Skip to content

fix(graphql-costing): account for aliased expensive mutations — enforce query-cost limits against resolver multiplication - #774

Closed
unohee wants to merge 13 commits into
mainfrom
swarm/AGT-3473-fix-graphql-costing-account-for-aliased-
Closed

unohee wants to merge 13 commits into
mainfrom
swarm/AGT-3473-fix-graphql-costing-account-for-aliased-

Conversation

@unohee

@unohee unohee commented Sep 27, 2026

Copy link
Copy Markdown
Collaborator

Summary

Published because this run stopped and needs a human: autonomous execution failed 4 times

It has not been reviewed and is very likely incomplete — this PR is a draft on purpose. It exists so the work is reviewable instead of sitting on a branch that was never pushed.

Change shape

429 file(s): 211 source · 185 test · 9 docs · 24 other

Base freshness

Branch base is 175 commit(s) behind main at publication.

⚠ Conflicts with main in: CHANGELOG.md, package-lock.json, package.json, src/automation/runnerExecution.ts, src/issues/graphql/costAnalysis.ts, src/issues/graphql/server.test.ts
GitHub runs no pull_request workflows on a PR it cannot merge, so any green checks here are not the verification gate. Opened as a draft; rebase before review.

⚠️ File overlap with in-flight work

This branch changes files that other open PRs / active branches also touch. Coordinate before merging to avoid divergent parallel edits (INT-2388 #3):

Linear

Closes AGT-3473


🤖 Generated with OpenSwarm

unohee added a commit that referenced this pull request Sep 28, 2026
…d CLI/provider validation (#788)

Salvages the boundary work from draft PRs #764, #774 and #778 onto current main.

From #764:
- support/outboundUrl: resolvePublicHttpUrl returns the validated addresses,
  createPinnedPublicLookup answers the connect hook from that same set (no
  second DNS round-trip), and publicFetch installs a per-request pinned
  dispatcher instead of a shared unpinned agent.
- issues/graphql/server: GRAPHQL_MAX_DEPTH/FIELD_COUNT/ALIAS_COUNT/COST plus
  createGraphQLCostRule, and exact-path '/graphql' matching.
- mcp/mcpClient: MAX_INPUT_SCHEMA_BYTES/PROPERTIES with countSchemaProperties.
- auth/oauthPkce: isLoopbackRemote guard on the callback server (+ re-export).
- verify/runner: buildVerifyToolchainPath replaces the inherited sandbox PATH.
- adapters/webTools: cancel the redirect body before the next hop.

From #774:
- issues/graphql/costAnalysis: registry CRUD costs (registerEntity 100,
  updateEntity/removeEntity 80, addEntityRelation/removeEntityRelation 60).
- issues/graphql/server: applyCors returns early without an Origin header.
- bulkRegisterEntities alias/fragment-multiplication tests.

From #778:
- adapters/rateLimitError: parseRetryAfterSeconds handles HTTP-date
  Retry-After; classifyLimitResponse falls back to the codex reset epoch.
- cli/mcpCommand: preset/url/command validation before persisting the registry.
- cli/prCreate: fail closed on a dirty tree or a branch with no upstream.
- adapters/webTools: refuse non-http(s) redirect destinations.

Kept main's newer clone-timeout/resource-budget code in verify/runner and its
onValidate cost plugin; dropped the already-in-main #774 files and all scratch
probe files.
@unohee

unohee commented Sep 28, 2026

Copy link
Copy Markdown
Collaborator Author

Closing: superseded — the salvageable work in this draft was rebased onto current main, verified, and re-published as a reviewed PR: absorbed into #788. Closing the stale draft instead of merging it, because it was 170-250 commits behind, carried scratch files, and (in several cases) reverted main's later hardening.

@unohee unohee closed this Sep 28, 2026
@unohee
unohee deleted the swarm/AGT-3473-fix-graphql-costing-account-for-aliased- branch September 28, 2026 07:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant