fix(resilience): Grok Build OAuth 403 content refusal is a per-request rejection, not a ban (#14258) - #14259
Merged
diegosouzapw merged 2 commits intoSep 29, 2026
Conversation
Owner
|
This is a solid, well-evidenced fix — the request-refusal-vs-ban distinction is exactly right and the test pins both the new branch and a regression guard so a genuine account ban still resolves to |
sprintberlin
force-pushed
the
fix/grok-403-request-refusal
branch
from
September 21, 2026 15:55
410ad96 to
100903b
Compare
Contributor
Author
|
Rebased onto the current |
sprintberlin
force-pushed
the
fix/grok-403-request-refusal
branch
from
September 21, 2026 17:12
100903b to
858f462
Compare
Contributor
Author
…t rejection, not a ban xAI's Grok Build upstream declines safety-sensitive prompts with 403 "I can't help with that request." — a refusal of THAT request, not of the credential. Because grok-cli is an OAuth provider, the 403 fell through to the generic FORBIDDEN classification and chatCore wrote the terminal banned state, disabling the whole connection permanently. Measured in production (2026-09-19): the same token answered 200 16 s before the refusal, a token refresh succeeded 3 s before it, and an in-flight call completed 200 2 s after it; the account was never banned by xAI. The single refusal took the provider out of the tier-1 combo for 16.75 h until a manual dashboard reconnect. Same defect shape and same resolution as diegosouzapw#12859/diegosouzapw#12864 (Anthropic OAuth "Request not allowed"): classify the verbatim refusal as REQUEST_REJECTED before the terminal 403 fall-through. The existing requestRejectedFailure leaf then applies the bounded cooldown ladder (5 min, 15 min, terminal only on 3 consecutive refusals) and the failing request falls through to the next combo target. Closes diegosouzapw#14258
…tap files Keeps tap.testFiles aligned with the new refusal regression suite matching the pattern established in diegosouzapw#12864.
sprintberlin
force-pushed
the
fix/grok-403-request-refusal
branch
from
September 22, 2026 07:11
858f462 to
da476e7
Compare
Contributor
Author
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
403 "I can't help with that request.") was classified asFORBIDDENand persisted as the terminalbannedconnection state. From then on every later request was answered locally with[grok-cli] All 1 connection(s) banned by upstream — please reconnect in the dashboarduntil an operator reconnected.grok-cliisauthType: "oauth", it skipped the recoverable API-key 403 short-circuit and fell through to the generic OAuthFORBIDDENdefault. The Anthropic carve-out from fix(sse): Anthropic OAuth 403 "Request not allowed" is a per-request refusal — cooldown with backoff instead of an instant ban (#12859) #12864 (Request not allowed) does not match this body.Related Issues
FORBIDDENfall-through)Validation
npx prettier --checkandnpx eslinton the changed filesrelease/v3.8.51at7a921299c5); focused checks rerun afterwardTests Added Or Updated
tests/unit/grok-request-refusal-not-a-ban.test.ts(new)tests/unit/anthropic-request-not-allowed-not-a-ban.test.ts,tests/unit/error-classifier.test.ts,tests/unit/request-rejected-streak.test.tsCoverage Notes
classifyProviderError()andresolveTerminalConnectionStatus()on the verbatim wrapped xAI body, the plain-text and JSON-wrapped variants, and a generic grok-cli 403 that must still remainFORBIDDEN.Reviewer Notes
grok-cliand this phrase: the production body isI can't help with that request.; matching it on other providers would hide genuine account-level 403s. The Anthropic helper stays provider-scoped for the same reason.REQUEST_REJECTEDinstead ofnullorFINGERPRINT_REJECTION:nullwould skip cooldown entirely and keep retrying a refusing model;FINGERPRINT_REJECTIONis a CDN/client-signature class. The existinghandleRequestRejectedFailure()leaf already implements the intended policy (5 min → 15 min → terminal only on 3 consecutive refusals, probes never escalate).3.8.50; this PR targets the active cyclerelease/v3.8.51.Release branch not green: release/v3.8.51).