Repository navigation
feat(retry): rotate credentials on credential-scoped failures - #8
Merged
yelixir-dev merged 2 commits intoOct 3, 2026
Merged
Conversation
…lures Upstream reports an empty balance as HTTP 400 whose body says 'You have insufficient credits to make this request' instead of the 402 that recordFailure and isFatalCredFailure expect. A bare 400 stays provider-scoped and released without marking, but the same status with an insufficient-credits body is now classified as credential-scoped billing failure, so the key cools down like a 402 instead of staying ready and failing every request. Failure plumbing carries the upstream error text from HTTP responses, stream error events, and caught CommandCodeHttpErrors in both the CommandCode and provider clients. Cover with router and client regression cases for the billing cooldown and the untouched plain-400 path.
A8Cl233395
force-pushed
the
feat/retry-credential-rotation
branch
from
October 2, 2026 17:38
8589cd5 to
5f5141a
Compare
Credential-scoped failures (401/402/403, and 400 responses whose body reports insufficient credits) now fall over to the next key instead of failing the request, while bare client errors such as a plain 400 still fail fast. The retry predicate is unified across the alpha and provider tunnels: the provider path gains insufficient-credit 400 rotation and the alpha path gains 403 rotation.
Owner
|
Thanks — rotating to another key on insufficient-credits 400s and 403s, and sharing one retry predicate between the Alpha and Provider paths, closes the gap #7 left. Verified before merging: #7 + #8 merged cleanly onto current Merging as-is. We'll follow up on |
yelixir-dev
added a commit
that referenced
this pull request
Oct 3, 2026
Release PR #7 and PR #8: a 400 "insufficient credits" response is now credential-scoped (cooldown that survives billing refreshes, matching the CLI's own check), and insufficient-credits 400s and 403s rotate the request to another key on both the Alpha and Provider paths. Plain 400/404/422 still fail fast. Update the README routing paragraph (en/ko/zh), KNOW_HOW, ARCHITECTURE and both deployment guides, and record the release in PROCESS_LOG.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
Credential-scoped failures (401/402/403, and the 400 insufficient-credits responses classified by #<PR #1 编号>) cool the key down but the request still failed on the first attempt:
shouldRetry(400)wasfalse, so the proxy never rotated to a healthy key even when one was available. The two tunnels were also inconsistent — the provider tunnel retried 403, the alpha tunnel did not.Changes
shouldRetryStatus(statusCode, errorMessage)shared by both tunnels (removes the duplicated local copy inprovider.ts).NoAvailableCommandCodeCredentialError.Tests
insufficient_creditscooldown, the successful key stays clean).How tested
vitest run— 299/303 passing; the 4 failures are pre-existing platform-dependent tests (POSIX permission bits,launchctl), unrelated to this change.