Fix: rate limit real probe (#110)

* fix(rate-limit): real provider liveness probe instead of time-based stub

The rate-limit recovery sweeper cleared a provider and resumed parked agents
purely on elapsed time — _do_probe was a stub that always returned True once
the retry_after window passed, so it never confirmed the provider had actually
stopped rate-limiting us. Under a sustained limit that resumes agents straight
into another 429, re-parking them: avoidable churn.

Make the probe real. _do_probe now issues a free, unmetered liveness call —
Anthropic GET /v1/models or Ollama GET /api/tags — and treats any non-429
response as the limit having lifted. A 429 keeps the provider parked; a
network error keeps it parked too (retry next sweep). When the provider can't
be probed (no API key, or an unrecognized provider), it falls back to the
prior time-expiry optimism rather than stranding agents. _probe_target keeps
URL/header resolution separate and testable, and _do_probe stays a
monkeypatchable boundary so the existing sweep tests are unaffected.

Also drop two acceptance-criteria-number labels from comments in this file.

* chore(rate-limit): clear merged gate debt in rate-limit tests + deps lint

The rate-limit PR landed with ruff violations the full gate flags but the
authors' runs missed: test_rate_limit_sweep.py was unformatted, and
test_rate_limit_tracker.py had unsorted/unused imports and magic-value
comparisons. Format the sweep test, drop the dead imports, and bind the
magic comparison values to locals. Also strip acceptance-criteria-number
labels from comments/docstrings across the three rate-limit test files
(leaving genuine acceptance_criteria=[...] test data untouched), and add
api/deps.py to the PLC0415 per-file-ignore — it is the DI wiring hub and
defers a couple of service imports to call time to avoid import cycles,
the same rationale already applied to api/routes, runtime, and services.

* fix(rate-limit): resolve redis type errors in RateLimitStateTracker

A cold mypy run (the gate's true state — prior passes were warm-cache only)
flagged four redis-typing errors in rate_limit_tracker.py that the merge
missed: three unused type:ignore[type-arg] on redis.Redis, and an
aclose() the bundled redis type stub doesn't expose.

Drop the now-unused ignores, and close the scan client via
'async with redis.from_url(...) as r:' instead of a finally-block
aclose(). The context manager closes the client on exit using the modern
redis.asyncio API — no deprecated close(), no stub-missing aclose(), no
suppression. Extend the test's redis mock to model the async
context-manager protocol so it returns itself on enter.

* test(prompter): pass route='main_pm' in the product main-PM routing test

Pre-existing master failure, unrelated to the rate-limit work. The test is
named ...product_routes_to_main_pm and asserts team=MAIN_PM, but called
confirm_live_draft without a route, so it got the 'board' default — which
assigns the Product Owner and yields team=BOARD by design (the board-review
path keeps the root at team=board until the CEO approves). The Main-PM path
is selected with route='main_pm', exactly as the sibling
...main_pm_route_assigns_main_pm test does. Add the missing kwarg so the test
verifies the path it names; behaviour under test is unchanged.

* Updated uv.lock

* refactor(complexity): bring all rank-C blocks under the xenon B ceiling

The full quality gate's xenon step (--max-absolute B --max-modules A
--max-average A) failed on eight rank-C blocks plus the extraction module
average — debt the rate-limit and token-analytics merges deferred. Reduce
each by extracting cohesive helpers, behaviour unchanged:

- orchestrator._probe_one_provider: split into _too_early_to_probe,
  _on_probe_success, _on_probe_failure, _parked_agents_for.
- rate_limit_tracker.list_rate_limited_providers: extract _read_rate_limited_entry
  and a _decode helper.
- trigger_filter.decide_spawn: extract _stale_trigger_decision (drops the
  PLR0911 suppression too).
- ollama_embedder (embed_query, _embed_batch_sync, aembed_query,
  _embed_batch_async): share _rl_backoff / _map_embed_error / _log_429 /
  _sleep_connect_retry / _asleep_connect_retry; remove a dead post-loop guard
  in aembed_query.
- mentor._synthesize_answer: extract _select_system_prompt and
  _answer_from_response.
- indexes/base.ask: extract the 429-retried LLM call into _ask_llm.
- extraction.__init__: extract _compile_patterns so the module average
  lands at rank A.

xenon now exits 0; rate-limit, optimal_brain, extraction, and events suites
all green.

* chore(deps): drop obsolete types-redis stub; honor redis 8.0 inline types

types-redis 4.6 (typed for redis 4.x) shadowed redis 8.0's own inline types,
which both masked real annotation mismatches in stream_bus.py and forced
awkward workarounds elsewhere. The stale stub is why the mypy gate only ever
passed warm-cached: a cold run under the wrong stub disagreed with the code.

Remove types-redis (and its orphaned transitive stubs) so mypy uses redis's
shipped types. That surfaces that xreadgroup/xclaim return bytes-keyed records
while _handle_message is annotated str — the code already decodes bytes
defensively, so this is an annotation gap, not a runtime bug. Make the types
honest: cast each result to its concrete shape and decode the stream name and
message id to str at the dispatch boundary via a _to_str helper.

mypy roboco/ is now clean cold (247 files) against redis's real types; events
suite green.

* Updated uv.lock

* fix(workspace): install the dev extra so agents can run make quality

Agent workspaces were set up with plain `uv sync`, which installs only the
project's default dependency group (pytest) — not the `dev` *extra* where the
gate tools live (ruff, mypy, xenon, radon, vulture, bandit, deptry). So an
agent's .venv had pytest but no linters, and `make quality` died immediately
on `ruff: command not found`. Agents literally could not lint, type-check, or
complexity-check their own work, which is how format/mypy/xenon debt merged
unseen. Sync the `dev` extra (`uv sync --extra dev`) so the workspace gets the
full toolchain the setup's own docstring already promised.

* fix(panel): rate-limit endpoint shape + websocket path

Two panel-facing breakages from the rate-limit rework:

- GET /api/system/rate-limits returned a raw list, but the panel store reads
  response.entries — so `r.entries is not iterable` crashed the banner sync on
  page load. Return the panel's contract: a { entries: [...] } envelope whose
  items are camelCase {provider, affectedAgents, hitAt, resumeAt,
  retryAfterSeconds}, derived from the raw Redis state (resumeAt = hitAt +
  retryAfter).
- The rate-limit websocket hook passed "/ws/system" while getWebSocketUrl()
  already supplies the "/ws" base, producing the doubled "/ws/ws/system" URL.
  Pass "/system" to match the agents/channels/notifications hooks.

Note: the backend /ws/system endpoint itself does not yet exist (the rework
shipped the panel hook only); the REST fix keeps the banner correct on load
and reconnect until that endpoint is built.

* test(workspace): assert uv sync installs the dev extra

Follow the workspace setup change: the dependency-install command is now
`uv sync --extra dev` so the agent workspace gets the lint/type/complexity
toolchain. Update the three assertions that pinned the old `uv sync`.

* feat(ws): add /ws/system stream and bridge rate-limit events to the panel

The rate-limit rework shipped the panel's websocket hook but no backend: there
was no /ws/system endpoint and nothing forwarded RATE_LIMIT_HIT/LIFTED to a
socket, so the banner got no live updates.

Build the missing half:
- ConnectionManager grows a system-wide connection set with connect_system /
  broadcast_system, and disconnect() now clears it.
- A /ws/system websocket endpoint (operator stream, no per-agent keying) with
  the same connected + ping/pong lifecycle as the other streams.
- websocket_bridge subscribes RATE_LIMIT_HIT/LIFTED and forwards each to
  broadcast_system tagged with the type the panel switches on. Both events
  ride the same StreamEventBus singleton, and the subscriptions register
  before start_listening(), so the consumer reads their streams.

Pairs with the panel hook now passing '/system' (getWebSocketUrl supplies the
'/ws' base). Covered by handler, manager, and endpoint-lifecycle tests.

---------

Co-authored-by: Renn F <rennf93@users.noreply.github.com>
This commit is contained in:
Renzo F
2026-06-11 18:16:20 +02:00
committed by GitHub
co-authored by Renn F
parent 98e618c243
commit 303c2db289
23 changed files with 1069 additions and 658 deletions
+9 -2
View File
@@ -637,7 +637,12 @@ async def test_confirm_live_draft_main_pm_route_assigns_main_pm(
@pytest.mark.asyncio
async def test_confirm_live_draft_product_routes_to_main_pm(db_session: Any) -> None:
"""A product-scoped live draft is a board-led coordination root (Main PM)."""
"""A product-scoped draft via the "Approve & Start" path is a Main-PM root.
The board path (the ``route="board"`` default) keeps the root at
``team=board`` until the CEO approves; the Main-PM path is selected
explicitly with ``route="main_pm"``.
"""
_project_id, ceo_id = await _seed_project_and_ceo(db_session)
product_id = uuid4()
product = ProductTable(
@@ -656,7 +661,9 @@ async def test_confirm_live_draft_product_routes_to_main_pm(db_session: Any) ->
"acceptance_criteria": ["works end to end"],
"team": "backend",
}
task_id = await service.confirm_live_draft(draft, ceo_id, product_id=product_id)
task_id = await service.confirm_live_draft(
draft, ceo_id, product_id=product_id, route="main_pm"
)
row = await db_session.get(TaskTable, task_id)
assert row.team == Team.MAIN_PM
assert row.product_id == product_id
+13 -15
View File
@@ -9,15 +9,11 @@ visible to a fresh instance.
from __future__ import annotations
import json
from typing import Any
from unittest.mock import AsyncMock, MagicMock
import pytest
from unittest.mock import AsyncMock
from roboco.services.gateway.rate_limit_tracker import RateLimitStateTracker
# ---------------------------------------------------------------------------
# Helpers
# ---------------------------------------------------------------------------
@@ -93,9 +89,10 @@ class TestActivateAndRead:
async def test_activate_stores_retry_after(self) -> None:
mock = _make_redis_mock()
tracker = _make_tracker(redis_mock=mock)
await tracker.activate(retry_after=30.0)
retry_after = 30.0
await tracker.activate(retry_after=retry_after)
state = await tracker.get_state()
assert state["retry_after"] == 30.0
assert state["retry_after"] == retry_after
async def test_activate_stores_affected_agents(self) -> None:
mock = _make_redis_mock()
@@ -132,10 +129,10 @@ class TestProbeFailures:
mock = _make_redis_mock()
tracker = _make_tracker(redis_mock=mock)
await tracker.activate()
await tracker.increment_probe_failures()
await tracker.increment_probe_failures()
count = await tracker.increment_probe_failures()
assert count == 3
increments = 3
for _ in range(increments):
count = await tracker.increment_probe_failures()
assert count == increments
async def test_reset_sets_zero(self) -> None:
mock = _make_redis_mock()
@@ -152,10 +149,10 @@ class TestProbeFailures:
# Tests: cross-reconnection persistence
# ---------------------------------------------------------------------------
#
# AC2: "State persists across client reconnection: a test writes state via
# State persists across client reconnection: a test writes state via
# activate(), creates a new RateLimitStateTracker instance pointing at the
# same Redis URL, calls is_rate_limited() and get_state() and gets back the
# same values — proving state survives a process restart."
# same values — proving state survives a process restart.
#
# We simulate this by sharing the same backing dict between two mock Redis
# clients — one injected into the first tracker and one injected into the
@@ -188,9 +185,10 @@ class TestStatePersistsAcrossReconnection:
async def test_get_state_survives_reconnection(self) -> None:
shared_store: dict[str, Any] = {}
retry_after = 45.0
mock_a = _make_redis_mock(initial_store=shared_store)
tracker_a = _make_tracker(provider="anthropic", redis_mock=mock_a)
await tracker_a.activate(retry_after=45.0, affected_agents=["be-dev-2"])
await tracker_a.activate(retry_after=retry_after, affected_agents=["be-dev-2"])
mock_b = _make_redis_mock(initial_store=mock_a._store)
tracker_b = RateLimitStateTracker(
@@ -200,7 +198,7 @@ class TestStatePersistsAcrossReconnection:
state = await tracker_b.get_state()
assert state["rate_limited"] is True
assert state["retry_after"] == 45.0
assert state["retry_after"] == retry_after
assert state["affected_agents"] == ["be-dev-2"]
async def test_clear_via_first_instance_visible_to_second(self) -> None:
@@ -59,7 +59,7 @@ def test_detect_python_project(tmp_path: Path) -> None:
commands = _detect_dep_commands(ws)
assert commands == [("uv sync", ["uv", "sync"])]
assert commands == [("uv sync --extra dev", ["uv", "sync", "--extra", "dev"])]
def test_detect_pnpm_project(tmp_path: Path) -> None:
@@ -103,7 +103,7 @@ def test_detect_monorepo_both_ecosystems(tmp_path: Path) -> None:
commands = _detect_dep_commands(ws)
assert ("uv sync", ["uv", "sync"]) in commands
assert ("uv sync --extra dev", ["uv", "sync", "--extra", "dev"]) in commands
assert ("pnpm install", ["pnpm", "install", "--frozen-lockfile"]) in commands
@@ -167,7 +167,7 @@ async def test_install_runs_detected_command(tmp_path: Path) -> None:
ran = await svc.install_dev_deps(ws)
assert ran is True
assert ["uv", "sync"] in captured
assert ["uv", "sync", "--extra", "dev"] in captured
assert (ws / _DEP_INSTALL_MARKER).is_file()