Summary
Rust session routing snapshots a per-session sender under the router lock, then enqueues outside the lock. When a canceled startup or session is replaced using the same SessionId, a concurrent JSON-RPC request or session.event notification can be sent to the stale registration after the replacement has become current.
Expected behavior
Routing should be serialized with registration replacement: a delivery should go to the registration current when it is enqueued, or be dropped if no registration exists. Session-ID reuse and the wire protocol should remain unchanged.
Scope
The affected path is the upstream Rust SDK router in rust/src/router.rs; no changes to the vendored SDK or github/github-app are involved.
Summary
Rust session routing snapshots a per-session sender under the router lock, then enqueues outside the lock. When a canceled startup or session is replaced using the same
SessionId, a concurrent JSON-RPC request orsession.eventnotification can be sent to the stale registration after the replacement has become current.Expected behavior
Routing should be serialized with registration replacement: a delivery should go to the registration current when it is enqueued, or be dropped if no registration exists. Session-ID reuse and the wire protocol should remain unchanged.
Scope
The affected path is the upstream Rust SDK router in
rust/src/router.rs; no changes to the vendored SDK orgithub/github-appare involved.