fix: bound oversized tool-result text at ingress - #38
Merged
Brian Krabach (bkrabach) merged 2 commits intoSep 11, 2026
Merged
Conversation
Add a default-on UTF-8 byte cap for direct tool-result text while preserving tool identity, pair metadata, and opaque blocks. Emit numeric truncation telemetry and a retrieval-safe marker without retaining the original payload. Generated with Amplifier Co-Authored-By: Amplifier <240397093+microsoft-amplifier@users.noreply.github.com>
Use valid TOML table syntax for the context configuration and document the explicit ingress-cap override without the removed max_messages setting. Generated with Amplifier Co-Authored-By: Amplifier <240397093+microsoft-amplifier@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
A single oversized tool result could remain protected through every compaction level and reach the provider unchanged (the 3.16 MB reproduction). This adds a default-on ingress guard that bounds direct tool-result text before it enters canonical context or resume state.
max_tool_result_bytes = 131072UTF-8 bytes; one explicit constructor/config setting supports legitimate larger text.Verification
Local commands and results:
uv run pytest -q tests/test_tool_result_ingress.py— 19 passeduv run pytest -q— 124 passed, 1 xfaileduv run ruff check .— cleanuv run python -m compileall -q amplifier_module_context_simple tests— passtomllib;max_tool_result_bytes == 131072The focused regression
test_default_caps_the_real_oversized_protected_tool_result_before_compactionreproduces the prior failure condition and verifies the result is bounded before compaction. The pre-fix local receipt recorded the 3,163,313-byte result remaining unchanged at compaction level 8; the implementation now bounds it at ingress.Prepared real-provider validation covered four flows across Anthropic and OpenAI: normal 77,129-byte results were unchanged with zero ingress events; oversized serialized 3,163,313-byte results became 131,072 bytes in context and the next provider request with one event; nonce-only tail retrieval passed; no provider errors, 400s, fallback, or level-8 compaction occurred. This was a prepared streaming-orchestrator/provider harness, not a full Click CLI run.
Breaking changes
Oversized direct tool-result text is now irreversibly clipped by default before admission. Callers that legitimately need larger text must explicitly raise
max_tool_result_bytes.