fix(resilience): restore expired-connection retry-budget probe in health sweep - #11672
Merged
diegosouzapw merged 1 commit intoAug 26, 2026
Conversation
…lth sweep diegosouzapw#11592 pinned the token-health terminal-skip boundary: an expired connection is exempt from the skip while it still has retry budget AND is not account_deactivated, so transient OAuth failures can self-heal. diegosouzapw#11608's merge-batch reintroduced a `!isGitHubAccessTokenOnlyConnection` carve-out that contradicts that policy — a GitHub connection parked at "expired" with invalid_grant and retry budget remaining was never probed again, so a transient failure could never recover. Drop the carve-out; the account_deactivated case (the real diegosouzapw#8182 wasted-probe guard) stays covered by its own test.
Contributor
Author
diegosouzapw
merged commit Aug 26, 2026
e95a255
into
diegosouzapw:release/v3.8.51
13 of 29 checks passed
muhamadgalihsaputra
pushed a commit
to niyatna/NiyatnaRoute
that referenced
this pull request
Sep 27, 2026
…lth sweep (diegosouzapw#11672) Merged via /merge-batch (2026-08-26, v3.8.51). Boarded no worktree combinado; validação única: typecheck/complexity/cognitive-complexity/file-size/changelog verdes, lint nos mesmos 228 achados pré-existentes confirmados contra o tip puro, testes focados passando. Obrigado pela contribuição.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What was broken
checkConnection()insrc/lib/tokenHealthCheck.tsstopped probing expired GitHub connections that still have retry budget. The health sweep's terminal-skip guard treated such connections as terminal, so a transient OAuth failure could never self-heal.Red evidence (before)
On
release/v3.8.51tip (and PR #11644's CI):The test (
tests/unit/token-health-no-refresh-token-expired-5326.test.ts:217, pinned by #11592) creates a GitHub access-token-only connection withtestStatus: "expired",errorCode: "invalid_grant", retry budget remaining, and assertslastHealthCheckAtgets written (i.e. the sweep probes it).Root cause
Two recent PRs contradicted each other:
account_deactivated… only genuinely dead accounts stay unprobed." Its test pins the probing behavior.!isGitHubAccessTokenOnlyConnection(conn)carve-out toisRecoverableExpiredWithRetryBudget, resurrecting the old pre-exemption behavior that test(token-health): pin the real terminal-skip boundary, not the pre-exemption one #11592 explicitly deprecated.Fix
src/lib/tokenHealthCheck.ts— remove the carve-out fromisRecoverableExpiredWithRetryBudget(lines 599–602; 6 deleted lines):const isRecoverableExpiredWithRetryBudget = conn.testStatus === "expired" && conn.lastErrorType !== "account_deactivated" && - // GitHub access-token-only connections have their own dedicated exemption - // (isRecoverableGithubCopilotNoRefresh above): ONLY the exact - // "no_refresh_token" shape self-heals. An "expired" GitHub connection for a - // different reason (e.g. invalid_grant) is genuinely terminal and must stay - // skipped, otherwise the generic retry-budget exemption below reopens #8182's - // wasted-probe fix for every "expired" GitHub connection. - !isGitHubAccessTokenOnlyConnection(conn) && getExpiredRetryCount(conn) < EXPIRED_RETRY_MAX;The
account_deactivatedcase — the actual #8182 wasted-probe guard — is still skipped and still covered by its own test (checkConnection still skips an expired GitHub connection whose account is deactivated (#8182)).Green evidence (after)
Full file:
tests/unit/token-health-no-refresh-token-expired-5326.test.ts(all 7 tests, including both halves of the boundary).Files changed
src/lib/tokenHealthCheck.ts!isGitHubAccessTokenOnlyConnectioncarve-outchangelog.d/fixes/11592-token-health-retry-budget-boundary.mdThis fixes a base-red inherited failure on
release/v3.8.51(tracked in #11449) surfacing on PR #11644's CI.