Conversation
0fa7b23 to
78290b6
Compare
|
Thanks for sticking with this — the exact-model routing lease design here (dedicated |
9cc0579 to
de9c762
Compare
…ng lease scoping Co-authored-by: diegosouzapw <8016841+diegosouzapw@users.noreply.github.com>
…coping quotaCache.ts kept three private helpers (resolveAntigravityExactQuota, isUsableQuota, isAntigravityQuotaKeyForFamily) plus their normalizer and two imports that no code path reaches since the lease/routing modules took over, and getQuotaScopeLabelForProvider's parameters became unused once it started answering "model" unconditionally. Removed the dead code, marked the kept signature's parameters and pruned the now-stale eslint suppression entry, clearing the five no-unused-vars errors this PR introduced. Co-authored-by: diegosouzapw <8016841+diegosouzapw@users.noreply.github.com>
ccd1e92 to
bceb341
Compare
|
Closing this one — not because the diagnosis was wrong, but because both halves of it were settled on the release branch while this PR waited. Exact-model scoping already shipped. Your repro file The quota axis went the other way. The tip solves family-vs-model quota through There is also a live signal that the branch is mid-redesign: after your rebase, What we are keeping. Thanks for four iterations on this, @Ardem2025. The lease idea is the part nobody else had. |
…ifecycle (re-land of #10011) (#13929) * feat(sse): reserve the Antigravity account for the request's stream lifecycle Re-land of the account-lease half of #10011 on the current release branch. Its exact-model-scoping half had already shipped in #8050 and its quota half lost to the tip's aggregate-family design (selectAntigravityQuotaWindowNames / antigravityQuotaFamily.ts); none of that is reintroduced here. The lease is a concurrency reservation only and never reads or writes quota state. The Antigravity account selected for a request is reserved for the whole streaming lifecycle of that request, so a concurrent retry — or the credential handoff inside getProviderCredentialsWithQuotaPreflight — cannot re-pick an account already committed to an in-flight upstream stream. The reservation is scoped to (connection, callable upstream model) rather than the whole account, so one account can still serve two different models at once; catalog ids that resolve to the same upstream id (the gemini-3.7-flash tiers, all gemini-3.7-flash-tiered) share one lease. When every eligible account is leased for that model the request returns a structured 503 antigravity_pool_busy with a bounded Retry-After instead of piling onto a busy account. Opt-in behind ANTIGRAVITY_ACCOUNT_LEASE_ENABLED (runtime, default false). With the flag off no reservation is taken, credentials carry no routing descriptor, every release/hold is a no-op on an undefined lease id, and account selection and dispatch behave exactly as before. #10011's original test suite asserted family semantics for a lease that was exact-model scoped and failed deterministically on its own head; the model ids it used (gemini-3.5-flash / gemini-3-flash-agent) no longer exist in the catalog. The contradiction is resolved in favour of one coherent semantic — exact callable upstream model — and the tests assert it against the alias tables as they are on this branch. Co-authored-by: Ardem2025 <openclaw-auto@example.invalid> * fix(sse): widen the Antigravity lease reservation result so auth.ts narrows it The discriminated-union form of reserveAntigravityLeaseForSelection's return type did not narrow under tsconfig.typecheck-api.json, so reading `reserved.lease` after the `reserved.busy` early return raised TS2339 in the API Route Typecheck gate. A single optional-property shape carries the same information and type-checks everywhere. Co-authored-by: Ardem2025 <openclaw-auto@example.invalid> --------- Co-authored-by: Ardem2025 <openclaw-auto@example.invalid>
…ifecycle (re-land of diegosouzapw#10011) (diegosouzapw#13929) * feat(sse): reserve the Antigravity account for the request's stream lifecycle Re-land of the account-lease half of diegosouzapw#10011 on the current release branch. Its exact-model-scoping half had already shipped in diegosouzapw#8050 and its quota half lost to the tip's aggregate-family design (selectAntigravityQuotaWindowNames / antigravityQuotaFamily.ts); none of that is reintroduced here. The lease is a concurrency reservation only and never reads or writes quota state. The Antigravity account selected for a request is reserved for the whole streaming lifecycle of that request, so a concurrent retry — or the credential handoff inside getProviderCredentialsWithQuotaPreflight — cannot re-pick an account already committed to an in-flight upstream stream. The reservation is scoped to (connection, callable upstream model) rather than the whole account, so one account can still serve two different models at once; catalog ids that resolve to the same upstream id (the gemini-3.7-flash tiers, all gemini-3.7-flash-tiered) share one lease. When every eligible account is leased for that model the request returns a structured 503 antigravity_pool_busy with a bounded Retry-After instead of piling onto a busy account. Opt-in behind ANTIGRAVITY_ACCOUNT_LEASE_ENABLED (runtime, default false). With the flag off no reservation is taken, credentials carry no routing descriptor, every release/hold is a no-op on an undefined lease id, and account selection and dispatch behave exactly as before. diegosouzapw#10011's original test suite asserted family semantics for a lease that was exact-model scoped and failed deterministically on its own head; the model ids it used (gemini-3.5-flash / gemini-3-flash-agent) no longer exist in the catalog. The contradiction is resolved in favour of one coherent semantic — exact callable upstream model — and the tests assert it against the alias tables as they are on this branch. Co-authored-by: Ardem2025 <openclaw-auto@example.invalid> * fix(sse): widen the Antigravity lease reservation result so auth.ts narrows it The discriminated-union form of reserveAntigravityLeaseForSelection's return type did not narrow under tsconfig.typecheck-api.json, so reading `reserved.lease` after the `reserved.busy` early return raised TS2339 in the API Route Typecheck gate. A single optional-property shape carries the same information and type-checks everywhere. Co-authored-by: Ardem2025 <openclaw-auto@example.invalid> --------- Co-authored-by: Ardem2025 <openclaw-auto@example.invalid>
Summary
This is the routing/lease part of the production-tested patch stack. Image-generation account rotation is intentionally separate in #9908.
Related Issues
Validation
npm run lint(CI; focused files were exercised locally)Focused test result: 14/14 passed on Node 22.22.3 against the active
release/v3.8.50tree.Tests Added Or Updated
tests/unit/antigravity-quota-routing-exact-model.test.tstests/unit/antigravity-routing-state.test.tstests/unit/antigravity-lease-lifecycle.test.tstests/unit/antigravity-pool-busy.test.tstests/unit/auth-antigravity-account-retry-v2.test.tstests/unit/repro-antigravity-404-family-cooldown-hijack.test.tsCoverage Notes
The focused tests cover exact-model quota keys, routing reservations, pool-busy behavior, lease release after stream completion, credential handoff, and 404/429 sibling-model isolation.
Reviewer Notes
auth.tswas reconciled by retaining the release branch's exact-lock behavior while removing the obsolete family-only cooldown guard.