Repository navigation
C4b: allocation accounting, fetch/exec byte caps, and --deadline - #112
Merged
Merged
Conversation
Review C4b (S4/S6/S7): bytecode runner now enforces cumulative allocation charges against MaxMemoryBytes (default 64 MiB), caps fetch bodies and exec combined output (default 10 MiB each), and accepts an optional wall-clock --deadline that cancels fetch/exec/sleep/model work and is checked in the instruction loop. Exceeded ceilings raise structured LIMIT_EXCEEDED. Shared allocation counter and context propagate to SPAWN_AGENT children. Flags wired on -run-bc and howlframe run (--max-memory-bytes, --max-fetch-bytes, --max-exec-output-bytes, --deadline). AST interpreter unchanged; print and blocking read_line remain open; no C5, no HFBC/opcode change, no prod -compile-bc flip; #90 stays Partial. Journal: docs/journals/2026-10-06_c4b_resource_limits.md Co-authored-by: howlcipher <howlcipher@users.noreply.github.com>
howlcipher
commented
Oct 6, 2026
howlcipher
left a comment
Owner
Author
There was a problem hiding this comment.
Dev-lead COMMENT (head 9f55bc65aeee607b09276422f6faab9a4355e297)
Verdict: merge-ready. Diff matches claimed C4b scope. CI build green. Undraft + squash-merge when you are ready.
What matches
- Memory: shared
allocationBudget(mutex, never reclaimed) charged at concat/convert strings, MAKE_LIST/MAKE_DICT, APPEND, STR_SPLIT/JOIN, map_set new keys, map_keys slots, encode_json, HTML escape, read_file/fetch/exec viachargeBytes(source + 8× slot ≈ 9n), and model response strings. Overflow-safechargeSlots. Fail-closed forMaxMemoryBytes <= 0on positive charges. Shared into SPAWN_AGENT, legacy SPAWN, and HTTP handler children. - Fetch/exec caps: default 10 MiB each; LimitReader(max+1) then reject;
limitedOutputWrite-only (no ReadFrom bypass) + cancel on overflow; under-cap nonzero exit staysIO_ERROR. CLI + VM fail-closed for<= 0. - Deadline: optional
ExecutionPolicy.Deadline;WithTimeoutshared with children; instruction-loopcheckDeadline; sleep select; fetch/exec/model via context; deadline → structuredLIMIT_EXCEEDED(not IO_ERROR). Absent = none; CLI rejects0s/invalid. - CLI:
--max-memory-bytes/--max-fetch-bytes/--max-exec-output-bytes/--deadlineon-run-bcandrun(bytecode), viaresourcePolicy. C4a--max-call-depth/ MaxCallDepth preserved. - Tests: defaults, opcode boundaries, spawn share, fetch/exec caps (httptest + in-memory transport), deadline sleep/loop/exec/fetch/model/response-body, CLI both runners, inherited exec without deadline unchanged.
- Docs: S4/S6/S7 honestly PARTIAL; deferrals (AST, uncapped print, read_line not cancelled, approximate ≠ RSS) match the code.
Non-blockers (documented)
- Append charges full list size each time (cumulative overcharge vs live heap) — intentional approximate policy.
- Model response bodies have no dedicated byte cap (only alloc charge + request deadline).
- Deferred paths as claimed: AST interpreter, print, blocking read_line / some host I/O.
Hard nos
Intact: no prod HFIR / -compile-bc flip, #90 Partial, no HFBC/opcode change, no C5/harness/DOM; C4a call-depth behavior preserved.
No blockers.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Implements review candidate C4b on top of C4a (#111 /
cdf2e2fc): bytecode runner resource limits for S4/S6/S7.MaxMemoryBytes(default 64 MiB,--max-memory-bytes). Cumulative approximate charges on string concat, append, MAKE_LIST/MAKE_DICT, str_split/str_join, read_file, fetch/exec bodies, encode_json, and related large sites. Shared counter across SPAWN_AGENT children. Exceed → structuredLIMIT_EXCEEDED.--max-fetch-bytes,--max-exec-output-bytes). LimitReader / bounded combined stdout+stderr; fail-closed for non-positive ceilings in the VM; CLI rejects<= 0.--deadlineoptional positivetime.ParseDurationwall-clock budget onExecutionPolicy. Threadedcontext.Contextinto fetch, exec, sleep, and model HTTP calls; instruction loop also checks cancellation. Absent flag = no deadline; explicit0s/invalid rejected.-run-bcandhowlframe run(bytecode/bc), alongside existing--max-instructions/--max-call-depth.change_log.md, journaldocs/journals/2026-10-06_c4b_resource_limits.md, doc 11 C4 status, S4/S6/S7 honestly marked PARTIAL where AST/print/read_lineremain open.Hard nos intact
No prod
-compile-bc/HFIR flip; #90 stays Partial; no HFBC/opcode change; no DOM invent; no C5 receipts/harness; C4a MaxCallDepth behavior preserved.Defaults
--max-memory-bytes67108864(64 MiB)--max-fetch-bytes10485760(10 MiB)--max-exec-output-bytes10485760(10 MiB)--deadlineDeferrals
AST interpreter memory/deadline/recursion still open;
printuncapped; blockingread_line(and some host I/O) not deadline-cancelled; charges are approximate construction accounting, not exact RSS.Test plan
gofmt -l .cleango vet ./...go test ./internal/vm/ -count=1(incl. new resource limit / deadline / byte-cap tests)go test ./... -count=1green outside sandbox (Go 1.24.4)