Skip to content

Hide internal and legacy Copilot models from Pi/omp catalogs - #766

Merged
hardbeat920 merged 1 commit into
hardbeat920:mainfrom
nwoolls:feat/filter-omp-copilot-models
Oct 6, 2026
Merged

hardbeat920 merged 1 commit into
hardbeat920:mainfrom
nwoolls:feat/filter-omp-copilot-models

Conversation

@nwoolls

@nwoolls nwoolls commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

Copilot's /models endpoint returns internal agents (exec-agent-, copilot-search-, trajectory-compaction) and dated GPT-3.5/4 snapshots that never appear in its own picker. omp drops the picker/policy flags, so filter these ids by name. omp's 71-model Copilot list drops to the 53 models in its picker set.

What changed

modelsFromRpcData now skips github-copilot models whose ids match a short list of internal and dated-snapshot patterns (isHiddenCopilotModel in piProtocol.ts). It applies to both omp and Pi, since they share the same model-list code; other providers' models (e.g. openai/gpt-4o-mini) are unaffected.

Why

With omp, MonoCode's model picker listed all 71 Copilot models, including internal agents and old dated snapshots that aren't meant to be chosen and may fail when used. Hermes avoids this because Copilot's own agent returns only the models the account can use. omp gets its list from the same Copilot /models endpoint but drops the picker and policy flags, so MonoCode can't tell which models are hidden or disabled.

This change hides the models that are never in Copilot's picker. It doesn't hide models the account can't use (e.g. ones disabled by org policy); that needs omp to pass Copilot's policy and billing fields through get_available_models. I didn't filter on omp's cost field. It's a fixed public price table, not Copilot billing, so cost == 0 mostly means "no price data". Filtering on it would hide usable models like Sonnet 4.6 and GPT-5.4.

UI

Before

Screenshot 2026-10-05 at 8 55 07 PM

After

Screenshot 2026-10-05 at 8 55 28 PM

Checklist

  • I ran npm run check
  • This PR is small and focused
  • I did not mix unrelated changes

Summary by CodeRabbit

  • Bug Fixes
    • Removed internal, legacy, and dated GitHub Copilot model entries from the available model list. Supported Copilot models and other providers’ models remain available.

Copilot's /models endpoint returns internal agents (exec-agent-*,
copilot-search-*, trajectory-compaction) and dated GPT-3.5/4 snapshots
that never appear in its own picker. omp drops the picker/policy flags,
so filter these ids by name. omp's 71-model Copilot list drops to the
53 models in its picker set.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Repository UI
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 00e91855-4616-4684-87d4-5b37234511ed
📥 Commits

Reviewing files that changed from the base of the PR and between 98da85a and 0a850ee.

📒 Files selected for processing (2)
  • src/integrations/harness/providers/pi/piProtocol.test.ts
  • src/integrations/harness/providers/pi/piProtocol.ts

Included review availability: This review used your included allowance. Your plan provides up to 8 included reviews per hour; 6 remain after this review.


📝 Walkthrough

Walkthrough

The RPC model conversion now filters selected internal, trajectory-compaction, and legacy or dated model IDs for GitHub Copilot. A test checks that supported Copilot IDs and an OpenAI model remain in the results.

Changes

GitHub Copilot model filtering

Layer / File(s) Summary
Filter selected model IDs
src/integrations/harness/providers/pi/piProtocol.ts, src/integrations/harness/providers/pi/piProtocol.test.ts
A Copilot-only helper identifies selected model IDs. modelsFromRpcData skips matching models before constructing and deduplicating native IDs. The test checks that selected IDs are absent while supported Copilot IDs and an OpenAI model remain.

Priority: ➖ Normal

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Bug fix

Suggested reviewers: shxntanu

Merge Risk: ⚪ Minimal · up to 0a850

The change filters selected internal and legacy Copilot IDs while the added test retains supported Copilot and OpenAI models; no confirmed user-facing mismatch remains.

Security Architecture Review

Security architecture risk: 🔵 Low · up to 0a850

Removed saved selections can automatically resolve to a different service for new conversations. This is conditional on another service being available. Existing conversations retain their original routing, and no actual disclosure was established.

Retained concerns

  • Medium · security · inferred: Filtering a saved Copilot model out of a successful catalog refresh can cause new-session construction to substitute the catalog default. That default is not constrained to the saved upstream provider, so a mixed-provider configuration can redirect subsequent session content to another configured service. This is a conditional routing regression, not a verified disclosure or authentication bypass.
Security review details

Security Blast Radius

  • inferred — The routing concern is bounded to Pi/omp selections whose Copilot IDs are removed and cannot otherwise resolve. Crossing to another upstream service additionally requires a nonempty catalog whose fallback belongs to that service; successful execution depends on its configured access. This does not imply new cross-tenant privileges or deployment exposure.

Security Findings and Attack Paths

  • inferred — A saved default or prior selection can supply a now-filtered ID to new-session construction. Resolution can substitute another provider's catalog entry, which becomes the execution target for subsequent text and attachments. Source establishes this conditional path, but not an attacker exploit or production disclosure.

Trust Boundaries and Controls

  • observed — Existing sessions provide their stored model string directly to execution. When that string is absent from the catalog, native-ID extraction preserves its provider/model suffix. Catalog filtering therefore does not itself reroute an already-restored session; this limits the concern to paths that resolve and replace the selection.

Resilience and Maintainability Implications

  • observed — Refresh constructs the result before publishing it, deduplicates concurrent refreshes per flavor, and clears inflight state for retry. Empty results and failures retain the previous overlay. Discovery finally clears its timer and closes, unwatches, and attempts to kill the probe child. These existing containment mechanisms remain unchanged.

Hardening Proposals

  • proposed — Separate picker visibility from saved execution identity. When a saved selection becomes unavailable, preserve its upstream-provider boundary or require an explicit replacement choice before constructing a session that uses another service.
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 3 functions across 2 files. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly describes the main change: hiding internal and legacy Copilot models from Pi and omp catalogs.
Description check ✅ Passed The description covers what changed and why, includes before-and-after UI screenshots, and completes all checklist items.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
  • Fix all pre-merge checks with AI
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@hardbeat920

Copy link
Copy Markdown
Owner

@nwoolls thanks you. Looks good to me :)

@hardbeat920
hardbeat920 merged commit 5aef862 into hardbeat920:main Oct 6, 2026
10 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants