Skip to content

Wire EnforceResourceCeiling into runtime and sandbox enforcement - #3159

Merged
serrrfirat merged 4 commits into
reborn-integrationfrom
sandcastle/issue-3144-wire-enforce-resource-ceiling
May 2, 2026
Merged

serrrfirat merged 4 commits into
reborn-integrationfrom
sandcastle/issue-3144-wire-enforce-resource-ceiling

Conversation

@serrrfirat

Copy link
Copy Markdown
Collaborator

Closes #3144

Summary

Wires Obligation::EnforceResourceCeiling into the Reborn host-runtime obligation path so non-output resource ceilings are either handed to host-owned enforcement or rejected fail-closed instead of being silently accepted.

Issue context

Implementation

  • Includes EnforceResourceCeiling in post-dispatch obligation handling.
  • Adds host-runtime resource ceiling validation/handoff logic for estimate/usage ceilings.
  • Rejects unsupported sandbox quota fields fail-closed rather than accepting unenforced limits.
  • Keeps existing EnforceOutputLimit behavior intact.
  • Documents the host-runtime resource ceiling handoff behavior.

Changed files

Cargo.lock
crates/ironclaw_capabilities/src/obligations.rs
crates/ironclaw_host_runtime/Cargo.toml
crates/ironclaw_host_runtime/src/obligations.rs
crates/ironclaw_host_runtime/tests/builtin_obligation_handler_contract.rs
docs/reborn/contracts/host-runtime.md

Diff stat

Cargo.lock                                         |   1 +
crates/ironclaw_capabilities/src/obligations.rs    |   1 +
crates/ironclaw_host_runtime/Cargo.toml            |   1 +
crates/ironclaw_host_runtime/src/obligations.rs    | 160 +++++++++++++++-
crates/ironclaw_host_runtime/tests/builtin_obligation_handler_contract.rs | 201 ++++++++++++++++++++-
docs/reborn/contracts/host-runtime.md              |   3 +-
6 files changed, 360 insertions(+), 7 deletions(-)

Acceptance criteria coverage

  • EnforceResourceCeiling now has a concrete host-runtime handoff path.
  • Non-output ceiling fields are checked against estimates/usage or fail closed.
  • Unsupported sandbox quota fields are rejected instead of silently accepted.
  • Tests cover allow/deny paths for non-output ceiling fields.
  • Existing output-limit behavior is kept separate.

Verification requested by issue

cargo test -p ironclaw_host_runtime
cargo test -p ironclaw_resources
cargo test -p ironclaw_dispatcher
python3.11 scripts/check_no_panics.py --base origin/reborn-integration --head HEAD

Review notes

This PR was generated from the Sandcastle branch for #3144 and should be reviewed against reborn-integration.

Task: complete issue #3144; refs obligations PR #3080 and resource authority #3141.

Decisions: support invoke/resume ceilings by decomposing them into host-owned estimate checks plus post-dispatch ResourceUsage/output checks; keep spawn and unenforced sandbox CPU/memory/disk quotas fail-closed; preserve EnforceOutputLimit behavior.

Files: host-runtime obligation handler/tests/docs, capabilities post-dispatch classification, host-runtime Cargo metadata.

Notes: no FEATURE_PARITY.md update needed; Reborn resource-ceiling behavior is tracked in docs/reborn/contracts/host-runtime.md.
@github-actions github-actions Bot added scope: docs Documentation scope: dependencies Dependency updates size: M 50-199 changed lines risk: low Changes to docs, tests, or low-risk modules contributor: core 20+ merged PRs labels May 1, 2026
@serrrfirat serrrfirat linked an issue May 1, 2026 that may be closed by this pull request
5 tasks

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request implements the EnforceResourceCeiling obligation within the BuiltinObligationHandler. The changes introduce logic to validate resource estimates against defined ceilings before capability dispatch and verify actual resource usage (including USD cost, token counts, and wall-clock time) after dispatch. The PR also adds the rust_decimal dependency, updates the host runtime documentation, and includes comprehensive contract tests. Feedback was provided regarding the naming of a helper function to ensure consistency with other validation methods.

Ok(())
}

fn check_optional_decimal_ceiling(

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

medium

The function name check_optional_decimal_ceiling is misleading because it actually requires the actual value to be present if a ceiling is specified. Renaming it to check_required_decimal_ceiling would be more consistent with check_required_integer_ceiling and better reflect its behavior.

Suggested change
fn check_optional_decimal_ceiling(
fn check_required_decimal_ceiling(

@serrrfirat serrrfirat mentioned this pull request May 1, 2026
14 of 37 tasks
@serrrfirat
serrrfirat merged commit 98692d5 into reborn-integration May 2, 2026
14 checks passed
@serrrfirat
serrrfirat deleted the sandcastle/issue-3144-wire-enforce-resource-ceiling branch May 2, 2026 06:04
theredspoon pushed a commit to theredspoon/ironclaw that referenced this pull request Jun 21, 2026
…rai#3159)

* RALPH: wire EnforceResourceCeiling handoff

Task: complete issue nearai#3144; refs obligations PR nearai#3080 and resource authority nearai#3141.

Decisions: support invoke/resume ceilings by decomposing them into host-owned estimate checks plus post-dispatch ResourceUsage/output checks; keep spawn and unenforced sandbox CPU/memory/disk quotas fail-closed; preserve EnforceOutputLimit behavior.

Files: host-runtime obligation handler/tests/docs, capabilities post-dispatch classification, host-runtime Cargo metadata.

Notes: no FEATURE_PARITY.md update needed; Reborn resource-ceiling behavior is tracked in docs/reborn/contracts/host-runtime.md.

* fix(host-runtime): fail closed unsupported resource ceilings

* fix(host-runtime): enforce resource output ceiling on published bytes
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

contributor: core 20+ merged PRs risk: low Changes to docs, tests, or low-risk modules scope: dependencies Dependency updates scope: docs Documentation size: M 50-199 changed lines

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Wire EnforceResourceCeiling into runtime and sandbox enforcement

1 participant