fix: bound Cursor blob-store memory - #845
Conversation
|
Important Review skippedDraft detected. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: ASSERTIVE Plan: Pro Plus Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Comment |
|
Maintainer triage status: this is valuable work. It bounds Cursor blobs while using scoped pins to protect active requests, has strong test coverage, and defines saturation behavior explicitly. It currently conflicts with |
|
Superseded by #892, which implements this defect's fix natively on top of the wave-1 retained-state framework (the PR's shape was used as a reference; see the PR description in #892 for the defect-specific deltas, including where the framework already covered part of it). Thank you for the contribution — the analysis in this PR drove the fix. |
Campaign preparation (docs-only): five units under devlog/_plan/260802_wtN_* with 000 research + 010 implementation roadmaps, claim ledgers verified by a lunasearch fan-out (Anthropic 1M windows, Copilot mixed-wire, DeepSeek service_tier, WHATWG extension origins, POSIX rename-over-symlink). wt1 update-path: PR lidge-jun#871, issue lidge-jun#879 (star-prompt deferral leakage), lidge-jun#557 optional wt2 zero-leak: PRs lidge-jun#840 lidge-jun#841 lidge-jun#843 lidge-jun#844 lidge-jun#845 lidge-jun#847 (tracker lidge-jun#820) wt3 provider-wire: PRs lidge-jun#746 lidge-jun#860 lidge-jun#839/lidge-jun#854, issue lidge-jun#875 triage, lidge-jun#616/lidge-jun#837 optional wt4 server-config: PRs lidge-jun#850 (CORS origin confusion), lidge-jun#869 (symlink destruction) wt5 windows-service: PRs lidge-jun#868, lidge-jun#861 (issue lidge-jun#848)
… bounds Three explorer passes found wave-1 landings already on dev (77243d9 framework, d1408b9 continuation cap+spill, 034d320 cache caps, a616078 translator budgets), so the campaign narrows to refinements: lidge-jun#841 admission boundary (direct-spill oversized, bounded snapshot read, bounded replay), lidge-jun#847 collector per-call scope + mandatory budget + 502 normalization, lidge-jun#844 incremental frames + typed partial-EOF, lidge-jun#845 NOOP (superseded), lidge-jun#843 fixed-size SHA-256 key identities, lidge-jun#840 ACL timeout-memo release + destination keying.
Remote setBlobArgs blobId bytes became an unbounded, uncounted hex Map key (a multi-MiB ID across 4096 entries). key() now passes through the hex of raw IDs up to 64 bytes (every ID the live protocol carries is a 32-byte digest) and maps anything larger to a fixed 64-char SHA-256 of the raw bytes; the derivation is symmetric across setBlobArgs and getBlobArgs so the round-trip is preserved. Retained key bytes are tracked in a separate keyBytes metric so the 64 MiB payload cap and its exact-byte tests are untouched. Refines lidge-jun#845 (audit refuted the NOOP).
Summary
setBlobArgsinstead of acknowledging a store that did not happenPart of #820. This is a focused request-lifetime lease implementation rather than #829 app-wide memory infrastructure.
Verification
bun test tests/cursor-*.test.ts(398 pass)bun run typecheckbun run privacy:scanCompatibility
Content-addressed IDs and get/set protobuf shapes remain unchanged. A single blob above 16 MiB or a request whose unique pinned blobs cannot fit 64 MiB now fails explicitly rather than evicting an in-flight reference or retaining unbounded data.