🤖 bug: a rolled-back Coder creation leaves its provisioning session (and a retry can reuse an expired token)
メンテナーはふだん 1 日以内に返信
まだ誰も着手していません。
評価
- 難易度
- 4/5
- 見積もり時間
- 3〜5日
- 初心者へのやさしさ
- 55/100
- issue の種類
- バグ
- 明瞭さ
- おおむね明確
- 活発さ
- 活発
- 技術スタック
- typescript
- 領域
- backend
調査の方向性
Trace the rollback path from WorkspaceService.abortUnsanitizedCreation and compare it with CoderSSHRuntime.finalizeConfig, postCreateSetup, and the existing validateBeforePersist disposal. Confirm how provisioningSessions are keyed and aged, then verify that a rollback disposes the session and that a later retry cannot reuse an expired token.
索引モデルが issue の本文から書いたものです。
説明
Problem
A new-mode Coder creation (coder.existingWorkspace unset) creates a provisioning session in CoderSSHRuntime.finalizeConfig (coderService.ensureProvisioningSession(workspaceName), which runs coder tokens create --lifetime 5m). The session is consumed only by postCreateSetup (takeProvisioningSession), which runs in init after registration. When the creation rolls back before init (for example, the registration write rejects, #4745), nothing disposes it:
- The session stays in
CoderService.provisioningSessionsfor the process lifetime, and the token stays on the Coder deployment until it expires (5 min). - A retry with the same Coder workspace name gets the stale session back:
ensureProvisioningSessionreturns an existing entry without checking its age, so a retry more than 5 minutes later may hand an expired token tocoderService.createWorkspace.
validateBeforePersist already disposes the session when it refuses (disposeProvisioningSession); the registration rollback in WorkspaceService.abortUnsanitizedCreation does not.
Proposal
Dispose the provisioning session when a new-mode Coder creation rolls back before init (a runtime hook the rollback can call), and/or have ensureProvisioningSession replace a session older than its token lifetime.
Found while closing #4775 item 2 (SSH, Docker and Coder creations otherwise provision nothing before init). Pre-existing.
Generated with xum • Model: anthropic:claude-opus-5-5 • Thinking: high
- 主要言語
- TypeScript
- スター
- 2k
- フォーク
- 139
- 平均マージ
- 6時間 35分
- マージ済み PR(30日)
- 819
環境構築
- Dockerfile または Docker Compose ファイルあり
- プルリクエストのテンプレートなし
- コントリビューションガイドなし
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
coder/xum のほかの issue
-
approved
難易度 2/5 1〜3時間 初心者へのやさしさ 82/100
メンテナーはふだん 1 日以内に返信
-
🤖 Delegated-turn delivery and peer-limit follow-ups from #5311 and #5327対応中かも @ThomasK33 が今日担当しました。 オープン
メンテナーはふだん 1 日以内に返信
-
🤖 Compaction follow-up dispatch: remaining follow-ups from #5313対応中かも @ThomasK33 が今日担当しました。 オープン
メンテナーはふだん 1 日以内に返信
-
🤖 Concurrency primitive and fileLock hazards found by the formal models (#5309, #5319 follow-ups)対応中かも @ThomasK33 が今日担当しました。 オープン
メンテナーはふだん 1 日以内に返信
-
🤖 History persistence follow-ups from the formal-verification fixes (#5312, #5316, #5318)対応中かも @ThomasK33 が今日担当しました。 オープン
メンテナーはふだん 1 日以内に返信
似ている issue
-
area/frontend good first issue kind/cooldown
難易度 2/5 1〜3時間 初心者へのやさしさ 78/100
メンテナーはふだん 1 日以内に返信
-
bug
難易度 2/5 1〜3時間 初心者へのやさしさ 85/100
voidzero-dev/oxc-angular-compiler#511 ·
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 78/100
langchain-ai/deepagentsjs#898 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
-
難易度 1/5 1時間未満 初心者へのやさしさ 92/100
anomalyco/models.dev#8509 · コメント 2 件 ·
メンテナーはふだん 1 日以内に返信
-
bug documentation P2 UI/UX
難易度 2/5 1〜3時間 初心者へのやさしさ 85/100
メンテナーはふだん 1 日以内に返信