Redact and clamp park fault text; pin the planner wire schema - #2059
Merged
Merged
Conversation
A model-plane park stored LlmApiException.Message on its marker, in the node's failure text and in the park log. That message ends with the provider's whole error body, verbatim and unbounded, so a gateway that echoed a credential or answered with a page wrote it to the durable run row and the log. InfraPark.FaultText now redacts scope secrets, then clamps to 512 characters (never inside a surrogate pair, which Npgsql refuses to write), and the generic park and the supervisor's own park use that one text for the marker, the failure and the log line. The planner's provider schema stopped being its validation schema in the previous change, but tests and docs still said otherwise: - the prompt still quoting the full contract schema, and the re-ask request still sending the wire schema, are now asserted - the validation-schema tests are named for what they check, and the flat-acceptance test walks every field a branch declares, not only the ones it requires - the portability guard also requires every array to declare its items, the second candidate for the empty HTTP 500 - the structured client docs say the provider receives WireJsonSchema ?? JsonSchema and that validation uses JsonSchema - an Undefined WireJsonSchema counts as unset instead of failing at serialization
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
LlmApiException.Messageends with the provider's whole error body, verbatim and unbounded, and the park put it on the durable marker, in the failure text and in the log. OneInfraPark.FaultTextnow feeds all three, for the generic park and for the supervisor's own park (whose log line now carries the fault text too). Redaction runs before the clamp, and the clamp never cuts a surrogate pair, which Npgsql's strict UTF-8 encoder refuses to write.items. The two validation-schema tests are renamed for what they check.JsonSchema/ResponseSchema(the provider receivesWireJsonSchema ?? JsonSchema; validation usesJsonSchema), and treat adefault(JsonElement)wire schema as unset instead of failing at serialization.The wire schema itself does not change. Refs #2052.
Test plan
JsonSchemaCombinatorsTests38,StructuredResponseContractTests54,TypedModelSchemaBranchTests38,InfraParkTests13,AgentSupervisorNodeInfraParkTests1 (new; the real supervisor node over a faulting turn service)InfraParkRideTests22 (skip message quotes the clamped text the production park stored);SupervisorInfraParkFlowTests4,LlmCompleteInfraParkFlowTests4 andInfraParkRideFlowTests6 against local PostgresWithSchemaInstruction(Anthropic and OpenAI): the planner capture and re-ask tests go reditemsinPlannerSchema.WireSchemaorArbiterDecisionSchema: the guard goes red, naming the schema and the JSON pathProviderSchemaback to a bare??: the undefined-wire-schema test goes red for both providers