Repository navigation
fix(slack): backport stream pacing and honor shared cooldowns - #6
Merged
JoshSnider merged 4 commits intoSep 22, 2026
Merged
Conversation
…nstead of re-striking inside the penalty `_on_edit_failure` treated a flood-refused edit as a generic failure: a strike plus `min(interval * 2, 10)`. Starting from the 0.8s default that is 1.6s then 3.2s, so all three strikes (and three more refused requests, each extending the ban) were spent in about five seconds of a penalty Telegram had already told us is 9s or longer, and edits were then abandoned for the rest of the turn. - The interim interval now becomes `max(doubling, retry_after)` (capped at 30s; interim edits are skipped, not slept, so a long wait only costs a stale preview). - `_should_edit`'s `buffer_threshold` clause no longer overrides an active flood backoff: once the reply passed 24 codepoints every 50ms tick re-edited regardless of the interval, which made both the legacy doubling and any server wait dead letters. Slim redo of the retry_after half of NousResearch#105340 (analysis by @AlexxRussell on NousResearch#116312); the pause/join-budget machinery there is not needed once the interval itself is honoured. (cherry picked from commit 75d92e3)
(cherry picked from commit 07897c4)
Backport the upstream Slack Retry-After parser helper and keep its full cooldown across workspace threads, including final edits. Adapt upstream throttle regressions to the merged six-second backoff behavior.
૮ >ﻌ< ა ci reviewrunning on a5631fb — chore: preserve backport and fork contributor attribution Still running 2 jobs:
|
JoshSnider
merged commit Sep 22, 2026
a9b74ca
into
codex/codex-gateway-oauth-tars-pin
29 of 32 checks passed
jakeoliver-withvariable
pushed a commit
that referenced
this pull request
Sep 22, 2026
The loopback SSH hint hard-coded http://127.0.0.1:<port>/callback while a pre-registered client (Asana) redirects to http://localhost:<port>/callback, the URL the app must register verbatim. Thread redirect_host from the oauth config into the redirect handler so the hint prints the same host the provider will use. Live pass copy nit #6 on NousResearch#113907.
jakeoliver-withvariable
pushed a commit
that referenced
this pull request
Sep 22, 2026
Adopts the DNS-rebinding-pinned transport hardening (repo issues #2/#3, PR #3) and the starter-feed/settings failure-surfacing + SSRF-gated icon proxy fix (issue #6, PR #8). Full range in tony-simons-aiowa/hermes-newswire deccdc4..e6b438e (13 commits): Security-relevant highlights: - All outbound fetches (feeds, redirects, icons) now go through a pinned transport: the SSRF gate's validated address set is bound to the actual connection — no second DNS lookup, so DNS rebinding/TOCTOU has no window; the plugin fails closed if the pin seam changes. - New GET /icon.json proxies favicons through the same gate and returns base64 data URLs — the renderer's <img> no longer performs unpinned DNS resolutions of feed-controlled hostnames. 64 KB cap enforced mid-transfer; image content-type allowlist; bounded, normalized TTL cache. - Renderer surfaces backend failures (settings/sources banners, starter-feed inline errors) instead of silent no-ops. Capabilities unchanged (all empty — dashboard plugin, no tools/hooks/ env). Verification at the new pin: 129 pytest, 33 renderer interaction checks, 26 ESM render smoke, hermes plugins validate clean.
jakeoliver-withvariable
pushed a commit
that referenced
this pull request
Sep 22, 2026
…iew PR #6 + plugin-data state move)
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
75d92e3d7bea0f137411f9b514f344e88ff1533bfrom fix(telegram): streaming previews stop earning flood penalties — shared send+edit slot, retry_after honoured, word-boundary continuation (#116312, salvage #116385) NousResearch/hermes-agent#116987 and07897c42051a82fa2dd6a394577f912958459c18from fix(gateway): respect streaming edit intervals after buffer threshold NousResearch/hermes-agent#112949, preserving authorship and cherry-pick provenance. Adapt only the locations because this deployed pin predates the stream-consumer module split.b2846bc11901f6d0cabd7ad33711ac9e64a4966a. No broad upstream upgrade, provider, dependency, or prompt changes.Test plan
4c61c5760f5b3c6f68ce5b6541136fdb59bff46e.