Skip to content

fix: source_events_per_minute=0 must block all events, not disable th… - #23

Open
manishmcsa01-cmd wants to merge 1 commit into
theschoolofai:mainfrom
manishmcsa01-cmd:fix/zero-source-rate-limit-bypass
Open

manishmcsa01-cmd wants to merge 1 commit into
theschoolofai:mainfrom
manishmcsa01-cmd:fix/zero-source-rate-limit-bypass

Conversation

@manishmcsa01-cmd

Copy link
Copy Markdown

…e limit

Bug: In AutonomyGovernor.admit_event(), the guard:
if self.source_events_per_minute > 0:
skips the rate limit entirely when the value is 0. An operator setting source_events_per_minute=0 intends 'block all events from any source', but actually gets 'allow unlimited events' -- the control does not hold.

This is exactly the kind of bug the session warns about: a ceiling that resets to infinity at the boundary value.

Fix: Change the guard to >= 0 and handle the zero case explicitly by refusing immediately with a clear reason.

Test: test_zero_source_rate_limit_blocks_all_events fails before this change (verdict.admitted is True) and passes after (admitted is False).

…e limit

Bug: In AutonomyGovernor.admit_event(), the guard:
    if self.source_events_per_minute > 0:
skips the rate limit entirely when the value is 0. An operator setting
source_events_per_minute=0 intends 'block all events from any source',
but actually gets 'allow unlimited events' -- the control does not hold.

This is exactly the kind of bug the session warns about: a ceiling that
resets to infinity at the boundary value.

Fix: Change the guard to >= 0 and handle the zero case explicitly by
refusing immediately with a clear reason.

Test: test_zero_source_rate_limit_blocks_all_events fails before this
change (verdict.admitted is True) and passes after (admitted is False).
@theschoolofai

Copy link
Copy Markdown
Owner

Session 16 — graded ✅

Score: +100.

source_events_per_minute=0 disabled the limiter instead of blocking every event, so the strictest setting was the most permissive. A falsy-zero defect on a security control.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants