Skip to content

fix(proxy): preserve terminal service-tier provenance - #18

Merged
ericjuta merged 1 commit into
mainfrom
fix/terminal-service-tier-provenance
Sep 14, 2026
Merged

ericjuta merged 1 commit into
mainfrom
fix/terminal-service-tier-provenance

Conversation

@ericjuta

@ericjuta ericjuta commented Sep 14, 2026 •

Copy link
Copy Markdown
Owner

Summary

Preserve the final upstream terminal service tier through continuation folding, and distinguish successful terminal evidence from billing fallback in request logs and mismatch counters.

This fixes reporting provenance. It does not change requested tiers, reasoning effort, transport, continuation limits, or historical rows, and does not claim improved latency or guaranteed Fast delivery.

Type of change

  • fix: — bug fix

OpenSpec

  • Includes an OpenSpec change and synchronized normative specs/context.
  • Preserves upstream terminal field presence and values on the codex-faithful response path.

Change directory: openspec/changes/fix-terminal-service-tier-provenance/

Archival and deployment tasks remain open until the release evidence exists.

Changes

  • Keep explicit final terminal tiers, including omission, instead of copying the first created-event tier.
  • Record actual_service_tier only from explicit successful terminal evidence across direct streaming, native WebSocket, and the HTTP bridge.
  • Keep effective billable-tier fallback independent; count mismatches only for successful requests with actual evidence. Preserve existing counter coverage and bounded labels.
  • Cover conflicting, missing, failed, interrupted, and folded terminal cases through runtime and request-log regressions.
  • Repair inherited gate failures without changing routing policy: narrow JSON/mock typing, remove replica-salted ambiguity from a sticky-budget fixture while retaining its counterexample, restore the invalidation-poller singleton between tests, correct a stale multipart route expectation, and apply existing formatting/spec wrapping conventions.
  • Upgrade perl-base through the existing runtime security-upgrade list to clear three fixable critical base-image CVEs.

Test plan

Validation used isolated source copies and disposable data, without production credentials or model benchmarks.

Check Result
Actual folding API, synthetic upstream events 5 cases passed; requested priority retained
Final unit suite, including Helm rendering 4,706 passed, 3 existing skips
Integration core 1,357 passed, 7 PostgreSQL-only skips
HTTP bridge / native WebSocket integration 188 passed
End-to-end SDK compatibility 27 passed
Disposable PostgreSQL matrix 84 passed
SQLite / PostgreSQL migration policy Both passed
Frontend lint, typecheck, build, tests Passed; 832 tests in 123 files
Ruff / format / ty Passed; 838 Python files formatted
Strict OpenSpec validation 39 specs and this change passed
Wheel build and packaged frontend assets Passed
Docker build and fixable-critical vulnerability gate Passed
Helm lint/template/schema checks Passed; 18 resources valid at Kubernetes 1.32 and 1.35
Bundled / external-DB kind application smokes Both passed
Local read-only flow and security reviews, including gate follow-up No findings

The initial full gate and first parallel unit attempt failed. Those failures are preserved in private validation evidence; the affected checks were rerun after fixing test isolation, fixture determinism, isolated tool discovery, and the base-image vulnerability. This table reports the resulting checks, not a fabricated all-green first invocation.

Checklist

  • Conventional Commits title.
  • Regression coverage for changed public behavior.
  • Required local validation and independent source review completed.
  • OpenSpec synchronized and strictly validated.
  • CHANGELOG left to release-please.
  • Current-head GitHub CI and @codex review clean before merge.

Keep successful terminal tier evidence separate from accounting fallback across continuation, HTTP, and WebSocket settlement. Stabilize inherited validation fixtures and upgrade the existing runtime perl-base package to clear fixed critical vulnerabilities.
@chatgpt-codex-connector

Copy link
Copy Markdown

To use Codex here, create an environment for this repo.

@ericjuta

Copy link
Copy Markdown
Owner Author

@codex review

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 14, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-14T23:03:24.887894Z 649d732 Manual request
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. Nice work!

Reviewed commit: 649d73258e

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@ericjuta
ericjuta merged commit d3475cc into main Sep 14, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant