Repository navigation
fix(ai): accept OpenCodex 2.75 health identity - #6297
Conversation
OpenCodex 2.75 reports status and service fields instead of the legacy identity pair. Accept both contracts while retaining exact port validation.
e2e (tester)Head
5 ran, every exit 0. Worktree Verdict: PASS |
snowykr
left a comment
There was a problem hiding this comment.
Verdict
APPROVED
Summary
The PR adds the OpenCodex 2.75 health identity alongside the legacy identity while retaining exact candidate-port validation. Review of the fixed PR head found no verified actionable defects across A1–A5.
Findings / Required Changes
No blocking or actionable findings.
CI / Verification
At reviewed head 00007b054a62314b4ef94fbfee8ad93776f7ab03, PR-triggered CI run 37153568463 reported success, including Affected path validation / test:packages/ai/test/openai-opencodex-responses.test.ts. The new tests cover the alternate identity, foreign or missing service, and mismatched port; existing tests cover the legacy identity. Tests were not rerun locally for this review.
Axis Coverage
| Axis | Verdict | Coverage |
|---|---|---|
| A1 — Intent / Policy / Contract | APPROVED |
Adds a strictly matched alternate identity and preserves the legacy shape and exact-port contract; traced provider and status consumers. |
| A2 — Architecture / Correctness / Failure | APPROVED |
Candidate ordering, timeout, redirect rejection, validation, fallback, and downstream endpoint use remain coherent; no new failure path found. |
| A3 — Security / Privacy / Trust | APPROVED |
Loopback restrictions, redirect rejection, expected-port binding, and existing local-provider authority are unchanged; no new trust-boundary crossing found. |
| A4 — Verification / Tests / CI | APPROVED |
Focused tests cover the new identity and rejection cases, and the exact-head PR CI test job passed. |
| A5 — Context / Compatibility / Platform | APPROVED |
Traced model discovery, status checks, and package exports; no incompatible consumer or materially applicable shared validator found. |
Limitations
The external OpenCodex 2.75 health-response producer is not in this repository, so its deployed payload was not independently verified beyond the supplied contract shape and mocked tests. CI job logs and artifact payloads were not independently inspected; the PR-triggered check summary and focused test-job result were available. No intent_projection evidence was available.
|
Merged into dev as
— |
Fixes #6295
What
OpenCodex discovery now accepts the ocx 2.75.0
/healthzidentity contract ({"status":"ok","service":"opencodex","version":"2.75.0","port":10100,...}) in addition to the legacy{ok:true, version:"opencodex", port}shape.packages/ai/src/providers/openai-opencodex-responses.ts:HealthPayloadgains optionalstatus/service;isOpenCodexHealth()accepts either identity shape and still requiresport === expectedPort.packages/ai/test/openai-opencodex-responses.test.ts: 4 new tests indescribe("OpenCodex discovery").Candidate/redirect/loopback resolution, catalog fetch and other providers are unchanged.
Why
ocx 2.75.0 changed the
/healthzresponse tostatus/service, so discovery rejected a genuine local OpenCodex and the provider disappeared (#6295). The exact-port binding check is kept so an unrelated service on the port is still rejected.Testing
devbefore the source change.bun test packages/ai/test/openai-opencodex-responses.test.ts→ 15 pass, 0 failbun --cwd=packages/ai run check→ Biome clean, TypeScript OKbun run --workspaces --if-present check:types→ rc=0Acceptance
isOpenCodexHealth()status/service branchaccepts the ocx 2.75 health contract{status:"ok",service:"other",port}rejectedservice === "opencodex"rejects a health response with a foreign serviceidentityOk && health.port === expectedPortrejects the ocx 2.75 health contract with a mismatched port{status:"ok"}without service rejectedrejects the status health contract without a service{ok:true, version:"opencodex"}still acceptedNeeds e2e
None. The change is covered by unit tests with a mocked fetch; CI runs the package tests.
Risk
low-riskregression-riskhigh-riskApproval
Agent
Implemented by a coding agent (gjc), first attempt, no fallback.
Open questions
packages/ai/changelog.d/; happy to add one if this counts as user-facing.devbun checkpasses (package check + workspace type check)packages/<pkg>/changelog.d/(if user-facing)