fix(credential-health): stop the sweep defaulting to 5 minutes - #14924
Merged
diegosouzapw merged 2 commits intoSep 29, 2026
Conversation
diegosouzapw#12138 raised the credential health sweep default to 60 minutes but left the 5-minute value behind in four places, so the sweep could still run at 5 min: - getConnIntervalMs() kept `globalIntervalMs = 300_000` as its default parameter, so any caller omitting the second argument probed connections five times more often than the operator's configured cadence. Both current call sites pass it, so this was latent rather than live. - open-sse/config/constants.ts exported CREDENTIAL_HEALTH_CHECK_INTERVAL with a 300_000 fallback and a doc comment naming 5 minutes. Nothing reads it, but ENVIRONMENT.md cites it as the source of the default. - docs/reference/ENVIRONMENT.md advertised 300000. - src/lib/copilot/systemPrompt.ts documented 300000 in its config table. The per-connection fallback now reads the same DEFAULT_SWEEP_INTERVAL_MS the global resolver uses (hoisted into the probePolicy leaf so scheduler.ts can import it without a cycle), so the two cannot drift apart again. Three tests pin the 60-minute fallback, the 0 opt-out, and the per-connection override.
6 tasks done
diegosouzapw
merged commit Sep 29, 2026
f8b3bc0
into
diegosouzapw:release/v3.8.51
11 of 16 checks passed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
#12138 raised the credential health sweep default to 60 minutes, but left the 5-minute value behind in four places. The sweep can therefore still run at 5 minutes — about 12x the intended cadence — issuing a real credential probe against every active connection.
The leftovers
getConnIntervalMs(conn, globalIntervalMs = 300_000)DEFAULT_SWEEP_INTERVAL_MSopen-sse/config/constants.tsCREDENTIAL_HEALTH_CHECK_INTERVAL300_0003_600_000docs/reference/ENVIRONMENT.md3000003600000src/lib/copilot/systemPrompt.tsconfig table3000003600000scheduler.tsheader commentThe first is the only functional one, and it is latent rather than live: both current call sites pass
globalIntervalMsexplicitly. It is exactly the trap that resurfaces the moment someone adds a third call site.Why a shared constant rather than a corrected number
DEFAULT_SWEEP_INTERVAL_MSnow lives in theprobePolicyleaf, whichscheduler.tsalready imports (so no cycle), and both the global resolver and the per-connection fallback read it. The two cannot drift again.The change inside
resolveInconclusiveProbeRecheckDelayMsis behaviour-neutral: its only caller passesgetSweepInterval(), which is always finite and positive, so that fallback branch is unreachable today.Tests
Three cases added to
tests/unit/credential-health-sweep-interval.test.ts:healthCheckInterval: 0opts the connection out entirely18/18 pass across the credential-health suites.
check:env-doc-sync,check:file-size,typecheck:core,check:open-sse-typecheckand ESLint are all clean.For operators landing here from probe traffic
If you are seeing frequent tiny completions against a connection, the sweep is the cause. Three levers, in precedence order:
0(never test this connection)0disables the sweepCREDENTIAL_HEALTH_CHECK_INTERVAL(ms, minimum 10000)A stored
intervalMinutesorhealthCheckIntervaloverrides the 60-minute default, so if you are on 5 minutes today that is almost certainly an explicit value left behind from testing #12043 / #12138 rather than the default.