fix(daemon): validate wire ops before label; keep resolved scope - #1413
ScriptedAlchemy wants to merge 0 commit into
Conversation
|
75e6f10 to
007b270
Compare
ScriptedAlchemy
left a comment
There was a problem hiding this comment.
rspack-team-mode — tip 007b2707ebcc (draft)
Outcome: validate wire surface_operation against the typed body before labeling, derive operation() from the body (no unreachable! on foreign wire), and fail-closed with_resolved_scope(Some(_)) on payloads that cannot carry scope — right ownership fix. Tests cover preserve / refuse / None. Draft → COMMENT only. No merge-bar issues.
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
9fd7f40 to
d2c9294
Compare
Performance Comparison
|
Summary
Closes two tip wire defects from the #707 first-principles pack (report 20):
Production panic from the wire —
dispatchlabeled the request viaoperation()beforevalidate(). AGitReadpayload with a foreignsurface_operationhitunreachable!and killed the connection task. Labeling now derives from the typed body (total),validate()rejects mismatchedsurface_operationfor GitRead/NativeIntegration, and dispatch validates first.Cross-project selector silent alias —
with_resolved_scopedroppedSome(scope)for every payload except FeedbackGet / Configuration / ObservatoryRead. It now returnsResult: preserves scope on those three, acceptsNoneeverywhere, and fails closed withInvalidRequestwhen a selector cannot apply. Application-surface request build applies the selector after construction so unsupported ops cannot fall through to the active project.Proof
No FastEmbed.
Base
Draft into campaign tip
codex/tracedecay-total-redesign-plan-reopened(#707). Not master / not #745.