Skip to content

[uk-ai-resilience] Three untracked go/allocation-size-overflow alerts in MCP-gateway config generators (Tier C) #59773

Description

@github-actions

Summary

Three open CodeQL go/allocation-size-overflow alerts (CWE-190, severity: warning) in actively-changed MCP-gateway/tooling config generators have no matching open tracking issue, breaking the classification → control-verification loop for this run's recent-changes scope (7-day lookback since 2026-09-02).

A related alert (#672) in the same mcp_setup_generator.go file was previously tracked in #58261, but that alert has since closed/resolved without preventing recurrence of the same finding class at a different line (#677) and in a sibling file (#676/#675).

Tier & risk-scoring

  • Tier: C — Restricted Pending Review
  • Exposure amplification: Low–Medium (feeds GitHub Actions workflow YAML and MCP container config generation, so an overflow-triggered panic or undersized allocation could affect all generated workflows using these code paths)
  • Patchability: High
  • Detectability: Medium (CodeQL catches it, but it isn't visible in the tracking-issue backlog)
  • Operational fragility: Medium
  • Ownership confidence: Low (CODEOWNERS coverage for these files could not be verified this run)

Remediation action

  • Guard the size computation with a bounds check before use in the allocation, or widen the intermediate type (e.g., accumulate as uint64/int64 before converting to a slice length), in both mcp_setup_generator.go:146 and mcp_github_config.go:84.
  • Add a regression test exercising a large/edge-case input to confirm no panic or wraparound occurs.
  • After fixing, verify the alerts actually transition to fixed/dismissed in code scanning before closing this issue (see the companion alert-dismissal hygiene issue for why this verification step matters).

SLA urgency

High — untracked alerts in actively-changed, workflow-generation-critical code reduce confidence in the classification step of the operational governance loop.

Discussion report

See the "UK AI Governance: recent-change risk review (2026-09-02 to 2026-09-09)" discussion created by this run for full asset graph, control verification, and risk-scoring context.

Generated by UK AI Operational Resilience · copilot · auto · 80.5 AIC · ⌖ 6.82 AIC · ⊞ 8.1K · ◷

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions