Skip to content

fix(runtime): surface provider HTTP rejections instead of RUNTIME_FINAL_ERROR - #121

Merged
drewstone merged 1 commit into
mainfrom
fix/runtime-final-error-provider-status-20261006
Oct 6, 2026
Merged

drewstone merged 1 commit into
mainfrom
fix/runtime-final-error-provider-status-20261006

Conversation

@drewstone

Copy link
Copy Markdown
Contributor

Problem

The Release Live Evidence runs 37391592677 (Oct 6) and 36551284049 (Sep 29) failed live-tangle with only error="RUNTIME_FINAL_ERROR". run-event-mapper passed every final error through safeDiagnostic, which collapses any free-text message to that bare code.

Root cause of the live failure (configuration, not code)

  • The Router access log on origin nbg1 shows the CI request at 2026-10-06T00:00:51Z (x-tangle-client: braid/0.3.4, from a GitHub Actions IP). The Router returned 401, a 90-byte body that matches {"error":{"message":"Invalid API key","type":"authentication_error","code":"invalid_key"}} exactly. The Sep 29 attempts got the same 401. The last braid client 200 was on 2026-09-27 at 05:42Z.
  • The credential in release-live/BRAID_LIVE_TANGLE_ENV_JSON (last updated 2026-09-27T04:22Z) is now rejected by Platform. chore(release): remove temporary model probe #117 already recorded the same 401 invalid_key on Sep 29.
  • Run locally, the same check with a valid key passes, both from the build and from the packed npm tarball. With an invalid key it reproduces the exact CI signature.

Change

  • Added providerHttpFailureDiagnostic, which turns runtime's router <status>: <body> message into a public diagnostic, for example RUNTIME_PROVIDER_UNAUTHORIZED: provider returned HTTP 401 (authentication_error/invalid_key). Only the status and the provider's own type and code tokens survive. Tokens that look like credentials are dropped, and free text never reaches state.
  • The classifier now applies to final errors, backend_error, and the reconnect and replay terminal paths.
  • With this change, the local invalid-key reproduction now reports the classified 401 instead of the bare code.

Validation

  • Ran pnpm install --frozen-lockfile and the full pnpm check: both pass.
  • Added regression tests in test/application.test.ts.
  • An independent review found that credential-shaped tokens could leak, that the reconnect path was missing, plus anchoring and nested-body problems. All are fixed; the re-review found nothing blocking.

🤖 Generated with Claude Code

…AL_ERROR

The protected live-tangle check failed with only RUNTIME_FINAL_ERROR. The
runtime's real message was a Router 401 invalid_key, but the run-event mapper
reduced every free-text final error to the bare code.

Classify Router HTTP failures into a public diagnostic that keeps the status
class, HTTP status, and the provider's own error type and code tokens. Tokens
that look like credentials are dropped, and provider free text still never
reaches durable state. The same classifier now covers backend_error events and
the reconnect and replay terminal paths.

@tangletools tangletools left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Auto-approved PR — f6137c69

Blanket team auto-approval is intentional. This is not a code review.
No automated review runs on this PR. This approval rests on the rule above alone.

tangletools · auto-approval · reason: blanket_auto_approve · 2026-10-06T00:57:51Z

@drewstone
drewstone merged commit 84f1442 into main Oct 6, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants