Skip to content

feat(sessions): bound history transport for harness reads - #5724

Closed
iscekic wants to merge 3 commits into
shared-agent-harness-3bb0-s19from
shared-agent-harness-3bb0-s20
Closed

feat(sessions): bound history transport for harness reads#5724
iscekic wants to merge 3 commits into
shared-agent-harness-3bb0-s19from
shared-agent-harness-3bb0-s20

Conversation

@iscekic

@iscekic iscekic commented Aug 29, 2026

Copy link
Copy Markdown
Contributor

No new behavior — current session history views do not enable the new optional limits.


Summary

fetchSessionMessagesPage adds optional SessionMessagesPageOptions.bounded, reusing a fixed 1 mebibyte (MiB) response limit and 30-second transport deadline.
Both success and error bodies face byte limits before decoding; the shared reader validates Content-Length, streamed bytes, encoding, and application/json success bodies.
The reader cancels unfinished streams; bounded status and validation errors omit upstream details, while omitted or false options preserve legacy transport and reporting.

Files
  • apps/web/src/lib/session-ingest-client.ts — source, modified; 30 changed lines. Sends Accept: application/json, the existing authorization token, and an abort signal without changing pagination query parameters. Requires Content-Type: application/json for successful bodies and valid utf-8, while enforcing declared and streamed byte counts. A 404 returns null after the bounded read completes; nullable history and typed worker outcomes retain their existing shape. Other status failures include only the status code; malformed data produces a generic error without validation details or client-side captureException calls.

GetSessionMessagesPageInputSchema adds optional boolean bounded to getSessionMessagesPage, retaining ownership, organization access, cursor validation, the 50-message default, and the 100-message maximum.
Bounded requests skip the optional watermark query and return watermarkEventId: null; this avoids an extra service call but does not seed event replay.
For bounded failures, INTERNAL_SERVER_ERROR keeps its stable message without console logging or the upstream cause; omitted or false preserves legacy errors and watermarks.

Files
  • apps/web/src/routers/cli-sessions-v2-router.ts — source, modified; 24 changed lines. Forwards bounded only when supplied, preserves the cursor-to-before mapping, and keeps the shared access check before transport. Skips the Cloud Agent watermark read for bounded calls and removes upstream causes to keep response bodies and credentials out of Sentry. Worker null still becomes NOT_FOUND, and results still include watermarkEventId.

Tests: 2 files modified — apps/web/src/lib/session-ingest-client.test.ts (187 changed lines) and apps/web/src/routers/cli-sessions-v2-router.test.ts (151 changed lines), covering bounded reads and legacy compatibility.
Generated: 0 files changed.


Verification

No manual tests ran because this level adds bounded history transport without activating the harness.
Harness opt-in, composition, presentation, and live proof remain in later slices.

Visual Changes

Visual Changes: N/A

Reviewer Notes

  • Scope: level 20 only, between shared-agent-harness-3bb0-s19 and shared-agent-harness-3bb0-s20.
  • Repository: Kilo-Org/cloud; worktree: /Users/igor/Projects/.worktrees/shared-agent-harness-3bb0.
  • The supplied evidence records six passing scoped commands: formatting, lint, client tests, pure router tests, format checking, and whitespace checking.
  • The implementer reports 71 passing client cases and 15 passing pure router cases; the reviewer reports five passing scoped commands.
  • The router tests use database and transport doubles; they do not prove live service behavior.
  • Continuous integration (CI) owns database execution and project-wide type checks.

Human steps

This change requires no human steps before merge or after merge.

Notes

Runtime verification remains pending at the stack tip. This level adds bounded history transport without activating the harness.

Stacked PRs — merge bottom to top. Each level shows only its own diff.

Runtime verification (E2E, user advocacy, simplify) runs on the tip PR over every level.
Every level keeps its own checks, its own bot review, and its own threads; each one is answered on its own PR.
Each level is its own deliverable: it builds and passes its own checks alone.
A finding on a level is repaired on that level, then carried upward with stack.sh forward.

  1. shared-agent-harness-3bb0chore(agent-harness): register workspaces and enforce CI boundaries #5632
  2. shared-agent-harness-3bb0-s2feat(agent-harness): define portable domain and snapshots #5637
  3. shared-agent-harness-3bb0-s3feat(agent-harness): define commands tools and permission policy #5639
  4. shared-agent-harness-3bb0-s4feat(agent-harness): share client state and cursor recovery #5643
  5. shared-agent-harness-3bb0-s5feat(agent-harness): persist command intents and execution receipts #5647
  6. shared-agent-harness-3bb0-s6feat(db): add harness ingress grants and retirement fences #5655
  7. shared-agent-harness-3bb0-s7feat(agent-harness): deliver legacy history and project durable text #5659
  8. shared-agent-harness-3bb0-s8feat(agent-harness): authorize durable grants and registered clients #5662
  9. shared-agent-harness-3bb0-s9feat(agent-harness): fence retirement and retry payload cleanup #5667
  10. shared-agent-harness-3bb0-s10feat(agent-harness): persist authoritative state in SQLite #5675
  11. shared-agent-harness-3bb0-s11feat(agent-harness): admit durable runs and revisioned commands #5678
  12. shared-agent-harness-3bb0-s12feat(agent-harness): recover queued runs and stream checkpointed steps #5688
  13. shared-agent-harness-3bb0-s13feat(agent-harness): resolve interactions and dispatch tools sequentially #5693
  14. shared-agent-harness-3bb0-s14feat(agent-harness): fence designated client tool execution #5697
  15. shared-agent-harness-3bb0-s15feat(agent-harness): synchronize durable snapshots and legacy history #5701
  16. shared-agent-harness-3bb0-s16feat(agent-harness): reuse authorized invitations with durable replay #5704
  17. shared-agent-harness-3bb0-s17feat(integrations): bound repository transport for harness reads #5710
  18. shared-agent-harness-3bb0-s18feat(integrations): expose bounded authorized repository reads #5714
  19. shared-agent-harness-3bb0-s19feat(agent-harness): expose named authorized resource reads #5718
  20. shared-agent-harness-3bb0-s20feat(sessions): bound history transport for harness reads #5724 ← this PR
  21. shared-agent-harness-3bb0-s21feat(agent-harness): read scoped Cloud Agent context and progress #5726
  22. shared-agent-harness-3bb0-s22fix(agent-harness): preserve ordered Cloud Agent dispatch identity #5731
  23. shared-agent-harness-3bb0-s23feat(agent-harness): hand coding work to authorized Cloud Agent sessions #5733
  24. shared-agent-harness-3bb0-s24feat(agent-harness): authorize scoped MCP gateway connections #5737
  25. shared-agent-harness-3bb0-s25feat(agent-harness): bound MCP gateway transport in the Worker #5740
  26. shared-agent-harness-3bb0-s26feat(agent-harness): execute validated remote MCP tools #5743
  27. shared-agent-harness-3bb0-s27refactor(exa): share provider dispatch and usage recording #5746
  28. shared-agent-harness-3bb0-s28feat(agent-harness): authorize bounded web provider requests #5747
  29. shared-agent-harness-3bb0-s29feat(agent-harness): normalize web sources and preserve citations #5749
  30. shared-agent-harness-3bb0-s30feat(agent-harness): define closed internal operation contracts #5753
  31. shared-agent-harness-3bb0-s31feat(agent-harness): authorize internal maintenance operations #5754
  32. shared-agent-harness-3bb0-s32feat(agent-harness): authorize named Kilo operation dispatch #5755
  33. shared-agent-harness-3bb0-s33feat(agent-harness): authorize internal provider operations #5757
  34. shared-agent-harness-3bb0-s34feat(agent-harness): secure the internal operations endpoint #5758
  35. shared-agent-harness-3bb0-s35feat(agent-harness): bound and sanitize model streams #5767
  36. shared-agent-harness-3bb0-s36feat(agent-harness): secure billed model inference #5776
  37. shared-agent-harness-3bb0-s37test(agent-harness): cover model gateway security boundaries #5777 (tip)

@kilo-code-bot

kilo-code-bot Bot commented Aug 29, 2026

Copy link
Copy Markdown
Contributor

Code Review Summary

Status: No Issues Found | Recommendation: Merge

Files Reviewed (4 files)
  • apps/web/src/lib/session-ingest-client.ts
  • apps/web/src/lib/session-ingest-client.test.ts
  • apps/web/src/routers/cli-sessions-v2-router.ts
  • apps/web/src/routers/cli-sessions-v2-router.test.ts

Reviewed by grok-4.6 · Input: 277.7K · Output: 16.1K · Cached: 527.4K

Review guidance: REVIEW.md from base branch shared-agent-harness-3bb0-s19

This was referenced Aug 29, 2026
@iscekic

iscekic commented Aug 31, 2026

Copy link
Copy Markdown
Contributor Author

Closing: the owner stopped this workflow section. The branch is retained.

@iscekic iscekic closed this Aug 31, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant