fix: bound streamed tool argument memory - #847
Conversation
|
Important Review skippedDraft detected. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: ASSERTIVE Plan: Pro Plus Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Comment |
|
CI follow-up: the first Windows run passed 6,514 tests and timed out only the unrelated existing image-normalization P2 case at 5.39 seconds against its 5-second test limit. Re-running the failed Windows job passed. Ubuntu, macOS, Windows, package-install, target-enforcement, label, and React checks are now green. |
|
Thanks for this — it is a valuable part of the #820 series, especially because it bounds streamed tool-argument memory across the major translation paths. It currently conflicts with dev, so it will need a rebase, followed by an independent review from someone other than the author, before it can land.\n\nFor the broader draft series (#840, #841, #843, #844, #845, and #847), is there a specific landing order we should follow, or would it be better to consolidate any of the overlapping work? We are tracking #820 and would like to get these into the next cycle. |
|
Superseded by #892, which implements this defect's fix natively on top of the wave-1 retained-state framework (the PR's shape was used as a reference; see the PR description in #892 for the defect-specific deltas, including where the framework already covered part of it). Thank you for the contribution — the analysis in this PR drove the fix. |
Campaign preparation (docs-only): five units under devlog/_plan/260802_wtN_* with 000 research + 010 implementation roadmaps, claim ledgers verified by a lunasearch fan-out (Anthropic 1M windows, Copilot mixed-wire, DeepSeek service_tier, WHATWG extension origins, POSIX rename-over-symlink). wt1 update-path: PR lidge-jun#871, issue lidge-jun#879 (star-prompt deferral leakage), lidge-jun#557 optional wt2 zero-leak: PRs lidge-jun#840 lidge-jun#841 lidge-jun#843 lidge-jun#844 lidge-jun#845 lidge-jun#847 (tracker lidge-jun#820) wt3 provider-wire: PRs lidge-jun#746 lidge-jun#860 lidge-jun#839/lidge-jun#854, issue lidge-jun#875 triage, lidge-jun#616/lidge-jun#837 optional wt4 server-config: PRs lidge-jun#850 (CORS origin confusion), lidge-jun#869 (symlink destruction) wt5 windows-service: PRs lidge-jun#868, lidge-jun#861 (issue lidge-jun#848)
… bounds Three explorer passes found wave-1 landings already on dev (77243d9 framework, d1408b9 continuation cap+spill, 034d320 cache caps, a616078 translator budgets), so the campaign narrows to refinements: lidge-jun#841 admission boundary (direct-spill oversized, bounded snapshot read, bounded replay), lidge-jun#847 collector per-call scope + mandatory budget + 502 normalization, lidge-jun#844 incremental frames + typed partial-EOF, lidge-jun#845 NOOP (superseded), lidge-jun#843 fixed-size SHA-256 key identities, lidge-jun#840 ACL timeout-memo release + destination keying.
Summary
Why
Compatible upstreams can omit SSE delimiters or stream unbounded tool argument fragments. Those buffers were protocol-required, but they had no byte ownership limit and could grow for the lifetime of a turn. Truncating and completing a call would produce invalid or unsafe executable input, so overflow now fails truthfully while preserving the existing sequential tool event contract.
Validation
bun teston 15 related bridge, Chat, OpenAI Chat, and SSE suites: 206 passbun run typecheckbun run privacy:scanRelated to #820. Focused alternative to the overlapping portions of #829.