dbd061e119
The cpu-fast lane disables cross-check to fit a low-memory box, but a request could still send cross_check=on and override it, lazy-loading the HR-matting model and running the 2048 forward -> the exact OOM (worker SIGKILL -> 502) cpu-fast exists to avoid. BGFILTER_CROSS_CHECK=0 did not protect against this because the per-request form field wins. Add CrossCheckSettings.lock (default False). When set, PipelineManager resolves cross-check to the base value and ignores per-request overrides, so a locked off-lane silently honours cross_check=on as off -- no HR-matting load, no cross-check run, no error (200), and the response header reports "off". Enable it in cpu-fast.yaml (enabled: false, lock: true). Verified end-to-end: cross_check=on on the locked lane returns without loading the cross-checker. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>