Add IsSendingAnonymousRequests to VFS.Heartbeat - #2125
Open
Tyrie Vella (tyrielv) wants to merge 1 commit into
Open
Tyrie Vella (tyrielv) wants to merge 1 commit into
Tyrie Vella (tyrielv) wants to merge 1 commit into
Conversation
Expose whether outgoing gvfs.exe requests are sent without an Authorization header via the periodic VFS.Heartbeat event, sourced from the enlistment's existing public GitAuthentication.IsAnonymous property. Application Insights shows a fleet failure mode where mounts get stuck unable to download blob sizes or objects (SizesUnavailableException), affecting roughly 6% of active machines with no repro in hand. The suspected cause is an anonymous-auth latch: when the initial anonymous config probe comes back indeterminate, GitAuthentication never clears IsAnonymous, so HttpRequestor permanently omits the Authorization header. Today no heartbeat or telemetry field exposes this state, so the mechanism cannot be confirmed or sized in the field. This change is intentionally scoped away from GitAuthentication.cs and HttpRequestor.cs, which are being reworked by unrelated in-flight fixes for the same bug. The new field is named for the observable effect on the wire (no Authorization header sent) rather than for the internal property, and reads the same way regardless of which build emits it, even though IsAnonymous's default value before the first auth probe completes differs between the current code and the in-flight fix. Assisted-by: Claude Sonnet 5 Signed-off-by: Tyrie Vella <tyrielv@gmail.com>
Tyrie Vella (tyrielv)
force-pushed
the
tyrielv/isanonymous-heartbeat
branch
from
September 30, 2026 21:33
2b82279 to
6dd6f63
Compare
Tyrie Vella (tyrielv)
marked this pull request as ready for review
September 30, 2026 21:34
Tyrie Vella (tyrielv)
enabled auto-merge
September 30, 2026 21:34
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem and Context
Some VFS for Git mounts get stuck unable to download blob sizes or objects, with no reliable repro. The suspected cause is an anonymous-auth latch: when the initial anonymous config probe against the Git server comes back neither clearly successful nor clearly
401 Unauthorized(an indeterminate result),GitAuthenticationmarks itself initialized but never clears itsIsAnonymousflag. From that point on,HttpRequestorpermanently omits theAuthorizationheader on every outgoing request to a server that may actually require one.Today nothing in the periodic
VFS.Heartbeattelemetry event exposes this auth state, so the mechanism can't be confirmed or sized across the fleet.This change is intentionally scoped away from
GitAuthentication.csandHttpRequestor.cs— both are being reworked by other in-flight fixes for this same underlying bug, and touching them here would create merge conflicts. The new field reads through the enlistment's existing publicAuthenticationproperty instead.Changes
IsSendingAnonymousRequests(bool) toFileSystemCallbacks.GetAndResetHeartBeatMetadata, sourced fromGitAuthentication.IsAnonymous. Named for the observable wire effect (noAuthorizationheader sent) rather than the internal property name, so the field reads the same regardless of which build emits it.Known gaps and deliberate decisions
IsAnonymous == falsecase — no test harness seam exists to flipGitAuthentication.IsAnonymoustofalsewithout either a real HTTP round-trip or editingGitAuthentication.cs(out of scope here, see above). Only the default (true) case is covered.GitAuthentication.IsAnonymousto default tofalseinstead oftrue. When that lands, the two heartbeat unit tests updated here will need their expected value flipped. This is expected, not a defect in this change: the field's meaning (true/false = no/yesAuthorizationheader sent) is unaffected, only the transient pre-probe default changes, and that window is negligible relative to the hourly heartbeat cadence.