Skip to content

fix(service): never reuse a MicroVM launch token after a counter reset - #8

Closed
TomasPalsson wants to merge 3 commits into
fix/nsjail-no-cgroup-clonefrom
fix/clienttoken-reuse
Closed

TomasPalsson wants to merge 3 commits into
fix/nsjail-no-cgroup-clonefrom
fix/clienttoken-reuse

Conversation

@TomasPalsson

@TomasPalsson TomasPalsson commented Oct 8, 2026 •

Copy link
Copy Markdown

Replaced by #9: the same change as one squashed commit, cherry-picked from LibreChat-AI#322.

A stateful runtime session idle longer than the rtsx:gen TTL (8h10m) gets
the fixed config-derived seed generation again, so its next launch resends
sess-<rt>-<seed>, the token its first launch used. AWS still remembers that
token and rejects it with "The provided clientToken was used with different
request parameters" (HTTP 400, non-transient). The PENDING intent then keeps
that token and every later request replays it.

Red run (bun 1.3.14, the CI version) on unfixed ad213ba:

$ bun test src/sandbox-backend/lambda-microvm.test.ts -t "never reissues|stops replaying"
  expect(secondToken).not.toBe(firstToken)
  Expected: not "sess-rt_session_1-3972529254911613"
  expect(tokens[2]).not.toBe(poisoned)
  Expected: not "sess-rt_session_1-3972529254911613"
  0 pass, 2 fail
exit=1
Stateful runtime sessions launch with clientToken sess-<rt>-<generation>.
The rtsx:gen counter expires after 8h10m idle, and the next allocation
returned the fixed config-derived seed again, so a user returning the next
morning resent the token of their first launch. AWS still remembers it and
rejects the reuse with "The provided clientToken was used with different
request parameters", even for an identical request body. That validation
failure is non-transient, so the PENDING intent kept the token and every
later request replayed it until AWS forgot the token (~24h in eu-west-1).

- Salt the session and hosted-app generation seeds with random bytes, so a
  reset counter always starts at a new generation. Token shape is unchanged.
- Retire a PENDING intent when AWS rejects its token as reused; AWS launched
  nothing, so the next request allocates a fresh generation.

Tests that used the seed as a fixed fixture value now compute it once; the
hookless-launch test checks the token shape instead of the old fixed seed.
…ts generation

Review follow-up: two seed assertions became true by chance once seeds were salted; they now check the salt. Moves the retire JSDoc back above its method.
@TomasPalsson

Copy link
Copy Markdown
Author

Replaced by #9 (one squashed commit, same tree).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant