AAEE86
dc3743aecf
refactor(ws): 拆分 LogicalTurn 与 ProviderAttempt,结算改表驱动
...
评审第 5 条:一个 ResponsesWebSocketTurn 同时代表 logical turn 和 provider
attempt,finalize() 又用 outcome.cancelled() 一个布尔驱动 billing、candidate
状态和供应商效果,于是 provider 终态已经到达、只是最后一跳写客户端失败时,
供应商事实会被 Cancelled 覆盖掉。
- ResponsesWebSocketTurn → ResponsesProviderAttempt,
ActiveResponsesWebSocketTurn → ActiveProviderAttempt:类型名字明确它只代表
一次上游执行,logical turn 由 C1 落地的 LogicalTurn 承担。
- 新增 settlement.rs:AttemptProviderOutcome × AttemptClientDelivery 两个正交
事实,classify_attempt_settlement 一张表推出 status_code / billing /
candidate 状态 / candidate 错误分类 / 供应商效果 / 是否提交 execution report。
- attempt 观察到 provider 终态即记录 provider_outcome。结算信号
ResponsesWebSocketTurnOutcome 只回答「为什么现在结算」:ProviderTerminal 与
Failure 对 provider 是权威的,Cancelled 只描述客户端/连接层面的停止,不再
覆盖已观察到的 provider 事实。
- candidate 状态与 candidate 错误分类分开输出:现状存在
「missing_terminal=true 而记账层判 Success」的组合(report kind 不要求观察到
终态事件时),会写出 status=Success + error_type=stream_missing_terminal_event,
这个组合必须原样保留。
classify_responses_websocket_turn_effect 的判定表原样搬入 settlement.rs,分支
和顺序均未改动,两个既有不变量测试随之迁移。
行为等价。结算表当前口径与拆分前完全一致:客户端投递失败仍与「供应商声明取消」
落在同一侧(作废账单、candidate 记 Cancelled、只释放 lease、不提交 execution
report),即使 provider 终态已经到达——这一行由
settlement_table_row_client_delivery_failure_currently_voids_a_reached_terminal
锁住现状,修正它是下一步独立的行为修正。
新增 15 个测试:outcome → 双事实映射表逐行(含 stream_timeout 只在 504 失败一族
成立、provider 终态即使 504 也不投射流式超时)、结算表逐行、投递失败时
forced_error 必须为 None、已观察终态不被 Cancelled 覆盖、以及跨整张表的
「每个分支都释放 pool key lease」「作废账单一律不提交 report」不变量。
2026-08-17 14:53:05 +08:00
AAEE86
1c5ee5228c
refactor(ws): 用 ResponsesTurnState 收敛连接 turn 状态
...
评审第 2 条:BoundResponsesConnection 用 response_in_flight、active_turn、
active_response_create 三个可独立变化的字段编码同一件事,8 种组合里只有 3 种
合法,非法组合只能靠调用点的 if 和「记得同时改另外两个字段」来避免。
三字段合并为一个 ResponsesTurnState:
Idle 没有进行中的 logical turn
Responding { logical, attempt } logical 与 attempt 必须同时存在
Replanning { logical } attempt 已取走去结算/重绑,logical 仍在
Replanning 不是新概念:配额透明重试期间现状就处于这个状态,只是靠
Option::take 意外得到。转换只能走 begin / detach_attempt / resume / end,
response_in_flight 与「是否接受新 response.create」都由变体推导。
由此消除的运行时不变量(原来全靠调用点自觉):
- 有 attempt 必有 logical turn
- response_in_flight 与 attempt 同生共死(原来 client 写失败后
active_turn=None 而 response_in_flight 仍为 true)
- logical turn 结束时必须清 attempt:原来 `active_response_create = None`
在 connection.rs 里手写 13 处,漏一处就残留;现在只有 end() 一个出口
- 上游绑定返回的连接不再自带 response_in_flight=true 的半成品状态
同时删除 update_response_in_flight:Started 帧把已经是 true 的字段再设一次,
Close 帧因为没有解析出的 frame 而根本不触发,是纯冗余写;它在 Idle 态收到
Started 帧时还会把 response_in_flight 置真,从而永久阻塞后续 response.create。
行为等价。ActiveResponsesWebSocketRequest 改名 LogicalTurn 并随状态机移入
新的 turn_state.rs;状态机对 attempt 类型泛型化,测试用轻量替身驱动同一套
转换逻辑,无需 AppState 或真实 socket。
2026-08-17 14:52:57 +08:00
AAEE86
9d80281b53
fix(ws): route WS planning and continuation through PII redaction
2026-08-17 14:52:49 +08:00
AAEE86
3b036299d4
fix(ws): enforce absolute upstream handshake and initial-message deadlines
2026-08-17 14:52:39 +08:00
AAEE86
f70ae68273
fix(ws): treat max_output_tokens incomplete as legitimate terminal
2026-08-17 14:52:33 +08:00
AAEE86
a498875591
feat(gateway): Responses WebSocket 连通性探针
...
新增 aether-codex-ws-probe 与 aether-openai-responses-ws-probe 两个
二进制,用于在不暴露凭据的前提下验证上游 WebSocket 端点可用性:凭据
只从环境变量读取,不写入日志。公共流程放在
bin/support/responses_ws_probe.rs,各 profile 只负责自己的鉴权与
请求头要求。
2026-08-17 14:51:18 +08:00
AAEE86
71b54070e8
feat(gateway): Codex/OpenAI Responses WebSocket 代理模式
...
在 /v1/responses 上支持 WebSocket 升级,把客户端帧中继到上游 Codex /
OpenAI Responses WebSocket 端点,同时保持既有的路由、鉴权、配额与用量
语义:
- 路由与准入:control/route/ai.rs 识别 WebSocket 升级请求;
websocket/ingress.rs 复用 API Key 鉴权、IP 规则与并发许可,并引入
独立的 WebSocket 连接许可
- 中继:websocket/responses/* 按 connection / session / turn 分层,
帧解析归一化、socket 写入有界、continuation 保持调度亲和性
- 配额:orchestration/codex_quota_breaker.rs 在账号配额耗尽时熔断并
自动恢复,不再直接断开客户端连接
- 用量:每个 turn 的终态用量落库,request_metadata 记录
websocket_mode / websocket_transport,管理端与 usage 视图暴露
is_websocket
- 管理端:provider 可配置 Responses WebSocket 开关
2026-08-17 14:50:33 +08:00
ZheFox
32944538e9
fix(gateway): stop candidate persistence retry storms
2026-08-17 13:49:12 +08:00
ZheFox
b13d9b9b40
fix(codex): restore upstream model discovery
2026-08-15 19:36:28 +08:00
zhefox
810c3dfe2b
fix(codex): serve versioned dynamic model catalogs
2026-08-14 18:41:44 +08:00
elky
5b0c763086
fix(codex): fence concurrent quota updates
2026-08-14 09:28:07 +08:00
elky
f3a12c1008
fix(ai): preserve Codex image edit validation
2026-08-13 11:31:17 +08:00
elky
8cf381b0c3
feat(codex): add OAuth fingerprint convergence
2026-08-13 09:57:17 +08:00
elky
edb8362adc
fix(provider): omit default model test temperature
2026-08-12 16:56:18 +08:00
elky
29fa4aed19
perf(gateway): raise default server pool floor
2026-08-12 16:56:18 +08:00
zhefox
985ff3c36a
test(gateway): align claude_code endpoint reconciliation
2026-08-05 14:34:20 +08:00
zhefox
4d67569873
fix(gateway): support claude_code cross-format Claude messages
2026-08-05 13:57:20 +08:00
zhefox
669f4bddc5
fix: align Responses routing and model permissions
2026-08-03 18:48:01 +08:00
elky
06f5d3c8c0
fix(gateway): complete worker registration cleanup
2026-07-31 11:32:07 +08:00
elky
082407fa51
Merge PR #697 : prevent duplicate worker registrations
2026-07-31 11:11:14 +08:00
fawney19
6688ee26db
Merge pull request #702 from MMEXA/fix/reconcile-auth-channel-mismatch-formats
...
fix(gateway): 修复批量更新 API 格式时的认证通道状态冲突
2026-07-31 10:28:37 +08:00
elky
beb003b7ad
feat(models): add external catalog proxy selection
2026-07-31 09:32:25 +08:00
MMEXA
6ecfe0f0a1
fix(gateway): reconcile auth mismatch formats on key update
2026-07-30 22:14:08 +08:00
ZheFox
ff47d8d48a
fix(gateway): route response history through ai seam
2026-07-30 20:34:41 +08:00
ZheFox
84022c4d48
Merge upstream/main into main
2026-07-30 19:40:39 +08:00
ZheFox
118f441029
feat(gateway): persist OpenAI Responses continuation history
2026-07-30 19:26:52 +08:00
elky
20399b004d
Merge PR #700 : fix admin pool batch update body buffering
...
Preserve main's failover and usage metadata fixes, restore default tunnel regression coverage, and satisfy current Clippy.
2026-07-30 17:56:37 +08:00
elky
050eb77508
fix(ai): harden responses replay and failure diagnostics
2026-07-30 17:19:54 +08:00
elky
1ab4f079c9
fix(gateway): restore failover and usage diagnostics
2026-07-30 09:12:11 +08:00
MMEXA
d7d8db45ba
test(gateway): align tunnel error fixture with failover policy
2026-07-30 06:44:59 +08:00
MMEXA
e55793c765
fix(ci): satisfy gateway clippy on upstream baseline
2026-07-30 05:14:34 +08:00
MMEXA
d8902ea612
fix(gateway): buffer admin pool batch update bodies
2026-07-30 05:14:34 +08:00
elky
a04673a90d
feat(gateway): harden failover and payload handling
...
Retry pre-response transport failures across candidates with an explicit stop policy, and propagate end-to-end timing into usage records and UI diagnostics.
Remove legacy body, import, cookie, PII, and tunnel replay caps while preserving optional operator-configured gateway limits.
2026-07-30 01:03:27 +08:00
zhefox
f8000012f7
fix(ci): stabilize cross-platform workflow checks
2026-07-29 21:55:43 +08:00
worker-2
6080f8cc88
fix(gateway): stabilize worker task records
...
Key worker boot records by task so process restarts update the existing
row instead of registering another row for each gateway instance.
Closes #693
Confidence: high
Scope-risk: narrow
2026-07-29 17:27:51 +08:00
ZheFox
9d9316e434
Merge branch 'fawney19:main' into main
2026-07-28 13:56:34 +08:00
ZheFox
1b697b1111
feat(providers): support FedRAMP Codex agent identity registration
2026-07-28 13:29:30 +08:00
ZheFox
f0f87b56a3
feat(providers): add credential-fenced OAuth key cleanup
2026-07-28 11:32:11 +08:00
elky
4148ab1931
fix(routing): harden routed pool scheduling
2026-07-27 22:06:28 +08:00
elky
550cc36760
feat(providers): expand OAuth account management
...
Add Claude Code manual and cookie authorization, including redacted batch tasks. Harden OAuth imports, duplicate replacement, provider dialogs, and related account-management tests.
2026-07-27 15:53:28 +08:00
elky
531cf11025
feat(gateway): harden provider request execution
...
Preserve exact request payloads and model client surface and API operation explicitly.
Add Anthropic compatibility profiles, bounded stream commitment, and scoped OAuth retry behavior across provider transports.
2026-07-27 09:36:31 +08:00
elky
10d369f59c
feat(providers): add provider transfer limits
2026-07-26 15:06:56 +08:00
elky
778cfb1a5c
feat(data): complete portable SQL backend parity
...
Align MySQL and SQLite schemas, migrations, usage, stats, export, and backfill behavior with the shared data contracts. Extend gateway startup and maintenance support across all SQL drivers.
2026-07-25 21:28:21 +08:00
ZheFox
ec36cfbf75
Merge pull request #690 from zhefox/main
...
fix(provider): classify deleted Codex agent runtime as invalid
2026-07-23 11:22:30 +08:00
ZheFox
7bf228a33c
fix(provider): classify deleted Codex agent runtime as invalid
2026-07-23 11:21:55 +08:00
elky
3606290ac8
fix(provider): harden Agent Identity OAuth lifecycle
2026-07-23 09:33:00 +08:00
elky
fdbc2607ec
feat(provider): add dedicated Codex Agent Identity flow
2026-07-22 20:19:29 +08:00
elky
856605defa
fix(model-directives): harden suffix configuration
2026-07-22 14:19:09 +08:00
elky
713010fa0a
fix(gateway): restore auth role refresh and Rust checks
...
Refresh the resolved user role without bypassing owner group and key policies. Resolve Rust 1.95 Clippy failures and make the pending persistence bound test scheduler-independent.
2026-07-22 11:25:24 +08:00
ZheFox
cd2fbeeead
Merge pull request #689 from AAEE86/feat/agent-identity-support
...
feat(codex): enroll agent identity from session token
2026-07-22 10:32:06 +08:00