Conversation
|
Important Draft PR not reviewedDraft PRs are not automatically reviewed by default.
To automatically review draft PRs, update your CodeRabbit configuration: reviews:
auto_review:
drafts: trueThanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
⏳ DRAFT
What to do
Review readiness checklist
1/4 boxes ticked. This pull request was already a draft. Its draft status will be preserved after every issue above is resolved. Hygiene
|
리뷰 · 우선순위 55 / 80이 PR은 Codex 요청을 게이트웨이(중계)로 보낼 때, 응답에 라인 - src/server/auth-cors.ts · responseTierAuthoritative — 비밀이 아닌 편집기 필드 한 줄인데, 인증/관리 표면으로 잡혀 라인 - docs-site …/zh-cn/…/providers.md — 영문은 “Response service-tier authority” 절 전체가 있는데, 중국어는 표에 한 줄만 있습니다. 표 형식 페이지라면 맞을 수 있지만, 영문과 같은 깊이로 읽히지는 않습니다. 라인 - 선언 없는 게이트웨이 — 기본은 예전처럼 응답을 권위로 봅니다. 중계인데 설정을 안 쓰면 라인 - 본문 검증 — 좁힌 FastWire·권위·툴팁 검사는 통과했다고 적혀 있습니다. 전체 스위트는 통과하지 못했고, Draft·체크리스트도 아직 준비 완료가 아닙니다. 메인테이너의 판단이 필요한 지점 너의 추천 이 댓글은 grok-bot이 작성했습니다 |
|
Maintainer triage: Criteria (P2): Medium: provider/client-specific bug with a workaround, bounded enhancement tied to a tracked issue, perf, or CI reliability. Rebased onto current |
…tative A relay can echo service_tier default (or priority) without that echo proving what the upstream scheduled. Providers may now set the optional boolean responseTierAuthoritative: false so the echo stays in logs as evidence only: an eligible Fast request is recorded as applied/assumed, and pricing never treats the echo, or a confirmed label, as response confirmation. Omitting the field keeps the legacy authoritative reading, canonical ChatGPT forwarding stays observational, and the outbound tier decision and local downgrades are unchanged. Carries #5497. Co-authored-by: BigHulk <happyhls@gmail.com>
…tative (#6112) Providers may set the optional boolean responseTierAuthoritative: false so a relay's service_tier echo stays in logs as evidence only: an eligible Fast request is recorded as applied/assumed, and pricing never treats the echo, or a confirmed label, as response confirmation. Omitting the field keeps the legacy authoritative reading, canonical ChatGPT forwarding stays observational, and the outbound tier decision and local downgrades are unchanged. Carries #5497. Co-authored-by: BigHulk <happyhls@gmail.com>
|
Thank you, @hulkbig. This landed on It was carried onto current |
|
Thanks for carrying this into #6112 and preserving the contract and attribution. The added guard keeps persisted confirmed outcomes from being priced as response-confirmed when responseTierAuthoritative is false. |
Summary
Codex requests relayed through an OpenAI-compatible gateway could be labeled
response-declinedwhen the gateway returnedservice_tier: default, even though that response field cannot establish whether Fast was granted. The destination exception introduced for #2558 only matched direct canonical ChatGPT forwarding.responseTierAuthoritative. Setting it tofalsereuses the existing observation policy without naming any gateway or changing capability declarations, routing, or outbound tier serialization.fastOutcome: applied/confirmation: assumed(requested, actual effect unconfirmed). Neither adefaultnor apriorityecho can confirm or deny Fast. Canonical Codex forwarding retains its built-in exception; official API and undeclared routes retain legacy judgments.responseTierAuthoritative: falsewhen the response contract warrants it; upgrading alone does not change undeclared routes. Mixed-contract gateways can use separate provider entries. This does not establish that Fast actually accelerated any request.Related: #2558 (the direct-route fix is already merged). No live provider configuration or service was modified.
Verification
Tested head:
1152e3c9fc2130a0518e4dc5c79de8f16505607b. This includesdev6c2f7676dcedba21bdbacf4fb84a7b2c286d1ee6and a compatibility fix for its new exhaustive model-rename field map: provider-wide response-tier authority is preserved when a model is renamed. The latest checkeddevisc37f4f5f43351feee3ca46736770429ccbd068df; the branch is 4 commits behind it, within the documented 10-commit readiness tolerance. Those intervening commits concern Claude state, CI, and release/version bookkeeping.service_tier: priority, raw echo preservation, persisted logs/tooltips, strict config validation/editor redaction, pricing provenance, and unchanged authority across model renames. Actual Fast acceleration remains unconfirmed.bun run structure:check,bun run privacy:scan, andgit diff --checkpassed. The English/Chinese documentation build passed with 497 pages.bun run test --timeout 60000, with the actualGITHUB_SHAandOCX_TEST_MAIN_TIMEOUT_MS=1800000. This replaces the earlier incomplete-timeout evidence; it is not a clean full-suite pass.jq/service tools, a child-reaping init, and dual-stack networking; its 2-CPU VM also hit short startup watchdogs. After provisioning those container-only prerequisites, the 11 affected files were rerun withCI=true,--parallel=2, and the same 60-second per-test timeout: 514 passed / 3 failed / 23 skipped. Source and assertions were unchanged. Standard public DNS-over-HTTPS was used only inside the test container to avoid the host's fake-IP DNS; no request/response assertion was bypassed.devbaseline reproduced all three (226 passed / 3 failed across the two affected files):CLI subcommand help > status prints diagnostics without starting the proxy,CLI subcommand help > invalid service and codex-shim usage include remove alias, andservice diagnostics > status summary exposes the service log path. The observed diagnostics explicitly report service management as unsupported in Docker. See the documented container exceptions.The local-CI attestation remains unchecked: successful builds and classified baseline failures are not being presented as all tests green. No installed proxy, live provider configuration, or running user service was changed, and Astra capability declarations are untouched.
Security review of the implementation: the single
auth-cors.tsaddition classifies this non-secret boolean as editor-owned. Credential fields, request authentication, CORS, endpoint validation and runtime-only editor exclusions are unchanged; the regression verifies that the declaration round-trips while API keys remain redacted. The hygiene gate still requires maintainer review andmaintainer-sponsoredfor that path. CodeRabbit's previous success status was a skipped draft review, not a completed review.Checklist
All CI tests are green on my local testing.
I pushed my PR to the latest dev commit.
I resolved all correct Codex and CodeRabbit findings.
My PR is ready for review.