Skip to content

[WRONG BRANCH] fix(logs): bound response metadata inspection - #177

Draft
luvs01 wants to merge 1 commit into
mainfrom
codex/propose-fix-for-unbounded-response-buffering
Draft

[WRONG BRANCH] fix(logs): bound response metadata inspection#177
luvs01 wants to merge 1 commit into
mainfrom
codex/propose-fix-for-unbounded-response-buffering

Conversation

@luvs01

@luvs01 luvs01 commented Aug 8, 2026

Copy link
Copy Markdown
Owner

Motivation

  • Prevent untrusted upstream responses (JSON or SSE) from being fully buffered by the metadata-inspection paths and exhausting proxy memory or defeating client backpressure.

Description

  • Add a global inspection cap MAX_RESPONSE_LOG_INSPECTION_BYTES (32 MiB) and an InspectionConsumerOptions.maxInspectionBytes option to bound total bytes inspected for metadata.
  • Update the bounded inspection pump to only feed up to the inspection limit into the inspector and to cancel the inspection reader branch when the limit is reached so client delivery (the other tee branch) and backpressure are preserved.
  • Replace unbounded response.text() usage in deferred JSON logging with a streaming relay that forwards chunks to the client while retaining only a bounded prefix (or detaching) for metadata parsing; non-JSON error bodies keep a bounded prefix for logging.
  • Add focused regression tests: a test that the metadata SSE inspection detaches at its total byte limit and a test that oversized deferred JSON responses are forwarded to the client without retaining the full body for inspection.

Testing

  • Ran bun run typecheck, which completed successfully.
  • Ran bun run privacy:scan, which completed successfully.
  • Ran focused Bun tests bun test tests/request-log.test.ts tests/consume-for-inspection-cancel.test.ts but the test run failed in this environment due to a Bun runtime/tooling mismatch (missing node:zlib zstdDecompressSync export in the installed Bun), which prevented the harness from loading the suite; the failing test run is an environment limitation and not indicative of the change correctness.

Codex Task

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, add credits to your account and enable them for code reviews in your settings.

@coderabbitai

coderabbitai Bot commented Aug 8, 2026

Copy link
Copy Markdown

Warning

Review limit reached

@luvs01, you've reached your PR review limit, so we couldn't start this review.

Next review available in: 46 minutes

Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available.
You're only billed for reviews past your plan's rate limits ($0.25/file).

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: b9e3f243-ee9b-450f-aad8-ad4d70678497

📥 Commits

Reviewing files that changed from the base of the PR and between 8a9c0ef and f00eaae.

📒 Files selected for processing (3)
  • src/server/relay.ts
  • tests/consume-for-inspection-cancel.test.ts
  • tests/request-log.test.ts

Comment @coderabbitai help to get the list of available commands.

@github-actions

github-actions Bot commented Aug 8, 2026

Copy link
Copy Markdown

⚠️ Wrong target branch

This pull request currently targets main, but pull requests must target one of dev.

@luvs01 Please retarget this PR to dev. All contributions go to dev; main receives only release promotions. See our Contributing guide for details. Thanks! 🙏

Its title has been prefixed with [WRONG BRANCH].

This pull request is being kept as a draft automatically. Once every issue above is resolved, it will be marked ready for review again.

@github-actions github-actions Bot changed the title fix(logs): bound response metadata inspection [WRONG BRANCH] fix(logs): bound response metadata inspection Aug 8, 2026
@github-actions
github-actions Bot marked this pull request as draft August 8, 2026 14:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant