Skip to content

Release: relay mirrored gateway approvals after stream loss (#5041, fixes #5000) - #5044

Merged
nesquena-hermes merged 4 commits into
masterfrom
release/stage-5041-approval
Jun 27, 2026
Merged

nesquena-hermes merged 4 commits into
masterfrom
release/stage-5041-approval

Conversation

@nesquena-hermes

Copy link
Copy Markdown
Collaborator

Ships @rodboev's #5041 — relay mirrored gateway approvals after stream loss (fixes #5000).

What this does

When you approve/deny a gateway-routed tool-use request, /api/approval/respond walked back through the session's active_stream_id to find the run. If that pointer was gone (reconnect, background tab, ended stream), responding failed with gateway_run_unavailable even though the mirrored approval card still carried the originating gateway run info. The handler now relays a mirrored gateway approval using the approval's own carried origin (scoped to the same session + approval id), keeping the card actionable across stream loss.

Gate results

  • ast.parse (route_approvals.py + routes.py) ✓ · ruff forward-gate CLEAN (0 new violations)
  • Codex regression gate: SAFE TO SHIP — verified stream-alive relay still uses active_stream_id→_STREAM_RUN_IDS (unchanged), stream-lost relay only uses the mirrored approval for the same sid+approval_id (no cross-session misroute), missing-origin approvals still return gateway_run_unavailable, auth/CSRF gates intact in the shared POST path. test_gateway_approval_legacy_path.py 14/14 + adjacent approval checks 11/11.
  • Full pytest suite: 10766 passed, 10 skipped, 0 failed

Backend-only (api/), no served-page change → no browser smoke needed. Pre-merge head re-check: live PR head code byte-identical to the gated branch.

Attribution: credit @rodboev in CHANGELOG. Closes #5041 + #5000 on merge.

@greptile-apps

greptile-apps Bot commented Jun 27, 2026

Copy link
Copy Markdown
Contributor

Greptile Summary

This PR keeps gateway approval cards usable after the live stream pointer is gone. The main changes are:

  • Adds a session-scoped lookup for mirrored gateway approval run_id values.
  • Falls back to the mirrored approval origin when /api/approval/respond cannot find an active stream run.
  • Clears the local mirrored approval state after a successful gateway relay.
  • Adds tests for stream-loss relay and empty-pending gateway clicks.
  • Updates the changelog for the release note.

Confidence Score: 5/5

This looks safe to merge.

  • No blocking issues found in the changed code.

Important Files Changed

Filename Overview
api/route_approvals.py Adds a helper that reconciles mirrored gateway approvals and returns a matching mirrored run_id for the same session and approval id.
api/routes.py Extends approval responses to relay through a mirrored gateway origin when the active stream lookup is unavailable.
tests/test_gateway_approval_legacy_path.py Adds tests for gateway approval relay after stream loss and for gateway-mode clicks with no pending approval.
CHANGELOG.md Adds the release note for the gateway approval recovery behavior.

Reviews (1): Last reviewed commit: "Release: relay mirrored gateway approval..." | Re-trigger Greptile

@nesquena-hermes
nesquena-hermes merged commit 8b2d3db into master Jun 27, 2026
11 checks passed
@nesquena-hermes
nesquena-hermes deleted the release/stage-5041-approval branch June 27, 2026 06:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

bug(gateway/approval): approve/deny relay fails on every approval — "active run unavailable"

2 participants