Skip to content

fix: fail closed and bound semantic search execution - #126

Closed
afoote-mitre wants to merge 5 commits into
af/0.4.0-review-04-search-runtimefrom
af/0.4.0-review-05-contracts
Closed

afoote-mitre wants to merge 5 commits into
af/0.4.0-review-04-search-runtimefrom
af/0.4.0-review-05-contracts

Conversation

@afoote-mitre

@afoote-mitre afoote-mitre commented Aug 5, 2026 •

Copy link
Copy Markdown
Collaborator

Stack

5 of 6 in the 0.4.0 review stack.

  • Base: af/0.4.0-review-04-search-runtime
  • Previous: #125
  • Next: #127

Why These Changes Are Needed

Later review found remaining fail-open edges in upstream response handling and query construction, plus CPU/event-loop risk in semantic CPE evaluation. This range closes those paths, bounds semantic work more tightly, and makes asynchronous startup and event-loop pressure observable.

Review Size

Changed lines are additions plus deletions in this PR's adjacent diff. Generated files are package-lock.json and api-docs/openapi.json; tests are *.test.js and files under test/.

Category Changed Lines
Total 1,220
Generated files 0
Tests 783
Non-generated, non-test 437

Change-to-File Map

Change Why It Is Needed Primary Implementation Files Test / Contract Coverage
Fail closed on incomplete OpenSearch responses Prevent incomplete totals, hits, or metadata from being treated as usable search results. utils/searchResponseValidator.js, utils/searchCandidateProcessor.js, controllers/searchController.js Matching validator/candidate/controller test suites
Fail closed on invalid query construction Ensure builder failures and invalid DSL cannot fall through to provider execution or broad fallback behavior. utils/searchQueryBuilder.js, controllers/searchController.js utils/searchQueryBuilder.test.js, controllers/searchController.test.js
Bound semantic CPE evaluation Reduce unnecessary candidate processing and cap application CPU work during semantic applicability filtering. utils/searchCandidateProcessor.js, utils/cpe.js, utils/searchPostFilterCache.js Matching candidate/CPE/cache tests
Handle asynchronous startup failures Convert rejected startup work into the controlled fatal-startup path instead of an unhandled promise rejection. server.js server.test.js
Report rolling event-loop telemetry Make event-loop pressure visible while keeping metrics bounded rather than accumulating process-lifetime samples. utils/searchPerformance.js, config/default.jsonc utils/searchPerformance.test.js
Keep operational policy current Align documentation and delivery-policy expectations with the new telemetry and safeguards. README.md, .github/dependabot.yml, test/delivery-policy.test.js test/delivery-policy.test.js

Reviewer Focus

  • Confirm every invalid upstream/query state terminates with a sanitized error.
  • Review semantic evaluation bounds without changing standard-search total semantics.
  • Confirm startup rejection cannot become an unhandled promise rejection.
  • Verify telemetry is rolling/bounded and does not log request payloads or secrets.

@afoote-mitre
afoote-mitre force-pushed the af/0.4.0-review-05-contracts branch from a50d4df to 64ce9c3 Compare August 5, 2026 13:17
@afoote-mitre afoote-mitre changed the title test: add read-only OpenSearch contract checks fix: fail closed and bound semantic search execution Aug 5, 2026
@afoote-mitre
afoote-mitre force-pushed the af/0.4.0-review-05-contracts branch from 64ce9c3 to b140e65 Compare August 5, 2026 13:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant