Skip to content

fix(pixel-settings): reject active token limits exceeding provider capacity - #5696

Merged
gabsprogrammer merged 1 commit into
Osmantic:public-betafrom
vaibhavsrv:fix/pixel-settings-active-output-bounds
Sep 19, 2026
Merged

gabsprogrammer merged 1 commit into
Osmantic:public-betafrom
vaibhavsrv:fix/pixel-settings-active-output-bounds

Conversation

@vaibhavsrv

Copy link
Copy Markdown
Contributor

Why this matters

In ods/bin/pixel_settings/contract.py, _capabilities(value) validates runtime capability evidence reported by providers and host environments before computing preferences or accepting settings readbacks. While providerMaxOutputTokens > providerContextTokens and activeMaxOutputTokens > activeContextTokens are explicitly rejected, the contract omitted checks bounding active token limits against provider capacity: activeContextTokens > providerContextTokens and activeMaxOutputTokens > providerMaxOutputTokens.

When inconsistent capability documents are received where active context or active output tokens exceed provider capacities (such as corrupted state or misconfigured models), _capabilities() silently accepts the dictionary as valid. Later callers invoking preview_preferences() with empty change sets then fail with deferred preference-validation errors (context-exceeds-declared-or-observed-capacity or output-exceeds-capacity) rather than immediately diagnosing the malformed runtime capability evidence with invalid-runtime-capabilities.

This surgical fix adds upper-bound constraints ensuring that active token limits do not exceed provider capacities during runtime capability validation.

Validation

  • Baseline reproduction: Tested contract.preview_preferences({}, caps(activeContextTokens=200000)) and contract.preview_preferences({}, caps(activeMaxOutputTokens=20000)) on unpatched contract.py; baseline failed capability evidence validation assertions by yielding deferred preview rejection instead of invalid-runtime-capabilities.
  • Post-fix behavior: Both cases immediately raise SettingsError("invalid-runtime-capabilities") during _capabilities verification; all 46 contract unit tests pass cleanly.
  • Telemetry: pixel-settings suites: 46 passed. New-test syntax and diff checks pass; new regressions wired into test suite.

Overlap check

Risk / AI disclosure

AI-assisted investigation, implementation and CLI regressions. This strengthens capability validation bounds and does not change valid runtime profiles or downstream defaults. Independent human review and platform/runtime qualification remain gates. No running configuration, deployment or upstream merge changed.

Follow-up integration evidence

Composed with #5695 at b44474771 without conflicts. Production and test diffs passed together; settings and provider checks remain intact.
Backlog composition was local-only (production/test diffs, excluding workflow/Makefile wiring); it is not an upstream merge or independent human approval. Declared live-review gates remain open.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants