Skip to content

feat(fastwire): let a relay declare its service_tier echo non-authoritative - #6112

Merged
lidge-jun merged 1 commit into
devfrom
codex/t4-provider-compat-fastwire
Sep 27, 2026
Merged

lidge-jun merged 1 commit into
devfrom
codex/t4-provider-compat-fastwire

Conversation

@lidge-jun

@lidge-jun lidge-jun commented Sep 27, 2026 •

Copy link
Copy Markdown
Owner

Summary

Some OpenAI-compatible relays echo service_tier in their responses without that echo proving what the upstream actually scheduled. Today such an echo decides the Fast outcome: a relay that answers "default" to a priority request marks it response-declined, and a "priority" echo is recorded, and priced, as confirmed.

A provider can now declare responseTierAuthoritative: false. For that provider the echo stays in logs as evidence only: an eligible Fast request is recorded as applied / assumed, and pricing uses the requested-tier estimate. Neither the raw echo nor a confirmed label counts as response confirmation.

  • Omitting the field keeps today's authoritative reading for every existing provider.
  • Canonical ChatGPT Codex forwarding stays observational (Fast requests are falsely classified as downgraded from ChatGPT backend service_tier metadata #2558) even if a user sets true.
  • The outbound service_tier, the tier decision, and local unsupported-route downgrades are unchanged. The field cannot enable Fast.
  • The value is a strict optional boolean (config validation rejects "false", 0, null and objects), round-trips through the provider editor without exposing the API key, survives a model rename, and is kept on persisted attempt and final usage records. Old records without it read as before.
  • Scope: the flag governs the Responses-path observation. The native Chat Completions passthrough records no response-tier evidence today, so an echo there never confirms Fast or reaches pricing and the flag has nothing to change on that path.
  • Docs: provider configuration reference (English and zh-cn) and the Codex integration guide; structure docs for config, providers, runtime, Responses and the management API.

This carries #5497 by @hulkbig onto current dev, adapted to the moved code. The only behaviour added beyond the original is that a persisted confirmed label with the flag false is priced as a requested-tier estimate.

Co-authored-by: BigHulk happyhls@gmail.com

Verification

  • New tests/routing/fastwire-response-authority.test.ts (27 cases: JSON and SSE relay sends, default and priority echoes with false, absent and true legacy, canonical forward with true, malformed config, editor round trip, persisted attempt and final entries, old records, cost with false + confirmed, unsupported Fast route downgrade). Red-green: with the original cost.ts and core-normalize.ts 10/27 fail; with the change 27/27 pass.
  • On the exact head 95c59fc8da: bun test over the new file plus fastwire-observability, model-rename-migration, provider-config-validation, usage-cost, cost-cap-unknown-evidence, test-layout, test-layout-tooling and file-size-ratchet — 261 pass, 0 fail.
  • bun run typecheck, bun run structure:check, bun run privacy:scan, bun run skill:surface:check, git diff --check — passed. docs-site bun install --frozen-lockfile && bun run build passed.
  • bun run test:changed selects most of the suite here (core-normalize, usage/log and usage/cost are imported widely). In a separate /private/tmp checkout it hit the local 900 s wrapper limit while seven release lanes shared one test lock: 28,409 passed and 19 failed across six service and native-toggle files. Rerunning those files plus the interrupted cli-status-json gave 348 pass and 3 fail. The three failures are the launcher shutdown tests, which fail because this machine's real opencodex proxy is running on port 10100, so the test's launcher starts as a second instance. The other 16 passed in isolation. Full-suite coverage is left to hosted CI.
  • Independent read-only review of the full carry against the plan and fix(fastwire): honor declared response tier authority for relays #5497: PASS, no blockers.

Checklist

  • Scope stays focused and avoids unrelated cleanup.
  • Docs or release notes were updated when needed.
  • Security-sensitive changes were reviewed for secrets, auth, and unsafe defaults.

Summary by CodeRabbit

  • New Features
    • Providers can mark service-tier response echoes as non-authoritative. Fast requests may still be sent, but their Fast status remains unconfirmed, and cost estimates use the requested tier rather than treating the echo as confirmed.
    • Request logs retain the authority setting and raw tier observations. Existing defaults remain unchanged; canonical ChatGPT Codex forwarding continues to treat echoes as non-authoritative.
  • Documentation
    • Added configuration guidance for the new optional provider setting and its effects on Fast status and cost estimates.

@lidge-jun
lidge-jun requested a review from Ingwannu as a code owner September 27, 2026 16:47
@coderabbitai

coderabbitai Bot commented Sep 27, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository: lidge-jun/opencodex/.coderabbit.yaml

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 52c90611-0a8d-4474-82ae-fae6f464102e

📥 Commits

Reviewing files that changed from the base of the PR and between 468b954 and 2e83368.

📒 Files selected for processing (21)
  • docs-site/src/content/docs/guides/codex-integration.md
  • docs-site/src/content/docs/reference/configuration/providers.md
  • docs-site/src/content/docs/zh-cn/reference/configuration/providers.md
  • scripts/test-layout/layout.json
  • src/config/schema/leaf-validators.ts
  • src/providers/fastwire.ts
  • src/providers/model-rename-fields.ts
  • src/providers/openai-tiers-destination.ts
  • src/server/auth-cors.ts
  • src/server/responses/core-normalize.ts
  • src/types/provider.ts
  • src/usage/cost.ts
  • src/usage/log.ts
  • structure/config.md
  • structure/gui-and-management-api.md
  • structure/providers-and-adapters.md
  • structure/runtime.md
  • structure/transports/responses.md
  • tests/fixtures/test-layout-expected.json
  • tests/providers/model-rename-migration.test.ts
  • tests/routing/fastwire-response-authority.test.ts

Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 3 remain after this review.


📝 Walkthrough

Walkthrough

Adds the optional responseTierAuthoritative provider setting. Responses routes use it to interpret service-tier echoes, retain authority in tier outcomes, and determine pricing provenance. Canonical ChatGPT Codex forwarding remains non-authoritative. Documentation and tests cover configuration, routing, persistence, and pricing.

Changes

Response Tier Authority

Layer / File(s) Summary
Configure response-tier authority
src/types/provider.ts, src/config/schema/leaf-validators.ts, src/providers/openai-tiers-destination.ts, src/server/responses/core-normalize.ts, src/server/auth-cors.ts, src/providers/model-rename-fields.ts, tests/providers/model-rename-migration.test.ts, docs-site/src/content/docs/reference/configuration/providers.md, docs-site/src/content/docs/zh-cn/reference/configuration/providers.md, docs-site/src/content/docs/guides/codex-integration.md, structure/config.md, structure/providers-and-adapters.md
Adds the optional boolean provider setting and resolves authority for canonical Codex forwarding. Configuration and provider editing accept the setting, and model renames preserve it. Documentation describes the setting and its behavior.
Record response-tier outcomes
src/types/provider.ts, src/providers/fastwire.ts, src/usage/log.ts, src/server/responses/core-normalize.ts, tests/routing/fastwire-response-authority.test.ts, scripts/test-layout/layout.json, tests/fixtures/test-layout-expected.json, structure/runtime.md, structure/transports/responses.md
Passes authority into tier observation and retains it in normalized outcomes. Routing tests cover streaming and non-streaming requests, response echoes, logs, and downgrades.
Apply authority to pricing provenance
src/usage/cost.ts, tests/routing/fastwire-response-authority.test.ts, structure/gui-and-management-api.md
Requires authoritative response evidence for response-confirmed pricing. Tests cover the requested-tier fallback when outcomes are non-authoritative.

Priority: ➖ Normal

Estimated code review effort: 3 (Moderate) | ~20 minutes

Change: Feature

Sequence Diagram(s)

sequenceDiagram
  participant ProviderConfig
  participant CoreNormalize
  participant FastWire
  participant UsageLog
  participant CostEstimation
  ProviderConfig->>CoreNormalize: response-tier authority setting
  CoreNormalize->>FastWire: tier observation context
  FastWire->>UsageLog: tier outcome with authority and response tier
  UsageLog->>CostEstimation: normalized tier outcome
Loading

Possibly related PRs

  • lidge-jun/opencodex#1965: Establishes the FastWire observation contract that this change extends with provider-specific response-tier authority.
  • lidge-jun/opencodex#2080: Adds related priority response-tier observation and pricing behavior; this change adjusts how Responses-route echoes affect those outcomes.
  • lidge-jun/opencodex#1956: Introduces persisted tier outcomes and per-attempt pricing, which this change extends with authority-aware pricing provenance.

Suggested reviewers: luvs01

Merge Risk: ⚪ Minimal · up to 2e833

No actionable issue remains before merge; normal checks still apply.

Security Architecture Review

Security architecture risk: 🟡 Moderate · up to 2e833

The change makes Fast outcomes and price estimates depend on a provider setting rather than the upstream response alone. The setting does not enable Fast or change what is sent upstream, but an assumed outcome is not proof of the service actually delivered. No new security-boundary bypass was established.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — A provider setting affects eligible Responses requests routed to that provider and their usage estimates. It does not by itself expand Fast eligibility or alter the outbound service tier.

Trust Boundaries and Controls

  • observed — An upstream-controlled echo is still recorded, but false provider authority prevents it from becoming Fast confirmation or response-confirmed pricing evidence. Locally unavailable Fast remains a downgrade.
  • inferred — The new editor-writable field gives an admitted provider editor control over evidence policy, but the examined editor parser continues to reject redacted fields. The reviewed path does not establish direct data-plane control of this setting.

Resilience and Maintainability Implications

  • observed — Request logging attaches the tier outcome to the active attempt, and usage normalization preserves its authority value. Price estimation reads the attempt outcome when present rather than reinterpreting its response echo alone.
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 55.56% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 9 functions across 11 files. (10 skipped:… Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly summarizes the main change: it lets a relay declare its service_tier echo non-authoritative.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Full details: Docstring Coverage

Explanation

Docstring coverage is 55.56% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 9 functions across 11 files. (10 skipped: 10 unsupported.)

  • Fix all pre-merge checks with AI
✨ Finishing Touches 💡 1
📝 Generate docstrings 💡
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 27, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-27T16:52:20.129555Z 95c59fc PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 95c59fc8da

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

config.fastMode,
callerTier,
isCanonicalOpenAiForwardProvider(route.provider) ? false : undefined,
responseTierAuthorityForProvider(route.provider),

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Apply response authority to native Chat requests

When /v1/chat/completions targets an eligible openai-chat provider, handleChatCompletions exits through handleNativeChatCompletions before this normalizer runs. That path builds its tier decision directly in buildOpenAIChatPassthroughRequest and never calls responseTierAuthorityForProvider or creates tier metadata, so responseTierAuthoritative: false is ignored: the response echo is not retained as assumed evidence and persisted attempts omit the authority flag. Thread this policy through the native Chat request/response path and add focused streaming and non-streaming coverage.

AGENTS.md reference: AGENTS.md:L447-L451

Useful? React with 👍 / 👎.

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Traced this and it holds in the narrow sense: the native Chat passthrough never consults the declaration. It also never observes the echo. buildOpenAIChatPassthroughRequest returns no tierLog (src/adapters/openai-chat/passthrough.ts), and neither the JSON path (src/server/chat-native.ts) nor the SSE path (src/server/chat-native-sse.ts) records service_tier into logCtx.responseServiceTier or an attempt outcome. So on that path an echo can't confirm or deny Fast, and pricing falls back to the requested tier (serviceTierContext in src/usage/cost.ts), which is what responseTierAuthoritative: false asks for anyway.

Nothing is mis-recorded there today. Adding response-tier observation to native Chat would be a new feature and is out of scope for this carry. I've noted in the PR description that the flag governs the Responses-path observation, and that native Chat records no response-tier evidence.

@github-actions github-actions Bot added the enhancement New feature or request label Sep 27, 2026
@github-actions

Copy link
Copy Markdown
Contributor

✅ Deterministic PR hygiene checks passed.

@lidge-jun

Copy link
Copy Markdown
Owner Author

리뷰 · 우선순위 60 / 80

이 PR은 중계 서버가 돌려준 service_tier를, Fast가 실제로 적용됐다는 증거로 보지 않게 하는 설정을 넣어요. 바탕은 dev예요.

지금 코드는 중계 응답의 service_tier를 믿어요. 우리가 priority를 보냈는데 응답이 "default"면 Fast가 거절된 것(response-declined)으로 적어요. 응답이 "priority"면 확인된 것으로 보고, 요금도 확인된 Fast로 계산해요. 어떤 중계는 그 칸을 요청을 따라 적을 뿐이라, 그 값만으로 빠른 처리가 됐는지 알 수 없어요.

공급자 설정에 responseTierAuthoritative: false를 적으면, 그 응답 칸은 로그에만 남아요. Fast를 보낼 수 있는 요청은 applied와 assumed로 기록되고, 요금은 요청한 등급의 견적으로 계산해요. 설정을 빼면 예전처럼 응답을 믿어요. ChatGPT Codex로 그대로 넘기는 주소는 사용자가 true를 적어도 응답을 믿지 않아요. 이 설정은 Fast를 켜지 않고, 나가는 service_tier도 바꾸지 않아요. 값은 참과 거짓만 받아요. "false", 0, null은 설정 검사에서 거절해요. 편집기에서 다시 읽어도 API 키는 안 나가요. 모델 이름을 바꿔도 이 값은 남아요. 예전에 저장된 기록에 이 칸이 없으면 예전 방식으로 읽어요.

열려 있는 #5497을 지금 dev에 다시 올린 변경이에요. #5497보다 하나 더 있어요. 저장된 기록의 확인 상태가 confirmed여도, 그 기록의 이 설정이 거짓이면 확인 요금이 아니라 요청 견적으로 계산해요.

라인 - src/server/chat-native.ts 332행. /v1/chat/completions의 네이티브 Chat은 src/server/responses/core-normalize.ts 229행을 거치지 않아요. 332행은 buildOpenAIChatPassthroughRequest만 불러서 나가는 service_tier를 정해요. 응답의 service_tier로 Fast 결과를 만들지 않아서, responseTierAuthoritative: false가 그 시도 기록에는 안 남아요. 그 길은 원래도 응답을 response-declined로 읽지 않아요. 이번 수정이 적용되는 곳은 Responses로 들어와서 tierObservation을 쓰는 길이에요.

라인 - src/usage/cost.ts 442행. 이 설정이 거짓이고 요청이 priority면, 응답이 default여도 요청 견적의 배율을 써요. 이 PR 테스트의 가격표에서 그 배율은 2예요. 중계가 실제로 Fast를 안 줬어도 거절로 깎지 않아요. 문서에 적힌 견적이에요. 확인된 요금은 아니에요.

메인테이너의 판단이 필요한 지점

네이티브 Chat 시도에도 같은 tierOutcome을 남길지 정하면 돼요. 그 길은 응답을 거절로 읽지 않아서, 이 PR이 고친 오해가 거기서 반복되지는 않아요. 기록 모양만 Responses 쪽과 달라요.

#5497은 아직 열려 있고 지금 dev와 충돌해요. 이 PR이 그 내용을 현재 dev에 다시 담았어요. #5497을 닫을지 정하면 돼요.

이 설정을 끈 공급자는 응답이 default여도 priority 요청 견적을 유지해요. 그 견적을 쓸지 정하면 돼요.

너의 추천

바탕은 dev로 두세요. types.ts와 config.ts를 나누는 일과는 다른 변경이에요. #5497은 이 PR이 대신하므로 닫으세요. 네이티브 Chat은 이번 머지에 넣지 않아도 돼요. 나중에 그 길의 기록도 맞추려면 runNativeChatAttempt에서 responseTierAuthorityForProvider로 tierOutcome을 만들면 돼요. 요금은 요청 견적으로 두는 지금 계산이 이 PR의 목적과 맞아요.

이 댓글은 grok-bot이 작성했습니다

…tative

A relay can echo service_tier default (or priority) without that echo
proving what the upstream scheduled. Providers may now set the optional
boolean responseTierAuthoritative: false so the echo stays in logs as
evidence only: an eligible Fast request is recorded as applied/assumed,
and pricing never treats the echo, or a confirmed label, as response
confirmation. Omitting the field keeps the legacy authoritative reading,
canonical ChatGPT forwarding stays observational, and the outbound tier
decision and local downgrades are unchanged.

Carries #5497.

Co-authored-by: BigHulk <happyhls@gmail.com>
@lidge-jun

Copy link
Copy Markdown
Owner Author

Maintainer integration into dev (MAINTAINERS.md, dev-only integration without a second approval). This is not a self-approval.

  • Exact head: 2e83368b3fc5906d23891c904f86beca48d9d3c2, which contains current dev 468b954cc4.
  • Cross-platform CI run 36339549490 (pull_request): aggregate ci success; dispatch- and path-gated jobs skipped. enforce-target succeeded on the same head.
  • Independent read-only review of the carry: PASS. The Codex P2 about native Chat is answered: that path records no response-tier evidence, so the flag has nothing to change there. The PR description states the scope.
  • The squash commit keeps Co-authored-by: BigHulk <happyhls@gmail.com> for the carried fix(fastwire): honor declared response tier authority for relays #5497.

@lidge-jun
lidge-jun merged commit 773c24b into dev Sep 27, 2026
34 of 35 checks passed
@lidge-jun
lidge-jun deleted the codex/t4-provider-compat-fastwire branch September 27, 2026 18:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant