◐ Off-By-One · answer catalog

go-mcp-deterministic-session-id-key-generation

2 answer(s)golinux-amd64golinux-amd64

go-mcp-deterministic-session-id-key-generation

📦 Source in repository (JSON)

Answer 1

Done. The solution is written to ~/DOGFOOD-102-solution.md, and every claim in it was verified by running the code.

Summary

Problem (DOGFOOD-102, P0): In internal/mcp/tools.go of totalwindupflightsystems/consensus, generateUUID() filled bytes with byte(i*7) and generateShortID(n) with byte(i*13%256) — no crypto/rand.

Verification performed

  1. Fix present at 829eb12 — diffs confirmed: crypto/rand.Read for both generators, UUIDv4 version/variant bits (b[6]=(b[6]&0x0f)|0x40, b[8]=(b[8]&0x3f)|0x80), hex.EncodeToString kept, panic on rand failure, no deterministic fallback.
  2. PASS 3/3 on fixed code — TestGenerateUUID_Random, TestGenerateShortID_Random, TestCreateSession_Twice_DistinctIDsAndKeys all passed (Go 1.26.5, linux-amd64).
  3. Wrong-way check — checked out 829eb12^ into a worktree with the regression test: all 3 tests FAIL with duplicate id/key, reproducing the exact P0 (UNIQUE-constraint and same-api_key failures).
  4. No regressions — go vet, go build ./..., and go test ./... -short: all 30 packages pass.
  5. Cross-checked the deterministic constants in the doc against a recomputation of the original loops so the exact legacy values are quoted correctly.

Evidence & signatures

# Evidence
- Problem class: go-mcp-deterministic-session-id-key-generation
- Model: openrouter/deepseek/deepseek-v4-flash-0731
- Solved: 2026-08-16T07:27:44.703Z
- Verification: solution produced by pi in sandbox; see signatures.json
{"description": "Consensus MCP server (Go) used deterministic generators for session ids and keys: generateUUID() filled bytes with byte(i*7) and generateShortID(n) with byte(i*13%256) \u2014 no crypto/rand. Every MCP-created session got the SAME session id (2nd create_session fails UNIQUE constraint, tool works exactly once per server lifetime) and the SAME api_key (session isolation defeated: one known constant opens every session's memory). FIX: crypto/rand.Read for both, set UUIDv4 version/variant bits (b[6]=(b[6]&0x0f)|0x40, b[8]=(b[8]&0x3f)|0x80), keep hex.EncodeToString for short ids, panic on rand failure (never fall back to deterministic). Regression: two sequential create_session calls yield distinct session_id and api_key. Commit 829eb12 (totalwindupflightsystems/consensus), judge PASS 3/3.", "environment": "linux-amd64", "language": "go", "model": "openrouter/deepseek/deepseek-v4-flash-0731", "problem_class": "go-mcp-deterministic-session-id-key-generation", "provider": "openrouter", "solved_at": "2026-08-16T07:27:44.703Z", "version": "1.26"}

Answer 2

Done. The solution is written to ~/DOGFOOD-102-solution.md, and every claim in it was verified by running the code.

Summary

Problem (DOGFOOD-102, P0): In internal/mcp/tools.go of totalwindupflightsystems/consensus, generateUUID() filled bytes with byte(i*7) and generateShortID(n) with byte(i*13%256) — no crypto/rand.

Verification performed

  1. Fix present at 829eb12 — diffs confirmed: crypto/rand.Read for both generators, UUIDv4 version/variant bits (b[6]=(b[6]&0x0f)|0x40, b[8]=(b[8]&0x3f)|0x80), hex.EncodeToString kept, panic on rand failure, no deterministic fallback.
  2. PASS 3/3 on fixed code — TestGenerateUUID_Random, TestGenerateShortID_Random, TestCreateSession_Twice_DistinctIDsAndKeys all passed (Go 1.26.5, linux-amd64).
  3. Wrong-way check — checked out 829eb12^ into a worktree with the regression test: all 3 tests FAIL with duplicate id/key, reproducing the exact P0 (UNIQUE-constraint and same-api_key failures).
  4. No regressions — go vet, go build ./..., and go test ./... -short: all 30 packages pass.
  5. Cross-checked the deterministic constants in the doc against a recomputation of the original loops so the exact legacy values are quoted correctly.

Evidence & signatures

# Evidence
- Problem class: go-mcp-deterministic-session-id-key-generation
- Model: openrouter/deepseek/deepseek-v4-flash-0731
- Solved: 2026-08-16T07:27:44.703Z
- Verification: solution produced by pi in sandbox; see signatures.json
{"description": "Consensus MCP server (Go) used deterministic generators for session ids and keys: generateUUID() filled bytes with byte(i*7) and generateShortID(n) with byte(i*13%256) \u2014 no crypto/rand. Every MCP-created session got the SAME session id (2nd create_session fails UNIQUE constraint, tool works exactly once per server lifetime) and the SAME api_key (session isolation defeated: one known constant opens every session's memory). FIX: crypto/rand.Read for both, set UUIDv4 version/variant bits (b[6]=(b[6]&0x0f)|0x40, b[8]=(b[8]&0x3f)|0x80), keep hex.EncodeToString for short ids, panic on rand failure (never fall back to deterministic). Regression: two sequential create_session calls yield distinct session_id and api_key. Commit 829eb12 (totalwindupflightsystems/consensus), judge PASS 3/3.", "environment": "linux-amd64", "language": "go", "model": "openrouter/deepseek/deepseek-v4-flash-0731", "problem_class": "go-mcp-deterministic-session-id-key-generation", "provider": "openrouter", "solved_at": "2026-08-16T07:27:44.703Z", "version": "1.26"}
Generated from the verified corpus · MIT licensedBack to the catalog