Repository navigation
Conversation
- Return 503 with Retry-After when an event post cannot be queued instead of acknowledging events that will never be processed, and remove the saved payload files. - Send Retry-After when event submission is disabled and when a request is throttled. - Decompress queued payloads with a size limit so a highly compressed post cannot expand into unbounded memory before its size is checked. - Delete the payload when a post exceeds the size limit, and record the uncompressed size metric from the decompressed payload. - Delete queued event post files older than seven days, which are left behind when a queue entry is dead-lettered.
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 2aa8e7ed43
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| .Produces<WorkInProgressResult>(StatusCodes.Status202Accepted) | ||
| .ProducesProblem(StatusCodes.Status400BadRequest) | ||
| .ProducesProblem(StatusCodes.Status404NotFound) | ||
| .ProducesProblem(StatusCodes.Status503ServiceUnavailable) |
There was a problem hiding this comment.
Remove the spurious 503 response from event deletion
Remove this response declaration and its snapshot entry: DeleteEvents only reads and removes stored events and never invokes the event-post queue or EventQueueUnavailable, so this change incorrectly advertises a new public response that the endpoint cannot produce. Generated clients will consequently model a queue-unavailable failure for an unrelated delete operation.
AGENTS.md reference: AGENTS.md:L72-L72
Useful? React with 👍 / 👎.
Summary
PR 1 of the ingestion plan in #2368 (plan): make the existing accept path honest about failures and tell clients when to retry.
POSTandGETevent submissions used to return202/200, and the events were never processed. They now return503withRetry-After: 30, and the saved files are removed.EventPostService.SaveAndEnqueueAsyncalso turns storage and queue exceptions into the same failure result instead of leaving orphaned files.Retry-Afteron every retryable response:503when event submission is disabled:300seconds.429: the seconds until the throttle window resets.EventPostsJob. Payloads are decompressed with the uncompressed size limit applied while reading. Previously the whole payload was expanded into memory before the size check, so a highly compressed post could exhaust job memory.EventPostsJobfixes:CleanupDataJobdeletes queued event post files (q/) older than seven days. Those files are left behind when a queue entry is dead-lettered. Seven days keeps the window for an administrator to requeue them; events older than three days are discarded by the pipeline anyway.Compatibility
503response, documented on every event submission endpoint, plusRetry-Afterheaders. The OpenAPI snapshot diff contains only those503entries.503as retryable and keep the batch. The .NET client suspends for 5 minutes; the JavaScript client suspends until the next 15-minute boundary.Verification
dotnet build Exceptionless.slnx: 0 warnings, 0 errors.429carriesRetry-After, and the disabled-submission503carriesRetry-After: 300.