Repository navigation
fix: preserve longest Claude upstream cooldown - #15856
Conversation
Replace embedded NUL bytes with equivalent JavaScript escape sequences. Co-Authored-By: Codex <noreply@openai.com>
Add a real-Postgres regression for preserving longer Claude cooldowns and failure reasons, with the native cooldown path as a control. Co-Authored-By: Codex <noreply@openai.com>
Keep the database cooldown deadline authoritative and only update the failure reason when the new deadline wins. Co-Authored-By: Codex <noreply@openai.com>
|
Warning Review limit reachedNext included review available in 10 minutes. View limit detailsLimit details: You’ve used all 10 included reviews currently available. You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Review configuration: ⚙️ Run configurationConfiguration used: Repository: manaflow-ai/cmux/.coderabbit.yaml Review profile: ASSERTIVE Plan: Advanced Run ID: 📒 Files selected for processing (2)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
All contributors have signed the CLA ✍️ ✅ |
|
Merge receipt for |
|
Post-merge review. Auto-merge landed this before the review ran, so the findings and their resolution are here instead of in the pre-merge thread. That ordering is my mistake, not the author's, and the follow-up below fixes what it let through. Verified independently, on this branch's merge commit
Finding, blocking, fixed forward in the follow-up: this fixed the deadline and regressed the reason.
The same class of defect predates this PR on the native side: The rule both tables need is one rule: the deadline takes the maximum, a non-transient reason outranks a transient one, and otherwise the winning deadline owns the reason. Left for the follow-up PR (all four orderings covered as tests, shared precedence helper so the taxonomy stops being a bare string in two files): I will link it here when it is open. Not dogfooded on the fleet for the structural reason: #8029 disabled Vercel branch previews while keeping |
|
Correction to my review above: I wrote that CI did not execute these dbTests here. That is wrong, and it understates the evidence behind this merge. CI does run them. What misled me is that a different job, Nothing else in the review changes. The finding about |
0e44675 test: bound remote bootstrap subprocess waits (manaflow-ai#15608) a192a14 fix(agent-chat): show ACP plans as structured step lists (manaflow-ai#15889) d7f59a3 ci: place attempt 2 like attempt 1, owned minis first (manaflow-ai#15406) d87c3be feat(agent-chat): register Cursor Agent as an ACP provider (manaflow-ai#15877) 1bd5083 fix: preserve Codex provider for workspace auto-naming (manaflow-ai#15635) 03e1245 fix(worktree-seed): budget each pattern and refuse dangling escapes (manaflow-ai#15860) 5c28fcb fix(agent-chat): stop a disposed ACP session from resurrecting its agent (manaflow-ai#15872) 11216d2 Fix Codex Agent Chat Stop interrupt request (manaflow-ai#15837) d6b8c15 ci: watch Unix cmux-tui installer changes (manaflow-ai#15874) 0fc35d6 feat(agent-chat): register goose as an ACP provider (manaflow-ai#15871) 7f27bfc cmux ssh: security hardening from the ssh audit (manaflow-ai#15768) 8599250 fix(agent-chat): launch gemini with --experimental-acp (manaflow-ai#15868) 849376a docs: classify contributor issue difficulty (manaflow-ai#15627) 2761cc9 Keep agents with live background work out of hibernation (manaflow-ai#15278) eae02a6 Cloud: rebake the devbox ladder with cmux-tui 02dac3c (manaflow-ai#15866) 7ed2f6b ci: bound open pull-request media revisions (manaflow-ai#15861) 13c417c Notify on SubagentStop in the notifications hook docs (manaflow-ai#15854) 5cfc6a6 fix: make cmux-tui installs immutable across release uploads (manaflow-ai#15859) 4eee1b1 fix: preserve longest Claude upstream cooldown (manaflow-ai#15856) 204b936 Pin Cloud panes to the daemon's terminal grid (manaflow-ai#15792) fc13b7c cmux-tui: fix the replay row scroll and stale hook fence tests breaking the full gate (manaflow-ai#15240) 87d66af Add Cloud to the menu bar extra and a main-menu Cloud menu (manaflow-ai#15822) # Conflicts: # .github/workflows/ci-failure-attribution.yml # .github/workflows/ci-macos.yml # .github/workflows/ci-owned-pool-rescue.yml # .github/workflows/ci-queue-janitor.yml # .github/workflows/ci.yml # .github/workflows/cmux-tui-artifacts.yml # .github/workflows/cmux-tui-build-package.yml # .github/workflows/cmux-tui-sdks.yml # .github/workflows/pr-media-prune.yml # .github/workflows/remote-daemon.yml
Summary
A concurrent shorter Claude provider cooldown no longer shortens a longer deadline already stored for the account. The Claude Postgres store now keeps
cooldown_untilauthoritative withGREATEST, updateslast_failure_codeonly when the new deadline wins, and bumpsupdated_aton every write.This mirrors the native counterpart:
In production, Anthropic can return a multi-hour retry-after on a 429. A concurrent
upstream_unavailableresult has a 20-second cooldown. Before this fix, that 20-second write could erase the multi-hour 429 wall, return the wrong retry-after to clients, and put the account back into rotation while it was still rate limited. The surviving failure code now remainsrate_limiteduntil a longer cooldown wins.The two embedded NUL bytes in
claudeUpstream.tsare also replaced with\\x00escape sequences. This is runtime-identical and makes the file greppable.Tests
The focused command was red before the fix at commit
1cb1a88a854:The same command is green at commit
ebe305872ab:Additional validation:
bun x tsc --noEmitpassed.bun run lint:complexitypassed with 42 findings matched to the existing baseline.bun test tests/coderouter-claude-upstream.test.tspassed, 19 tests.bun test tests/coderouter-claude-proxy.test.tspassed, 44 tests.python3 scripts/verify-local.pypassed all 15 selected checks.markAccountCooldownpath as a control.Dogfood
There is no fleet dogfood because PR #8029 disabled Vercel branch previews while keeping main deployments. An unmerged web change has no preview URL, and a fleet build would only exercise main. The real-Postgres dbTest is the evidence in its place.
Changelog
🤖 Generated with Claude Code
Summary by cubic
Fixes Claude cooldown handling so a concurrent shorter cooldown can no longer overwrite a longer deadline already stored for an account.
The Claude store now keeps
cooldown_untilauthoritative usingGREATEST, updateslast_failure_codeonly when the new deadline wins, and bumpsupdated_aton every write. This prevents a 20-second cooldown from erasing a multi-hour Anthropic 429 rate limit, which could put a rate-limited account back into rotation and return the wrong retry-after to clients. Also replaces two embedded NUL bytes inclaudeUpstream.tswith\x00escape sequences (runtime-identical, makes the file greppable).Written for commit ebe3058. Summary will update on new commits.