Remediator: early-return when mark_resolving returns None (incident closed mid-flight) #2
Labels
No labels
correctness
coverage
milestone:M4
polish
security
tech-debt
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
public/warden#2
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
M3 review (deferred, low-probability). In
remediate.RemediatorTier 0, if the incident closes between OPENED and the daemon thread running,store.mark_resolving(fp)returns None; the code falls back to the staleinc.idand still fires the capability exec (latermark_resolvedno-ops). The per-fingerprint gate makes it rare, but a deterministic fix should not run against an already-closed incident. Fix: early-return (skip exec) whenmark_resolvingis None.Fixed in v0.18.0 (M6-hardening, commit
e8d5348).Remediator._tier0now early-returns{outcome: no_action, reason: incident_closed_before_exec}whenmark_resolvingreturns None — the capability exec no longer fires against an already-closed incident, no escalation, gate released exactly once. Covered by a direct test.