Address review feedback on #1911:
- Greptile P1 (blocking): OAuth scope/permission failures are permanent
(operator must re-authorize), so they are removed from the transient-auth
classifier. A new SCOPE_ERROR_RE exclusion runs BEFORE the transient match,
so scope errors wrapped in a generic {"type":"authentication_error"}
envelope are also excluded instead of being retried for ~10 s.
- CodeRabbit: add a test for abort during the auth-retry sleep, covering the
auth-specific short-circuit (the existing abort test only exercised the
rate-limit backoff path).
- Add a regression test asserting scope errors (plain text, JSON-wrapped, and
OAuth error codes insufficient_scope/invalid_scope) are not retried.
- Add a changeset (@runfusion/fusion: patch) — engine retry behavior ships in
the published CLI bundle.
- Add FNXC requirement comments encoding the retry-budget invariants
(separate auth budget, flat ~5 s delay, no rate-limit-attempt consumption,
abort short-circuit, scope exclusion ordering).
Tests: 17/17 (rate-limit-retry). tsc --noEmit clean. eslint --fix clean.