fix(inference): treat Codex 404s as expired credentials - #1138
Merged
TheGreatAxios merged 4 commits intoSep 21, 2026
Merged
TheGreatAxios merged 4 commits into
TheGreatAxios merged 4 commits into
Conversation
Contributor
|
All contributors have signed the CLA. |
The 'expired' credential-404 marker misfires on model-deprecation 404s
("model 'gpt-4o' has expired - migrate ..."): reclassifying those as
credential_failure would send the operator to log in again for a model
that no longer exists. Add a deprecation veto (model mention plus
retirement signal) that runs before the auth markers, with a keeper
test. Drop the cross-lane refresh-failed terminal test: that input
shape is owned by #1139 (CL-8628), which covers the same dedup in
runner/refresh-lock tests.
TheGreatAxios
force-pushed
the
cl-8627-classify-expired-codex-credentials-as-credential-failures
branch
from
September 21, 2026 03:50
cd520ee to
258eaea
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Codex profile "<name>" is not authorized. Log in again. (<diagnostic>)), wire body retained on raw, profile still named for the TUI auth matchers.carriesCodexReLoginHintinsrc/inference-gateway-error.ts) between the classifier brand and the terminal-guidance dedup; the two can no longer drift.codexCredential404ReclassifiedStats) so future backend 404 reasons are caught.The model 'gpt-3.5-turbo' does not existstays fatal. Non-Codex provider scoping preserved (auth signals never leak across providers).Why: defaulting every bare Codex 404 to credential_failure misdirects routing/config 404s to re-login; positive auth-marker matching keeps the classifier-layer approach while failing closed.
Overlap with #1139
terminal Codex refresh-failed auth error renders one re-login hint): both lanes land credential failures in the CodexAuthError copy shape, and the terminal dedup swallows the generic hint for either source.Verification
bun test src/inference-gateway-error.test.ts src/inference-error-message.test.tspasses (74 pass, 0 fail)bun run typecheckpassesbun run lint(oxfmt --check + oxlint) cleanbun run check:dead-exports— 0 violationsbun run check(lint + typecheck + dead-exports + build + full suite) — 7762 pass, 0 fail across 522 files00fee074pushed to the same branch, unmergedFixes CL-8627