Skip to content

Report payload size when a Copilot or Claude Code hook POST fails - #309

Merged
anonpran merged 2 commits into
stagingfrom
nanda/hook-error-payload-size
Sep 13, 2026
Merged

anonpran merged 2 commits into
stagingfrom
nanda/hook-error-payload-size

Conversation

@anonpran

@anonpran anonpran commented Sep 13, 2026 •

Copy link
Copy Markdown
Contributor

Why

Hook telemetry is being rejected with 413 Request Entity Too Large:

client Sentry issue events (14d)
Copilot AI-GATEWAY-1A5, -14M 712
Claude Code AI-GATEWAY-ZN, -78 261

We cannot currently size the problem. The hook reports that the call failed but never how big the request was, and the Sentry event we do get is the follow-up error report (content-length: 191), not the rejected request. So we have no basis for choosing an nginx proxy-body-size value.

The discovery agent already logs exactly this (payload_size_bytes: 2689633), which is the only reason we have a hard number on that side. This copies the same idea into both hooks.

What

In copilot/hooks/unbound.py and claude-code/hooks/unbound.py:

  • report_error_to_gateway() and log_error() take an optional extra dict, merged into the error entry.
  • send_to_api() passes payload_size_bytes on failure.
  • data is encoded once and reused, so the reported size is the exact byte count handed to curl, not a character count.

Structured field rather than text in the message on purpose: the gateway fingerprints on message.substring(0, 100), so a varying byte count in the message would split one issue into hundreds of groups.

Only send_to_api is instrumented. The other --data-binary sites in these hooks (skills sync, policy fetch) are small and not implicated in the 413s.

Note on effect

This field only surfaces in Sentry once the gateway forwards it — hookErrorHandler.ts currently passes through client_timestamp only. Until that companion change lands this PR is inert but harmless.

Rollout is via SCRIPT_URL in each hook's mdm/setup.py, which points at main, so this needs promoting past staging to reach machines.

Scope

Copilot and Claude Code, which are ~97% of the 413 volume. augment/ (31 events) takes the identical change if we want it.

Testing

tests/copilot + tests/claude_code — 996 passed. The 2 failures are in copilot and are identical on clean staging (verified by stashing), so they are pre-existing and unrelated.

Backward compatible: extra defaults to None and every existing caller is unchanged.

🤖 Generated with Claude Code

RetriggerConfidence Score: 5/5

The PR appears safe to merge, with no outstanding correctness, security, or repository-rule issues.

Summary

  • Encodes each exchange once and reuses the exact bytes passed to curl.
  • Adds the encoded payload size as structured payload_size_bytes context when a POST fails.
  • Extends existing error-reporting helpers with optional structured fields while preserving existing callers.
  • The prior HTTP-error concern is resolved: the existing -fsSL curl options include -f, so HTTP 413 responses produce a nonzero exit status and reach the instrumented failure branch.

Reviews (3) · Last reviewed commit: "Report payload size when a Claude Code h..."

Hook telemetry is being rejected with 413 (704 events in 14 days), but the
error report carries no size, so we cannot tell how far over the limit the
payloads are or pick an ingress limit from data.

Attach payload_size_bytes as a structured field rather than embedding it in
the message: the gateway fingerprints on message.substring(0, 100), so a
varying byte count in the text would split one issue into hundreds.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Uc9SimrhSKoJVj1WynML1a
@anonpran
anonpran requested a review from a team September 13, 2026 12:26

@vigneshsubbiah16 vigneshsubbiah16 left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Security consensus: no issues found. (reviewers: claude, semgrep, gitleaks)


🤖 consensus review · reviewers: Claude, Semgrep, Gitleaks · head ea2d55af · 2026-09-13T12:31Z

Same change as the Copilot hook: claude-code telemetry is rejected with 413
(261 events in 14 days across AI-GATEWAY-ZN and -78) with no size recorded.

Only send_to_api is instrumented. The other --data-binary sites in this hook
(skills sync, policy fetch) are small and are not implicated in the 413s.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Uc9SimrhSKoJVj1WynML1a
@anonpran anonpran changed the title Report payload size when a Copilot hook POST fails Report payload size when a Copilot or Claude Code hook POST fails Sep 13, 2026
Comment thread copilot/hooks/unbound.py
@anonpran
anonpran merged commit 0a78f32 into staging Sep 13, 2026
4 checks passed

@vigneshsubbiah16 vigneshsubbiah16 left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Security consensus: no issues found. (reviewers: claude, semgrep, gitleaks)


🤖 consensus review · reviewers: Claude, Semgrep, Gitleaks · head ab6c46f2 · 2026-09-13T12:51Z

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants