Conversation
Validate profiles without inheriting runtime retries and reject exhausted budgets or quotas while preserving recoverable rate limits. Cover the real provider transport and authenticated HTTP endpoint, including safe subscription quota diagnostics. Co-authored-by: openhands <openhands@all-hands.dev>
Contributor
|
📁 PR Artifacts Notice This PR contains a |
Author
|
@VascoSch92 local checks pass. please approve the fork ci run. |
2 of 6 tasks
1 of 2 tasks
ak684
approved these changes
Sep 25, 2026
ak684
left a comment
Contributor
There was a problem hiding this comment.
No blocking code findings. All 126 profile tests and the authenticated HTTP regression passed locally. I also tested this with #5309 and managed-key recovery: 202 focused tests plus the HTTP regression passed. The author still needs to complete the HUMAN note and mark this ready; required CI remains pending.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
HUMAN:
AGENT:
Why
Profile validation currently accepts an exhausted-budget 429 as valid after inheriting the profile's runtime retry policy. A live HTTP reproduction made 15 provider POSTs before returning
valid=true.Summary
Issue Number
Fixes #5100
How to Test
Results: 2,198 Agent Server tests passed; 510 cross-package tests passed with one existing skip; 13 stress tests passed. All repository-wide pre-commit checks (including Pyright) and the package build passed. Independent review and subscription-token re-verification found no remaining material issues. Additional local CI guards passed: deterministic OpenAPI export, schema quality and Swagger validation, deprecation deadlines, persisted-settings compatibility (14 fixtures and eight payloads from published v1.49.1), and REST compatibility using oasdiff 1.19.1 (no breaking changes or additive response type widenings).
TMPDIR=/tmpavoids the macOS tmux socket-path limit encountered with the default temporary directory.The focused end-to-end reproduction is:
This starts a real authenticated Agent Server and a loopback HTTP provider. Without mocking LiteLLM or the SDK, the provider returns
429withtype: budget_exceeded. Before the fix the endpoint returnedvalid=trueafter 15 provider POSTs; after the fix it returnsvalid=false, a redactedLLMRateLimitError, and exactly one provider POST. The credential is synthetic and no paid inference is used.Video/Screenshots
This is a headless API change. Before/after reproduction and validation evidence.
Design Doc
Scope and acceptance criteria.
Type
Notes
The deadline bounds the endpoint's wait; an OAuth refresh already executing in a worker thread cannot itself be forcibly stopped. The request/response schema and runtime retry defaults are unchanged. All validation reported in AGENT was performed by coding agents. This draft retains the template's HUMAN placeholder for a human contributor to complete before review starts.