Repository navigation
fix(providers,agent): share devin model list, validate auth URL, fix token tracking - #226
Conversation
- Update router test to load queries from fixture file - Add auto-detection patterns for search, skeleton, and trace intents - Expand fixture with 30 labeled queries for better coverage
…token tracking - Register the `swe-1-7-max` alias for `swe-1-7` and correct its context window to 262_144 tokens in the Devin model catalog. - Validate the devin `base_url` before building auth requests, falling back to the configured API server when it is not an http/https URL. This fixes `failed to build auth request: invalid format` for `devin2`. - Convert Devin `ModelUsageStats` to `TokenUsage` correctly, treating `input_tokens` as the total prompt and cache fields as additive details, with a safe fallback when the server already reports input as non-cached. - Report the post-compaction conversation size in `TurnComplete` instead of the summary output token count, so the TUI context meter no longer resets after compaction.
|
Warning Review limit reached
Next review available in: 46 minutes You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. How can I continue?After more reviews become available, a review can be triggered using the To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews. How do review limits work?CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability. For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window. Please refer docs for additional details. Review details⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Pro Plus Run ID: 📒 Files selected for processing (22)
📝 WalkthroughSummary by CodeRabbit
WalkthroughThe pull request updates Fusion lifecycle and lane handling, post-compaction context accounting, and Devin provider behavior. Devin model aliases, context windows, URL validation, and usage conversion now use corrected values and fallback rules. ChangesFusion orchestration
Devin provider accounting
Estimated code review effort: 4 (Complex) | ~60 minutes Possibly related PRs
Poem
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
…liases The two available SWE-1.7 variants are `-max` and `-medium`; `-max` is now the canonical id and `swe-1-7`, `swe-1.7`, and `swe-1.7-max` are aliases for it. Dot-prefixed aliases are also added for `-medium` and `-lightning` to match the names the Devin API recognizes. The Devin provider now picks the first catalog prefix that is present in the server-side CLI model-config map before looking up the wire uid, so aliases resolve to the correct server model regardless of which form is canonical in the catalog.
Use the explicit canonical SWE-1.7 Max id in the provider manifest so the default model spec is unambiguous.
`apply_fusion_route` was collapsing `Switch(Sidekick)` and `EscalateToLead` into `FusionLane::Lead`, so `route_after_compact` could return a sidekick route but the main agent never actually entered the sidekick lane. The function now extracts the lane from the route, updates the Fusion state, and applies the matching lane context. Updated the unit test to assert the expected sidekick lane while still checking that the lead model and provider are not replaced.
|
@codex review |
|
@cursor review |
|
@coderabbitai review |
|
@BugBot review |
✅ Action performedReview finished.
|
There was a problem hiding this comment.
Actionable comments posted: 14
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@n00n-agent/src/agent/compaction.rs`:
- Around line 164-169: Update the TurnComplete send in finish_compact to stop
silently discarding delivery failures: propagate the channel-send error through
a typed error and return it from finish_compact, then ensure compact_history
propagates that result. If delivery is intentionally best effort instead, use an
explicitly named fallback with sanitized structured logging.
In `@n00n-agent/src/agent/run.rs`:
- Around line 1042-1053: The FusionFailure value returned by
fusion_failure_from_result is currently discarded in handle_fusion_results via
FusionState::delegate_failed. Either propagate and record the failure kind in
FusionState or include it in the relevant warn!/info! telemetry fields;
otherwise remove fusion_failure_from_result and its unused classification path
until a consumer is implemented.
- Around line 379-403: Reset the retained fusion lifecycle at the beginning of
each run before the FusionPhase::Planning emission. Update the run method’s
fusion_state handling so a subsequent user turn starts from a fresh non-terminal
state while preserving the existing success, cancellation, and failure
transitions.
In `@n00n-agent/src/agent/tool_dispatch.rs`:
- Around line 2196-2210: Update fusion_dispatch_guard_denies_non_delegate_policy
to pass DelegationKind values directly through #[test_case] instead of accepting
string policy keys and matching with a fallback. Move the relevant fusion import
to the test module header so DelegationKind can be referenced in the test-case
attributes, while preserving the existing enabled values, labels, and
authorization assertion.
