Repository navigation
🎟️ fix: Never Reuse MicroVM Launch Tokens After a Counter Reset - #9
Merged
TomasPalsson merged 1 commit intoOct 8, 2026
Merged
Conversation
Stateful runtime sessions launch with clientToken sess-<rt>-<generation>. The rtsx:gen counter expires with the session record (max duration + 10 minutes), and the next allocation returned the fixed config-derived seed again. A user returning after an idle night therefore resent the token of their first launch. AWS still remembers it and rejects the reuse with "The provided clientToken was used with different request parameters", even for a byte-identical request. That validation failure is not transient, so the PENDING intent kept the token and every later request replayed it until AWS forgot the token (about 24h in eu-west-1). - Salt the session and hosted-app generation seeds with random bytes so a reset counter always starts at a new generation. Token shape, range and length are unchanged; the allocate script still never lowers a live counter. - Retire a PENDING intent when AWS rejects its token as reused. AWS launched nothing, so the next request allocates a fresh generation. - Tests: registry loss on an unchanged config must not resend the token, and a reuse rejection must not be replayed. Fixtures that used the seed as a constant compute it once; seed tests assert the salt. (cherry picked from commit cfd373d)
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
One squashed commit, cherry-picked (
-x) from the upstream PR LibreChat-AI#322 ontofix/nsjail-no-cgroup-clone. It replaces #8, which had the same change as three commits.The only fork-specific change is in the new registry-loss test. It deletes the hash-tagged keys (
rtsx:sess:{rt_session_1},rtsx:gen:{rt_session_1}) that this branch uses for Redis Cluster. The tree is identical to #8.See LibreChat-AI#322 for the root cause, the fix and the test evidence. Summary: after
rtsx:genexpires, the fixed config-derived seed re-issued a session's first MicroVM clientToken. AWS still remembered that token and rejected it as "used with different request parameters". The non-transient rejection was then replayed on every request. The fix salts the seed, and retires a PENDING intent whose token AWS rejected as reused.Verification with bun 1.3.14:
bun test src/sandbox-backend/lambda-microvm.test.ts src/hosted-app: 158 pass, 0 fail.Expected: not "sess-rt_session_1-3972529254911613".