Skip to content

Cap intent LLM request text at 64 KiB so classify cannot unbounded-prompt the provider - #359

Merged
tylerreckart merged 3 commits into
mainfrom
fix/intent-llm-text-cap
Sep 21, 2026
Merged

tylerreckart merged 3 commits into
mainfrom
fix/intent-llm-text-cap

Conversation

@cursor

@cursor cursor Bot commented Sep 19, 2026 •

Copy link
Copy Markdown
Contributor

Problem

POST /v1/intent already rejects message bodies above 64 KiB, but orchestrator depth-0 hybrid/llm classify (apply_intent_ingress → resolve_intent → build_llm_user_prompt) embeds in.text wholesale. TUI, HTTP chat, and POST /v1/events can carry much larger payloads (HTTP request bodies are capped at 16 MiB), so a single ingress turn can send an unbounded provider prompt — cost and availability, not a style nit.

Heuristic classify is unchanged: it still sees the full text. Only the LLM user prompt is capped.

Fix

  • kIntentLlmTextMaxBytes = 64 * 1024 (same number as the HTTP route).
  • build_llm_user_prompt UTF-8-safely truncates request text and appends \n[truncated], matching presence/advisor field caps.
  • Isolated to src/intent.cpp + include/intent.h + tests/test_intent.cpp.

Tests

unit_intent:

  • mode=llm with 64 KiB + 4 KiB of x produces a [REQUEST] body ≤ 64 KiB that includes [truncated].
  • A request of exactly 64 KiB is forwarded unchanged.

Suite 27/27 locally (100 assertions) + ASan + UBSan.

Independently mergeable against main (0456350). git merge-tree --write-tree vs #321, #347, #350, #351, #353, #355, #356, #357, and #358 is CLEAN including CHANGELOG this run. Do not re-fix #321–#358.

Open in Web View Automation 

Note

Low Risk
Localized intent prompt shaping with tests; heuristic routing and HTTP reject behavior are unchanged aside from preventing oversized LLM prompts.

Overview
Orchestrator hybrid/llm intent classify now caps the [REQUEST] block in build_llm_user_prompt at 64 KiB (kIntentLlmTextMaxBytes), matching POST /v1/intent. Oversized TUI, chat, or event text is UTF-8–safely shortened and tagged with \n[truncated] before the provider call.

Heuristic classify is unchanged and still sees the full in.text. New unit_intent cases cover over-limit truncation and exact-boundary passthrough; CHANGELOG documents the fix.

Reviewed by Cursor Bugbot for commit 2ca3ecc. Bugbot is set up for automated code reviews on this repo. Configure here.

POST /v1/intent already rejects messages above 64 KiB, but orchestrator
hybrid/llm classify embedded in.text wholesale. A large TUI, chat, or
event payload became an unbounded provider prompt. Truncate UTF-8-safely
with a [truncated] marker, matching the HTTP limit.

Co-authored-by: Tyler Reckart <tylerreckart@users.noreply.github.com>
@tylerreckart
tylerreckart marked this pull request as ready for review September 21, 2026 12:58
@tylerreckart
tylerreckart enabled auto-merge (squash) September 21, 2026 12:58
@tylerreckart
tylerreckart merged commit 7a4a2eb into main Sep 21, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants