Skip to content

feat(codex): add transparent native provider transport - #2943

Open
rixzkiye wants to merge 1 commit into
decolua:masterfrom
rixzkiye:feat/codex-native-parity-pr
Open

rixzkiye wants to merge 1 commit into
decolua:masterfrom
rixzkiye:feat/codex-native-parity-pr

Conversation

@rixzkiye

Copy link
Copy Markdown
Contributor

Summary

Add a dedicated Codex Native provider path that keeps Codex CLI in control of
agent behavior, sessions, tools, compaction, and model metadata. 9Router only
handles client authentication, account selection, quota-aware failover, proxy
selection, and protocol relay.

  • relay native request bodies, SSE bytes, WebSocket text frames, and unknown
    future fields without passing through the Universal translator
  • sanitize client credentials and hop-by-hop headers, then rebuild OAuth bearer
    and ChatGPT account headers from the selected 9Router Codex account
  • expose native models, responses, compact, memory trace, search, and image
    endpoints under /v1/codex
  • add a one-port WebSocket gateway with compression, ping/pong, close-code,
    backpressure, HTTP CONNECT, SOCKS, and strict-proxy handling
  • group full ModelInfo metadata into deterministic account cohorts and cache
    catalogs per client version/account/ETag
  • add HMAC session affinity, quota hysteresis, model/proxy capability ranking,
    lease lifecycle tracking, and safe pre-output failover
  • prevent replay after semantic output and avoid replaying ambiguous image or
    auxiliary-operation transport failures
  • add provider-scoped Codex command auth without overwriting the user's global
    ~/.codex/auth.json
  • add native readiness/repair controls and account/catalog/lease visibility to
    the Codex dashboard card
  • package the gateway and its recursive runtime dependency tree for standalone,
    CLI, Docker, and the native development launcher

Motivation

Codex CLI's native model metadata and reasoning levels (including max and
ultra) must be handled as a provider protocol, not translated as Universal
chat traffic. Responses requests do not always repeat client_version, so the
native relay resolves it from the request, installed Codex CLI, or the most
recent valid catalog instead of returning a false
codex_catalog_unavailable 503.

Safety properties

  • client Authorization, account ID, cookies, forwarding, proxy, host, and
    hop-by-hop headers never reach the upstream
  • internal lease APIs require both a process-local secret and a loopback peer
  • tokens, raw prompts, and raw session IDs are not exposed in dashboard state
  • an account can be retried only before semantic output; partial text,
    reasoning, tool calls, images, or output items disable replay for that turn
  • no fabricated model catalog is returned; a last-known-good catalog is marked
    stale and absence of any valid catalog is explicit
  • realtime voice/WebRTC remains out of scope

Verification

  • ESLint passed for all added and modified Codex Native files
  • 27/27 focused unit and contract tests passed:
    • raw body/header/SSE passthrough and credential rebuilding
    • client-version fallback and versioned catalog behavior
    • metadata cohorts, affinity, quota hysteresis, and proxy eligibility
    • internal lease API loopback protection
    • WebSocket compression, ping/pong, close behavior, binary rejection, model
      cohort switching, and handshake header filtering
    • auxiliary endpoint mapping and image no-replay behavior
  • pnpm build passed from an isolated worktree based on current
    origin/master, including all 133 routes, build traces, and standalone
    gateway dependency packaging

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant