diff --git a/src/server/admin.rs b/src/server/admin.rs index 9d1364b..0f4533b 100644 --- a/src/server/admin.rs +++ b/src/server/admin.rs @@ -3119,23 +3119,14 @@ async fn approve_held_access( return match handle_approve_claimed(server, caller, handle, snapshot).await { AdminResponse::GateAction { message, - policy, - execution_failure, - exit_code, + policy: None, + execution_failure: None, + exit_code: None, .. } => AccessDecisionResult { request: handle.to_string(), - success: policy.as_ref().is_none_or(|p| p.allowed) - && execution_failure.is_none() - && exit_code.is_none_or(|code| code == 0), - state: if policy.as_ref().is_some_and(|p| !p.allowed) { - "denied" - } else if execution_failure.is_some() { - "exec_failed" - } else { - "approved" - } - .to_string(), + success: true, + state: "approved".to_string(), target: None, remaining_uses: None, use_policy: "unavailable".to_string(), diff --git a/src/server/execute.rs b/src/server/execute.rs index 298b82e..63b2996 100644 --- a/src/server/execute.rs +++ b/src/server/execute.rs @@ -3260,6 +3260,9 @@ fn spawn_owned_command( identity: Option<&PreparedExecIdentity>, secret_files: Option, ) -> std::result::Result { + // Install the drop guard before fallible setup or spawn. Drop cancels an + // unstarted launch and releases its lease; after adoption, the cleanup + // worker retains the lease until reaping succeeds. let child = ManagedChild { ownership: ChildOwnership::prepare(secret_files).map_err(|error| { LaunchError::from_io(