Report payload size when a Copilot or Claude Code hook POST fails - #309
Merged
Merged
Conversation
Hook telemetry is being rejected with 413 (704 events in 14 days), but the error report carries no size, so we cannot tell how far over the limit the payloads are or pick an ingress limit from data. Attach payload_size_bytes as a structured field rather than embedding it in the message: the gateway fingerprints on message.substring(0, 100), so a varying byte count in the text would split one issue into hundreds. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Uc9SimrhSKoJVj1WynML1a
AakashVelusamy
approved these changes
Sep 13, 2026
vigneshsubbiah16
left a comment
Collaborator
There was a problem hiding this comment.
✅ Security consensus: no issues found. (reviewers: claude, semgrep, gitleaks)
🤖 consensus review · reviewers: Claude, Semgrep, Gitleaks · head ea2d55af · 2026-09-13T12:31Z
Same change as the Copilot hook: claude-code telemetry is rejected with 413 (261 events in 14 days across AI-GATEWAY-ZN and -78) with no size recorded. Only send_to_api is instrumented. The other --data-binary sites in this hook (skills sync, policy fetch) are small and are not implicated in the 413s. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Uc9SimrhSKoJVj1WynML1a
vigneshsubbiah16
left a comment
Collaborator
There was a problem hiding this comment.
✅ Security consensus: no issues found. (reviewers: claude, semgrep, gitleaks)
🤖 consensus review · reviewers: Claude, Semgrep, Gitleaks · head ab6c46f2 · 2026-09-13T12:51Z
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
Hook telemetry is being rejected with 413 Request Entity Too Large:
We cannot currently size the problem. The hook reports that the call failed but never how big the request was, and the Sentry event we do get is the follow-up error report (
content-length: 191), not the rejected request. So we have no basis for choosing an nginxproxy-body-sizevalue.The discovery agent already logs exactly this (
payload_size_bytes: 2689633), which is the only reason we have a hard number on that side. This copies the same idea into both hooks.What
In
copilot/hooks/unbound.pyandclaude-code/hooks/unbound.py:report_error_to_gateway()andlog_error()take an optionalextradict, merged into the error entry.send_to_api()passespayload_size_byteson failure.datais encoded once and reused, so the reported size is the exact byte count handed to curl, not a character count.Structured field rather than text in the message on purpose: the gateway fingerprints on
message.substring(0, 100), so a varying byte count in the message would split one issue into hundreds of groups.Only
send_to_apiis instrumented. The other--data-binarysites in these hooks (skills sync, policy fetch) are small and not implicated in the 413s.Note on effect
This field only surfaces in Sentry once the gateway forwards it —
hookErrorHandler.tscurrently passes throughclient_timestamponly. Until that companion change lands this PR is inert but harmless.Rollout is via
SCRIPT_URLin each hook'smdm/setup.py, which points at main, so this needs promoting past staging to reach machines.Scope
Copilot and Claude Code, which are ~97% of the 413 volume.
augment/(31 events) takes the identical change if we want it.Testing
tests/copilot+tests/claude_code— 996 passed. The 2 failures are in copilot and are identical on cleanstaging(verified by stashing), so they are pre-existing and unrelated.Backward compatible:
extradefaults toNoneand every existing caller is unchanged.🤖 Generated with Claude Code
The PR appears safe to merge, with no outstanding correctness, security, or repository-rule issues.
Summary
payload_size_bytescontext when a POST fails.-fsSLcurl options include-f, so HTTP 413 responses produce a nonzero exit status and reach the instrumented failure branch.Reviews (3) · Last reviewed commit: "Report payload size when a Claude Code h..."