Skip to content

registry

User key registry for Stained Glass Output Protection in vLLM, shared across all vLLM processes.

Warning

Under almost no circumstances should you need to import this module directly. If stainedglass_output_protection is installed, vLLM loads it automatically via the vllm.general_plugins entry point.

Classes:

Name Description
SessionKey

A request's shared AES key and the cipher built from it.

Functions:

Name Description
get_shared_registry

Get the shared registry for managing keys across vLLM processes.

remove_key

Remove a key from the registry by first marking it as a sentinel allowing existing generation steps to not crash and then remove

SessionKey

Bases: NamedTuple

A request's shared AES key and the cipher built from it.

The cipher is built once per request, when the key is derived, because constructing an AESGCM expands the AES key schedule and the encryption path runs once per generated token. The raw bytes are retained alongside it: they remain the canonical form of the key.

Attributes:

Name Type Description
cipher AESGCM

Cipher bound to key, reused for every token of the request.

key bytes

The shared AES key derived from the x25519 exchange.

cipher instance-attribute

cipher: AESGCM

Cipher bound to key, reused for every token of the request.

key instance-attribute

key: bytes

The shared AES key derived from the x25519 exchange.

get_shared_registry

get_shared_registry() -> MutableMapping[
    str, SessionKey | None
]

Get the shared registry for managing keys across vLLM processes.

This function provides access to a shared dictionary that maps string keys to optional byte values.

Returns:

Type Description
MutableMapping[str, SessionKey | None]

A mutable mapping representing the shared key registry.

remove_key async

remove_key(
    request_id: str,
    shared_registry: MutableMapping[str, SessionKey | None],
) -> None

Remove a key from the registry by first marking it as a sentinel allowing existing generation steps to not crash and then remove after 60 seconds.

Parameters:

Name Type Description Default

request_id

str

Request to remove from the registry.

required

shared_registry

MutableMapping[str, SessionKey | None]

Shared registry from which to delete key.

required