Copy link
Copy Markdown
Contributor

/gcbrun

@Yuan325

Yuan325 commented Aug 13, 2026

Copy link
Copy Markdown
Contributor

/gcbrun

@Yuan325

Yuan325 commented Aug 13, 2026

Copy link
Copy Markdown
Contributor

/gcbrun

@Yuan325

Yuan325 commented Aug 13, 2026

Copy link
Copy Markdown
Contributor

/gcbrun

@Yuan325

Yuan325 commented Aug 13, 2026

Copy link
Copy Markdown
Contributor

/gcbrun

@duwenxin99
duwenxin99 merged commit 947f42f into googleapis:main Aug 13, 2026
20 checks passed
Yuan325 added a commit that referenced this pull request Aug 14, 2026
🤖 I have created a release *beep* *boop*
---


##
[1.9.0](v1.8.0...v1.9.0)
(2026-08-14)


### Features

* **groups:** Add ttlMs and cacheScope customization to config
([#3805](#3805))
([a5d4947](a5d4947))
* **migrate:** Convert toolset to group kind during migration
([#3704](#3704))
([0adeaa5](0adeaa5))
* **server/mcp:** Introduce generic client extension registry
([#3723](#3723))
([016245c](016245c))
* **skill:** Add review-prs skill for mcp-toolbox
([#3743](#3743))
([5b7bacc](5b7bacc))
* **source/bigquery:** Add apiEndpoint field to override BigQuery API
host ([#3437](#3437))
([4da1600](4da1600))
* **source/databaseinsights:** Add databaseinsights source
([#3461](#3461))
([3b9615d](3b9615d))
* **sources/spanner:** Rename execute_sql_dql to execute_sql_readonly
([#3776](#3776))
([cf5a0c8](cf5a0c8))
* **tools/bigtable:** Add admin lifecycle and listing tools
([#3596](#3596))
([801d589](801d589))
* **tools/bigtable:** Bigtable-list-schemas MCP tool
([#3683](#3683))
([9228c61](9228c61))
* **tools/databaseinsights:** Add Advanced Query Insights tools for
AlloyDB ([#3722](#3722))
([74d18ae](74d18ae))
* **tools/looker:** Add additional tools to allow dashboards to be
modified, and their layouts altered.
([#3597](#3597))
([b2b80fb](b2b80fb))
* **tools:** Add cloud-sql-connect-gce for pg, mysql, mssql
([#3740](#3740))
([ca58fa4](ca58fa4))


### Bug Fixes

* **auth/mcp:** Derive PRM URL from Toolbox URL
([#3765](#3765))
([aa30842](aa30842))
* **config:** Ignore environment variables in YAML comments
([#3807](#3807))
([79aa732](79aa732)),
refs [#3793](#3793)
* **mcp:** Return Tool execution error for invalid input param
([#3799](#3799))
([8120197](8120197))
* **prebuilt/cloud-storage:** Declare tool collections as groups
([#3764](#3764))
([7d468be](7d468be))
* **server/mcp:** Disallow client overriding URL bound parameters
([#3798](#3798))
([f15a9c7](f15a9c7))
* **server:** Avoid a nil-flusher panic in the SSE handler
([#3520](#3520))
([947f42f](947f42f))
* **tools/bigquery:** Keep the provider error classification in
bigquery-execute-sql
([#3738](#3738))
([42570b8](42570b8))
* **tools/looker:** Scope the filters quoting rule to values in query
description
([#3788](#3788))
([78eb0b8](78eb0b8))
* **util:** Convert exponent-form JSON numbers in ConvertNumbers
([#3730](#3730))
([e9713ee](e9713ee))

---
This PR was generated with [Release
Please](https://github.com/googleapis/release-please). See
[documentation](https://github.com/googleapis/release-please#release-please).

---------

Co-authored-by: release-please[bot] <55107282+release-please[bot]@users.noreply.github.com>
Co-authored-by: Yuan Teoh <45984206+Yuan325@users.noreply.github.com>
github-actions Bot pushed a commit that referenced this pull request Aug 14, 2026
🤖 I have created a release *beep* *boop*
---

##
[1.9.0](v1.8.0...v1.9.0)
(2026-08-14)

### Features

* **groups:** Add ttlMs and cacheScope customization to config
([#3805](#3805))
([a5d4947](a5d4947))
* **migrate:** Convert toolset to group kind during migration
([#3704](#3704))
([0adeaa5](0adeaa5))
* **server/mcp:** Introduce generic client extension registry
([#3723](#3723))
([016245c](016245c))
* **skill:** Add review-prs skill for mcp-toolbox
([#3743](#3743))
([5b7bacc](5b7bacc))
* **source/bigquery:** Add apiEndpoint field to override BigQuery API
host ([#3437](#3437))
([4da1600](4da1600))
* **source/databaseinsights:** Add databaseinsights source
([#3461](#3461))
([3b9615d](3b9615d))
* **sources/spanner:** Rename execute_sql_dql to execute_sql_readonly
([#3776](#3776))
([cf5a0c8](cf5a0c8))
* **tools/bigtable:** Add admin lifecycle and listing tools
([#3596](#3596))
([801d589](801d589))
* **tools/bigtable:** Bigtable-list-schemas MCP tool
([#3683](#3683))
([9228c61](9228c61))
* **tools/databaseinsights:** Add Advanced Query Insights tools for
AlloyDB ([#3722](#3722))
([74d18ae](74d18ae))
* **tools/looker:** Add additional tools to allow dashboards to be
modified, and their layouts altered.
([#3597](#3597))
([b2b80fb](b2b80fb))
* **tools:** Add cloud-sql-connect-gce for pg, mysql, mssql
([#3740](#3740))
([ca58fa4](ca58fa4))

### Bug Fixes

* **auth/mcp:** Derive PRM URL from Toolbox URL
([#3765](#3765))
([aa30842](aa30842))
* **config:** Ignore environment variables in YAML comments
([#3807](#3807))
([79aa732](79aa732)),
refs [#3793](#3793)
* **mcp:** Return Tool execution error for invalid input param
([#3799](#3799))
([8120197](8120197))
* **prebuilt/cloud-storage:** Declare tool collections as groups
([#3764](#3764))
([7d468be](7d468be))
* **server/mcp:** Disallow client overriding URL bound parameters
([#3798](#3798))
([f15a9c7](f15a9c7))
* **server:** Avoid a nil-flusher panic in the SSE handler
([#3520](#3520))
([947f42f](947f42f))
* **tools/bigquery:** Keep the provider error classification in
bigquery-execute-sql
([#3738](#3738))
([42570b8](42570b8))
* **tools/looker:** Scope the filters quoting rule to values in query
description
([#3788](#3788))
([78eb0b8](78eb0b8))
* **util:** Convert exponent-form JSON numbers in ConvertNumbers
([#3730](#3730))
([e9713ee](e9713ee))

---
This PR was generated with [Release
Please](https://github.com/googleapis/release-please). See
[documentation](https://github.com/googleapis/release-please#release-please).

---------

Co-authored-by: release-please[bot] <55107282+release-please[bot]@users.noreply.github.com>
Co-authored-by: Yuan Teoh <45984206+Yuan325@users.noreply.github.com> 5de8f13
github-actions Bot pushed a commit to rodineyw/mcp-toolbox that referenced this pull request Aug 14, 2026
🤖 I have created a release *beep* *boop*
---

##
[1.9.0](googleapis/mcp-toolbox@v1.8.0...v1.9.0)
(2026-08-14)

### Features

* **groups:** Add ttlMs and cacheScope customization to config
([googleapis#3805](googleapis#3805))
([a5d4947](googleapis@a5d4947))
* **migrate:** Convert toolset to group kind during migration
([googleapis#3704](googleapis#3704))
([0adeaa5](googleapis@0adeaa5))
* **server/mcp:** Introduce generic client extension registry
([googleapis#3723](googleapis#3723))
([016245c](googleapis@016245c))
* **skill:** Add review-prs skill for mcp-toolbox
([googleapis#3743](googleapis#3743))
([5b7bacc](googleapis@5b7bacc))
* **source/bigquery:** Add apiEndpoint field to override BigQuery API
host ([googleapis#3437](googleapis#3437))
([4da1600](googleapis@4da1600))
* **source/databaseinsights:** Add databaseinsights source
([googleapis#3461](googleapis#3461))
([3b9615d](googleapis@3b9615d))
* **sources/spanner:** Rename execute_sql_dql to execute_sql_readonly
([googleapis#3776](googleapis#3776))
([cf5a0c8](googleapis@cf5a0c8))
* **tools/bigtable:** Add admin lifecycle and listing tools
([googleapis#3596](googleapis#3596))
([801d589](googleapis@801d589))
* **tools/bigtable:** Bigtable-list-schemas MCP tool
([googleapis#3683](googleapis#3683))
([9228c61](googleapis@9228c61))
* **tools/databaseinsights:** Add Advanced Query Insights tools for
AlloyDB ([googleapis#3722](googleapis#3722))
([74d18ae](googleapis@74d18ae))
* **tools/looker:** Add additional tools to allow dashboards to be
modified, and their layouts altered.
([googleapis#3597](googleapis#3597))
([b2b80fb](googleapis@b2b80fb))
* **tools:** Add cloud-sql-connect-gce for pg, mysql, mssql
([googleapis#3740](googleapis#3740))
([ca58fa4](googleapis@ca58fa4))

### Bug Fixes

* **auth/mcp:** Derive PRM URL from Toolbox URL
([googleapis#3765](googleapis#3765))
([aa30842](googleapis@aa30842))
* **config:** Ignore environment variables in YAML comments
([googleapis#3807](googleapis#3807))
([79aa732](googleapis@79aa732)),
refs [googleapis#3793](googleapis#3793)
* **mcp:** Return Tool execution error for invalid input param
([googleapis#3799](googleapis#3799))
([8120197](googleapis@8120197))
* **prebuilt/cloud-storage:** Declare tool collections as groups
([googleapis#3764](googleapis#3764))
([7d468be](googleapis@7d468be))
* **server/mcp:** Disallow client overriding URL bound parameters
([googleapis#3798](googleapis#3798))
([f15a9c7](googleapis@f15a9c7))
* **server:** Avoid a nil-flusher panic in the SSE handler
([googleapis#3520](googleapis#3520))
([947f42f](googleapis@947f42f))
* **tools/bigquery:** Keep the provider error classification in
bigquery-execute-sql
([googleapis#3738](googleapis#3738))
([42570b8](googleapis@42570b8))
* **tools/looker:** Scope the filters quoting rule to values in query
description
([googleapis#3788](googleapis#3788))
([78eb0b8](googleapis@78eb0b8))
* **util:** Convert exponent-form JSON numbers in ConvertNumbers
([googleapis#3730](googleapis#3730))
([e9713ee](googleapis@e9713ee))

---
This PR was generated with [Release
Please](https://github.com/googleapis/release-please). See
[documentation](https://github.com/googleapis/release-please#release-please).

---------

Co-authored-by: release-please[bot] <55107282+release-please[bot]@users.noreply.github.com>
Co-authored-by: Yuan Teoh <45984206+Yuan325@users.noreply.github.com> 5de8f13
github-actions Bot pushed a commit to Jaleel-zhu/genai-toolbox that referenced this pull request Aug 14, 2026
🤖 I have created a release *beep* *boop*
---

##
[1.9.0](googleapis/mcp-toolbox@v1.8.0...v1.9.0)
(2026-08-14)

### Features

* **groups:** Add ttlMs and cacheScope customization to config
([googleapis#3805](googleapis#3805))
([a5d4947](googleapis@a5d4947))
* **migrate:** Convert toolset to group kind during migration
([googleapis#3704](googleapis#3704))
([0adeaa5](googleapis@0adeaa5))
* **server/mcp:** Introduce generic client extension registry
([googleapis#3723](googleapis#3723))
([016245c](googleapis@016245c))
* **skill:** Add review-prs skill for mcp-toolbox
([googleapis#3743](googleapis#3743))
([5b7bacc](googleapis@5b7bacc))
* **source/bigquery:** Add apiEndpoint field to override BigQuery API
host ([googleapis#3437](googleapis#3437))
([4da1600](googleapis@4da1600))
* **source/databaseinsights:** Add databaseinsights source
([googleapis#3461](googleapis#3461))
([3b9615d](googleapis@3b9615d))
* **sources/spanner:** Rename execute_sql_dql to execute_sql_readonly
([googleapis#3776](googleapis#3776))
([cf5a0c8](googleapis@cf5a0c8))
* **tools/bigtable:** Add admin lifecycle and listing tools
([googleapis#3596](googleapis#3596))
([801d589](googleapis@801d589))
* **tools/bigtable:** Bigtable-list-schemas MCP tool
([googleapis#3683](googleapis#3683))
([9228c61](googleapis@9228c61))
* **tools/databaseinsights:** Add Advanced Query Insights tools for
AlloyDB ([googleapis#3722](googleapis#3722))
([74d18ae](googleapis@74d18ae))
* **tools/looker:** Add additional tools to allow dashboards to be
modified, and their layouts altered.
([googleapis#3597](googleapis#3597))
([b2b80fb](googleapis@b2b80fb))
* **tools:** Add cloud-sql-connect-gce for pg, mysql, mssql
([googleapis#3740](googleapis#3740))
([ca58fa4](googleapis@ca58fa4))

### Bug Fixes

* **auth/mcp:** Derive PRM URL from Toolbox URL
([googleapis#3765](googleapis#3765))
([aa30842](googleapis@aa30842))
* **config:** Ignore environment variables in YAML comments
([googleapis#3807](googleapis#3807))
([79aa732](googleapis@79aa732)),
refs [googleapis#3793](googleapis#3793)
* **mcp:** Return Tool execution error for invalid input param
([googleapis#3799](googleapis#3799))
([8120197](googleapis@8120197))
* **prebuilt/cloud-storage:** Declare tool collections as groups
([googleapis#3764](googleapis#3764))
([7d468be](googleapis@7d468be))
* **server/mcp:** Disallow client overriding URL bound parameters
([googleapis#3798](googleapis#3798))
([f15a9c7](googleapis@f15a9c7))
* **server:** Avoid a nil-flusher panic in the SSE handler
([googleapis#3520](googleapis#3520))
([947f42f](googleapis@947f42f))
* **tools/bigquery:** Keep the provider error classification in
bigquery-execute-sql
([googleapis#3738](googleapis#3738))
([42570b8](googleapis@42570b8))
* **tools/looker:** Scope the filters quoting rule to values in query
description
([googleapis#3788](googleapis#3788))
([78eb0b8](googleapis@78eb0b8))
* **util:** Convert exponent-form JSON numbers in ConvertNumbers
([googleapis#3730](googleapis#3730))
([e9713ee](googleapis@e9713ee))

---
This PR was generated with [Release
Please](https://github.com/googleapis/release-please). See
[documentation](https://github.com/googleapis/release-please#release-please).

---------

Co-authored-by: release-please[bot] <55107282+release-please[bot]@users.noreply.github.com>
Co-authored-by: Yuan Teoh <45984206+Yuan325@users.noreply.github.com> 5de8f13
github-actions Bot pushed a commit to pepe57/genai-toolbox that referenced this pull request Aug 14, 2026
🤖 I have created a release *beep* *boop*
---

##
[1.9.0](googleapis/mcp-toolbox@v1.8.0...v1.9.0)
(2026-08-14)

### Features

* **groups:** Add ttlMs and cacheScope customization to config
([googleapis#3805](googleapis#3805))
([a5d4947](googleapis@a5d4947))
* **migrate:** Convert toolset to group kind during migration
([googleapis#3704](googleapis#3704))
([0adeaa5](googleapis@0adeaa5))
* **server/mcp:** Introduce generic client extension registry
([googleapis#3723](googleapis#3723))
([016245c](googleapis@016245c))
* **skill:** Add review-prs skill for mcp-toolbox
([googleapis#3743](googleapis#3743))
([5b7bacc](googleapis@5b7bacc))
* **source/bigquery:** Add apiEndpoint field to override BigQuery API
host ([googleapis#3437](googleapis#3437))
([4da1600](googleapis@4da1600))
* **source/databaseinsights:** Add databaseinsights source
([googleapis#3461](googleapis#3461))
([3b9615d](googleapis@3b9615d))
* **sources/spanner:** Rename execute_sql_dql to execute_sql_readonly
([googleapis#3776](googleapis#3776))
([cf5a0c8](googleapis@cf5a0c8))
* **tools/bigtable:** Add admin lifecycle and listing tools
([googleapis#3596](googleapis#3596))
([801d589](googleapis@801d589))
* **tools/bigtable:** Bigtable-list-schemas MCP tool
([googleapis#3683](googleapis#3683))
([9228c61](googleapis@9228c61))
* **tools/databaseinsights:** Add Advanced Query Insights tools for
AlloyDB ([googleapis#3722](googleapis#3722))
([74d18ae](googleapis@74d18ae))
* **tools/looker:** Add additional tools to allow dashboards to be
modified, and their layouts altered.
([googleapis#3597](googleapis#3597))
([b2b80fb](googleapis@b2b80fb))
* **tools:** Add cloud-sql-connect-gce for pg, mysql, mssql
([googleapis#3740](googleapis#3740))
([ca58fa4](googleapis@ca58fa4))

### Bug Fixes

* **auth/mcp:** Derive PRM URL from Toolbox URL
([googleapis#3765](googleapis#3765))
([aa30842](googleapis@aa30842))
* **config:** Ignore environment variables in YAML comments
([googleapis#3807](googleapis#3807))
([79aa732](googleapis@79aa732)),
refs [googleapis#3793](googleapis#3793)
* **mcp:** Return Tool execution error for invalid input param
([googleapis#3799](googleapis#3799))
([8120197](googleapis@8120197))
* **prebuilt/cloud-storage:** Declare tool collections as groups
([googleapis#3764](googleapis#3764))
([7d468be](googleapis@7d468be))
* **server/mcp:** Disallow client overriding URL bound parameters
([googleapis#3798](googleapis#3798))
([f15a9c7](googleapis@f15a9c7))
* **server:** Avoid a nil-flusher panic in the SSE handler
([googleapis#3520](googleapis#3520))
([947f42f](googleapis@947f42f))
* **tools/bigquery:** Keep the provider error classification in
bigquery-execute-sql
([googleapis#3738](googleapis#3738))
([42570b8](googleapis@42570b8))
* **tools/looker:** Scope the filters quoting rule to values in query
description
([googleapis#3788](googleapis#3788))
([78eb0b8](googleapis@78eb0b8))
* **util:** Convert exponent-form JSON numbers in ConvertNumbers
([googleapis#3730](googleapis#3730))
([e9713ee](googleapis@e9713ee))

---
This PR was generated with [Release
Please](https://github.com/googleapis/release-please). See
[documentation](https://github.com/googleapis/release-please#release-please).

---------

Co-authored-by: release-please[bot] <55107282+release-please[bot]@users.noreply.github.com>
Co-authored-by: Yuan Teoh <45984206+Yuan325@users.noreply.github.com> 5de8f13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

priority: p2 Moderately-important priority. Fix may not be included in next release. release candidate Use label to signal PR should be included in the next release. type: bug Error or flaw in code with unintended results or allowing sub-optimal usage patterns.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants