Skip to content

fix(responses): enforce configured total sends during recovery - #4947

Merged
lidge-jun merged 2 commits into
devfrom
codex/lane-g-2590-send-cap
Sep 18, 2026
Merged

lidge-jun merged 2 commits into
devfrom
codex/lane-g-2590-send-cap

Conversation

@lidge-jun

@lidge-jun lidge-jun commented Sep 17, 2026 •

Copy link
Copy Markdown
Owner

Summary

Restore the configured total-send invariant found by the 2.59.0 merged-tree audit. A provider configured with attempts=1 authorizes one physical upstream send total. A later rebuild previously passed zero remaining attempts to the shared recovery helper, which could still grant a final-reserve send.

Configured exhaustion now stops rebuild work before response consumption or request mutation and returns the original upstream response. The recovery helper preserves its default reserve behavior for unconfigured providers. No retry count, timeout, delay or shared request cap is increased.

Verification

  • Local verification was NOT RUN because this lane forbids local tests, suites, typecheck, builds, installs and proxy execution. Hosted CI is the executable verification.
  • Static source review, independent Sol review and git diff --check completed.
  • Separate composed-budget regressions prove configured attempts=1 cannot draw reserve and the unconfigured default still allocates/refunds its fourth-send reserve.
  • An end-to-end Console Go recovery case checks one physical send and the original 400 response body. Existing recovery regressions remain intact.
  • First hosted run 35279024423 passed the physical-send and response assertions but found that the new no-recovery assertion expected an absent field. The existing request-attempt initializer creates an empty array. Head 50ecf06 now asserts that initialized empty list and has fresh CI run 35279717343; no production behavior or send-count assertion was weakened.
  • On that corrected head, Linux 1/4–4/4, gates and the new send-cap cases passed. macOS 2/2 job 105398860800 failed only the separately reproduced combo connect-cancellation teardown hook at 30050.44 ms (12810 pass, 12 skip, 1 fail), matching the failure on the status-fixture-only PR test(cli): measure cold status setup before timed projections #4948. The release host assigned that hook to another lane. This PR remains draft rather than claiming a fully green exact head; no test rerun or timeout change was used.
  • Exact base: a0f611d. The release host will verify the new combined dev SHA after integration.

Checklist

  • Scope stays focused and avoids unrelated cleanup.
  • Docs or release notes were updated when needed.
  • Security-sensitive changes were reviewed for secrets, auth, and unsafe defaults. Configured limits only narrow dispatch and cannot spend an extra recovery send.

@coderabbitai

coderabbitai Bot commented Sep 17, 2026 •

Copy link
Copy Markdown
Contributor

Warning

Review limit reached

Next included review available in 28 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used all 10 included reviews currently available.

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 4d155452-637a-4671-8427-8218a3ea2cb4

📥 Commits

Reviewing files that changed from the base of the PR and between a0f611d and 50ecf06.

📒 Files selected for processing (5)
  • src/server/responses/passthrough-dispatch.ts
  • src/server/responses/request-send-budget.ts
  • structure/transports/responses.md
  • tests/responses/responses-console-go-upload-retry.test.ts
  • tests/responses/responses-passthrough-transient-policy.test.ts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

Copy link
Copy Markdown
Contributor

✅ Deterministic PR hygiene checks passed.

@github-actions github-actions Bot added the bug Something isn't working label Sep 17, 2026
@lidge-jun

Copy link
Copy Markdown
Owner Author

Merging on the macOS exception now recorded in #4956, with the Windows evidence this change needed.

At its exact head all nine Windows shards are green in the dispatched lane=all run, along with the full Linux suite, gates, and the cross-platform smokes. The outstanding macOS legs are the long-standing defect in #4956, which was shown this evening to affect Windows as well and which has now been traced to spawned Bun child processes that are assigned a PID, write nothing to either stream, and never exit. A dedicated lane owns that investigation.

Holding this fix for that defect would delay a correctness fix for a problem it does not share and cannot influence. The release candidate remains held on #4956; this merge is not a promotion and makes no claim about macOS at this SHA.

@lidge-jun
lidge-jun marked this pull request as ready for review September 18, 2026 00:00
@lidge-jun
lidge-jun requested a review from Ingwannu as a code owner September 18, 2026 00:00
@lidge-jun
lidge-jun merged commit ad9eab3 into dev Sep 18, 2026
63 of 67 checks passed
@lidge-jun
lidge-jun deleted the codex/lane-g-2590-send-cap branch September 18, 2026 00:00
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 18, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-18T00:05:59.061096Z 50ecf06 Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 50ecf06273

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

if (opaqueBlobRecovery.kind === "recovered") {
upstreamResponse = opaqueBlobRecovery.response;
continue passthroughRecovery;
if (!configuredTransientSendBudgetExhausted()) {

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Preserve the upstream response when recovery has no allowance

When transientRetryOn5xx.attempts is 4–10 and the initial transient ladder consumes all three base sends, this predicate remains true because the configured total still has headroom. A recovery-eligible final response (for example, a 502 encrypted-function-output rejection) is therefore consumed and cancelled by attemptOpaqueBlobRecovery, but rebuildAndRefetch then receives zero attempts because line 911 disables the final reserve for every configured policy; the client gets a synthetic request_send_budget_exhausted 429 instead of the original upstream response. Gate the recovery on its effective allowance before mutating the response, or permit the reserve while the configured total still has headroom.

AGENTS.md reference: src/AGENTS.md:L19-L19

Useful? React with 👍 / 👎.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant