Skip to content

Fix/sync tool gate bypass - #92

Merged
gladstomych-sa merged 2 commits into
mainfrom
fix/sync-tool-gate-bypass
Sep 15, 2026
Merged

gladstomych-sa merged 2 commits into
mainfrom
fix/sync-tool-gate-bypass

Conversation

@yanny-sec

Copy link
Copy Markdown
Contributor

Summary

sync_gate failed open while the WS handshake was incomplete: it read "policy not established yet" as "nothing to gate" and returned False, so the tool ran. The fix removes that premature check and defers the decision to _async_gate, which waits for the handshake before deciding. The only remaining fail-open is ws is None, e.g. the SDK is not running at all. The trade-off is that a handshake which never completes now blocks rather than passes.

Closes #91

Test plan

Checklist

  • CLA signed (see CLA.md)
  • Tests pass locally
  • Docs updated where needed
  • British English; no em-dashes; no marketing fluff

@yanny-sec yanny-sec self-assigned this Sep 15, 2026
@yanny-sec yanny-sec added the bug Something isn't working label Sep 15, 2026
@gladstomych-sa
gladstomych-sa self-requested a review September 15, 2026 12:49

@gladstomych-sa gladstomych-sa left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@gladstomych-sa
gladstomych-sa merged commit 55d46f4 into main Sep 15, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[bug] Block mode silently bypassed for synchronous (def) LangChain tools

2 participants