fix: widen source guard to include manual:device_code entries

The _sync_codex_entry_from_auth_store source guard returned early for
source='manual:device_code', which is the recommended quarantine-safe
configuration (hermes auth add openai-codex produces SOURCE_MANUAL_DEVICE_CODE).
The PR's fix for refresh_token adoption was unreachable for these entries.

Widen the guard to accept both 'device_code' and 'manual:device_code'.

Follow-up to #70111. Issue reporter (imgyf) confirmed this caused a
12-of-16 fleet outage on Aug 1.

Co-authored-by: imgyf <imgyf@users.noreply.github.com>
This commit is contained in:
kshitij
2026-08-03 00:23:21 +05:30
parent 0ab4cdc27d
commit 7380b48589
+1 -1
View File
@@ -795,7 +795,7 @@ class CredentialPool:
device_code-sourced entries; env/API-key-sourced entries have no
auth.json shadow to sync from.
"""
if self.provider != "openai-codex" or entry.source != "device_code":
if self.provider != "openai-codex" or entry.source not in ("device_code", "manual:device_code"):
return entry
try:
with _auth_store_lock():