Skip to content

Activate required numeric bounds in dogfood - #1150

Open
KeenWill wants to merge 5 commits into
agent/bounds-required-config-gatefrom
agent/daemon-live-bounds-activation-stack
Open

Activate required numeric bounds in dogfood#1150
KeenWill wants to merge 5 commits into
agent/bounds-required-config-gatefrom
agent/daemon-live-bounds-activation-stack

Conversation

@KeenWill

@KeenWill KeenWill commented Aug 22, 2026

Copy link
Copy Markdown
Owner

Summary

  • merge the completed required numeric-bound configuration stack with the live deploy line
  • install the published 62-field dogfood policy before startup, retaining the ruled values without local defaults
  • heap-erase authoritative scheduler-pass futures before Tokio task construction; the absorbed adapter graph otherwise overflowed a worker stack when recovered goals activated

Meaningfully changed lines: 384 (excluding Cargo.lock).

Numeric-bound ceilings added: none. This stack makes existing audited bounds required configuration; dogfood uses the values published by #1124 unchanged.

Absorption ledger

Validation and deployment

Configuration tests (279), focused merged suites, warning-denied Clippy, the scheduler heap-erasure regression, daemon all-feature check, and release build pass. The approved web-search live smoke remains ignored.

…ll/signalbox into agent/daemon-live-redacted-tool-closeout

# Conflicts:
#	crates/model-provider-runtime/src/lib.rs
#	crates/model-runtime/src/cli_redaction.rs
Copilot AI lite review requested due to automatic review settings August 22, 2026 23:48
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for security reviews. Please try again later.

@coderabbitai

coderabbitai Bot commented Aug 22, 2026

Copy link
Copy Markdown

Warning

Your free Security trial is over. An organization admin can activate billing to continue.

@coderabbitai

coderabbitai Bot commented Aug 22, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro Plus

Run ID: fc6e1e24-5266-48d2-8e78-c206a6363ef9

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Comment @coderabbitai help to get the list of available commands.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@KeenWill
KeenWill deployed to claude-smoke August 22, 2026 23:49 — with GitHub Actions Active
@KeenWill
KeenWill changed the base branch from agent/daemon-live-redacted-tool-closeout-pr to agent/bounds-required-config-gate August 22, 2026 23:58
@chatgpt-codex-connector

Copy link
Copy Markdown

💡 Codex Review

.for_each_concurrent(self.numeric_bounds.concurrent_targets, |target| {

P2 Badge Reject zero convergence concurrency

When max_concurrent_convergence_sweep_targets is configured as 0, this passes Some(0) to StreamExt::for_each_concurrent, whose API interprets zero as no limit. Consequently, a value distinct from the schema's sole unbounded spelling ("none") launches every configured convergence target concurrently, defeating the operator's pressure bound; reject zero during construction or define an explicit paused path before calling this API.


configured_u64(model_configuration, "min_metadata_page_size"),
configured_u64(model_configuration, "max_metadata_page_size"),

P2 Badge Reject inverted metadata page-size ranges

The numeric-bound parser validates these two fields independently, so a configuration such as min_metadata_page_size = 101 and max_metadata_page_size = 100 starts successfully. Both metadata and conversation queries then reject every possible page size—clients learn the same impossible range—making both listing surfaces unusable until restart; validate min <= max while loading the configuration.


(`agent/scheduler-pass-pause`). Deployment-owned scheduler and liveness bounds
are verified against this PR (`agent/bounds-required-config-protocol`).

P2 Badge Update the scheduler specification for configured bounds

This newly added verification claim leaves the owning specification's implemented-behavior paragraphs stale: the Loop section still promises a fixed 16-pass cap and one-second sweep, while Ambiguous-operation reconciliation still specifies fixed 64-item windows, retry timings, and a five-attempt budget. Those values are now deployment policies and may be "none", so readers implementing the contract will preserve behavior the code no longer enforces; update those owning paragraphs along with this verification marker.

