Remediator: early-return when mark_resolving returns None (incident closed mid-flight) #2

Closed
opened 2026-09-10 12:20:57 +00:00 by jmz · 1 comment
Owner

M3 review (deferred, low-probability). In remediate.Remediator Tier 0, if the incident closes between OPENED and the daemon thread running, store.mark_resolving(fp) returns None; the code falls back to the stale inc.id and still fires the capability exec (later mark_resolved no-ops). The per-fingerprint gate makes it rare, but a deterministic fix should not run against an already-closed incident. Fix: early-return (skip exec) when mark_resolving is None.

**M3 review (deferred, low-probability).** In `remediate.Remediator` Tier 0, if the incident closes between OPENED and the daemon thread running, `store.mark_resolving(fp)` returns None; the code falls back to the stale `inc.id` and still fires the capability exec (later `mark_resolved` no-ops). The per-fingerprint gate makes it rare, but a deterministic fix should not run against an already-closed incident. **Fix:** early-return (skip exec) when `mark_resolving` is None.
Author
Owner

Fixed in v0.18.0 (M6-hardening, commit e8d5348). Remediator._tier0 now early-returns {outcome: no_action, reason: incident_closed_before_exec} when mark_resolving returns None — the capability exec no longer fires against an already-closed incident, no escalation, gate released exactly once. Covered by a direct test.

Fixed in v0.18.0 (M6-hardening, commit e8d5348). `Remediator._tier0` now early-returns `{outcome: no_action, reason: incident_closed_before_exec}` when `mark_resolving` returns None — the capability exec no longer fires against an already-closed incident, no escalation, gate released exactly once. Covered by a direct test.
jmz closed this issue 2026-09-10 16:17:42 +00:00
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
public/warden#2
No description provided.