go-mcp-deterministic-session-id-key-generation
Done. The solution is written to ~/DOGFOOD-102-solution.md, and every claim in it was verified by running the code.
Problem (DOGFOOD-102, P0): In internal/mcp/tools.go of totalwindupflightsystems/consensus, generateUUID() filled bytes with byte(i*7) and generateShortID(n) with byte(i*13%256) — no crypto/rand.
create_session got the same session_id (00070e15-1c23-2a31-383f-464d545b6269); the 2nd insert hit sessions.id UUID PRIMARY KEY → tool worked exactly once per server lifetime.api_key (cs_sk_000d1a27…); one known constant opened every session's memory → session isolation defeated.829eb12 — diffs confirmed: crypto/rand.Read for both generators, UUIDv4 version/variant bits (b[6]=(b[6]&0x0f)|0x40, b[8]=(b[8]&0x3f)|0x80), hex.EncodeToString kept, panic on rand failure, no deterministic fallback.TestGenerateUUID_Random, TestGenerateShortID_Random, TestCreateSession_Twice_DistinctIDsAndKeys all passed (Go 1.26.5, linux-amd64).829eb12^ into a worktree with the regression test: all 3 tests FAIL with duplicate id/key, reproducing the exact P0 (UNIQUE-constraint and same-api_key failures).go vet, go build ./..., and go test ./... -short: all 30 packages pass.# Evidence - Problem class: go-mcp-deterministic-session-id-key-generation - Model: openrouter/deepseek/deepseek-v4-flash-0731 - Solved: 2026-08-16T07:27:44.703Z - Verification: solution produced by pi in sandbox; see signatures.json
{"description": "Consensus MCP server (Go) used deterministic generators for session ids and keys: generateUUID() filled bytes with byte(i*7) and generateShortID(n) with byte(i*13%256) \u2014 no crypto/rand. Every MCP-created session got the SAME session id (2nd create_session fails UNIQUE constraint, tool works exactly once per server lifetime) and the SAME api_key (session isolation defeated: one known constant opens every session's memory). FIX: crypto/rand.Read for both, set UUIDv4 version/variant bits (b[6]=(b[6]&0x0f)|0x40, b[8]=(b[8]&0x3f)|0x80), keep hex.EncodeToString for short ids, panic on rand failure (never fall back to deterministic). Regression: two sequential create_session calls yield distinct session_id and api_key. Commit 829eb12 (totalwindupflightsystems/consensus), judge PASS 3/3.", "environment": "linux-amd64", "language": "go", "model": "openrouter/deepseek/deepseek-v4-flash-0731", "problem_class": "go-mcp-deterministic-session-id-key-generation", "provider": "openrouter", "solved_at": "2026-08-16T07:27:44.703Z", "version": "1.26"}Done. The solution is written to ~/DOGFOOD-102-solution.md, and every claim in it was verified by running the code.
Problem (DOGFOOD-102, P0): In internal/mcp/tools.go of totalwindupflightsystems/consensus, generateUUID() filled bytes with byte(i*7) and generateShortID(n) with byte(i*13%256) — no crypto/rand.
create_session got the same session_id (00070e15-1c23-2a31-383f-464d545b6269); the 2nd insert hit sessions.id UUID PRIMARY KEY → tool worked exactly once per server lifetime.api_key (cs_sk_000d1a27…); one known constant opened every session's memory → session isolation defeated.829eb12 — diffs confirmed: crypto/rand.Read for both generators, UUIDv4 version/variant bits (b[6]=(b[6]&0x0f)|0x40, b[8]=(b[8]&0x3f)|0x80), hex.EncodeToString kept, panic on rand failure, no deterministic fallback.TestGenerateUUID_Random, TestGenerateShortID_Random, TestCreateSession_Twice_DistinctIDsAndKeys all passed (Go 1.26.5, linux-amd64).829eb12^ into a worktree with the regression test: all 3 tests FAIL with duplicate id/key, reproducing the exact P0 (UNIQUE-constraint and same-api_key failures).go vet, go build ./..., and go test ./... -short: all 30 packages pass.# Evidence - Problem class: go-mcp-deterministic-session-id-key-generation - Model: openrouter/deepseek/deepseek-v4-flash-0731 - Solved: 2026-08-16T07:27:44.703Z - Verification: solution produced by pi in sandbox; see signatures.json
{"description": "Consensus MCP server (Go) used deterministic generators for session ids and keys: generateUUID() filled bytes with byte(i*7) and generateShortID(n) with byte(i*13%256) \u2014 no crypto/rand. Every MCP-created session got the SAME session id (2nd create_session fails UNIQUE constraint, tool works exactly once per server lifetime) and the SAME api_key (session isolation defeated: one known constant opens every session's memory). FIX: crypto/rand.Read for both, set UUIDv4 version/variant bits (b[6]=(b[6]&0x0f)|0x40, b[8]=(b[8]&0x3f)|0x80), keep hex.EncodeToString for short ids, panic on rand failure (never fall back to deterministic). Regression: two sequential create_session calls yield distinct session_id and api_key. Commit 829eb12 (totalwindupflightsystems/consensus), judge PASS 3/3.", "environment": "linux-amd64", "language": "go", "model": "openrouter/deepseek/deepseek-v4-flash-0731", "problem_class": "go-mcp-deterministic-session-id-key-generation", "provider": "openrouter", "solved_at": "2026-08-16T07:27:44.703Z", "version": "1.26"}