Skip to content

fix(spend): refuse unbooked dispatches under applicable ceilings - #6538

Merged
lidge-jun merged 1 commit into
devfrom
codex/spend-capacity-guard
Oct 3, 2026
Merged

lidge-jun merged 1 commit into
devfrom
codex/spend-capacity-guard

Conversation

@lidge-jun

@lidge-jun lidge-jun commented Oct 3, 2026 •

Copy link
Copy Markdown
Owner

Summary

  • A configured token ceiling could still authorize a new dispatch when the spend ledger refused to reserve tokens because tracking capacity was full. The request tracker now refuses every unbooked predispatch send when a ceiling applies to that request's root, identity or pool, using the existing refusal diagnostics.
  • Requests without an applicable ceiling remain observe-only. Already-sent reports preserve their physical-send count without claiming a local refusal. That existing post-reporting path can still leave durable accounting incomplete when a booking fails; this patch does not claim to resolve it.
  • The only runtime change is src/server/responses/request-spend.ts. Ledger serialization, hashes, journal version, receipt handling and updater behavior are unchanged. This is an isolated follow-up associated with fix(responses): record the canonical spend pool for request usage #6370; that source PR remains open and its canonical accounting work is not included.

Co-authored-by: Epinephrine luvs01@hanmail.net

Verification

  • Original capacity probe reproduced RED on current dev; after the repair, the probe plus 15 new tests passed: 16 tests / 118 assertions. New cases cover both tracking limits, each configured scope, absent scopes, observe-only requests, already-sent reports, policy/identity changes and specific denial reasons.

  • bun test tests/responses/responses-spend-capacity-guard.test.ts tests/responses/responses-spend-ledger-wiring.test.ts tests/responses/chat-native-spend.test.ts tests/lib/spend-reservation-ledger.test.ts tests/lib/spend-ledger-file-journal.test.ts tests/lib/spend-ceiling-enforcement.test.ts tests/lib/workflow-budget.test.ts tests/lib/execution-budget-permits.test.ts tests/server/spend-instrumentation-log.test.ts tests/server/spend-ledger-lifecycle.test.ts tests/config/config-spend-ceilings.test.ts tests/responses/responses-core-modules.test.ts tests/test-layout.test.ts tests/test-layout-tooling.test.ts tests/ci-workflows/file-size-ratchet.test.ts: 179 passed, 0 failed, 1,860 assertions.

  • bun test tests/server/inference-send-budget.test.ts tests/responses/responses-send-budget-errors.test.ts tests/responses/responses-send-budget-counts.test.ts: 34 passed, 0 failed, 159 assertions.

  • bun run typecheck, bun run privacy:scan, bun run structure:check, and git diff --check: passed. cd docs-site && bun install --frozen-lockfile && bun run build: passed, 561 pages and 77,944 checked internal links.

  • Independent architecture and plan/security review passed; independent implementation security review found no blockers and passed nine additional scope/ownership/laziness probes. The ledger, ownership, execution-budget and workflow-policy source bytes match base dd9a980ec071285e628a35d8cdefaea785b8916b.

  • Full local suite deferred under the documented resource exception due to concurrent worktrees. Focused changed behavior and source-oracle checks are recorded above; hosted full relevant CI is required at the current PR head. Native packaged Windows/macOS and live-provider behavior were not tested. Coordinator owns integration and final combined regression.

  • Exact-head hosted Cross-platform CI37148359842, pull_request attempt1, succeeded at c46febd82eb99df72855af91f130fcfb7fbf4929: all17 executed jobs passed;8 deliberate platform/filter skips remain untested. Target/hygiene/label/ReactDoctor checks also passed.

  • Coordinator independent capacity/security review passed the exact head. Nonblocking follow-up retained: Native Chat/Messages may replace the tracker-specific capacity diagnostic with generic spend-exhausted; enforcement still refuses. Coordinator owns its disposition and merge.

Checklist

  • Scope stays focused and avoids unrelated cleanup.
  • Docs or release notes were updated when needed.
  • Security-sensitive changes were reviewed for secrets, auth, and unsafe defaults.

Summary by CodeRabbit

  • Bug Fixes
    • Requests subject to a token limit are now refused before dispatch when their token reservation cannot be recorded, including when tracking capacity is full. Requests without an applicable limit remain in observe-only mode.
  • Documentation
    • Clarified token reservation and limit behavior in the server configuration documentation.

Check the existing ledger policy against each charge's scopes before translating
a refused booking. Capacity and duplicate failures cannot authorize another send
under a configured ceiling. Preserve observe-only and post-reported behavior.

Co-authored-by: Epinephrine <luvs01@hanmail.net>
@coderabbitai

coderabbitai Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Note

Currently processing new changes in this PR. This may take a few minutes, please wait...

⚙️ Run configuration
  • Configuration used: Repository: lidge-jun/opencodex/.coderabbit.yaml
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: 5bed7cb6-4046-451a-a65d-4fd4da66bdc7
📥 Commits

Reviewing files that changed from the base of the PR and between dd9a980 and c46febd.

📒 Files selected for processing (10)
  • docs-site/src/content/docs/ja/reference/configuration/server.md
  • docs-site/src/content/docs/ko/reference/configuration/server.md
  • docs-site/src/content/docs/reference/configuration/server.md
  • docs-site/src/content/docs/ru/reference/configuration/server.md
  • docs-site/src/content/docs/zh-cn/reference/configuration/server.md
  • scripts/test-layout/layout.json
  • src/server/responses/request-spend.ts
  • structure/transports/responses-spend.md
  • tests/fixtures/test-layout-expected.json
  • tests/responses/responses-spend-capacity-guard.test.ts
 _____________________________________________________________________________________________
< Use the power of command shells. Use the shell when graphical user interfaces don't cut it. >
 ---------------------------------------------------------------------------------------------
  \
   \   \
        \ /\
        ( )
      .( o ).
✨ Finishing Touches
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

github-actions Bot commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

✅ Deterministic PR hygiene checks passed.

@github-actions github-actions Bot added the bug Something isn't working label Oct 3, 2026
@lidge-jun
lidge-jun marked this pull request as ready for review October 3, 2026 19:43
@lidge-jun
lidge-jun requested a review from Ingwannu as a code owner October 3, 2026 19:43
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 3, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-03T19:47:08.355798Z c46febd Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@lidge-jun

Copy link
Copy Markdown
Owner Author

Maintainer integration decision: integrate this narrow capacity guard into dev under the owner-authorized stabilization train and current maintainer-integration policy. This is not self-approval. Independent coordinator code/security review at c46febd82eb99df72855af91f130fcfb7fbf4929 found no blockers and verified the demonstrated applicable-ceiling booking-failure admission defect is closed. The sole runtime change is the request tracker; the ledger, hash domains, journal schema, ownership, execution budget and workflow budget are byte-identical to dev. The separate canonical migration in #6370 remains deferred and unresolved.

The baseline failed before repair; the same probe plus 15 new cases passed afterward. The supplied broader consumer sets total213passes. Applicability, observe-only availability, alreadySent handling, privacy, docs and matching layout registrations were reviewed. Union line caps and map parity pass.

Explicit nonblocking Low follow-up: Native Chat/Messages handlers still collapse the tracker-selected capacity reason into generic spend-exhausted diagnostics. The physical send is correctly refused; the remaining difference affects explanation, not enforcement. This is retained as a follow-up in this integration record rather than being claimed fixed. Full integrated independent regression and final complete platform CI remain required before publication.

The optional external CodeRabbit review context is still pending and is not counted as a passing review. Current-head independent review is complete and every currently published finding is resolved; post-merge/final review checks remain mandatory.

Hosted receipt: https://github.com/lidge-jun/opencodex/actions/runs/37148359842, attempt 1, pull_request, tested head c46febd82eb99df72855af91f130fcfb7fbf4929 / base dd9a980ec071285e628a35d8cdefaea785b8916b. Current reviewed dev base dd9a980ec071285e628a35d8cdefaea785b8916b; conflict-free union tree a5d4b49dfa58c46e2a1ecb3f6dd04dcb34524418. All four Linux shards and selected gates/storage/API/docs/structure/Docker/keyring/npm-global jobs succeeded. Skipped full-platform suites are not claimed passing; final integrated lane=all remains required.

@lidge-jun
lidge-jun merged commit efc20e7 into dev Oct 3, 2026
40 of 41 checks passed
@lidge-jun
lidge-jun deleted the codex/spend-capacity-guard branch October 3, 2026 19:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant