Skip to content

fix(video): harden result cache identity and coalescing - #11362

Merged
diegosouzapw merged 4 commits into
release/v3.8.50from
fix/v3850-video-fu01-cache
Aug 24, 2026
Merged

diegosouzapw merged 4 commits into
release/v3.8.50from
fix/v3850-video-fu01-cache

Conversation

@diegosouzapw

Copy link
Copy Markdown
Owner

Summary

Completes the Video Bridge FU-01 cache-hardening slice on top of the live release/v3.8.50 tip.

  • fingerprints the authorized video bytes and all result-affecting dimensions before a persistent cache hit
  • validates cached metadata strictly and deletes/recomputes corrupt entries
  • bounds the TTL/LRU cache by entry count, per-entry bytes, and aggregate bytes
  • coalesces protected HTTPS downloads and result production without persisting raw URLs or media
  • isolates coalescing identity by tenant context and keeps waiter aborts independent from the producer
  • bounds model selection and cache waits by the request deadline/abort signal
  • separates persistent cache-hit telemetry from singleflight coalescing
  • logs fail-open cache failures without leaking media or credential material

TDD evidence

The regression suite was built RED→GREEN around:

  • stable HTTPS URL serving changed bytes
  • concurrent identical requests with cache enabled and disabled
  • single protected download with independent extractions
  • waiter abort, all-waiter abandonment, and fresh-flight replacement
  • tenant isolation
  • corrupt/unavailable cache fail-open behavior
  • invalid numeric metadata and byte-length mismatches
  • never-resolving model selection under timeout/abort
  • per-entry and aggregate byte bounds
  • coalesced telemetry not counted as persistent hits

Validation

  • focused Video Bridge matrix: 70/70 PASS
  • dedicated final result-cache suite: 33/33 PASS
  • npm run typecheck:core: PASS
  • targeted ESLint: PASS
  • npm run check:cycles: PASS (429 configured files)
  • changelog integrity: PASS
  • tracked-artifacts gate: PASS
  • git diff --check: PASS
  • independent read-only review: CLEAN (no blocker/P1/P2)

typecheck:noimplicit:core remains base-red only: 36 diagnostics are all in the untouched open-sse/translator/response/openai-responses/pureHelpers.ts; that blob is byte-identical between the PR base and head.

Release disposition

This PR resolves FU-01 only. It does not claim completion of FU-02 through FU-09 and does not authorize merge, tagging, or release publication. Please keep it open for owner review.

Comment thread src/lib/guardrails/videoBridge.ts Fixed
Comment thread src/lib/guardrails/videoBridge.ts Fixed
@diegosouzapw

Copy link
Copy Markdown
Owner Author

Babysit evidence — head d4ade9d1d3921b0425cb0263f47a0471eee8dd93

  • CodeQL remediation took two steps: f54c93c replaced the original SHA-256 identity digest with a process HMAC, but the query still followed principalId from apiKeyInfo and opened alert fix(429): parse long quota reset times from error body #859. d4ade9d instead keeps that authenticated, ephemeral principal as an unhashed in-memory tuple scope and hashes only the non-secret request fingerprint.
  • Verified result: the JavaScript/TypeScript CodeQL job passed on exact head d4ade9d1; analysis 1661479378 is bound to that SHA; alert #859 now reports its latest instance as fixed and is absent from the open-alert query. No alert was dismissed or waived, and the review thread auto-resolved.
  • The remaining reds are not PR-specific: Fast Production Build was externally cancelled during Next.js compilation with the exact same no-assertion signature as the exact-base dafb4ae8 run; DAST received SIGTERM in Build CLI bundle, before server startup, Schemathesis, or promptfoo, matching the prior #11342 infrastructure cancellation.

PR-specific security verdict: PASS. Overall CI is not being called green while those base/infra cancellations remain. PR intentionally remains open and draft for human review.

@diegosouzapw
diegosouzapw marked this pull request as ready for review August 24, 2026 12:24
@diegosouzapw
diegosouzapw merged commit 761d38f into release/v3.8.50 Aug 24, 2026
27 of 30 checks passed
diegosouzapw added a commit that referenced this pull request Aug 24, 2026
Merged via consolidated batch validation (worktree `.claude/worktrees/batch-0824d`), stacked on the just-merged #11362 as documented. Moves the Video Bridge frame cap to post-dedup, bounds the perceptual candidate pool to at most 2x budget (max 16), includes the dedup policy/version in result-cache identity, adds cooperative abort checks to the comparator loop. Static gates green; own dedup/cache-version regression suite passed in the combined-batch run (grayscale-16x16-mean-cells-v2 policy, real fixtures). Thanks!
diegosouzapw added a commit that referenced this pull request Aug 24, 2026
Merged via consolidated batch validation (worktree `.claude/worktrees/batch-0824d`), stacked on the just-merged #11362 as documented. Moves the Video Bridge frame cap to post-dedup, bounds the perceptual candidate pool to at most 2x budget (max 16), includes the dedup policy/version in result-cache identity, adds cooperative abort checks to the comparator loop. Static gates green; own dedup/cache-version regression suite passed in the combined-batch run (grayscale-16x16-mean-cells-v2 policy, real fixtures). Thanks!
diegosouzapw pushed a commit that referenced this pull request Aug 24, 2026
…11382/#11383 growth

These entries were already validated in an earlier merge-batch worktree but
never reached origin (worktree discarded before pushing). Re-adding them
here since #11355's test/route.ts growth (1215->1237) is now live on
origin/release/v3.8.50 and fails the frozen cap otherwise.
muhamadgalihsaputra pushed a commit to niyatna/NiyatnaRoute that referenced this pull request Sep 27, 2026
…#11362)

Merged via consolidated batch validation (worktree `.claude/worktrees/batch-0824d`). Completes the Video Bridge FU-01 cache-hardening slice: fingerprints authorized video bytes + result-affecting dimensions before a persistent cache hit, strict metadata validation with corrupt-entry recompute, TTL/LRU bounds by count/entry-bytes/aggregate-bytes, coalesced protected HTTPS downloads isolated by tenant, deadline/abort-bounded model selection. Static gates green; own regression suite (tests/unit/guardrails/videoBridgeResultCache.test.ts) passed in the combined-batch run. Thanks!
muhamadgalihsaputra pushed a commit to niyatna/NiyatnaRoute that referenced this pull request Sep 27, 2026
Merged via consolidated batch validation (worktree `.claude/worktrees/batch-0824d`), stacked on the just-merged diegosouzapw#11362 as documented. Moves the Video Bridge frame cap to post-dedup, bounds the perceptual candidate pool to at most 2x budget (max 16), includes the dedup policy/version in result-cache identity, adds cooperative abort checks to the comparator loop. Static gates green; own dedup/cache-version regression suite passed in the combined-batch run (grayscale-16x16-mean-cells-v2 policy, real fixtures). Thanks!
muhamadgalihsaputra pushed a commit to niyatna/NiyatnaRoute that referenced this pull request Sep 27, 2026
…apw#11344/diegosouzapw#11381/diegosouzapw#11362/diegosouzapw#11382/diegosouzapw#11383 growth

These entries were already validated in an earlier merge-batch worktree but
never reached origin (worktree discarded before pushing). Re-adding them
here since diegosouzapw#11355's test/route.ts growth (1215->1237) is now live on
origin/release/v3.8.50 and fails the frozen cap otherwise.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants