Skip to content

feat(protocols): protocol paths as a first-class concern — PF-01..PF-12 - #5820

Merged
lidge-jun merged 173 commits into
devfrom
feat/pf12-protocol-rollout
Sep 25, 2026
Merged

lidge-jun merged 173 commits into
devfrom
feat/pf12-protocol-rollout

Conversation

@lidge-jun

@lidge-jun lidge-jun commented Sep 25, 2026 •

Copy link
Copy Markdown
Owner

Summary

Protocol-first-class unit (devlog/_plan/260924_protocol_first_class/), landed as one squash of the reviewed stack #5808 → #5809 → #5810 → #5811 → #5812 → #5813 → #5814 → #5815 → #5816 → #5817 → #5819 → this PR, rebased onto the current dev. Chat Completions and Anthropic Messages reach the shared execution owner without the public Responses wire as a mandatory detour; every new lane is behind a protocols.rollout.* switch that defaults off.

Verification

  • Head 3df0d8f4d28e (rebased onto current dev): bun x tsc --noEmit exit 0; gui bun x tsc -b exit 0; bun run structure:check, bun run skill:surface:check, bun run privacy:scan pass; file-size ratchet, core–Lab boundary, repo hygiene, skill-ocx and headless CLI parity tests pass locally (137 + 9 pass, 0 fail).
  • Before the rebase onto current dev: every stacked PR's required CI passed on its exact head; full local bun run test on the stack head showed only failures that reproduce identically on a checkout without this stack (Lab CL-03/07/08, SEC-02, release helper timeouts); cd gui && bun test --isolate tests 2398 pass, 0 fail.
  • Post-merge regression run on dev is recorded in a comment on this PR.

Maintainer integration

Integrated into dev by a maintainer under the MAINTAINERS.md maintainer-integration exception, as a single squash, at the maintainer's explicit direction and without waiting for CI on this rebased head. Exact-head evidence above is local; CI on this head runs after merge and is checked in the post-merge comment.

Screenshots

See #5809, #5810, #5812 and #5817 (captured from the stack head in an isolated home).

Checklist

  • Scope stays focused and avoids unrelated cleanup.
  • Docs or release notes were updated when needed.
  • Security-sensitive changes were reviewed for secrets, auth, and unsafe defaults.

@lidge-jun
lidge-jun requested a review from Ingwannu as a code owner September 25, 2026 04:32
@coderabbitai

coderabbitai Bot commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Note

Currently processing new changes in this PR. This may take a few minutes, please wait...

⚙️ Run configuration

Configuration used: Repository: lidge-jun/opencodex/.coderabbit.yaml

Review profile: ASSERTIVE

Plan: Advanced

Run ID: ab8c4bb6-2f67-48cb-973c-3dd299d2a7cf

📥 Commits

Reviewing files that changed from the base of the PR and between 6fbab23 and 02832f8.

📒 Files selected for processing (188)
  • devlog/_plan/260924_protocol_first_class/000_plan.md
  • devlog/_plan/260924_protocol_first_class/010_contract_and_baseline.md
  • devlog/_plan/260924_protocol_first_class/020_engine_and_codecs.md
  • devlog/_plan/260924_protocol_first_class/030_gui_and_management_api.md
  • devlog/_plan/260924_protocol_first_class/040_acceptance_and_rollout.md
  • docs-site/astro.config.mjs
  • docs-site/src/content/docs/guides/protocol-paths.md
  • docs-site/src/content/docs/reference/cli.md
  • docs-site/src/content/docs/reference/cli/agents.md
  • docs-site/src/content/docs/reference/configuration/server.md
  • docs-site/src/content/docs/reference/management-api.md
  • gui/src/app-routing.ts
  • gui/src/components/ComboWorkspace.tsx
  • gui/src/components/apikeys-workspace/ApiKeysWorkspace.tsx
  • gui/src/components/combo-workspace-detail-panel.tsx
  • gui/src/components/combo-workspace-types.ts
  • gui/src/components/protocols/ComboProtocolPlan.tsx
  • gui/src/components/protocols/FeatureDispositionList.tsx
  • gui/src/components/protocols/ProtocolBadge.tsx
  • gui/src/components/protocols/ProtocolPlanPanel.tsx
  • gui/src/components/protocols/ProtocolTracePanel.tsx
  • gui/src/components/protocols/protocol-labels.ts
  • gui/src/components/provider-workspace/ProviderDetails.tsx
  • gui/src/components/provider-workspace/ProviderProtocolPanel.tsx
  • gui/src/components/provider-workspace/ProviderSettings.tsx
  • gui/src/hash-routing.ts
  • gui/src/i18n/de.ts
  • gui/src/i18n/en.ts
  • gui/src/i18n/fr.ts
  • gui/src/i18n/ja.ts
  • gui/src/i18n/ko.ts
  • gui/src/i18n/ru.ts
  • gui/src/i18n/tr.ts
  • gui/src/i18n/vi.ts
  • gui/src/i18n/zh-TW.ts
  • gui/src/i18n/zh.ts
  • gui/src/main.tsx
  • gui/src/pages/ApiKeys.tsx
  • gui/src/pages/Combos.tsx
  • gui/src/pages/CompatibilityMatrix.tsx
  • gui/src/pages/Logs.tsx
  • gui/src/pages/Providers.tsx
  • gui/src/pages/api-keys-endpoints-panel.tsx
  • gui/src/pages/api-keys-utils.ts
  • gui/src/pages/api-surface-cards.tsx
  • gui/src/pages/compatibility-matrix-shared.ts
  • gui/src/pages/compatibility-protocol-filter.tsx
  • gui/src/pages/compatibility-protocol-pairs.ts
  • gui/src/pages/logs-filter-bar.tsx
  • gui/src/pages/logs-filter.ts
  • gui/src/pages/models-tab.ts
  • gui/src/pages/providers-deep-link.ts
  • gui/src/protocol-api.ts
  • gui/src/protocol-deep-links.ts
  • gui/src/styles-apikeys-workspace.css
  • gui/src/styles/protocol-evidence.css
  • gui/tests/api-surface-cards.test.tsx
  • gui/tests/combo-protocol-plan.test.tsx
  • gui/tests/compatibility-protocol-filter.test.tsx
  • gui/tests/fr-localization.test.ts
  • gui/tests/locale-parity.test.ts
  • gui/tests/logs-protocol-trace.test.tsx
  • gui/tests/protocol-api.test.ts
  • gui/tests/protocol-deep-links.test.ts
  • gui/tests/provider-protocol-panel.test.tsx
  • gui/tests/providers-deep-link.test.tsx
  • scripts/test-layout/layout.json
  • skills/ocx/references/01_management_surface.md
  • src/adapters/anthropic.ts
  • src/adapters/anthropic/beta-allowlist.ts
  • src/adapters/anthropic/passthrough.ts
  • src/bridge/response-json.ts
  • src/chat/outbound.ts
  • src/claude/claude-code-block.ts
  • src/claude/inbound.ts
  • src/claude/outbound.ts
  • src/cli/api-protocols.ts
  • src/cli/capabilities.ts
  • src/cli/dispatch.ts
  • src/cli/help.ts
  • src/cli/registry.ts
  • src/config/schema/config-schema.ts
  • src/protocols/baseline.ts
  • src/protocols/codecs/chat.ts
  • src/protocols/codecs/messages.ts
  • src/protocols/codecs/responses.ts
  • src/protocols/contract.ts
  • src/protocols/dto.ts
  • src/protocols/encoders/adapter-events.ts
  • src/protocols/encoders/chat.ts
  • src/protocols/encoders/messages.ts
  • src/protocols/envelope.ts
  • src/protocols/features.ts
  • src/protocols/guard.ts
  • src/protocols/opaque-state.ts
  • src/protocols/path.ts
  • src/protocols/plan-snapshot.ts
  • src/protocols/plan.ts
  • src/protocols/provider-summary.ts
  • src/protocols/settings.ts
  • src/protocols/shadow-plan.ts
  • src/protocols/shadow.ts
  • src/protocols/trace.ts
  • src/server/chat-completions.ts
  • src/server/chat-native-eligibility.ts
  • src/server/chat-native.ts
  • src/server/claude-messages.ts
  • src/server/inference/attempt.ts
  • src/server/inference/client-encoder-delivery.ts
  • src/server/inference/client-wire-log.ts
  • src/server/inference/client-wire.ts
  • src/server/inference/context.ts
  • src/server/inference/final-log.ts
  • src/server/management-api.ts
  • src/server/management/agent-settings-routes.ts
  • src/server/management/api-access.ts
  • src/server/management/native-integration-routes.ts
  • src/server/management/protocol-routes.ts
  • src/server/management/protocol-settings-patch.ts
  • src/server/management/route-registry.ts
  • src/server/messages-native-eligibility.ts
  • src/server/messages-native-oauth.ts
  • src/server/messages-native.ts
  • src/server/relay.ts
  • src/server/request-log-filter.ts
  • src/server/request-log.ts
  • src/server/responses/adapter-delivery.ts
  • src/server/responses/core-combo-native.ts
  • src/server/responses/core-combo.ts
  • src/server/responses/core-options.ts
  • src/server/responses/core.ts
  • src/types.ts
  • src/types/config.ts
  • src/usage/log.ts
  • structure/INDEX.md
  • structure/config.md
  • structure/dashboard-and-usage.md
  • structure/data-planes/inbound-compat.md
  • structure/data-planes/protocol-paths.md
  • structure/gui-and-management-api.md
  • structure/manifest.json
  • structure/transports/responses.md
  • tests/adapters/anthropic/anthropic-beta-allowlist.test.ts
  • tests/adapters/anthropic/anthropic-messages-passthrough-oauth.test.ts
  • tests/adapters/anthropic/anthropic-messages-passthrough.test.ts
  • tests/adapters/anthropic/anthropic-opaque-strip.test.ts
  • tests/claude-integration/messages-native-decline-trace.test.ts
  • tests/claude-integration/messages-native-oauth.test.ts
  • tests/claude-integration/messages-native-opaque-state.test.ts
  • tests/claude-integration/messages-native.test.ts
  • tests/claude-integration/messages-surface-matrix.test.ts
  • tests/cli/cli-api-protocols.test.ts
  • tests/cli/cli-capabilities.test.ts
  • tests/cli/cli-headless-parity.test.ts
  • tests/config/protocol-settings.test.ts
  • tests/fixtures/test-layout-expected.json
  • tests/helpers/responses-core-source.ts
  • tests/lib/reasoning-replay-scope-source.test.ts
  • tests/responses/chat-native-combo.test.ts
  • tests/responses/chat-native-decline-reason.test.ts
  • tests/responses/messages-native-bridge-policy.test.ts
  • tests/responses/messages-native-eligibility.test.ts
  • tests/responses/messages-native-oauth-eligibility.test.ts
  • tests/responses/protocol-baseline.test.ts
  • tests/responses/protocol-contract.test.ts
  • tests/responses/protocol-direct-encoders-chat.test.ts
  • tests/responses/protocol-direct-encoders-messages.test.ts
  • tests/responses/protocol-dto.test.ts
  • tests/responses/protocol-envelope.test.ts
  • tests/responses/protocol-features.test.ts
  • tests/responses/protocol-guard.test.ts
  • tests/responses/protocol-ingress-guard.test.ts
  • tests/responses/protocol-opaque-state.test.ts
  • tests/responses/protocol-path.test.ts
  • tests/responses/protocol-plan-snapshot.test.ts
  • tests/responses/protocol-plan.test.ts
  • tests/responses/protocol-shadow-plan.test.ts
  • tests/responses/protocol-trace.test.ts
  • tests/server/api-access-endpoints.test.ts
  • tests/server/inference-attempt.test.ts
  • tests/server/inference-client-encoder-delivery.test.ts
  • tests/server/inference-client-wire.test.ts
  • tests/server/inference-final-log.test.ts
  • tests/server/inference-send-budget.test.ts
  • tests/server/protocol-provider-summary.test.ts
  • tests/server/protocol-routes.test.ts
  • tests/server/protocol-settings-route.test.ts
  • tests/usage/request-log-protocol-trace.test.ts
 ______________________________________________________
< Unit tests are cute. Integration tests pay the rent. >
 ------------------------------------------------------
  \
   \   \
        \ /\
        ( )
      .( o ).
✨ Finishing Touches
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 25, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-25T06:28:40.800001Z 3df0d8f Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 6f3c0290db

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread src/protocols/shadow.ts
const exact = settled.provider && settled.model
? plan.candidates.find(candidate => candidate.provider === settled.provider && candidate.model === settled.model)
: undefined;
return exact ?? plan.candidates.find(candidate => candidate.eligible);

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Select the combo child that actually answered

When shadowPlan is enabled and a combo selects or fails over to a non-first candidate with a different protocol path, this fallback compares the observed trace against the wrong candidate. The combo runtime deliberately replaces the final context with provider: "combo" and the requested selector in src/server/responses/core-combo.ts:676-680, so exact cannot match the plan's physical provider/model candidates and the first eligible candidate is always used, producing a false planMismatch. Derive the settled candidate from the final attempt's provider/model or otherwise preserve the answering child's identity.

Useful? React with 👍 / 👎.

@github-actions

Copy link
Copy Markdown
Contributor

✅ Deterministic PR hygiene checks passed.

@lidge-jun

Copy link
Copy Markdown
Owner Author

리뷰 · 우선순위 64 / 80

이 PR은 "미리 계산한 경로"와 "요청이 실제로 간 경로"가 같은지 확인하는 기능을 넣는다. 스위치 이름은 protocols.rollout.shadowPlan이고 기본값은 꺼짐이다. 켜면 Chat이랑 Messages 요청이 들어올 때, 대시보드 미리보기와 같은 계산으로 경로 계획을 적어 둔다. 요청이 끝나면 그 계획이랑 실제 경로를 비교한다. 다르면 로그에 planMismatch: true만 붙인다. 요청을 한 번 더 보내지 않고, 설정도 바꾸지 않는다. 비교가 실패해도 그 요청은 그대로 끝난다.

명령도 세 개가 늘었다. ocx api protocols로 지금 정책이랑 기능 이름을 볼 수 있다. ocx api explain은 모델 하나의 경로를 미리 계산하는데, 그 계산은 바깥 모델 서버로 나가지 않는다. ocx api policy는 그냥 치면 보여 주기만 하고, --messages나 --unrepresentable, --rollout을 붙이면 설정 파일의 프로토콜 값을 바꾼다. 문서에는 경로 설명, 설정 키, 명령 사용법이 들어갔다. 이 브랜치의 기준은 dev가 아니라 바로 아래 작업인 feat/pf10-auth-opaque-state다.

src/protocols/trace.ts withShadowPlan - 콤보 요청이 성공하면 src/server/responses/core-combo.ts가 로그의 provider를 "combo"로 덮어쓰고, model은 사용자가 보낸 이름으로 남긴다. 실제로 답한 자식의 공급자 이름과 모델 이름은 그 자리에 없다. src/protocols/shadow.ts의 settledCandidate는 그때 일치하는 후보를 못 찾고, 목록에서 처음 가능한 후보랑 비교한다. 뒤에 있는 자식이 다른 길로 답하면 틀린데 planMismatch: true가 찍힌다. 테스트 a combo is compared against the target that answered는 { provider: "r", model: "m3" }를 직접 넣어서 통과시킨다. 콤보가 실제로 남기는 provider: "combo"는 안 본다. 가이드의 Shadow plan 절은 "콤보면 답한 대상을 본다"고 적혀 있는데, 그 연결은 아직 없다.

메인테이너의 판단이 필요한 지점

기준 브랜치가 dev가 아니다. PF-10이 먼저 dev에 들어간 뒤에 이걸 올려야 한다. PF-10 내용이 바뀌면 이 브랜치도 다시 맞춰야 한다.

섀도 비교는 Chat이랑 Messages만 한다. Responses 요청은 일부러 빼 두었고, PR 본문이랑 가이드에도 그렇게 적혀 있다. Responses가 실제 트래픽의 대부분이면, 스위치를 켜도 그 요청은 검사되지 않는다.

본문은 타입 검사와 구조 검사가 통과했다고 적고, 전체 테스트 결과는 나중에 붙인다고 해 두었다.

너의 추천

콤보가 끝난 뒤에도 실제로 답한 자식의 provider와 model이 로그에 남게 하고, withShadowPlan이 그 값으로 비교하게 해라. 테스트도 provider: "combo"인 컨텍스트로 하나 넣어라. 그 수정 전에는 shadowPlan을 켜도 콤보에서 나온 planMismatch는 믿지 마라. Responses는 이번 범위 밖으로 둬도 된다. 가이드에 이미 비교하지 않는다고 적혀 있다.

이 댓글은 grok-bot이 작성했습니다

@github-actions github-actions Bot added the enhancement New feature or request label Sep 25, 2026
@devin-ai-integration devin-ai-integration Bot added the priority: P3 Low: new provider/client integration, large or experimental feature (>2000 LOC or >50 files), RFC/ro label Sep 25, 2026
@devin-ai-integration

Copy link
Copy Markdown
Contributor

Maintainer triage: priority: P3 — protocol-first-class series PF-12 rollout (default off).

Criteria (P3): Low: new provider/client integration, large or experimental feature (>2000 LOC or >50 files), RFC/roadmap, or long-stale branch.

Related / overlapping PRs:

Records the stacked work packets (PF-01..PF-12), the invariants every packet keeps,
and the per-packet design so Chat Completions and Messages can reach the shared
execution policy without the public Responses wire as a mandatory detour.
One leaf module names protocols, upstream wires, path hops, delivery modes and a
closed reason-code list, and maps the older spellings (InboundWire "anthropic",
adapter ids, Lab identities) explicitly instead of renaming them in place.
Which request features survive each cross-wire hop, in the compatibility-manifest
vocabulary, so a path's losses (Chat n and logprobs through Responses, Messages
top_k) are computed from the path instead of discovered by users.
Current and target paths for 3 ingresses x 3 upstreams x stream, so every later
packet changes a named cell on purpose rather than drifting the contract.
ProtocolPlanV1 and ProtocolTraceV1 with bounded validators shared by the server and
the dashboard, fixed before the parallel GUI and runtime packets depend on them.
The dashboard imports these modules directly; the boundary test fails on any import
that would drag server, router or Lab code into the GUI.
apiSurfaces stays raw in the schema so a mistyped enabled can never degrade to
"inherit" and reopen a surface; protocols degrades to absence because every default
is the conservative one. No request path reads either key yet.
One reader for apiSurfaces/protocols: a malformed Messages value closes the surface,
an absent one inherits claudeCode.enabled, and every rollout switch defaults off.
The new area needs an owner doc; inbound-compat and config link to it instead of
restating the vocabulary.
…rivacy scan

A literal bearer header and a userinfo URL read as secrets to privacy:scan; constructing
them from parts keeps the same assertions without tripping the scanner.
…race

A pure leaf decides disagreement on mode, upstream and request path for the settled
candidate; finalize sets planMismatch only when an input was recorded, never on throw.
…s entry marks

Behind protocols.rollout.shadowPlan (off): the preview snapshot with basis dispatch is
kept beside the marks; nothing is read, sent or stored with the switch off.
…w safety

Covers settled-candidate selection, the uncompared response path and compatibility
rejects, and that old trace rows without planMismatch stay valid.
Thin clients of the protocol management routes; policy reads when bare and writes only
when a setting flag is given, leaving value validation to the server.
…-verb exemptions

The mutation-consistency check now reads the registry's mutates flag, so the read-only
plan POST is not forced to claim a write; the skill surface is regenerated.
…rity

Each verb's method, path and body, --json passthrough, exit 2 before any send on bad
argv, and that every protocol route is verbed rather than exempt.
Delivery modes, preview, trace, the unrepresentable policy, every rollout switch off by
default, the shadow plan, and what still travels the internal Responses bridge.
…ults

Operators editing config.json need the unrepresentable policy and each rollout switch,
and that a malformed block falls back to the defaults.
Routes, which invocation writes, server-side validation of switch names, and the
management reference now points at the CLI verbs and the guide.
…ated inventory

Each scenario states whether it is implemented, behind which switch, which tests name it
and that none has live evidence; the inventory is rechecked against this branch.
…verbs

protocol-paths owns where the input is recorded, what is compared and what is not, and
the CLI client; the management doc drops the deferred-verb note.
…0 ships them

The guide and configuration reference were written before native Messages over OAuth
and the anthropic-beta allowlist landed below this change.
The verbs exist now, so the headless parity map names them instead of the owed-verb
placeholder.
The shared runtime request helper sends its JSON content type on every call, so the
GET case should not pin a missing header.
A long path such as Responses → Messages · Translated overflowed the narrow model column
and was cut off, hiding the mode. The badge now wraps inside the cell.
@lidge-jun
lidge-jun force-pushed the feat/pf12-protocol-rollout branch from e076aab to 02832f8 Compare September 25, 2026 06:19
@lidge-jun lidge-jun changed the title feat(protocols): shadow plan, ocx api verbs and protocol-path docs (PF-12) feat(protocols): protocol paths as a first-class concern — PF-01..PF-12 Sep 25, 2026
@lidge-jun
lidge-jun changed the base branch from feat/pf10-auth-opaque-state to dev September 25, 2026 06:19
@github-actions

github-actions Bot commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

⏳ DRAFT

  • UI screenshot required.

What to do

  • Add a screenshot of the UI change to the PR description.

Automatic draft conversion failed (token cannot change draft status). Please convert this pull request to a draft manually. The required enforce-target check will keep failing until every issue above is resolved.

@github-actions
github-actions Bot marked this pull request as draft September 25, 2026 06:19
…nking

The Responses passthrough already drops replayed opaque reasoning when the serving
identity changed or the blob was rejected; the Anthropic adapter now does the same for
signed thinking and redacted_thinking blocks.
@lidge-jun
lidge-jun force-pushed the feat/pf12-protocol-rollout branch from 02832f8 to 3df0d8f Compare September 25, 2026 06:21
@lidge-jun
lidge-jun marked this pull request as ready for review September 25, 2026 06:22
@lidge-jun
lidge-jun merged commit 0f4c8d4 into dev Sep 25, 2026
27 of 30 checks passed
@lidge-jun
lidge-jun deleted the feat/pf12-protocol-rollout branch September 25, 2026 06:22

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 3df0d8f4d2

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment on lines +116 to +117
const persist = ctx.deps.saveConfigPreservingClaudeCode
?? (await import("../../config")).saveConfigPreservingClaudeCode;

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Resolve persistence before mutating the live config

When production leaves the persistence seam unset, this await import() runs after applyProtocolSettingsPatch has already mutated the shared live config. A concurrent management request can therefore modify and save the same object during this suspension; the eventual save may unintentionally include that request's changes, and a failed save restores the old snapshot over the concurrent in-memory update. Resolve the persister before taking the snapshot and applying the patch, or perform mutation and persistence under the same serialized config transaction.

Useful? React with 👍 / 👎.

Comment on lines +138 to +140
const nativeBody = (target: ComboTarget, route: RouteResult | undefined): Rec | undefined => {
if (!route || route.provider.adapter !== "openai-chat") return undefined;
const body = envelope.freshBody();

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Avoid retaining discarded combo eligibility copies

With nativeChatCombos enabled, judge() invokes this helper for every openai-chat candidate only to retain a boolean verdict, but freshBody() charges the entire clone as retained request_copies and provides no release handle. Those discarded eligibility clones remain charged for the request, and the selected candidate is cloned again during dispatch, so a sufficiently large request with several candidates can hit the 32 MiB translator limit and return a local 413 before sending anything even though only one candidate body is needed. Cache the eligible body for later dispatch or inspect eligibility without creating a charged clone.

Useful? React with 👍 / 👎.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request priority: P3 Low: new provider/client integration, large or experimental feature (>2000 LOC or >50 files), RFC/ro

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant