Skip to content

fix(providers): retry Antigravity quota summary once with legacy UA on 403 - #5943

Closed
codingbooo wants to merge 1 commit into
lidge-jun:devfrom
codingbooo:fix/issue-5940-antigravity-quota-403
Closed

codingbooo wants to merge 1 commit into
lidge-jun:devfrom
codingbooo:fix/issue-5940-antigravity-quota-403

Conversation

@codingbooo

@codingbooo codingbooo commented Sep 26, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Fixes #5940 by adding a one-time compatibility retry with User-Agent: antigravity/1.0 when v1internal:retrieveUserQuotaSummary returns HTTP 403 on a valid Google Antigravity OAuth account.

Changes

  • In src/providers/quota/antigravity.ts:
    • When retrieveUserQuotaSummary returns HTTP 403, cancels the first response body and retries the exact accounting endpoint once with User-Agent: antigravity/1.0, preserving the bearer token and project payload.
    • HTTP 401 is not retried and remains an authentication failure.
    • Redirect errors remain blocked.
    • Inference and discovery user agents remain strictly unchanged.
  • Added comprehensive unit tests in tests/providers/provider-antigravity-quota-retry.test.ts covering 403 retry, body release, 401 non-retry, and fallback.
  • Updated documentation in providers.md and transport inventory.

Verification

  • bun run typecheck: clean 0 errors.
  • bun test tests/providers/provider-antigravity-quota-retry.test.ts: 10 pass, 0 fail.
  • bun test tests/providers/provider-account-quota.test.ts tests/providers/provider-quota.test.ts: 235 pass, 0 fail.

Checklist

  • I have tested my changes locally.
  • I have updated relevant documentation / tests.
  • I have followed the project's code style and contributing guidelines.

Review readiness checklist

This PR stays in draft until every box below is ticked. Tick all four boxes once the requirements are met:

  • Required local validation passed; commands, results, and any full-suite exception are documented.

  • I pushed my PR to a recent dev commit (at most 10 behind; a maintainer may still ask for the exact tip before merge).

  • I resolved all correct Codex and CodeRabbit findings.

  • My PR is ready for review.

Summary by CodeRabbit

  • Bug Fixes

    • Antigravity quota checks now retry once with a legacy User-Agent after an HTTP 403, while keeping the same account credentials and project. HTTP 401 responses are not retried.
    • If the retry does not provide a usable quota summary, the existing model-based fallback remains available. Discovery and inference behavior is unchanged.
  • Documentation

    • Updated provider configuration and transport references to describe the retry behavior.

@github-actions

Copy link
Copy Markdown
Contributor

✅ Deterministic PR hygiene checks passed.

@github-actions github-actions Bot added the bug Something isn't working label Sep 26, 2026
@coderabbitai

coderabbitai Bot commented Sep 26, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository: lidge-jun/opencodex/.coderabbit.yaml

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 8855aba9-b592-47d4-9fe3-43cdb1001544

📥 Commits

Reviewing files that changed from the base of the PR and between bb3f3c2 and e9ba84b.

📒 Files selected for processing (8)
  • docs-site/src/content/docs/reference/configuration/providers.md
  • scripts/test-layout/layout.json
  • src/providers/quota/antigravity.ts
  • structure/transports/inventory.md
  • tests/fixtures/test-layout-expected.json
  • tests/providers/provider-account-quota.test.ts
  • tests/providers/provider-antigravity-quota-retry.test.ts
  • tests/providers/provider-quota.test.ts

Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 8 remain after this review.


📝 Walkthrough

Walkthrough

The Antigravity quota probe now retries a quota-summary request once with User-Agent: antigravity/1.0 after HTTP 403. It preserves the bearer token, project, and endpoint. HTTP 401 is not retried. Tests and documentation cover the behavior.

Changes

Antigravity quota retry

Layer / File(s) Summary
Quota-summary retry and validation
src/providers/quota/antigravity.ts, tests/providers/provider-antigravity-quota-retry.test.ts, tests/providers/provider-account-quota.test.ts, tests/providers/provider-quota.test.ts, docs-site/src/content/docs/reference/configuration/providers.md, structure/transports/inventory.md, scripts/test-layout/layout.json, tests/fixtures/test-layout-expected.json
On HTTP 403, the quota probe best-effort cancels the response body and retries the same summary endpoint with antigravity/1.0. Tests cover request identity, cancellation failure, non-retry statuses, retry outcomes, and models fallback. The documentation describes the retry, and the test-layout mappings include the new test.

Priority: ➖ Normal

Estimated code review effort: 3 (Moderate) | ~20 minutes

Change: Bug fix · Severity of issue fixed: Medium

Merge Risk: ⚪ Minimal · up to e9ba8

The quota retry is bounded to one attempt and preserves the request identity and transport path. No actionable merge-blocking risk was identified; the change appears mergeable with normal checks.

Security Architecture Review

Security architecture risk: 🔵 Low · up to e9ba8

The retry is limited to Antigravity quota accounting and keeps the same credential, project, destination, and outbound protections. A stalled response-body cancellation could, however, prevent quota recovery from completing.

Retained concerns

  • Low · reliability · inferred: A 403 response whose body-cancellation promise does not settle can block the retry and the existing models fallback, leaving the quota probe pending.
Security review details

Security Blast Radius

  • inferred — The additional credential-bearing request is confined to one retry per quota-probe invocation against the same account-quota endpoint; the reviewed code does not add a destination chosen by the quota caller.

Trust Boundaries and Controls

  • observed — The retry uses the existing outbound boundary rather than a direct fetch. Its built-in path retains destination resolution and pinned direct POST handling, or configured proxy routing, with redirects handled manually.

Resilience and Maintainability Implications

  • inferred — A cancellation that rejects permits the retry, as tested. A cancellation that remains pending has no separate bound in this transition and can prevent the fallback path from being reached.

Hardening Proposals

  • proposed — Define a bounded cancellation and connection-release policy for the denied response so a stalled cleanup cannot indefinitely prevent retry or fallback.
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 25.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 4 functions across 4 files. (4 skipped: 4… Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Linked Issues check ✅ Passed Issue #5940 requires one retry of the canonical quota-summary request after HTTP 403. src/providers/quota/antigravity.ts implements this in probeAntigravityUsageQuota: it cancels the first respons…
Out of Scope Changes check ✅ Passed The changes remain within Issue #5940. The source change implements the quota-summary compatibility retry. The new tests verify the retry, security behavior, and fallback behavior. The updates to `doc…
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely describes the main change: retrying the Antigravity quota summary request once with the legacy User-Agent after HTTP 403.
Full details: Docstring Coverage

Explanation

Docstring coverage is 25.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 4 functions across 4 files. (4 skipped: 4 unsupported.)

  • Fix all pre-merge checks with AI
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

github-actions Bot commented Sep 26, 2026 •

Copy link
Copy Markdown
Contributor

✅ READY

  • all PR quality gates passed; the review readiness checklist is complete.

Review readiness checklist

  • ✅ Required local validation passed; commands, results, and any full-suite exception are documented.
  • ✅ I pushed my PR to a recent dev commit (at most 10 behind; a maintainer may still ask for the exact tip before merge).
  • ✅ I resolved all correct Codex and CodeRabbit findings.
  • ✅ My PR is ready for review.

✅ 4/4 boxes ticked.

This pull request is already Ready for Review.
The review-ready label marks this PR as ready; review automation runs independently.
Maintainers: @lidge-jun @Ingwannu

@github-actions
github-actions Bot marked this pull request as draft September 26, 2026 13:24
@codingbooo
codingbooo marked this pull request as ready for review September 26, 2026 13:26
@github-actions
github-actions Bot marked this pull request as draft September 26, 2026 13:26
@codingbooo
codingbooo marked this pull request as ready for review September 26, 2026 13:28
@lidge-jun

Copy link
Copy Markdown
Owner

리뷰 · 우선순위 44 / 80

구글 Antigravity 계정은 로그인이 되는데, 사용량만 403으로 막히는 경우가 있습니다. 프로그램이 요청에 붙이는 이름(User-Agent)이 IDE 모양이기 때문입니다. 그 이름만 antigravity/1.0으로 바꾸면, 같은 로그인 토큰과 같은 프로젝트로 사용량이 나옵니다.

이 PR은 사용량 요약 주소가 403일 때 그 주소만 한 번 더 부릅니다. 두 번째 요청의 이름만 예전 이름입니다. 토큰과 프로젝트는 그대로입니다. 401은 다시 부르지 않습니다. 두 번째도 401이나 403이면 사용 불가로 끝냅니다. 두 번째가 다른 오류면, 모델 목록으로 넘어가는 예전 길은 남습니다. 답을 만드는 요청과 모델 찾기의 이름은 바꾸지 않습니다.

바탕 브랜치는 dev입니다. types.ts와 config.ts를 나누는 일이 아닙니다. 열려 있는 #5099도 403을 다루지만, 그건 다른 계정으로 넘기는 작업입니다.

라인 - src/providers/quota/antigravity.ts:268. 403이 오면 응답 본문의 cancel()이 끝날 때까지 기다립니다. 던진 오류는 무시합니다. 끝나지 않으면 계속 기다립니다. 프록시 없이 구글 주소로 직접 붙는 길은 src/lib/pinned-http.ts:244에서 200이 아닌 응답의 본문을 이미 버리고 연결을 끊습니다. 그때 본문이 없어서 이 기다림은 지나갑니다. 프록시를 타는 fetch는 403 본문이 남아 있습니다. 그 cancel()이 안 끝나면, 예전 이름으로 다시 부르는 일과 모델 목록으로 넘어가는 일이 시작되지 않습니다. 새 테스트는 cancel()이 오류를 던지는 경우만 확인합니다.

라인 - src/providers/quota/antigravity.ts:272. 다시 부른 결과가 401이나 403이면 바로 돌아갑니다. 그 본문은 닫지 않습니다. 바로 위의 리다이렉트 검사는 본문을 닫습니다. 프록시 길에서는 거절된 두 번째 응답이 연결을 붙잡고 있을 수 있습니다.

메인테이너의 판단이 필요한 지점

권한이 정말 없는 계정도 403이면 요청이 한 번 더 나갑니다. 코드는 이름 때문에 막힌 것과 권한이 없는 것을 미리 나누지 못합니다. 이슈 #5940은 그 한 번을 허용합니다.

antigravity/1.0은 src/adapters/client-fingerprint.ts에 이름이 없습니다. 그 파일은 짧은 antigravity 이름을 답을 만드는 요청에 쓰면 안 된다고 적습니다. 이번 재시도는 사용량 요약에만 붙습니다.

#5099는 같이 닫을 PR이 아닙니다.

너의 추천

한 번 다시 부르는 수정은 두세요. 본문이 없으면 cancel()을 기다리지 마세요. 본문이 있으면 짧게만 기다리고, 늦으면 그대로 다시 부르세요. 272줄에서 401이나 403으로 끝날 때도 그 본문을 닫으세요. 다른 열린 PR은 닫지 마세요. 그 두 곳만 맞으면 머지해도 됩니다.

이 댓글은 grok-bot이 작성했습니다

lidge-jun added a commit that referenced this pull request Sep 26, 2026
| PR | Change | Author |
| --- | --- | --- |
| #5968 | Revalidate context relay admission against the live hub-link key policy before dispatch. | luvs01 |
| #5966 | Start the link tunnel supervisor only after the listener owns a bound target, and start it after issue recovery. | luvs01 |
| #5933 | Honor an explicitly configured Devin reset wait while preserving stream heartbeats and bounded retry behavior. | luvs01 |
| #5952 | Expand measured Command Code effort ladders. | codingbooo |
| #5942 | Project Claude input estimates onto the settled wire and canonical combo target. | moseoridev |
| #5943 | Retry a quota-summary 403 once on the same fixed Antigravity endpoint with the legacy User-Agent. | codingbooo |

Integration commits add a real delayed-body hub-link revocation regression; a failed-bind and recovered-bind supervisor regression; the first rejected Command Code send retry; and explicit layout registrations for the Devin cooldown and Claude projection tests. The Claude source PR already records `targetRoute.modelId` and includes the combo-alias regression; reverting that line makes the alias case fail.

Review follow-up: the DeepSeek V4 Flash DSH/ZCode export expectations now match all five calibrated efforts. Devin combo children now bypass the optional stated-reset wait and surface their pre-output refusal, so the combo can advance promptly; standalone opted-in turns retain reset waiting and heartbeats. The delayed-reset combo and real Devin adapter regressions were red before the fix and green after it.

The alternate Antigravity 403 PR (#5976) was left out because the included implementation covers the same retry with more extensive tests for bearer/project identity, cancellation failure, retry bounds, redirects, and fallback. No code was taken from that alternative.

Independent security review is requested before merge for link admission and tunnel startup (`src/server/index/serve-options.ts`, `src/server/index/optional-listeners.ts`, `src/server/index/link-listener.ts`, `src/server/management/link-routes.ts`), Devin wait/replay (`src/adapters/devin.ts`, `src/adapters/devin/cloud-direct/stated-reset-retry.ts`, `src/adapters/run-turn-queue.ts`, `src/server/responses/run-turn-execution.ts`), and the credential-bearing Antigravity retry (`src/providers/quota/antigravity.ts`).

Co-authored-by: Epinephrine <luvs01@hanmail.net>
Co-authored-by: luvs01 <27862058+luvs01@users.noreply.github.com>
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Co-authored-by: codingbo <cnsdbo@163.com>
Co-authored-by: moseoridev <sjssjs1344@gmail.com>
@lidge-jun

Copy link
Copy Markdown
Owner

Thanks! This landed on dev through bug-PR merge train batch 9C, #5987 (merge 81aea0f). Your change is one commit on dev with you as the author and a Co-authored-by trailer. Closing since the content is now on dev.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working review-ready

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants