Skip to content

fix(slack): backport stream pacing and honor shared cooldowns - #6

Merged
JoshSnider merged 4 commits into
codex/codex-gateway-oauth-tars-pinfrom
fix/slack-stream-pacing
Sep 22, 2026
Merged

JoshSnider merged 4 commits into
codex/codex-gateway-oauth-tars-pinfrom
fix/slack-stream-pacing

Conversation

@JoshSnider

@JoshSnider JoshSnider commented Sep 22, 2026 •

Copy link
Copy Markdown

Summary

Test plan

teknium1 and others added 3 commits September 22, 2026 09:47
…nstead of re-striking inside the penalty

`_on_edit_failure` treated a flood-refused edit as a generic failure: a strike plus
`min(interval * 2, 10)`. Starting from the 0.8s default that is 1.6s then 3.2s, so all
three strikes (and three more refused requests, each extending the ban) were spent in
about five seconds of a penalty Telegram had already told us is 9s or longer, and
edits were then abandoned for the rest of the turn.

- The interim interval now becomes `max(doubling, retry_after)` (capped at 30s; interim
  edits are skipped, not slept, so a long wait only costs a stale preview).
- `_should_edit`'s `buffer_threshold` clause no longer overrides an active flood backoff:
  once the reply passed 24 codepoints every 50ms tick re-edited regardless of the
  interval, which made both the legacy doubling and any server wait dead letters.

Slim redo of the retry_after half of NousResearch#105340 (analysis by @AlexxRussell on NousResearch#116312);
the pause/join-budget machinery there is not needed once the interval itself is honoured.

(cherry picked from commit 75d92e3)
Backport the upstream Slack Retry-After parser helper and keep its full cooldown across workspace threads, including final edits. Adapt upstream throttle regressions to the merged six-second backoff behavior.
@github-actions

github-actions Bot commented Sep 22, 2026 •

Copy link
Copy Markdown

૮ >ﻌ< ა ci review

running on a5631fb — chore: preserve backport and fork contributor attribution


Still running 2 jobs: OS-specific tests / Windows-only tests, Python tests / Run tests

⚠️ Warnings

OSV vulnerability scan · View job

83 known vulnerabilities found in pinned dependencies.

How to fix:

Review the findings in the Security tab. Update the affected dependencies if a patched version is available.

@JoshSnider
JoshSnider merged commit a9b74ca into codex/codex-gateway-oauth-tars-pin Sep 22, 2026
29 of 32 checks passed
jakeoliver-withvariable pushed a commit that referenced this pull request Sep 22, 2026
The loopback SSH hint hard-coded http://127.0.0.1:<port>/callback while a
pre-registered client (Asana) redirects to http://localhost:<port>/callback,
the URL the app must register verbatim. Thread redirect_host from the oauth
config into the redirect handler so the hint prints the same host the
provider will use. Live pass copy nit #6 on NousResearch#113907.
jakeoliver-withvariable pushed a commit that referenced this pull request Sep 22, 2026
Adopts the DNS-rebinding-pinned transport hardening (repo issues #2/#3,
PR #3) and the starter-feed/settings failure-surfacing + SSRF-gated icon
proxy fix (issue #6, PR #8). Full range in
tony-simons-aiowa/hermes-newswire deccdc4..e6b438e (13 commits):

Security-relevant highlights:
- All outbound fetches (feeds, redirects, icons) now go through a pinned
  transport: the SSRF gate's validated address set is bound to the actual
  connection — no second DNS lookup, so DNS rebinding/TOCTOU has no
  window; the plugin fails closed if the pin seam changes.
- New GET /icon.json proxies favicons through the same gate and returns
  base64 data URLs — the renderer's <img> no longer performs unpinned
  DNS resolutions of feed-controlled hostnames. 64 KB cap enforced
  mid-transfer; image content-type allowlist; bounded, normalized TTL
  cache.
- Renderer surfaces backend failures (settings/sources banners,
  starter-feed inline errors) instead of silent no-ops.

Capabilities unchanged (all empty — dashboard plugin, no tools/hooks/
env). Verification at the new pin: 129 pytest, 33 renderer interaction
checks, 26 ESM render smoke, hermes plugins validate clean.
jakeoliver-withvariable pushed a commit that referenced this pull request Sep 22, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants