diff --git a/tests/agent/test_credential_pool_anthropic_refresh_race.py b/tests/agent/test_credential_pool_anthropic_refresh_race.py index 9d815c4e0e..e8420016ed 100644 --- a/tests/agent/test_credential_pool_anthropic_refresh_race.py +++ b/tests/agent/test_credential_pool_anthropic_refresh_race.py @@ -71,7 +71,7 @@ def _fake_pool_store(monkeypatch): """ store: Dict[str, list] = {} - def _write(provider, entries, *, removed_ids=None, status_cleared_ids=None): + def _write(provider, entries, *, removed_ids=None, status_cleared_ids=None, token_bases=None): store[provider] = list(entries) def _read(provider=None): diff --git a/website/docs/user-guide/features/credential-pools.md b/website/docs/user-guide/features/credential-pools.md index 7eae3eab0a..c7baa1624e 100644 --- a/website/docs/user-guide/features/credential-pools.md +++ b/website/docs/user-guide/features/credential-pools.md @@ -319,7 +319,7 @@ This means subagents benefit from the same rate-limit resilience as the parent, The credential pool uses a threading lock for all state mutations (`select()`, `mark_exhausted_and_rotate()`, `try_refresh_current()`, `mark_used()`). This ensures safe concurrent access when the gateway handles multiple chat sessions simultaneously. -Across processes (many subagents, a gateway plus a CLI, cron jobs), OAuth refreshes are serialized through a file lock on `auth.json`. When one shared OAuth grant expires under many concurrent processes, exactly one process performs the refresh; the others detect that the on-disk token no longer matches the one that failed and adopt it instead of rotating the single-use refresh token again. A process that loses the lock race keeps its entry healthy and retries — lock contention is never recorded as a credential failure. +Across processes (many subagents, a gateway plus a CLI, cron jobs), OAuth refreshes are serialized through a file lock on `auth.json`. When one shared OAuth grant expires under many concurrent processes, exactly one process performs the refresh; the others detect that the on-disk token no longer matches the one that failed and adopt it instead of rotating the single-use refresh token again. A process that loses the lock race keeps its entry healthy and retries — lock contention is never recorded as a credential failure. A session or process still holding an older copy of the pool never writes that copy's tokens back over a pair another one rotated since; it keeps the newer pair on disk and adopts it. ## Architecture