Skip to content

[ENG-4060] Account for reporting outcomes and compare refresh secrets in full - #301

Merged
patchstackdave merged 2 commits into
mainfrom
fix/reporting-hardening
Sep 29, 2026
Merged

patchstackdave merged 2 commits into
mainfrom
fix/reporting-hardening

Conversation

@patchstackdave

@patchstackdave patchstackdave commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Three small reporting and hardening changes.

Callback failures are reported per callback. A host callback that throws is still contained and reported once. That report was kept per hook name for the whole process, so a second guard's broken hook was never mentioned. It is now kept per callback. A process-wide cap stops a host that creates a fresh callback per request from producing output on every request.

Block-log records are counted. protection.blockLogHealth() returns how many block records were accepted, delivered, failed or dropped, and how many are still queued. It is present only when the block log is on. Before this, a record lost to a full queue, a failed send or a shutdown budget was counted nowhere. AGENT-INSTALL.md and the stop() declaration now say so. Each accepted record is counted exactly once, so recorded always equals delivered + failed + dropped + queued. That holds even when a transport ignores cancellation: the batch in flight is counted as dropped when the shutdown budget runs out, and an answer arriving later does not count it again.

The refresh secret is compared through fixed-length digests. The comparison no longer takes less time when a wrong value differs early. Without Web Crypto it falls back to a full-length comparison.

One existing test assumed the push handler starts its refresh within one microtask. The digest makes that step asynchronous, so the test now waits for the refresh. It still checks that concurrent pushes share one refresh.

AGENT-INSTALL.md changed, so the hostile field-test run is still outstanding. It has to run immediately after the release that contains this change: a run before that release inspects the previously published docs.

Validation: full suite, typecheck, build, and the capability and rule-contract checks.

Part of ENG-4060.

🤖 Generated with Claude Code

Report each failing host callback once, rather than once per hook name for the
whole process, with a process-wide cap on warnings. Count block-log records as
delivered, failed or dropped, exposed as protection.blockLogHealth(). Compare the
refresh secret through fixed-length digests.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@coderbuds

coderbuds Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

Comprehensive accounting and secure secret comparison with robust tests.

🎯 Quality: 100% Elite · 📦 Size: Large — consider splitting if possible

🤖 Authorship: Agent-written — Claude Code, going by its own attribution. Whether a person read it is unknown; coding agents can call the report-ai-usage tool to say.

📈 This month: Your 161st PR — above team average · Averaging Excellent

See how your team is trending →

A transport can ignore its abort signal and never settle. The batch it held is
now counted as dropped when the shutdown budget runs out, and an answer that
arrives afterwards does not count it again, so accepted records always equal
delivered + failed + dropped + queued.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@patchstackdave

Copy link
Copy Markdown
Contributor Author

/review

@patchstackdave
patchstackdave merged commit 7a65355 into main Sep 29, 2026
18 checks passed
@patchstackdave
patchstackdave deleted the fix/reporting-hardening branch September 29, 2026 09:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants