[stack 2/8] feat: expand providers and make native model discovery account-aware - #305
Draft
OnlineChef (ChefGroep) wants to merge 39 commits into
Draft
OnlineChef (ChefGroep) wants to merge 39 commits into
OnlineChef (ChefGroep) wants to merge 39 commits into
Conversation
Contributor
|
Important Draft PR not reviewedDraft PRs are not automatically reviewed by default.
To automatically review draft PRs, update your CodeRabbit configuration: reviews:
auto_review:
drafts: true
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
This was referenced Oct 4, 2026
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Stacked re-landing of #297 (
feat/providers-account-cli-20261003). Position 2/8; base:stack/20261005-01-prompt-cache. Merge bottom-up; each layer is a real merge of the original PR head, so the diff shows only that PR plus any conflict resolution (noted in the merge commit message).Stack
Original description:
Summary
~/.codex/auth.json.GET /v1/models?client_version=...Codex client route, preserving authoritative context/reasoning metadata for newly rolled-out models.openaiidentity and normal ChatGPT/Codex login, while OCX owns the proxy transport plus one canonical merged$CODEX_HOME/opencodex-catalog.json.model_catalog_jsonpointers while OCX owns routing, restore the pre-OCX value through the existing journal on stop/eject, and fail back to native Codex metadata when the managed catalog omits the selected native GPT/Codex model.Root cause
There were two coupled sources of native-model metadata drift.
First,
activeCodexAccountIdcontrols OpenCodex pool routing, but the physical Codex main credential remains~/.codex/auth.json. Native catalog refresh could therefore stay pinned to a stale Desktop login even while another pool account was healthy. Current Codex model discovery only needs the account Bearer token plusChatGPT-Account-IDforGET /backend-api/codex/models?client_version=...; this PR uses that request contract directly instead of copying pool credentials into Codex's native auth store.Second, config injection previously preserved an arbitrary pre-existing root
model_catalog_jsonwhile OCX simultaneously owned the active transport. That created split authority: a parallel or stale merged catalog could omit a newly rolled-out native model even though the normal ChatGPT/Codex account could serve it. Codex then synthesized generic fallback model metadata for the selected slug. Besides reporting the wrong context window, generic fallback can also lose native tool/search capability metadata and change direct-vs-deferred tool exposure.The corrected ownership model is native-first and additive. On loopback, Codex keeps its built-in
openaiprovider identity, normal ChatGPT/Codex authentication, and native thread identity. OCX owns only the managed proxy transport plus the canonical merged$CODEX_HOME/opencodex-catalog.jsonwhile routing is active. Bare native rows in that catalog come from authoritative account/client discovery; routed providers remain namespaced additions.If the managed catalog does not contain the currently selected bare native GPT/Codex model, OCX deliberately leaves
model_catalog_jsonunset so Codex can use its native model metadata instead of silently entering generic fallback. User-owned external providers and unmarked rootopenai_base_urlvalues remain ownership boundaries and are left untouched.Safety boundaries
~/.codex/auth.json.codexAccountPools: falseremains a hard standalone boundary: pool credentials are not consulted.model_providerand rootopenai_base_urlvalues are atomic ownership boundaries; OCX does not half-manage only their catalog.Coverage
Regression coverage includes selected-pool preference, dead-main fallback, one shared fallback deadline, safe degradation on response-body failure, account-pool opt-out, authoritative new native slugs, live metadata preservation in the catalog builder, preservation of deferred/search-tool capability fields, replacement of competing root catalog pointers, native fallback when the selected native model is absent from the managed catalog, atomic user-owned routing boundaries, registry/free-tier parity, and a hermetic end-to-end server test that proves
/v1/models?client_version=9.9.9forwards the exact client version and account headers while returning the live native row.Non-goals
This PR does not swap Codex Desktop/app-server login state, rewrite the native auth file, or fold the larger Codex/app-server lifecycle decoupling into the provider/catalog change.
The proxy already runs independently as its own service. Remaining Codex coupling is primarily lifecycle/integration: config/catalog injection and stale long-lived
codex app-serverconsumers after disk catalog changes. Remote CLI endpoint/profile orchestration should be a separate PR built on the existing sharedruntimeRequest(baseUrl)management client.