Skip to content

fix(checkpoint): cap full upstream cursor at 512 characters - #541

Merged
khaliqgant merged 2 commits into
mainfrom
garden-rfc-b-532-boundary
Oct 8, 2026
Merged

khaliqgant merged 2 commits into
mainfrom
garden-rfc-b-532-boundary

Conversation

@miyaontherelay

@miyaontherelay miyaontherelay commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

Checkpoint upstream cursor validation now rejects 513-character tokens and caps the complete token at 512 characters. The upstream:v1: prefix is 12 characters, so the tail bound is 500; #532 used 501. Updated all three Go validators, OpenAPI patterns, and boundary tests consistently.

Validation: checkpoint pattern, verify, handback and resume Go tests pass across mountsync, relayfile and CLI; the full relevant suites passed for #532. This correction follows #532 and should be included before publishing the mount/CLI prerequisite for relayfile-cloud#293. No release triggered.


Note

Low Risk
Tightens validation only; cursors at the previous 513-character boundary would now be rejected, aligning clients and API with the intended 512-character cap.

Overview
Corrects an off-by-one in checkpoint eventCursor validation so the full upstream:v1: token is capped at 512 characters (12-character prefix + 500-character tail), not 513.

The same regex bound is applied in the CLI (checkpointCursorPattern), mount sync, relayfile seal store, and three OpenAPI eventCursor patterns. Boundary tests now treat a 500-character tail as valid and reject 501+.

Reviewed by Cursor Bugbot for commit af61cc4. Bugbot is set up for automated code reviews on this repo. Configure here.

@coderabbitai

coderabbitai Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Important

Review skipped

Review was skipped as selected files did not have any reviewable changes.

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 5007af74-658a-4a67-95d4-53851d1edf23
📥 Commits

Reviewing files that changed from the base of the PR and between 3283f9d and af61cc4.

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: fd487f86-d7ae-4a84-88d2-4cdc3470e662
📥 Commits

Reviewing files that changed from the base of the PR and between 447250e and 3283f9d.

📒 Files selected for processing (7)
  • cmd/relayfile-cli/checkpoint_lifecycle.go
  • cmd/relayfile-cli/checkpoint_lifecycle_test.go
  • internal/mountsync/syncer.go
  • internal/mountsync/syncer_test.go
  • internal/relayfile/checkpoint_seal.go
  • internal/relayfile/checkpoint_seal_test.go
  • openapi/relayfile-v1.openapi.yaml

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

The upstream:v1: cursor suffix limit changes from 501 characters to 500 in validation patterns and OpenAPI schemas. Boundary tests now accept 500 characters and reject 501.

Changes

Upstream cursor length limit

Layer / File(s) Summary
Cursor validation and boundary tests
internal/relayfile/checkpoint_seal.go, cmd/relayfile-cli/checkpoint_lifecycle.go, internal/mountsync/syncer.go, openapi/relayfile-v1.openapi.yaml, internal/relayfile/checkpoint_seal_test.go, cmd/relayfile-cli/checkpoint_lifecycle_test.go, internal/mountsync/syncer_test.go
The cursor patterns and three OpenAPI schema constraints now limit upstream suffixes to 500 characters. Tests accept a 500-character suffix and reject a 501-character suffix.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~8 minutes

Change: Bug fix

Suggested reviewers: khaliqgant

Merge Risk: ⚪ Minimal · up to 3283f

The cursor limit is consistently capped at 512 characters including its prefix, with tests for the 500/501-character suffix boundary. No material merge risk is evident.

🚥 Pre-merge checks | ✅ 4 | ❓ 1

❌ Failed checks (1 inconclusive)

Check name Status Explanation Resolution
Docstring Coverage ❓ Inconclusive Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 2 functions across 5 files. (2 skipped: 1 … Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Title check ✅ Passed The title accurately describes the main change: the full upstream cursor is capped at 512 characters.
Description check ✅ Passed The description directly explains the 512-character cap, the off-by-one correction, the affected validators and OpenAPI patterns, and the boundary tests.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Full details: Docstring Coverage

Explanation

Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 2 functions across 5 files. (2 skipped: 1 unsupported, 1 too large.)

✨ Finishing Touches 💡 2
📝 Generate docstrings 💡
  • Commit to this branch
  • Create a new PR
🛠️ Fix failing CI checks 💡
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

A rabbit checks the cursor line
Five hundred marks now fit just fine
At five-oh-one, the tests say no
The schemas match the rules below
Then hops away through fields of snow

Comment @coderabbitai help to get the list of available commands.

@github-actions

github-actions Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

Relayfile Eval Review

Run: .relayfile/evals/runs/2026-10-08T18-09-42-345Z-HEAD-provider
Mode: provider
Git SHA: 95fe151

Passed: 4 | Needs human: 0 | Reviewable: 0 | Missing output: 0 | Failed: 0 | Skipped: 0

Human Review Cases

No reviewable human-review cases captured Relayfile output.

@miyaontherelay
miyaontherelay marked this pull request as ready for review October 8, 2026 02:04

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 7 files

View guided diff | Re-trigger cubic

@devin-ai-integration devin-ai-integration Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔍 Devin Review: 1 flag

Not posted on this PR by your GitHub settings — view it in Devin Review. (Configure)

Devin Review

…dary

Session-Id: 2c051289-3e25-4998-bb9a-b205eb1ebe4c
@khaliqgant
khaliqgant merged commit f66b94e into main Oct 8, 2026
13 checks passed
@khaliqgant
khaliqgant deleted the garden-rfc-b-532-boundary branch October 8, 2026 19:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants