Skip to content

fix(daemon): validate wire ops before label; keep resolved scope - #1413

Closed
ScriptedAlchemy wants to merge 0 commit into
codex/tracedecay-total-redesign-plan-reopenedfrom
cursor/wire-validate-and-scope-b5a3
Closed

ScriptedAlchemy wants to merge 0 commit into
codex/tracedecay-total-redesign-plan-reopenedfrom
cursor/wire-validate-and-scope-b5a3

Conversation

@ScriptedAlchemy

Copy link
Copy Markdown
Owner

Summary

Closes two tip wire defects from the #707 first-principles pack (report 20):

  1. Production panic from the wire — dispatch labeled the request via operation() before validate(). A GitRead payload with a foreign surface_operation hit unreachable! and killed the connection task. Labeling now derives from the typed body (total), validate() rejects mismatched surface_operation for GitRead/NativeIntegration, and dispatch validates first.

  2. Cross-project selector silent alias — with_resolved_scope dropped Some(scope) for every payload except FeedbackGet / Configuration / ObservatoryRead. It now returns Result: preserves scope on those three, accepts None everywhere, and fails closed with InvalidRequest when a selector cannot apply. Application-surface request build applies the selector after construction so unsupported ops cannot fall through to the active project.

Proof

cargo test -p tracedecay-daemon-protocol --lib wire_input_fail_closed_tests
# 5 passed (foreign surface_operation → InvalidRequest + non-panicking label;
#            scope preserved on carriers; refused on GitRead; None accepted)

cargo check -p tracedecay-daemon-service -p tracedecay --tests
# ok

No FastEmbed.

Base

Draft into campaign tip codex/tracedecay-total-redesign-plan-reopened (#707). Not master / not #745.

Open in Web Open in Cursor 

@changeset-bot

changeset-bot Bot commented Sep 16, 2026 •

Copy link
Copy Markdown

⚠️ No Changeset found

Latest commit: d2c9294

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@cursor
cursor Bot force-pushed the cursor/wire-validate-and-scope-b5a3 branch from 75e6f10 to 007b270 Compare September 16, 2026 08:50

@ScriptedAlchemy ScriptedAlchemy left a comment

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

rspack-team-mode — tip 007b2707ebcc (draft)

Outcome: validate wire surface_operation against the typed body before labeling, derive operation() from the body (no unreachable! on foreign wire), and fail-closed with_resolved_scope(Some(_)) on payloads that cannot carry scope — right ownership fix. Tests cover preserve / refuse / None. Draft → COMMENT only. No merge-bar issues.

@ScriptedAlchemy
ScriptedAlchemy marked this pull request as ready for review September 16, 2026 09:40
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 16, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-16T09:45:03.556210Z 007b270 Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@cursor cursor Bot closed this Sep 16, 2026
@cursor
cursor Bot force-pushed the cursor/wire-validate-and-scope-b5a3 branch from 9fd7f40 to d2c9294 Compare September 16, 2026 11:13
@github-actions

Copy link
Copy Markdown
Contributor

Performance Comparison codex/tracedecay-total-redesign-plan-reopened → cursor/wire-validate-and-scope-b5a3

Total Elapsed Time: 8.09s → 8.34s (+3.0%)
CPU Baseline: 84.19µs → 80.01µs (-5.0%)
Benchmark ID: index-bench-timing

timing - Execution duration of functions.

+---------------------------------------------+----------------------------+---------------------------------+----------------------------------+----------------------------------+------------------------------+
| Function                                    | Calls                      | Avg                             | P95                              | Total                            | % Total                      |
+---------------------------------------------+----------------------------+---------------------------------+----------------------------------+----------------------------------+------------------------------+
| tracedecay-index-bench                      | 1 → 1 (+0.0%)              | 8.09s → 8.34s (+3.1%)           | 8.10s → 8.34s (+3.0%)            | 8.09s → 8.34s (+3.1%)            | 100.00% → 100.00% (+0.0%)    |
+---------------------------------------------+----------------------------+---------------------------------+----------------------------------+----------------------------------+------------------------------+
| code_index.workers.install                  | 81 → 81 (+0.0%)            | 34.28ms → 38.58ms (+12.5%)      | 203.69ms → 269.22ms (+32.2%) ⚠️  | 2.78s → 3.13s (+12.6%)           | 34.30% → 37.49% (+9.3%)      |
+---------------------------------------------+----------------------------+---------------------------------+----------------------------------+----------------------------------+------------------------------+
| domain.canonical.sha256                     | 85787 → 85787 (+0.0%)      | 34.22µs → 36.27µs (+6.0%)       | 108.42µs → 109.18µs (+0.7%)      | 2.94s → 3.11s (+5.8%)            | 36.27% → 37.32% (+2.9%)      |
+---------------------------------------------+----------------------------+---------------------------------+----------------------------------+----------------------------------+------------------------------+
| code_index.build.and_publish                | 2 → 2 (+0.0%)              | 732.49ms → 752.13ms (+2.7%)     | 1.03s → 1.01s (-1.9%)            | 1.46s → 1.50s (+2.7%)            | 18.10% → 18.04% (-0.3%)      |
+---------------------------------------------+----------------------------+---------------------------------+----------------------------------+----------------------------------+------------------------------+
| query.artifact.finalization.advance_wake    | 28 → 28 (+0.0%)            | 54.41ms → 52.62ms (-3.3%)       | 411.57ms → 410.78ms (-0.2%)      | 1.52s → 1.47s (-3.3%)            | 18.82% → 17.67% (-6.1%)      |
+---------------------------------------------+----------------------------+---------------------------------+----------------------------------+----------------------------------+------------------------------+
| query.artifact.batch.sqlite                 | 5 → 5 (+0.0%)              | 287.87ms → 283.09ms (-1.7%)     | 317.46ms → 315.36ms (-0.7%)      | 1.44s → 1.42s (-1.4%)            | 17.78% → 16.98% (-4.5%)      |
+---------------------------------------------+----------------------------+---------------------------------+----------------------------------+----------------------------------+------------------------------+
| query.artifact.batch.parallel_prepare       | 5 → 5 (+0.0%)              | 215.98ms → 249.59ms (+15.6%)    | 263.59ms → 289.14ms (+9.7%)      | 1.08s → 1.25s (+15.7%)           | 13.34% → 14.97% (+12.2%)     |
+---------------------------------------------+----------------------------+---------------------------------+----------------------------------+----------------------------------+------------------------------+
| domain.canonical.json_bytes                 | 206681 → 206681 (+0.0%)    | 4.94µs → 5.53µs (+11.9%)        | 4.53µs → 4.51µs (-0.4%)          | 1.02s → 1.14s (+11.8%)           | 12.62% → 13.70% (+8.6%)      |
+---------------------------------------------+----------------------------+---------------------------------+----------------------------------+----------------------------------+------------------------------+
| code_index.extract.parser_artifact          | 276 → 276 (+0.0%)          | 4.14ms → 4.08ms (-1.4%)         | 7.03ms → 6.69ms (-4.8%)          | 1.14s → 1.13s (-0.9%)            | 14.11% → 13.52% (-4.2%)      |
+---------------------------------------------+----------------------------+---------------------------------+----------------------------------+----------------------------------+------------------------------+
| query.artifact.batch.postings               | 5 → 5 (+0.0%)              | 225.96ms → 221.25ms (-2.1%)     | 254.28ms → 249.17ms (-2.0%)      | 1.13s → 1.11s (-1.8%)            | 13.96% → 13.27% (-4.9%)      |
+---------------------------------------------+----------------------------+---------------------------------+----------------------------------+----------------------------------+------------------------------+
| code_index.restore.file_admit               | 260 → 260 (+0.0%)          | 2.84ms → 3.51ms (+23.6%) ⚠️     | 4.58ms → 6.07ms (+32.5%) ⚠️      | 738.43ms → 913.07ms (+23.7%) ⚠️  | 9.12% → 10.95% (+20.1%) ⚠️   |
+---------------------------------------------+----------------------------+---------------------------------+----------------------------------+----------------------------------+------------------------------+
| code_index.build.materialize_full           | 1 → 1 (+0.0%)              | 746.08ms → 732.32ms (-1.8%)     | 746.59ms → 732.43ms (-1.9%)      | 746.08ms → 732.32ms (-1.8%)      | 9.22% → 8.78% (-4.8%)        |
+---------------------------------------------+----------------------------+---------------------------------+----------------------------------+----------------------------------+------------------------------+
| code_index.collect.materialize_full         | 1 → 1 (+0.0%)              | 731.62ms → 718.18ms (-1.8%)     | 731.91ms → 718.27ms (-1.9%)      | 731.62ms → 718.18ms (-1.8%)      | 9.04% → 8.61% (-4.8%)        |
+---------------------------------------------+----------------------------+---------------------------------+----------------------------------+----------------------------------+------------------------------+
| 🆕 code_index.lexical_source.batch_stage    | 0 → 6 (+100.0%) ⚠️         | 0.00ns → 112.78ms (+100.0%) ⚠️  | 0.00ns → 161.22ms (+100.0%) ⚠️   | 0.00ns → 676.67ms (+100.0%) ⚠️   | 0.00% → 8.12% (+100.0%) ⚠️   |
+---------------------------------------------+----------------------------+---------------------------------+----------------------------------+----------------------------------+------------------------------+
| code_index.build.assemble                   | 2 → 2 (+0.0%)              | 291.10ms → 317.28ms (+9.0%)     | 302.51ms → 355.99ms (+17.7%)     | 582.20ms → 634.56ms (+9.0%)      | 7.19% → 7.61% (+5.8%)        |
+---------------------------------------------+----------------------------+---------------------------------+----------------------------------+----------------------------------+------------------------------+
| 🗑️ query.artifact.batch.postings.ngram_rows | 5 → 0 (-100.0%) 🚀         | 129.48ms → 0.00ns (-100.0%) 🚀  | 145.10ms → 0.00ns (-100.0%) 🚀   | 647.40ms → 0.00ns (-100.0%) 🚀   | 8.00% → 0.00% (-100.0%) 🚀   |
+---------------------------------------------+----------------------------+---------------------------------+----------------------------------+----------------------------------+------------------------------+

Generated with hotpath-rs

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant