Repository navigation
Conversation
SwartzMss
marked this pull request as ready for review
July 23, 2026 13:58
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
finish_reasonand optional token usage metadatafindingsand an explicit supportedseverity: "error", rejecting structurally or semantically invalid findings instead of producing false clean reviews{, so malformed braces or quotes cannot hide a later valid JSON payloadsystemmessagesRoot cause
The runner retried transport and HTTP failures, but treated an HTTP 200 response containing truncated
submit_review_findingsarguments as a terminal JSON parse failure. The response DTO also discarded completion metadata, so logs could not distinguish an output-length stop from other provider-side generation failures.AiFindingsResponse.findingsand finding severity were permissive, allowing missing fields or unsupported values to become successful error findings or false clean reviews. Candidate parsing conflated missing payloads with malformed JSON, returned early inside assistant content, compared findings in provider order, and used global brace/string state that let a malformed prefix hide later valid JSON.Candidate enumeration and HTTP body reads were also unbounded. Repeated timeout finalization could discard compacted evidence, replace the active diff-only constraint, or downgrade malformed recovery to an untrusted user instruction. The last HTTP attempt used narrower duplicated error mapping, turning recognized timeout responses into
AiRequestFailedand preventing the existing diff-only timeout fallback.Impact
Malformed final output gets one bounded recovery attempt, while missing-payload and overflow protocol errors fail immediately without an extra API request. Missing
findings, missing/unsupported severity, and semantically invalid non-empty findings can no longer produce false clean reviews.All submit tool payloads and all bounded JSON objects found in assistant content are independently parsed and validated. Multiple valid candidates are accepted only when their canonical findings agree, regardless of order; conflicting empty/non-empty results return
AiResponseParseFailed. A malformed prefix no longer prevents recovery from a later valid object.Tool and content candidates share an eight-candidate limit, response bodies are limited to 4 MiB, malformed recovery remains a trusted system instruction, and repeated timeouts retain acquired evidence plus active diff-only constraints.
Validation
cargo fmt --checkgit diff --checkcargo clippy --all-targets --all-features -- -D warningscargo test— 198 library tests, 5 binary tests, and 21 end-to-end tests passed