Adopt production-safe runtime defaults and forwarder retry limits.

Lower CLI/WebCRT/audit caps, log startup capacity warnings, and bound oclaw requeues so reconnect storms cannot thrash memory.

Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
oliver 2026-08-02 18:08:28 +08:00
parent d56020d84c
commit fa577aa3bd
22 changed files with 238 additions and 69 deletions

View file

@ -17,7 +17,7 @@ _in_use_lock = threading.Lock()
def _ensure_sem() -> threading.BoundedSemaphore:
global _sem, _limit
with _lock:
want = max(1, int(getattr(settings, "cli_max_concurrent", 20) or 20))
want = max(1, int(getattr(settings, "cli_max_concurrent", 12) or 12))
if _sem is None or want != _limit:
_sem = threading.BoundedSemaphore(want)
_limit = want
@ -32,10 +32,20 @@ def cli_budget_status() -> dict[str, int]:
return {"limit": _limit, "in_use": used, "available": max(0, _limit - used)}
def clamp_cli_workers(requested: int, *, hard_cap: int) -> int:
def clamp_cli_workers(requested: int, *, hard_cap: int | None = None) -> int:
"""Clamp a feature concurrency against the global CLI budget and a hard cap."""
budget = max(1, int(getattr(settings, "cli_max_concurrent", 20) or 20))
return max(1, min(int(hard_cap), int(requested or 1), budget))
budget = max(1, int(getattr(settings, "cli_max_concurrent", 12) or 12))
feature_cap = int(
hard_cap
if hard_cap is not None
else (getattr(settings, "cli_feature_hard_cap", 16) or 16)
)
feature_cap = max(1, feature_cap)
return max(1, min(int(feature_cap), int(requested or 1), budget))
def feature_hard_cap() -> int:
return max(1, int(getattr(settings, "cli_feature_hard_cap", 16) or 16))
@contextmanager