Skip to content

Fix global flag placement and environment precedence - #382

Merged
saioai merged 25 commits into
mainfrom
codex/global-flags-placement
Oct 8, 2026
Merged

saioai merged 25 commits into
mainfrom
codex/global-flags-placement

Conversation

@saioai

@saioai saioai commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

This addresses three problems in SDK-1186: global flag placement, environment overrides, and completion blocked by request settings.

What changes

  1. Global flag placement: Flags such as --project now work before, between, or after command words. Authentication and organization/project values reach the API request. Webhook settings also inherit.
  2. Environment overrides: An invalid OPENAI_BASE_URL no longer blocks a valid --base-url. Explicit client-certificate and key flags also override their environment defaults, wherever the flags appear.
  3. Completion: Invalid URL or certificate settings no longer block completion-script output. Completion stays local and sends no API request. This complements the dynamic-completion fix already merged in Improve command groups and add task shortcuts #379.

Commands

No new commands or flags. These now send the same project header:

openai --project proj-example models list       # before
openai models --project proj-example list       # between
openai models list --project proj-example       # after

Environment variables still supply defaults. For example, this URL overrides OPENAI_BASE_URL:

openai models list --base-url https://api.example.invalid/v1

An empty --base-url keeps the existing environment fallback.
An empty client-certificate option overrides its environment default; incomplete certificate/key pairs and duplicate certificate/key options still fail.
Flags defined by an individual command keep their local meaning.
For example, an invite’s --project field sets membership without replacing the root project header.

Completion-script output works even when request settings are invalid:

openai @completion bash

Code

pkg/custom makes the five root flags available to subcommands and keeps the root project separate from invite fields.
It also distinguishes explicit client-certificate options from environment defaults.
internal/autocomplete keeps file completion working through the flag wrapper.
main.go uses the explicit URL when the SDK cannot parse the environment URL.
It temporarily replaces that environment value for the command and restores it before error handling or exit.
Helper processes inherit the temporary value; the parent shell stays unchanged.
The runner stays in main.go because release builds compile that file directly. Local help and completion bypass request setup.
Generated commands and dependencies are unchanged.

Tested

On macOS arm64, 36 focused command and cleanup tests passed without skips. Focused restoration race checks also passed.
These cover malformed URLs, all flag positions, empty fallback, preserved environment defaults, privacy, help, and completion.
Cleanup checks cover success, errors, cancellation, panic, child-process inheritance, and repeated runs.

Independent review passed 92 request, streaming, cancellation, and verified client-certificate cases.
The invalid-percent URL regressions fail before this fix and pass afterward.
The corrected CI tests retain malformed-argument, no-write, and no-request checks.
The single-file entrypoint builds locally. Completion-script and manpage generation also pass.

Native Windows/Linux checks and the full mock-server suite were not rerun locally. CI results for the updated commit are pending.

Demo

Real CLI binaries in macOS Bash terminals, using a local mock API.
The output shows the project header that the mock received. Existing --transform=id -r options keep results on one line.
Before is 0eae357, the source merged by #379. After is 250c875.
The recordings show flag placement; automated tests cover the URL and completion fixes.

Global flag placement comparison

Before:

Before: only root placement succeeds

After:

After: all three placements succeed

Recording recipe

@saioai

saioai commented Oct 7, 2026

Copy link
Copy Markdown
Contributor Author

@codex review

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-08T03:39:28.156505Z 04d9379 Manual request
🔒 Security Review ✅ Completed 2026-10-08T03:42:09.477774Z 04d9379 Manual request
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector

Copy link
Copy Markdown

🛡️ Codex Security Review · Automatically triggered

Security review completed. No security issues were found in this pull request.

Reviewed commit: 250c87594e

View security finding report

Only the user who started this review can view the report in Codex.

ℹ️ About Codex security reviews in GitHub

This is an experimental Codex feature. Security reviews are triggered when:

  • You comment "@codex security review"
  • A regular code review gets triggered (for example, "@codex review" or when a PR is opened), and you’re opted in so security review runs alongside code review

Once complete, Codex will leave suggestions, or a comment if no findings are found.

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. Hooray!

Reviewed commit: 250c87594e

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Base automatically changed from codex/command-experience to main October 7, 2026 23:14
@github-actions

github-actions Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

Castiron custom code

Evaluated main: e6d3f50b92af3ae55cab7ff069d10bcfea7b5ecf.

✅ No new custom-code files detected.

2 mixed files remain; 0 existing customizations changed.

Compared e6d3f50b92af → 04d93793c75a. Generated baselines verified.

2 existing customizations unchanged
  • pkg/cmd/adminorganizationcertificate.go
  • pkg/cmd/audiovoice.go

A changed generated baseline means this report cannot reliably identify which handwritten lines changed.

Inspect the custom-code diff

Download the exact patch produced by this run (requires repository access):

gh run download 37722744437 --repo openai/openai-cli \
  --name castiron-custom-code-37722744437-1 --dir /tmp/castiron-custom-code-37722744437-1
git apply --stat /tmp/castiron-custom-code-37722744437-1/custom-code.patch
cat /tmp/castiron-custom-code-37722744437-1/custom-code.patch

Or reproduce it from an SDK checkout containing the vendored reporter:

git fetch --no-tags origin e6d3f50b92af3ae55cab7ff069d10bcfea7b5ecf 04d93793c75a192bca1448a1f52d5b9208544742
python3 scripts/castiron/custom_code_report.py report \
  --base e6d3f50b92af3ae55cab7ff069d10bcfea7b5ecf \
  --head 04d93793c75a192bca1448a1f52d5b9208544742 --fetch --require-head-hash --public \
  --out /tmp/castiron-custom-code-04d93793c75a
cat /tmp/castiron-custom-code-04d93793c75a/custom-code.patch

This is the current full custom patch for mixed files, not an attribution of only the handwritten lines changed by this PR.

Full report and patch

@saioai
saioai marked this pull request as ready for review October 7, 2026 23:39
@saioai
saioai requested a review from a team as a code owner October 7, 2026 23:39

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: c35da86ae3

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread cmd/openai/main.go Outdated
Comment thread cmd/openai/main.go Outdated

@markstuart-oai markstuart-oai left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed c35da86ae3ba07ad5ba7ae63539444ede34b6220. One URL-precedence gap remains; see the inline comment.

The root-flag wrapper, project body/header separation, and mTLS explicit-value handling fit the existing architecture. Completion remains local, and the new demos use the isolated capture harness.

Hosted build, lint, and CodeQL checks pass. The test job still fails the two reported groups: their expectations conflict with the new URL precedence and local completion behavior. Update those cases while retaining the sensitive-error and no-file-write assertions.

This was a source-only review, including the pinned CLI/SDK dependencies and failing CI log. I did not execute repository tests or reproduce the URL case at runtime.

Comment thread cmd/openai/main.go Outdated
@saioai

saioai commented Oct 8, 2026

Copy link
Copy Markdown
Contributor Author

@codex review

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. More of your lovely PRs please.

Reviewed commit: 7027834097

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@chatgpt-codex-connector

Copy link
Copy Markdown

🛡️ Codex Security Review · Automatically triggered

Security review completed. No security issues were found in this pull request.

Reviewed commit: 7027834097

View security finding report

Only the user who started this review can view the report in Codex.

ℹ️ About Codex security reviews in GitHub

This is an experimental Codex feature. Security reviews are triggered when:

  • You comment "@codex security review"
  • A regular code review gets triggered (for example, "@codex review" or when a PR is opened), and you’re opted in so security review runs alongside code review

Once complete, Codex will leave suggestions, or a comment if no findings are found.

@dpiet-oai dpiet-oai left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

One current-head issue remains; see the inline comment.

Comment thread cmd/openai/global_flag_environment_test.go Outdated
@saioai

saioai commented Oct 8, 2026

Copy link
Copy Markdown
Contributor Author

@codex review

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. Hooray!

Reviewed commit: 825ed0c512

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@chatgpt-codex-connector

Copy link
Copy Markdown

🛡️ Codex Security Review · Automatically triggered

Security review completed. No security issues were found in this pull request.

Reviewed commit: 825ed0c512

View security finding report

Only the user who started this review can view the report in Codex.

ℹ️ About Codex security reviews in GitHub

This is an experimental Codex feature. Security reviews are triggered when:

  • You comment "@codex security review"
  • A regular code review gets triggered (for example, "@codex review" or when a PR is opened), and you’re opted in so security review runs alongside code review

Once complete, Codex will leave suggestions, or a comment if no findings are found.

@saioai

saioai commented Oct 8, 2026

Copy link
Copy Markdown
Contributor Author

@codex review

@saioai
saioai requested a review from dpiet-oai October 8, 2026 03:27
@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. 👍

Reviewed commit: 04d93793c7

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@chatgpt-codex-connector

Copy link
Copy Markdown

🛡️ Codex Security Review · Automatically triggered

Security review completed. No security issues were found in this pull request.

Reviewed commit: 04d93793c7

View security finding report

Only the user who started this review can view the report in Codex.

ℹ️ About Codex security reviews in GitHub

This is an experimental Codex feature. Security reviews are triggered when:

  • You comment "@codex security review"
  • A regular code review gets triggered (for example, "@codex review" or when a PR is opened), and you’re opted in so security review runs alongside code review

Once complete, Codex will leave suggestions, or a comment if no findings are found.

@saioai
saioai added this pull request to the merge queue Oct 8, 2026
Merged via the queue into main with commit da762ff Oct 8, 2026
25 checks passed
@saioai
saioai deleted the codex/global-flags-placement branch October 8, 2026 06:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants