Skip to content

trunk-merge/pr-110220/45c5d137-71d7-42ea-b845-682127efcae5 - #110277

Closed
trunk-io[bot] wants to merge 2 commits into
masterfrom
trunk-merge/pr-110220/45c5d137-71d7-42ea-b845-682127efcae5
Closed

trunk-io[bot] wants to merge 2 commits into
masterfrom
trunk-merge/pr-110220/45c5d137-71d7-42ea-b845-682127efcae5

Conversation

@trunk-io

@trunk-io trunk-io Bot commented Oct 1, 2026

Copy link
Copy Markdown
Trunk Merge Pull Request Banner

This pull request was created and is being managed by Trunk Merge.

This pull request is based on the master branch at SHA 3d99563a1be0535d4c0244363d3c8e3fa5aabf79.

See more details here.

When CI completes, this pull request will be closed automatically.

Pull Requests Being Tested

This pull request is testing the changes from pull request 110220.

robbie-c and others added 2 commits October 1, 2026 18:41
Neon 1.1 calls napi_delete_async_work inside debug_assert_eq! in its
async-work completion callback. A release build drops that call, so every
cx.task() in the replay-anonymizer addon left its async work alive. Each
one keeps two V8 global handles: its resource object and the async context
frame that was active at the call. With OpenTelemetry on, that frame holds
the step's tracing context, so the ML mirror heap grew with every
anonymized message until the pod restarted.

The release profile now builds Neon with debug assertions, so the delete
runs. A test checks that the async context of a finished call can be
collected. Only a release build of the addon can fail it, and CI builds
the addon in release mode.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

🧰 Additional context used
📚 Code guidelines (4)
.cursor/rules/rust.mdc — auto-discovered
.agents/security.md — configured
.agents/skills/writing-tests/SKILL.md — configured
.agents/skills/writing-code-comments/SKILL.md — configured

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository: PostHog/posthog/.coderabbit.yaml

Review profile: QUIET

Plan: Enterprise

Run ID: 8a6a5a92-e62d-4a0d-a5b2-874bf41db802

📥 Commits

Reviewing files that changed from the base of the PR and between 3d99563 and 3303323.

📒 Files selected for processing (2)
  • nodejs/src/ingestion/pipelines/sessionreplay/ml-mirror/native-anonymize-task.test.ts
  • rust/Cargo.toml

Included review availability: This review used your included allowance. Your plan provides up to 12 included reviews per hour; 4 remain after this review.


📝 Walkthrough

Walkthrough

The Neon release profile now enables debug assertions. A new native anonymizer test performs 20 calls in separate async-local stores, then checks that the stores are collectible after garbage collection. The test throws if the native addon cannot load in CI and skips with a warning otherwise.

Priority: ➖ Normal

Merge Risk: ⚪ Minimal · up to 33033

The release configuration enables Neon cleanup assertions, and the regression test is integrated into CI. No actionable merge-blocking risk remains beyond normal build and test checks.

Security Architecture Review

Security architecture risk: 🔵 Low · up to 33033

The change is intended to improve cleanup after anonymization without adding access or changing data contracts. Risk is low, but cleanup and failure behavior during interruption and shutdown are not fully verified.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The directly confirmed production exposure is the existing native anonymizer processing replay payloads in Node.js workers. The override applies to Neon in workspace release builds, rather than one tenant. No newly reachable service or data store is established; complete deployment exposure is unavailable.

Trust Boundaries and Controls

  • observed — Replay payloads already cross from JavaScript into native asynchronous processing. Existing task-body panic handling converts anonymization failures into results, while the caller drops rejected calls and handles failed results without passing them as successful anonymized output. These controls are unchanged and do not prove containment of failures inside Neon itself.

Resilience and Maintainability Implications

  • observed — The existing server initializes allow lists and runs an anonymizer startup self-test before proceeding. Runtime rejection and unclassified failure paths log and count failures before dropping messages, providing containment and operational signals without a new assertion-specific recovery mechanism.
🚥 Pre-merge checks | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Description check ⚠️ Warning The description only contains Trunk Merge metadata and does not explain the problem, changes, testing, test rationale, release status, notifications, docs impact, or agent context required by the repo… Replace or supplement the Trunk Merge metadata with a completed repository-template description. Describe the Neon release-build issue, the native anonymizer test, how the changes were tested, the test rationale, release-status selection, d…
Full details: Description check

Explanation

The description only contains Trunk Merge metadata and does not explain the problem, changes, testing, test rationale, release status, notifications, docs impact, or agent context required by the repository template.

Resolution

Replace or supplement the Trunk Merge metadata with a completed repository-template description. Describe the Neon release-build issue, the native anonymizer test, how the changes were tested, the test rationale, release-status selection, docs and changelog decisions, and the required agent context.

  • Fix all pre-merge checks with AI
✨ Finishing Touches
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Comment @coderabbitai help to get the list of available commands.

@trunk-io trunk-io Bot closed this Oct 1, 2026
@trunk-io
trunk-io Bot deleted the trunk-merge/pr-110220/45c5d137-71d7-42ea-b845-682127efcae5 branch October 1, 2026 19:08
@trunk-io

trunk-io Bot commented Oct 1, 2026 •

Copy link
Copy Markdown
Author

Static Badge   Static Badge   Static Badge

View Full Report ↗︎ ⋅ Docs

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant