Skip to content

feat(agent-computer): report bounded per-Bot profile bytes - #730

Open
yxflc11 wants to merge 1 commit into
CopilotKit:mainfrom
yxflc11:codex/bounded-profile-usage
Open

yxflc11 wants to merge 1 commit into
CopilotKit:mainfrom
yxflc11:codex/bounded-profile-usage

Conversation

@yxflc11

@yxflc11 yxflc11 commented Oct 3, 2026

Copy link
Copy Markdown

Problem and change

A client can stop/reset one Bot's profile but cannot measure it without mounting the computer's private volume. Add token-protected GET /computers/profile-usage, returning only {profileBytes: number | null} for the existing validated Bot identity. It never starts Chromium, creates a session/profile, reads file contents, or grants deletion authority.

The Linux implementation counts regular-file logical bytes through open directory descriptors. It skips symbolic links without following their targets (including Chromium singleton links), uses O_NOFOLLOW when opening every child directory, and refuses hardlinks, special files, changed directories, cross-device traversal and unsafe totals. It permits one traversal per process, caps entries at 10,000 and depth at 16, and checks a 2-second cooperative deadline around filesystem operations. A kernel-blocked filesystem call cannot be forcibly interrupted. Missing profiles return 0; refused/incomplete measurements and unsupported platforms return null. No profile paths or partial totals are returned.

The route is separate from unauthenticated /health, rejects query parameters and non-GET methods, and uses no new dependencies. agent-computer/PROFILE_USAGE.md documents the exact scope, including Linux-only descriptor traversal and the lack of an atomic live-filesystem snapshot.

Verification

  • Actual Linux HTTP dispatcher, profile usage, Bot identity and authentication tests: 46 passed, 1 unsupported-platform case skipped, using Bun 1.4.2 in the existing isolated browser image with no network and disposable profiles.
  • macOS Bun 1.3.14: the unsupported-platform case passed; 4 Linux traversal cases skipped as intended.
  • HTTP coverage verifies authentication, invalid Bot/path rejection, method restrictions, single-Bot byte count and no browser startup.
  • No personal profile, login, model or external browser request was used.

Reviewed against upstream commit cb5dc32a44517622c6db4e527e61d3abb389b43c.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant