Commit Graph

4 Commits

Author SHA1 Message Date
can1357 df0bb6e31a feat: implemented provider wire codecs and optimized telemetry and parsing
- Added internal protobuf wire codecs, message builders, and protocol definitions for Cursor and Devin providers.
- Deferred loading of OTel SDK and OTLP exporters and added bounded caches to optimize startup and lookup performance.
- Added SQLite-backed parse caching for legacy extension source analysis and streaming file chunk parsing for changelogs.
- Added support for rendering context usage overflow above 100% in the status line component.
2026-08-20 07:54:06 +02:00
Brian Corrigan 3bfce1d7b4 Treat content-length as transport-owned in both providers
The fetch layer recomputes Bedrock's content-length from the serialized body,
so a caller value would be covered by the SigV4 signature but never sent, and
AWS rejects the mismatch. Cursor streams its Connect body after the headers
(initial frame, heartbeats, tool responses), so no caller-supplied length can
describe it and an HTTP/2 peer resets the stream once the body diverges.

Reserved in both, and both regressions now send a Content-Length to prove it
never reaches the wire.
2026-08-09 15:32:48 -06:00
Brian Corrigan 9dc3594187 Test the Cursor transport contract, and treat host as transport-owned
Three review findings.

host is transport-owned even though this request never sets it: node's http2
client suppresses the :authority it derives from the URL when a plain host
header is present, so a caller value silently retargeted the request at another
virtual host. Added to the reserved set.

The tests exercised only the exported sanitizer, so if streamCursor stopped
merging callerHeaders every one of them would still have passed while the wire
lost the headers. They now drive streamCursor against a local HTTP/2 server and
assert what the server actually received: an ordinary header arrives, names are
lower-cased, connection-specific and pseudo-headers neither arrive nor kill the
request, the request's own headers are not overridable, and the authority is
not retargetable. All five fail if the merge is removed. That also lets
sanitizeCursorCallerHeaders stop being exported.

The changelog entry pointed at #8046, the parent work, rather than the PR being
released here, and lacked the contributor credit the external-contribution
convention requires.
2026-08-09 15:15:47 -06:00
Brian Corrigan 7527fd53a2 fix(ai): honor StreamOptions.headers in Bedrock and Cursor
Both transports built their request header maps from scratch and never read
options.headers, so caller-supplied tracing or attribution headers were
silently dropped while working on every other provider. Bedrock now merges
caller headers before SigV4 signing so the signature covers them; Cursor
merges them into its HTTP/2 request.

Merging exposed three rules each transport enforces that a caller cannot be
allowed to violate, all covered by regressions that fail against the previous
code:

- SigV4 generates host/x-amz-date/x-amz-content-sha256/x-amz-security-token
  for itself. signRequest signs a caller value but returns its own, so a
  caller supplying any of them would sign one set of bytes and send another.
- HTTP/2 forbids the HTTP/1 connection-specific headers, and node's
  http2.request() throws on them rather than ignoring them.
- Header names are compared case-insensitively on the wire, so a caller
  Content-Type beside a fixed content-type is a duplicate rather than an
  override. Caller names are lower-cased and copies of headers each request
  sets itself are dropped.
2026-08-09 14:10:12 -06:00