fix: decode SSE incrementally without limiting event size - #3687
Conversation
| assert decoder._data == ["partial"] | ||
| task.cancel() | ||
| with pytest.raises(asyncio.CancelledError): | ||
| await task |
HAYDEN-OAI
left a comment
There was a problem hiding this comment.
Reviewed the incremental SSE framing and decoding paths, including newline and chunk boundaries, fragmented UTF-8, event-state handling, large-payload compatibility, cancellation, and synchronous/asynchronous parity. No substantive correctness, compatibility, reliability, or security issues found.
jbeckwith-oai
left a comment
There was a problem hiding this comment.
Independent two-pass review confirms the incremental SSE decoder preserves unlimited line/event sizes, fragmented UTF-8 and CR/LF framing, multiline data, existing completion semantics, sync/async compatibility, cancellation, and response cleanup without unnecessary full-frame retention. Realistic >64 MiB regressions and substantive CI/CodeQL pass. Automated no-effect reports on awaited tasks are false positives; no actionable findings.
Automated Release PR --- ## [3.4.0](openai/openai-python@v3.3.1...v3.4.0) (2026-08-25) ### Features * **api:** Add obfuscation field to ChatCompletionChunk ([openai#3690](openai#3690)) ([c7d8e1d](openai@c7d8e1d)) * **api:** add project residency configuration and cost quantity units ([openai#3726](openai#3726)) ([bc4f8ef](openai@bc4f8ef)) ### Bug Fixes * **api:** encode Realtime call offers and session configuration ([openai#3736](openai#3736)) ([555ac48](openai@555ac48)) * apply consistent origin checks to WebSocket redirects ([openai#3693](openai#3693)) ([1b324d0](openai@1b324d0)) * **azure:** encode deployment names consistently ([openai#3683](openai#3683)) ([689538d](openai@689538d)) * **azure:** keep provider validation errors value-free ([openai#3691](openai#3691)) ([72529c0](openai@72529c0)) * **azure:** resolve one authentication mode ([openai#3689](openai#3689)) ([e3d0681](openai@e3d0681)) * compute custom-code summaries from trusted workflow code ([openai#3692](openai#3692)) ([2b5868d](openai@2b5868d)) * create upload example fixtures in private directories ([openai#3686](openai#3686)) ([f36e6f7](openai@f36e6f7)) * decode SSE incrementally without limiting event size ([openai#3687](openai#3687)) ([2598d53](openai@2598d53)) * keep Python SDK diagnostics metadata-only ([openai#3685](openai#3685)) ([600aa8d](openai@600aa8d)) * Preserve Azure authentication boundaries across transports ([openai#3684](openai#3684)) ([06ef57c](openai@06ef57c)) * preserve the configured TLS hostname ([openai#3694](openai#3694)) ([aa5fbc4](openai@aa5fbc4)) * preserve WebSocket send queue byte accounting during flush ([openai#3688](openai#3688)) ([96f966d](openai@96f966d)) ### Chores * **api:** Clarify image background docs and preview support ([openai#3703](openai#3703)) ([bedb9a7](openai@bedb9a7)) * **api:** document supported image generation models ([openai#3695](openai#3695)) ([8edd9ae](openai@8edd9ae)) * **api:** move chat validation tests out of generated code ([openai#3698](openai#3698)) ([9d3ba20](openai@9d3ba20)) * **api:** move webhook tests out of generated code ([openai#3700](openai#3700)) ([04ecb3c](openai@04ecb3c)) * **api:** remove redundant generated formatting ([openai#3696](openai#3696)) ([5ac1e03](openai@5ac1e03)) * **api:** remove redundant generated test edits ([openai#3697](openai#3697)) ([351ef84](openai@351ef84)) * **api:** Update SDK generation metadata only ([openai#3716](openai#3716)) ([e43b422](openai@e43b422)) * set a ceiling for Python SDK customization ([openai#3714](openai#3714)) ([04d5d79](openai@04d5d79)) ### Documentation * **api:** restore generated ChatKit API index ([openai#3705](openai#3705)) ([4534106](openai@4534106)) * standardize Python SDK vulnerability disclosure policy ([openai#3642](openai#3642)) ([1fc0a21](openai@1fc0a21)) ### Refactors * **api:** isolate audio response format selection ([openai#3701](openai#3701)) ([ece4324](openai@ece4324)) * **api:** isolate vector-store polling helpers ([openai#3713](openai#3713)) ([a002ef3](openai@a002ef3)) * **api:** move file processing polling into SDK-owned helpers ([openai#3712](openai#3712)) ([5f20c51](openai@5f20c51)) * **api:** share embedding response decoding ([openai#3699](openai#3699)) ([50de9af](openai@50de9af)) * **api:** share webhook signature verification ([openai#3704](openai#3704)) ([e14ac34](openai@e14ac34)) --- This PR was generated with [Release Please](https://github.com/googleapis/release-please). See [documentation](https://github.com/googleapis/release-please#release-please). Co-authored-by: openai-sdks[bot] <284451331+openai-sdks[bot]@users.noreply.github.com>
Summary
[DONE]drain changes.This removes quadratic prefix copying and unnecessary whole-frame retention. It does not impose a memory bound on arbitrarily large data events or unfinished lines.
Validation
git diff --checkpassed.d3667578e1a4e8da9d1962bfd403d98f4a0f945c; its exhaustive short-input CR/LF fragmentation matrix also passed.Independent PR against public main. Please confirm this handwritten shared-runtime patch is preserved in the next Castiron Python candidate; no schema or generation-metadata change is needed.