constitution · epochs · watch · epoch 3

comparison

c_2dc96aace098 (tommy-mor) vs c_ca9169f732b8 (tommy-mor)

download prompt · raw event · cmp_4d2fbf6a9db7fc

council reasoning

~anthropic/claude-sonnet-latest · winner A · 65:35 · permalink

A adds a substantial, tested infrastructure change (RocksDB-backed entity storage, streaming event replay) that reduces startup RAM and cleanly separates raw payloads from in-memory tree state, verified by new unit/integration tests. B is a smaller but real bugfix (mandatory OAuth with retry-on-401/403 and better error truncation) that fixes a genuine production reliability issue, but its scope and lasting architectural impact are narrower than A's.

~x-ai/grok-latest · winner A · 3:1 · permalink

A introduces lasting architectural value by offloading bulky Reddit entity JSON from the in-memory GlobalTree into a RocksDB-backed EntityStore (via the vendored durable crate) and by replacing full event-log materialization with true streaming replay, which directly cuts startup RAM; the integration touches entity_store, event_log, reducer, state and reddit paths with accompanying tests. B is a correct, necessary production bugfix (force OAuth when credentials exist, refresh on 401/403, avoid the public www.reddit.com block page, plus a fly.toml pin) but is narrower in scope and impact.

openai/gpt-chat-latest · winner A · 5:1 · permalink

Side A makes a substantial architectural change: it introduces a RocksDB-backed `durable` workspace crate, moves raw Reddit entity JSON out of the in-memory tree into a persistent `EntityStore`, and replaces startup's `load_all()` with streamed event-log replay via `EventLog::replay`, reducing memory usage while preserving functionality. Side B is a valuable operational bugfix that requires OAuth when configured, refreshes tokens after 401/403, and avoids fallback to blocked public endpoints, but its scope is limited compared with Side A's long-term persistence and scalability improvements.

sides

A — c_2dc96aace098 (tommy-mor)

message

[285b64d4] Offload Reddit payloads to RocksDB and stream event log replay.

Vendor durable as a workspace crate, store entity JSON in entity_db instead
of GlobalTree, and replay events.jsonl one line at a time to cut startup RAM.

Co-authored-by: Cursor <cursoragent@cursor.com>

diff preview

diff --git a/Cargo.lock b/Cargo.lock
index e55d87f32ab32064686431c7082ef8c9ca872d63..8fc09f9ac978bd7ccf57f177989057b606677db8 100644
--- a/Cargo.lock
+++ b/Cargo.lock
@@ -11,6 +11,18 @@ dependencies = [
  "memchr",
 ]
 
+[[package]]
+name = "anes"
+version = "0.1.6"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "4b46cbb362ab8752921c97e041f5e366ee6297bd428a31275b9fcf1e380f7299"
+
+[[package]]
+name = "anstyle"
+version = "1.0.14"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "940b3a0ca603d1eade50a4846a2afffd5ef57a9feac2c0e2ec2e14f9ead76000"
+
 [[package]]
 name = "anyhow"
 version = "1.0.102"
@@ -56,6 +68,12 @@ version = "1.1.2"
 source = "registry+https://github.com/rust-lang/crates.io-index"
 checksum = "1505bd5d3d116872e7271a6d4e16d81d0c8570876c8de68093a09ac269d8aac0"
 
+[[package]]
+name = "autocfg"
+version = "1.5.1"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "f2032f911046de80f0a198e0901378627c33f59ea0ac00e363d481118bd70a53"
+
 [[package]]
 name = "axum"
 version = "0.7.9"
@@ -153,6 +171,75 @@ version = "0.22.1"
 source = "registry+https://github.com/rust-lang/crates.io-index"
 checksum = "72b3254f16251a8381aa12e40e3c4d2f0199f8c6508fbecb9d91f575e0fbb8c6"
 
+[[package]]
+name = "bincode"
+version = "1.3.3"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "b1f45e9417d87227c7a56d22e471c6206462cba514c7590c09aff4cf6d1ddcad"
+dependencies = [
+ "serde",
+]
+
+[[package]]
+name = "bindgen"
+version = "0.65.1"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "cfdf7b466f9a4903edc73f95d6d2bcd5baf8ae620638762244d3f60143643cc5"
+dependencies = [
+ "bitflags 1.3.2",
+ "cexpr",
+ "clang-sys",
+ "lazy_static",
+ "lazycell",
+ "peeking_take_while",
+ "prettyplease",
+ "proc-macro2",
+ "quote",
+ "regex",
+ "rustc-hash 1.1.0",
+ "shlex",
+ "syn",
+]
+
+[[package]]
+name = "bindgen"
+version = "0.72.1"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "993776b509cfb49c750f11b8f07a46fa23e0a1386ffc01fb1e7d343efc387895"
+dependencies = [
+ "bitflags 2.11.1",
+ "cexpr",
+ "clang-sys",
+ "itertools 0.13.0",
+ "proc-macro2",
+ "quote",
+ "regex",
+ "rustc-hash 2.1.2",
+ "shlex",
+ "syn",
+]
+
+[[package]]
+name = "bit-set"
+version = "0.8.0"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "08807e080ed7f9d5433fa9b275196cfc35414f66a0c79d864dc51a0d825231a3"
+dependencies = [
+ "bit-vec",
+]
+
+[[package]]
+name = "bit-vec"
+version = "0.8.0"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "5e764a1d40d510daf35e07be9eb06e75770908c27d411ee6c92109c9840eaaf7"
+
+[[package]]
+name = "bitflags"
+version = "1.3.2"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "bef38d45163c2f1dde094a7dfd33ccf595c92905c8f8f4fdc18d06fb1037718a"
+
 [[package]]
 name = "bitflags"
 version = "2.11.1"
@@ -171,6 +258,22 @@ version = "1.11.1"
 source = "registry+https://github.com/rust-lang/crates.io-index"
 checksum = "1e748733b7cbc798e1434b6ac524f0c1ff2ab456fe201501e6497c8417a4fc33"
 
+[[package]]
+name = "bzip2-sys"
+version = "0.1.13+1.0.8"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "225bff33b2141874fe80d71e07d6eec4f85c5c216453dd96388240f96e1acc14"
+dependencies = [
+ "cc",
+ "pkg-config",
+]
+
+[[package]]
+name = "cast"
+version = "0.3.0"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "37b2a672a2cb129a2e41c10b1224bb368f9f37a2b16b612598138befd7b37eb5"
+
 [[package]]
 name = "cc"
 version = "1.2.62"
@@ -178,15 +281,89 @@ source = "registry+https://github.com/rust-lang/crates.io-index"
 checksum = "a1dce859f0832a7d088c4f1119888ab94ef4b5d6795d1ce05afb7fe159d79f98"
 dependencies = [
  "find-msvc-tools",
+ "jobserver",
+ "libc",
  "shlex",
 ]
 
+[[package]]
+name = "cexpr"
+version = "0.6.0"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "6fac387a98bb7c37292057cffc56d62ecb629900026402633ae9160df93a8766"
+dependencies = [
+ "nom",
+]
+
 [[package]]
 name = "cfg-if"
 version = "1.0.4"
 source = "registry+https://github.com/rust-lang/crates.io-index"
 checksum = "9330f8b2ff13f34540b44e946ef35111825727b38d33286ef986142615121801"
 
+[[package]]
+name = "ciborium"
+version = "0.2.2"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "42e69ffd6f0917f5c029256a24d0161db17cea3997d185db0d35926308770f0e"
+dependencies = [
+ "ciborium-io",
+ "ciborium-ll",
+ "serde",
+]
+
+[[package]]
+name = "ciborium-io"
+version = "0.2.2"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "05afea1e0a06c9be33d539b876f1ce3692f4afea2cb41f740e7743225ed1c757"
+
+[[package]]
+name = "ciborium-ll"
+version = "0.2.2"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "57663b653d948a338bfb3eeba9bb2fd5fcfaecb9e199e87e1eda4d9e8b240fd9"
+dependencies = [
+ "ciborium-io",
+ "half",
+]
+
+[[package]]
+name = "clang-sys"
+version = "1.8.1"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "0b023947811758c97c59bf9d1c188fd619ad4718dcaa767947df1cadb14f39f4"
+dependencies = [
+ "glob",
+ "libc",
+ "libloading",
+]
+
+[[package]]
+name = "clap"
+version = "4.6.1"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "1ddb117e43bbf7dacf0a4190fef4d345b9bad68dfc649cb349e7d17d28428e51"
+dependencies = [
+ "clap_builder",
+]
+
+[[package]]
+name = "clap_builder"
+version = "4.6.0"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "714a53001bf66416adb0e2ef5ac857140e7dc3a0c48fb28b2f10762fc4b5069f"
+dependencies = [
+ "anstyle",
+ "clap_lex",
+]
+
+[[package]]
+name = "clap_lex"
+version = "1.1.0"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "c8d4a3bb8b1e0c1050499d1815f5ab16d04f0959b233085fb31653fbfc9d98f9"
+
 [[package]]
 name = "cookie"
 version = "0.18.1"
@@ -224,6 +401,73 @@ version = "0.8.7"
 source = "registry+https://github.com/rust-lang/crates.io-index"
 checksum = "773648b94d0e5d620f64f280777445740e61fe701025087ec8b57f45c791888b"
 
+[[package]]
+name = "criterion"
+version = "0.5.1"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "f2b12d017a929603d80db1831cd3a24082f8137ce19c69e6447f54f5fc8d692f"
+dependencies = [
+ "anes",
+ "cast",
+ "ciborium",
+ "clap",
+ "criterion-plot",
+ "is-terminal",
+ "itertools 0.10.5",
+ "num-traits",
+ "once_cell",
+ "oorandom",
+ "plotters",
+ "rayon",
+ "regex",
+ "serde",
+ "serde_derive",
+ "serde_json",
+ "tinytemplate",
+ "walkdir",
+]
+
+[[package]]
+name = "criterion-plot"
+version = "0.5.0"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "6b50826342786a51a89e2da3a28f1c32b06e387201bc2d19791f622c673706b1"
+dependencies = [
+ "cast",
+ "itertools 0.10.5",
+]
+
+[[package]]
+name = "crossbeam-deque"
+version = "0.8.6"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "9dd111b7b7f7d55b72c0a6ae361660ee5853c9af73f70c3c2ef6858b950e2e51"
+dependencies = [
+ "crossbeam-epoch",
+ "crossbeam-utils",
+]
+
+[[package]]
+name = "crossbeam-epoch"
+version = "0.9.18"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "5b82ac4a3c2ca9c3460964f020e1402edd5753411d7737aa39c3714ad1b5420e"
+dependencies = [
+ "crossbeam-utils",
+]
+
+[[package]]
+name = "crossbeam-utils"
+version = "0.8.21"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "d0a5c400df2834b80a4c3327b3aad3a4c4cd4de0629063962b03235697506a28"
+
+[[package]]
+name = "crunchy"
+version = "0.2.4"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "460fbee9c2c2f33933d720630a6a0bac33ba7053db5344fac858d4b8952d77d5"
+
 [[package]]
 name = "deranged"
 version = "0.5.8"
@@ -250,6 +494,25 @@ version = "0.15.7"
 source = "registry+https://github.com/rust-lang/crates.io-index"
 checksum = "1aaf95b3e5c8f23aa320147307562d361db0ae0d51242340f558153b4eb2439b"
 
+[[package]]
+name = "durable"
+version = "0.1.0"
+dependencies = [
+ "bincode",
+ "criterion",
+ "proptest",
+ "rocksdb",
+ "serde",
+ "tempfile",
+ "thiserror",
+]
+
+[[package]]
+name = "either"
+version = "1.16.0"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "91622ff5e7162018101f2fea40d6ebf4a78bbe5a49736a2020649edf9693679e"
+
 [[package]]
 name = "encoding_rs"
 version = "0.8.35"
@@ -373,6 +636,18 @@ dependencies = [
  "wasi",
 ]
 
+[[package]]
+name = "getrandom"
+version = "0.3.4"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "899def5c37c4fd7b2664648c28120ecec138e4d395b459e5ca34f9cce2dd77fd"
+dependencies = [
+ "cfg-if",
+ "libc",
+ "r-efi 5.3.0",
+ "wasip2",
+]
+
 [[package]]
 name = "getrandom"
 version = "0.4.2"
@@ -381,11 +656,17 @@ checksum = "0de51e6874e94e7bf76d726fc5d13ba782deca734ff60d5bb2fb2607c7406555"
 dependencies = [
  "cfg-if",
  "libc",
- "r-efi",
+ "r-efi 6.0.0",
  "wasip2",
  "wasip3",
 ]
 
+[[package]]
+name = "glob"
+version = "0.3.3"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "0cc23270f6e1808e30a928bdc84dea0b9b4136a8bc82338574f23baf47bbd280"
+
 [[package]]
 name = "h2"
 version = "0.4.14"
@@ -405,6 +686,17 @@ dependencies = [
  "tracing",
 ]
 
+[[package]]
+name = "half"
+version = "2.7.1"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "6ea2d84b969582b4b1864a92dc5d27cd2b77b622a8d79306834f1be5ba20d84b"
+dependencies = [
+ "cfg-if",
+ "crunchy",
+ "zerocopy",
+]
+
 [[package]]
 name = "hashbrown"
 version = "0.15.5"
@@ -426,6 +718,12 @@ version = "0.5.0"
 source = "registry+https://github.com/rust-lang/crates.io-index"
 checksum = "2304e00983f87ffb38b55b444b5e3b60a884b5d30c0fca7d82fe33449bbe55ea"
 
+[[package]]
+name = "hermit-abi"
+version = "0.5.2"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "fc0fef456e4baa96da950455cd02c081ca953b141298e41db3fc7e36b1da849c"
+
 [[package]]
 name = "http"
 version = "1.4.1"
@@ -676,12 +974,51 @@ version = "2.12.0"
 source = "registry+https://github.com/rust-lang/crates.io-index"
 checksum = "d98f6fed1fde3f8c21bc40a1abb88dd75e67924f9cffc3ef95607bad8017f8e2"
 
+[[package]]
+name = "is-terminal"
+version = "0.4.17"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "3640c1c38b8e4e43584d8df18be5fc6b0aa314ce6ebf51b53313d4306cca8e46"
+dependencies = [
+ "hermit-abi",
+ "libc",
+ "windows-sys 0.61.2",
+]
+
+[[package]]
+name = "itertools"
+version = "0.10.5"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "b0fd2260e829bddf4cb6ea802289de2f86d6a7a690192fbe91b3f46e0f2c8473"
+dependencies = [
+ "either",
+]
+
+[[package]]
+name = "itertools"
+version = "0.13.0"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "413ee7dfc52ee1a4949ceeb7dbc8a33f2d6c088194d9f922fb8318faf1f01186"
+dependencies = [
+ "either",
+]
+
 [[package]]
 name = "itoa"
 version = "1.0.18"
 source = "registry+https://github.com/rust-lang/crates.io-index"
 checksum = "8f42a60cbdf9a97f5d2305f08a87dc4e09308d1276d28c869c684d7777685682"
 
+[[package]]
+name = "jobserver"
+version = "0.1.34"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "9afb3de4395d6b3e67a780b6de64b51c978ecf11cb9a462c66be7d4ca9039d33"
+dependencies = [
+ "getrandom 0.3.4",
+ "libc",
+]
+
 [[package]]
 name = "js-sys"
 version = "0.3.99"
@@ -700,6 +1037,12 @@ version = "1.5.0"
 source = "registry+https://github.com/rust-lang/crates.io-index"
 checksum = "bbd2bcb4c963f2ddae06a2efc7e9f3591312473c50c6685e1f298068316e66fe"
 
+[[package]]
+name = "lazycell"
+version = "1.3.0"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "830d08ce1d1d941e6b30645f1a0eb5643013d835ce3779a5fc208261dbe10f55"
+
 [[package]]
 name = "leb128fmt"
 version = "0.1.0"
@@ -712,6 +

… preview truncated; 197,635 characters omitted

download full diff A

B — c_ca9169f732b8 (tommy-mor)

message

[8f69c309] Require Reddit OAuth when credentials are set and refresh on 401/403.

Avoid falling back to the public www.reddit.com API from cloud IPs, which
returns Reddit's network-security block page. Also pin SORTER2_BASE_URL in fly.toml.

Co-authored-by: Cursor <cursoragent@cursor.com>

diff preview

diff --git a/fly.toml b/fly.toml
index f0c6a39f643c204987debc177234d95a8ef44b65..ca7e0088a7efd7d58d29d808f8d89080b2bff233 100644
--- a/fly.toml
+++ b/fly.toml
@@ -5,6 +5,7 @@ primary_region = "iad"
   dockerfile = "Dockerfile"
 
 [env]
+  SORTER2_BASE_URL = "https://reddit.sorter.social"
   SORTER2_DATA_DIR = "/data"
   SORTER2_EVENT_LOG = "/data/events.jsonl"
   PORT = "8080"
diff --git a/server/src/reddit.rs b/server/src/reddit.rs
index a874814f8927192ee62cab2d0db1efd27dcd57b7..f409764c1e1f36216f1b08107043c2eab905694c 100644
--- a/server/src/reddit.rs
+++ b/server/src/reddit.rs
@@ -283,26 +283,35 @@ async fn reddit_worker(
         );
         tokio::time::sleep(current_delay).await;
 
-        if let Some(c) = &creds {
-            oauth = ensure_oauth_token(&client, &oauth_token_base, c, oauth.take()).await;
-        }
-
-        let token = oauth.as_ref().map(|t| t.access_token.as_str());
-        let fetch_base = if token.is_some() {
-            tracing::debug!(
-                item = %fetch_id,
-                base = %oauth_api_base,
-                "reddit fetch using OAuth bearer"
-            );
-            &oauth_api_base
-        } else {
-            &api_base
-        };
-        let url = match kind {
-            FetchKind::SelfEntity => map_item_to_reddit_api(&fetch_id, fetch_base),
-            FetchKind::Children => map_children_url(&fetch_id, fetch_base),
+        let outcome = match &creds {
+            Some(c) => {
+                // OAuth is required when credentials are configured — never fall
+                // back to the public www.reddit.com JSON endpoints (cloud IPs
+                // get blocked with a 403 HTML interstitial).
+                fetch_with_oauth(
+                    &client,
+                    &oauth_token_base,
+                    &oauth_api_base,
+                    c,
+                    &mut oauth,
+                    &fetch_id,
+                    kind,
+                )
+                .await
+            }
+            None => {
+                let url = match kind {
+                    FetchKind::SelfEntity => map_item_to_reddit_api(&fetch_id, &api_base),
+                    FetchKind::Children => map_children_url(&fetch_id, &api_base),
+                };
+                match do_fetch(&client, &url, &fetch_id, None).await {
+                    Ok(FetchOutcome::AuthRejected { status, detail }) => {
+                        Err(format!("Reddit API {status}: {detail}"))
+                    }
+                    other => other,
+                }
+            }
         };
-        let outcome = do_fetch(&client, &url, &fetch_id, token).await;
 
         match outcome {
             Ok(FetchOutcome::Payload(payload)) => {
@@ -342,6 +351,12 @@ async fn reddit_worker(
                 current_delay = (current_delay * 2).min(Duration::from_secs(60));
                 notify(done, FetchJobResult::RateLimited { reset_secs });
             }
+            Ok(FetchOutcome::AuthRejected { status, detail }) => {
+                let e = format!("Reddit API {status}: {detail}");
+                tracing::warn!(item = %fetch_id, err = %e, "reddit fetch auth rejected");
+                current_delay = (current_delay * 2).min(Duration::from_secs(60));
+                notify(done, FetchJobResult::Failed(e));
+            }
             Err(e) => {
                 tracing::warn!(item = %fetch_id, err = %e, "reddit fetch failed");
                 current_delay = (current_delay * 2).min(Duration::from_secs(60));
@@ -357,6 +372,60 @@ enum FetchOutcome {
     Payload(Value),
     NotFound,
     RateLimited { reset_secs: u64 },
+    /// Bearer rejected — caller should drop the cached token and retry once.
+    AuthRejected { status: StatusCode, detail: String },
+}
+
+async fn fetch_with_oauth(
+    client: &Client,
+    oauth_token_base: &str,
+    oauth_api_base: &str,
+    creds: &RedditCredentials,
+    oauth: &mut Option<OAuthToken>,
+    fetch_id: &ItemId,
+    kind: FetchKind,
+) -> Result<FetchOutcome, String> {
+    for attempt in 0..2 {
+        let force_refresh = attempt > 0;
+        *oauth = Some(
+            ensure_oauth_token(client, oauth_token_base, creds, oauth.take(), force_refresh)
+                .await?,
+        );
+        let token = oauth
+            .as_ref()
+            .expect("token set above")
+            .access_token
+            .clone();
+
+        tracing::debug!(
+            item = %fetch_id,
+            base = %oauth_api_base,
+            attempt,
+            "reddit fetch using OAuth bearer"
+        );
+
+        let url = match kind {
+            FetchKind::SelfEntity => map_item_to_reddit_api(fetch_id, oauth_api_base),
+            FetchKind::Children => map_children_url(fetch_id, oauth_api_base),
+        };
+        match do_fetch(client, &url, fetch_id, Some(&token)).await? {
+            FetchOutcome::AuthRejected { status, detail } if attempt == 0 => {
+                tracing::warn!(
+                    item = %fetch_id,
+                    %status,
+                    %detail,
+                    "reddit OAuth rejected; refreshing token and retrying"
+                );
+                *oauth = None;
+                continue;
+            }
+            FetchOutcome::AuthRejected { status, detail } => {
+                return Err(format!("Reddit API {status}: {detail}"));
+            }
+            other => return Ok(other),
+        }
+    }
+    unreachable!("loop always returns")
 }
 
 async fn ensure_oauth_token(
@@ -364,35 +433,35 @@ async fn ensure_oauth_token(
     oauth_base: &str,
     creds: &RedditCredentials,
     existing: Option<OAuthToken>,
-) -> Option<OAuthToken> {
-    if let Some(t) = existing {
-        if Instant::now() < t.expires_at - Duration::from_secs(60) {
-            tracing::debug!("reddit OAuth token still valid");
-            return Some(t);
+    force_refresh: bool,
+) -> Result<OAuthToken, String> {
+    if !force_refresh {
+        if let Some(t) = existing {
+            if Instant::now() < t.expires_at - Duration::from_secs(60) {
+                tracing::debug!("reddit OAuth token still valid");
+                return Ok(t);
+            }
         }
     }
 
     let url = format!("{}/api/v1/access_token", oauth_base.trim_end_matches('/'));
-    tracing::debug!(%url, "reddit OAuth token request");
+    tracing::debug!(%url, force_refresh, "reddit OAuth token request");
 
     let resp = client
         .post(&url)
         .basic_auth(&creds.client_id, Some(&creds.client_secret))
         .form(&[("grant_type", "client_credentials")])
         .send()
-        .await;
-
-    let resp = match resp {
-        Ok(r) => r,
-        Err(e) => {
-            tracing::warn!("reddit OAuth token request failed: {e}");
-            return None;
-        }
-    };
+        .await
+        .map_err(|e| format!("Reddit OAuth token request failed: {e}"))?;
 
     if !resp.status().is_success() {
-        tracing::warn!("reddit OAuth token HTTP {}", resp.status());
-        return None;
+        let status = resp.status();
+        let body = resp.text().await.unwrap_or_default();
+        return Err(format!(
+            "Reddit OAuth token HTTP {status}: {}",
+            truncate_for_error(&body)
+        ));
     }
 
     #[derive(Deserialize)]
@@ -401,21 +470,40 @@ async fn ensure_oauth_token(
         expires_in: u64,
     }
 
-    let body: TokenResponse = match resp.json().await {
-        Ok(b) => b,
-        Err(e) => {
-            tracing::warn!("reddit OAuth token parse failed: {e}");
-            return None;
-        }
-    };
+    let body: TokenResponse = resp
+        .json()
+        .await
+        .map_err(|e| format!("Reddit OAuth token parse failed: {e}"))?;
 
-    tracing::debug!(expires_in = body.expires_in, "reddit OAuth token acquired");
-    Some(OAuthToken {
+    tracing::info!(expires_in = body.expires_in, "reddit OAuth token acquired");
+    Ok(OAuthToken {
         access_token: body.access_token,
         expires_at: Instant::now() + Duration::from_secs(body.expires_in),
     })
 }
 
+fn truncate_for_error(body: &str) -> String {
+    let compact: String = body.split_whitespace().collect::<Vec<_>>().join(" ");
+    if compact.is_empty() {
+        return "(empty body)".into();
+    }
+    // Prefer the human-readable block message over dumping Reddit's CSS.
+    if let Some(idx) = compact.find("You've been blocked") {
+        let slice: String = compact.chars().skip(idx).take(160).collect();
+        return if compact.chars().count() > idx + 160 {
+            format!("{slice}…")
+        } else {
+            slice
+        };
+    }
+    let chars: String = compact.chars().take(200).collect();
+    if compact.chars().count() > 200 {
+        format!("{chars}…")
+    } else {
+        chars
+    }
+}
+
 async fn do_fetch(
     client: &Client,
     url: &str,
@@ -460,15 +548,16 @@ async fn do_fetch(
 
     if !status.is_success() {
         let body = resp.text().await.unwrap_or_default();
+        let detail = truncate_for_error(&body);
         tracing::debug!(
             item = %id,
             %status,
             body_len = body.len(),
-            body_prefix = %body.chars().take(240).collect::<String>(),
+            %detail,
             "reddit non-success body"
         );
         if status == StatusCode::FORBIDDEN || status == StatusCode::UNAUTHORIZED {
-            return Err(format!("Reddit API {status}: {body}"));
+            return Ok(FetchOutcome::AuthRejected { status, detail });
         }
         return Ok(FetchOutcome::NotFound);
     }
@@ -716,6 +805,15 @@ fn reddit_direct_image_url(url: &str) -> bool {
 mod tests {
     use super::*;
 
+    #[test]
+    fn truncate_error_prefers_block_message() {
+        let html = r#"<style>.x{color:red}</style><div>You've been blocked by network security. To continue, log in</div>"#;
+        let msg = truncate_for_error(html);
+        assert!(msg.starts_with("You've been blocked"));
+        assert!(msg.len() < 200);
+        assert!(!msg.contains(".x{color"));
+    }
+
     #[test]
     fn map_subreddit_about_url() {
         let id = ItemId::from_url("https://reddit.com/r/rust").unwrap();

download full diff B

Hardlinks — judgments / attempts / prompt

prompt download

judgments

attempts

Prompt text is loaded only by the download route.