Mark bypass queue finding resolved
This commit is contained in:
parent
1284a83b52
commit
6a2018545b
|
|
@ -174,7 +174,11 @@ Process GC removes exited processes only after output has been read. An abandone
|
|||
|
||||
**Remediation:** add an absolute retention TTL independent of `LastRead`, plus output-size limits.
|
||||
|
||||
## Medium and lower findings
|
||||
The following medium finding was verified fixed in commit `1284a83`:
|
||||
|
||||
- **M8. Bypass queue retains cancelled requests** — cancellation now removes the request from the active set, and `NextPending` discards stale queue entries.
|
||||
|
||||
The remaining medium and lower findings are listed below.
|
||||
|
||||
### M1. Workflow and prompt goroutines are unbounded
|
||||
|
||||
|
|
@ -246,13 +250,9 @@ A wildcard event subscription is created with `context.Background()`. Rebuilding
|
|||
|
||||
### M8. Bypass queue retains cancelled requests
|
||||
|
||||
**Evidence:** `cmd/toolsrv/internal/bypass/bypass.go:59-85`.
|
||||
**Status:** Fixed in `1284a83`.
|
||||
|
||||
Cancellation deletes the request from the map but leaves it in the pending channel.
|
||||
|
||||
**Impact:** cancelled requests consume queue slots and can block valid bypass requests.
|
||||
|
||||
**Remediation:** make cancellation observable to the pending consumer and discard cancelled entries before presenting them for approval.
|
||||
Cancellation removes the request from the active set. `NextPending` discards stale cancelled entries before presenting requests for approval.
|
||||
|
||||
### M9. Concurrent bypass resolution can panic
|
||||
|
||||
|
|
|
|||
Loading…
Reference in New Issue