Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

Closing a product leaves its SSO request live on the paired host

Open
#987 0 comments 0 reactions 1 assignee View on GitHub

Maintainers usually reply within 1 day

@decrypto21 is already working on this.

Since Sep 25, 2026.

Assessment

This issue has not been assessed yet.

Description

Closing a product leaves its SSO request live on the paired host

Follow-up to #263.

Problem

ProductRuntime::dispose() (truapi-server/src/host_core.rs:1551) aborts in-flight calls instead of cancelling them. The token never fires, so withdraw_request (pairing_host/sso_channel.rs:314) never runs and no SSO Cancel is sent. The phone keeps the prompt, and approving it still allocates or signs.

Reproduction

  1. A pairing host stays up; a product connected to it calls resourceAllocation.request. The phone shows the sheet.
  2. Kill the product process.
  3. The phone receives nothing; the sheet stays up.

An explicit abort() on the same setup closes the sheet within about 1 s.

Fix

  • The dispatcher fires every in-flight token with CancellationReason::Cancelled.
  • dispose() calls that first, then aborts after AUTHORITY_CANCEL_UNWIND_GRACE.
  • Test: dispose mid-SSO-call and assert a Cancel statement is submitted.

Related: #926, #933.

Dominant language
Swift
Stars
10
Forks
3
Avg merge
1d 10h
Merged PRs (30d)
201

Getting set up

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from paritytech/host-rust-core

All issues in paritytech/host-rust-core

Similar issues

More Swift issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.