Skip to content

Add IsSendingAnonymousRequests to VFS.Heartbeat - #2125

Open
Tyrie Vella (tyrielv) wants to merge 1 commit into
microsoft:masterfrom
tyrielv:tyrielv/isanonymous-heartbeat
Open

Tyrie Vella (tyrielv) wants to merge 1 commit into
microsoft:masterfrom
tyrielv:tyrielv/isanonymous-heartbeat

Conversation

@tyrielv

Copy link
Copy Markdown
Contributor

Problem and Context

Some VFS for Git mounts get stuck unable to download blob sizes or objects, with no reliable repro. The suspected cause is an anonymous-auth latch: when the initial anonymous config probe against the Git server comes back neither clearly successful nor clearly 401 Unauthorized (an indeterminate result), GitAuthentication marks itself initialized but never clears its IsAnonymous flag. From that point on, HttpRequestor permanently omits the Authorization header on every outgoing request to a server that may actually require one.

Today nothing in the periodic VFS.Heartbeat telemetry event exposes this auth state, so the mechanism can't be confirmed or sized across the fleet.

This change is intentionally scoped away from GitAuthentication.cs and HttpRequestor.cs — both are being reworked by other in-flight fixes for this same underlying bug, and touching them here would create merge conflicts. The new field reads through the enlistment's existing public Authentication property instead.

Changes

  • Added IsSendingAnonymousRequests (bool) to FileSystemCallbacks.GetAndResetHeartBeatMetadata, sourced from GitAuthentication.IsAnonymous. Named for the observable wire effect (no Authorization header sent) rather than the internal property name, so the field reads the same regardless of which build emits it.
  • Updated the two existing heartbeat-metadata unit tests to assert the new key and the updated metadata count.

Known gaps and deliberate decisions

  • No unit test for the IsAnonymous == false case — no test harness seam exists to flip GitAuthentication.IsAnonymous to false without either a real HTTP round-trip or editing GitAuthentication.cs (out of scope here, see above). Only the default (true) case is covered.
  • In-flight sibling branch will change this field's default value — a separate branch reworks GitAuthentication.IsAnonymous to default to false instead of true. When that lands, the two heartbeat unit tests updated here will need their expected value flipped. This is expected, not a defect in this change: the field's meaning (true/false = no/yes Authorization header sent) is unaffected, only the transient pre-probe default changes, and that window is negligible relative to the hourly heartbeat cadence.

Expose whether outgoing gvfs.exe requests are sent without an Authorization header via the periodic VFS.Heartbeat event, sourced from the enlistment's existing public GitAuthentication.IsAnonymous property.

Application Insights shows a fleet failure mode where mounts get stuck unable to download blob sizes or objects (SizesUnavailableException), affecting roughly 6% of active machines with no repro in hand. The suspected cause is an anonymous-auth latch: when the initial anonymous config probe comes back indeterminate, GitAuthentication never clears IsAnonymous, so HttpRequestor permanently omits the Authorization header. Today no heartbeat or telemetry field exposes this state, so the mechanism cannot be confirmed or sized in the field.

This change is intentionally scoped away from GitAuthentication.cs and HttpRequestor.cs, which are being reworked by unrelated in-flight fixes for the same bug. The new field is named for the observable effect on the wire (no Authorization header sent) rather than for the internal property, and reads the same way regardless of which build emits it, even though IsAnonymous's default value before the first auth probe completes differs between the current code and the in-flight fix.

Assisted-by: Claude Sonnet 5

Signed-off-by: Tyrie Vella <tyrielv@gmail.com>
@tyrielv
Tyrie Vella (tyrielv) force-pushed the tyrielv/isanonymous-heartbeat branch from 2b82279 to 6dd6f63 Compare September 30, 2026 21:33
@tyrielv
Tyrie Vella (tyrielv) marked this pull request as ready for review September 30, 2026 21:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant