Normalize OpenAI provider-prefixed models in api-proxy - #9005
Conversation
Co-authored-by: lpcox <15877973+lpcox@users.noreply.github.com>
Co-authored-by: lpcox <15877973+lpcox@users.noreply.github.com>
Co-authored-by: lpcox <15877973+lpcox@users.noreply.github.com>
There was a problem hiding this comment.
Copilot review overview
🟢 Approval recommended
The normalization and diagnostic persistence are consistent, securely handled, and adequately covered by tests.
Review effort: Balanced
Findings: None
What changed in this PR
Normalizes provider-prefixed model IDs and preserves sanitized upstream error diagnostics for troubleshooting.
Changes:
- Strips redundant provider prefixes across API-proxy providers.
- Stores upstream errors separately with
0600permissions. - Adds regression coverage for normalization and diagnostics.
| File | Description |
|---|---|
containers/api-proxy/body-handler.js |
Applies normalization to writable requests. |
containers/api-proxy/model-resolver.js |
Normalizes models during resolution. |
containers/api-proxy/model-resolver.test.js |
Tests OpenAI direct resolution. |
containers/api-proxy/model-body-rewriter-prefix.test.js |
Tests OpenAI request rewriting. |
containers/api-proxy/upstream-response.js |
Routes upstream errors to dedicated persistence. |
containers/api-proxy/token-persistence.js |
Adds secure upstream-error logging. |
containers/api-proxy/token-tracker.schema.test.js |
Verifies records and permissions. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
|
✅ Copilot review passed with no inline comments. @copilot Add the |
|
@copilot address the review feedback |
Co-authored-by: lpcox <15877973+lpcox@users.noreply.github.com>
|
✅ Smoke Copilot BYOK completed. Copilot BYOK mode operational. 🔓
|
|
Chroot tests passed! Smoke Chroot - All security and functionality tests succeeded.
|
|
🔌 Smoke Services — All services reachable! ✅
|
|
📰 VERDICT: Smoke Copilot has concluded. All systems operational. This is a developing story. 🎤
|
|
✅ Smoke Claude passed Warning Firewall blocked 1 domainThe following domain was blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "api.anthropic.com"See Network Configuration for more information.
|
|
📡 Smoke OTel Tracing completed. All tracing scenarios validated. ✅ Warning Firewall blocked 1 domainThe following domain was blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "o205451.ingest.us.sentry.io"See Network Configuration for more information.
|
|
Smoke Cloud Hypervisor reports failed. Cloud Hypervisor + Copilot failed.
|
|
✅ Build Test Suite completed successfully! Warning Firewall blocked 8 domainsThe following domains were blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "api.nuget.org"
- "bun.sh"
- "dc.services.visualstudio.com"
- "deno.land"
- "dl.deno.land"
- "github.com"
- "releaseassets.githubusercontent.com"
- "repo.maven.apache.org"See Network Configuration for more information.
|
|
🔌 Smoke Services — Service connectivity failed to deliver outputs
|
|
❌ Smoke Copilot BYOK AOAI (api-key) reports failed. AOAI BYOK (api-key) mode investigation needed...
|
|
✅ Smoke Copilot BYOK completed. Copilot BYOK mode operational. 🔓
|
|
✅ Smoke Claude passed Warning Firewall blocked 1 domainThe following domain was blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "api.anthropic.com"See Network Configuration for more information.
|
|
❌ Smoke Gemini reports failed. Facets need polishing... Warning Firewall blocked 1 domainThe following domain was blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "play.googleapis.com"See Network Configuration for more information.
|
|
✨ The prophecy is fulfilled... Smoke Codex has completed its mystical journey. The stars align. 🌟 Warning Firewall blocked 13 domainsThe following domains were blocked by the firewall during workflow execution:
[!TIP] tools:
github:
mode: gh-proxySee GitHub Tools for more information on To allow these domains, add them to the network:
allowed:
- defaults
- "ab.chatgpt.com"
- "accounts.google.com"
- "android.clients.google.com"
- "api.github.com"
- "clients2.google.com"
- "collector.github.com"
- "contentautofill.googleapis.com"
- "github.com"
- "github.githubassets.com"
- "msfeed25.pkgs.visualstudio.com"
- "update.googleapis.com"
- "www.google.com"
- "www.gstatic.com"See Network Configuration for more information.
|
|
📡 Smoke OTel Tracing completed. All tracing scenarios validated. ✅ Warning Firewall blocked 1 domainThe following domain was blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "o205451.ingest.us.sentry.io"See Network Configuration for more information.
|
Smoke Test: Cloud Hypervisor + Copilot
Result: ALL CHECKS PASSED Warning Firewall blocked 2 domainsThe following domains were blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "example.com"
- "github.com"See Network Configuration for more information.
|
|
EGRESS_RESULT allow=pass deny=pass ✅ Allowed domain (github.com) reachable — HTTP 200 Overall status: PASS
Warning Firewall blocked 2 domainsThe following domains were blocked by the firewall during workflow execution:
[!TIP] tools:
github:
mode: gh-proxySee GitHub Tools for more information on To allow these domains, add them to the network:
allowed:
- defaults
- "api.github.com"
- "example.com"See Network Configuration for more information.
|
Smoke Test: Claude Engine Validation
Overall result: PASS Warning Firewall blocked 1 domainThe following domain was blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "api.anthropic.com"See Network Configuration for more information.
|
|
Smoke Test: Copilot Engine —
Overall: PASS
|
Smoke Test: Copilot BYOK (Direct) Mode — PASS ✅
Running in direct BYOK mode with
|
|
Smoke Test: Services Connectivity
Overall: PASS
|
🏗️ Build Test Suite Results
Overall: 8/8 ecosystems passed — PASS ✅ All repositories cloned successfully and all 18 project builds/tests completed without errors. Note: Java initially failed with Warning Firewall blocked 8 domainsThe following domains were blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "api.nuget.org"
- "bun.sh"
- "dc.services.visualstudio.com"
- "deno.land"
- "dl.deno.land"
- "github.com"
- "releaseassets.githubusercontent.com"
- "repo.maven.apache.org"See Network Configuration for more information.
|
Chroot Version Comparison Results
Overall: FAILED — Node.js version mismatch between host and chroot environments (
|
Smoke Test
Warning Firewall blocked 13 domainsThe following domains were blocked by the firewall during workflow execution:
[!TIP] tools:
github:
mode: gh-proxySee GitHub Tools for more information on To allow these domains, add them to the network:
allowed:
- defaults
- "ab.chatgpt.com"
- "accounts.google.com"
- "android.clients.google.com"
- "api.github.com"
- "clients2.google.com"
- "collector.github.com"
- "contentautofill.googleapis.com"
- "github.com"
- "github.githubassets.com"
- "msfeed25.pkgs.visualstudio.com"
- "update.googleapis.com"
- "www.google.com"
- "www.gstatic.com"See Network Configuration for more information.
|
📡 OTel Tracing Smoke Test Results
Summary: All core OTEL integration points (module, tests, env wiring, token-tracker hook) validated successfully. No span export observed this run, consistent with no active OTLP collector traffic — not a regression. Warning Firewall blocked 1 domainThe following domain was blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "o205451.ingest.us.sentry.io"See Network Configuration for more information.
|
…o all providers PR #9005 extended the redundant <provider>/ model-prefix strip (stripRedundantModelPrefixInBody / stripRedundantProviderPrefix) from Copilot-only to every provider route, so an OpenAI-bound LiteLLM-style openai/gpt-6-sol model ID is normalized before forwarding. Prior docs described this normalization as Copilot-specific. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
…ed in PR #9005 (#9062) * docs: document that redundant provider-prefix stripping now applies to all providers PR #9005 extended the redundant <provider>/ model-prefix strip (stripRedundantModelPrefixInBody / stripRedundantProviderPrefix) from Copilot-only to every provider route, so an OpenAI-bound LiteLLM-style openai/gpt-6-sol model ID is normalized before forwarding. Prior docs described this normalization as Copilot-specific. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * docs: address provider prefix review feedback Co-authored-by: lpcox <15877973+lpcox@users.noreply.github.com> --------- Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com> Co-authored-by: lpcox <15877973+lpcox@users.noreply.github.com>
Pi sends OpenAI Responses requests with LiteLLM-style model IDs such as
openai/gpt-6-sol; the proxy only stripped redundant provider prefixes for Copilot, causing OpenAI to receive an invalid model name and return opaque 400s. Upstream error bodies also were not reliably preserved in artifacts for postmortem debugging.<provider>/stripping for all api-proxy providers, including OpenAI.Upstream error diagnostics
api-proxy-logs/upstream-errors.jsonl.0600records.Regression coverage