elky
579f2c7cc1
feat(security): harden gateway boundaries and usage policies
...
Consolidate subscription usage policy enforcement, privacy-safe persistence, and gateway security hardening into one reviewable change.
Includes bounded HTTP and execution envelopes, header and protocol guards, DNS and relay validation, authentication and secret projection hardening, secure backup/install paths, and regression coverage.
2026-09-04 03:45:52 +08:00
ZheFox
587486ab0c
Merge remote-tracking branch 'upstream/main' into codex/fix-antigravity-quota
2026-09-03 13:24:39 +08:00
fawney
2cb4d554aa
feat(routing): consolidate scheduling strategy configuration
2026-09-03 11:05:59 +08:00
ZheFox
f822df6cce
Merge remote-tracking branch 'origin/main' into codex/fix-antigravity-quota
2026-09-03 10:46:49 +08:00
ZheFox
45c840b8d3
fix(providers): refresh Antigravity grouped quotas
2026-09-03 10:46:44 +08:00
elky
7323d41fbe
feat(routing): move sticky-key retries into routing policy with lazy attempts
...
Replace the provider/endpoint max_retries fields as the source of same-key
retries with a routing policy setting, sticky_key_attempts (default 2). Only
the first-ranked candidate is retried on the same key; every failover
candidate gets a single attempt so failover keeps advancing instead of
retrying each fallback key.
Materialize exactly one attempt per candidate and derive same-key retries in
the attempt loop after a candidate-scoped failure, so the retry budget no
longer inflates up-front materialization and needs no upper bound. The budget
travels in the report context; retries reuse the plan with a fresh candidate
id and incremented retry index. Pool groups only retry their first key within
the retry-index stride.
Expose the setting in the routing profile editor and the set_scheduling rule
action, and drop the max_retries input from the provider form.
2026-09-02 20:48:40 +08:00
zhefox
7ae984df4b
fix(gateway): detect DeepSeek custom relay models
2026-09-01 22:49:35 +08:00
elky
a39048ecce
feat(codex): stabilize identity across retries
2026-09-01 15:33:40 +08:00
ZheFox
5bcdcca784
fix(formats): normalize Responses additional tools for Chat
2026-08-28 23:03:56 +08:00
ZheFox
4185ad1b1e
feat(gateway): add Codex Live transport
2026-08-20 21:59:05 +08:00
ZheFox
654f798d25
fix(ws): harden Responses continuation state
2026-08-20 08:51:16 +08:00
ZheFox
bef282cfee
fix(responses): replay DeepSeek opaque reasoning state
2026-08-20 00:40:48 +08:00
ZheFox
c8118edf36
fix(ws): harden Responses connection lifecycle
...
Revalidate control policy per turn, isolate downstream credentials, and make planner/turn ownership cancellation-safe.
Preserve opaque protocol events, align configurable timeout semantics, and extend end-to-end security and settlement coverage.
2026-08-17 18:50:29 +08:00
AAEE86
71b54070e8
feat(gateway): Codex/OpenAI Responses WebSocket 代理模式
...
在 /v1/responses 上支持 WebSocket 升级,把客户端帧中继到上游 Codex /
OpenAI Responses WebSocket 端点,同时保持既有的路由、鉴权、配额与用量
语义:
- 路由与准入:control/route/ai.rs 识别 WebSocket 升级请求;
websocket/ingress.rs 复用 API Key 鉴权、IP 规则与并发许可,并引入
独立的 WebSocket 连接许可
- 中继:websocket/responses/* 按 connection / session / turn 分层,
帧解析归一化、socket 写入有界、continuation 保持调度亲和性
- 配额:orchestration/codex_quota_breaker.rs 在账号配额耗尽时熔断并
自动恢复,不再直接断开客户端连接
- 用量:每个 turn 的终态用量落库,request_metadata 记录
websocket_mode / websocket_transport,管理端与 usage 视图暴露
is_websocket
- 管理端:provider 可配置 Responses WebSocket 开关
2026-08-17 14:50:33 +08:00
elky
f3a12c1008
fix(ai): preserve Codex image edit validation
2026-08-13 11:31:17 +08:00
elky
8cf381b0c3
feat(codex): add OAuth fingerprint convergence
2026-08-13 09:57:17 +08:00
zhefox
669f4bddc5
fix: align Responses routing and model permissions
2026-08-03 18:48:01 +08:00
ZheFox
84022c4d48
Merge upstream/main into main
2026-07-30 19:40:39 +08:00
ZheFox
118f441029
feat(gateway): persist OpenAI Responses continuation history
2026-07-30 19:26:52 +08:00
elky
050eb77508
fix(ai): harden responses replay and failure diagnostics
2026-07-30 17:19:54 +08:00
zhefox
f8000012f7
fix(ci): stabilize cross-platform workflow checks
2026-07-29 21:55:43 +08:00
elky
4148ab1931
fix(routing): harden routed pool scheduling
2026-07-27 22:06:28 +08:00
elky
531cf11025
feat(gateway): harden provider request execution
...
Preserve exact request payloads and model client surface and API operation explicitly.
Add Anthropic compatibility profiles, bounded stream commitment, and scoped OAuth retry behavior across provider transports.
2026-07-27 09:36:31 +08:00
elky
10d369f59c
feat(providers): add provider transfer limits
2026-07-26 15:06:56 +08:00
MMEXA
5b332da7d7
fix(codex): 补齐缓存身份终态请求头
2026-07-17 08:11:16 +08:00
MMEXA
d9796d502b
fix(codex): 统一通用缓存键与原生会话身份
2026-07-17 06:13:09 +08:00
ZheFox
71fcb9c168
fix(codex): 服务端压缩使用标准 Responses 合约
2026-07-16 12:02:33 +08:00
MMEXA
20b27a13b2
feat(codex): 按操作语义路由 Responses V2 压缩
...
(cherry picked from commit 2fc604e047 )
2026-07-16 00:34:42 +08:00
elky
8616fe6ee2
refactor(workspace): enforce layered crate boundaries
2026-07-15 23:47:19 +08:00
MMEXA
2316df5c9a
feat(codex): align Search and execution protocol
2026-07-12 03:04:15 +08:00
MMEXA
14c4e3a04e
fix(codex): enforce provider request identity
2026-07-11 18:09:14 +08:00
MMEXA
46a903aada
fix(codex): align current reasoning request semantics
2026-07-11 09:15:08 +08:00
MMEXA
dfa121dd5b
feat(openai): align GPT-5.6 and Codex request contracts
2026-07-11 07:40:12 +08:00
elky
bc1da3bf3f
feat(security): harden client IP and admin controls
2026-07-10 15:13:12 +08:00
MMEXA
2122660a5c
对齐原生 Antigravity 控制面与显示模型
2026-07-08 22:34:29 +08:00
MMEXA
f9c8ec41f4
完善 Antigravity 与 Gemini 跨格式兼容
2026-07-08 22:34:29 +08:00
elky
6f00e9fc67
Improve gateway transport and usage runtime
2026-06-25 22:36:27 +08:00
elky
d336d1a7fa
Improve gateway scheduling and runtime admission
2026-06-24 01:53:45 +08:00
elky
f1c30439ff
fix: preserve provider auth metadata
2026-06-20 22:11:42 +08:00
MMEXA
938f11981d
fix(ai-serving): route Antigravity auth enum through facade
2026-06-19 22:25:52 +08:00
MMEXA
6c4e730e60
修复 Antigravity OAuth 配额复检缺 project
2026-06-19 22:21:22 +08:00
ZheFox
302620cb94
Merge branch 'fawney19:main' into main
2026-06-16 12:17:28 +08:00
elky
669636d3e4
Harden PII redaction format conversion
2026-06-14 20:36:57 +08:00
elky
30b545785f
feat: improve failover rules and request timeline
2026-06-11 00:49:29 +08:00
elky
e9b4efc2d4
fix(ai-serving): preserve explicit request encoding
2026-06-10 18:16:55 +08:00
zhefox
04ba8cbe9e
fix(gateway): support openai image accept negotiation
2026-06-08 20:40:30 +08:00
Mas0nShi
1a45ec9386
Fix Gemini CLI streaming policy for OpenAI chat
2026-05-28 15:05:05 +08:00
fawney19
2c28d9979c
Merge commit 'refs/pr/585'
...
# Conflicts:
# apps/aether-gateway/src/ai_serving/planner/passthrough/provider/family/request.rs
# apps/aether-gateway/src/tests/ai_execute/stream_provider_gemini/local_cli.rs
# apps/aether-gateway/src/tests/ai_execute/sync/gemini/cli.rs
# apps/aether-gateway/src/tests/control/admin/provider_query.rs
# crates/aether-provider-transport/src/gemini_cli/mod.rs
# crates/aether-provider-transport/src/gemini_cli/request.rs
# crates/aether-provider-transport/src/gemini_cli/url.rs
# crates/aether-provider-transport/src/lib.rs
2026-05-28 13:19:42 +08:00
Mas0nShi
9ad9858ac2
Merge origin/main into fix/gemini-cli-v1internal
2026-05-28 11:58:00 +08:00
MMEXA
adca142d1e
fix: adapt gemini cli to v1internal endpoint
2026-05-28 00:24:56 +08:00