fix: keep a burst of pushes from turning off phone approval - #241
Merged
Merged
Conversation
Relay gives urgent pushes their own per-token rate-limit bucket and sends Retry-After on 429. tether-notify retries urgent pushes on 429/503/transport errors with bounded backoff.
…nt bucket is missing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Failure mode
The relay rate-limits per device token. A burst of routine pushes (several agents finishing at once) could use up that bucket, and the next permission prompt or question then got a 429.
tether-notifytreated any non-2xx as a plain failure with no retry, and a failed push inholdmeans "not held", so the prompt silently fell back to the terminal and never reached the phone.Changes
level) use a separate per-token bucket,PER_TOKEN_URGENT, so normal and quiet bursts cannot starve them.PER_IPis unchanged. A 429 now carries aRetry-Afterhint.sendPushretries on 429, 503 and transport errors, honoringRetry-After. Bounded: at most 3 retries, each wait capped at 5 s, total waiting budget 12 s per call, sinceholdruns synchronously inside a hook. Retries are per device, so a device that already accepted is not re-sent. Non-urgent pushes and 4xx responses are not retried. Sleep is injectable, so tests do not wait.Tests
Retry-After.Deploy
The relay needs a deploy after merge so the new
PER_TOKEN_URGENTbinding exists. Until thenc.env.PER_TOKEN_URGENTis undefined and urgent pushes would fail, so deploy the relay before or together with the host tool rollout.Replaces #240, which closed when its stacked base branch was deleted after #238 merged.