Skip to content

fix(fastwire): honor declared response tier authority for relays - #5497

Closed
hulkbig wants to merge 4 commits into
lidge-jun:devfrom
hulkbig:codex/fast-response-tier-authority
Closed

hulkbig wants to merge 4 commits into
lidge-jun:devfrom
hulkbig:codex/fast-response-tier-authority

Conversation

@hulkbig

@hulkbig hulkbig commented Sep 22, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Codex requests relayed through an OpenAI-compatible gateway could be labeled response-declined when the gateway returned service_tier: default, even though that response field cannot establish whether Fast was granted. The destination exception introduced for #2558 only matched direct canonical ChatGPT forwarding.

  • Add the optional, strictly boolean provider declaration responseTierAuthoritative. Setting it to false reuses the existing observation policy without naming any gateway or changing capability declarations, routing, or outbound tier serialization.
  • An eligible serialized priority request retains the raw response tier and reports fastOutcome: applied / confirmation: assumed (requested, actual effect unconfirmed). Neither a default nor a priority echo can confirm or deny Fast. Canonical Codex forwarding retains its built-in exception; official API and undeclared routes retain legacy judgments.
  • Persist the authority flag with each attempt and the final outcome. Cost estimation ignores a non-authoritative echo and uses existing requested-tier provenance; it cannot treat that echo as confirmed billing evidence. Existing log tooltips retain the raw response and the assumed qualifier.
  • Document configuration, provider scope, defaults, historical-record compatibility, and cost semantics in English and Chinese. Gateway users must explicitly add responseTierAuthoritative: false when the response contract warrants it; upgrading alone does not change undeclared routes. Mixed-contract gateways can use separate provider entries. This does not establish that Fast actually accelerated any request.

Related: #2558 (the direct-route fix is already merged). No live provider configuration or service was modified.

Verification

Tested head: 1152e3c9fc2130a0518e4dc5c79de8f16505607b. This includes dev 6c2f7676dcedba21bdbacf4fb84a7b2c286d1ee6 and a compatibility fix for its new exhaustive model-rename field map: provider-wide response-tier authority is preserved when a model is renamed. The latest checked dev is c37f4f5f43351feee3ca46736770429ccbd068df; the branch is 4 commits behind it, within the documented 10-commit readiness tolerance. Those intervening commits concern Claude state, CI, and release/version bookkeeping.

  • Local production dashboard builds, TypeScript checks, and package preparation passed on both macOS arm64 and an isolated Linux arm64 container, with Bun 1.4.0 and frozen dependency locks. No tracked build output or dependency change is included.
  • The response-authority and model-rename regression files passed: 73 passed, 0 failed. Coverage includes direct Codex, explicitly non-authoritative relays, undeclared/explicit-true relays, the official API, JSON and SSE through the real Responses handler, exact outbound service_tier: priority, raw echo preservation, persisted logs/tooltips, strict config validation/editor redaction, pricing provenance, and unchanged authority across model renames. Actual Fast acceleration remains unconfirmed.
  • bun run structure:check, bun run privacy:scan, and git diff --check passed. The English/Chinese documentation build passed with 497 pages.
  • The full local Linux suite completed on this head: 28,447 passed / 38 failed / 55 skipped (899 seconds, exit 1). It was run through bun run test --timeout 60000, with the actual GITHUB_SHA and OCX_TEST_MAIN_TIMEOUT_MS=1800000. This replaces the earlier incomplete-timeout evidence; it is not a clean full-suite pass.
  • The minimal test container initially lacked jq/service tools, a child-reaping init, and dual-stack networking; its 2-CPU VM also hit short startup watchdogs. After provisioning those container-only prerequisites, the 11 affected files were rerun with CI=true, --parallel=2, and the same 60-second per-test timeout: 514 passed / 3 failed / 23 skipped. Source and assertions were unchanged. Standard public DNS-over-HTTPS was used only inside the test container to avoid the host's fake-IP DNS; no request/response assertion was bypassed.
  • The remaining three failures exactly match the repository's documented container service-management limitations. An untouched checkout of the same dev baseline reproduced all three (226 passed / 3 failed across the two affected files): CLI subcommand help > status prints diagnostics without starting the proxy, CLI subcommand help > invalid service and codex-shim usage include remove alias, and service diagnostics > status summary exposes the service log path. The observed diagnostics explicitly report service management as unsupported in Docker. See the documented container exceptions.

The local-CI attestation remains unchecked: successful builds and classified baseline failures are not being presented as all tests green. No installed proxy, live provider configuration, or running user service was changed, and Astra capability declarations are untouched.

Security review of the implementation: the single auth-cors.ts addition classifies this non-secret boolean as editor-owned. Credential fields, request authentication, CORS, endpoint validation and runtime-only editor exclusions are unchanged; the regression verifies that the declaration round-trips while API keys remain redacted. The hygiene gate still requires maintainer review and maintainer-sponsored for that path. CodeRabbit's previous success status was a skipped draft review, not a completed review.

Checklist

  • Scope stays focused and avoids unrelated cleanup.
  • Docs or release notes were updated when needed.
  • Security-sensitive changes were reviewed for secrets, auth, and unsafe defaults. (Implementation inspected and privacy scan passed; maintainer review pending.)
  • All CI tests are green on my local testing.

  • I pushed my PR to the latest dev commit.

  • I resolved all correct Codex and CodeRabbit findings.

  • My PR is ready for review.

@coderabbitai

coderabbitai Bot commented Sep 22, 2026

Copy link
Copy Markdown
Contributor

Important

Draft PR not reviewed

Draft PRs are not automatically reviewed by default.

  • Trigger a manual review

To automatically review draft PRs, update your CodeRabbit configuration:

reviews:
  auto_review:
    drafts: true

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions github-actions Bot added bug Something isn't working intake: hygiene-blocked Deterministic PR hygiene checks failed labels Sep 22, 2026
@github-actions

Copy link
Copy Markdown
Contributor

⚠️ Deterministic hygiene checks failed.

  • unsponsored_surface — This changes an authentication, workflow, release-automation, or dependency surface. MAINTAINERS.md requires security review for these; ask a maintainer to apply maintainer-sponsored once they have reviewed it. Paths: src/server/auth-cors.ts.

@github-actions

github-actions Bot commented Sep 22, 2026 •

Copy link
Copy Markdown
Contributor

⏳ DRAFT

  • hygiene: unsponsored_surface.

What to do

  • Fix unsponsored_surface — This changes an authentication, workflow, release-automation, or dependency surface. MAINTAINERS.md requires security review for these; ask a maintainer to apply maintainer-sponsored once they have reviewed it. Paths: src/server/auth-cors.ts.
  • Tick all four boxes in the PR description once you're done (currently 1/4).

Review readiness checklist

  • ⬜ All CI tests are green on my local testing.
  • ✅ I pushed my PR to the latest dev commit.
  • ⬜ I resolved all correct Codex and CodeRabbit findings.
  • ⬜ My PR is ready for review.

1/4 boxes ticked.

This pull request was already a draft. Its draft status will be preserved after every issue above is resolved.
@hulkbig Tick the boxes once your local CI is green, your branch is on the latest dev commit, and every correct Codex and CodeRabbit finding is resolved.

Hygiene

⚠️ Deterministic hygiene checks failed.

  • unsponsored_surface — This changes an authentication, workflow, release-automation, or dependency surface. MAINTAINERS.md requires security review for these; ask a maintainer to apply maintainer-sponsored once they have reviewed it. Paths: src/server/auth-cors.ts.

@lidge-jun

Copy link
Copy Markdown
Owner

리뷰 · 우선순위 55 / 80

이 PR은 Codex 요청을 게이트웨이(중계)로 보낼 때, 응답에 service_tier: default가 와도 Fast를 거절당한 것처럼 잘못 찍히던 일을 고칩니다. 예전에 #2558은 ChatGPT Codex로 바로 보내는 길만 예외로 두었습니다. 게이트웨이는 그 예외에 안 들어가서, 같은 응답 때문에 로그에 response-declined가 났습니다. 이번엔 provider 설정에 responseTierAuthoritative라는 참/거짓 칸을 둡니다. false로 적으면 “이 길의 응답 등급은 Fast 여부를 증명하지 못한다”고 선언합니다. Fast를 켜거나 나가는 service_tier를 바꾸지는 않습니다. priority를 보낸 요청은 응답 에코를 그대로 남기고, fastOutcome: applied / confirmation: assumed(요청은 보냈고, 실제 효과는 미확인)로 기록합니다. 비용 계산도 그 에코를 “확정 요금”으로 쓰지 않고, 예전에 쓰던 요청 등급 쪽을 따릅니다. 공식 API와 선언 없는 게이트웨이는 예전처럼 응답을 믿습니다. Codex 정본 주소 + forward는 설정이 true여도 계속 비권위입니다. 문서는 영문 안내·중국어 표·structure에 넣었고, Responses 실경로 회귀 테스트가 새로 있습니다. base는 dev입니다. types/config 분할·프리뷰 배포와는 무관합니다. 같은 주제로 닫을 다른 열린 PR은 없습니다. 지금 Draft이고, 위생 검사 unsponsored_surface(src/server/auth-cors.ts) 때문에 게이트가 막혀 있습니다. 본문도 전체 bun run test는 타임아웃·환경 문제로 통과하지 못했다고 적혀 있습니다.

라인 - src/server/auth-cors.ts · responseTierAuthoritative — 비밀이 아닌 편집기 필드 한 줄인데, 인증/관리 표면으로 잡혀 maintainer-sponsored가 필요합니다. 키 노출·CORS·엔드포인트 검사는 안 바뀌었고, 회귀도 에디터 왕복 때 apiKey가 안 나가는지 봅니다. 코드 위험보다 합치기 전 스폰서 라벨이 빠져 있는 상태입니다.

라인 - docs-site …/zh-cn/…/providers.md — 영문은 “Response service-tier authority” 절 전체가 있는데, 중국어는 표에 한 줄만 있습니다. 표 형식 페이지라면 맞을 수 있지만, 영문과 같은 깊이로 읽히지는 않습니다.

라인 - 선언 없는 게이트웨이 — 기본은 예전처럼 응답을 권위로 봅니다. 중계인데 설정을 안 쓰면 default 에코에 또 response-declined가 납니다. 이름·URL로 추측하지 않기로 한 설계라서 의도이지만, 고친 뒤에도 설정 안 한 중계는 증상이 그대로입니다.

라인 - 본문 검증 — 좁힌 FastWire·권위·툴팁 검사는 통과했다고 적혀 있습니다. 전체 스위트는 통과하지 못했고, Draft·체크리스트도 아직 준비 완료가 아닙니다.

메인테이너의 판단이 필요한 지점
게이트웨이는 운영자가 false를 직접 적는 방식이 맞는지, 아니면 더 많은 목적지를 자동으로 비권위로 둘지 정해야 합니다. auth-cors.ts 한 줄에 maintainer-sponsored를 지금 붙일지, 보안 리뷰를 더 볼지도 정해야 합니다. Draft를 풀고 전체 스위트를 다시 돌리기 전에 머지할지 여부도 판단이 필요합니다.

너의 추천
Draft를 풀고 maintainer-sponsored를 붙인 뒤에 합치세요. 좁힌 회귀가 있으면 그걸로 충분해 보입니다. 합치기 전에 게이트웨이 사용자 안내에 responseTierAuthoritative: false를 꼭 적으라고 한 번 더 짚어 주세요. 중국어 쪽은 표만으로 둘지, 영문 절을 짧게라도 맞출지 정해 주세요. 이 PR을 닫을 중복은 없습니다.

이 댓글은 grok-bot이 작성했습니다

@devin-ai-integration devin-ai-integration Bot added the priority: P2 Medium: provider/client-specific bug with a workaround, bounded enhancement tied to a tracked issue, label Sep 24, 2026
@devin-ai-integration

Copy link
Copy Markdown
Contributor

Maintainer triage: priority: P2 — fastwire response-tier authority for relays.

Criteria (P2): Medium: provider/client-specific bug with a workaround, bounded enhancement tied to a tracked issue, perf, or CI reliability.

Rebased onto current dev: branch rebase/pr-5497 @ dd48dec4f (compare). Your fork branch could not be updated directly; you can adopt it with git fetch https://github.com/lidge-jun/opencodex.git rebase/pr-5497 && git reset --hard FETCH_HEAD && git push --force-with-lease. CI was intentionally not run.

lidge-jun added a commit that referenced this pull request Sep 27, 2026
…tative

A relay can echo service_tier default (or priority) without that echo
proving what the upstream scheduled. Providers may now set the optional
boolean responseTierAuthoritative: false so the echo stays in logs as
evidence only: an eligible Fast request is recorded as applied/assumed,
and pricing never treats the echo, or a confirmed label, as response
confirmation. Omitting the field keeps the legacy authoritative reading,
canonical ChatGPT forwarding stays observational, and the outbound tier
decision and local downgrades are unchanged.

Carries #5497.

Co-authored-by: BigHulk <happyhls@gmail.com>
lidge-jun added a commit that referenced this pull request Sep 27, 2026
…tative (#6112)

Providers may set the optional boolean responseTierAuthoritative: false
so a relay's service_tier echo stays in logs as evidence only: an
eligible Fast request is recorded as applied/assumed, and pricing never
treats the echo, or a confirmed label, as response confirmation.
Omitting the field keeps the legacy authoritative reading, canonical
ChatGPT forwarding stays observational, and the outbound tier decision
and local downgrades are unchanged.

Carries #5497.

Co-authored-by: BigHulk <happyhls@gmail.com>
@lidge-jun

Copy link
Copy Markdown
Owner

Thank you, @hulkbig. This landed on dev through #6112 (squash commit 773c24b), and the commit credits you with a Co-authored-by trailer.

It was carried onto current dev because the branch had drifted and conflicted with the newer fastEnabled and cost code. Your contract is intact: a provider can set responseTierAuthoritative: false so a relay's service_tier echo is kept as evidence only, omitting it keeps today's behaviour, and canonical ChatGPT forwarding stays observational. Review added one guard on top: a persisted confirmed label is also not priced as response-confirmed when the flag is false. Closing this in favour of #6112.

@hulkbig

hulkbig commented Sep 30, 2026

Copy link
Copy Markdown
Contributor Author

Thanks for carrying this into #6112 and preserving the contract and attribution. The added guard keeps persisted confirmed outcomes from being priced as response-confirmed when responseTierAuthoritative is false.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working intake: hygiene-blocked Deterministic PR hygiene checks failed priority: P2 Medium: provider/client-specific bug with a workaround, bounded enhancement tied to a tracked issue,

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants