⏱️ fix: Fit Workspace Command Timeouts Inside the Configured Request Budget - #16464
Conversation
|
@codex review |
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 445a9895c1
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
Exact-head review handoff: |
|
@codex review the latest head |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: da76f75a26
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
Exact-head review handoff: |
|
@codex review the latest head |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 8aa19f1357
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
Exact-head review handoff: |
|
Exact-head review handoff: |
|
@codex review the latest head, final review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 2bb5e18b81
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
Exact-head review handoff: |
Summary
An attached (BYOM) code environment can set both a command timeout ceiling (
limits.maxCommandTimeoutMs) and a total HTTP budget (limits.maxRequestTimeoutMs, #16421). The two were never reconciled. Background Bash calls default to the full command ceiling, andexecuteWorkspaceToolreserves that timeout plus 5 s settlement and 5 s delivery grace inside the budget. With a ceiling of 80 s and a budget of 90 s, the reserve is exactly 90 s, so every background command was refused before dispatch: "Workspace execution cannot fit within the remaining HTTP budget. The operation was not started." Nothing ran, but every such background task failed. One deployment hit this 13 times in six hours. The tool schema also advertised timeouts up to 80 s that could never start.The command ceiling is now fitted to the budget wherever it is resolved. It becomes the lower of the configured ceiling and the budget minus settlement grace, delivery grace and an operator-configurable minimum admission allowance (10 s by default), so a fitted command can still wait briefly for a busy worker. With the configuration above, the ceiling becomes 70 s: background calls default to 70 s with up to 10 s of queue time before local dispatch overhead, the schema advertises 70 s, and an explicit 80 s request is rejected up front with the deployment-limit message instead of failing at dispatch. Without a request budget, nothing changes.
How it works
The resolver feeds both the Bash tool (
ToolService.js) and theworkspaceCommandTimeoutMaxMsthat agent initialization passes on, so they agree. The helper lives next to the grace constants incode/workspace.ts, so the fit and the dispatch-time reserve check cannot drift apart. SetconfigSchema.limits.minCommandAdmissionMsfrom 1000 to 300000 milliseconds in an attached code environment to change the reserve; omission retains 10000 milliseconds. With an HTTP budget configured, validation requiresmaxRequestTimeoutMs > (minCommandAdmissionMs ?? 10000) + 10000 msso the explicit or default admission reserve, settlement, delivery, and at least 1 ms of command execution fit. Omitting the admission setting with a budget of 20000 ms or less is rejected at configuration parsing; omitting the HTTP budget retains legacy behavior. Invalid combinations are rejected during configuration parsing instead of advertising a timeout that cannot honor the reserve. When rolling out the new setting, upgrade configuration readers before adding the field tolibrechat.yaml.Type of change
Testing
Tested environments/configuration:
limits: { maxCommandTimeoutMs: 80000, maxRequestTimeoutMs: 90000 }, where background Bash calls were failing before dispatch.Automated tests:
packages/api:npx jest src/code src/agents/__tests__/initialize(548 passed, 1 skipped). New cases:The attached-environment YAML example shows the configured minimum admission allowance before local auth overhead: with a 125 s HTTP budget and the 10 s default allowance, a command can advertise at most 105 s; a 120 s command requires at least 140 s on the actual network path.
Current-head verification: Config schema: 266 passed; command/workspace: 125 passed; ToolService wiring: 1 passed. Data-provider
npx tsc --noEmit, scoped ESLint, Prettier and import sort passed locally. CI verifies the API TypeScript workspace and the production build; local API typechecking is limited by incomplete shared dependencies. A simulated 200 ms credential-signing delay at the minimum 1 s admission reserve still dispatches with 800 ms of queue allowance. The Playwright test selectors follow the steering preference copy merged todevin #16465, and the failed-call accessible-name assertion follows the counted label merged in #16468. Both changes only affect E2E assertions against GitHub’s actualdevmerge.