Repository navigation
Conversation
miravoss26
reviewed
Oct 5, 2026
miravoss26
left a comment
Contributor
There was a problem hiding this comment.
Mira's read (pr-steward sweep). 2-line summary: when a driver probe rotates the shared secret, the live driver is now restarted so it picks up the fresh value. Persist happens only on change, and both the rotated and unchanged paths have tests.
Findings:
- [medium]
go/internal/api/api_drivers_debug.go: the deferred restart callsRestartByName(probe.Name), but the secret's owner issecretOwner(the live driver). They match in these tests. If a probe name ever differs from the live driver's name, the restart hits the wrong driver or none. Suggest restartingsecretOwner(live.Name).
Security screen: no new hosts, no secrets in non-test code (test fixtures only), stdlib imports only.
Needs a human decision on the restart target before merge. Not auto-merge eligible (repo not on the POLICY allowlist).
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Follow-up to #1507. When a Test connection probe reuses a live driver's persisted OAuth secret, the probe can rotate the shared refresh token while the live driver keeps the previous token in memory. Restart the live driver after the probe is removed when the probe successfully persisted a different shared secret, so it reloads the current token from the SecretStore.
This intentionally addresses the observed stale in-memory token after a successful probe rotation. It does not attempt to serialize simultaneous refreshes of the same OAuth token family.
Tests
go test ./internal/api -run 'TestHandleDriverTest(RestartsRunningDriverAfterRefreshTokenRotation|DoesNotRestartRunningDriverWhenSecretUnchanged)$' -count=1 -v— PASSgo test ./internal/api -count=1— PASS/did not containview-live; this patch changes only the API implementation and API tests.Hardware validation
Validated on the FTW hardware build used for beta.6. A MyUplink Test connection rotated the persisted refresh token, the temporary probe was removed, and the running
myuplinkdriver was immediately restarted and became ready again. Repeated Test connection runs behaved the same way, and noinvalid_grantrecurred beyond the previous ~1 hour failure window.Depends on #1507.