Mark bypass queue finding resolved

This commit is contained in:
Ollie Agent 2026-08-18 07:03:02 +02:00
parent 1284a83b52
commit 6a2018545b
1 changed files with 7 additions and 7 deletions

View File

@ -174,7 +174,11 @@ Process GC removes exited processes only after output has been read. An abandone
**Remediation:** add an absolute retention TTL independent of `LastRead`, plus output-size limits.
## Medium and lower findings
The following medium finding was verified fixed in commit `1284a83`:
- **M8. Bypass queue retains cancelled requests** — cancellation now removes the request from the active set, and `NextPending` discards stale queue entries.
The remaining medium and lower findings are listed below.
### M1. Workflow and prompt goroutines are unbounded
@ -246,13 +250,9 @@ A wildcard event subscription is created with `context.Background()`. Rebuilding
### M8. Bypass queue retains cancelled requests
**Evidence:** `cmd/toolsrv/internal/bypass/bypass.go:59-85`.
**Status:** Fixed in `1284a83`.
Cancellation deletes the request from the map but leaves it in the pending channel.
**Impact:** cancelled requests consume queue slots and can block valid bypass requests.
**Remediation:** make cancellation observable to the pending consumer and discard cancelled entries before presenting them for approval.
Cancellation removes the request from the active set. `NextPending` discards stale cancelled entries before presenting requests for approval.
### M9. Concurrent bypass resolution can panic