aws / aws/aws-lambda-rust-runtime

Add Lambda-Runtime-Invocation-Id header support for cross-wiring protection

未关闭
#1,155 0 条评论 1 个 reaction 已指派 1 人 已被 @darklight3it 认领 在 GitHub 查看
主要语言
Rust
星标
3.6k
派生
396
PR 合并指标
30 天内没有已合并 PR

描述

## Summary

Lambda now sends a `Lambda-Runtime-Invocation-Id` header on `/runtime/invocation/next` responses. Runtimes should echo this header back on `/runtime/invocation/{requestId}/response` and `/runtime/invocation/{requestId}/error` to enable RAPID to detect and reject stale responses from timed-out invocations.

## Problem

When an invoke times out, the runtime process continues running. If a new invoke arrives with the same `requestId` (customer-provided or retried by upstream), RAPID accepts it. The still-running old invocation eventually posts its response, and RAPID delivers the wrong response to the new invoke (cross-wiring).

This affects both On-Demand and Lambda Managed Instances (LMI), and Rust is a supported LMI runtime.

## What needs to change

1. **Parse** `Lambda-Runtime-Invocation-Id` from the `/next` response headers (optional — may be absent with older RAPID)
2. **Store** it alongside the invocation context
3. **Echo** it as a request header on `/response` and `/error`
4. If the header is absent from `/next`, don't send it back (backward compat)

## Backward Compatibility

- Old RAPID (doesn't send the header) + New RIC (no header to echo) → no change ✅
- New RAPID (sends the header) + Old RIC (doesn't echo) → RAPID skips validation ✅
- New RAPID + New RIC → header echoed, RAPID validates match ✅

## Reference Implementations

- Python RIC: https://github.com/aws/aws-lambda-python-runtime-interface-client/pull/214

贡献指南

打开贡献指南

评估

这个 Issue 还没有评估数据。

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。