Skip to content

fix(inference): treat Codex 404s as expired credentials - #1138

Merged
TheGreatAxios merged 4 commits into
mainfrom
cl-8627-classify-expired-codex-credentials-as-credential-failures
Sep 21, 2026
Merged

TheGreatAxios merged 4 commits into
mainfrom
cl-8627-classify-expired-codex-credentials-as-credential-failures

Conversation

@TheGreatAxios

@TheGreatAxios TheGreatAxios commented Sep 19, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

  • Positive-marker polarity (review rework): a known-Codex fatal 404 reclassifies to credential_failure ONLY when the message or raw body carries an auth-rejection signal (not authorized / unauthorized / invalid token / expired / revoked). Bare, routing/config, and genuine unknown-model 404s stay fatal with switch-models guidance — no unknown-model allowlist to rot.
  • Original diagnostic preserved alongside the branded copy (Codex profile "<name>" is not authorized. Log in again. (<diagnostic>)), wire body retained on raw, profile still named for the TUI auth matchers.
  • ONE shared predicate (carriesCodexReLoginHint in src/inference-gateway-error.ts) between the classifier brand and the terminal-guidance dedup; the two can no longer drift.
  • Wire-grounded revoked-credential 404 fixture test (harness shape: fatal + statusText message + JSON body on raw) plus a reclassification counter and last-body sample (codexCredential404ReclassifiedStats) so future backend 404 reasons are caught.
  • Dotted-model regression: message-only The model 'gpt-3.5-turbo' does not exist stays fatal. Non-Codex provider scoping preserved (auth signals never leak across providers).

Why: defaulting every bare Codex 404 to credential_failure misdirects routing/config 404s to re-login; positive auth-marker matching keeps the classifier-layer approach while failing closed.

Overlap with #1139

  • Joint surface (best-effort combined test included: terminal Codex refresh-failed auth error renders one re-login hint): both lanes land credential failures in the CodexAuthError copy shape, and the terminal dedup swallows the generic hint for either source.
  • Merge order per reviews: fix(codex): serialize shared-credential OAuth token refreshes #1139 first, then this rebases.

Verification

  • bun test src/inference-gateway-error.test.ts src/inference-error-message.test.ts passes (74 pass, 0 fail)
  • bun run typecheck passes
  • bun run lint (oxfmt --check + oxlint) clean
  • bun run check:dead-exports — 0 violations
  • bun run check (lint + typecheck + dead-exports + build + full suite) — 7762 pass, 0 fail across 522 files
  • Fix-up commit 00fee074 pushed to the same branch, unmerged

Fixes CL-8627

@linear-code

linear-code Bot commented Sep 19, 2026

Copy link
Copy Markdown

CL-8627

@github-actions

github-actions Bot commented Sep 21, 2026 •

Copy link
Copy Markdown
Contributor

All contributors have signed the CLA.
Posted by the CLA Assistant Lite bot.

The 'expired' credential-404 marker misfires on model-deprecation 404s
("model 'gpt-4o' has expired - migrate ..."): reclassifying those as
credential_failure would send the operator to log in again for a model
that no longer exists. Add a deprecation veto (model mention plus
retirement signal) that runs before the auth markers, with a keeper
test. Drop the cross-lane refresh-failed terminal test: that input
shape is owned by #1139 (CL-8628), which covers the same dedup in
runner/refresh-lock tests.
@TheGreatAxios
TheGreatAxios force-pushed the cl-8627-classify-expired-codex-credentials-as-credential-failures branch from cd520ee to 258eaea Compare September 21, 2026 03:50
@TheGreatAxios
TheGreatAxios merged commit 1528e33 into main Sep 21, 2026
13 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant