Repository navigation
fix(proxies): classify refusal cause and hang, add bounded opt-in recovery pass - #14233
Merged
diegosouzapw merged 3 commits intoSep 22, 2026
Conversation
maxmad64bis
force-pushed
the
fix/proxy-health-refusal-cause-recovery
branch
from
September 20, 2026 00:54
766b5d8 to
450e2f2
Compare
4 of 5 tasks
maxmad64bis
force-pushed
the
fix/proxy-health-refusal-cause-recovery
branch
from
September 20, 2026 01:21
450e2f2 to
e4ae1ac
Compare
This was referenced Sep 20, 2026
maxmad64bis
marked this pull request as ready for review
September 20, 2026 07:46
The recovery-pass interval this PR adds is read from process.env, so the env/docs contract gate (check-env-doc-sync) requires it in .env.example and docs/reference/ENVIRONMENT.md. Co-authored-by: diegosouzapw <8016841+diegosouzapw@users.noreply.github.com>
Owner
|
Thanks @maxmad64bis — merging via the release merge-train. Validated in local merge-train (mt-train10c) on the devbox @ train tip 4d841aa1c740bbaa03868dc0a403c62099a99a42 with the 72 sibling PRs of this batch: typecheck:core, file-size, complexity, cognitive-complexity, changelog-integrity green; changed-area node:test 831/831 (0 failing) and vitest 480/482 — the two reds are |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
A destination refusing the probe was misread as a dead proxy, and refused proxies were never re-tested. This PR carries the refusal cause next to the verdict without touching proxy status, plus an opt-in recovery pass. Defaults: stalled handshakes count like frank failures, unproven 403s stay neutral, recovery off unless
PROXY_HEALTH_RECOVERY_ENABLEDis set.Related Issues
Validation
npm run lint— touched files clean locally; the full run is red on the base (inherited, non-blocking, see Reviewer Notes)Tests Added Or Updated
tests/unit/proxy-health-refusal-cause.test.ts(new, 5): 401/403/429/451 matrix over proven/unproven/absent; 403 without evidence neutral, never mutates.tests/unit/proxy-health-probe-error.test.ts(new, 3): stalled handshake vs plain local abort vs frank connection failure.tests/unit/proxy-health-recovery-plan.test.ts(new, 4): quota-refusal only, drops unreachable (even with 429 observation) and null keys; oldest-first with volume cut.tests/unit/proxy-health-recovery-pass.test.ts(updated, 4): fake probe plus real refusal memory; success lifts, failure doubles recurrence, off means zero probes.tests/unit/proxy-health-recovery-default.test.ts(new, 1): real default path, no injected probe (local 429 relay then 200, real registry/memory).tests/unit/proxy-health-decide-action-6246.test.ts(extended, 8): stalled handshake equals frank failure at/below threshold, opt-ins on/off.tsc0, ESLint clean; RED-then-GREEN (new tests failed on missing imports first; default-path RED by stash, GREEN after).Coverage Notes
src/lib/proxyHealth/decision.tscovered by cause/probe-error/decide-action suites;scheduler.tsrecovery by plan/pass/default-path suites.tscOOMs here, so evidence is the filtered run (0 errors).Reviewer Notes
probeLedgerKeyshared keyed probe type) and the refusal-cause sidecar (beside the verdict, never branched into status). Pre-PR fix: the default probe took an object instead of a key string and could never recover anyone; the default-path test locks it. Registry and planner admit only quota-refusal entries: unreachable excluded twice.e4ae1ac4; fix(api): a target refusing the egress IP is not a healthy proxy #10654/fix(proxy-health): refused probe responses reset the consecutive-failure streak #13608; normalized failures identical to sibling fix(sse): neutral 403 code for non-quota refusals #14234): unproven 403s neutral with no status write, 451 carried with no write, unset flag zero probes.release/v3.8.51fails the same 9 jobs (API Route Typecheck, Docs Gates, Fast Quality Gates, Merge integrity, ESLint, Unit fast-path 1-4/4); every file cited by the failing gates is outside this diff. Non-blocking for this PR.