Conversation
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
* Align integration creation UI with admin permissions * Show disabled integration actions for members
…UsefulSoftwareCo#2056) Scope discovery capped the request at 100 scopes. A resource that advertises more (PostHog lists 150) got a token missing the scopes its MCP server needs, so every new connection synced zero tools. Bound the request by scope-string length (8 KiB) instead. A credential-only health check then reported healthy over the sync-stamped rejection, hiding the failure. Sync-supplied verdicts now carry the tool_sync_failed reason and are served until a sync succeeds. Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
* Accept Slack bot and user OAuth grants * Preserve standard bearer response metadata
* Prefer OAuth when adding connections * Verify authentication method selection stays usable * Check client availability before preferring OAuth
…eCo#2072) Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
…Co#2071) * e2e: reproduce health-probe churn on the integrations list Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> * Probe connection health through a per-connection atom Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> * e2e: bound the churn scenario to its own connections Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> --------- Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
…#2081) Co-authored-by: Cursor <cursoragent@cursor.com>
…#2110) (UsefulSoftwareCo#2115) * Revert "Test cloud admin verification and ordinary access (UsefulSoftwareCo#2110)" This reverts commit fec546e. * Revert "Require MFA to unlock cloud administration (UsefulSoftwareCo#2109)" This reverts commit d0ca1b6.
…2120) * Test organization settings MFA and ordinary access * Verify organization settings in seat billing fixture
Brings in the 22 upstream commits, including background rebuilds for TTL-expired catalogs and policy-scoped toolkit tool reads (UsefulSoftwareCo#2061). Conflicts in packages/core/sdk/src/executor.ts: - stampSyncedWithHealth: keep clearing tools_sync_started_at and take the upstream plugin-verdict last_health shape. - syncStaleConnectionTools: take the upstream urgent/deferred split and re-apply the unfinished-attempt backoff check inside it. Claude-Session: https://claude.ai/code/session_01VMqJkxznzTQaFVHHcttxpJ
crypto.subtle.importKey needs a BufferSource over an ArrayBuffer; the decoded PEM was typed as Uint8Array<ArrayBufferLike>, which failed the sdk typecheck. Both code paths already allocate a fresh ArrayBuffer. Claude-Session: https://claude.ai/code/session_01VMqJkxznzTQaFVHHcttxpJ
A tools read could start a rebuild for every stale connection at once, up to ten in parallel, and overlapping reads stacked more. In a Durable Object session with several large OpenAPI catalogs this ran the instance out of memory, the session reset, and the unfinished-attempt backoff then kept those catalogs from ever building. - Background rebuilds take a permit from one executor-wide semaphore, sized by the new toolsSyncConcurrency option (default unchanged). The permit is taken inside the single-flight run, so a later read joins a queued rebuild instead of queueing a copy. - A start stamp from a rebuild this executor is still running is joined, not reported as a dead attempt. - A retry of an attempt that never finished runs after the other stale catalogs, so one catalog that kills its instance cannot block the rest. - Urgent rebuilds are started before deferred ones so the read's grace wait is spent on the catalogs it waits for. - host-cloudflare runs rebuilds one at a time. Claude-Session: https://claude.ai/code/session_01VMqJkxznzTQaFVHHcttxpJ
Author
|
Superseded by #7: same code (identical tree at the bounded-rebuild commit), landed as a rebase of our patch stack onto upstream main instead of a merge, plus rebuild and Jev logging. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What users see
Before this change, tool search on this host failed with "Execution lost: the session was reset" whenever many connections had stale catalogs at once, for example several large OpenAPI specs. After the crash, the unfinished-attempt backoff skipped those connections, so their catalogs never got built: a connected integration listed zero tools. With this change, search answers from the stored catalogs, and stale catalogs rebuild one at a time in the background until they all converge.
What changed
upstream/mainintoskyward(22 commits, one merge commit, no rebase). This includes Scope toolkit tool reads and stop gating reads on TTL-expired catalogs UsefulSoftwareCo/executor#2061: reads no longer wait on TTL-expired catalogs, and connection/integration lists do not wait on syncs. Two conflict hunks inpackages/core/sdk/src/executor.tswere resolved by keeping both sides:stampSyncedWithHealthkeeps ourtools_sync_started_at: nulland takes upstream's newlast_healthshape.syncStaleConnectionToolstakes upstream's urgent/deferred structure, with our crash-loop breaker re-applied inside its loop.c74b3a5ce). Scope toolkit tool reads and stop gating reads on TTL-expired catalogs UsefulSoftwareCo/executor#2061 alone does not fix this crash: OpenAPI catalogs have no TTL, so a stale-marked one takes the urgent path and still rebuilds 10 at a time inside the session Durable Object.ExecutorConfig.toolsSyncConcurrency, an executor-wide semaphore around background rebuilds. The SDK default stays 10; host-cloudflare sets 1.github-app.ts(Uint8Array<ArrayBuffer>). The sdk typecheck already failed without it.No D1 schema changes.
Testing
connections.test.ts: with 5 stale connections, a concurrency of 1 and two overlapping reads, both reads return from the stored rows, at most one rebuild runs at a time, and each catalog rebuilds exactly once. A connection whose earlier attempt died rebuilds after the healthy one. Both tests fail with the fix removed.bun run typecheck: 44 of 45 packages pass.@executor-js/desktopfails the same way onskyward(two vite copies).format:checkfails on the same 6 files as onskyward, none of them touched here.bun run buildpasses, includingassert-shell-asset.Risks