Repository navigation
Make relay rate limiter fail open on missing rule and skip when unconfigured - #8773
Conversation
…e is missing The relay token route 503s every request when CMUX_RELAY_TOKEN_RATE_LIMIT_ID is unset or its Vercel firewall rule was deleted (not-found), taking every device off the relay network. These tests encode the intended behavior: no configured rule means no rate limiting, and a deleted rule fails open. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…figured enforceRelayRateLimit (used by /api/relay/token and /api/relay/preferences) treated every firewall-check outcome except success as fatal: an unset rule id env failed with rate_limit_not_configured and a deleted Vercel rule (not-found) failed as rate_limit_unavailable, both returning 503 for every authenticated request. With the Vercel rate-limit rules removed, every device's relay policy fetch failed with policyUnavailable, hosts never started their iroh endpoints, and phones could not discover or connect to Macs. Mirror the not-found fail-open that PR 8714 applied to services/iroh/ routeHandler.ts: an unset rule id now skips rate limiting entirely, and a not-found rule logs a warning and proceeds. Real limits (429), blocked requests, and genuine check failures (thrown/unexpected status, still 503) keep their behavior. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Bugbot is paused — on-demand spend limit reachedBugbot uses usage-based billing for this team and has hit its on-demand spend limit. A team admin can raise the spend limit in the Cursor dashboard, or wait for the next billing cycle to continue. |
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: ASSERTIVE Plan: Pro Plus Run ID: 📒 Files selected for processing (2)
📝 WalkthroughWalkthroughRelay token rate limiting now skips missing configuration and fails open when a configured rule is absent, while preserving blocked-request and rate-limit outage responses through updated route tests. ChangesRelay rate-limit behavior
Estimated code review effort: 2 (Simple) | ~10 minutes Possibly related PRs
🚥 Pre-merge checks | ✅ 25✅ Passed checks (25 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Greptile SummaryThis PR fixes a relay outage caused by
Confidence Score: 4/5Safe to merge — the fail-open changes are intentional, well-scoped to the two benign infrastructure states, and both behaviors are directly tested. The logic change is correct and the two new test cases plus the augmented blocked case verify the exact failure modes described. The only gaps are minor: the return type still advertises RelayConfigurationError even though no code path can produce it, and the new console.warn uses a free-form string rather than the structured key pattern the rest of the file follows. Neither affects runtime behavior. web/services/relay/http.ts — return type annotation and log format are the only items worth a second look. Important Files Changed
Flowchart%%{init: {'theme': 'neutral'}}%%
flowchart TD
A[enforceRelayRateLimit called] --> B{isVercel?}
B -- No --> C[Effect.void — pass]
B -- Yes --> D{ruleId set and non-empty?}
D -- "No — NEW: skip, not 503" --> C
D -- Yes --> E[call check ruleId]
E -- throws --> F[RelayRateLimitError rate_limit_unavailable → 503]
E -- ok --> G{rateLimited or error=blocked?}
G -- Yes --> H[RelayRateLimitError rate_limited → 429]
G -- No --> I{error = not-found?}
I -- "Yes — NEW: fail open, not 503" --> J[console.warn + Effect.void — pass]
I -- No --> K{any other error?}
K -- Yes --> F
K -- No --> C
|
| // means the operator deleted the limit, so treat it as "no limit" and | ||
| // fail open rather than 503-ing every request. Genuine unavailability | ||
| // (a thrown check or an unexpected status) still fails closed below. | ||
| console.warn("relay rate-limit rule not found; failing open"); |
There was a problem hiding this comment.
The new warning uses a bare string, while every other operational event in this file uses a structured key + payload (e.g.
console.error("relay.policy.unavailable", tag)). Using a consistent key makes the event filterable in log aggregation.
| console.warn("relay rate-limit rule not found; failing open"); | |
| console.warn("relay.rate_limit.rule_not_found", { ruleId }); |
Note: If this suggestion doesn't match your team's coding style, reply to this and let me know. I'll remember it for next time!
Problem
enforceRelayRateLimitinweb/services/relay/http.ts(used by/api/relay/tokenand/api/relay/preferences) hard-fails on every non-success firewall outcome: an unsetCMUX_RELAY_TOKEN_RATE_LIMIT_IDfails withrate_limit_not_configuredand a deleted Vercel firewall rule (not-found) fails asrate_limit_unavailable, both returning 503 to every authenticated request. Since the Vercel rate-limit rules were removed, every device's relay policy fetch has been failing (policyUnavailablein the client diag rings), macOS hosts loop onendpointStarting -> relayPolicyRefreshFailed -> endpointFailedand never come up, and phones cannot discover or connect to Macs.#8714 fixed this exact class in
web/services/iroh/routeHandler.tsbut did not cover this second limiter.Fix
not-found(rule deleted): warn and fail open, mirroring 8714.rateLimited/blockedstill 429 with retry-after; thrown or unexpected check outcomes still fail closed with 503.Commits
Two-commit regression structure: commit 1 adds the failing tests (red), commit 2 the fix (green).
Verification
bun test tests/relay-token-route.test.ts tests/relay-preferences-route.test.ts tests/iroh-route-handler.test.ts: 29 pass.bun run typecheckclean.relayPolicyRefreshFailed(policyUnavailable)loop whileCMUX_RELAY_TOKEN_RATE_LIMIT_IDpoints at a deleted rule.🤖 Generated with Claude Code
Need help on this PR? Tag
@codesmith-botwith what you need. Autofix is disabled.Summary by cubic
Fail open in the relay rate limiter when the Vercel rule is missing or unconfigured to stop 503s on
/api/relay/tokenand/api/relay/preferencesand restore device connectivity. Matches the existing behavior inservices/iroh/routeHandler.ts.CMUX_RELAY_TOKEN_RATE_LIMIT_ID: skip rate limiting.not-found: warn and proceed (no limit).rateLimitedandblocked; unexpected errors still 503.Written for commit 69c8cb3. Summary will update on new commits.
Summary by CodeRabbit
New Features
Bug Fixes