Define fail open#1587
Open
Chigybillionz wants to merge 9 commits into
Open
Conversation
Chigybillionz
force-pushed
the
define-fail-open
branch
from
July 20, 2026 12:56
7adefea to
7baa5c3
Compare
Chigybillionz
force-pushed
the
define-fail-open
branch
from
July 20, 2026 19:03
2592630 to
f2fd1ac
Compare
Collaborator
|
@Chigybillionz tell your agent to run bun command with prettier to format the code Then check ✅ it again with bun after with bun prettier check ✅... That the case for all your issues. If you have CODEX try using it or just connect your GitHub with GPT and use chatGPT work with the GitHub mcp It should also solve it |
Author
|
Am sending it the push...
So sorry for the delay...
My phone had faults.. but am back
…On Tue, Jul 21, 2026, 10:51 AM Uthaimin ***@***.***> wrote:
*kryputh* left a comment (Stellar-Mail/stealth#1587)
<#1587 (comment)>
@Chigybillionz <https://github.com/Chigybillionz> tell your agent to run
bun command with prettier to format the code
Then check ✅ it again with bun after with bun prettier check ✅...
That the case for all your issues. If you have CODEX try using it or just
connect your GitHub with GPT and use chatGPT work with the GitHub mcp
It should also solve it
—
Reply to this email directly, view it on GitHub
<#1587?email_source=notifications&email_token=BMBZJ5FH7T2EQPYPM4OTC4D5F44KFA5CNFSNUABFM5UWIORPF5TWS5BNNB2WEL2JONZXKZKDN5WW2ZLOOQXTKMBTGI2TIMBRGU42M4TFMFZW63VHNVSW45DJN5XKKZLWMVXHJLDGN5XXIZLSL5RWY2LDNM#issuecomment-5032540159>,
or unsubscribe
<https://github.com/notifications/unsubscribe-auth/BMBZJ5EKH64FQC5DNSZUJGL5F44KFAVCNFSNUABGKJSXA33TNF2G64TZHMYTEMZQGQ3DGOJYGA5US43TOVSTWNBZGIZTONRUHE4THILWAI>
.
Triage notifications, keep track of coding agent tasks and review pull
requests on the go with GitHub Mobile for iOS
<https://github.com/notifications/mobile/ios/BMBZJ5FI2PRPMQCXGXOT3C35F44KFA5CNFSNUABFM5UWIORPF5TWS5BNNB2WEL2JONZXKZKDN5WW2ZLOOQXTKMBTGI2TIMBRGU42M4TFMFZW63VHNVSW45DJN5XKKZLWMVXHJKTGN5XXIZLSL5UW64Y>
and Android
<https://github.com/notifications/mobile/android/BMBZJ5CDLVCFDI4AIZGX3LT5F44KFA5CNFSNUABFM5UWIORPF5TWS5BNNB2WEL2JONZXKZKDN5WW2ZLOOQXTKMBTGI2TIMBRGU42M4TFMFZW63VHNVSW45DJN5XKKZLWMVXHJLTGN5XXIZLSL5QW4ZDSN5UWI>.
Download it today!
You are receiving this because you were mentioned.Message ID:
***@***.***>
|
Author
|
… Am sending it the push...
So sorry for the delay...
My phone had faults.. but am back
On Tue, Jul 21, 2026, 10:51 AM Uthaimin ***@***.***> wrote:
> *kryputh* left a comment (Stellar-Mail/stealth#1587)
> <#1587 (comment)>
>
> @Chigybillionz <https://github.com/Chigybillionz> tell your agent to run
> bun command with prettier to format the code
>
> Then check ✅ it again with bun after with bun prettier check ✅...
>
> That the case for all your issues. If you have CODEX try using it or just
> connect your GitHub with GPT and use chatGPT work with the GitHub mcp
>
> It should also solve it
>
> —
> Reply to this email directly, view it on GitHub
> <#1587?email_source=notifications&email_token=BMBZJ5FH7T2EQPYPM4OTC4D5F44KFA5CNFSNUABFM5UWIORPF5TWS5BNNB2WEL2JONZXKZKDN5WW2ZLOOQXTKMBTGI2TIMBRGU42M4TFMFZW63VHNVSW45DJN5XKKZLWMVXHJLDGN5XXIZLSL5RWY2LDNM#issuecomment-5032540159>,
> or unsubscribe
> <https://github.com/notifications/unsubscribe-auth/BMBZJ5EKH64FQC5DNSZUJGL5F44KFAVCNFSNUABGKJSXA33TNF2G64TZHMYTEMZQGQ3DGOJYGA5US43TOVSTWNBZGIZTONRUHE4THILWAI>
> .
> Triage notifications, keep track of coding agent tasks and review pull
> requests on the go with GitHub Mobile for iOS
> <https://github.com/notifications/mobile/ios/BMBZJ5FI2PRPMQCXGXOT3C35F44KFA5CNFSNUABFM5UWIORPF5TWS5BNNB2WEL2JONZXKZKDN5WW2ZLOOQXTKMBTGI2TIMBRGU42M4TFMFZW63VHNVSW45DJN5XKKZLWMVXHJKTGN5XXIZLSL5UW64Y>
> and Android
> <https://github.com/notifications/mobile/android/BMBZJ5CDLVCFDI4AIZGX3LT5F44KFA5CNFSNUABFM5UWIORPF5TWS5BNNB2WEL2JONZXKZKDN5WW2ZLOOQXTKMBTGI2TIMBRGU42M4TFMFZW63VHNVSW45DJN5XKKZLWMVXHJLTGN5XXIZLSL5QW4ZDSN5UWI>.
> Download it today!
> You are receiving this because you were mentioned.Message ID:
> ***@***.***>
>
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Close #1552
Summary of the issue
Define fail-open and fail-closed behavior for abuse-service outages (#1552) so that dependency failures do not accidentally grant universal access (fail-open when it should be risk-controlled) or universally deny requests without an explicit risk decision.
Root cause
Dependency-failure policy for the abuse checks was not consistently established/documented such that each protected abuse decision could deterministically fall back (allow vs deny) with observable reasoning when the dependency (rate-counter storage) was unavailable.
Solution implemented
Classified abuse checks by outage policy (fail_open vs fail_closed) per protected route.
Wrapped each abuse dependency operation with a shared fallback mechanism that:
chooses the correct fail-open/fail-closed behavior,
attaches outage metadata to the decision,
emits metrics and audit events so the fallback choice is observable.
Ensured high-risk mutation behavior fails closed by propagating the abuse fallback outage decision to the API layer as a dependency-unavailable error.
Affected files
src/server/api/abuse-service.ts
src/server/api/postage-service.ts
src/server/api/metrics.ts
tests/unit/api/abuse-service.test.ts
Fix explanation
Explicit outage policy per protected route
ABUSE_OUTAGE_POLICIES explicitly assigns an outage policy for every AbuseCheck under the protected postage_submit route.
Deterministic fail-open / fail-closed fallback
withOutagePolicy(route, check, operation) catches dependency errors and returns:
fail_open => allowed: true, flagged: true, and outage metadata
fail_closed => allowed: false, retryAfterSeconds: 60, and outage metadata
Fallback decisions are observable
observeAbuseFallback(...) emits:
metrics.incrementCounter("abuse_dependency_fallback", fields)
metrics.recordAuditEvent("abuse.dependency_fallback", fields)
Fields include route, check, policy, decision, and errorType.
High-risk mutations fail closed where required
submitPostage routes dependency-unavailable fallout into a 503 dependency_unavailable error using the abuse decision’s outagePolicy / outageRoute.
For fail_closed checks, abuse decisions become denies, preventing accidental acceptance during outage conditions.
Code changes
src/server/api/abuse-service.ts
Added/used ABUSE_OUTAGE_POLICIES
Added/used withOutagePolicy and observeAbuseFallback for deterministic fallback + observability
src/server/api/postage-service.ts
Mapped abuse outage decisions to an explicit 503 dependency_unavailable response (with outage metadata)
src/server/api/metrics.ts
Existing stubs used by unit tests for emitted metrics/audit verification
tests/unit/api/abuse-service.test.ts
Added/kept tests for outage policy coverage, fail_open/fail_closed behaviors, and timeout/dependency failure handling
Testing steps (how to verify the fix)
Run unit tests:
npm test
Specifically validate:
tests/unit/api/abuse-service.test.ts
ensures outage policy coverage
ensures fail_open vs fail_closed behavior
ensures metrics + audit events are emitted
ensures timeout/dependency failure paths behave as fail_closed where required
Please kindly review this task. If there are any corrections, improvements, adjustments, or merge conflicts that you notice regarding my implementation, I'd really appreciate your feedback. I'd also love to hear your overall review of my work on this branch. Thank you!