Skip to content

fix(bedrock): expose Opus 5.5 output token limit - #1903

Merged
edelauna merged 1 commit into
Zoo-Code-Org:mainfrom
PierrunoYT:fix/bedrock-opus-5-5-output-limit
Oct 4, 2026
Merged

edelauna merged 1 commit into
Zoo-Code-Org:mainfrom
PierrunoYT:fix/bedrock-opus-5-5-output-limit

Conversation

@PierrunoYT

Copy link
Copy Markdown
Contributor

Summary

  • mark Bedrock Claude Opus 5.5 as supporting configurable max output tokens
  • expose the existing Max Tokens slider up to the documented 128K ceiling
  • honor explicit Opus 5.5 output limits with reasoning disabled as well as enabled
  • replace the provider test's model-name suffix check with the model capability flag

Context

Follow-up to #1718. That PR added explicit output-limit handling and exposed the control for Sonnet 5 and Opus 5, but Opus 5.5 retained the 128K model ceiling without supportsMaxTokens. As a result, users received the new “increase Max Output Tokens” error but had no Opus 5.5 control with which to do so.

Validation

  • Bedrock provider suite: 119 passed
  • ThinkingBudget UI suite: 42 passed
  • @roo-code/types, webview, and extension typechecks passed
  • full pre-commit lint: 11 packages passed
  • rendered the Opus 5.5 gallery state locally and confirmed the 16,384 default slider and reasoning control render without clipping

@coderabbitai

coderabbitai Bot commented Oct 4, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Repository: Zoo-Code-Org/Zoo-Code/.coderabbit.yaml
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: f484d145-41f5-459a-88a9-1c2263e30a5b
📥 Commits

Reviewing files that changed from the base of the PR and between 3859e5d and c041824.

📒 Files selected for processing (3)
  • packages/types/src/providers/bedrock.ts
  • src/api/providers/__tests__/bedrock.spec.ts
  • webview-ui/src/components/settings/__tests__/ThinkingBudget.spec.tsx

Included review availability: This review used your included allowance. Your plan provides up to 4 included reviews per hour; 3 remain after this review.

📜 Recent review details
🧰 Additional context used
📓 Path-based instructions (7)
Treat model, provider, MCP, path, command, and tool data as untrusted.

⚙️ CodeRabbit configuration file

Files:

  • src/api/providers/__tests__/bedrock.spec.ts
For persisted settings, verify the complete schema/storage/runtime/webview round trip, shared default semantics, and focused true plus false/unset tests.

⚙️ CodeRabbit configuration file

Files:

  • packages/types/src/providers/bedrock.ts
  • webview-ui/src/components/settings/__tests__/ThinkingBudget.spec.tsx
Require regression coverage at the lowest valid harness with behavior-focused assertions, including relevant negative, error, false/unset, and boundary cases.

⚙️ CodeRabbit configuration file

Files:

  • webview-ui/src/components/settings/__tests__/ThinkingBudget.spec.tsx
  • src/api/providers/__tests__/bedrock.spec.ts
Check strict typing and exhaustive behavior across normal, boundary, error, cancellation, retry, and compatibility paths.

⚙️ CodeRabbit configuration file

Files:

  • packages/types/src/providers/bedrock.ts
  • webview-ui/src/components/settings/__tests__/ThinkingBudget.spec.tsx
  • src/api/providers/__tests__/bedrock.spec.ts
Check React state and effect dependencies, cleanup, accessibility, i18n, and light/dark theme behavior.

⚙️ CodeRabbit configuration file

Files:

  • webview-ui/src/components/settings/__tests__/ThinkingBudget.spec.tsx
Verify extension/webview contracts, cancellation and error propagation, VS Code lifecycle correctness, and behavior under retries and partial failure.

⚙️ CodeRabbit configuration file

Files:

  • src/api/providers/__tests__/bedrock.spec.ts
Act as an adversarial second-opinion reviewer.

⚙️ CodeRabbit configuration file

Files:

  • packages/types/src/providers/bedrock.ts
  • webview-ui/src/components/settings/__tests__/ThinkingBudget.spec.tsx
  • src/api/providers/__tests__/bedrock.spec.ts
🔇 Additional comments (3)
packages/types/src/providers/bedrock.ts (1)

261-261: LGTM!

src/api/providers/__tests__/bedrock.spec.ts (1)

144-144: LGTM!

Also applies to: 149-150, 154-154

webview-ui/src/components/settings/__tests__/ThinkingBudget.spec.tsx (1)

87-87: LGTM!


📝 Summary

Summary by CodeRabbit

  • New Features
    • Amazon Bedrock’s Claude Opus 5.5 model now supports configuring an output limit of up to 128,000 tokens.

Walkthrough

Bedrock metadata now marks anthropic.claude-opus-5-5 as supporting max tokens. Provider and settings tests cover its 128,000-token output ceiling.

Changes

Bedrock Opus 5.5 token ceiling

Layer / File(s) Summary
Model capability and ceiling tests
packages/types/src/providers/bedrock.ts, src/api/providers/__tests__/bedrock.spec.ts, webview-ui/src/components/settings/__tests__/ThinkingBudget.spec.tsx
The Opus 5.5 model entry sets supportsMaxTokens. The provider test derives expected limits from that capability and includes the model at 128,000 tokens. The settings test adds the same ceiling to its test matrix.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~8 minutes

Change: Bug fix

Merge Risk: ⚪ Minimal · up to c0418

Opus 5.5’s 128,000-token limit is honored with reasoning enabled or disabled. Values above that limit can reach Bedrock, but no resulting failure is established; no actionable merge-blocking risk remains.

Security Architecture Review

Security architecture risk: 🔵 Low · up to c0418

The change makes an existing response-size setting configurable without changing access or destinations. Ordinary selections stay within the advertised limit, but enforcement outside that control is not fully established.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The demonstrated exposure is the output budget of requests using the affected model configuration, including streaming and non-streaming calls. The flag does not alter model ARN selection or global and cross-region routing. Wider tenant, asset, or environment exposure is not established.

Security Findings and Attack Paths

  • inferred — A supplied setting above 128,000 can reach the request. This was already possible with reasoning enabled; the capability flag extends it to reasoning-disabled calls. Establishing an attack would additionally require an unauthorized configuration source and a harmful downstream consequence, neither of which is established here. This is not a verified vulnerability.

Trust Boundaries and Controls

  • observed — Output sizing is taken from provider configuration, independently of model routing. The same configuration schema exposes both the output limit and reasoning toggle, so above-ceiling configuration does not require newly granted authority. Authentication and configuration-ingress controls outside this flow remain unverified.

Hardening Proposals

  • proposed — If the advertised maximum is intended to be an enforced application policy, preserve an immutable catalog ceiling and validate explicit settings against it before request construction. This would strengthen a pre-existing enforcement gap rather than remedy a demonstrated privilege escalation.
🚥 Pre-merge checks | ✅ 7 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Regression Evidence ⚠️ Warning The change exposes the Max Output Tokens slider for Bedrock Opus 5.5, but the required Playwright component snapshot does not cover that new visible state. The existing ThinkingBudget.visual.tsx tes… Extend the Bedrock output-budget Playwright story and snapshot coverage to render Opus 5.5, then add or update the corresponding component snapshot.
✅ Passed checks (7 passed)
Check name Status Explanation
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Security Boundaries ✅ Passed The changed production path only adds supportsMaxTokens: true to the static anthropic.claude-opus-5-5 model metadata in packages/types/src/providers/bedrock.ts. It exposes the existing Max Token…
Persistence Integrity ✅ Passed No changed persistence path exists. The only production change adds supportsMaxTokens: true to the Bedrock Opus 5.5 model metadata; the other changes update tests. This metadata enables the existing…
Lifecycle Resource Cleanup ✅ Passed The changed runtime code only adds supportsMaxTokens: true to the Bedrock Opus 5.5 model metadata. The other changes update tests. The diff adds no listener, watcher, provider lifecycle, timer, task…
Title check ✅ Passed The title clearly and concisely states the main change: exposing the Bedrock Opus 5.5 output token limit.
Description check ✅ Passed The description explains the change, its context, and validation results. It references follow-up issue #1718, but it does not use all template headings or complete the pre-submission checklist.
Full details: Regression Evidence

Explanation

The change exposes the Max Output Tokens slider for Bedrock Opus 5.5, but the required Playwright component snapshot does not cover that new visible state. The existing ThinkingBudget.visual.tsx test mounts the bedrock-output-budget story, whose default model is Opus 5; neither the story nor snapshot coverage changed. The new Vitest case verifies the Opus 5.5 slider functionally, but it does not provide a Playwright component snapshot for Opus 5.5.

  • Fix all pre-merge checks with AI
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

github-actions Bot commented Oct 4, 2026 •

Copy link
Copy Markdown
Contributor

Review status

Thanks for contributing. This comment tracks the review sequence and the next action.

Current step: Awaiting fresh human maintainer or CODEOWNER approval.

Automated review is complete for the latest commit but does not replace human approval.

Review-state labels are managed by this workflow; do not edit them manually. community-approved is managed the same way — do not add or remove it manually. It signals a fresh community code approval for the current head as an advisory priority only; maintainer review is still required.

@codecov

codecov Bot commented Oct 4, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

@github-actions github-actions Bot added coderabbit-review-active Required CI passed; CodeRabbit review is active awaiting-coderabbit Waiting for CodeRabbit to approve the latest commit labels Oct 4, 2026
@github-actions github-actions Bot added awaiting-maintainer CodeRabbit approved; waiting for a human maintainer and removed coderabbit-review-active Required CI passed; CodeRabbit review is active awaiting-coderabbit Waiting for CodeRabbit to approve the latest commit labels Oct 4, 2026
@edelauna
edelauna added this pull request to the merge queue Oct 4, 2026
Merged via the queue into Zoo-Code-Org:main with commit 754a916 Oct 4, 2026
22 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

awaiting-maintainer CodeRabbit approved; waiting for a human maintainer

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants