Repository navigation
fix(server): a desktop left running past a day keeps its local backend credential - #16257
juliusmarminge wants to merge 1 commit into
Conversation
…d credential The desktop hands each backend one bootstrap token for the life of the desktop process, but the server expired that grant after 24 hours. After that the renderer's topology poll re-presented the dead token to secondary (WSL) backends every few seconds forever: ~100k `Unknown bootstrap credential` failures a day in prod traces, from a handful of long-running desktops. The grant now lives as long as the server process that was launched with it. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
ApprovabilityVerdict: Not approved Macroscope's review found this PR not approvable — This fix keeps the administrative desktop bootstrap credential valid for the entire backend process, allowing long-running desktops to re-authenticate after a day. Because it changes an existing authentication behavior and extends the default credential lifetime, the security and product-default implications warrant human review. Notes:
You can add or adjust custom eligibility rules. Learn more. |
Thread transfer impact✅ Thread transfer remains within every enforced ceiling.
Baseline: Scenario and decoded snapshot size10 historical turns, 5 command tools per turn, 878.9 KiB retained MCP result per historical turn, and a 1.05 MiB retained result in the measured turn.
Updated in place by a trusted workflow. PR artifacts are strictly validated and never executed. |
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
📒 Files selected for processing (2)
Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 0 remain after this review. 📝 WalkthroughWalkthroughThe desktop bootstrap grant now has no expiry during the server process lifetime. Seeded-grant expiration checks only apply when a grant has an expiry. The test verifies successful consumption after 30 days. ChangesDesktop bootstrap grant lifetime
Priority: ⬆️ High Estimated code review effort: 2 (Simple) | ~10 minutes Change: Bug fix Merge Risk: ⚪ Minimal · up to The grant remains usable beyond 30 days, avoiding expiry failures for long-running desktops. The inspected consumer and restart behavior reveal no actionable merge blocker. 🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
Full details: Description checkResolution Add a Scope and approval section with the issue or maintainer approval, or explain why this focused fix qualifies without prior approval. Add a Verification section with the focused test or manual check, the observed result, and anything not checked.
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
🧰 Additional context used📚 Code guidelines (1)Comment |
|
Closing in favor of a stack that keeps the 24h expiry on the desktop bootstrap token: the renderer stops re-presenting a rejected token, the desktop rotates the token before it expires, and the renderer renews its session without the bootstrap token. Removing the expiry would have let a leaked admin-scoped token mint sessions for as long as the backend runs. |
Problem
Prod traces show about 100k
PairingGrantStore.consume: Unknown bootstrap credentialfailures a day, followed byServer authentication credential is invalid. The count has been rising since 10-03, and 885k accumulated over 15 days. About 92% come from roughly 100 long-lived client loops. The worst one has failed once every 4s since 2026-10-03, producing 53.8k errors.How it happens:
DesktopBackendConfiguration.ts) and hands it to every backend, including the parallel WSL one.consumereturned "expired" once, deleted the grant, and returned "Unknown" from then on.apps/web/src/connection/platform.ts) and re-exchanges the same token whenever it has no fresh cached registration. So a desktop running for more than a day kept hammering its WSL backend with a dead credential and never connected to it.Fix
The
desktop-bootstrapgrant no longer has an expiry; it lives exactly as long as the server process that was launched with it. That was the intent of the original comment ("Letting it live for the lifetime of the backend process"). The token only travels over the trusted fd3/stdin channel and is already unlimited-use.BootstrapGrant.expiresAtbecomes nullable; nothing reads it afterconsume.The test that expected expiry after the TTL now asserts the grant is still valid after 30 days.
Claude Opus 5.5 via Claude Code
🤖 Generated with Claude Code