Skip to content

fix(server): retry expired T3 Connect link proofs - #12078

Closed
Gigioxx wants to merge 1 commit into
pingdotgg:mainfrom
Gigioxx:t3code/fix-12061-expired-link-proof
Closed

Gigioxx wants to merge 1 commit into
pingdotgg:mainfrom
Gigioxx:t3code/fix-12061-expired-link-proof

Conversation

@Gigioxx

@Gigioxx Gigioxx commented Sep 16, 2026 •

Copy link
Copy Markdown
Contributor

Problem

When a headless server starts before its clock synchronizes, the relay rejects its environment link proof with RelayEnvironmentLinkProofExpiredError (401). That response stopped startup reconciliation permanently, so the environment stayed unreachable over T3 Connect until a restart.

Change

Treat a schema-validated RelayEnvironmentLinkProofExpiredError 401 as retryable. Startup reconciliation reuses its existing backoff and mints a fresh proof on each attempt. Revoked credentials and unrecognized 401 responses remain permanent failures.

Scope and approval

Fixes #12061, triaged as an accepted bug by a maintainer: #12061 (comment)

Verification

Problem established before the fix: a real local server with an isolated relay fixture reproduced the startup warning and no further link attempts. The new regression test stopped after one request instead of retrying.

Checks run on the current head (rebased on main):

  • vp test run src/cloud/relayResponse.test.ts src/cloud/http.test.ts (apps/server): 62 passed, including the new expired-proof retry case and the revoked-credential non-retry assertion.
  • vp lint and vp fmt --check on the changed files: clean.
  • Server typecheck was not completed locally on this head (machine resource limits); relying on CI.

Earlier manual check (before rebase): with the isolated relay fixture, the server recovered after the first one-second backoff, requesting a new challenge and signing a new proof. Isolated Chromium loaded Settings, Connections against the recovered server.

Not checked: a live relay, an actual NTP adjustment, or Cloudflare tunnel provisioning. No UI changes.

Created with GPT-6 in Codex. Rebased and PR body updated by Claude Opus 5.5 in Claude Code.

@github-actions github-actions Bot added vouch:unvouched PR author is not yet trusted in the VOUCHED list. size:XS 0-9 changed lines (additions + deletions). labels Sep 16, 2026
@coderabbitai

coderabbitai Bot commented Sep 16, 2026 •

Copy link
Copy Markdown

Review Change StackReview Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Advanced

Run ID: ec36d0b2-8682-428a-b86e-c636c48bc668

📥 Commits

Reviewing files that changed from the base of the PR and between ccf220b and 8997836.

📒 Files selected for processing (2)
  • apps/server/src/cloud/relayResponse.test.ts
  • apps/server/src/cloud/relayResponse.ts

Included review availability: Your plan provides up to 10 included reviews per hour; 8 remain after this review.


📝 Walkthrough

Walkthrough

The relay response handler now classifies expired link-proof 401 responses as retryable internal errors. Tests confirm one retry succeeds, diagnostics remain intact, and revoked authorization remains non-retryable.

Changes

Relay proof retry handling

Layer / File(s) Summary
Expired proof classification and validation
apps/server/src/cloud/relayResponse.ts, apps/server/src/cloud/relayResponse.test.ts
Expired link-proof 401 responses map to EnvironmentHttpInternalServerError. Tests verify one retry succeeds, diagnostic text is preserved, and invalid-bearer authorization is not retried.

Priority: ➖ Normal

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Bug fix · Severity of issue fixed: Medium

Suggested reviewers: juliusmarminge

Merge Risk: ⚪ Minimal · up to 89978

Expired link proofs now retry through the existing backoff flow with a newly generated proof, while revoked and unrecognized authorization failures remain permanent.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Linked Issues check ✅ Passed The change meets the coding requirements in [#12061]. filterRelayResponse now classifies only a schema-recognized HTTP 401 RelayEnvironmentLinkProofExpiredError as `EnvironmentHttpInternalServerEr…
Out of Scope Changes check ✅ Passed The diff is limited to relay response classification and focused tests. These changes directly support the retry behavior in [#12061]. No unrelated product behavior or unrelated files are changed.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 2…
Title check ✅ Passed The title clearly and concisely describes the main change: retrying expired T3 Connect link proofs on the server.
Description check ✅ Passed The description covers the problem, change, scope approval, verification steps, observed results, limitations, and agent attribution. It also explains that revoked and unrecognized 401 responses remai…
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Comment @coderabbitai help to get the list of available commands.

@macroscopeapp

macroscopeapp Bot commented Sep 16, 2026 •

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Not approved

Macroscope's review found this PR not approvable — This patch changes production authentication-proof handling by turning one 401 response into a retryable startup reconciliation failure, causing fresh authenticated link attempts under the existing backoff. The change is narrow and tested, but its authentication implications warrant human review.

Notes:

  • Diff unchanged. Approvability was decided on eligibility alone.

You can add or adjust custom eligibility rules. Learn more.

@juliusmarminge juliusmarminge added the macroscope-review Opt PRs made by unvouched contributors in for Macroscope review. Vouched contributors auto-reviews label Oct 1, 2026 — with ChatGPT Codex Connector
@Gigioxx
Gigioxx force-pushed the t3code/fix-12061-expired-link-proof branch from 8997836 to 2818276 Compare October 1, 2026 03:26
@maria-rcks

Copy link
Copy Markdown
Collaborator

Note

Written by claude-opus-5-5 on behalf of Maria

Hi! We are cleaning up open PRs, and this one appears to have been created with an older model (gpt-6). If this change is really important, we recommend rebuilding the PR with a newer model if possible.

@maria-rcks maria-rcks closed this Oct 11, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

macroscope-review Opt PRs made by unvouched contributors in for Macroscope review. Vouched contributors auto-reviews size:XS 0-9 changed lines (additions + deletions). vouch:unvouched PR author is not yet trusted in the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Bug]: T3 Connect link is never retried after startup reconcile fails (clock skew at boot leaves relay link dead until restart)

3 participants