Conversation
… probes Publish the lidge-jun#5848 implementation alternatives and executable specifications. Prefer an opt-in native remote-only list policy over a shared-backend relay. Keep the existing runtime, authentication, routing and history untouched. Validation: 60 isolated Python tests passed; native/Bun/mobile validation remains outstanding. This is an RFC and research unit, not a production fix for lidge-jun#5848.
|
Important Draft PR not reviewedDraft PRs are not automatically reviewed by default.
To automatically review draft PRs, update your CodeRabbit configuration: reviews:
auto_review:
drafts: trueThanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
✅ Deterministic PR hygiene checks passed. |
리뷰 · 우선순위 36 / 80이 PR은 연구 문서와 파이썬 시험만 추가합니다. 휴대폰 목록에서 다음에 만들 방법으로 적힌 안은 이렇습니다. 휴대폰 앱을 그대로 두고, 서버가 원격 접속이라고 확인한 옆에 남겨 둔 다른 안은 로컬 중계입니다. 앱 서버로 가기 전에, 빠뜨린 라인 - 라인 - 메인테이너의 판단이 필요한 지점 이 PR로 #5848을 닫을지. 닫으면 목록이 고쳐진 것으로 남습니다. 작성자는 고침이 아니라고 적었고 PR은 draft입니다. 다음 구현을 네이티브 서버의 원격 전용 설정으로 갈지, 예시 TOML 키를 지금 설정에 넣을지. 업스트림 앱 서버에는 그 키가 없습니다. 너의 추천 draft로 유지하세요. #5848과 중복 #5906은 열어 두세요. 베이스는 이 댓글은 grok-bot이 작성했습니다 |
|
Applied at a0f933c: On the relay's null-vs-omission difference: |
Ingwannu
left a comment
There was a problem hiding this comment.
Reviewed exact head a0f933c. The probe does not yet match the upstream ThreadId contract claimed by this PR. Upstream parses ThreadId as a UUID; the Python probe rejects only blank strings and its own fixtures accept non-UUID values such as fixture-parent, p, and a. This can certify behavior the upstream implementation would reject.
Please validate UUID syntax in the probe and change the fixtures/negative cases accordingly. Also update the verification counts: the current static inventory is 23 native + 29 relay + 9 loopback = 61 cases, while the documentation/PR text still says 22/60. Hosted CI did not execute these Python probes on this head; most relevant jobs were skipped, so the corrected probes need an actually executed CI path before approval.
Summary
Draft RFC and executable specifications only — this is not a production fix, does not change OpenCodex runtime behavior, and does not close #5848.
Related: #5848, duplicate #5906, openai/codex#48358, and the existing #6007/#6070 mitigation.
This PR publishes the investigated alternatives in one isolated research unit,
devlog/_plan/260928_remote_thread_provider_policy/, so the next implementation can be reviewed against a concrete contract rather than adding an unverified backend relay to the runtime.Preferred implementation proposal
When host-side control is needed without changing the mobile app, prefer an operator-opt-in, native Codex app-server policy for remote
thread/listrequests. The actual Rust configuration, schema, and request-handler plumbing remain to be implemented upstream; the Python code here is an executable specification, not that implementation.ConnectionOrigin::RemoteControl, never a client name or caller-supplied field.[]; preserve the existing parent/ancestor-query exception.Option<Vec<String>>semantics.Alternatives included
chatgpt_base_url: a concrete research fallback, with the existing loopback-only mock probe retained. The shared base URL, enrollment identity, token forwarding, multi-segment messages, reconnects, and non-remote backend consumers make it inappropriate to ship as a small default-on workaround. Live ChatGPT/mobile operation is unverified.The original provider-isolation rationale in openai/codex#5658 is retained. Global omission-to-all changes and history retagging are not proposed. The illustrative configuration name in the design is not an existing supported setting. ADR-5848 and the current warning remain unchanged pending an accepted and released implementation.
Verification
Base:
devateb7f0f0970c2298f8b2d66d170c4d4be869f301b. Authored head:1e3a1c94ea0c74f6ca448d1460ba67d187c823bb.Executed on Linux with Python 3.13.5 and aiohttp 3.13.3:
cd devlog/_plan/260928_remote_thread_provider_policy/probes python -m unittest -v test_native_policy test_probe test_loopback_bridge60 tests passed, 0 failures: 22 proposed native-policy contract tests, 29 raw-frame transformation tests, and 9 localhost HTTP/WebSocket mock-relay tests. The synthetic database contains 5,200
openairows, oneopencodexrow, and one unrelated-provider row. Fixture filtering/pagination produces 1 / 5,201 / 5,202 results as appropriate, without mutating its dump. This is not a native Codex database or native cursor test.Also checked:
git diff --cached --check: passed for the authored files.Not run / not established: native Rust implementation/build/tests, actual mobile pairing/list/resume, production multi-chunk/reconnect handling, OpenCodex Bun typecheck/full tests/structure/privacy gates, and independent security review. Bun and a full checkout were unavailable in the execution environment; the checkout attempt failed at DNS resolution. These Python tests do not substitute for those gates, so this PR remains draft. Detailed commands and limitations are in
020_verification.md.Checklist
Review readiness
devcommit observed at publication.