Skip to content

fix(client-runtime): retry auth-blocked reconnects during server-update resume - #138

Merged
gannonh merged 2 commits into
mainfrom
cursor/recover-remote-update-auth-98e7
Aug 26, 2026
Merged

fix(client-runtime): retry auth-blocked reconnects during server-update resume#138
gannonh merged 2 commits into
mainfrom
cursor/recover-remote-update-auth-98e7

Conversation

@gannonh

@gannonhgannonh commented Aug 26, 2026

Copy link
Copy Markdown
Owner

What Changed

nudgeReconnectDuringUpdateRestart now also retries when the connection supervisor is blocked on authentication during a remote server-update resume. Permission and configuration blocks stay idle.

Why

A restarted remote server can reject the first environment credential. The supervisor then parks in blocked, and the resume loop used to stop nudging because it only watched backoff. Recovery could sit until the four-minute timeout.

This ports upstream pingdotgg/t3code#7953 and keeps the existing one-second pacing and four-minute resume lifetime.

Scope

  • packages/client-runtime/src/state/server.ts. Widen the nudge stream type and admit phase === "blocked" only when lastFailure?.reason === "authentication".
  • packages/client-runtime/src/state/server.test.ts. Helper filter test plus a command-boundary test of createServerEnvironmentAtoms(...).updateServer.

Out of scope: credential storage, authorization policy, supervisor retry policy, contracts, server, UI.

Closes#134

Tradeoffs

Retrying every blocked reason would hide real setup failures. The filter admits only authentication.

Blast Radius

Web, desktop, and mobile share this client-runtime command. Remote update resume is the only new retry path. Idle blocked permission and configuration behavior is unchanged.

Verification

  • vp test run packages/client-runtime/src/state/server.test.ts (15 passed)
  • vp run --filter @kata-sh/code-client-runtime typecheck (exit 0)
  • Identity grep of the diff for @t3tools/, T3CODE_, t3@, t3code, pingdotgg/t3code (no matches)

Build report: #134 (comment)

Acceptance criteria matrix

Full matrix: #134 (comment)

CriterionResultEvidence
Every backoff entry schedules one reconnect nudge after the existing pacing intervalPassHelper tests: 3 backoff entries, 3 nudges; TestClock pacing
An authentication-blocked state schedules one reconnect nudge after the existing pacing intervalPassupdateServer command-boundary test plus filter
Permission-blocked and configuration-blocked states schedule no reconnect nudgePassHelper streams permission, authentication, configuration; expects 1 retry
Retry loop stops when the update command settles, fails, or reaches its existing resume timeoutPassCommand test settles to idle. Fail and timeout paths not driven. Lifetime still forkChild plus timeoutOption (4 minutes)
Deterministic command test: transient auth block, ready event, success, idlePassrecovers the update command after a transient credential rejection
Focused client-runtime server tests and typecheck passPass15 tests, typecheck exit 0
Product diff preserves #127 Kata update copy and contains no new T3 identityPass@kata-sh/code-cli@ copy test; identity grep empty

Totals: 7 Pass / 0 Fail / 0 Blocked (acceptance checkboxes). Supplementary live remote update: Blocked (no disposable target).

Convergence: #134 (comment)

UI Changes

None.

Checklist

  • This PR is small and focused
  • I explained what changed and why
  • I included before/after screenshots for any UI changes
  • I included a video for animation/interaction changes
Open in WebOpen in Cursor

…te resume
A restarted remote server can reject the environment credential once and
leave the supervisor blocked. The update resume loop only nudged backoff,
so recovery stopped.
Admit authentication-blocked supervisor states on the same one-second
cadence as backoff. Permission and configuration failures stay blocked.
A command-boundary test drives the public updateServer path through that
transient block to a matching ready event.
Refs #134
Co-authored-by: Gannon Hall <gannonh@users.noreply.github.com>
@coderabbitai

coderabbitaiBot commented Aug 26, 2026

Copy link
Copy Markdown

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: d4649ab5-3006-449a-9c03-4ab0c2c9bd41


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@gannonh

Copy link
Copy Markdown
OwnerAuthor

@coderabbitai review

@coderabbitai

coderabbitaiBot commented Aug 26, 2026

Copy link
Copy Markdown
⚠️ Action not completed

Review rate limited.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

Co-authored-by: Gannon Hall <gannonh@users.noreply.github.com>

@chatgpt-codex-connectorchatgpt-codex-connectorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit:5f2875ccb6

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment threadpackages/client-runtime/src/state/server.ts
@gannonh
gannonh merged commit 10fd039 into mainAug 26, 2026
5 checks passed
@gannonh
gannonh deleted the cursor/recover-remote-update-auth-98e7 branch August 26, 2026 19:49
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Vendor-pull slice 3b: recover remote updates after credential rejection

2 participants

@gannonh@cursoragent
, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
fix(client-runtime): retry auth-blocked reconnects during server-update resume by gannonh · Pull Request #138 · gannonh/kata-code · GitHub
Skip to content

fix(client-runtime): retry auth-blocked reconnects during server-update resume - #138

Merged
gannonh merged 2 commits into
mainfrom
cursor/recover-remote-update-auth-98e7
Aug 26, 2026
Merged

fix(client-runtime): retry auth-blocked reconnects during server-update resume#138
gannonh merged 2 commits into
mainfrom
cursor/recover-remote-update-auth-98e7

Conversation

@gannonh

@gannonhgannonh commented Aug 26, 2026

Copy link
Copy Markdown
Owner

What Changed

nudgeReconnectDuringUpdateRestart now also retries when the connection supervisor is blocked on authentication during a remote server-update resume. Permission and configuration blocks stay idle.

Why

A restarted remote server can reject the first environment credential. The supervisor then parks in blocked, and the resume loop used to stop nudging because it only watched backoff. Recovery could sit until the four-minute timeout.

This ports upstream pingdotgg/t3code#7953 and keeps the existing one-second pacing and four-minute resume lifetime.

Scope

  • packages/client-runtime/src/state/server.ts. Widen the nudge stream type and admit phase === "blocked" only when lastFailure?.reason === "authentication".
  • packages/client-runtime/src/state/server.test.ts. Helper filter test plus a command-boundary test of createServerEnvironmentAtoms(...).updateServer.

Out of scope: credential storage, authorization policy, supervisor retry policy, contracts, server, UI.

Closes#134

Tradeoffs

Retrying every blocked reason would hide real setup failures. The filter admits only authentication.

Blast Radius

Web, desktop, and mobile share this client-runtime command. Remote update resume is the only new retry path. Idle blocked permission and configuration behavior is unchanged.

Verification

  • vp test run packages/client-runtime/src/state/server.test.ts (15 passed)
  • vp run --filter @kata-sh/code-client-runtime typecheck (exit 0)
  • Identity grep of the diff for @t3tools/, T3CODE_, t3@, t3code, pingdotgg/t3code (no matches)

Build report: #134 (comment)

Acceptance criteria matrix

Full matrix: #134 (comment)

CriterionResultEvidence
Every backoff entry schedules one reconnect nudge after the existing pacing intervalPassHelper tests: 3 backoff entries, 3 nudges; TestClock pacing
An authentication-blocked state schedules one reconnect nudge after the existing pacing intervalPassupdateServer command-boundary test plus filter
Permission-blocked and configuration-blocked states schedule no reconnect nudgePassHelper streams permission, authentication, configuration; expects 1 retry
Retry loop stops when the update command settles, fails, or reaches its existing resume timeoutPassCommand test settles to idle. Fail and timeout paths not driven. Lifetime still forkChild plus timeoutOption (4 minutes)
Deterministic command test: transient auth block, ready event, success, idlePassrecovers the update command after a transient credential rejection
Focused client-runtime server tests and typecheck passPass15 tests, typecheck exit 0
Product diff preserves #127 Kata update copy and contains no new T3 identityPass@kata-sh/code-cli@ copy test; identity grep empty

Totals: 7 Pass / 0 Fail / 0 Blocked (acceptance checkboxes). Supplementary live remote update: Blocked (no disposable target).

Convergence: #134 (comment)

UI Changes

None.

Checklist

  • This PR is small and focused
  • I explained what changed and why
  • I included before/after screenshots for any UI changes
  • I included a video for animation/interaction changes
Open in WebOpen in Cursor

…te resume
A restarted remote server can reject the environment credential once and
leave the supervisor blocked. The update resume loop only nudged backoff,
so recovery stopped.
Admit authentication-blocked supervisor states on the same one-second
cadence as backoff. Permission and configuration failures stay blocked.
A command-boundary test drives the public updateServer path through that
transient block to a matching ready event.
Refs #134
Co-authored-by: Gannon Hall <gannonh@users.noreply.github.com>
@coderabbitai

coderabbitaiBot commented Aug 26, 2026

Copy link
Copy Markdown

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: d4649ab5-3006-449a-9c03-4ab0c2c9bd41


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@gannonh

Copy link
Copy Markdown
OwnerAuthor

@coderabbitai review

@coderabbitai

coderabbitaiBot commented Aug 26, 2026

Copy link
Copy Markdown
⚠️ Action not completed

Review rate limited.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

Co-authored-by: Gannon Hall <gannonh@users.noreply.github.com>

@chatgpt-codex-connectorchatgpt-codex-connectorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit:5f2875ccb6

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment threadpackages/client-runtime/src/state/server.ts
@gannonh
gannonh merged commit 10fd039 into mainAug 26, 2026
5 checks passed
@gannonh
gannonh deleted the cursor/recover-remote-update-auth-98e7 branch August 26, 2026 19:49
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Vendor-pull slice 3b: recover remote updates after credential rejection

2 participants

@gannonh@cursoragent
, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' fix(client-runtime): retry auth-blocked reconnects during server-update resume by gannonh · Pull Request #138 · gannonh/kata-code · GitHub
Skip to content

fix(client-runtime): retry auth-blocked reconnects during server-update resume - #138

Merged
gannonh merged 2 commits into
mainfrom
cursor/recover-remote-update-auth-98e7
Aug 26, 2026
Merged

fix(client-runtime): retry auth-blocked reconnects during server-update resume#138
gannonh merged 2 commits into
mainfrom
cursor/recover-remote-update-auth-98e7

Conversation

@gannonh

@gannonhgannonh commented Aug 26, 2026

Copy link
Copy Markdown
Owner

What Changed

nudgeReconnectDuringUpdateRestart now also retries when the connection supervisor is blocked on authentication during a remote server-update resume. Permission and configuration blocks stay idle.

Why

A restarted remote server can reject the first environment credential. The supervisor then parks in blocked, and the resume loop used to stop nudging because it only watched backoff. Recovery could sit until the four-minute timeout.

This ports upstream pingdotgg/t3code#7953 and keeps the existing one-second pacing and four-minute resume lifetime.

Scope

  • packages/client-runtime/src/state/server.ts. Widen the nudge stream type and admit phase === "blocked" only when lastFailure?.reason === "authentication".
  • packages/client-runtime/src/state/server.test.ts. Helper filter test plus a command-boundary test of createServerEnvironmentAtoms(...).updateServer.

Out of scope: credential storage, authorization policy, supervisor retry policy, contracts, server, UI.

Closes#134

Tradeoffs

Retrying every blocked reason would hide real setup failures. The filter admits only authentication.

Blast Radius

Web, desktop, and mobile share this client-runtime command. Remote update resume is the only new retry path. Idle blocked permission and configuration behavior is unchanged.

Verification

  • vp test run packages/client-runtime/src/state/server.test.ts (15 passed)
  • vp run --filter @kata-sh/code-client-runtime typecheck (exit 0)
  • Identity grep of the diff for @t3tools/, T3CODE_, t3@, t3code, pingdotgg/t3code (no matches)

Build report: #134 (comment)

Acceptance criteria matrix

Full matrix: #134 (comment)

CriterionResultEvidence
Every backoff entry schedules one reconnect nudge after the existing pacing intervalPassHelper tests: 3 backoff entries, 3 nudges; TestClock pacing
An authentication-blocked state schedules one reconnect nudge after the existing pacing intervalPassupdateServer command-boundary test plus filter
Permission-blocked and configuration-blocked states schedule no reconnect nudgePassHelper streams permission, authentication, configuration; expects 1 retry
Retry loop stops when the update command settles, fails, or reaches its existing resume timeoutPassCommand test settles to idle. Fail and timeout paths not driven. Lifetime still forkChild plus timeoutOption (4 minutes)
Deterministic command test: transient auth block, ready event, success, idlePassrecovers the update command after a transient credential rejection
Focused client-runtime server tests and typecheck passPass15 tests, typecheck exit 0
Product diff preserves #127 Kata update copy and contains no new T3 identityPass@kata-sh/code-cli@ copy test; identity grep empty

Totals: 7 Pass / 0 Fail / 0 Blocked (acceptance checkboxes). Supplementary live remote update: Blocked (no disposable target).

Convergence: #134 (comment)

UI Changes

None.

Checklist

  • This PR is small and focused
  • I explained what changed and why
  • I included before/after screenshots for any UI changes
  • I included a video for animation/interaction changes
Open in WebOpen in Cursor

…te resume
A restarted remote server can reject the environment credential once and
leave the supervisor blocked. The update resume loop only nudged backoff,
so recovery stopped.
Admit authentication-blocked supervisor states on the same one-second
cadence as backoff. Permission and configuration failures stay blocked.
A command-boundary test drives the public updateServer path through that
transient block to a matching ready event.
Refs #134
Co-authored-by: Gannon Hall <gannonh@users.noreply.github.com>
@coderabbitai

coderabbitaiBot commented Aug 26, 2026

Copy link
Copy Markdown

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: d4649ab5-3006-449a-9c03-4ab0c2c9bd41


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@gannonh

Copy link
Copy Markdown
OwnerAuthor

@coderabbitai review

@coderabbitai

coderabbitaiBot commented Aug 26, 2026

Copy link
Copy Markdown
⚠️ Action not completed

Review rate limited.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

Co-authored-by: Gannon Hall <gannonh@users.noreply.github.com>

@chatgpt-codex-connectorchatgpt-codex-connectorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit:5f2875ccb6

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment threadpackages/client-runtime/src/state/server.ts
@gannonh
gannonh merged commit 10fd039 into mainAug 26, 2026
5 checks passed
@gannonh
gannonh deleted the cursor/recover-remote-update-auth-98e7 branch August 26, 2026 19:49
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Vendor-pull slice 3b: recover remote updates after credential rejection

2 participants

@gannonh@cursoragent
, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' fix(client-runtime): retry auth-blocked reconnects during server-update resume by gannonh · Pull Request #138 · gannonh/kata-code · GitHub
Skip to content

fix(client-runtime): retry auth-blocked reconnects during server-update resume - #138

Merged
gannonh merged 2 commits into
mainfrom
cursor/recover-remote-update-auth-98e7
Aug 26, 2026
Merged

fix(client-runtime): retry auth-blocked reconnects during server-update resume#138
gannonh merged 2 commits into
mainfrom
cursor/recover-remote-update-auth-98e7

Conversation

@gannonh

@gannonhgannonh commented Aug 26, 2026

Copy link
Copy Markdown
Owner

What Changed

nudgeReconnectDuringUpdateRestart now also retries when the connection supervisor is blocked on authentication during a remote server-update resume. Permission and configuration blocks stay idle.

Why

A restarted remote server can reject the first environment credential. The supervisor then parks in blocked, and the resume loop used to stop nudging because it only watched backoff. Recovery could sit until the four-minute timeout.

This ports upstream pingdotgg/t3code#7953 and keeps the existing one-second pacing and four-minute resume lifetime.

Scope

  • packages/client-runtime/src/state/server.ts. Widen the nudge stream type and admit phase === "blocked" only when lastFailure?.reason === "authentication".
  • packages/client-runtime/src/state/server.test.ts. Helper filter test plus a command-boundary test of createServerEnvironmentAtoms(...).updateServer.

Out of scope: credential storage, authorization policy, supervisor retry policy, contracts, server, UI.

Closes#134

Tradeoffs

Retrying every blocked reason would hide real setup failures. The filter admits only authentication.

Blast Radius

Web, desktop, and mobile share this client-runtime command. Remote update resume is the only new retry path. Idle blocked permission and configuration behavior is unchanged.

Verification

  • vp test run packages/client-runtime/src/state/server.test.ts (15 passed)
  • vp run --filter @kata-sh/code-client-runtime typecheck (exit 0)
  • Identity grep of the diff for @t3tools/, T3CODE_, t3@, t3code, pingdotgg/t3code (no matches)

Build report: #134 (comment)

Acceptance criteria matrix

Full matrix: #134 (comment)

CriterionResultEvidence
Every backoff entry schedules one reconnect nudge after the existing pacing intervalPassHelper tests: 3 backoff entries, 3 nudges; TestClock pacing
An authentication-blocked state schedules one reconnect nudge after the existing pacing intervalPassupdateServer command-boundary test plus filter
Permission-blocked and configuration-blocked states schedule no reconnect nudgePassHelper streams permission, authentication, configuration; expects 1 retry
Retry loop stops when the update command settles, fails, or reaches its existing resume timeoutPassCommand test settles to idle. Fail and timeout paths not driven. Lifetime still forkChild plus timeoutOption (4 minutes)
Deterministic command test: transient auth block, ready event, success, idlePassrecovers the update command after a transient credential rejection
Focused client-runtime server tests and typecheck passPass15 tests, typecheck exit 0
Product diff preserves #127 Kata update copy and contains no new T3 identityPass@kata-sh/code-cli@ copy test; identity grep empty

Totals: 7 Pass / 0 Fail / 0 Blocked (acceptance checkboxes). Supplementary live remote update: Blocked (no disposable target).

Convergence: #134 (comment)

UI Changes

None.

Checklist

  • This PR is small and focused
  • I explained what changed and why
  • I included before/after screenshots for any UI changes
  • I included a video for animation/interaction changes
Open in WebOpen in Cursor

…te resume
A restarted remote server can reject the environment credential once and
leave the supervisor blocked. The update resume loop only nudged backoff,
so recovery stopped.
Admit authentication-blocked supervisor states on the same one-second
cadence as backoff. Permission and configuration failures stay blocked.
A command-boundary test drives the public updateServer path through that
transient block to a matching ready event.
Refs #134
Co-authored-by: Gannon Hall <gannonh@users.noreply.github.com>
@coderabbitai

coderabbitaiBot commented Aug 26, 2026

Copy link
Copy Markdown

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: d4649ab5-3006-449a-9c03-4ab0c2c9bd41


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@gannonh

Copy link
Copy Markdown
OwnerAuthor

@coderabbitai review

@coderabbitai

coderabbitaiBot commented Aug 26, 2026

Copy link
Copy Markdown
⚠️ Action not completed

Review rate limited.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

Co-authored-by: Gannon Hall <gannonh@users.noreply.github.com>

@chatgpt-codex-connectorchatgpt-codex-connectorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit:5f2875ccb6

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment threadpackages/client-runtime/src/state/server.ts
@gannonh
gannonh merged commit 10fd039 into mainAug 26, 2026
5 checks passed
@gannonh
gannonh deleted the cursor/recover-remote-update-auth-98e7 branch August 26, 2026 19:49
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Vendor-pull slice 3b: recover remote updates after credential rejection

2 participants

@gannonh@cursoragent
, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' fix(client-runtime): retry auth-blocked reconnects during server-update resume by gannonh · Pull Request #138 · gannonh/kata-code · GitHub
Skip to content

fix(client-runtime): retry auth-blocked reconnects during server-update resume - #138

Merged
gannonh merged 2 commits into
mainfrom
cursor/recover-remote-update-auth-98e7
Aug 26, 2026
Merged

fix(client-runtime): retry auth-blocked reconnects during server-update resume#138
gannonh merged 2 commits into
mainfrom
cursor/recover-remote-update-auth-98e7

Conversation

@gannonh

@gannonhgannonh commented Aug 26, 2026

Copy link
Copy Markdown
Owner

What Changed

nudgeReconnectDuringUpdateRestart now also retries when the connection supervisor is blocked on authentication during a remote server-update resume. Permission and configuration blocks stay idle.

Why

A restarted remote server can reject the first environment credential. The supervisor then parks in blocked, and the resume loop used to stop nudging because it only watched backoff. Recovery could sit until the four-minute timeout.

This ports upstream pingdotgg/t3code#7953 and keeps the existing one-second pacing and four-minute resume lifetime.

Scope

  • packages/client-runtime/src/state/server.ts. Widen the nudge stream type and admit phase === "blocked" only when lastFailure?.reason === "authentication".
  • packages/client-runtime/src/state/server.test.ts. Helper filter test plus a command-boundary test of createServerEnvironmentAtoms(...).updateServer.

Out of scope: credential storage, authorization policy, supervisor retry policy, contracts, server, UI.

Closes#134

Tradeoffs

Retrying every blocked reason would hide real setup failures. The filter admits only authentication.

Blast Radius

Web, desktop, and mobile share this client-runtime command. Remote update resume is the only new retry path. Idle blocked permission and configuration behavior is unchanged.

Verification

  • vp test run packages/client-runtime/src/state/server.test.ts (15 passed)
  • vp run --filter @kata-sh/code-client-runtime typecheck (exit 0)
  • Identity grep of the diff for @t3tools/, T3CODE_, t3@, t3code, pingdotgg/t3code (no matches)

Build report: #134 (comment)

Acceptance criteria matrix

Full matrix: #134 (comment)

CriterionResultEvidence
Every backoff entry schedules one reconnect nudge after the existing pacing intervalPassHelper tests: 3 backoff entries, 3 nudges; TestClock pacing
An authentication-blocked state schedules one reconnect nudge after the existing pacing intervalPassupdateServer command-boundary test plus filter
Permission-blocked and configuration-blocked states schedule no reconnect nudgePassHelper streams permission, authentication, configuration; expects 1 retry
Retry loop stops when the update command settles, fails, or reaches its existing resume timeoutPassCommand test settles to idle. Fail and timeout paths not driven. Lifetime still forkChild plus timeoutOption (4 minutes)
Deterministic command test: transient auth block, ready event, success, idlePassrecovers the update command after a transient credential rejection
Focused client-runtime server tests and typecheck passPass15 tests, typecheck exit 0
Product diff preserves #127 Kata update copy and contains no new T3 identityPass@kata-sh/code-cli@ copy test; identity grep empty

Totals: 7 Pass / 0 Fail / 0 Blocked (acceptance checkboxes). Supplementary live remote update: Blocked (no disposable target).

Convergence: #134 (comment)

UI Changes

None.

Checklist

  • This PR is small and focused
  • I explained what changed and why
  • I included before/after screenshots for any UI changes
  • I included a video for animation/interaction changes
Open in WebOpen in Cursor

…te resume
A restarted remote server can reject the environment credential once and
leave the supervisor blocked. The update resume loop only nudged backoff,
so recovery stopped.
Admit authentication-blocked supervisor states on the same one-second
cadence as backoff. Permission and configuration failures stay blocked.
A command-boundary test drives the public updateServer path through that
transient block to a matching ready event.
Refs #134
Co-authored-by: Gannon Hall <gannonh@users.noreply.github.com>
@coderabbitai

coderabbitaiBot commented Aug 26, 2026

Copy link
Copy Markdown

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: d4649ab5-3006-449a-9c03-4ab0c2c9bd41


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@gannonh

Copy link
Copy Markdown
OwnerAuthor

@coderabbitai review

@coderabbitai

coderabbitaiBot commented Aug 26, 2026

Copy link
Copy Markdown
⚠️ Action not completed

Review rate limited.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

Co-authored-by: Gannon Hall <gannonh@users.noreply.github.com>

@chatgpt-codex-connectorchatgpt-codex-connectorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit:5f2875ccb6

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment threadpackages/client-runtime/src/state/server.ts
@gannonh
gannonh merged commit 10fd039 into mainAug 26, 2026
5 checks passed
@gannonh
gannonh deleted the cursor/recover-remote-update-auth-98e7 branch August 26, 2026 19:49
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Vendor-pull slice 3b: recover remote updates after credential rejection

2 participants

@gannonh@cursoragent
, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' fix(client-runtime): retry auth-blocked reconnects during server-update resume by gannonh · Pull Request #138 · gannonh/kata-code · GitHub
Skip to content

fix(client-runtime): retry auth-blocked reconnects during server-update resume - #138

Merged
gannonh merged 2 commits into
mainfrom
cursor/recover-remote-update-auth-98e7
Aug 26, 2026
Merged

fix(client-runtime): retry auth-blocked reconnects during server-update resume#138
gannonh merged 2 commits into
mainfrom
cursor/recover-remote-update-auth-98e7

Conversation

@gannonh

@gannonhgannonh commented Aug 26, 2026

Copy link
Copy Markdown
Owner

What Changed

nudgeReconnectDuringUpdateRestart now also retries when the connection supervisor is blocked on authentication during a remote server-update resume. Permission and configuration blocks stay idle.

Why

A restarted remote server can reject the first environment credential. The supervisor then parks in blocked, and the resume loop used to stop nudging because it only watched backoff. Recovery could sit until the four-minute timeout.

This ports upstream pingdotgg/t3code#7953 and keeps the existing one-second pacing and four-minute resume lifetime.

Scope

  • packages/client-runtime/src/state/server.ts. Widen the nudge stream type and admit phase === "blocked" only when lastFailure?.reason === "authentication".
  • packages/client-runtime/src/state/server.test.ts. Helper filter test plus a command-boundary test of createServerEnvironmentAtoms(...).updateServer.

Out of scope: credential storage, authorization policy, supervisor retry policy, contracts, server, UI.

Closes#134

Tradeoffs

Retrying every blocked reason would hide real setup failures. The filter admits only authentication.

Blast Radius

Web, desktop, and mobile share this client-runtime command. Remote update resume is the only new retry path. Idle blocked permission and configuration behavior is unchanged.

Verification

  • vp test run packages/client-runtime/src/state/server.test.ts (15 passed)
  • vp run --filter @kata-sh/code-client-runtime typecheck (exit 0)
  • Identity grep of the diff for @t3tools/, T3CODE_, t3@, t3code, pingdotgg/t3code (no matches)

Build report: #134 (comment)

Acceptance criteria matrix

Full matrix: #134 (comment)

CriterionResultEvidence
Every backoff entry schedules one reconnect nudge after the existing pacing intervalPassHelper tests: 3 backoff entries, 3 nudges; TestClock pacing
An authentication-blocked state schedules one reconnect nudge after the existing pacing intervalPassupdateServer command-boundary test plus filter
Permission-blocked and configuration-blocked states schedule no reconnect nudgePassHelper streams permission, authentication, configuration; expects 1 retry
Retry loop stops when the update command settles, fails, or reaches its existing resume timeoutPassCommand test settles to idle. Fail and timeout paths not driven. Lifetime still forkChild plus timeoutOption (4 minutes)
Deterministic command test: transient auth block, ready event, success, idlePassrecovers the update command after a transient credential rejection
Focused client-runtime server tests and typecheck passPass15 tests, typecheck exit 0
Product diff preserves #127 Kata update copy and contains no new T3 identityPass@kata-sh/code-cli@ copy test; identity grep empty

Totals: 7 Pass / 0 Fail / 0 Blocked (acceptance checkboxes). Supplementary live remote update: Blocked (no disposable target).

Convergence: #134 (comment)

UI Changes

None.

Checklist

  • This PR is small and focused
  • I explained what changed and why
  • I included before/after screenshots for any UI changes
  • I included a video for animation/interaction changes
Open in WebOpen in Cursor

…te resume
A restarted remote server can reject the environment credential once and
leave the supervisor blocked. The update resume loop only nudged backoff,
so recovery stopped.
Admit authentication-blocked supervisor states on the same one-second
cadence as backoff. Permission and configuration failures stay blocked.
A command-boundary test drives the public updateServer path through that
transient block to a matching ready event.
Refs #134
Co-authored-by: Gannon Hall <gannonh@users.noreply.github.com>
@coderabbitai

coderabbitaiBot commented Aug 26, 2026

Copy link
Copy Markdown

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: d4649ab5-3006-449a-9c03-4ab0c2c9bd41


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@gannonh

Copy link
Copy Markdown
OwnerAuthor

@coderabbitai review

@coderabbitai

coderabbitaiBot commented Aug 26, 2026

Copy link
Copy Markdown
⚠️ Action not completed

Review rate limited.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

Co-authored-by: Gannon Hall <gannonh@users.noreply.github.com>

@chatgpt-codex-connectorchatgpt-codex-connectorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit:5f2875ccb6

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment threadpackages/client-runtime/src/state/server.ts
@gannonh
gannonh merged commit 10fd039 into mainAug 26, 2026
5 checks passed
@gannonh
gannonh deleted the cursor/recover-remote-update-auth-98e7 branch August 26, 2026 19:49
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Vendor-pull slice 3b: recover remote updates after credential rejection

2 participants

@gannonh@cursoragent
, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' fix(client-runtime): retry auth-blocked reconnects during server-update resume by gannonh · Pull Request #138 · gannonh/kata-code · GitHub
Skip to content

fix(client-runtime): retry auth-blocked reconnects during server-update resume - #138

Merged
gannonh merged 2 commits into
mainfrom
cursor/recover-remote-update-auth-98e7
Aug 26, 2026
Merged

fix(client-runtime): retry auth-blocked reconnects during server-update resume#138
gannonh merged 2 commits into
mainfrom
cursor/recover-remote-update-auth-98e7

Conversation

@gannonh

@gannonhgannonh commented Aug 26, 2026

Copy link
Copy Markdown
Owner

What Changed

nudgeReconnectDuringUpdateRestart now also retries when the connection supervisor is blocked on authentication during a remote server-update resume. Permission and configuration blocks stay idle.

Why

A restarted remote server can reject the first environment credential. The supervisor then parks in blocked, and the resume loop used to stop nudging because it only watched backoff. Recovery could sit until the four-minute timeout.

This ports upstream pingdotgg/t3code#7953 and keeps the existing one-second pacing and four-minute resume lifetime.

Scope

  • packages/client-runtime/src/state/server.ts. Widen the nudge stream type and admit phase === "blocked" only when lastFailure?.reason === "authentication".
  • packages/client-runtime/src/state/server.test.ts. Helper filter test plus a command-boundary test of createServerEnvironmentAtoms(...).updateServer.

Out of scope: credential storage, authorization policy, supervisor retry policy, contracts, server, UI.

Closes#134

Tradeoffs

Retrying every blocked reason would hide real setup failures. The filter admits only authentication.

Blast Radius

Web, desktop, and mobile share this client-runtime command. Remote update resume is the only new retry path. Idle blocked permission and configuration behavior is unchanged.

Verification

  • vp test run packages/client-runtime/src/state/server.test.ts (15 passed)
  • vp run --filter @kata-sh/code-client-runtime typecheck (exit 0)
  • Identity grep of the diff for @t3tools/, T3CODE_, t3@, t3code, pingdotgg/t3code (no matches)

Build report: #134 (comment)

Acceptance criteria matrix

Full matrix: #134 (comment)

CriterionResultEvidence
Every backoff entry schedules one reconnect nudge after the existing pacing intervalPassHelper tests: 3 backoff entries, 3 nudges; TestClock pacing
An authentication-blocked state schedules one reconnect nudge after the existing pacing intervalPassupdateServer command-boundary test plus filter
Permission-blocked and configuration-blocked states schedule no reconnect nudgePassHelper streams permission, authentication, configuration; expects 1 retry
Retry loop stops when the update command settles, fails, or reaches its existing resume timeoutPassCommand test settles to idle. Fail and timeout paths not driven. Lifetime still forkChild plus timeoutOption (4 minutes)
Deterministic command test: transient auth block, ready event, success, idlePassrecovers the update command after a transient credential rejection
Focused client-runtime server tests and typecheck passPass15 tests, typecheck exit 0
Product diff preserves #127 Kata update copy and contains no new T3 identityPass@kata-sh/code-cli@ copy test; identity grep empty

Totals: 7 Pass / 0 Fail / 0 Blocked (acceptance checkboxes). Supplementary live remote update: Blocked (no disposable target).

Convergence: #134 (comment)

UI Changes

None.

Checklist

  • This PR is small and focused
  • I explained what changed and why
  • I included before/after screenshots for any UI changes
  • I included a video for animation/interaction changes
Open in WebOpen in Cursor

…te resume
A restarted remote server can reject the environment credential once and
leave the supervisor blocked. The update resume loop only nudged backoff,
so recovery stopped.
Admit authentication-blocked supervisor states on the same one-second
cadence as backoff. Permission and configuration failures stay blocked.
A command-boundary test drives the public updateServer path through that
transient block to a matching ready event.
Refs #134
Co-authored-by: Gannon Hall <gannonh@users.noreply.github.com>
@coderabbitai

coderabbitaiBot commented Aug 26, 2026

Copy link
Copy Markdown

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: d4649ab5-3006-449a-9c03-4ab0c2c9bd41


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@gannonh

Copy link
Copy Markdown
OwnerAuthor

@coderabbitai review

@coderabbitai

coderabbitaiBot commented Aug 26, 2026

Copy link
Copy Markdown
⚠️ Action not completed

Review rate limited.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

Co-authored-by: Gannon Hall <gannonh@users.noreply.github.com>

@chatgpt-codex-connectorchatgpt-codex-connectorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit:5f2875ccb6

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment threadpackages/client-runtime/src/state/server.ts
@gannonh
gannonh merged commit 10fd039 into mainAug 26, 2026
5 checks passed
@gannonh
gannonh deleted the cursor/recover-remote-update-auth-98e7 branch August 26, 2026 19:49
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Vendor-pull slice 3b: recover remote updates after credential rejection

2 participants

@gannonh@cursoragent
, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })(); fix(client-runtime): retry auth-blocked reconnects during server-update resume by gannonh · Pull Request #138 · gannonh/kata-code · GitHub
Skip to content

fix(client-runtime): retry auth-blocked reconnects during server-update resume - #138

Merged
gannonh merged 2 commits into
mainfrom
cursor/recover-remote-update-auth-98e7
Aug 26, 2026
Merged

fix(client-runtime): retry auth-blocked reconnects during server-update resume#138
gannonh merged 2 commits into
mainfrom
cursor/recover-remote-update-auth-98e7

Conversation

@gannonh

@gannonhgannonh commented Aug 26, 2026

Copy link
Copy Markdown
Owner

What Changed

nudgeReconnectDuringUpdateRestart now also retries when the connection supervisor is blocked on authentication during a remote server-update resume. Permission and configuration blocks stay idle.

Why

A restarted remote server can reject the first environment credential. The supervisor then parks in blocked, and the resume loop used to stop nudging because it only watched backoff. Recovery could sit until the four-minute timeout.

This ports upstream pingdotgg/t3code#7953 and keeps the existing one-second pacing and four-minute resume lifetime.

Scope

  • packages/client-runtime/src/state/server.ts. Widen the nudge stream type and admit phase === "blocked" only when lastFailure?.reason === "authentication".
  • packages/client-runtime/src/state/server.test.ts. Helper filter test plus a command-boundary test of createServerEnvironmentAtoms(...).updateServer.

Out of scope: credential storage, authorization policy, supervisor retry policy, contracts, server, UI.

Closes#134

Tradeoffs

Retrying every blocked reason would hide real setup failures. The filter admits only authentication.

Blast Radius

Web, desktop, and mobile share this client-runtime command. Remote update resume is the only new retry path. Idle blocked permission and configuration behavior is unchanged.

Verification

  • vp test run packages/client-runtime/src/state/server.test.ts (15 passed)
  • vp run --filter @kata-sh/code-client-runtime typecheck (exit 0)
  • Identity grep of the diff for @t3tools/, T3CODE_, t3@, t3code, pingdotgg/t3code (no matches)

Build report: #134 (comment)

Acceptance criteria matrix

Full matrix: #134 (comment)

CriterionResultEvidence
Every backoff entry schedules one reconnect nudge after the existing pacing intervalPassHelper tests: 3 backoff entries, 3 nudges; TestClock pacing
An authentication-blocked state schedules one reconnect nudge after the existing pacing intervalPassupdateServer command-boundary test plus filter
Permission-blocked and configuration-blocked states schedule no reconnect nudgePassHelper streams permission, authentication, configuration; expects 1 retry
Retry loop stops when the update command settles, fails, or reaches its existing resume timeoutPassCommand test settles to idle. Fail and timeout paths not driven. Lifetime still forkChild plus timeoutOption (4 minutes)
Deterministic command test: transient auth block, ready event, success, idlePassrecovers the update command after a transient credential rejection
Focused client-runtime server tests and typecheck passPass15 tests, typecheck exit 0
Product diff preserves #127 Kata update copy and contains no new T3 identityPass@kata-sh/code-cli@ copy test; identity grep empty

Totals: 7 Pass / 0 Fail / 0 Blocked (acceptance checkboxes). Supplementary live remote update: Blocked (no disposable target).

Convergence: #134 (comment)

UI Changes

None.

Checklist

  • This PR is small and focused
  • I explained what changed and why
  • I included before/after screenshots for any UI changes
  • I included a video for animation/interaction changes
Open in WebOpen in Cursor

…te resume
A restarted remote server can reject the environment credential once and
leave the supervisor blocked. The update resume loop only nudged backoff,
so recovery stopped.
Admit authentication-blocked supervisor states on the same one-second
cadence as backoff. Permission and configuration failures stay blocked.
A command-boundary test drives the public updateServer path through that
transient block to a matching ready event.
Refs #134
Co-authored-by: Gannon Hall <gannonh@users.noreply.github.com>
@coderabbitai

coderabbitaiBot commented Aug 26, 2026

Copy link
Copy Markdown

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: d4649ab5-3006-449a-9c03-4ab0c2c9bd41


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@gannonh

Copy link
Copy Markdown
OwnerAuthor

@coderabbitai review

@coderabbitai

coderabbitaiBot commented Aug 26, 2026

Copy link
Copy Markdown
⚠️ Action not completed

Review rate limited.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

Co-authored-by: Gannon Hall <gannonh@users.noreply.github.com>

@chatgpt-codex-connectorchatgpt-codex-connectorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit:5f2875ccb6

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment threadpackages/client-runtime/src/state/server.ts
@gannonh
gannonh merged commit 10fd039 into mainAug 26, 2026
5 checks passed
@gannonh
gannonh deleted the cursor/recover-remote-update-auth-98e7 branch August 26, 2026 19:49
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Vendor-pull slice 3b: recover remote updates after credential rejection

2 participants

@gannonh@cursoragent