Skip to content

fix(codex): align client identity, scope model failures and validate streams - #3870

Open
anndev-69 wants to merge 4 commits into
decolua:masterfrom
anndev-69:fix/codex-compatibility-and-model-health
Open

anndev-69 wants to merge 4 commits into
decolua:masterfrom
anndev-69:fix/codex-compatibility-and-model-health

Conversation

@anndev-69

@anndev-69 anndev-69 commented Sep 8, 2026 •

Copy link
Copy Markdown
Contributor

Codex discovery can list a model while requests advertise an older client identity. Separately, a model-access 400/404 currently marks the whole connection unavailable, quota auto-ping hardcodes gpt-5.5, and HTTP 200 streams can contain failures that are discarded or counted as successful pings.

This change handles these paths together:

  • Share client identity 0.153.4 across discovery, chat, images and credential probes. Preserve the original author of Jordannst's image identity change.
  • Keep Codex model-access failures on the affected account/model pair, retaining fallback to another account and eligibility for other models. Show a separate model warning in Connections. Client-version failures return directly without cycling through accounts. Other provider/auth/quota failures retain existing behavior.
  • Select the quota auto-ping model in the Codex dashboard, defaulting to Luna with low reasoning. Preserve per-account opt-ins and record success only after a completed Responses event. Failed saves revert the selection and show an error.
  • Parse incremental SSE, data-only events, CRLF, EOF and completed-response image output. Preserve upstream errors/statuses, cancel the upstream reader on client disconnect, and never emit image success after a terminal failure.
  • Allow explicit, opt-in CODEX_IMAGE_MODEL_ALIASES for clients that cannot yet change image IDs. There is no automatic model rewrite. A model-access 404 does not establish global retirement or grant access to an alias target.

Configuration, behavior and local fixture instructions are in docs/CODEX_COMPATIBILITY.md. No dependencies or database schema change.

Validation

Final commit: 1137fefc. All HTTP/browser evidence below uses synthetic local accounts and upstream responses, not a live-provider availability claim.

npm test --prefix tests -- unit/codex unit/quota-auto-ping.test.js unit/image-generation.test.js unit/auth-status.test.js --exclude unit/codex-image-fetch.test.js
 Test Files  15 passed (15)
      Tests  119 passed (119)

Reproduction: copying the framing, model-health and quota auto-ping regression suites onto the previous PR head 3abca444 produced 16 failed / 18 passed. The corresponding suites pass on this branch.

npm run build completed, including standalone asset copying. ESLint over changed JavaScript files has zero new findings compared with the previous implementation. It still reports three existing react-hooks/set-state-in-effect errors and four existing warnings. The expanded test run additionally reproduces two existing remote-image-inlining failures in codex-image-fetch.test.js; the same two fail at 3abca444, so that file is excluded from the green command above rather than presenting the wider run as fully green.

After building, start node tests/fixtures/codex-http-server.cjs, then run:

node tests/fixtures/codex-http-check.mjs

Actual output:

invalid API key: HTTP 401
configured legacy image alias: HTTP 200, 68 PNG bytes
unavailable unmapped model: HTTP 404
connection remains active; warning scoped to gpt-5.4-image
same account, other model: HTTP 200
embedded client-version failure, JSON: HTTP 400
embedded client-version failure, SSE: HTTP 200, error status 400, no done event
HTTP fixture checks passed

Browser verification against the built local dashboard: the synthetic account remains active with a separate model warning; selecting Sol persists to /api/settings while keeping auto-ping disabled and account opt-ins unchanged. Injecting a fixture-only failed PATCH restores Sol after selecting Terra and displays “Could not save auto-ping settings”. The test server binds to loopback, creates a fresh temporary database and blocks external fetches.

Operational notes

Model entitlement remains an upstream/account constraint. Operators must select an accessible ping model and explicitly choose any image alias target. Existing account errors from earlier requests can be rechecked with Test Connection One-by-One. SSE clients receive errors inside the already-open HTTP 200 stream; JSON/binary callers receive mapped HTTP failure statuses. Rollback is a code revert; remove the optional alias environment variable and saved codexAutoPing.model if returning to the previous policy. There is no data migration to reverse.

Jordannst and others added 4 commits September 8, 2026 09:56
Keep model-access errors on the account/model pair, make quota auto-ping use an operator-selected model, and require a completed ping response. Parse incremental SSE and preserve upstream failure statuses for image clients. Support explicit image aliases without assuming global model retirement.
Qurtison pushed a commit to Qurtison/9router that referenced this pull request Sep 8, 2026
…e model failures and validate streams

# Conflicts:
#	.env.example
#	open-sse/config/codexConstants.js
#	open-sse/handlers/imageProviders/codex.js
#	src/app/api/providers/[id]/models/route.js
#	tests/unit/image-generation.test.js
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants