Repository navigation
Cap intent LLM request text at 64 KiB so classify cannot unbounded-prompt the provider - #359
Merged
Merged
Conversation
POST /v1/intent already rejects messages above 64 KiB, but orchestrator hybrid/llm classify embedded in.text wholesale. A large TUI, chat, or event payload became an unbounded provider prompt. Truncate UTF-8-safely with a [truncated] marker, matching the HTTP limit. Co-authored-by: Tyler Reckart <tylerreckart@users.noreply.github.com>
This was referenced Sep 19, 2026
# Conflicts: # CHANGELOG.md
tylerreckart
marked this pull request as ready for review
September 21, 2026 12:58
tylerreckart
enabled auto-merge (squash)
September 21, 2026 12:58
# Conflicts: # CHANGELOG.md
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
POST /v1/intentalready rejectsmessagebodies above 64 KiB, but orchestrator depth-0 hybrid/llm classify (apply_intent_ingress→resolve_intent→build_llm_user_prompt) embedsin.textwholesale. TUI, HTTP chat, andPOST /v1/eventscan carry much larger payloads (HTTP request bodies are capped at 16 MiB), so a single ingress turn can send an unbounded provider prompt — cost and availability, not a style nit.Heuristic classify is unchanged: it still sees the full text. Only the LLM user prompt is capped.
Fix
kIntentLlmTextMaxBytes = 64 * 1024(same number as the HTTP route).build_llm_user_promptUTF-8-safely truncates request text and appends\n[truncated], matching presence/advisor field caps.src/intent.cpp+include/intent.h+tests/test_intent.cpp.Tests
unit_intent:mode=llmwith64 KiB + 4 KiBofxproduces a[REQUEST]body ≤ 64 KiB that includes[truncated].Suite 27/27 locally (100 assertions) + ASan + UBSan.
Independently mergeable against
main(0456350).git merge-tree --write-treevs #321, #347, #350, #351, #353, #355, #356, #357, and #358 is CLEAN including CHANGELOG this run. Do not re-fix #321–#358.Note
Low Risk
Localized intent prompt shaping with tests; heuristic routing and HTTP reject behavior are unchanged aside from preventing oversized LLM prompts.
Overview
Orchestrator hybrid/llm intent classify now caps the
[REQUEST]block inbuild_llm_user_promptat 64 KiB (kIntentLlmTextMaxBytes), matchingPOST /v1/intent. Oversized TUI, chat, or event text is UTF-8–safely shortened and tagged with\n[truncated]before the provider call.Heuristic classify is unchanged and still sees the full
in.text. Newunit_intentcases cover over-limit truncation and exact-boundary passthrough; CHANGELOG documents the fix.Reviewed by Cursor Bugbot for commit 2ca3ecc. Bugbot is set up for automated code reviews on this repo. Configure here.