[ENG-4060] Account for reporting outcomes and compare refresh secrets in full - #301
Merged
Merged
Conversation
Report each failing host callback once, rather than once per hook name for the whole process, with a process-wide cap on warnings. Count block-log records as delivered, failed or dropped, exposed as protection.blockLogHealth(). Compare the refresh secret through fixed-length digests. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
Comprehensive accounting and secure secret comparison with robust tests. 🎯 Quality: 100% Elite · 📦 Size: Large — consider splitting if possible 🤖 Authorship: Agent-written — Claude Code, going by its own attribution. Whether a person read it is unknown; coding agents can call the 📈 This month: Your 161st PR — above team average · Averaging Excellent |
A transport can ignore its abort signal and never settle. The batch it held is now counted as dropped when the shutdown budget runs out, and an answer that arrives afterwards does not count it again, so accepted records always equal delivered + failed + dropped + queued. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Contributor
Author
|
/review |
daniloradovic
approved these changes
Sep 29, 2026
mariojgt
approved these changes
Sep 29, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Three small reporting and hardening changes.
Callback failures are reported per callback. A host callback that throws is still contained and reported once. That report was kept per hook name for the whole process, so a second guard's broken hook was never mentioned. It is now kept per callback. A process-wide cap stops a host that creates a fresh callback per request from producing output on every request.
Block-log records are counted.
protection.blockLogHealth()returns how many block records were accepted, delivered, failed or dropped, and how many are still queued. It is present only when the block log is on. Before this, a record lost to a full queue, a failed send or a shutdown budget was counted nowhere.AGENT-INSTALL.mdand thestop()declaration now say so. Each accepted record is counted exactly once, sorecordedalways equalsdelivered + failed + dropped + queued. That holds even when a transport ignores cancellation: the batch in flight is counted as dropped when the shutdown budget runs out, and an answer arriving later does not count it again.The refresh secret is compared through fixed-length digests. The comparison no longer takes less time when a wrong value differs early. Without Web Crypto it falls back to a full-length comparison.
One existing test assumed the push handler starts its refresh within one microtask. The digest makes that step asynchronous, so the test now waits for the refresh. It still checks that concurrent pushes share one refresh.
AGENT-INSTALL.mdchanged, so the hostile field-test run is still outstanding. It has to run immediately after the release that contains this change: a run before that release inspects the previously published docs.Validation: full suite, typecheck, build, and the capability and rule-contract checks.
Part of ENG-4060.
🤖 Generated with Claude Code