Skip to content

Fix audit findings: GPU pool, index integrity, worker/snapshot, API, CI - #39

Merged
codewarnab merged 2 commits into
mainfrom
fix/audit-findings
Oct 4, 2026
Merged

codewarnab merged 2 commits into
mainfrom
fix/audit-findings

Conversation

@codewarnab

Copy link
Copy Markdown
Owner

Summary

Fixes 22 bugs and security issues from a repo audit. The silent benchmark auto-send is intentional and unchanged.

High

  • GPU device pool: concurrent create() calls share one in-flight acquisition, so they no longer reset the refcount or destroy each other's device. Release and device-lost handling now check the device's identity.
  • Buffer limits: GPU buffers are clamped to maxStorageBufferBindingSize. Before, an oversized binding made every query return 0 results while the engine still reported 'webgpu'.
  • Batch atomicity: filter getters run before any change, so a getter that throws no longer leaves DocumentIndex corrupted.

Library

  • Readback captures the generation number before awaiting, so a destroy during the wait throws AbortError, not TypeError. The engine is torn down if init fails, and calling init() twice releases the previous device.
  • Filters on high-cardinality string fields use posting lists, so memory stays bounded. Field reads use own properties only, highlights are safe for a __proto__ field, and the ID comparator is a total order. Number and boolean filter values are coerced more strictly.
  • The worker builds a new index before swapping it in and handles messages one at a time; DESTROY resets the session. The client applies state only after the worker succeeds.
  • Snapshots reject duplicate or non-scalar docIds and non-object docs, and accept typed-array buffers. Custom IndexedDB stores are now created on an existing database.
  • The native CPU baseline uses the same normalization as the exact scorer. Bun now loads .wgsl imports as text.

API / site / CI

  • /api/submit-benchmark keeps a capped list of submissions per fingerprint, deduped per IP, so nobody can poison a slot by submitting first. It stores only validated fields and returns 413 for bodies over 8 KB, 400 for null entries, and 502 when the store is down. The rate-limit expiry now heals itself.
  • The site clamps the payload to server limits and validates saved history. The corpus page defaults to 100k when size is missing and builds large corpora in chunks. The benchmark app's test engine is gated to dev mode.
  • Workflow actions are pinned to commit SHAs with least-privilege permissions. Release runs only after CI passes on main.

Behaviour changes

  • Boolean filter fields accept only true/false (or "true"/"false"). Blank number bounds throw InvalidFilterError.
  • Numeric IDs sort before string IDs when scores tie.
  • A database upgraded to create custom IndexedDB store names can't be opened by older library versions. Default store names aren't affected.
  • The benchmark's native baseline is slower, so its numbers can't be compared with past history.
  • The bundle budget goes from 90 KB to 96 KB gzip; this PR adds about 4.8 KB.

Known follow-ups

  • The vgpu mock never runs WGSL, so check:shaders is still the only real check of the shaders.
  • The release job runs the browser test but never installs Chrome. This predates this PR.
  • Two low-priority items: the client and worker could disagree if a worker sent back a malformed restore result, and restoring a snapshot with embedded docs now copies its records back from the worker.

Test plan

  • check:shaders, typecheck, build, check:bundle-size, check:public-api
  • test:mock, contracts, records, highlight, mutations, worker, snapshot, observability, parity, filtering, faceting, diagnostics, search-modes, cpu-baseline, reliability, benchmarks, and normalization (including the Turkish locale run)
  • New test:regressions (38 tests, added to CI); bun test packages/webgpu-search/test passes 260/260
  • Handler tests for the API with a mocked fetch

🤖 Generated with Claude Code

codewarnab and others added 2 commits October 4, 2026 15:53
- GPU: in-flight device acquisition with correct refcounts; identity-checked
  release/lost handling; clamp buffers to maxStorageBufferBindingSize;
  capture generation before readback await; tear down on init failure;
  native baseline uses exact-scorer normalization; bun .wgsl text loader.
- Index: batch mutations are atomic (filter getters run before mutation);
  posting-list storage for high-cardinality string filters; own-property
  field reads; __proto__-safe highlights; total-order id comparator;
  stricter number/boolean filter coercion.
- Worker/snapshot: build-then-swap INIT/RESTORE; serialized message queue
  with DESTROY session reset; client commits after worker success; reject
  duplicate/non-scalar docIds and non-object docs; accept typed-array
  buffers; create custom IDB stores via version upgrade.
- API: per-fingerprint capped submission list with per-IP dedup, whitelisted
  record, 413 size limit, null-safe validation, 502 on store errors,
  self-healing rate-limit expiry.
- Site: clamp payload to server limits, validate stored history, sane
  corpus size param with chunked generation; gate benchmark test engine.
- CI: SHA-pinned actions, least-privilege permissions, release only after
  green CI on main; new test:regressions suite; bundle budget 90->96 KB.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Copilot AI balanced review requested due to automatic review settings October 4, 2026 15:54
@vercel

vercel Bot commented Oct 4, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
Project Deployment Actions Updated
webgpu-search Ignored Ignored Oct 4, 2026 3:54pm UTC

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@codewarnab
codewarnab merged commit adf41c9 into main Oct 4, 2026
4 checks passed
@codewarnab
codewarnab deleted the fix/audit-findings branch October 4, 2026 15:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants