Skip to content

fix: retry dropped permission replies - #14360

Merged
marius-kilocode merged 2 commits into
mainfrom
analyze-subagent-spawn-permission-errors
Sep 21, 2026
Merged

marius-kilocode merged 2 commits into
mainfrom
analyze-subagent-spawn-permission-errors

Conversation

@marius-kilocode

Copy link
Copy Markdown
Collaborator

What Problem This Solves

Auto-approve and manual permission replies travel over a pooled HTTP connection to the CLI backend. When that socket is closed before the response completes, the reply fails with a transient transport error and the permission request stays pending. With auto-approve on, the agent waits indefinitely. With auto-approve off, the prompt cannot be resolved.

Why This Change Was Made

The reply path had no retry for transport failures, so a single dropped connection stranded the request. The fix retries only transient transport failures (including undici's TypeError: terminated) and never retries a decisive server error, so a missing request or a client/server mismatch still fails fast. It covers manual replies, auto-approve replies, and the pending-permission recovery list.

User Impact

  • Auto-approve no longer stalls when a reply hits a dropped connection.
  • Manual "Allow once", "Deny", and "Always" approvals recover from the same drop.
  • No behavior change for genuine server errors.

Evidence

Reproduced in isolated VS Code with the self-test harness and a TCP proxy that drops the first permission reply:

  • Before: the reply was dropped and the chat stayed blocked at "Permission required".
  • After: the same permission ID was retried 503 ms after the drop, forwarded successfully, and the command completed with exit status 0 without manual approval.

Focused checks: SDK permission tests 13 passed, extension permission recovery tests 33 passed, extension typecheck and lint passed.

This fixes the dropped-reply failure only. It does not address separate reports of "Unknown permission route" or an unclickable "Allow once".

Auto-approve and manual permission replies use a pooled HTTP connection to
the CLI backend. When that socket is closed before the response completes,
the reply fails and the permission request stays pending, so the agent waits
and the chat shows a permission prompt that cannot be resolved.

Retry only transient transport failures, and never retry a decisive server
error. Apply the retry to manual replies, auto-approve replies, and the
pending-permission recovery list.
Comment thread packages/sdk/js/src/kilocode/permission.ts Outdated
Comment thread packages/sdk/js/src/kilocode/permission.ts Outdated
Comment thread packages/kilo-vscode/tests/unit/permission-recovery.test.ts
@kilo-code-bot

kilo-code-bot Bot commented Sep 21, 2026 •

Copy link
Copy Markdown
Contributor

Code Review Summary

Status: No Issues Found | Recommendation: Merge

Files Reviewed (2 files)
  • packages/sdk/js/src/kilocode/permission.ts
  • packages/kilo-vscode/tests/unit/permission-recovery.test.ts
Previous Review Summary (commit 675ed4b)

Current summary above is authoritative. Previous snapshots are kept for context only.

Previous review (commit 675ed4b)

Status: 3 Issues Found | Recommendation: Address before merge

Overview

Severity Count
CRITICAL 0
WARNING 0
SUGGESTION 3
Issue Details (click to expand)

SUGGESTION

File Line Issue
packages/sdk/js/src/kilocode/permission.ts 14 Comment names packages/core/src/util/retry.ts as the sync source, but core lacks the exact "terminated" match and "fetch failed", so a future resync would regress this fix.
packages/sdk/js/src/kilocode/permission.ts 54 throw last is unreachable dead code; the loop always throws on its final iteration.
packages/kilo-vscode/tests/unit/permission-recovery.test.ts 376 The cancellation test would pass even if the retry loop did not stop, because reply is never re-invoked after shouldContinue returns false.
Files Reviewed (6 files)
  • .changeset/retry-permission-transport-drops.md - 0 issues
  • packages/kilo-vscode/src/commands/toggle-auto-approve.ts - 0 issues
  • packages/kilo-vscode/src/kilo-provider/handlers/permission-handler.ts - 0 issues
  • packages/kilo-vscode/tests/unit/permission-recovery.test.ts - 1 issue
  • packages/sdk/js/src/kilocode/permission.ts - 2 issues
  • packages/sdk/js/test/kilocode/permission.test.ts - 0 issues

No new memory leaks or unbounded resources were introduced: retry's backoff timer is awaited and reclaimed, replyOnce always settles (errors are caught, cancellation is intentionally suppressed), and void fetchAndSendPendingPermissions(ctx) cannot reject because its body is wrapped in try/catch. The shared deadline in respondToPermission is still respected because each retry recomputes AbortSignal.timeout(budget()) against the same absolute deadline.

Fix these issues in Kilo Cloud


Reviewed by deepseek-v4.1-flash · Input: 0 · Output: 0 · Cached: 0

Review guidance: REVIEW.md from base branch main

Point the transient-classifier comment at the VS Code mirror it matches,
drop the unreachable trailing throw, and assert the cancellation path stops
the retry loop.
Comment thread packages/sdk/js/src/kilocode/permission.ts
@marius-kilocode
marius-kilocode merged commit c9e93d1 into main Sep 21, 2026
34 checks passed
@marius-kilocode
marius-kilocode deleted the analyze-subagent-spawn-permission-errors branch September 21, 2026 14:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants