Skip to content

fix: bound Cursor blob-store memory - #845

Closed
Ingwannu wants to merge 1 commit into
devfrom
agent/bound-cursor-blob-store
Closed

fix: bound Cursor blob-store memory#845
Ingwannu wants to merge 1 commit into
devfrom
agent/bound-cursor-blob-store

Conversation

@Ingwannu

@Ingwannu Ingwannu commented Aug 1, 2026

Copy link
Copy Markdown
Owner

Summary

  • cap Cursor blobs at 16 MiB each, 64 MiB total, and the existing 4,096 entries
  • pin every root/step/turn blob advertised by an active request until success, failure, or generator cancellation
  • evict only expired or LRU unpinned blobs; fail preparation when pinned data leaves no safe capacity
  • return a protobuf error for rejected server setBlobArgs instead of acknowledging a store that did not happen
  • store external root candidates only after replay pruning

Part of #820. This is a focused request-lifetime lease implementation rather than #829 app-wide memory infrastructure.

Verification

  • bun test tests/cursor-*.test.ts (398 pass)
  • bun run typecheck
  • bun run privacy:scan

Compatibility

Content-addressed IDs and get/set protobuf shapes remain unchanged. A single blob above 16 MiB or a request whose unique pinned blobs cannot fit 64 MiB now fails explicitly rather than evicting an in-flight reference or retaining unbounded data.

@coderabbitai

coderabbitai Bot commented Aug 1, 2026

Copy link
Copy Markdown

Important

Review skipped

Draft detected.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 61fb09ca-66c5-4ad0-a83c-0ee40db40455

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Comment @coderabbitai help to get the list of available commands.

@lidge-jun

Copy link
Copy Markdown
Owner

Maintainer triage status: this is valuable work. It bounds Cursor blobs while using scoped pins to protect active requests, has strong test coverage, and defines saturation behavior explicitly. It currently conflicts with dev, so a rebase is needed. It also shares the Cursor transport/docs surface with #844; please land the two in a defined order (or consolidate them) to avoid overlapping integration work. An independent, non-author review is required before landing.

@lidge-jun

Copy link
Copy Markdown
Owner

Superseded by #892, which implements this defect's fix natively on top of the wave-1 retained-state framework (the PR's shape was used as a reference; see the PR description in #892 for the defect-specific deltas, including where the framework already covered part of it). Thank you for the contribution — the analysis in this PR drove the fix.

@lidge-jun lidge-jun closed this Aug 2, 2026
olddonkey pushed a commit to olddonkey/opencodex that referenced this pull request Aug 2, 2026
Campaign preparation (docs-only): five units under devlog/_plan/260802_wtN_*
with 000 research + 010 implementation roadmaps, claim ledgers verified by a
lunasearch fan-out (Anthropic 1M windows, Copilot mixed-wire, DeepSeek
service_tier, WHATWG extension origins, POSIX rename-over-symlink).

wt1 update-path: PR lidge-jun#871, issue lidge-jun#879 (star-prompt deferral leakage), lidge-jun#557 optional
wt2 zero-leak: PRs lidge-jun#840 lidge-jun#841 lidge-jun#843 lidge-jun#844 lidge-jun#845 lidge-jun#847 (tracker lidge-jun#820)
wt3 provider-wire: PRs lidge-jun#746 lidge-jun#860 lidge-jun#839/lidge-jun#854, issue lidge-jun#875 triage, lidge-jun#616/lidge-jun#837 optional
wt4 server-config: PRs lidge-jun#850 (CORS origin confusion), lidge-jun#869 (symlink destruction)
wt5 windows-service: PRs lidge-jun#868, lidge-jun#861 (issue lidge-jun#848)
Wibias pushed a commit to Wibias/opencodex that referenced this pull request Aug 3, 2026
… bounds

Three explorer passes found wave-1 landings already on dev (77243d9
framework, d1408b9 continuation cap+spill, 034d320 cache caps,
a616078 translator budgets), so the campaign narrows to refinements:
lidge-jun#841 admission boundary (direct-spill oversized, bounded snapshot read,
bounded replay), lidge-jun#847 collector per-call scope + mandatory budget + 502
normalization, lidge-jun#844 incremental frames + typed partial-EOF, lidge-jun#845 NOOP
(superseded), lidge-jun#843 fixed-size SHA-256 key identities, lidge-jun#840 ACL
timeout-memo release + destination keying.
Wibias pushed a commit to Wibias/opencodex that referenced this pull request Aug 3, 2026
Remote setBlobArgs blobId bytes became an unbounded, uncounted hex Map
key (a multi-MiB ID across 4096 entries). key() now passes through the
hex of raw IDs up to 64 bytes (every ID the live protocol carries is a
32-byte digest) and maps anything larger to a fixed 64-char SHA-256 of
the raw bytes; the derivation is symmetric across setBlobArgs and
getBlobArgs so the round-trip is preserved. Retained key bytes are
tracked in a separate keyBytes metric so the 64 MiB payload cap and its
exact-byte tests are untouched. Refines lidge-jun#845 (audit refuted the NOOP).
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants