Skip to content
This repository was archived by the owner on Oct 1, 2026. It is now read-only.

[CTX-0082] fix(protocol): establish one strict live request and protocol owner (#138) - #148

Merged
Xuepoo merged 1 commit into
mainfrom
ctx-0082/fix-live-request-owner
Sep 27, 2026
Merged

Xuepoo merged 1 commit into
mainfrom
ctx-0082/fix-live-request-owner

Conversation

@Xuepoo

@Xuepoo Xuepoo commented Sep 27, 2026

Copy link
Copy Markdown
Contributor

Priority: P1 | Area: DevTools live client and protocol | Labels: P1,fix,area:devtools | Milestone: v0.1.0 | RFC: OQ-004 | Task: CTX-0082

Closes #138

Scope

DEV-001, DEV-002, DEV-006, DEV-007, DEV-008, DEV-013, DEV-021. DEV-001/002/008/013/021 were already delivered by #144 (d16e244); this PR closes the remaining DEV-006 and DEV-007 and supplies the owed DEV-001 activation evidence.

Changes

DEV-006 — one closed response decoder (src/protocol.ts)

  • Exactly one non-empty JSONL line; extra lines rejected.
  • Non-object / null JSON rejected without an uncaught TypeError.
  • Exact top-level key allowlist; exclusive result xor error.
  • ErrorCategory validated against the closed union; string code and message bounded (message truncated to 512).
  • id must be a nonnegative safe integer; fatal UTF-8 stays at the wire boundary.
  • Duplicate object keys rejected before JSON.parse via shared src/json-guard.ts (also adopted by the campaign ctl-envelope validator).
  • error.details bounded to 4 KiB (rejected, never echoed) per the DevTools RFC.

DEV-007 — fail closed instead of fragmenting

  • IpcTransport.encodeSingleLiveRequest throws FrameTooLarge before any socket write when a logical live request exceeds one 256 KiB frame. Oversized live sends remain explicitly unavailable until the core bitty inbound continuation contract lands (recorded as risk PX-0560; server half is a cross-repository follow-up).

DEV-001 — hermetic activation evidence

  • New subprocess test spawns the real bin/bitty-devtools.ts over a loopback Unix socket: inspect dials exactly once; --help and malformed args never dial.

Verification

  • just check green: prettier + markdownlint clean, tsc --noEmit clean, bun test 693 pass / 0 fail, Rust 90 + 20 pass.
  • Independent review (ctx-0082-reviewer): APPROVE, with the two minor decoder findings addressed here.

Non-claims

No wire-level continuation is implemented; live trace/control remain unavailable by design. No server-side change is made in this repository.

…-closed continuation (#138)

- DEV-006: replace permissive decodeResponse with a closed exact-record
  decoder (single JSONL line, key allowlist, exclusive result/error,
  validated ErrorCategory, bounded code/message/details, duplicate-key
  rejection via shared src/json-guard.ts).
- DEV-007: live requests fail closed before any socket write when a
  logical request exceeds one 256 KiB frame; oversized sends stay
  unavailable until the core continuation contract lands.
- DEV-001: hermetic subprocess loopback test for bin/bitty-devtools.ts
  (inspect dials once; --help and malformed args never dial).
@Xuepoo Xuepoo added this to the v0.1.0 milestone Sep 27, 2026
@Xuepoo Xuepoo added area:devtools devtools area P1 Priority P1 fix Bug fix labels Sep 27, 2026
@Xuepoo
Xuepoo merged commit 7befc9a into main Sep 27, 2026
9 checks passed
@Xuepoo
Xuepoo deleted the ctx-0082/fix-live-request-owner branch September 27, 2026 13:00
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

area:devtools devtools area fix Bug fix P1 Priority P1

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[P1] Establish one strict live request and protocol owner

1 participant