a6fdadfcee
Port from openclaw/openclaw#123194: a hostile or misbehaving remote MCP server could stream an unbounded HTTP catalog/tool-result body that the MCP SDK buffers and JSON-parses before any of Hermes' post-parse limits (resource cap, tool-result truncation) run. New _make_mcp_body_cap_transport wraps the owned httpx AsyncClient's transport on the Streamable HTTP (mcp >= 1.24) and SSE paths: - finite HTTP bodies capped at 10 MiB (Content-Length rejected up front, streamed bodies capped chunk-by-chunk); - each SSE event capped at 10 MiB, with accounting reset at completed event boundaries so long-lived streams/keepalives are unlimited; - violations raise httpx.ReadError naming the byte cap, handled by the existing transport teardown/reconnect path (#66092). verify/cert now live on the inner AsyncHTTPTransport (client-level TLS kwargs are inert once a custom transport is passed); the SSE httpx_client_factory is always injected so the cap applies with default TLS too. Legacy mcp < 1.24 path (SDK-internal client, no hook) stays uncapped — same degradation as strict_redirect_headers.