AGENTS.md reference: AGENTS.md:L46-L49


pub fn try_new(
title: Option<String>,
tags: Vec<String>,
attributes: Vec<(String, String)>,
archived: bool,
) -> Result<Self, SessionMetadataContentError> {
Self::try_new_with_count_limits(title, tags, attributes, archived, None, None)

P1 Badge Enforce metadata count limits in the status tool

Making the default constructor pass None for both count policies removes the only cardinality check used by session_status_update: its decoder still calls SessionMetadataContent::try_new at crates/tools-basic/src/session_status.rs:477-482, and the production tool is constructed without either deployment limit. A confirmed model tool call can therefore persist more tags or attributes than numeric_bounds.max_session_metadata_tags and max_session_metadata_attributes allow, potentially creating thousands of indexed rows despite the configured cap; route the limits into this tool ingress before using the unbounded constructor.


if configured_u64(&services.model_configuration, "max_blob_replica_count")
.is_some_and(|maximum| metadata.replica_count > maximum)
{
return Err(ProcessConnectionError::EncodeInvariant);

P2 Badge Enforce the blob replica cap before recording replicas

This post-read assertion is the only production use of max_blob_replica_count; blob upload still registers a verified replica unconditionally in apps/signalboxd/src/blob_upload_runtime.rs:171-197. For example, the accepted configuration value 0 still permits a new upload to commit one replica, after which every blob_metadata request for it terminates with EncodeInvariant instead of a response. Enforce the configured cap while admitting or registering replicas (or reject an impossible configuration) rather than discovering the violation on reads.


Self::try_new_with_content_limit(command_id, session, content, delivery, None)

P2 Badge Apply the configured message limit in signalbox-debug

The unbounded convenience constructor is still used by signalbox-debug at apps/signalboxd/src/bin/signalbox-debug.rs:543-553. In --anthropic mode that binary reads the deployment configuration and routes the new provider and tool-round bounds, but an input longer than numeric_bounds.max_message_utf8_bytes is nevertheless accepted and persisted because this call supplies None; read and pass the configured message limit before submitting the diagnostic session input.

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@github-actions

Copy link
Copy Markdown
Contributor

Rust coverage (report only)

Report only. This measurement has no threshold, gates no merge, and
fails no check; it exists so untested code stays visible.

Measured suite Outcome
workspace (--all-targets --all-features) success
persistence PostgreSQL (--ignored) success
signalboxd PostgreSQL (--ignored) failure
terminal-client PostgreSQL (--ignored) success
What this number does not measure
  • Doctests. cargo llvm-cov --doctests needs a nightly
    toolchain; this workspace pins stable, so the compile-fail
    sealing proofs and every other doctest are outside the
    denominator.
  • Live smokes, which spend real network requests or
    credentials and are never run here: the tools-github and
    tools-web smokes stay --ignored, and the whole-daemon and
    real-provider terminal smokes are skipped by name above.
  • The Swift native client, which Xcode measures separately.
  • One environment-clearing test in signalbox-tools-exec,
    which instrumenting its supervisor process perturbs. The
    workflow comment on the workspace step states why; rust.yml
    runs that test uninstrumented and gates on it.
  • Dedicated test files. cargo-llvm-cov excludes tests/
    and benches/ targets and *tests.rs modules from the
    report by default, so that test code is counted neither
    covered nor uncovered here. Inline #[cfg(test)] modules
    inside a source file are the exception: they are
    instrumented, and they land on both sides. A test body
    that ran counts as covered, which makes every percentage
    below optimistic; the body of an #[ignore]d test no
    measured suite runs counts as uncovered, which puts test
    lines into the file ranking. Read both tables as close,
    not exact.
Measure Covered Total Percent
Lines 253802 310989 81.61%
Functions 20700 25155 82.29%
Regions 321565 402358 79.92%

Per crate, least-covered first

Crate Line % Lines Function % Region %
crates/program-runtime 7.57% 38/502 5.77% 6.13%
crates/runner-wire 60.41% 644/1066 62.67% 59.14%
apps/signalboxd 63.69% 35461/55674 70.81% 63.59%
crates/tools-sessions 65.06% 378/581 63.29% 61.68%
apps/signalbox-runner 69.47% 1784/2568 70.93% 70.29%
crates/approval-judge-eval 73.87% 492/666 76.12% 76.41%
crates/tool-schema-derive 74.20% 279/376 88.00% 72.42%
crates/tools-basic 75.37% 771/1023 66.15% 79.16%
crates/model-runtime-claude-cli 76.49% 1653/2161 73.10% 77.35%
crates/tools-github 77.06% 2408/3125 74.19% 74.82%
crates/tools-exec 77.43% 5174/6682 74.71% 73.71%
apps/client 78.88% 13283/16840 89.58% 75.76%
crates/persistence 80.06% 53900/67323 78.03% 75.48%
crates/tools-code-host 80.39% 7089/8818 80.46% 76.60%
crates/blob-store-filesystem 80.50% 1371/1703 70.17% 80.45%
crates/model-provider-runtime 81.47% 2454/3012 85.71% 79.95%
crates/blob-store 82.57% 308/373 75.41% 83.68%
crates/tools-conversations 83.01% 508/612 83.78% 77.65%
crates/egress-transport 85.35% 134/157 83.33% 77.61%
crates/conversation-import-claude-code 85.45% 740/866 66.09% 84.67%
crates/tools-plan 85.71% 768/896 88.89% 81.74%
crates/conversation-import-codex 85.76% 873/1018 64.00% 83.56%
crates/tools-workspace 86.36% 2977/3447 82.14% 87.30%
crates/tools-web 86.59% 2978/3439 87.93% 85.03%
crates/tools-git 87.40% 8750/10011 86.50% 83.24%
crates/application 88.63% 19154/21610 87.86% 88.80%
crates/model-runtime-codex-cli 90.00% 1548/1720 90.98% 89.95%
crates/test-bin 90.91% 10/11 100.00% 70.00%
crates/domain 92.28% 60106/65137 91.36% 94.12%
crates/web-contract 92.31% 408/442 82.61% 82.09%
crates/conversation-import-json 92.51% 284/307 96.88% 91.36%
crates/model-runtime-openai 93.55% 3812/4075 97.50% 91.72%
crates/process-protocol 93.67% 8469/9041 95.89% 86.68%
crates/model-runtime-anthropic 93.88% 3910/4165 97.51% 91.26%
crates/model-runtime 93.98% 9221/9812 93.29% 94.70%
crates/expect-table 95.60% 977/1022 100.00% 95.75%
crates/tool-contract 97.18% 688/708 96.47% 95.54%

25 files with the most uncovered lines

File Uncovered lines Line %
apps/signalboxd/src/process_runtime.rs 6571 53.43%
apps/signalboxd/src/repo_watch_runtime.rs 2235 69.20%
apps/signalboxd/src/runner_protocol_runtime.rs 2212 34.75%
crates/persistence/src/submit_input.rs 2071 71.81%
apps/client/src/lib.rs 1697 79.51%
apps/signalboxd/src/review_orchestration_runtime.rs 1333 2.56%
apps/signalboxd/src/main.rs 1303 47.46%
crates/persistence/src/model_execution.rs 1243 84.56%
crates/domain/src/turn_eligibility.rs 1223 90.33%
crates/persistence/src/runner_protocol.rs 1157 82.16%
crates/tools-code-host/src/code_host/github.rs 1052 76.26%
crates/persistence/src/review_workflow.rs 997 77.35%
crates/tools-exec/src/bin/signalbox-exec-supervisor.rs 885 45.61%
crates/persistence/src/tool_loop.rs 732 76.49%
crates/tools-github/src/lib.rs 717 76.47%
apps/signalboxd/src/convergence_sweep_runtime.rs 683 22.21%
apps/client/src/presentation.rs 680 80.55%
crates/persistence/src/process_read.rs 679 82.35%
apps/signalboxd/src/lib.rs 647 72.20%
crates/domain/src/submit_input.rs 640 88.03%
apps/signalboxd/src/daemon_tools.rs 573 89.68%
crates/process-protocol/src/lib.rs 572 93.67%
crates/persistence/src/review_orchestration.rs 569 75.66%
crates/persistence/src/session_delegation.rs 543 77.63%
crates/application/src/model_execution.rs 541 86.05%

Measured at cd918dde57beb27e4c8eeb5ac1660ed027be1d9c, the merge commit this pull request builds, whose head is 1fd78d4f037ac1b1886ed8ed3c94d8fb1f7bc661, by run 32606701692, which uploads the HTML report and LCOV as an artifact.

@codecov

codecov Bot commented Aug 23, 2026

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 98.30508% with 2 lines in your changes missing coverage. Please review.
✅ Project coverage is 82.27%. Comparing base (5466001) to head (1fd78d4).

Files with missing lines Patch % Lines
crates/model-runtime/src/cli_redaction.rs 96.00% 1 Missing ⚠️
crates/model-runtime/src/redaction.rs 0.00% 1 Missing ⚠️
Additional details and impacted files
Flag Coverage Δ
rust 82.85% <98.30%> (-0.01%) ⬇️

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants