Repository navigation
fix(spend): refuse unbooked dispatches under applicable ceilings - #6538
Conversation
Check the existing ledger policy against each charge's scopes before translating a refused booking. Capacity and duplicate failures cannot authorize another send under a configured ceiling. Preserve observe-only and post-reported behavior. Co-authored-by: Epinephrine <luvs01@hanmail.net>
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. Note Currently processing new changes in this PR. This may take a few minutes, please wait... ⚙️ Run configuration
📒 Files selected for processing (10)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
✅ Deterministic PR hygiene checks passed. |
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
|
Maintainer integration decision: integrate this narrow capacity guard into dev under the owner-authorized stabilization train and current maintainer-integration policy. This is not self-approval. Independent coordinator code/security review at The baseline failed before repair; the same probe plus 15 new cases passed afterward. The supplied broader consumer sets total213passes. Applicability, observe-only availability, alreadySent handling, privacy, docs and matching layout registrations were reviewed. Union line caps and map parity pass. Explicit nonblocking Low follow-up: Native Chat/Messages handlers still collapse the tracker-selected capacity reason into generic spend-exhausted diagnostics. The physical send is correctly refused; the remaining difference affects explanation, not enforcement. This is retained as a follow-up in this integration record rather than being claimed fixed. Full integrated independent regression and final complete platform CI remain required before publication. The optional external CodeRabbit review context is still pending and is not counted as a passing review. Current-head independent review is complete and every currently published finding is resolved; post-merge/final review checks remain mandatory. Hosted receipt: https://github.com/lidge-jun/opencodex/actions/runs/37148359842, attempt 1, pull_request, tested head |
Summary
src/server/responses/request-spend.ts. Ledger serialization, hashes, journal version, receipt handling and updater behavior are unchanged. This is an isolated follow-up associated with fix(responses): record the canonical spend pool for request usage #6370; that source PR remains open and its canonical accounting work is not included.Co-authored-by: Epinephrine luvs01@hanmail.net
Verification
Original capacity probe reproduced RED on current
dev; after the repair, the probe plus 15 new tests passed: 16 tests / 118 assertions. New cases cover both tracking limits, each configured scope, absent scopes, observe-only requests, already-sent reports, policy/identity changes and specific denial reasons.bun test tests/responses/responses-spend-capacity-guard.test.ts tests/responses/responses-spend-ledger-wiring.test.ts tests/responses/chat-native-spend.test.ts tests/lib/spend-reservation-ledger.test.ts tests/lib/spend-ledger-file-journal.test.ts tests/lib/spend-ceiling-enforcement.test.ts tests/lib/workflow-budget.test.ts tests/lib/execution-budget-permits.test.ts tests/server/spend-instrumentation-log.test.ts tests/server/spend-ledger-lifecycle.test.ts tests/config/config-spend-ceilings.test.ts tests/responses/responses-core-modules.test.ts tests/test-layout.test.ts tests/test-layout-tooling.test.ts tests/ci-workflows/file-size-ratchet.test.ts: 179 passed, 0 failed, 1,860 assertions.bun test tests/server/inference-send-budget.test.ts tests/responses/responses-send-budget-errors.test.ts tests/responses/responses-send-budget-counts.test.ts: 34 passed, 0 failed, 159 assertions.bun run typecheck,bun run privacy:scan,bun run structure:check, andgit diff --check: passed.cd docs-site && bun install --frozen-lockfile && bun run build: passed, 561 pages and 77,944 checked internal links.Independent architecture and plan/security review passed; independent implementation security review found no blockers and passed nine additional scope/ownership/laziness probes. The ledger, ownership, execution-budget and workflow-policy source bytes match base
dd9a980ec071285e628a35d8cdefaea785b8916b.Full local suite deferred under the documented resource exception due to concurrent worktrees. Focused changed behavior and source-oracle checks are recorded above; hosted full relevant CI is required at the current PR head. Native packaged Windows/macOS and live-provider behavior were not tested. Coordinator owns integration and final combined regression.
Exact-head hosted Cross-platform CI37148359842, pull_request attempt1, succeeded at
c46febd82eb99df72855af91f130fcfb7fbf4929: all17 executed jobs passed;8 deliberate platform/filter skips remain untested. Target/hygiene/label/ReactDoctor checks also passed.Coordinator independent capacity/security review passed the exact head. Nonblocking follow-up retained: Native Chat/Messages may replace the tracker-specific capacity diagnostic with generic spend-exhausted; enforcement still refuses. Coordinator owns its disposition and merge.
Checklist
Summary by CodeRabbit