Repository navigation
fix(logs): bound complete runtime log responses - #1981
ericcaiwx-star wants to merge 33 commits into
Conversation
|
🦞👀 Pull request received. I will update this pull request when review starts. ClawSweeper review completeClawSweeper finished reviewing this revision. The review result is being finalized. |
|
Codex review: needs maintainer review before merge. What this changesThis PR bounds complete serialized runtime-log responses to 512 KiB and preserves continuation through byte-cut pages. Example: An operator reads 70 container diagnostics containing many quoted arguments.
Review scores
ProductKind: Bug fix · Worth it: Yes · Fix scope: Complete Merge readiness✅ Ready for maintainer review This PR fixes a documented limit that current main still exceeds. Both prior P3 findings are resolved, and no actionable defect remains in the reviewed head. Priority: P2 Before mergeNone. FindingsNone. Agent review detailsHow this fits togetherOCC runtime-log readers receive authorized revision-scoped Driver output, sanitize it, and return bounded records and authenticated continuation cursors through the HTTP API. flowchart LR
A[Console or CLI] --> B[HTTP runtime logs route]
B --> C[OCC authorization and audit]
C --> D[Compute or Sandbox Driver]
D --> E[Sanitization and continuation]
E --> F[Serialized response budget]
F --> G[Records and signed cursor]
Technical reviewBest possible solution: Land the shared serialized-page budget with its authenticated prefix continuation and conservative masking and loss reporting. Do we have a high-confidence way to reproduce the issue? Current-main source confirms the incomplete size estimate, and the linked report records a real 587,750-byte HTTP response; this review did not execute target code. Is this the best way to solve the issue? Measuring the complete sanitized response in the existing shared reader boundary fixes the contract directly, while prefix-derived continuation avoids dropping records after serialization. AGENTS.md: found and applied where relevant. Codex review notes: model internal, reasoning medium; reviewed against d2fe579cd51f. Provenance checked
TestingProof path: shipped entry point. SecurityNone. EvidenceWhat I checked:
Review metrics
LabelsLabel changes:
Label justifications:
Rating scale6/6 🦀 challenger crab · 5/6 🦞 diamond lobster · 4/6 🐚 platinum hermit · 3/6 🦐 gold shrimp · 2/6 🦪 silver shellfish · 1/6 🧂 unranked krab. Overall follows the weaker of proof and patch quality; ✨ marks media proof (a screenshot, video, or linked artifact) that directly shows the changed behavior. WorkflowClawSweeper edits this one comment on every review. Comment HistoryReview history (16 earlier review cycles; latest 8 shown)
Reviewed October 11, 2026, 3:27 PM ET / 19:27 UTC (Revision 17). |
|
Fixed in a823952. Compact hash strings and window tuples retain all occurrences and identities; Sandbox checkpoints reuse their outer baseline, and container checkpoints keep their distinct baseline. Released array-hash cursors still decode. Admission limits are unchanged. The published parent returns HTTP 500 on the full-48-anchor native SDK/HTTP cut. This head delivers all 150 new rows in 55/55/40 with empty replay. Maximum accepted Driver identity projection drains 54/54/42 with cursor/payload 1,905/1,858; conservative full-state maxima are 1,930/1,883. Related checks: 399 pass, one Linux-only skip. Real owned kubelet and protocol/SDK/HTTP controls were rerun; Sandbox peer and maximum-name projection are explicit fixtures. Temporary owned resources are removed. |
|
Exact-head CI for Main |
…5-oct10 # Conflicts: # docs/flows/agent-runtime-logs.md
|
@clawsweeper re-review |
|
🦞👀 Re-review progress:
|
Restore three paragraphs tightened earlier (oversized-line frontier, PEM close rule, CLI cancellation) because the open #1981 rewrites them, and trimming them added three new conflict hunks there. Make room instead in paragraphs no open PR touches, and fold the Kubernetes note into the existing timestamp sentence. 2,495 words with the docs-site counter.
Resolve agent-runtime-logs flow doc conflict using current main wording. Co-authored-by: Cursor <cursoragent@cursor.com>
Merge resolution pushed the flow doc six words over the 2500-word limit. Co-authored-by: Cursor <cursoragent@cursor.com>
Drop a duplicate changelog line and tighten the overview after merging main. Co-authored-by: Cursor <cursoragent@cursor.com>
Runtime log pages could exceed the documented 512 KiB body limit because the old estimate counted raw messages before JSON escaping, cursor signing and HTTP metadata. Both readers now measure the complete serialized response and build a bounded delivered prefix. Cursor, masking and withholding state follow that raw prefix; the existing message cap, public schema, signing, authorization and legacy decoder remain.
Closes #1980.
Current main integration
Integration head
8a5bf0e9f3a1a1a2de8a9685df60f43bc66e360dnormally merges upstreamf1dd15739and resolves the sole conflict in the runtime-log flow document. The resolution preserves this PR's cursor/window contract and full changelog while incorporating main's explicit-zero and positive sub-second--sincerejection. The merged flow is 2,488 words, below the 2,500-word limit. No production runtime or test logic required manual conflict resolution.Moving full-window repair
Addresses the grouped-timestamp follow report, following the earlier full-window repair. A cut inside a millisecond group now advances counted timed overlap when the observed source window is ordered and the remaining times fit it. Every wire cut also retains the existing authenticated raw-window witness, including cuts with distinct messages: an identical late copy can arrive afterwards. Changed witnesses keep delivered progress only with the existing bounded overlap context; uncertain context resets visibly.
Short, untimed, unordered, overflowing and outside-floor snapshots retain their positional baseline. Stable snapshots drain; changed uncertain windows can reset and replay. Current order cannot establish historical order. Identical saturated replacements remain unobservable, so this is not a general lossless-stream guarantee. No backend sequence or new cursor field was added. Container checkpoint loss conservatively retains one reset gap and suppresses duplicate notices; equal row counts do not establish continuity.
Executed evidence
Frozen behavior-proof head:
db624383f759ebac29cb50140eba584b71bf1d72; current main-integration head:8a5bf0e9f3a1a1a2de8a9685df60f43bc66e360d; published parent before the behavior repair:59b9c9eec562e50df8e3cbe9669a2e6f697ba37d. Each intermediate failure and corrective review was retained, rather than reported as a pass.Actual loopback gRPC
GetSandboxLogs→ repository Backend/SDK/SandboxDriver → authenticated Fastify HTTP: controlled tail 1000, about 2 KiB messages, ten distinct messages per millisecond, three appended between each of eight polls:Twelve additional grouped cases (tails 200/1000, six deterministic 2–3/ms seeds) pass on the current head. One parent case was a genuine negative control; parent defects were observed in 11/12, not asserted for all seeds. A raw-identical grouped control compares the complete repeated group-ID sequence and multiplicities: current 1021 occurrences,0 excess copies,0 missing,replay 0. No unique-message metric substitutes for that check.
Further actual RPC/HTTP regressions:
Actual owned K3s v1.35.5+k3s1/kubelet → repository Kubernetes Driver/SDK → authenticated Fastify HTTP: deliberately seeded valid benign CRI records replace a short 80-row window with 80 newer small rows, retaining the same Pod/container and tail 100.
5da3emits no reset gap; current returns 80 replacement rows, exactly one gap and empty replay. This is controlled CRI input, not a naturally observed rotation or timestamp-frequency claim.Sandbox is an owned native gRPC protocol fixture peer, with fixture Compute placement; all proofs use in-memory domain state and native IAM/audit. No deployed upstream OpenShell engine, sandbox/model execution or production qualification is claimed. Artificial timestamp/order boundaries are disclosed; no host clock changed. The existing 1.8s delay control delays the original SDK call before transport.
Validation and gates
go test ./internal/occcli -count=1, andgo vet ./...pass. The first sandboxed attempt could not bind loopback ports; the identical unrestricted rerun passed.Repair-head CI Required, Static Checks and Runtime Image Fixture succeeded. Current merge-head CI Required and Static Checks also succeed with no failed checks; optional First Agent Smoke remains in progress. ClawSweeper reviewed exact head
8a5bf0e9f3a1a1a2de8a9685df60f43bc66e360dat 5/6 with sufficient proof, no findings, Before merge None, and Ready for maintainer review. Owned server, four volumes, private kubeconfig and temporary image export were removed; RPC/HTTP listeners closed. No force push, empty commit, bypass or contributor merge.Verification
Exact head
01092fae692ff4dd85d815fc212b21dd9734e51b. Node v26.7.0, macOS. Flow word count on this head is 2498.window_exceededfor the same Sandbox buffer loss.node --test --test-name-pattern "one window notice" tests/conformance/runtime-logs-sandbox.test.mjs: 1 pass, 0 fail, exit 0.node --test --test-name-pattern "sandbox (byte-window|follow)" tests/conformance/runtime-logs-sandbox.test.mjs: 12 pass, 0 fail, exit 0.