Repository navigation
Conversation
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (2)
Included review availability: Your plan provides up to 10 included reviews per hour; 8 remain after this review. 📝 WalkthroughWalkthroughThe relay response handler now classifies expired link-proof 401 responses as retryable internal errors. Tests confirm one retry succeeds, diagnostics remain intact, and revoked authorization remains non-retryable. ChangesRelay proof retry handling
Priority: ➖ Normal Estimated code review effort: 2 (Simple) | ~10 minutes Change: Bug fix · Severity of issue fixed: Medium Suggested reviewers: Merge Risk: ⚪ Minimal · up to Expired link proofs now retry through the existing backoff flow with a newly generated proof, while revoked and unrecognized authorization failures remain permanent. 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
ApprovabilityVerdict: Not approved Macroscope's review found this PR not approvable — This patch changes production authentication-proof handling by turning one 401 response into a retryable startup reconciliation failure, causing fresh authenticated link attempts under the existing backoff. The change is narrow and tested, but its authentication implications warrant human review. Notes:
You can add or adjust custom eligibility rules. Learn more. |
8997836 to
2818276
Compare
|
Note Written by Hi! We are cleaning up open PRs, and this one appears to have been created with an older model ( |
Problem
When a headless server starts before its clock synchronizes, the relay rejects its environment link proof with
RelayEnvironmentLinkProofExpiredError(401). That response stopped startup reconciliation permanently, so the environment stayed unreachable over T3 Connect until a restart.Change
Treat a schema-validated
RelayEnvironmentLinkProofExpiredError401 as retryable. Startup reconciliation reuses its existing backoff and mints a fresh proof on each attempt. Revoked credentials and unrecognized 401 responses remain permanent failures.Scope and approval
Fixes #12061, triaged as an accepted bug by a maintainer: #12061 (comment)
Verification
Problem established before the fix: a real local server with an isolated relay fixture reproduced the startup warning and no further link attempts. The new regression test stopped after one request instead of retrying.
Checks run on the current head (rebased on main):
vp test run src/cloud/relayResponse.test.ts src/cloud/http.test.ts(apps/server): 62 passed, including the new expired-proof retry case and the revoked-credential non-retry assertion.vp lintandvp fmt --checkon the changed files: clean.Earlier manual check (before rebase): with the isolated relay fixture, the server recovered after the first one-second backoff, requesting a new challenge and signing a new proof. Isolated Chromium loaded Settings, Connections against the recovered server.
Not checked: a live relay, an actual NTP adjustment, or Cloudflare tunnel provisioning. No UI changes.
Created with GPT-6 in Codex. Rebased and PR body updated by Claude Opus 5.5 in Claude Code.