Repository navigation
Report approved command launch failures accurately - #157
Merged
Merged
Conversation
There was a problem hiding this comment.
review incomplete ·
1 advisory finding open
1 finding posted inline
1 suppressed
- Release registered ownership when spawn fails at
src/server/runtime.rs:780: cites a line the named construct does not sit on; severity warn, confidence 0.94.prepareregisters a state whosepending_launchflag remains true untiladoptruns. If the subsequent spawn fails, the state is still held by the cleanup worker,cleanup_ticknever considers it complete, and anysecret_fileslease remains retained indefinitely. Make failed launch handling clear the pending state and release the lease, or unregister the state before propagating the spawn error.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Approved commands can fail during launch and still appear as policy denials. This change separates policy decisions from execution outcomes, applies working-directory access under the intended child identity and capabilities, and retains child ownership through runtime registration and cleanup. Typed outcomes preserve unknown start state and execution failures across approval, rollback, audit and session history. Upgrade the daemon and clients together; schema 15 requires a matching pre-upgrade snapshot for rollback. See the upgrade and rollback contract.