Repository navigation
fix(server): bound provider event log records and pass Codex images by path - #653
Merged
Merged
Conversation
Port of upstream commit b17cc2ab5d5029f898121798ca19db3288cba616 (#12305).
…requests Port of upstream commit 3fd21df62da3191f1abf12a0cd74df6de9ed30a2 (#11050).
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
Contributor
Thread transfer impact✅ Thread transfer remains within every enforced ceiling.
Baseline: Scenario and decoded snapshot size10 historical turns, 5 command tools per turn, 878.9 KiB retained MCP result per historical turn, and a 1.05 MiB retained result in the measured turn.
Updated in place by a trusted workflow. PR artifacts are strictly validated and never executed. |
This was referenced Sep 19, 2026
This branch was previously deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Ports two upstream server fixes from T3 Code. Part of upstream integration cycle #650, bounded at upstream
93e04160a0c0dece8a258384d2118a660415a53d.Sources
b17cc2ab5d5029f898121798ca19db3288cba6163fd21df62da3191f1abf12a0cd74df6de9ed30a2Bounded provider event log records
A provider event with a cyclic reference, a pathological nesting depth or a very large payload could previously drive unbounded traversal inside the NDJSON logger's serialization, and an event that serialized successfully was written at whatever size it happened to be.
boundProviderEventForLoggingnow walks a record before encoding it, with a 64 KiB character budget, a 1,024 field budget, a depth cap of 16 and aWeakSetancestor check. Records that fit are written unchanged. Records that do not fall back tosummarizeProviderEvent, which keeps routing and failure fields — provider, method, ids, status, error and stop reasons — while replacing long strings with{ omittedCharacters }and arrays with{ itemCount }. Escaping can still expand a bounded record past the budget, so serialization is re-checked by byte length and falls back to the summary a second time.Also suppresses three more high-volume transient frames:
turn/diff/updated,message.part.deltaand Anthropicstream_event/content_block_delta.Pylon's
commitGuardonmakeEventNdjsonLogStore.writeand Pylon's existing transient filters forclaude/stream_event/content_block_delta/,session/updateandmessage.part.updatedare preserved.Excluded: raw-frame suppression
Upstream's change also drops native frames whose envelope carries
stage: "raw", and unwrapsstage: "decoded"payloads. That part is deliberately not ported.Two reasons, both verified against this tree rather than assumed:
apps/server/src/provider/acp/AcpNativeLogging.tswrites protocol records as{ observedAt, event: { …, payload: { direction, stage, payload } } }. Upstream readsenvelope.stage, one level above where Pylon'sstageactually sits, so the branch never fires.GrokSkills.tsis the only otherstageemitter and its values are spawn/timeout/exit/decode.formatProtocolLogPayloadalready reduces the payload throughsummarizePayloadto{ valueType, byteLength }, and protocol logging is only attached underverboseProtocolLogging, an explicit opt-in. Those records are the evidence that survives when a frame fails to decode or a response never arrives, which is the Antigravity ACPsession/prompthang signature behind feat: add ACP prompt liveness and truthful forced stops #609.Revisit trigger: Pylon moves
stageto the envelope level inAcpNativeLogging.ts, or ACP raw frames begin carrying unsummarized payloads.Codex image attachments by path
Image attachments were read from disk and inlined into
turn/startas a base64 data URL, so the JSON-RPC request grew with the file. They are now passed as{ type: "localImage", path }and the CLI reads the file itself.localImageis a real content type inpackages/effect-codex-app-server/src/_generated/schema.gen.ts, so this is protocol-valid rather than a hopeful rename.Pylon's attachment-id validation against
serverConfig.attachmentsDirstill runs before the path is returned, so a path outside the attachment store is still rejected. Unlike upstream,FileSystem.FileSystemstays wired intomakeCodexAdapter— Pylon'smakeCodexSessionRuntimestill requires it.Behavior change worth noting
A circular or oversized event previously produced a
SchemaErrordiagnostic and no log line; it now produces a bounded summary line. The existing Pylon test asserting theSchemaErrorpath was replaced by one asserting the summary path, and it keeps the original assertion that the event's contents never reach the diagnostics. Summarization only narrows what is written — events under budget are unaffected.Verification
Run on the final head, not taken from a report:
vp test run apps/server/src/provider/Layers/EventNdjsonLogger.test.ts apps/server/src/provider/Layers/CodexAdapter.test.ts apps/server/src/provider/Layers/CodexSessionRuntime.test.ts— 3 files, 133 tests passed.vp run -F t3 typecheck— exit 0.vp checkon the six changed files — formatting and lint clean.Backend-only; no client evidence required.
Need help on this PR? Tag
@codesmith-botwith what you need. Autofix is disabled.