- Around line 2183-2237: Integrate FusionDispatchGuard into the production
process_tool_calls dispatch flow, constructing it with the current fusion
configuration, delegation classification, and tool audience before execution and
consulting authorize for each applicable call. Ensure denied origins,
non-delegate policies, recursive child audiences, and repeated direct main
delegation are rejected in the real run path, replacing the tests-only usage
without altering unrelated skill/non-skill dispatch behavior.
In `@n00n-agent/src/fusion/mod.rs`:
- Around line 305-332: The lifecycle currently blocks execution whenever
FusionState::lane is Sidekick, while callers mutate the public field directly.
In n00n-agent/src/fusion/mod.rs lines 305-332, make lane private and add a
setter that preserves phase/lane consistency, then update
n00n-agent/src/agent/run.rs lines 924-936 to use it instead of assigning
state.lane directly and combine the duplicated None checks; alternatively remove
the transition precondition and, if Lead must remain required, also remove
FusionRoute::Switch(FusionLane::Sidekick) from route_after_compact.
- Around line 373-386: Update enter_terminal to call FusionPhase::is_terminal
instead of duplicating the inline matches! variant list, while preserving the
existing error and state-transition behavior.
- Around line 92-98: Remove Clone and Copy from the derive attributes on
FusionDispatchGuard, retaining only the required non-copy traits. Preserve the
guard’s single-use ownership semantics so authorize cannot be invoked again
through an implicitly duplicated value.
- Around line 550-570: Update classify_delegation_contract to compare the
DelegationKind returned by classify_delegation directly with typed expected
variants, rather than converting the result to a Debug string. Replace the
string-based test-case expectations with DelegationKind values so variant
renames remain compile-time checked.
- Around line 487-500: Extract the repeated mutation signal strings into a
module-level MUTATION_SIGNALS constant immediately after imports, then update
both the DELEGATE list and the requests_mutation check to reference it. Remove
the inline array so both paths share one authoritative list and remain aligned.
In `@n00n-providers/src/providers/devin.rs`:
- Around line 158-169: Update resolve_api_server_url to parse the trimmed
base_url as an absolute URL before accepting it, requiring an http or https
scheme and a non-empty host; otherwise log the warning and return configured.
Add coverage for a malformed HTTP(S)-prefixed value such as “https://”,
including the corresponding validation path near the other base URL handling.
- Around line 214-245: Update devin_usage_to_token_usage so it does not infer
input-token semantics from numeric comparisons between input_tokens and cache
counters. Use an explicit Devin response format indicator, version, or
documented invariant to select whether input_tokens is total prompt usage or
non-cached input, preserving the corresponding cache details and total-input
calculations. Add fixtures covering both formats with overlapping counter
ranges.
In `@n00n-ui/src/chat.rs`:
- Around line 1007-1010: Add test cases to the FusionPhase rendering table
covering Complete, Cancelled, and Failed, using each phase’s expected display
string and unique test names. Preserve the existing cases for Planning,
Executing, Reviewing, and LeadFallback.
In `@plugins/fusion/init.lua`:
- Around line 123-125: Update the header function’s description truncation to
use utf8.offset when determining the 40-character boundary, then pass that
codepoint-safe boundary to string.sub so multi-byte UTF-8 characters are never
cut mid-sequence.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: ASSERTIVE
Plan: Pro Plus
Run ID: ac9530d9-95a9-4162-bf4a-f6ae54861105
📒 Files selected for processing (23)
changelog.d/devin-tokens.fixed.mdchangelog.d/fusion-beta-orchestration.added.mdchangelog.d/live-task-progress.fixed.mdn00n-agent/src/agent/compaction.rsn00n-agent/src/agent/run.rsn00n-agent/src/agent/tool_dispatch.rsn00n-agent/src/fusion/mod.rsn00n-agent/src/lib.rsn00n-agent/src/types.rsn00n-config/src/lib.rsn00n-lua/tests/real_plugins_restore.rsn00n-providers/src/providers/devin.rsn00n-providers/src/providers/devin_models.rsn00n-ui/src/app/tests.rsn00n-ui/src/chat.rsplugins/fusion/init.luasrc/cli.rssrc/cmd/agent.rssrc/cmd/mod.rssrc/cmd/tui.rssrc/print.rssrc/sdk_mode.rstests/fixtures/explore-queries.json
📜 Review details
⏰ Context from checks skipped due to timeout. (1)
- GitHub Check: Cursor Bugbot
🧰 Additional context used
📓 Path-based instructions (1)
**/*.rs
📄 CodeRabbit inference engine (AGENTS.md)
**/*.rs: Do not add unsafe code, FFI, global mutable state,static mut, or unchecked transmute-like behavior without written review, an explicit lint exception, and a SAFETY comment where applicable.
Do not useunwrap,expect,panic!,todo!,unimplemented!, ordbg!in production Rust code; tests are exempt from the unwrap/expect/panic restriction.
Do not silently discard failures withunwrap_or,unwrap_or_default,.ok()onResult, or equivalent defaults; return typed errors, reject the operation, or use an explicitly named fallback with sanitized structured logging.
Use idiomatic Rust, descriptive names, minimal state, and avoid unnecessary comments, bloat, and magic numbers or strings.
Import types at the top of the file and use short imported names; keep constants immediately after imports.
UseResult<T, E>and explicit error handling instead of panics; usethiserrorfor library/domain errors andcolor-eyreat binary edges.
Use#[derive(Copy)]only for structs containing one primitive field.
Prefer structured logging with useful fields and provide helpful, sanitized error messages.
Place unit tests in the same file inside#[cfg(test)]modules; use#[test_case]and snake_case test names.
Propagate typed errors with?,ok_or_else, andmap_err; library crates usethiserrorand binaries usecolor-eyre.
Treat LLM and provider output as untrusted input; validate schemas, domain constraints, and source evidence before persistence or action.
Do not log raw provider payloads, prompts, credentials, or user session data, and never commit credentials, API keys, tokens, cookies, or auth headers.
Validate and authorize HTTP, file, queue, configuration/environment, LLM, and provider-callback inputs before mutation or persistence.
Tool execution requires allowlisted tools, scoped credentials, explicit user context, audit events, and refusal or denial tests.
Files:
n00n-agent/src/types.rsn00n-lua/tests/real_plugins_restore.rssrc/sdk_mode.rssrc/cli.rsn00n-agent/src/agent/tool_dispatch.rsn00n-agent/src/lib.rssrc/print.rssrc/cmd/agent.rssrc/cmd/tui.rsn00n-ui/src/app/tests.rsn00n-ui/src/chat.rssrc/cmd/mod.rsn00n-providers/src/providers/devin_models.rsn00n-agent/src/agent/compaction.rsn00n-config/src/lib.rsn00n-providers/src/providers/devin.rsn00n-agent/src/fusion/mod.rsn00n-agent/src/agent/run.rs
🧠 Learnings (1)
📚 Learning: 2026-07-31T19:15:04.814Z
Learnt from: w0wl0lxd
Repo: w0wl0lxd/n00n PR: 206
File: changelog.d/orchestration-hardening.fixed.md:1-1
Timestamp: 2026-07-31T19:15:04.814Z
Learning: Files in changelog.d are changelog fragments intended for user-facing release notes and may begin directly with summary prose. Do not flag a missing Markdown H1 or require an H1 solely because Markdownlint MD041 reports it in these fragment files.
Applied to files:
changelog.d/fusion-beta-orchestration.added.mdchangelog.d/live-task-progress.fixed.mdchangelog.d/devin-tokens.fixed.md
🪛 markdownlint-cli2 (0.23.1)
changelog.d/fusion-beta-orchestration.added.md
[warning] 1-1: First line in a file should be a top-level heading
(MD041, first-line-heading, first-line-h1)
changelog.d/live-task-progress.fixed.md
[warning] 1-1: First line in a file should be a top-level heading
(MD041, first-line-heading, first-line-h1)
changelog.d/devin-tokens.fixed.md
[warning] 1-1: First line in a file should be a top-level heading
(MD041, first-line-heading, first-line-h1)
🔇 Additional comments (38)
tests/fixtures/explore-queries.json (1)
1-32: LGTM!changelog.d/live-task-progress.fixed.md (1)
1-1: LGTM!n00n-providers/src/providers/devin.rs (2)
38-41: LGTM!Also applies to: 63-63
711-726: LGTM!n00n-providers/src/providers/devin_models.rs (1)
823-855: LGTM!Also applies to: 2678-2683
n00n-config/src/lib.rs (4)
2248-2253: LGTM!
2255-2266: LGTM!
2268-2283: LGTM!
2285-2296: LGTM!src/cli.rs (1)
591-609: LGTM!src/cmd/mod.rs (2)
20-27: LGTM!
159-182: LGTM!src/cmd/agent.rs (1)
398-399: LGTM!src/cmd/tui.rs (1)
111-115: LGTM!n00n-agent/src/types.rs (1)
872-876: The serde derive concern forcrate::fusion::FusionPhaseis already raised onn00n-agent/src/fusion/mod.rsLines 43-54. The variant itself and its consumer coverage look correct.n00n-agent/src/fusion/mod.rs (8)
7-11: LGTM!
100-148: LGTM!
178-180: LGTM!Also applies to: 196-198
231-247: LGTM!
271-274: LGTM!
407-411: LGTM!Also applies to: 445-454
631-798: LGTM!
43-54: 🩺 Stability & AvailabilityNo change needed for
FusionPhaseserde derives.
AgentEventonly derivesSerialize, soFusionPhasedoes not needDeserializefor the current serde requirements.> Likely an incorrect or invalid review comment.n00n-agent/src/lib.rs (1)
21-23: LGTM!n00n-agent/src/agent/run.rs (4)
8-9: LGTM!Also applies to: 27-28, 44-45
561-561: LGTM!Also applies to: 649-654
743-787: LGTM!
1465-1479: LGTM!Also applies to: 1666-1915
n00n-ui/src/app/tests.rs (1)
2239-2268: LGTM!n00n-ui/src/chat.rs (2)
181-195: LGTM!
1027-1050: LGTM!src/print.rs (1)
369-369: LGTM!src/sdk_mode.rs (1)
1057-1057: LGTM!n00n-lua/tests/real_plugins_restore.rs (1)
766-766: LGTM!changelog.d/fusion-beta-orchestration.added.md (1)
1-1: LGTM!n00n-agent/src/agent/compaction.rs (2)
155-162: LGTM!
149-153: 🎯 Functional CorrectnessNo ownership change needed.
TokenUsageisCopy, soTurnCompleteEventreceives a copy andusageis still usable afterward.> Likely an incorrect or invalid review comment.changelog.d/devin-tokens.fixed.md (1)
1-7: LGTM!
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: a2ce319c25
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Charge main-agent API usage to the lead lane, include continue/tool tokens in post-compact TurnComplete context_size, and enforce FusionDispatchGuard plus Planning/Lead lifecycle checks in live tool dispatch so extra or sidekick-lane delegates cannot bypass review/fallback follow-up.
|
@coderabbitai review |
|
@codex review |
✅ Action performedReview finished.
|
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 399ef1f515
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
… tokens, and ui tests
|
@codex review |
|
@cursor review |
…ify token usage format
|
@codex review |
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes using high effort and found 2 potential issues.
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit 399ef1f. Configure here.
Codecov Report❌ Patch coverage is
📢 Thoughts on this report? Let us know! |
|
@codex review |
|
@cursor review |
Bugbot couldn't run - usage limit reachedBugbot is counted against Cursor usage for this user or team, and this run hit a usage or spend limit. A user or team admin can review and increase usage limits in the Cursor dashboard. (requestId: serverGenReqId_cfcc6727-f4f8-4722-9095-5bd7a7ed2288) |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: d422c9b88e
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review |
|
@cursor review |
Bugbot couldn't run - usage limit reachedBugbot is counted against Cursor usage for this user or team, and this run hit a usage or spend limit. A user or team admin can review and increase usage limits in the Cursor dashboard. (requestId: serverGenReqId_938c23f2-ef35-4b8b-be0f-aa553895e91a) |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: b677020756
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@cursor review verbose=true |
|
Bugbot request id: serverGenReqId_ff2bedc7-26e9-4b94-9d82-a1772f7c7b2d |
Bugbot rules debugNo rules were used for this review. https://cursor.com/docs/bugbot#team-rules Bugbot request id: serverGenReqId_ff2bedc7-26e9-4b94-9d82-a1772f7c7b2d |
Bugbot couldn't run - usage limit reachedBugbot is counted against Cursor usage for this user or team, and this run hit a usage or spend limit. A user or team admin can review and increase usage limits in the Cursor dashboard. (requestId: serverGenReqId_ff2bedc7-26e9-4b94-9d82-a1772f7c7b2d) |
…d after main merge
…apping after main merge

Why
The
devin/devin2providers had three related issues:swe-1-7-maxwas not the canonical model id; the SWE-1.7 family has only-maxand-mediumvariants.devin2as thebase_urlproducedfailed to build auth request: invalid formatbecause the value was used as a URL without validation.A code review also found that the pre-existing Fusion orchestration code on this branch had a real bug in
apply_fusion_route, which was fixed in this PR.What changed
swe-1-7-maxthe canonical id for the SWE-1.7 Max variant andswe-1-7-mediumcanonical for the Medium variant. Addedswe-1-7,swe-1.7,swe-1.7-max,swe-1.7-medium, andswe-1.7-lightningas aliases so all common forms resolve. Updated the Devin manifest'sdefault_modeltodevin/swe-1-7-max.resolve_api_server_urlnow trims and validatesbase_url, only accepting it when it starts withhttp://orhttps://; otherwise it falls back to the configured API server.devin_usage_to_token_usageto convert DevinModelUsageStatstoTokenUsage:input_tokensis treated as the total prompt (including cache reads/writes) when cache is smaller than or equal to it.input_tokensis already the non-cached remainder, the cache fields are kept as additive details andinputis left unchanged.debug!logging around usage conversion to make future Devin token bugs observable.finish_compactnow computes the post-compaction conversation size from the compacted history instead of using the summary output token count, so the TUI context meter no longer drops abruptly after compaction.apply_fusion_routeto honor the lane specified inFusionRoute::SwitchandFusionRoute::Stayinstead of always forcingLead, and updated the corresponding unit test.resolve_api_server_url,devin_usage_to_token_usage, the Devin model catalog aliases, and Fusion lane routing.Verification
cargo fmt --allcargo checkwas skipped locally because the worktree is oversubscribed; CI will run the full check.git commitpre-commit hooks passed (gitleaks,rustfmt,merge-conflict,conventional-commit).changelog.d/devin-tokens.fixed.mdfragment.Risk and rollback
git revertof the merge commit.Work log
No separate work-log file; this PR description and the
changelog.d/devin-tokens.fixed.mdfragment capture the session.Changelog
See
changelog.d/devin-tokens.fixed.md:swe-1-7-maxandswe-1-7-mediumas canonical SWE-1.7 model ids with dot/dash aliases.devin/devin2base_urlfor auth requests.Note
Medium Risk
Large Fusion lifecycle and agent-run behavior changes affect delegation, compaction events, and tool authorization; Devin auth/usage semantics touch billing and context display.
Overview
Devin provider and context meter (see
changelog.d/devin-tokens.fixed.md): canonicalswe-1-7-max/swe-1-7-mediumids with dot/dash aliases and a corrected 262k context window;base_urlis validated ashttp(s)://before auth; gRPC usage mapsinput_tokensto total prompt with cache fields as additive details when consistent. After compaction,TurnCompletenow uses tokenizer-basedcontext_sizeon the compacted history (plus tools in auto-compact) instead of summary output tokens, so the UI meter does not cliff-drop.Fusion orchestration is reworked around an explicit phase machine (
Planning→Executing→Reviewing/LeadFallback→Complete) withFusionDispatchGuard(one direct main-agent delegate, policy/classification checks) andFusionDispatchAuthpassed into tool dispatch. The run loop no longer hidesfusion_delegateor strips lead prompts per turn; delegation outcomes inject review/fallback synthetic messages and emitAgentEvent::FusionPhase(serde alias forFusionPhaseChanged).apply_fusion_routerespectsStay/Switchlanes and updates system prompt/tools viaapply_fusion_lane_context; post-compact routing escalates on repeated sidekick/tool errors and no longer switches the main agent off lead for mechanical summaries. Usage on the main wire stays on the lead lane; sidekick costs come from delegate telemetry.Tool dispatch checks the session filter before Fusion auth, defaults
model_tieron delegate calls, and treats blocked delegate results as non-failures in Fusion counters. Permission replay on cancel/closed channels is softened (ambiguous replay can deny without channel-closed errors).Reviewed by Cursor Bugbot for commit 73816c3. Bugbot is set up for automated code reviews on this repo. Configure here.