Summary
Four Azure clients log a pager-construction failure and return an empty commitment slice with a nil error. A caller comparing recommendations against existing commitments concludes the subscription holds no reservations and recommends or executes a duplicate purchase. Two sibling clients return the error on the same path, so the behaviour is inconsistent across the provider. The verifier narrowed the blast radius: the discarded error comes only from client construction, so a permission failure surfaces later at the first page fetch rather than here.
Location
providers/azure/services/cache/client.go:185 (same at cosmosdb/client.go:187, database/client.go:217, search/client.go:132) at 3c0f8ac94048a2c36fce5ccddee54e6c4849a5cd
Failure scenario
A credential, permission or client-construction failure is logged to stdout and converted into an empty slice with a nil error. A caller comparing recommendations against existing commitments concludes the subscription holds no reservations and recommends (or executes) a purchase that duplicates an existing one. synapse/client.go:168 and managedredis/client.go:179 return the error on this same path, so the behaviour is inconsistent across the provider.
Evidence
pager, err := c.createReservationsPager()
if err != nil {
log.Printf("WARNING: failed to create Redis reservations pager: %v", err)
return []common.Commitment{}, nil
}
Suggested fix
Return the wrapped error, matching synapse and managedredis.
Found by the 2026-09-02 codebase audit, finding A08b-022, reported by one reviewer and independently confirmed by a second. Full report: docs/audits/codebase-audit-2026-09-02.md.
Summary
Four Azure clients log a pager-construction failure and return an empty commitment slice with a nil error. A caller comparing recommendations against existing commitments concludes the subscription holds no reservations and recommends or executes a duplicate purchase. Two sibling clients return the error on the same path, so the behaviour is inconsistent across the provider. The verifier narrowed the blast radius: the discarded error comes only from client construction, so a permission failure surfaces later at the first page fetch rather than here.
Location
providers/azure/services/cache/client.go:185(same atcosmosdb/client.go:187,database/client.go:217,search/client.go:132) at 3c0f8ac94048a2c36fce5ccddee54e6c4849a5cdFailure scenario
A credential, permission or client-construction failure is logged to stdout and converted into an empty slice with a nil error. A caller comparing recommendations against existing commitments concludes the subscription holds no reservations and recommends (or executes) a purchase that duplicates an existing one.
synapse/client.go:168andmanagedredis/client.go:179return the error on this same path, so the behaviour is inconsistent across the provider.Evidence
Suggested fix
Return the wrapped error, matching synapse and managedredis.
Found by the 2026-09-02 codebase audit, finding
A08b-022, reported by one reviewer and independently confirmed by a second. Full report:docs/audits/codebase-audit-2026-09-02.md.