8dde5ee37f
tracker-policy-pr / check-pr (pull_request) Successful in 14s
test / integration-docker (pull_request) Successful in 40s
test / unit (pull_request) Successful in 46s
lint / lint (push) Successful in 57s
test / integration-firecracker (pull_request) Successful in 4m2s
test / coverage (pull_request) Successful in 16s
test / publish-infra (pull_request) Has been skipped
`_supervise_token_block` and `_await_token_response` called the synchronous `PolicyResolver` directly from mitmproxy's async request handling. Those RPCs funnel through `PolicyResolver._post_json`, which blocks on `urllib.request.urlopen`. Because the poll loop runs for the entire operator-approval window, a slow or unreachable orchestrator would repeatedly freeze the proxy event loop — stalling every other bottle's traffic — despite `_await_token_response`'s contract of not blocking the loop (#471 review, review #443). Dispatch both the propose and poll RPCs via `asyncio.to_thread` so the blocking urllib call runs in a worker thread and the event loop keeps serving other flows. Fail-closed semantics are unchanged: `PolicyResolveError` still propagates through the await and is caught exactly as before. Regression test records the thread each RPC executes on and asserts it is not the loop thread; it fails against the pre-fix inline calls and passes with the dispatch. Full egress-addon + policy-resolver + supervise-server suites green (155 tests). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>