Repository navigation
GPT-6 gateway lane on the all-engines OmniRoute instance: static headers and a one-slash model - #439
Merged
seathatflowsinourveins merged 2 commits intoSep 27, 2026
Conversation
…ers and a one-slash model The landscape-sweep GPT-6 lane can target the framework OmniRoute instance on 127.0.0.1:20129: all engines and output styles on, chained through node sharedgw to the shared gateway on 20128. The shared 20128 stays unchanged for the memory services and the other sessions. - build_args.py --omniroute-header stages static provider headers (model_providers.<id>.http_headers). An example is x-omniroute-compression: allow-lossy. codex_job.py checks each job's headers against the lane home and records them per job. - The lane's model has at most one provider segment: sharedgw/gpt-6-astra-max. Codex rust-v0.157.1 strips exactly one namespace segment when it looks up model metadata (models-manager/src/manager.rs L763-780). A two-slash slug such as sharedgw/cx/gpt-6-astra gets generic fallback metadata (model_info.rs L99-150), so both build_args and codex_job refuse it with a UsageError. - README: the framework lane passes -m sharedgw/gpt-6-astra-max. Manual commands must pass -m, because under -p stack-worker the profile's model otherwise wins. The slashless alias is removed: the built-in codex provider claims gpt-6-astra* before stored aliases and answers 401. The prompt-input parity check is documented, and effort evidence is read from requestBody.reasoning. - Two anti-pattern rows: the two-slash slug on a chained gateway, and a null call_logs effort column read as "effort not sent". No repository check enforces the second; the row says so. Built by GPT-6 (gpt-6-astra, effort max) in two rounds: the header build, then this amendment after verification found the two-slash fallback. The coordinator verified and committed. Checks, with TMPDIR outside every repository: - The changed tests before the amendment: FAILED (failures=3). - tests.test_landscape_sweep_harness and tests.test_codex_worker_lane: 179 tests OK (skipped=11). - The registry tests: 57 tests OK. - codex debug prompt-input for sharedgw/gpt-6-astra-max and cx/gpt-6-astra-max: identical item counts. Base instructions are identical by the bundled-catalog lookup rule. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…utbound effort evidence) One repair round for review-439's two major and seven minor findings. - Static provider headers: an allowlist of OmniRoute 3.8.51's four per-request switches replaces the credential-word denylist. The denylist admitted x-omniroute-self-hop, -video-bridge-broker and -lease-owner, which carry secrets. The builder and runner never echo a refused name or value. - Model names: the provider segment follows Codex's namespace rule, letters, digits, '_' and '-' only (manager.rs L763-780), in both entry points, with the fallback-metadata diagnostic. The no-partial-state test now runs the real `codex_call.sh start`. - The runner refuses staged headers without tomllib; header-less lanes keep Python 3.9. The builder's read-back is unconditional (staging already needs 3.11). - Effort evidence: the outbound request is pipelinePayloads.providerRequest in the detailed call log. requestBody is the body the gateway received. A non-null reasoning_effort_upstream is positive evidence. - README: a content-based parity check (without id and create_time, with the model masked), run as written; the alias mechanism is dropped and the 401 observation kept. The tests failed first (5 failures, 1 error) and now pass: 122 tests OK. A mutation pass caught 10 of 10 guard mutations. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
seathatflowsinourveins
force-pushed
the
claude/gpt6-lane-fw-instance-20260927
branch
from
September 27, 2026 23:16
854803b to
74c233d
Compare
seathatflowsinourveins
deleted the
claude/gpt6-lane-fw-instance-20260927
branch
September 27, 2026 23:47
seathatflowsinourveins
added a commit
that referenced
this pull request
Sep 28, 2026
…first recording; GPT-6 review agree) + dashboard gate row (#442) * Capability-gate host receipts round 2 (at main eb5ca78), superseding the first recording, with GPT-6 review agree The three gates re-ran live through host_receipts.py record --supersedes at the published repair (#440). Each receipt quotes only its own verdict line, which carries the retained results' sha256. The GPT-6 cross-family reviewer independently re-applied assertions.js to the retained results (260/260, 10/10, 10/10 component verdicts; hashes 3/3; M13 sentinels 52/52) and recorded codex_lane agree on each receipt itself. The grand-dashboard gets the codex-capability-gate row. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Register the round-2 capability-gate receipts and dashboard row (hot files) docs/lanes.md hot-file protocol after merging origin/main at b26add9 (#439): main's manifests/evidence.json with the three -2 receipts and observability/grand-dashboard/state.json registered, and the component evidence matrix regenerated (flip-rule violations 0). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Scout <scout@local> Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Scope
sharedgwto the shared gateway on 20128.7fa3849c(Pre-push registry gate: run the three registry tests on every pushed commit #438). Reviewed as55fc8d17..854803b0; the rebase changed no reviewed line, anddocs/harness-defaults.mdkeeps Pre-push registry gate: run the three registry tests on every pushed commit #438's row beside this PR's two rows.74c233d7lane:foundationtools/sota-convergence/landscape-sweep/{build_args.py,codex_job.py,README.md}tests/test_landscape_sweep_harness.pydocs/harness-defaults.md(two anti-pattern rows)manifests/evidence.json(registration)Changes
build_args.py --omniroute-header NAME=VALUEstages Codex'smodel_providers.<id>.http_headers, for examplex-omniroute-compression=allow-lossy.x-omniroute-compression,-no-cache,-no-memoryand-strip-reasoning.x-omniroute-*headers can carry a secret under a name with no credential word, so a word filter cannot keep them out:x-omniroute-self-hop,-video-bridge-brokerand-lease-owner, for example. Staged values are recorded instaged.jsonand in each job'sinputs.json.codex_job.pyapplies the same allowlist tostaged.json. It checks the lane home's table against it and records the headers per job.tomllibis missing (Python 3.9 and 3.10). A header-less lane still runs on 3.9. The builder's read-back is unconditional, because staging already needs 3.11._and-. On 20129 it issharedgw/gpt-6-astra-max.codex-rs/models-manager/src/manager.rsL763-780).model_info.rsL99-150): a different prompt template, no Responses Lite, no multi-agent, a 272k context window and a 10,000-byte tool-output truncation. That coverssharedgw/cx/gpt-6-astraandmy.gw/gpt-6-astra-max.mainalready refused a second slash. This PR adds the fallback-metadata diagnostic and the namespace character rule to both entry points.-m sharedgw/gpt-6-astra-max, because under-p stack-workerthe profile's model otherwise wins.idandcreate_timeand with the model masked. Its commands were run as written (evidence below).pipelinePayloads.providerRequestin its detailed call log, when detailed pipeline logging is on.requestBodyis the body that gateway received.reasoning_effort_upstreamis positive evidence; only a null effort column proves nothing.call_logseffort column read as "effort not sent", and the first correction's inbound field. No repository check enforces this; the row says so.SOTA sources
codex-rs/models-manager/src/manager.rsL763-780: the namespace rule.model_info.rsL99-150: the fallback metadata.codex-rs/core/src/prompt_debug.rs: prompt-input.codex-rs/model-provider-info/src/lib.rs:http_headers, whose values are aRedactedString.build_header_mapskips an invalid name or value.deny_unknown_fieldsis a JSON-schema attribute only.dd6e9607e), installed source:open-sse/handlers/chatCore/headers.ts: L18-33 no-memory, L35-46 compression, L48-65 strip-reasoning.src/lib/semanticCache.tsL483-486 and L501-504: no-cache.open-sse/services/compression/lossyRequestPolicy.tsL29-40:allow-lossy.open-sse/utils/selfHop.tsL1-12src/lib/guardrails/videoBridgeBrokerAuth.tsL7-19open-sse/utils/requestLogger.tsL100 and L109-111: lease-owner is redacted.open-sse/handlers/chatCore/attemptLogging.tsL513-516:providerRequestintopipelinePayloads. L575-582:requestBodyfrom the client body.src/lib/usage/callLogs.ts: L646-653 for the effort columns; L1047-1053 for the detail route.src/lib/db/detailedLogs.tsL56-64: detailed logging.open-sse/executors/codex.tsL1451-1465: the effort rewrite.Evidence-class table
d19e3a69, the rebased854803b0):FAILED (failures=6, errors=1). After the repair:tests.test_landscape_sweep_harnessRan 122 tests ... OK (skipped=3), again on the rebased headMODEL_NAME, the value and type checks, the tomllib refusal, a job directory created beforesettings, and an echoed refused nameprompt-inputcommands exit 0 with 4 items each (3 developer, 1 user).cmpof the normalized files exits 0; neither output contains the model slug. Earlier coordinator run (installed profile, prompt argument): 5 against 5 items, identical after the same normalization, and the negative controlsharedgw/cx/gpt-6-astradiffered (3 items)-msent the profile'sgpt-6-astraand got 401 six times, which is why-mis requiredgit pushscripts/validate.pypassed after re-registration perdocs/lanes.md. This push went through #438's gate:pre-push: running the registry tests on 74c233d7…, then OKReview round (review-439; one review, one repair)
settingsandcodex_call.sh startrequestBodyis inbound, not outboundpipelinePayloads.providerRequestand the detailed-logging condition. The column rule is narrowed.passed in the provider segmentmy.gw/gpt-6-astra-maxis testedsettings()codex_call.sh start(mutation M8 is caught)mainalready refused a second slash, and the test failed first on the diagnostic and the dotted namespaceNAME:VALUE, base, correlation-id citation, paths)Residual risks
apply_patchand sandbox PATH aliases (codex-rs/arg0/src/lib.rsL344-357). The parity run printed that warning. On Linux the sandbox falls back to the codex executable (L281-291), and the effect on shell-invokedapply_patchis not measured. This is a follow-up; it is out of scope for this round.validate-macosfailed once on an unrelatedcodex_laneinterruption-timing test, and the rerun passed. It is recorded as a flake to watch.Status
pipelinePayloads.providerRequest.🤖 Generated with Claude Code