Skip to content

fix(server): a desktop left running past a day keeps its local backend credential - #16257

Closed
juliusmarminge wants to merge 1 commit into
mainfrom
t3/desktop-bootstrap-no-expiry
Closed

juliusmarminge wants to merge 1 commit into
mainfrom
t3/desktop-bootstrap-no-expiry

Conversation

@juliusmarminge

@juliusmarminge juliusmarminge commented Oct 5, 2026 •

Copy link
Copy Markdown
Member

Problem

Prod traces show about 100k PairingGrantStore.consume: Unknown bootstrap credential failures a day, followed by Server authentication credential is invalid. The count has been rising since 10-03, and 885k accumulated over 15 days. About 92% come from roughly 100 long-lived client loops. The worst one has failed once every 4s since 2026-10-03, producing 53.8k errors.

How it happens:

  • The desktop creates one bootstrap token per desktop process (DesktopBackendConfiguration.ts) and hands it to every backend, including the parallel WSL one.
  • The server seeded that token as an unlimited-use grant that expired after 24h.
  • After that, consume returned "expired" once, deleted the grant, and returned "Unknown" from then on.
  • The renderer polls the secondary-backend topology every 3s (apps/web/src/connection/platform.ts) and re-exchanges the same token whenever it has no fresh cached registration. So a desktop running for more than a day kept hammering its WSL backend with a dead credential and never connected to it.

Fix

The desktop-bootstrap grant no longer has an expiry; it lives exactly as long as the server process that was launched with it. That was the intent of the original comment ("Letting it live for the lifetime of the backend process"). The token only travels over the trusted fd3/stdin channel and is already unlimited-use. BootstrapGrant.expiresAt becomes nullable; nothing reads it after consume.

The test that expected expiry after the TTL now asserts the grant is still valid after 30 days.

Claude Opus 5.5 via Claude Code

🤖 Generated with Claude Code


Devin Review

…d credential

The desktop hands each backend one bootstrap token for the life of the
desktop process, but the server expired that grant after 24 hours. After
that the renderer's topology poll re-presented the dead token to secondary
(WSL) backends every few seconds forever: ~100k
`Unknown bootstrap credential` failures a day in prod traces, from a
handful of long-running desktops. The grant now lives as long as the
server process that was launched with it.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@github-actions github-actions Bot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. size:S 10-29 changed lines (additions + deletions). labels Oct 5, 2026
@macroscopeapp

macroscopeapp Bot commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Not approved

Macroscope's review found this PR not approvable — This fix keeps the administrative desktop bootstrap credential valid for the entire backend process, allowing long-running desktops to re-authenticate after a day. Because it changes an existing authentication behavior and extends the default credential lifetime, the security and product-default implications warrant human review.

Notes:

  • Diff unchanged. Approvability was decided on eligibility alone.

You can add or adjust custom eligibility rules. Learn more.

@juliusmarminge juliusmarminge added the macroscope-review Opt PRs made by unvouched contributors in for Macroscope review. Vouched contributors auto-reviews label Oct 5, 2026
@github-actions

github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

Thread transfer impact

✅ Thread transfer remains within every enforced ceiling.

Provider Metric Main baseline This PR Impact PR ceiling
Codex Total thread wire 5.0 KiB 5.0 KiB 0 B (0.0%) 6.8 KiB ✅
Codex Thread snapshot wire 3.8 KiB 3.8 KiB 0 B (0.0%) 4.9 KiB ✅
Codex Live turn WebSocket wire 1.2 KiB 1.2 KiB 0 B (0.0%) 2.0 KiB ✅
Codex Live turn WebSocket decoded 20.9 KiB 20.9 KiB 0 B (0.0%) 29.3 KiB ✅
Codex Live turn messages 2 2 0 (0.0%) 8 ✅
Claude Total thread wire 5.0 KiB 5.0 KiB 0 B (0.0%) 6.8 KiB ✅
Claude Thread snapshot wire 3.8 KiB 3.8 KiB 0 B (0.0%) 4.9 KiB ✅
Claude Live turn WebSocket wire 1.2 KiB 1.2 KiB 0 B (0.0%) 2.0 KiB ✅
Claude Live turn WebSocket decoded 21.2 KiB 21.2 KiB 0 B (0.0%) 29.3 KiB ✅
Claude Live turn messages 2 2 0 (0.0%) 8 ✅

Baseline: ca95267 · PR result: 5e7f7e3 · Source CI: success

Scenario and decoded snapshot size

10 historical turns, 5 command tools per turn, 878.9 KiB retained MCP result per historical turn, and a 1.05 MiB retained result in the measured turn.

  • Codex decoded thread snapshot: 108.5 KiB
  • Claude decoded thread snapshot: 108.8 KiB

Updated in place by a trusted workflow. PR artifacts are strictly validated and never executed.

@coderabbitai

coderabbitai Bot commented Oct 5, 2026

Copy link
Copy Markdown

Review in Change Stack →

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Repository: pingdotgg/t3code/.coderabbit.yaml
  • Review profile: CHILL
  • Plan: Team
  • Run ID: 989f6c10-09c8-4cc0-8a44-f56ae47172bb
📥 Commits

Reviewing files that changed from the base of the PR and between ca95267 and 5e7f7e3.

📒 Files selected for processing (2)
  • apps/server/src/auth/PairingGrantStore.test.ts
  • apps/server/src/auth/PairingGrantStore.ts

Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

The desktop bootstrap grant now has no expiry during the server process lifetime. Seeded-grant expiration checks only apply when a grant has an expiry. The test verifies successful consumption after 30 days.

Changes

Desktop bootstrap grant lifetime

Layer / File(s) Summary
Seed and consume desktop bootstrap grants
apps/server/src/auth/PairingGrantStore.ts, apps/server/src/auth/PairingGrantStore.test.ts
The desktop bootstrap grant is seeded with a null expiry. Seeded grants expire only when their expiry is non-null. The test verifies that the grant can be consumed after 30 days.

Priority: ⬆️ High

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Bug fix

Merge Risk: ⚪ Minimal · up to 5e7f7

The grant remains usable beyond 30 days, avoiding expiry failures for long-running desktops. The inspected consumer and restart behavior reveal no actionable merge blocker.

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Description check ⚠️ Warning The description explains the problem and the fix in detail, but it omits the required Scope and approval section and does not report verification steps or results. Add a Scope and approval section with the issue or maintainer approval, or explain why this focused fix qualifies without prior approval. Add a Verification section with the focused test or manual check, the observed result, and anything no…
✅ Passed checks (4 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly describes the fix: a desktop running longer than a day keeps its local backend credential. It is specific and related to the main change.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 2…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Full details: Description check

Resolution

Add a Scope and approval section with the issue or maintainer approval, or explain why this focused fix qualifies without prior approval. Add a Verification section with the focused test or manual check, the observed result, and anything not checked.

  • Fix all pre-merge checks with AI
✨ Finishing Touches
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts
🧰 Additional context used
📚 Code guidelines (1)
docs/internals/effect-services.md — auto-discovered

Comment @coderabbitai help to get the list of available commands.

@juliusmarminge

Copy link
Copy Markdown
Member Author

Closing in favor of a stack that keeps the 24h expiry on the desktop bootstrap token: the renderer stops re-presenting a rejected token, the desktop rotates the token before it expires, and the renderer renews its session without the bootstrap token. Removing the expiry would have let a leaked admin-scoped token mint sessions for as long as the backend runs.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

macroscope-review Opt PRs made by unvouched contributors in for Macroscope review. Vouched contributors auto-reviews size:S 10-29 changed lines (additions + deletions). vouch:trusted PR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant