kiro: isolate delivered final answers to exact child conversation and serving identity - #403
kiro: isolate delivered final answers to exact child conversation and serving identity#403luvs01 wants to merge 10 commits into
Conversation
release: promote dev into main for v2.32.1
# Conflicts: # package.json
[WRONG BRANCH] merge dev into main for the v2.33.0 release
Promotes the dev integration line onto main. The resulting tree is byte-identical to origin/dev, including package.json at 2.34.0. The package.json conflict is resolved to dev's side, NOT to main's stale 2.33.0. Earlier promotions (lidge-jun#2553, lidge-jun#2507) kept the target's version so the release bump would land on its own "release: vX.Y.Z" commit. That is no longer legal: this very delta adds tests/release-version-line.test.ts, which fails when the in-tree version sits behind the highest release tag. With v2.34.0-preview.20260827 now published, 2.33.0 orders behind it, so a promotion carrying the stale line turns CI red on every shard that runs the suite. The consequence for the release step is that scripts/release.ts skips the bump (release.ts:568, currentVersion === version), so v2.34.0 gets tagged on this merge commit rather than on a separate release commit. The workflow creates the tag itself after publishing and validates expected-sha against the checked-out commit, so the tag still names exactly the audited tree.
[WRONG BRANCH] promote dev onto main for v2.34.0
[WRONG BRANCH] promote dev onto main for v2.35.0
[WRONG BRANCH] promote dev onto main for v2.36.0
|
✅ Deterministic PR hygiene checks passed. |
✅ READY
Hygiene✅ Deterministic PR hygiene checks passed. |
|
Important
This repository does not receive automatic reviews because it has fewer than 10 stars. ⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: ASSERTIVE Plan: Team Run ID: Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: dd0c6ffc27
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| const servingAccount = replayOAuthCredentialSnapshot?.accountId ?? codexLogAccountId(authCtx); | ||
| bindTurnTerminationScope(parsed, exactConversation |
There was a problem hiding this comment.
Rebind termination scope after OAuth account failover
With multiple Kiro OAuth accounts, a preflight 429 can switch the request to snapshot.accountId in rotateRunTurnAdapterOnPreflight429, but this scope remains bound to the account selected before that retry. A final response served by account B is therefore cached under account A; a replay served by B is sent upstream again, while a later request on A can be incorrectly locally terminated. Rebind the termination scope whenever generic OAuth failover succeeds, using the rotated snapshot's account ID.
Useful? React with 👍 / 👎.
Motivation
Description
sessionLaneIdFromRequest/ child session/thread), the admission identity,route.providerName,route.modelId, and the resolved serving account, then normalize/hash the composite before using it as the cache key viabindTurnTerminationScope.bindTurnTerminationScopeusage so no insufficiently scoped record is retained before routing and auth are known.a proxy-recorded final answer does not suppress a sibling conversationintests/server-kiro-completion-e2e.test.tsthat verifies two child sessions sharing a parent dispatch independently and that both upstream requests occur.Testing
bun test tests/server-kiro-completion-e2e.test.ts(with the repository-pinned Bun1.4.0) and the focused Kiro e2e tests passed.bun run typecheckandbun run privacy:scan, both of which succeeded.bun run test) exposed unrelated environment / Lab sandbox failures in this environment (proxy-related lab guards); focused regression tests, typecheck, and privacy scan passed and validate the fix for the reported issue.Codex Task