Clawpatch finding
Evidence
apis/src/openai/responses/mcp_dispatch/mod.rs:91-100 (MAX_APPROVAL_RESPONSES)
apis/src/openai/responses/mcp_dispatch/mod.rs:475-486 (McpDispatchFilter::resume_approvals)
apis/src/openai/responses/mcp_dispatch/mod.rs:652-670 (record_and_emit_approvals)
apis/src/openai/responses/mcp_dispatch/tests.rs:2860-2888 (resume_approvals_rejects_oversized_batch)
apis/src/openai/responses/agentic_loop/tests.rs:928-967 (multiple_client_function_calls_are_preserved)
Description
The dispatcher can emit and persist several approval requests from a batched model round, but it rejects the corresponding valid batch of approval-response input items solely because it contains more than one item. The PostgreSQL parameter-limit rationale only requires a finite upper bound, not a limit of one; the existing configured per-round MCP cap already provides a much smaller safe bound than the database limit.
Reproduction
Seed two pending approval records for the same previous_response_id, construct a continuation request whose input contains two matching mcp_approval_response items, and invoke McpDispatchFilter::on_request_body. The filter returns HTTP 400 before loading or atomically consuming either record, instead of applying both decisions.
Recommendation
Permit a bounded batch consistent with max_calls_per_round, deduplicate approval_request_id values before store access, and atomically load, resolve, consume, and apply all decisions as the existing batch-oriented code already supports.
Sequencing
Open PR #1133 modifies MCP dispatch/approval; revalidate after merge.
Clawpatch finding
fnd_sig-feat-custom-apis-responses-t_c4e0c33f62feat_custom_apis_responses_toolsb144a3dfbf0b46353cc17acfe2f85f7e8d7739e6Evidence
apis/src/openai/responses/mcp_dispatch/mod.rs:91-100(MAX_APPROVAL_RESPONSES)apis/src/openai/responses/mcp_dispatch/mod.rs:475-486(McpDispatchFilter::resume_approvals)apis/src/openai/responses/mcp_dispatch/mod.rs:652-670(record_and_emit_approvals)apis/src/openai/responses/mcp_dispatch/tests.rs:2860-2888(resume_approvals_rejects_oversized_batch)apis/src/openai/responses/agentic_loop/tests.rs:928-967(multiple_client_function_calls_are_preserved)Description
The dispatcher can emit and persist several approval requests from a batched model round, but it rejects the corresponding valid batch of approval-response input items solely because it contains more than one item. The PostgreSQL parameter-limit rationale only requires a finite upper bound, not a limit of one; the existing configured per-round MCP cap already provides a much smaller safe bound than the database limit.
Reproduction
Seed two pending approval records for the same previous_response_id, construct a continuation request whose input contains two matching mcp_approval_response items, and invoke McpDispatchFilter::on_request_body. The filter returns HTTP 400 before loading or atomically consuming either record, instead of applying both decisions.
Recommendation
Permit a bounded batch consistent with max_calls_per_round, deduplicate approval_request_id values before store access, and atomically load, resolve, consume, and apply all decisions as the existing batch-oriented code already supports.
Sequencing
Open PR #1133 modifies MCP dispatch/approval; revalidate after merge.