Report unsupported token accounting for Cursor native RunSSE - #9429
Conversation
Co-authored-by: lpcox <15877973+lpcox@users.noreply.github.com>
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Successful RunSSE responses with unsupported compression bypass the documented terminal accounting state.
Review effort: Balanced
Findings: 1
Open (1)
What changed in this PR
Adds explicit unsupported-accounting diagnostics for Cursor native RunSSE responses in the API proxy, without estimating token usage.
Changes:
- Reports unsupported accounting when native streams lack recognized usage.
- Adds regression coverage for native streams and existing provider accounting.
- Documents telemetry interpretation and budget limitations.
| File | Description |
|---|---|
| docs/api-proxy-sidecar.md | Documents unsupported accounting and incomplete budgets. |
| containers/api-proxy/token-tracker.cursor.test.js | Tests native diagnostics and recognized usage preservation. |
| containers/api-proxy/token-tracker-http.js | Adds the accounting state and structured warning. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| if (streaming && typeof reqPath === 'string' | ||
| && reqPath.split('?')[0] === '/agent.v1.AgentService/RunSSE') { |
|
@copilot address review feedback |
Co-authored-by: lpcox <15877973+lpcox@users.noreply.github.com>
Addressed in |
|
✅ Copilot review passed with no inline comments. @copilot Add the |
Documentation PreviewDocumentation has been built for this PR. To view locally:
Built from commit 602a2d9 |
✅ Coverage Check PassedOverall Coverage
📁 Per-file Coverage Changes (2 files)
Coverage comparison generated by |
|
❌ Smoke Copilot BYOK AOAI (Entra) reports failed. AOAI BYOK (Entra) mode investigation needed...
|
|
🛡️ Smoke Copilot Network Isolation confirmed the egress allowlist is enforced. ✅
|
|
✅ Smoke Claude passed
|
|
Chroot tests passed! Smoke Chroot - All security and functionality tests succeeded.
|
|
✅ Security Guard completed successfully! Security review complete — PR #9429 adds Cursor native RunSSE token accounting reporting with no security weakening. Changes are audit/logging only; no firewall, ACL, capability, or validation changes. No security vulnerabilities detected.
|
|
❌ Smoke Gemini reports failed. Facets need polishing...
|
|
🌑 The shadows whisper... Smoke Codex failed. The oracle requires further meditation...
|
|
🔌 Smoke Services — All services reachable! ✅
|
|
Smoke Cloud Hypervisor completed. Cloud Hypervisor + Copilot passed.
|
|
📰 VERDICT: Smoke Copilot has concluded. All systems operational. This is a developing story. 🎤
|
|
✅ Build Test Suite completed successfully!
|
|
📡 Smoke OTel Tracing completed. All tracing scenarios validated. ✅
|
|
❌ Smoke Copilot BYOK AOAI (api-key) reports failed. AOAI BYOK (api-key) mode investigation needed...
|
|
✅ Smoke Copilot BYOK completed. Copilot BYOK mode operational. 🔓
|
Smoke Test: Claude Engine Validation
Overall result: PASS
|
|
Smoke Test: Copilot BYOK (Direct Mode) ✅ PASS
Status: All tests passed. Direct BYOK inference path validated.
|
Smoke Test: Cloud Hypervisor + Copilot
Note: checks 2/4 could not verify AWF allow/deny behavior because the bash sandbox itself denies curl network calls outright (no exit code, immediate permission error), independent of the firewall. No bypass attempted.
|
|
Smoke Copilot: PASS
|
|
Smoke OTEL tracing:
|
|
EGRESS_RESULT allow=pass deny=pass
|
|
Services smoke test: PASS
|
Chroot Version Comparison
Not all tests passed: Node.js differs between host and chroot, so
|
🏗️ Build Test Suite Results
Overall: 6/8 ecosystems passed — FAIL Failures
All 8 repositories cloned successfully. The
|

Cursor inference succeeds through the custom OpenAI upstream, but native RunSSE responses without recognized usage leave telemetry empty. Authoritative native usage and executed-model metadata remain unverified; missing counts must not imply zero cost or an emitter failure.
Explicit accounting state
TRACK_END result=unsupported_accountingand a structured warning for 2xx RunSSE streams without recognized usage.Accounting boundaries
Regression coverage