Skip to content

fix(api): restart driver after probe rotates shared secret - #1517

Merged
frahlg merged 1 commit into
srcfl:cursor/driver-probe-secrets-658dfrom
segran2:fix/myuplink-probe-token-race
Oct 6, 2026
Merged

frahlg merged 1 commit into
srcfl:cursor/driver-probe-secrets-658dfrom
segran2:fix/myuplink-probe-token-race

Conversation

@segran2

@segran2 segran2 commented Oct 4, 2026

Copy link
Copy Markdown
Contributor

Summary

Follow-up to #1507. When a Test connection probe reuses a live driver's persisted OAuth secret, the probe can rotate the shared refresh token while the live driver keeps the previous token in memory. Restart the live driver after the probe is removed when the probe successfully persisted a different shared secret, so it reloads the current token from the SecretStore.

This intentionally addresses the observed stale in-memory token after a successful probe rotation. It does not attempt to serialize simultaneous refreshes of the same OAuth token family.

Tests

  • Added regression coverage that verifies a rotated shared secret advances the live driver's registry generation.
  • Added regression coverage that verifies persisting the same secret does not restart the live driver.
  • go test ./internal/api -run 'TestHandleDriverTest(RestartsRunningDriverAfterRefreshTokenRotation|DoesNotRestartRunningDriverWhenSecretUnchanged)$' -count=1 -v — PASS
  • go test ./internal/api -count=1 — PASS
  • Full local CI reached the UI smoke check, which failed because / did not contain view-live; this patch changes only the API implementation and API tests.

Hardware validation

Validated on the FTW hardware build used for beta.6. A MyUplink Test connection rotated the persisted refresh token, the temporary probe was removed, and the running myuplink driver was immediately restarted and became ready again. Repeated Test connection runs behaved the same way, and no invalid_grant recurred beyond the previous ~1 hour failure window.

Depends on #1507.

@miravoss26 miravoss26 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Mira's read (pr-steward sweep). 2-line summary: when a driver probe rotates the shared secret, the live driver is now restarted so it picks up the fresh value. Persist happens only on change, and both the rotated and unchanged paths have tests.

Findings:

  • [medium] go/internal/api/api_drivers_debug.go: the deferred restart calls RestartByName(probe.Name), but the secret's owner is secretOwner (the live driver). They match in these tests. If a probe name ever differs from the live driver's name, the restart hits the wrong driver or none. Suggest restarting secretOwner (live.Name).

Security screen: no new hosts, no secrets in non-test code (test fixtures only), stdlib imports only.

Needs a human decision on the restart target before merge. Not auto-merge eligible (repo not on the POLICY allowlist).

@frahlg
frahlg merged commit 532ccb5 into srcfl:cursor/driver-probe-secrets-658d Oct 6, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants