Repository navigation
Wire EnforceResourceCeiling into runtime and sandbox enforcement - #3159
serrrfirat merged 4 commits into
Conversation
Task: complete issue #3144; refs obligations PR #3080 and resource authority #3141. Decisions: support invoke/resume ceilings by decomposing them into host-owned estimate checks plus post-dispatch ResourceUsage/output checks; keep spawn and unenforced sandbox CPU/memory/disk quotas fail-closed; preserve EnforceOutputLimit behavior. Files: host-runtime obligation handler/tests/docs, capabilities post-dispatch classification, host-runtime Cargo metadata. Notes: no FEATURE_PARITY.md update needed; Reborn resource-ceiling behavior is tracked in docs/reborn/contracts/host-runtime.md.
There was a problem hiding this comment.
Code Review
This pull request implements the EnforceResourceCeiling obligation within the BuiltinObligationHandler. The changes introduce logic to validate resource estimates against defined ceilings before capability dispatch and verify actual resource usage (including USD cost, token counts, and wall-clock time) after dispatch. The PR also adds the rust_decimal dependency, updates the host runtime documentation, and includes comprehensive contract tests. Feedback was provided regarding the naming of a helper function to ensure consistency with other validation methods.
| Ok(()) | ||
| } | ||
|
|
||
| fn check_optional_decimal_ceiling( |
There was a problem hiding this comment.
The function name check_optional_decimal_ceiling is misleading because it actually requires the actual value to be present if a ceiling is specified. Renaming it to check_required_decimal_ceiling would be more consistent with check_required_integer_ceiling and better reflect its behavior.
| fn check_optional_decimal_ceiling( | |
| fn check_required_decimal_ceiling( |
# Conflicts: # crates/ironclaw_host_runtime/src/obligations.rs
…rai#3159) * RALPH: wire EnforceResourceCeiling handoff Task: complete issue nearai#3144; refs obligations PR nearai#3080 and resource authority nearai#3141. Decisions: support invoke/resume ceilings by decomposing them into host-owned estimate checks plus post-dispatch ResourceUsage/output checks; keep spawn and unenforced sandbox CPU/memory/disk quotas fail-closed; preserve EnforceOutputLimit behavior. Files: host-runtime obligation handler/tests/docs, capabilities post-dispatch classification, host-runtime Cargo metadata. Notes: no FEATURE_PARITY.md update needed; Reborn resource-ceiling behavior is tracked in docs/reborn/contracts/host-runtime.md. * fix(host-runtime): fail closed unsupported resource ceilings * fix(host-runtime): enforce resource output ceiling on published bytes
Closes #3144
Summary
Wires
Obligation::EnforceResourceCeilinginto the Reborn host-runtime obligation path so non-output resource ceilings are either handed to host-owned enforcement or rejected fail-closed instead of being silently accepted.Issue context
reborn-integrationnearai/ironclaw:sandcastle/issue-3144-wire-enforce-resource-ceilingImplementation
EnforceResourceCeilingin post-dispatch obligation handling.EnforceOutputLimitbehavior intact.Changed files
Diff stat
Acceptance criteria coverage
EnforceResourceCeilingnow has a concrete host-runtime handoff path.Verification requested by issue
Review notes
This PR was generated from the Sandcastle branch for #3144 and should be reviewed against
reborn-integration.