🪟 feat: Preserve Command Output Heads and Tails - #275
lia-by-librechat[bot] wants to merge 1 commit into
Conversation
B1 head handoffPushed head:
The summary and timeout probes fail on the previous collector; cancellation remains unchanged. The local public native sandbox suite stops at the existing private-storage ownership guard before command execution, and unchanged main reproduces that root-ownership rejection. CI's three full code-package matrix lanes and Linux native-sandbox lane passed this exact head. Existing Independent review was requested for this exact head. The child runner failed to complete and returned no review verdict or finding ledger. This is not a clean review; severity counts and dispositions are unavailable. No GitHub inline review findings were present at the handoff check. A1/A2 PRs are untouched. No deployment, merge, or benchmark improvement is claimed. |
|
@codex review Please review B1 at exact pushed head Scope: bounded head-and-tail native command output, separate stdout/stderr, stderr reservation, inline omission counts, UTF-8/combined-budget enforcement, and unchanged timeout/cancellation/result contracts. A1/A2 and filesystem/search/patch slices are excluded. Local focused collector/protocol/subprocess checks and real-Bash collector probes pass. Public native sandbox tests are blocked before execution by the existing private-storage ancestor guard in this worker; unchanged main reproduces the same root-ownership rejection. Full CI and independent exact-head review run separately. |
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: f11f51d036
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| const stdoutBudget = Math.min( | ||
| stdout.bytes, | ||
| budget - stderrReserve + Math.max(0, stderrReserve - stderr.bytes) | ||
| ); |
There was a problem hiding this comment.
Allocate quiet-stream space using rendered byte sizes
When one stream is noisy and the other contains malformed UTF-8, this calculation donates space based on the quiet stream's raw byte count even though decoding may expand each invalid byte into a three-byte replacement character. For example, with a 32-byte limit, large stdout, and stderr containing two 0xff bytes, stdout receives 30 bytes and stderr.render(2) returns an empty string, even though the six rendered stderr bytes could fit by reducing stdout's allocation. This can completely starve stderr in exactly the malformed-output case the collector supports; budget using the rendered size or rebalance unused space after rendering.
Useful? React with 👍 / 👎.
Summary
Attached native commands currently keep only the first output bytes that reach a shared stdout/stderr budget. Long test runs lose their final summaries, and noisy stdout can consume the entire allowance before an error reaches stderr.
Keep a bounded prefix and rolling suffix for each stream, then fit both into the existing combined
maxOutputByteslimit. Inline[... N bytes omitted ...]markers report dropped raw bytes. Stdout and stderr remain separate; quiet streams donate unused space, while noisy streams split the budget with the odd byte reserved for stderr. Sandbox violation annotations enter stderr before final rendering.This is B1 only. LibreChat A1/A2 remain in #16539 and #16540. No parent creation, read/search changes, edits, model-family selection, or patch execution is included. This does not depend on worker #271.
Mechanism
maxOutputBytes, independent of total output and chunk count. No references to oversized child buffers or per-chunk buffer arrays survive capture.truncatedflag.Verification
Focused checks and exact-head review results are recorded in the head handoff comment.
native-sandbox.test.tssuite is blocked before command execution by the existing private-storage ancestor guard because this worker sandbox's/belongs to uid 65534. Unchangedmainreproduces that failure. The guard was not weakened. Collector-boundary probes do not certify SRT admission or confinement.Not run locally: the complete
packages/codesuite, live SRT confinement tests, service/API builds or Bun suites. Onlypackages/codesource changes. No deployment or benchmark improvement is claimed.