feat(security): define tool execution budgets#901
Closed
luoye520ww wants to merge 1 commit into
Closed
Conversation
Collaborator
Author
|
Superseded by consolidated tool/process lifecycle PR #946, which passed Typecheck, Linux, macOS, and Windows packaged checks. Closing this duplicate to keep the review surface focused. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
Tool processes currently use unrelated timeout and output limits. There is no shared contract for process count, memory/CPU budgets, or network policy, so future runtime integrations could silently inherit unsafe defaults.
Root cause
Resource limits are defined per provider or tool family rather than at the managed-tool boundary. The existing
ToolOutputLimitsConfigonly covers output formatting and is not a process execution policy.Scope
This PR defines the
ToolExecutionBudgetcontract only. It does not change shell, MCP, LSP, extension-host, or subagent execution yet.Changes
none,approved, andfullnetwork policies withnoneas the default.kun/contracts.Safety
none.Typecheck
Both passed.
Tests
npm.cmd --prefix kun test -- tests/tool-execution-budget.test.tsResult: 1 file, 3 tests passed.
Actual validation
npm.cmd run lintandnpm.cmd run buildpassed. The targeted tests parse the real contract and verify safe defaults and rejection boundaries.Review performed
PR size
Follow-ups
Runtime enforcement is split into process registry, shell/LSP/extension-host integration, and network approval PRs.