From 7e033d0571f1661fc907b0dde2edc75e545981f7 Mon Sep 17 00:00:00 2001 From: AAEE86 Date: Wed, 23 Sep 2026 15:57:37 +0800 Subject: [PATCH] feat(codex): add dynamic CLI client profile --- apps/aether-gateway/src/ai_serving/api.rs | 6 +- .../planner/standard/codex/tests.rs | 28 +- .../aether-gateway/src/ai_serving/pure/mod.rs | 2 +- .../src/bin/aether-codex-ws-probe.rs | 28 +- apps/aether-gateway/src/codex_profile.rs | 468 ++++++++++++++++++ .../admin/provider/query/models/mod.rs | 3 +- apps/aether-gateway/src/lib.rs | 3 +- apps/aether-gateway/src/main.rs | 14 + .../aether-gateway/src/model_fetch/catalog.rs | 19 +- apps/aether-gateway/src/state/core.rs | 9 + apps/aether-gateway/src/task_runtime/mod.rs | 9 + .../src/tests/ai_execute/stream/image.rs | 2 +- .../src/tests/ai_execute/sync/image.rs | 2 +- .../src/tests/control/admin/provider_query.rs | 6 +- crates/aether-ai/formats/src/codex_profile.rs | 108 ++++ .../src/formats/openai/responses/codex.rs | 28 +- crates/aether-ai/formats/src/lib.rs | 6 +- crates/aether-model-fetch/src/logic.rs | 5 +- crates/aether-model-fetch/src/transport.rs | 16 +- .../transport/src/agent_identity.rs | 6 +- 20 files changed, 707 insertions(+), 61 deletions(-) create mode 100644 apps/aether-gateway/src/codex_profile.rs create mode 100644 crates/aether-ai/formats/src/codex_profile.rs diff --git a/apps/aether-gateway/src/ai_serving/api.rs b/apps/aether-gateway/src/ai_serving/api.rs index 9ff10edec..07bb62146 100644 --- a/apps/aether-gateway/src/ai_serving/api.rs +++ b/apps/aether-gateway/src/ai_serving/api.rs @@ -69,9 +69,9 @@ pub(crate) use aether_ai_formats::api::{ OPENAI_VIDEO_REMIX_SYNC_PLAN_KIND, }; pub(crate) use aether_ai_formats::protocol::stream::CanonicalUsage as StreamingCanonicalUsage; -/// Codex client identity headers re-exported for out-of-crate probe binaries, -/// which must reach `aether_ai_formats` through this seam. -pub use aether_ai_formats::{CODEX_CLIENT_ORIGINATOR, CODEX_CLIENT_USER_AGENT}; +/// Codex client identity accessors re-exported for out-of-crate probe binaries, +/// which must reach the runtime profile through this seam. +pub use aether_ai_formats::{codex_client_originator, codex_client_user_agent}; pub(crate) use aether_ai_formats::{CODEX_RESPONSES_LITE_HEADER, UPSTREAM_IS_STREAM_KEY}; pub(crate) fn parse_direct_request_body( diff --git a/apps/aether-gateway/src/ai_serving/planner/standard/codex/tests.rs b/apps/aether-gateway/src/ai_serving/planner/standard/codex/tests.rs index 52b3ef76f..30b51f6c6 100644 --- a/apps/aether-gateway/src/ai_serving/planner/standard/codex/tests.rs +++ b/apps/aether-gateway/src/ai_serving/planner/standard/codex/tests.rs @@ -505,9 +505,12 @@ fn projects_uuid_prompt_cache_identity_into_missing_session_headers() { assert_eq!(headers.get("x-client-request-id"), None); assert_eq!( headers.get("user-agent").map(String::as_str), - Some(aether_ai_formats::CODEX_CLIENT_USER_AGENT) + Some(aether_ai_formats::codex_client_user_agent().as_str()) + ); + assert_eq!( + headers.get("originator"), + Some(&aether_ai_formats::codex_client_originator()) ); - assert_eq!(headers.get("originator"), Some(&"codex_cli_rs".to_string())); assert!(!headers.contains_key("version")); assert_eq!(headers.get("x-openai-fedramp"), Some(&"true".to_string())); assert_eq!( @@ -615,9 +618,12 @@ fn injects_only_codex_client_headers_for_images_requests() { ); assert_eq!( headers.get("user-agent").map(String::as_str), - Some(aether_ai_formats::CODEX_CLIENT_USER_AGENT) + Some(aether_ai_formats::codex_client_user_agent().as_str()) + ); + assert_eq!( + headers.get("originator"), + Some(&aether_ai_formats::codex_client_originator()) ); - assert_eq!(headers.get("originator"), Some(&"codex_cli_rs".to_string())); assert!(!headers.contains_key("version")); assert_eq!(headers.get("x-openai-fedramp"), Some(&"true".to_string())); for name in ["x-client-request-id", "session-id", "thread-id"] { @@ -699,9 +705,12 @@ fn preserves_client_context_headers_and_enforces_codex_provider_identity() { ); assert_eq!( headers.get("user-agent").map(String::as_str), - Some(aether_ai_formats::CODEX_CLIENT_USER_AGENT) + Some(aether_ai_formats::codex_client_user_agent().as_str()) + ); + assert_eq!( + headers.get("originator"), + Some(&aether_ai_formats::codex_client_originator()) ); - assert_eq!(headers.get("originator"), Some(&"codex_cli_rs".to_string())); assert_eq!( headers .keys() @@ -763,9 +772,12 @@ fn compact_projects_uuid_prompt_cache_identity_into_session_headers() { assert_eq!(headers.get("x-client-request-id"), None); assert_eq!( headers.get("user-agent").map(String::as_str), - Some(aether_ai_formats::CODEX_CLIENT_USER_AGENT) + Some(aether_ai_formats::codex_client_user_agent().as_str()) + ); + assert_eq!( + headers.get("originator"), + Some(&aether_ai_formats::codex_client_originator()) ); - assert_eq!(headers.get("originator"), Some(&"codex_cli_rs".to_string())); assert!(!headers.contains_key("version")); assert_eq!(headers.get("x-openai-fedramp"), Some(&"true".to_string())); assert_eq!( diff --git a/apps/aether-gateway/src/ai_serving/pure/mod.rs b/apps/aether-gateway/src/ai_serving/pure/mod.rs index 41542a1f2..2b3eb5d7a 100644 --- a/apps/aether-gateway/src/ai_serving/pure/mod.rs +++ b/apps/aether-gateway/src/ai_serving/pure/mod.rs @@ -184,7 +184,7 @@ pub(crate) use aether_ai_formats::{ openai_responses_request_operation, openai_responses_synthetic_reasoning_item_id, strip_incompatible_openai_responses_reasoning_items, strip_incompatible_openai_responses_reasoning_items_with_policy, ApiOperation, ClientSurface, - CODEX_CLIENT_VERSION, OPENAI_RESPONSES_OPERATION_COMPACT, + OPENAI_RESPONSES_OPERATION_COMPACT, }; pub(crate) fn plan_kind_matches_api_operation( diff --git a/apps/aether-gateway/src/bin/aether-codex-ws-probe.rs b/apps/aether-gateway/src/bin/aether-codex-ws-probe.rs index b9def32c9..ec9437da9 100644 --- a/apps/aether-gateway/src/bin/aether-codex-ws-probe.rs +++ b/apps/aether-gateway/src/bin/aether-codex-ws-probe.rs @@ -7,7 +7,7 @@ #[path = "support/responses_ws_probe.rs"] mod responses_ws_probe; -use aether_gateway::{CODEX_CLIENT_ORIGINATOR, CODEX_CLIENT_USER_AGENT}; +use aether_gateway::{codex_client_originator, codex_client_user_agent}; use clap::Parser; use http::header::{AUTHORIZATION, USER_AGENT}; use http::{HeaderMap, HeaderName, HeaderValue}; @@ -78,14 +78,12 @@ fn handshake_headers(access_token: &str, account_id: &str) -> Result, +} + +#[derive(Debug, Deserialize, Serialize)] +struct CachedProfile { + version: String, + verified_at_unix_secs: u64, +} + +#[derive(Debug, thiserror::Error)] +enum ProfileRefreshError { + #[error("Codex CLI release client initialization failed: {0}")] + Client(#[from] reqwest::Error), + #[error("Codex CLI release request returned HTTP {0}")] + HttpStatus(u16), + #[error("Codex CLI release response exceeded {MAX_RELEASE_BYTES} bytes")] + ResponseTooLarge, + #[error("Codex CLI release metadata is invalid")] + InvalidMetadata, + #[error("Codex CLI release version is older than the active profile")] + Rollback, + #[error("Codex CLI profile cache operation failed: {0}")] + Cache(String), +} + +fn version_sequence(version: &str) -> Result { + let parsed = Version::parse(version).map_err(|_| ProfileRefreshError::InvalidMetadata)?; + if !parsed.pre.is_empty() + || !parsed.build.is_empty() + || parsed.major > 999 + || parsed.minor > 999 + || parsed.patch > 999 + { + return Err(ProfileRefreshError::InvalidMetadata); + } + Ok(1 + parsed.major * 1_000_000 + parsed.minor * 1_000 + parsed.patch) +} + +/// 校验官方 npm stable 标签及六个平台依赖来自同一版本发布。 +fn parse_cli_release(bytes: &[u8]) -> Result { + if bytes.len() > MAX_RELEASE_BYTES { + return Err(ProfileRefreshError::ResponseTooLarge); + } + let release = serde_json::from_slice::(bytes) + .map_err(|_| ProfileRefreshError::InvalidMetadata)?; + let sequence = version_sequence(&release.version)?; + if sequence == 0 + || release.name != "@openai/codex" + || CLI_TARGETS.iter().any(|target| { + release + .optional_dependencies + .get(&format!("@openai/codex-{target}")) + != Some(&format!("npm:@openai/codex@{}-{target}", release.version)) + }) + { + return Err(ProfileRefreshError::InvalidMetadata); + } + Ok(release.version) +} + +fn refresh_enabled_from(value: Option<&str>) -> bool { + !value.is_some_and(|value| { + matches!( + value.trim().to_ascii_lowercase().as_str(), + "0" | "false" | "off" + ) + }) +} + +fn refresh_enabled() -> bool { + refresh_enabled_from( + std::env::var("AETHER_CODEX_CLIENT_PROFILE_REFRESH") + .ok() + .as_deref(), + ) +} + +fn fixed_version_from(value: Option<&str>) -> Option { + let value = value?.trim(); + if value.is_empty() || version_sequence(value).is_err() { + None + } else { + Some(value.to_owned()) + } +} + +fn fixed_version_override() -> Option { + let value = std::env::var("AETHER_CODEX_CLIENT_VERSION").ok()?; + let version = fixed_version_from(Some(&value)); + if version.is_none() { + warn!( + event_name = "codex_client_profile_fixed_version_invalid", + "AETHER_CODEX_CLIENT_VERSION is invalid; using cached or built-in profile" + ); + } + version +} + +fn build_release_client() -> Result { + Client::builder() + .https_only(true) + .no_proxy() + .redirect(Policy::none()) + .connect_timeout(RELEASE_CONNECT_TIMEOUT) + .timeout(RELEASE_REQUEST_TIMEOUT) + .build() + .map_err(ProfileRefreshError::Client) +} + +async fn fetch_latest_cli_version(client: &Client) -> Result { + let response = client + .get(CLI_RELEASE_ENDPOINT) + .send() + .await + .map_err(ProfileRefreshError::Client)?; + if !response.status().is_success() { + return Err(ProfileRefreshError::HttpStatus(response.status().as_u16())); + } + if response + .content_length() + .is_some_and(|length| length > MAX_RELEASE_BYTES as u64) + { + return Err(ProfileRefreshError::ResponseTooLarge); + } + + let mut bytes = Vec::new(); + let mut stream = response.bytes_stream(); + while let Some(chunk) = stream.next().await { + let chunk = chunk.map_err(ProfileRefreshError::Client)?; + if bytes.len().saturating_add(chunk.len()) > MAX_RELEASE_BYTES { + return Err(ProfileRefreshError::ResponseTooLarge); + } + bytes.extend_from_slice(&chunk); + } + parse_cli_release(&bytes) +} + +async fn restore_cached_profile(runtime: &RuntimeState) -> Result<(), ProfileRefreshError> { + let Some(raw) = runtime + .kv_get(PROFILE_CACHE_KEY) + .await + .map_err(|err| ProfileRefreshError::Cache(err.to_string()))? + else { + return Ok(()); + }; + let cached = serde_json::from_str::(&raw) + .map_err(|_| ProfileRefreshError::InvalidMetadata)?; + if let Some(version) = + cached_version_to_restore(&cached, &aether_ai_formats::codex_client_version())? + { + aether_ai_formats::set_codex_cli_version(&version) + .map_err(|_| ProfileRefreshError::InvalidMetadata)?; + info!( + event_name = "codex_client_profile_restored", + version = %version, + verified_at_unix_secs = cached.verified_at_unix_secs, + "restored cached Codex CLI profile" + ); + } + Ok(()) +} + +fn cached_version_to_restore( + cached: &CachedProfile, + active_version: &str, +) -> Result, ProfileRefreshError> { + let cached_sequence = version_sequence(&cached.version)?; + let active_sequence = version_sequence(active_version)?; + Ok((cached_sequence >= active_sequence).then(|| cached.version.clone())) +} + +async fn refresh_once_with_fetch( + runtime: &RuntimeState, + fixed_version: Option<&str>, + refresh_is_enabled: bool, + fetch_latest: F, +) -> Result +where + F: FnOnce() -> Fut, + Fut: Future>, +{ + if let Some(version) = fixed_version { + aether_ai_formats::set_codex_cli_version(version) + .map_err(|_| ProfileRefreshError::InvalidMetadata)?; + return Ok(version.to_owned()); + } + + if let Err(error) = restore_cached_profile(runtime).await { + // 缓存损坏或暂时不可用不应阻断官方版本检查;当前进程继续使用旧画像。 + warn!( + event_name = "codex_client_profile_cache_restore_failed", + error = %error, + "could not restore cached Codex CLI profile" + ); + } + if !refresh_is_enabled { + return Ok(aether_ai_formats::codex_client_version()); + } + + let version = fetch_latest().await?; + let current = aether_ai_formats::codex_client_version(); + if version_sequence(&version)? < version_sequence(¤t)? { + return Err(ProfileRefreshError::Rollback); + } + + let cached = CachedProfile { + version: version.clone(), + verified_at_unix_secs: chrono::Utc::now().timestamp().max(0) as u64, + }; + let serialized = + serde_json::to_string(&cached).map_err(|_| ProfileRefreshError::InvalidMetadata)?; + aether_ai_formats::set_codex_cli_version(&version) + .map_err(|_| ProfileRefreshError::InvalidMetadata)?; + if let Err(error) = runtime + .kv_set(PROFILE_CACHE_KEY, serialized, Some(PROFILE_CACHE_TTL)) + .await + { + // 本地画像已经完成原子替换;缓存写失败只影响下次进程启动的恢复。 + warn!( + event_name = "codex_client_profile_cache_write_failed", + error = %error, + "published Codex CLI profile locally but could not persist the cache" + ); + } + Ok(version) +} + +async fn refresh_once(runtime: &RuntimeState) -> Result { + let fixed_version = fixed_version_override(); + refresh_once_with_fetch( + runtime, + fixed_version.as_deref(), + refresh_enabled(), + || async { + let client = build_release_client()?; + fetch_latest_cli_version(&client).await + }, + ) + .await +} + +pub(crate) async fn prewarm(runtime: &RuntimeState) -> Result { + refresh_once(runtime).await.map_err(|err| err.to_string()) +} + +pub(crate) fn spawn_worker(app: AppState) -> tokio::task::JoinHandle<()> { + crate::task_runtime::spawn_singleton_worker( + app, + crate::task_runtime::TASK_KEY_CODEX_CLIENT_PROFILE, + |app| async move { + let mut interval = tokio::time::interval(PROFILE_REFRESH_INTERVAL); + interval.set_missed_tick_behavior(tokio::time::MissedTickBehavior::Delay); + // 启动阶段由 prewarm 完成一次检查;后台任务只负责后续每日刷新,避免重复建连。 + interval.tick().await; + loop { + interval.tick().await; + match refresh_once(app.runtime_state()).await { + Ok(version) => info!( + event_name = "codex_client_profile_refreshed", + version = %version, + "refreshed Codex CLI profile" + ), + Err(error) => warn!( + event_name = "codex_client_profile_refresh_failed", + error = %error, + "keeping the previous Codex CLI profile after refresh failure" + ), + } + } + }, + ) +} + +#[cfg(test)] +mod tests { + use std::sync::{ + atomic::{AtomicBool, Ordering}, + Mutex, OnceLock, + }; + use std::time::Duration; + + use aether_runtime_state::{MemoryRuntimeStateConfig, RuntimeState}; + + use super::{ + cached_version_to_restore, fixed_version_from, parse_cli_release, refresh_enabled_from, + refresh_once_with_fetch, CachedProfile, ProfileRefreshError, PROFILE_CACHE_KEY, + }; + + static PROFILE_TEST_LOCK: OnceLock> = OnceLock::new(); + + struct ProfileRestore(aether_ai_formats::CodexClientProfile); + + impl Drop for ProfileRestore { + fn drop(&mut self) { + aether_ai_formats::set_codex_client_profile(self.0.clone()); + } + } + + fn profile_restore_guard() -> (std::sync::MutexGuard<'static, ()>, ProfileRestore) { + let lock = PROFILE_TEST_LOCK.get_or_init(|| Mutex::new(())); + let guard = lock.lock().expect("profile test lock"); + let restore = ProfileRestore(aether_ai_formats::codex_client_profile()); + (guard, restore) + } + + #[test] + fn accepts_only_one_verified_cli_release_for_all_targets() { + let body = serde_json::json!({ + "name": "@openai/codex", + "version": "0.200.1", + "optionalDependencies": { + "@openai/codex-darwin-arm64": "npm:@openai/codex@0.200.1-darwin-arm64", + "@openai/codex-darwin-x64": "npm:@openai/codex@0.200.1-darwin-x64", + "@openai/codex-linux-arm64": "npm:@openai/codex@0.200.1-linux-arm64", + "@openai/codex-linux-x64": "npm:@openai/codex@0.200.1-linux-x64", + "@openai/codex-win32-arm64": "npm:@openai/codex@0.200.1-win32-arm64", + "@openai/codex-win32-x64": "npm:@openai/codex@0.200.1-win32-x64" + } + }); + assert_eq!( + parse_cli_release(&serde_json::to_vec(&body).unwrap()).unwrap(), + "0.200.1" + ); + } + + #[test] + fn rejects_incomplete_platform_release() { + let body = serde_json::json!({ + "name": "@openai/codex", + "version": "0.200.1", + "optionalDependencies": {} + }); + assert!(parse_cli_release(&serde_json::to_vec(&body).unwrap()).is_err()); + } + + #[test] + fn refresh_and_fixed_version_environment_policies_are_strict() { + assert!(!refresh_enabled_from(Some("off"))); + assert!(!refresh_enabled_from(Some(" FALSE "))); + assert!(refresh_enabled_from(None)); + assert_eq!( + fixed_version_from(Some(" 0.200.1 ")).as_deref(), + Some("0.200.1") + ); + assert!(fixed_version_from(Some("0.200.1-beta.1")).is_none()); + assert!(fixed_version_from(Some("1.2")).is_none()); + } + + #[test] + fn cached_profile_never_rewinds_active_profile() { + let cached = CachedProfile { + version: "0.200.1".to_string(), + verified_at_unix_secs: 1, + }; + assert_eq!( + cached_version_to_restore(&cached, "0.200.0").unwrap(), + Some("0.200.1".to_string()) + ); + assert_eq!(cached_version_to_restore(&cached, "0.201.0").unwrap(), None); + } + + #[tokio::test] + async fn cache_hit_is_restored_without_network_when_refresh_is_disabled() { + let (_lock, _restore) = profile_restore_guard(); + let runtime = RuntimeState::memory(MemoryRuntimeStateConfig::default()); + runtime + .kv_set( + PROFILE_CACHE_KEY, + serde_json::to_string(&CachedProfile { + version: "0.200.1".to_string(), + verified_at_unix_secs: 1, + }) + .unwrap(), + Some(Duration::from_secs(60)), + ) + .await + .unwrap(); + + let result = refresh_once_with_fetch(&runtime, None, false, || async { + Err(ProfileRefreshError::HttpStatus(599)) + }) + .await + .unwrap(); + + assert_eq!(result, "0.200.1"); + assert_eq!(aether_ai_formats::codex_client_version(), "0.200.1"); + } + + #[tokio::test] + async fn refresh_failure_keeps_previous_profile() { + let (_lock, _restore) = profile_restore_guard(); + let runtime = RuntimeState::memory(MemoryRuntimeStateConfig::default()); + let before = aether_ai_formats::codex_client_profile(); + let result = refresh_once_with_fetch(&runtime, None, true, || async { + Err(ProfileRefreshError::HttpStatus(503)) + }) + .await; + + assert!(matches!(result, Err(ProfileRefreshError::HttpStatus(503)))); + assert_eq!(aether_ai_formats::codex_client_profile(), before); + } + + #[tokio::test] + async fn fixed_version_override_skips_network_and_publishes_profile() { + let (_lock, _restore) = profile_restore_guard(); + let runtime = RuntimeState::memory(MemoryRuntimeStateConfig::default()); + let fetch_called = AtomicBool::new(false); + let result = refresh_once_with_fetch(&runtime, Some("0.220.0"), true, || async { + fetch_called.store(true, Ordering::SeqCst); + Ok("0.221.0".to_string()) + }) + .await + .unwrap(); + + assert_eq!(result, "0.220.0"); + assert!(!fetch_called.load(Ordering::SeqCst)); + assert_eq!(aether_ai_formats::codex_client_version(), "0.220.0"); + } + + #[tokio::test] + async fn rollback_is_rejected_without_replacing_profile() { + let (_lock, _restore) = profile_restore_guard(); + aether_ai_formats::set_codex_cli_version("0.220.0").unwrap(); + let runtime = RuntimeState::memory(MemoryRuntimeStateConfig::default()); + let result = + refresh_once_with_fetch(&runtime, None, true, || async { Ok("0.219.9".to_string()) }) + .await; + + assert!(matches!(result, Err(ProfileRefreshError::Rollback))); + assert_eq!(aether_ai_formats::codex_client_version(), "0.220.0"); + } +} diff --git a/apps/aether-gateway/src/handlers/admin/provider/query/models/mod.rs b/apps/aether-gateway/src/handlers/admin/provider/query/models/mod.rs index cb0cc44e5..979dc57aa 100644 --- a/apps/aether-gateway/src/handlers/admin/provider/query/models/mod.rs +++ b/apps/aether-gateway/src/handlers/admin/provider/query/models/mod.rs @@ -594,11 +594,12 @@ async fn provider_query_fetch_models_for_key( }); } + let dynamic_client_version = aether_ai_formats::codex_client_version(); let client_version = is_codex.then(|| { codex_catalog .as_ref() .map(|catalog| catalog.client_version.as_str()) - .unwrap_or(crate::ai_serving::CODEX_CLIENT_VERSION) + .unwrap_or(dynamic_client_version.as_str()) }); let outcome = match fetch_models_from_transports_for_management(state.app(), &transports, client_version) diff --git a/apps/aether-gateway/src/lib.rs b/apps/aether-gateway/src/lib.rs index 57bd703a2..20c2ba715 100644 --- a/apps/aether-gateway/src/lib.rs +++ b/apps/aether-gateway/src/lib.rs @@ -37,6 +37,7 @@ mod bark_push; mod cache; mod client_session_affinity; mod clock; +mod codex_profile; mod constants; mod control; mod data; @@ -90,12 +91,12 @@ mod usage; mod video_tasks; mod wallet_runtime; +pub use self::ai_serving::api::{codex_client_originator, codex_client_user_agent}; pub(crate) use self::ai_serving::api::{ AiControlPlanRequest, EXECUTION_RUNTIME_STREAM_DECISION_ACTION, EXECUTION_RUNTIME_SYNC_DECISION_ACTION, GEMINI_FILES_DOWNLOAD_PLAN_KIND, OPENAI_VIDEO_CONTENT_PLAN_KIND, }; -pub use self::ai_serving::api::{CODEX_CLIENT_ORIGINATOR, CODEX_CLIENT_USER_AGENT}; pub(crate) use self::ai_serving::{ AiExecutionDecision, AiExecutionPlanPayload, AiStreamAttempt, AiSyncAttempt, }; diff --git a/apps/aether-gateway/src/main.rs b/apps/aether-gateway/src/main.rs index d765f7a83..022f53bb6 100644 --- a/apps/aether-gateway/src/main.rs +++ b/apps/aether-gateway/src/main.rs @@ -2513,6 +2513,20 @@ async fn run() -> Result<(), Box> { ); } } + match state.prewarm_codex_client_profile().await { + Ok(version) => { + info!( + codex_client_version = %version, + "prewarmed Codex client profile" + ); + } + Err(err) => { + warn!( + error = %err, + "failed to refresh Codex client profile; built-in or cached profile remains active" + ); + } + } match prewarm_direct_h2c_sender_cache_from_env_for_startup().await { Ok(Some(report)) => { if report.failed_targets > 0 { diff --git a/apps/aether-gateway/src/model_fetch/catalog.rs b/apps/aether-gateway/src/model_fetch/catalog.rs index 6b0d92e13..1b16b5a37 100644 --- a/apps/aether-gateway/src/model_fetch/catalog.rs +++ b/apps/aether-gateway/src/model_fetch/catalog.rs @@ -99,7 +99,7 @@ pub(crate) fn normalize_codex_client_version(raw: Option<&str>) -> NormalizedCod used_fallback: false, }, None => NormalizedCodexClientVersion { - value: crate::ai_serving::CODEX_CLIENT_VERSION.to_string(), + value: aether_ai_formats::codex_client_version(), used_fallback: true, }, } @@ -1521,7 +1521,7 @@ where .await?; let scope = target.credential_scope()?; let state = runtime.codex_catalog_runtime_state(); - let mut version = Version::parse(crate::ai_serving::CODEX_CLIENT_VERSION).ok()?; + let mut version = Version::parse(&aether_ai_formats::codex_client_version()).ok()?; if let Some(recent) = read_recent_codex_catalog_client_version(state, provider_id, key_id, scope).await { @@ -2463,7 +2463,7 @@ mod tests { .expect("management context"); assert_eq!( initial.client_version, - crate::ai_serving::CODEX_CLIENT_VERSION + aether_ai_formats::codex_client_version() ); assert!(initial.models.is_none()); @@ -2500,7 +2500,7 @@ mod tests { .unwrap(); assert_eq!( rebound.client_version, - crate::ai_serving::CODEX_CLIENT_VERSION + aether_ai_formats::codex_client_version() ); assert!(rebound.models.is_none()); } @@ -2557,7 +2557,10 @@ mod tests { format!("1.2.3-{}", "x".repeat(CODEX_CLIENT_VERSION_MAX_LEN)), ] { let normalized = normalize_codex_client_version(Some(&raw)); - assert_eq!(normalized.as_str(), crate::ai_serving::CODEX_CLIENT_VERSION); + assert_eq!( + normalized.as_str(), + aether_ai_formats::codex_client_version() + ); assert!(normalized.used_fallback()); assert!(!catalog_lkg_key(&target(), normalized.as_str()).contains(&raw)); } @@ -3753,7 +3756,11 @@ mod tests { .await .expect("seed legacy cache"); - let load = load_one(&runtime, &version(crate::ai_serving::CODEX_CLIENT_VERSION)).await; + let load = load_one( + &runtime, + &version(&aether_ai_formats::codex_client_version()), + ) + .await; assert!(load.snapshot(TEST_PROVIDER_ID, TEST_KEY_ID).is_none()); assert_eq!(runtime.execution_count(), 1); } diff --git a/apps/aether-gateway/src/state/core.rs b/apps/aether-gateway/src/state/core.rs index ab462ed90..e7cde0f8a 100644 --- a/apps/aether-gateway/src/state/core.rs +++ b/apps/aether-gateway/src/state/core.rs @@ -53,6 +53,7 @@ use super::super::router::RequestAdmissionError; use super::super::{control::GatewayControlDecision, error::GatewayError}; use super::super::{provider_transport, usage}; +use crate::codex_profile::spawn_worker as spawn_codex_client_profile_worker; use crate::maintenance::spawn_account_self_check_worker; use crate::maintenance::spawn_audit_cleanup_worker; use crate::maintenance::spawn_db_maintenance_worker; @@ -148,6 +149,10 @@ fn system_config_key_affects_provider_transport_snapshot(key: &str) -> bool { } impl AppState { + pub async fn prewarm_codex_client_profile(&self) -> Result { + crate::codex_profile::prewarm(self.runtime_state()).await + } + pub async fn prewarm_chat_pii_redaction_runtime_config(&self) -> Result { crate::privacy::read_chat_pii_redaction_runtime_config(self) .await @@ -2332,6 +2337,10 @@ impl AppState { crate::task_runtime::TASK_KEY_MODEL_FETCH_WORKER, spawn_model_fetch_worker(background_state.clone()), ); + supervise_worker( + crate::task_runtime::TASK_KEY_CODEX_CLIENT_PROFILE, + Some(spawn_codex_client_profile_worker(background_state.clone())), + ); supervise_worker( crate::task_runtime::TASK_KEY_VIDEO_TASK_POLLER, spawn_video_task_poller(background_state.clone()), diff --git a/apps/aether-gateway/src/task_runtime/mod.rs b/apps/aether-gateway/src/task_runtime/mod.rs index e8d4c95e9..226579c97 100644 --- a/apps/aether-gateway/src/task_runtime/mod.rs +++ b/apps/aether-gateway/src/task_runtime/mod.rs @@ -24,6 +24,7 @@ pub(crate) const TASK_KEY_USAGE_QUEUE_WORKER: &str = "usage.queue.worker"; pub(crate) const TASK_KEY_USAGE_COUNTER_FLUSH: &str = "usage.counter.flush.worker"; pub(crate) const TASK_KEY_VIDEO_TASK_POLLER: &str = "video.task.poller"; pub(crate) const TASK_KEY_MODEL_FETCH_WORKER: &str = "model.fetch.worker"; +pub(crate) const TASK_KEY_CODEX_CLIENT_PROFILE: &str = "maintenance.codex.client.profile"; pub(crate) const TASK_KEY_PROVIDER_QUOTA_RESET: &str = "provider.quota.reset.worker"; pub(crate) const TASK_KEY_ACCOUNT_SELF_CHECK: &str = "account.self_check.worker"; pub(crate) const TASK_KEY_POOL_SCORE_REBUILD: &str = "pool.score.rebuild.worker"; @@ -202,6 +203,14 @@ const TASK_DEFINITIONS: &[TaskDefinition] = &[ true, RETRY_ONCE, ), + TaskDefinition::new( + TASK_KEY_CODEX_CLIENT_PROFILE, + TaskKind::Scheduled, + "daily", + true, + true, + RETRY_ONCE, + ), TaskDefinition::new( TASK_KEY_PROVIDER_QUOTA_RESET, TaskKind::Scheduled, diff --git a/apps/aether-gateway/src/tests/ai_execute/stream/image.rs b/apps/aether-gateway/src/tests/ai_execute/stream/image.rs index 1b76e7cff..477bed8d4 100644 --- a/apps/aether-gateway/src/tests/ai_execute/stream/image.rs +++ b/apps/aether-gateway/src/tests/ai_execute/stream/image.rs @@ -421,7 +421,7 @@ async fn gateway_executes_codex_image_stream_via_local_decision_gate_after_oauth ); assert_eq!( seen_execution_runtime_request.headers["user-agent"], - aether_ai_formats::CODEX_CLIENT_USER_AGENT + aether_ai_formats::codex_client_user_agent() ); assert_eq!( seen_execution_runtime_request.headers["originator"], diff --git a/apps/aether-gateway/src/tests/ai_execute/sync/image.rs b/apps/aether-gateway/src/tests/ai_execute/sync/image.rs index 921e33eea..58e201f67 100644 --- a/apps/aether-gateway/src/tests/ai_execute/sync/image.rs +++ b/apps/aether-gateway/src/tests/ai_execute/sync/image.rs @@ -1119,7 +1119,7 @@ async fn gateway_executes_codex_image_sync_via_local_decision_gate_after_oauth_r ); assert_eq!( seen_execution_runtime_request.headers["user-agent"], - aether_ai_formats::CODEX_CLIENT_USER_AGENT + aether_ai_formats::codex_client_user_agent() ); assert_eq!( seen_execution_runtime_request.headers["originator"], diff --git a/apps/aether-gateway/src/tests/control/admin/provider_query.rs b/apps/aether-gateway/src/tests/control/admin/provider_query.rs index 82af4621c..801385e34 100644 --- a/apps/aether-gateway/src/tests/control/admin/provider_query.rs +++ b/apps/aether-gateway/src/tests/control/admin/provider_query.rs @@ -560,12 +560,12 @@ async fn gateway_recovers_codex_slug_only_models_from_a_stale_legacy_cache_impl( plan.url, format!( "https://chatgpt.com/backend-api/codex/models?client_version={}", - aether_ai_formats::CODEX_CLIENT_VERSION + aether_ai_formats::codex_client_version() ) ); assert_eq!( plan.headers.get("user-agent").map(String::as_str), - Some(aether_ai_formats::CODEX_CLIENT_USER_AGENT) + Some(aether_ai_formats::codex_client_user_agent().as_str()) ); assert_eq!(plan.provider_api_format, "openai:responses"); Json(json!({ @@ -764,7 +764,7 @@ async fn gateway_handles_admin_provider_query_models_falls_back_to_codex_preset_ plan.url, format!( "https://chatgpt.com/backend-api/codex/models?client_version={}", - aether_ai_formats::CODEX_CLIENT_VERSION + aether_ai_formats::codex_client_version() ) ); Json(json!({ diff --git a/crates/aether-ai/formats/src/codex_profile.rs b/crates/aether-ai/formats/src/codex_profile.rs new file mode 100644 index 000000000..1338a9f8c --- /dev/null +++ b/crates/aether-ai/formats/src/codex_profile.rs @@ -0,0 +1,108 @@ +use std::sync::{OnceLock, RwLock}; + +/// 当前支持的 Codex 客户端类型。 +#[derive(Clone, Copy, Debug, PartialEq, Eq)] +pub enum CodexClientKind { + Cli, + Desktop, +} + +/// Codex 上游请求使用的客户端画像。 +/// +/// 画像由网关后台任务更新,格式转换层只读取不可变快照,避免在请求路径执行网络操作。 +#[derive(Clone, Debug, PartialEq, Eq)] +pub struct CodexClientProfile { + pub client_kind: CodexClientKind, + pub codex_version: String, + pub originator: String, + pub user_agent: String, +} + +impl CodexClientProfile { + /// 从稳定版本号创建 CLI 画像;版本校验由发布检查器负责,构造器只拒绝明显非法值。 + pub fn cli(version: &str) -> Result { + let version = version.trim(); + if version.is_empty() + || version.len() > 64 + || !version.bytes().all(|byte| (32..=126).contains(&byte)) + { + return Err("invalid Codex CLI version"); + } + let originator = "codex_cli_rs".to_owned(); + Ok(Self { + client_kind: CodexClientKind::Cli, + codex_version: version.to_owned(), + user_agent: format!("{}/{}", originator, version), + originator, + }) + } +} + +impl Default for CodexClientProfile { + fn default() -> Self { + // 远程发布检查不可用时仍保持现有线上行为,避免启动或请求被版本服务拖住。 + Self::cli("0.153.4").expect("built-in Codex CLI profile must be valid") + } +} + +static ACTIVE_PROFILE: OnceLock> = OnceLock::new(); + +fn active_profile() -> &'static RwLock { + ACTIVE_PROFILE.get_or_init(|| RwLock::new(CodexClientProfile::default())) +} + +/// 返回当前画像的独立快照,调用方不会持有全局锁。 +pub fn codex_client_profile() -> CodexClientProfile { + active_profile() + .read() + .unwrap_or_else(std::sync::PoisonError::into_inner) + .clone() +} + +/// 原子替换当前画像,并返回替换前的画像。 +pub fn set_codex_client_profile(profile: CodexClientProfile) -> CodexClientProfile { + let mut current = active_profile() + .write() + .unwrap_or_else(std::sync::PoisonError::into_inner); + std::mem::replace(&mut *current, profile) +} + +/// 发布一份新的 CLI 画像。 +pub fn set_codex_cli_version(version: &str) -> Result { + let profile = CodexClientProfile::cli(version)?; + Ok(set_codex_client_profile(profile)) +} + +/// 返回当前画像的 Codex Core 版本。 +pub fn codex_client_version() -> String { + codex_client_profile().codex_version +} + +/// 返回当前画像的 User-Agent。 +pub fn codex_client_user_agent() -> String { + codex_client_profile().user_agent +} + +/// 返回当前画像的 originator。 +pub fn codex_client_originator() -> String { + codex_client_profile().originator +} + +#[cfg(test)] +mod tests { + use super::{CodexClientKind, CodexClientProfile}; + + #[test] + fn cli_profile_derives_wire_identity_from_version() { + let profile = CodexClientProfile::cli("0.200.1").expect("valid version"); + assert_eq!(profile.client_kind, CodexClientKind::Cli); + assert_eq!(profile.originator, "codex_cli_rs"); + assert_eq!(profile.user_agent, "codex_cli_rs/0.200.1"); + } + + #[test] + fn cli_profile_rejects_empty_or_control_values() { + assert!(CodexClientProfile::cli("").is_err()); + assert!(CodexClientProfile::cli("0.1.0\nspoof").is_err()); + } +} diff --git a/crates/aether-ai/formats/src/formats/openai/responses/codex.rs b/crates/aether-ai/formats/src/formats/openai/responses/codex.rs index 9af15f2d5..548a65894 100644 --- a/crates/aether-ai/formats/src/formats/openai/responses/codex.rs +++ b/crates/aether-ai/formats/src/formats/openai/responses/codex.rs @@ -1,6 +1,7 @@ use std::collections::BTreeMap; use std::sync::OnceLock; +use crate::codex_profile::codex_client_profile; use aether_ai_formats::provider_compat::proxy::rules::body_rules_handle_path; use serde::{Deserialize, Serialize}; use serde_json::{json, Value}; @@ -36,9 +37,6 @@ const CODEX_OPENAI_RESPONSES_COMPACT_BODY_FIELDS: &[&str] = &[ "prompt_cache_key", "text", ]; -pub const CODEX_CLIENT_VERSION: &str = "0.153.4"; -pub const CODEX_CLIENT_USER_AGENT: &str = "codex_cli_rs/0.153.4"; -pub const CODEX_CLIENT_ORIGINATOR: &str = "codex_cli_rs"; pub const CODEX_OPENAI_IMAGE_INTERNAL_MODEL: &str = "gpt-5.4-mini"; pub const CODEX_OPENAI_IMAGE_DEFAULT_MODEL: &str = "gpt-image-2"; pub const CODEX_OPENAI_IMAGE_DEFAULT_VARIATION_MODEL: &str = "dall-e-2"; @@ -2098,6 +2096,7 @@ pub fn apply_codex_openai_special_headers( }; let auth_identity = parse_codex_auth_identity(decrypted_auth_config_raw); + let client_profile = codex_client_profile(); remove_btree_header(provider_request_headers, "chatgpt-account-id"); remove_btree_header(provider_request_headers, "x-openai-fedramp"); @@ -2112,12 +2111,12 @@ pub fn apply_codex_openai_special_headers( set_codex_client_header( provider_request_headers, "user-agent", - CODEX_CLIENT_USER_AGENT, + &client_profile.user_agent, ); set_codex_client_header( provider_request_headers, "originator", - CODEX_CLIENT_ORIGINATOR, + &client_profile.originator, ); if endpoint_kind == CodexOpenAiEndpointKind::Search { remove_btree_header(provider_request_headers, CODEX_RESPONSES_LITE_HEADER); @@ -2175,17 +2174,18 @@ mod tests { build_codex_model_catalog_metadata, bundled_codex_model_cards, effective_codex_model_cards, parse_codex_auth_identity, project_codex_catalog_model_card, resolve_codex_responses_model_capabilities, - validate_codex_openai_responses_compact_request_contract, CODEX_CLIENT_ORIGINATOR, - CODEX_CLIENT_USER_AGENT, CODEX_CLIENT_VERSION, CODEX_OPENAI_IMAGE_INTERNAL_MODEL, - CODEX_OPENAI_RESPONSES_UNSUPPORTED_BODY_FIELDS, CODEX_RESPONSES_LITE_HEADER, + validate_codex_openai_responses_compact_request_contract, + CODEX_OPENAI_IMAGE_INTERNAL_MODEL, CODEX_OPENAI_RESPONSES_UNSUPPORTED_BODY_FIELDS, + CODEX_RESPONSES_LITE_HEADER, }; use serde_json::{json, Value}; #[test] fn codex_client_user_agent_matches_originator_and_version() { + let profile = crate::codex_client_profile(); assert_eq!( - CODEX_CLIENT_USER_AGENT, - format!("{CODEX_CLIENT_ORIGINATOR}/{CODEX_CLIENT_VERSION}") + profile.user_agent, + format!("{}/{}", profile.originator, profile.codex_version) ); } @@ -2963,11 +2963,11 @@ mod tests { ); assert_eq!( headers.get("user-agent").map(String::as_str), - Some(CODEX_CLIENT_USER_AGENT) + Some(crate::codex_client_user_agent().as_str()) ); assert_eq!( headers.get("originator").map(String::as_str), - Some(CODEX_CLIENT_ORIGINATOR) + Some(crate::codex_client_originator().as_str()) ); assert!(!headers.contains_key(CODEX_RESPONSES_LITE_HEADER)); assert!(!headers.contains_key("openai-beta")); @@ -3001,11 +3001,11 @@ mod tests { ); assert_eq!( headers.get("user-agent").map(String::as_str), - Some(CODEX_CLIENT_USER_AGENT) + Some(crate::codex_client_user_agent().as_str()) ); assert_eq!( headers.get("originator").map(String::as_str), - Some(CODEX_CLIENT_ORIGINATOR) + Some(crate::codex_client_originator().as_str()) ); assert!(!headers.contains_key(CODEX_RESPONSES_LITE_HEADER)); } diff --git a/crates/aether-ai/formats/src/lib.rs b/crates/aether-ai/formats/src/lib.rs index 4496e1900..a7af48b23 100644 --- a/crates/aether-ai/formats/src/lib.rs +++ b/crates/aether-ai/formats/src/lib.rs @@ -1,11 +1,16 @@ extern crate self as aether_ai_formats; pub mod api; +pub mod codex_profile; pub mod contracts; pub mod formats; pub mod protocol; pub mod provider_compat; +pub use codex_profile::{ + codex_client_originator, codex_client_profile, codex_client_user_agent, codex_client_version, + set_codex_cli_version, set_codex_client_profile, CodexClientKind, CodexClientProfile, +}; pub use contracts::{ApiOperation, ClientSurface}; pub use formats::context::{ @@ -50,7 +55,6 @@ pub use formats::openai::responses::codex::{ codex_responses_lite_tool_is_client_executed, effective_codex_model_cards, parse_codex_auth_identity, project_codex_catalog_model_card, resolve_codex_responses_model_capabilities, CodexAuthIdentity, CodexResponsesModelCapabilities, - CODEX_CLIENT_ORIGINATOR, CODEX_CLIENT_USER_AGENT, CODEX_CLIENT_VERSION, CODEX_MODEL_CATALOG_METADATA_FIELD, CODEX_RESPONSES_LITE_HEADER, }; pub use formats::openai::responses::request::{ diff --git a/crates/aether-model-fetch/src/logic.rs b/crates/aether-model-fetch/src/logic.rs index 270b13ba9..e0eb69759 100644 --- a/crates/aether-model-fetch/src/logic.rs +++ b/crates/aether-model-fetch/src/logic.rs @@ -993,7 +993,7 @@ fn build_codex_models_url(base_url: &str, client_version: Option<&str>) -> Optio } else if !has_client_version { query_parts.push(format!( "client_version={}", - aether_ai_formats::CODEX_CLIENT_VERSION + aether_ai_formats::codex_client_version() )); } if !query_parts.is_empty() { @@ -1354,6 +1354,7 @@ mod tests { #[test] fn build_models_fetch_url_uses_codex_backend_models_endpoint() { + let client_version = aether_ai_formats::codex_client_version(); assert_eq!( build_models_fetch_url( "codex", @@ -1363,7 +1364,7 @@ mod tests { Some(( format!( "https://chatgpt.com/backend-api/codex/models?client_version={}", - aether_ai_formats::CODEX_CLIENT_VERSION + client_version ), "openai:responses".to_string() )) diff --git a/crates/aether-model-fetch/src/transport.rs b/crates/aether-model-fetch/src/transport.rs index dc1e29b88..cc1d165e7 100644 --- a/crates/aether-model-fetch/src/transport.rs +++ b/crates/aether-model-fetch/src/transport.rs @@ -627,28 +627,30 @@ fn standard_models_fetch_headers( let api_format = aether_ai_formats::normalize_api_format_alias(api_format); let provider_type = provider_type.trim().to_ascii_lowercase(); if provider_type == "codex" && api_format.starts_with("openai:") { + // 模型目录请求也必须使用当前动态画像,不能回退到编译时固定版本。 + let dynamic_client_version = aether_ai_formats::codex_client_version(); let client_version = codex_client_version .map(str::trim) .filter(|value| !value.is_empty()) - .unwrap_or(aether_ai_formats::CODEX_CLIENT_VERSION); + .unwrap_or(dynamic_client_version.as_str()); return BTreeMap::from([ ( "user-agent".to_string(), format!( "{}/{client_version}", - aether_ai_formats::CODEX_CLIENT_ORIGINATOR + aether_ai_formats::codex_client_originator() ), ), ( "originator".to_string(), - aether_ai_formats::CODEX_CLIENT_ORIGINATOR.to_string(), + aether_ai_formats::codex_client_originator(), ), ]); } match api_format.as_str() { "openai:responses" | "openai:responses:compact" => BTreeMap::from([( "user-agent".to_string(), - aether_ai_formats::CODEX_CLIENT_USER_AGENT.to_string(), + aether_ai_formats::codex_client_user_agent(), )]), "claude:messages" => { let mut headers = BTreeMap::from([( @@ -894,7 +896,7 @@ mod tests { assert_eq!(plan.url, "https://example.com/models"); assert_eq!( plan.headers.get("user-agent").map(String::as_str), - Some(aether_ai_formats::CODEX_CLIENT_USER_AGENT) + Some(aether_ai_formats::codex_client_user_agent().as_str()) ); assert_eq!( plan.headers.get("authorization").map(String::as_str), @@ -993,7 +995,7 @@ mod tests { plan.url, format!( "https://chatgpt.com/backend-api/codex/models?client_version={}", - aether_ai_formats::CODEX_CLIENT_VERSION + aether_ai_formats::codex_client_version() ) ); assert_eq!( @@ -1018,7 +1020,7 @@ mod tests { ); assert_eq!( plan.headers.get("user-agent").map(String::as_str), - Some(aether_ai_formats::CODEX_CLIENT_USER_AGENT) + Some(aether_ai_formats::codex_client_user_agent().as_str()) ); assert!(!plan.headers.contains_key("version")); } diff --git a/crates/aether-provider/transport/src/agent_identity.rs b/crates/aether-provider/transport/src/agent_identity.rs index abdb9d806..d7b7ee3ac 100644 --- a/crates/aether-provider/transport/src/agent_identity.rs +++ b/crates/aether-provider/transport/src/agent_identity.rs @@ -780,11 +780,11 @@ async fn register_codex_agent_identity_from_access_token_with_auth_api_base_url( ), ( "user-agent".to_string(), - aether_ai_formats::CODEX_CLIENT_USER_AGENT.to_string(), + aether_ai_formats::codex_client_user_agent(), ), ( "originator".to_string(), - aether_ai_formats::CODEX_CLIENT_ORIGINATOR.to_string(), + aether_ai_formats::codex_client_originator(), ), ]); if options.is_fedramp_account { @@ -799,7 +799,7 @@ async fn register_codex_agent_identity_from_access_token_with_auth_api_base_url( content_type: Some("application/json".to_string()), json_body: Some(json!({ "abom": { - "agent_version": aether_ai_formats::CODEX_CLIENT_VERSION, + "agent_version": aether_ai_formats::codex_client_version(), "agent_harness_id": CODEX_AGENT_IDENTITY_AGENT_HARNESS_ID, "running_location": format!("cli-{}", std::env::consts::OS), },