Skip to content

fix(ai): accept OpenCodex 2.75 health identity - #6297

Merged
Yeachan-Heo merged 1 commit into
devfrom
gc-6295-ocx-healthz-identity
Oct 3, 2026
Merged

Yeachan-Heo merged 1 commit into
devfrom
gc-6295-ocx-healthz-identity

Conversation

@probepark

@probepark probepark commented Oct 3, 2026 •

Copy link
Copy Markdown
Collaborator

Fixes #6295

What

OpenCodex discovery now accepts the ocx 2.75.0 /healthz identity contract ({"status":"ok","service":"opencodex","version":"2.75.0","port":10100,...}) in addition to the legacy {ok:true, version:"opencodex", port} shape.

  • packages/ai/src/providers/openai-opencodex-responses.ts: HealthPayload gains optional status / service; isOpenCodexHealth() accepts either identity shape and still requires port === expectedPort.
  • packages/ai/test/openai-opencodex-responses.test.ts: 4 new tests in describe("OpenCodex discovery").

Candidate/redirect/loopback resolution, catalog fetch and other providers are unchanged.

Why

ocx 2.75.0 changed the /healthz response to status/service, so discovery rejected a genuine local OpenCodex and the provider disappeared (#6295). The exact-port binding check is kept so an unrelated service on the port is still rejected.

Testing

  • RED first: the new "accepts the ocx 2.75 health contract" test failed on dev before the source change.
  • bun test packages/ai/test/openai-opencodex-responses.test.ts → 15 pass, 0 fail
  • bun --cwd=packages/ai run check → Biome clean, TypeScript OK
  • bun run --workspaces --if-present check:types → rc=0

Acceptance

AC Implementation Local test
AC-1 ocx 2.75 payload on 10100 is discovered; calls = [/healthz, /v1/models] isOpenCodexHealth() status/service branch accepts the ocx 2.75 health contract
AC-2 {status:"ok",service:"other",port} rejected identity requires service === "opencodex" rejects a health response with a foreign service
AC-3 2.75 shape with wrong port rejected identityOk && health.port === expectedPort rejects the ocx 2.75 health contract with a mismatched port
AC-4 {status:"ok"} without service rejected same as AC-2 rejects the status health contract without a service
AC-5 legacy {ok:true, version:"opencodex"} still accepted legacy branch kept existing discovery tests (unchanged, passing)

Needs e2e

None. The change is covered by unit tests with a mocked fetch; CI runs the package tests.

Risk

  • low-risk
  • regression-risk
  • high-risk

Approval

Merge approval is expected to stay red on this agent-authored PR until a maintainer approves the exact head (human-review path, #6037); the contract check itself should be green.

Agent

Implemented by a coding agent (gjc), first attempt, no fallback.

Open questions

  • No changelog fragment added under packages/ai/changelog.d/; happy to add one if this counts as user-facing.

  • Target branch is dev
  • bun check passes (package check + workspace type check)
  • Tested locally
  • Changelog fragment added under packages/<pkg>/changelog.d/ (if user-facing)
  • Human approval or the required agent/owner verdict matches the exact PR head, not an earlier commit
  • Risk classification above matches the actual review path taken

OpenCodex 2.75 reports status and service fields instead of the legacy identity pair. Accept both contracts while retaining exact port validation.
@probepark

Copy link
Copy Markdown
Collaborator Author

e2e (tester)

Head 00007b0, work mac, real loopback socket. No ocx is installed on the mac, so the test used a Bun.serve stub on 127.0.0.1:10100. The port was free before each case and free after the run. OPENCODEX_HOME pointed at an empty dir, which forces the default-port fallback. Each case then ran bun -e 'fetchOpenCodexModels()' in the worktree.

check /healthz payload result
AC-1 2.75 payload discovered {status:"ok",service:"opencodex",version:"2.75.0",port:10100} ✅ pass: 1 model opencodex/provider/model @ http://127.0.0.1:10100/v1
AC-2 foreign service rejected {status:"ok",service:"other",port:10100} ✅ pass: null
AC-3 wrong port rejected {status:"ok",service:"opencodex",port:10101} ✅ pass: null
AC-4 status without service rejected {status:"ok",version:"2.75.0",port:10100} ✅ pass: null
AC-5 legacy still accepted {ok:true,version:"opencodex",port:10100} ✅ pass: 1 model

5 ran, every exit 0. Worktree git status was clean. Unit tests, lint and check were not rerun because CI covers them.
Evidence: https://github.com/probepark/qa-evidence/blob/main/Yeachan-Heo/gajae-code/6297/README.md

Verdict: PASS

@snowykr snowykr left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Verdict

APPROVED

Summary

The PR adds the OpenCodex 2.75 health identity alongside the legacy identity while retaining exact candidate-port validation. Review of the fixed PR head found no verified actionable defects across A1–A5.

Findings / Required Changes

No blocking or actionable findings.

CI / Verification

At reviewed head 00007b054a62314b4ef94fbfee8ad93776f7ab03, PR-triggered CI run 37153568463 reported success, including Affected path validation / test:packages/ai/test/openai-opencodex-responses.test.ts. The new tests cover the alternate identity, foreign or missing service, and mismatched port; existing tests cover the legacy identity. Tests were not rerun locally for this review.

Axis Coverage

Axis Verdict Coverage
A1 — Intent / Policy / Contract APPROVED Adds a strictly matched alternate identity and preserves the legacy shape and exact-port contract; traced provider and status consumers.
A2 — Architecture / Correctness / Failure APPROVED Candidate ordering, timeout, redirect rejection, validation, fallback, and downstream endpoint use remain coherent; no new failure path found.
A3 — Security / Privacy / Trust APPROVED Loopback restrictions, redirect rejection, expected-port binding, and existing local-provider authority are unchanged; no new trust-boundary crossing found.
A4 — Verification / Tests / CI APPROVED Focused tests cover the new identity and rejection cases, and the exact-head PR CI test job passed.
A5 — Context / Compatibility / Platform APPROVED Traced model discovery, status checks, and package exports; no incompatible consumer or materially applicable shared validator found.

Limitations

The external OpenCodex 2.75 health-response producer is not in this repository, so its deployed payload was not independently verified beyond the supplied contract shape and mocked tests. CI job logs and artifact payloads were not independently inspected; the PR-triggered check summary and focused test-job result were available. No intent_projection evidence was available.

@Yeachan-Heo
Yeachan-Heo merged commit a78bd9e into dev Oct 3, 2026
41 checks passed
@Yeachan-Heo

Copy link
Copy Markdown
Owner

Merged into dev as a78bd9eb.

—
[repo owner's gaebal-gajae (clawdbot) 🦞]

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants