Skip to content

fix(kimi): clarify stale CLI credential recovery - #4086

Open
steipete wants to merge 2 commits into
mainfrom
triage/20260921-kimi-cli-stale
Open

steipete wants to merge 2 commits into
mainfrom
triage/20260921-kimi-cli-stale

Conversation

@steipete

@steipete steipete commented Sep 28, 2026 •

Copy link
Copy Markdown
Owner

Kimi CLI-only sessions become stale once the access token enters CodexBar's expiry margin. The error now tells users to run kimi to renew the session or add a Kimi Code API key in Settings, and the guide explains the 14-minute cutoff for a 15-minute token.

The official Kimi clients coordinate rotating refresh tokens and persist replacements. This preserves CLI-owned credentials as read-only and retains Auto mode's existing API-key priority and web fallback. Synthetic tests cover the cutoff, expired and rejected-token fallback, an unchanged credential file, and recovery after the CLI replaces its credential.

Verification on the final tree:

  • CODEXBAR_SUPPRESS_TEST_KEYCHAIN_ACCESS=1 CODEXBAR_TEST_CODEX_FILE_ISOLATION=1 CODEXBAR_TEST_SESSION_FILE_ISOLATION=1 swift test --jobs 2 --filter 'KimiSettingsReaderTests|KimiAPIFetchStrategyTests|KimiUsageResponseParsingTests|KimiUsageSnapshotConversionTests|KimiTokenResolverTests|KimiAPIErrorTests|KimiCLICredentialLifecycleTests|KimiWebFallbackTests|CredentialNotificationTests|ProviderArchitectureGatekeeperTests|ProviderSettingsDescriptorTests': 216 tests in 11 suites passed, 0 failures. Live-test and real-Keychain opt-in variables were unset.
  • CODEXBAR_SUPPRESS_TEST_KEYCHAIN_ACCESS=1 swift test --package-path .build/kimi-error-proof --jobs 1 --filter KimiAPIErrorTests: isolated SwiftPM harness using the actual error source and permanent test file; pre-fix source 491ae688a89a failed with 4 expected assertions, and fixed source passed 2 tests, 0 failures.
  • A synthetic CODEXBAR_CONFIG / KIMI_CODE_HOME probe through the signed 0.67.0 CLI reproduced the old expired-credential message. The same probe against the freshly built CLI passed the new recovery contract. Both preserved credential bytes and modification time; cookies and Keychain access were disabled, and Kimi credential environment variables were cleared.
  • make check: 0 violations, 0 serious in 2670 files; repository checks passed.
  • Independent autoreview after syncing main: scoped-clean, no actionable P0–P2 findings.

Published main was merged into this branch without rewriting the fix. Relative to main 579f68406855, git diff --shortstat 579f68406855 HEAD -- Sources WidgetExtension is 1 file changed, 3 insertions(+), 6 deletions(-), net −3. Test changes are 3 files changed, 161 insertions(+), 22 deletions(-).

Fixes #4063. Thanks @kid0114 for the detailed report.

Keep rotating CLI credentials read-only and point users to CLI renewal or the Kimi Code API key setting. Add synthetic expiry, web fallback, and credential replacement coverage for #4063.
@clawsweeper

clawsweeper Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

🦞👀
ClawSweeper picked this up.

Pull request received. I will update this pull request when review starts.

ClawSweeper review complete

ClawSweeper finished reviewing this revision. The review result is being finalized.

View the workflow run.

@clawsweeper clawsweeper Bot added P3 Low-risk cleanup, docs, polish, ergonomics, or speculative feature. rating: 🦐 gold shrimp Decent PR readiness signal, but merge confidence is limited. status: 👀 ready for maintainer look ClawSweeper has no concrete contributor-facing blocker left for this PR. labels Sep 28, 2026
@clawsweeper

clawsweeper Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

Codex review: blocked before merge. Reviewed September 28, 2026, 12:55 AM ET / 04:55 UTC (Revision 3).

ClawSweeper review

What this changes

The PR clarifies Kimi CLI credential error messages and documentation, and adds synthetic tests for expiry, fallback, and recovery after the CLI replaces its credential.

Merge readiness

⛔ Blocked before merge - 3 items remain

The recovery guidance is a useful, focused change that current main and v0.68.0 lack. It leaves the linked report’s request for unattended CLI credential renewal unresolved, so its closing reference needs an explicit owner decision before merge.

Priority: P3
Reviewed head: 99c5da6981535c4c5dbef2f5dc3b770178b53eff
Owner decision: Required. See Decision needed.

Review scores

Measure Result What it means
Overall readiness 🦐 gold shrimp (3/6) The patch is focused and well covered synthetically; the reported after-fix CLI result lacks an inspectable trace.
Proof confidence 🦐 gold shrimp (3/6) Not applicable: The owner-authored PR is exempt from the external-contributor proof gate. Its changed production behavior is CLI credential error wording; the PR body reports a synthetic probe through a signed pre-fix CLI and a freshly built after-fix CLI, but supplies no captured output to inspect. Tests are supplemental, and no stored-data contract changes.
Patch quality 🐚 platinum hermit (4/6) No actionable review findings were identified.

Verification

Check Result Evidence
Real behavior Not applicable Not applicable: The owner-authored PR is exempt from the external-contributor proof gate. Its changed production behavior is CLI credential error wording; the PR body reports a synthetic probe through a signed pre-fix CLI and a freshly built after-fix CLI, but supplies no captured output to inspect. Tests are supplemental, and no stored-data contract changes.
Evidence reviewed 11 items Introduced production change: The introduced hunk changes the expired and rejected CLI credential descriptions; it does not change renewal or provider selection.
Remaining expiry behavior: Current main accepts a CLI access token only when its expiry exceeds the current time by more than 60 seconds; the reader decodes but does not use the refresh token.
Provider path: Auto mode tries API key, CLI credential, then web authentication; a stale CLI credential raises the error whose wording this PR changes.
Findings None None.
Security None None.

How this fits together

CodexBar chooses among a Kimi API key, a fresh Kimi CLI credential, and web authentication when fetching usage. If the CLI credential is stale, it can try web authentication or show a recovery error.

flowchart LR
A[API key] --> D[Auto source selection]
B[CLI credential file] --> C[Freshness check]
C --> D
D --> E[Kimi usage request]
D --> F[Web fallback]
C --> G[Recovery message]
Loading

Decision needed

Question Recommendation
Should this guidance-only PR close the linked request for unattended Kimi CLI credential renewal? Keep renewal tracked: Remove the closing reference and merge this PR as a recovery-guidance improvement while the renewal decision remains open.

Why: The PR deliberately retains the stale CLI-only behavior, while the linked report asks for continuous usage after the CLI exits.

Before merge

Agent review details

Security

None.

Review metrics

Metric Value Why it matters
Production and test changes production +3/−6 lines; tests +161/−22 lines The production change is limited to wording, with substantially more synthetic lifecycle coverage and no production code growth.

Root-cause cluster

Relationship: partial_overlap
Canonical: #4063
Summary: This PR improves recovery guidance for the reported stale-credential path but leaves its unattended-renewal request unresolved.

Members:

Proposal only: this assessment does not dispatch repair, suppress jobs, mutate sibling items, close, or merge anything.

Merge-risk options

Maintainer options:

  1. Keep renewal tracked (recommended)
    Remove the closing reference before merge so the unattended-renewal request stays open.
  2. Accept manual recovery
    Explicitly confirm that CLI renewal or an API key resolves the linked report despite the continuing CLI-only cutoff.

Technical review

Best possible solution:

Land the clearer recovery guidance while preserving CLI credential ownership, and keep the renewal request tracked unless the owner explicitly accepts manual renewal or an API key as its final resolution.

Do we have a high-confidence way to reproduce the issue?

Yes. Current source and the synthetic lifecycle cases define the stale-token cutoff and resulting error path; this read-only review did not execute them.

Is this the best way to solve the issue?

No for the linked renewal request: clearer wording provides a useful manual recovery path but does not keep CLI-only usage working unattended.

AGENTS.md: found and applied where relevant.

Codex review notes: model internal, reasoning high; reviewed against 579f68406855.

Labels

Label changes:

No label changes.

Label justifications:

  • P3: This is a limited Kimi recovery-guidance improvement with no changed credential handling.
  • merge-risk: 🚨 other: Merging with the closing reference could resolve the linked report while its unattended-renewal request remains unmet.
  • rating: 🦐 gold shrimp: Overall readiness is 🦐 gold shrimp; proof is 🦐 gold shrimp and patch quality is 🐚 platinum hermit.
  • status: 👀 ready for maintainer look: ClawSweeper has no concrete contributor-facing blocker left for this PR. Not applicable: The owner-authored PR is exempt from the external-contributor proof gate. Its changed production behavior is CLI credential error wording; the PR body reports a synthetic probe through a signed pre-fix CLI and a freshly built after-fix CLI, but supplies no captured output to inspect. Tests are supplemental, and no stored-data contract changes.

Evidence

What I checked:

Likely related people:

  • steipete: Suggested for follow-up; no historical authorship or introduction is verified. (role: unverified routing candidate; confidence: low)
  • Leechael: Suggested for follow-up; no historical authorship or introduction is verified. (role: unverified routing candidate; confidence: low)

Rank-up moves

Optional improvements that raise the rating; they are not merge blockers.

  • Resolve whether the linked renewal report stays open after this guidance change.

Rating scale

Score Internal tier Crab rank Meaning
6/6 S 🦀 challenger crab Exceptional readiness
5/6 A 🦞 diamond lobster Very strong readiness
4/6 B 🐚 platinum hermit Good normal PR; ordinary maintainer review
3/6 C 🦐 gold shrimp Useful, but confidence is limited
2/6 D 🦪 silver shellfish Proof or implementation needs work
1/6 F 🧂 unranked krab Not merge-ready
N/A NA 🌊 off-meta tidepool Rating does not apply

Overall follows the weaker of proof and patch quality.
Shiny media proof means a screenshot, video, or linked artifact directly shows the changed behavior. Runtime, network, CSP, and security claims still need visible diagnostics.

Workflow

  • ClawSweeper keeps one durable marker-backed review comment per issue or PR.
  • Re-runs edit this comment so the latest verdict, findings, and automation markers stay together instead of adding duplicate bot comments.
  • A fresh review can be triggered by eligible @clawsweeper re-review comments, exact-item GitHub events, scheduled/background review runs, or manual workflow dispatch.
  • PR/issue authors and users with repository write access can comment @clawsweeper re-review or @clawsweeper re-run on an open PR or issue to request a fresh review only.
  • Maintainers can also comment @clawsweeper review to request a fresh review only.
  • Fresh-review commands do not start repair, autofix, rebase, CI repair, or automerge.
  • Maintainer-only repair and merge flows require explicit commands such as @clawsweeper autofix, @clawsweeper automerge, @clawsweeper fix ci, or @clawsweeper address review.
  • Maintainers can comment @clawsweeper explain to ask for more context, or @clawsweeper stop to stop active automation.

History

Review history (2 earlier review cycles)
  • reviewed 2026-09-28T03:14:12.656Z sha a7cd8c0 :: needs maintainer review before merge. :: none
  • reviewed 2026-09-28T04:00:49.393Z sha 99c5da6 :: blocked before merge. :: none

Integrate current main without rewriting the recovery fix.
@clawsweeper clawsweeper Bot added the merge-risk: 🚨 other 🚨 Merging this PR has meaningful risk outside the owned taxonomy. label Sep 28, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

merge-risk: 🚨 other 🚨 Merging this PR has meaningful risk outside the owned taxonomy. P3 Low-risk cleanup, docs, polish, ergonomics, or speculative feature. rating: 🦐 gold shrimp Decent PR readiness signal, but merge confidence is limited. status: 👀 ready for maintainer look ClawSweeper has no concrete contributor-facing blocker left for this PR.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Kimi provider: CLI credential goes stale ~14 min after kimi-code CLI quits (refresh_token never used)

1 participant