Skip to content

fix(quota): retry Antigravity summary 403 with compatibility UA - #5976

Closed
RHODIZSECURITY wants to merge 1 commit into
lidge-jun:devfrom
RHODIZSECURITY:fix/antigravity-quota-403-compat-20260926
Closed

RHODIZSECURITY wants to merge 1 commit into
lidge-jun:devfrom
RHODIZSECURITY:fix/antigravity-quota-403-compat-20260926

Conversation

@RHODIZSECURITY

@RHODIZSECURITY RHODIZSECURITY commented Sep 26, 2026 •

Copy link
Copy Markdown
Contributor

Closes #5940.

Some valid Google Antigravity OAuth identities return HTTP 403 from retrieveUserQuotaSummary only when the quota probe uses the current IDE User-Agent. The same bearer and project succeed with the legacy Antigravity client family.

This change retries the canonical quota-summary endpoint exactly once on 403 with User-Agent: antigravity/1.0.

Safety boundaries:

  • 401 remains terminal and is not retried.
  • Inference/model-discovery fingerprints are unchanged.
  • The retry remains on the same canonical fixed destination.
  • Existing redirect and outbound-destination protections stay intact.

Validation on current dev:

  • focused quota suites: 237 pass / 0 fail / 990 assertions
  • bun x tsc --noEmit: PASS
  • live five-account pool after the fix: 5/5 quota rows available, 0 unavailable

No credentials, raw account identifiers, or private provider payloads are included.

Review readiness checklist

This PR stays in draft until every box below is ticked. Tick all four boxes once the requirements are met:

  • Required local validation passed; commands, results, and any full-suite exception are documented.

  • I pushed my PR to a recent dev commit (at most 10 behind; a maintainer may still ask for the exact tip before merge).

  • I resolved all correct Codex and CodeRabbit findings.

  • My PR is ready for review.

Summary by CodeRabbit

  • Bug Fixes
    • Improved Antigravity quota checks when the service returns a forbidden response, allowing a single retry to retrieve usage information.
    • Kept unauthorized responses as access-denied failures without retrying.

@coderabbitai

coderabbitai Bot commented Sep 26, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository: lidge-jun/opencodex/.coderabbit.yaml

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 6e7f9ef7-9954-45cd-aa03-00f29b8a02d6

📥 Commits

Reviewing files that changed from the base of the PR and between 6581b56 and 18847f6.

📒 Files selected for processing (3)
  • src/providers/quota/antigravity.ts
  • tests/providers/provider-account-quota.test.ts
  • tests/providers/provider-quota.test.ts

Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 9 remain after this review.


📝 Walkthrough

Walkthrough

The Antigravity quota probe now retries a quota-summary request once with a compatibility User-Agent when the initial response is HTTP 403. It does not retry HTTP 401. Tests cover both response paths and update request-count expectations.

Changes

Antigravity quota summary

Layer / File(s) Summary
403 compatibility retry
src/providers/quota/antigravity.ts, tests/providers/provider-account-quota.test.ts, tests/providers/provider-quota.test.ts
antigravity.ts:170-180 adds the antigravity/1.0 compatibility User-Agent. At 267-286, the probe retries once with that User-Agent after HTTP 403, best-effort cancels the first response body, and checks the retry for redirects. HTTP 401 is not retried. The account-quota tests at 743-802 cover the 403 and 401 paths; expectations at 991 and provider-quota.test.ts:3560 account for the additional 403 request.

Priority: ➖ Normal

Estimated code review effort: 3 (Moderate) | ~20 minutes

Change: Bug fix · Severity of issue fixed: Medium

Suggested reviewers: lidge-jun

Merge Risk: ⚪ Minimal · up to 18847

The quota compatibility retry is ready for normal merge checks; no issue requiring a pre-merge fix was identified.

Security Architecture Review

Security architecture risk: 🔵 Low · up to 18847

The retry keeps the same account credentials and fixed provider destination, with no identified credential-exposure path. A failure during the retry can, however, change a denied quota result into a fallback result; that behavior has not been validated for retry failures.

Retained concerns

  • Low · reliability · inferred: If the compatibility request throws after an initial 403, the probe can query the models endpoint and report available quota rather than preserving the initial access-denied outcome. Whether this exception path is intended is unresolved.
Security review details

Security Blast Radius

  • inferred — The additional authenticated request is bounded to the same provider summary endpoint and the account being probed; no new credential recipient or caller-selected outbound destination was identified in this path.

Trust Boundaries and Controls

  • observed — The changed request retains the existing outbound wrapper and checks redirects on both attempts. It changes the provider-facing User-Agent, not the bearer or project binding.

Resilience and Maintainability Implications

  • inferred — The exception path does not preserve the initial 403 as a terminal quota outcome. The evidence does not establish that models fallback after a failed compatibility retry is an intended denial policy.

Hardening Proposals

  • proposed — Specify the desired result when the compatibility retry times out or throws after a 403, and exercise that outcome with a focused test before relying on fallback behavior.
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 66.67% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 3 functions across 3 files. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely describes the main change: retrying the Antigravity quota-summary request with a compatibility User-Agent after HTTP 403.
Linked Issues check ✅ Passed The implementation in src/providers/quota/antigravity.ts adds ANTIGRAVITY_QUOTA_COMPAT_USER_AGENT and retries ANTIGRAVITY_QUOTA_SUMMARY_URL exactly once when the first response has status 403. T…
Out of Scope Changes check ✅ Passed The reported change set contains one quota implementation change in src/providers/quota/antigravity.ts and focused quota test updates in tests/providers/provider-account-quota.test.ts and `tests/p…
  • Fix all pre-merge checks with AI
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

Copy link
Copy Markdown
Contributor

✅ Deterministic PR hygiene checks passed.

@github-actions github-actions Bot added the bug Something isn't working label Sep 26, 2026
@github-actions

github-actions Bot commented Sep 26, 2026 •

Copy link
Copy Markdown
Contributor

⏳ DRAFT

  • review readiness checklist open (0/4 boxes ticked).

What to do

  • Tick all four boxes in the PR description once you're done (currently 0/4).

Review readiness checklist

  • ⬜ Required local validation passed; commands, results, and any full-suite exception are documented.
  • ⬜ I pushed my PR to a recent dev commit (at most 10 behind; a maintainer may still ask for the exact tip before merge).
  • ⬜ I resolved all correct Codex and CodeRabbit findings.
  • ⬜ My PR is ready for review.

0/4 boxes ticked.

This PR stays in draft until every box above is ticked.

Copy link
Copy Markdown
Contributor Author

@coderabbitai review

@coderabbitai

coderabbitai Bot commented Sep 26, 2026 •

Copy link
Copy Markdown
Contributor
✅ Action performed

Review finished.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@lidge-jun

Copy link
Copy Markdown
Owner

리뷰 · 우선순위 60 / 80

안티그래비티 계정 중에는 로그인과 추론은 되는데, 사용량만 거절되는 계정이 있습니다. 지금 프로그램 이름으로 사용량 요약을 물어보면 서버가 403을 줍니다. 같은 로그인 토큰과 같은 프로젝트로, 옛 이름 antigravity/1.0을 붙여 같은 주소에 다시 보내면 사용량이 돌아옵니다. 이 PR은 그 한 번을 넣습니다. 요약 주소가 403일 때만 첫 응답을 버리고, 같은 고정 주소로 옛 이름을 붙여 한 번 더 보냅니다. 두 번째도 401이거나 403이면 접근 거절입니다. 처음부터 401이면 다시 보내지 않습니다. 추론과 모델 찾기는 지금 이름을 그대로 씁니다. 주소가 다른 곳으로 넘어가려 하면 두 번째 요청도 막습니다. 이슈 #5940을 닫습니다. 바탕은 dev입니다. types.ts와 config.ts를 나누는 변경은 아닙니다.

라인 - src/providers/quota/antigravity.ts 284줄. 두 번째 요청이 8초 안에 끝나지 않거나 네트워크 오류로 예외가 나면, 292줄이 그 예외만 기억합니다. 처음의 403은 사라집니다. 297줄 모델 목록 조회로 넘어갑니다. 모델 목록이 성공하면 308줄에서 사용량이 있는 계정으로 보고합니다. 이 변경 전에는 요약 403에서 바로 접근 거절로 끝났고, 모델 목록은 보지 않았습니다.

라인 - 같은 함수 287줄. 두 번째 응답이 성공(200)도 아니고 401·403도 아니면, 함수는 그 try를 그냥 나옵니다. 실패 이유는 비어 있습니다. 역시 모델 목록으로 넘어가고, 목록이 성공하면 사용량이 있는 것처럼 보입니다. 새 테스트는 403 다음에 200이 오는 경우와, 401은 다시 보내지 않는 경우만 확인합니다. 두 번째가 실패하는 경우는 없습니다.

메인테이너의 판단이 필요한 지점

같은 수정의 열린 PR이 이미 있습니다. #5943(fix/issue-5940-antigravity-quota-403, 작성자 codingbooo)도 403일 때 antigravity/1.0으로 요약을 한 번 더 보냅니다. 초안이 아니고, 이 PR보다 먼저 열렸습니다. 둘 다 넣으면 안 됩니다. 어느 쪽을 남길지 정하면 됩니다. 두 번째 요청이 실패했을 때 접근 거절로 끝낼지, 모델 목록 사용량을 보여줄지도 같이 정하면 됩니다. 이 PR은 아직 초안이고, 설명의 준비 체크 4칸은 비어 있습니다.

너의 추천

403일 때만 같은 주소로 한 번 더 보내는 방향은 맞습니다. 401을 다시 보내지 않는 것도 맞습니다. 두 번째가 예외이거나 401·403이 아닌 오류이면, 모델 목록으로 사용량을 만들기 전에 접근 거절로 끝내는 쪽을 추천합니다. 그 경우를 테스트로 하나 넣으면 됩니다. #5943과 이 PR 중 하나만 머지하면 됩니다. 이 PR은 이름 상수와 403·401 테스트가 더 분명합니다. 위의 실패 처리를 고친 뒤 이쪽을 남기고 #5943을 닫아도 됩니다. 바탕이 이미 dev라서 옮길 이유는 없습니다. types.ts/config.ts 분할 때문에 이 PR을 닫을 이유도 없습니다.

이 댓글은 grok-bot이 작성했습니다

lidge-jun added a commit that referenced this pull request Sep 26, 2026
| PR | Change | Author |
| --- | --- | --- |
| #5968 | Revalidate context relay admission against the live hub-link key policy before dispatch. | luvs01 |
| #5966 | Start the link tunnel supervisor only after the listener owns a bound target, and start it after issue recovery. | luvs01 |
| #5933 | Honor an explicitly configured Devin reset wait while preserving stream heartbeats and bounded retry behavior. | luvs01 |
| #5952 | Expand measured Command Code effort ladders. | codingbooo |
| #5942 | Project Claude input estimates onto the settled wire and canonical combo target. | moseoridev |
| #5943 | Retry a quota-summary 403 once on the same fixed Antigravity endpoint with the legacy User-Agent. | codingbooo |

Integration commits add a real delayed-body hub-link revocation regression; a failed-bind and recovered-bind supervisor regression; the first rejected Command Code send retry; and explicit layout registrations for the Devin cooldown and Claude projection tests. The Claude source PR already records `targetRoute.modelId` and includes the combo-alias regression; reverting that line makes the alias case fail.

Review follow-up: the DeepSeek V4 Flash DSH/ZCode export expectations now match all five calibrated efforts. Devin combo children now bypass the optional stated-reset wait and surface their pre-output refusal, so the combo can advance promptly; standalone opted-in turns retain reset waiting and heartbeats. The delayed-reset combo and real Devin adapter regressions were red before the fix and green after it.

The alternate Antigravity 403 PR (#5976) was left out because the included implementation covers the same retry with more extensive tests for bearer/project identity, cancellation failure, retry bounds, redirects, and fallback. No code was taken from that alternative.

Independent security review is requested before merge for link admission and tunnel startup (`src/server/index/serve-options.ts`, `src/server/index/optional-listeners.ts`, `src/server/index/link-listener.ts`, `src/server/management/link-routes.ts`), Devin wait/replay (`src/adapters/devin.ts`, `src/adapters/devin/cloud-direct/stated-reset-retry.ts`, `src/adapters/run-turn-queue.ts`, `src/server/responses/run-turn-execution.ts`), and the credential-bearing Antigravity retry (`src/providers/quota/antigravity.ts`).

Co-authored-by: Epinephrine <luvs01@hanmail.net>
Co-authored-by: luvs01 <27862058+luvs01@users.noreply.github.com>
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Co-authored-by: codingbo <cnsdbo@163.com>
Co-authored-by: moseoridev <sjssjs1344@gmail.com>
@lidge-jun

Copy link
Copy Markdown
Owner

Closing as superseded: #5943 carried the same Antigravity quota-summary 403 retry to dev through bug-PR merge train batch 9C, #5987 (merge 81aea0f). The build lane compared the two and took #5943 for its broader negative-path coverage; no code from this PR was reused. Thanks for the fix.

@lidge-jun lidge-jun closed this Sep 26, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants