Skip to content

Normalize OpenAI provider-prefixed models in api-proxy - #9005

Merged
lpcox merged 9 commits into
mainfrom
copilot/fix-api-proxy-gpt-6-errors
Sep 26, 2026
Merged

lpcox merged 9 commits into
mainfrom
copilot/fix-api-proxy-gpt-6-errors

Conversation

Copilot AI commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

Pi sends OpenAI Responses requests with LiteLLM-style model IDs such as openai/gpt-6-sol; the proxy only stripped redundant provider prefixes for Copilot, causing OpenAI to receive an invalid model name and return opaque 400s. Upstream error bodies also were not reliably preserved in artifacts for postmortem debugging.

  • Model normalization
    • Apply redundant <provider>/ stripping for all api-proxy providers, including OpenAI.
    • Keep alias resolution and direct request normalization consistent.
// inbound
{ "model": "openai/gpt-6-sol", "stream": true }

// forwarded upstream
{ "model": "gpt-6-sol", "stream": true }
  • Upstream error diagnostics

    • Persist sanitized upstream error-response diagnostics to api-proxy-logs/upstream-errors.jsonl.
    • Store payload-bearing diagnostics as owner-only 0600 records.
    • Avoid duplicating large error payloads in the token tracker audit log.
  • Regression coverage

    • Added coverage for OpenAI provider-prefix stripping.
    • Added coverage for upstream error diagnostic file creation and permissions.

Copilot AI and others added 3 commits September 25, 2026 15:16
Co-authored-by: lpcox <15877973+lpcox@users.noreply.github.com>
Co-authored-by: lpcox <15877973+lpcox@users.noreply.github.com>
Co-authored-by: lpcox <15877973+lpcox@users.noreply.github.com>
Copilot AI changed the title [WIP] Fix API proxy errors for gpt-6-sol and gpt-6-luna Normalize OpenAI provider-prefixed models in api-proxy Sep 25, 2026
Copilot AI requested a review from lpcox September 25, 2026 15:22
@lpcox
lpcox marked this pull request as ready for review September 25, 2026 15:43
Copilot AI balanced review requested due to automatic review settings September 25, 2026 15:43

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The normalization and diagnostic persistence are consistent, securely handled, and adequately covered by tests.

Review effort: Balanced
Findings: None

What changed in this PR

Normalizes provider-prefixed model IDs and preserves sanitized upstream error diagnostics for troubleshooting.

Changes:

  • Strips redundant provider prefixes across API-proxy providers.
  • Stores upstream errors separately with 0600 permissions.
  • Adds regression coverage for normalization and diagnostics.
File Description
containers/​api-proxy/​body-handler.js Applies normalization to writable requests.
containers/​api-proxy/​model-resolver.js Normalizes models during resolution.
containers/​api-proxy/​model-resolver.test.js Tests OpenAI direct resolution.
containers/​api-proxy/​model-body-rewriter-prefix.test.js Tests OpenAI request rewriting.
containers/​api-proxy/​upstream-response.js Routes upstream errors to dedicated persistence.
containers/​api-proxy/​token-persistence.js Adds secure upstream-error logging.
containers/​api-proxy/​token-tracker.schema.test.js Verifies records and permissions.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@github-actions

Copy link
Copy Markdown
Contributor

✅ Copilot review passed with no inline comments.

@copilot Add the ready-for-aw label to this PR to trigger agentic CI smoke tests.

Comment thread containers/api-proxy/token-tracker.schema.test.js Fixed
@lpcox

lpcox commented Sep 25, 2026

Copy link
Copy Markdown
Collaborator

@copilot address the review feedback

Co-authored-by: lpcox <15877973+lpcox@users.noreply.github.com>

Copilot AI commented Sep 25, 2026

Copy link
Copy Markdown
Contributor Author

@copilot address the review feedback

Addressed in 4a54f1b. The permission assertion and JSONL read now use the same open file descriptor, eliminating the path-based check/read race.

@github-actions

github-actions Bot commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

✅ Smoke Copilot BYOK completed. Copilot BYOK mode operational. 🔓

🔑 BYOK report filed by Smoke Copilot BYOK

@github-actions

github-actions Bot commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

Chroot tests passed! Smoke Chroot - All security and functionality tests succeeded.

Tested by Smoke Chroot

@github-actions

github-actions Bot commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

🔌 Smoke Services — All services reachable! ✅

🔌 Service connectivity validated by Smoke Services

@github-actions

github-actions Bot commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

📰 VERDICT: Smoke Copilot has concluded. All systems operational. This is a developing story. 🎤

📰 BREAKING: Report filed by Smoke Copilot

@github-actions

github-actions Bot commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

✅ Smoke Claude passed

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • api.anthropic.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "api.anthropic.com"

See Network Configuration for more information.

Generated by Smoke Claude for #9005

@github-actions

github-actions Bot commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

📡 Smoke OTel Tracing completed. All tracing scenarios validated. ✅

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • o205451.ingest.us.sentry.io

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "o205451.ingest.us.sentry.io"

See Network Configuration for more information.

📡 OTel tracing validated by Smoke OTel Tracing

@github-actions

github-actions Bot commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

Smoke Cloud Hypervisor reports failed. Cloud Hypervisor + Copilot failed.

Cloud Hypervisor + Copilot smoke test by Smoke Cloud Hypervisor

@github-actions

github-actions Bot commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

✅ Build Test Suite completed successfully!

Warning

Firewall blocked 8 domains

The following domains were blocked by the firewall during workflow execution:

  • api.nuget.org
  • bun.sh
  • dc.services.visualstudio.com
  • deno.land
  • dl.deno.land
  • github.com
  • releaseassets.githubusercontent.com
  • repo.maven.apache.org

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "api.nuget.org"
    - "bun.sh"
    - "dc.services.visualstudio.com"
    - "deno.land"
    - "dl.deno.land"
    - "github.com"
    - "releaseassets.githubusercontent.com"
    - "repo.maven.apache.org"

See Network Configuration for more information.

Generated by Build Test Suite for #9005

@github-actions

github-actions Bot commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

🔌 Smoke Services — Service connectivity failed to deliver outputs ⚠️

🔌 Service connectivity validated by Smoke Services

@github-actions

github-actions Bot commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

❌ Smoke Copilot BYOK AOAI (api-key) reports failed. AOAI BYOK (api-key) mode investigation needed...

🔑 BYOK (AOAI api-key) report filed by Smoke Copilot BYOK AOAI (api-key)

@github-actions

github-actions Bot commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

✅ Smoke Copilot BYOK completed. Copilot BYOK mode operational. 🔓

🔑 BYOK report filed by Smoke Copilot BYOK

@github-actions

github-actions Bot commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

✅ Smoke Claude passed

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • api.anthropic.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "api.anthropic.com"

See Network Configuration for more information.

Generated by Smoke Claude for #9005

@github-actions

github-actions Bot commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

❌ Smoke Gemini reports failed. Facets need polishing...

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • play.googleapis.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "play.googleapis.com"

See Network Configuration for more information.

💎 Faceted by Smoke Gemini

@github-actions

github-actions Bot commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

✨ The prophecy is fulfilled... Smoke Codex has completed its mystical journey. The stars align. 🌟

Warning

Firewall blocked 13 domains

The following domains were blocked by the firewall during workflow execution:

  • ab.chatgpt.com
  • accounts.google.com
  • android.clients.google.com
  • api.github.com
  • clients2.google.com
  • collector.github.com
  • contentautofill.googleapis.com
  • github.com
  • github.githubassets.com
  • msfeed25.pkgs.visualstudio.com
  • update.googleapis.com
  • www.google.com
  • www.gstatic.com

[!TIP]
api.github.com is blocked because GitHub API access uses the built-in GitHub tools by default. Instead of adding api.github.com to network.allowed, use tools.github.mode: gh-proxy for direct pre-authenticated GitHub CLI access without requiring network access to api.github.com:

tools:
  github:
    mode: gh-proxy

See GitHub Tools for more information on gh-proxy mode.

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "ab.chatgpt.com"
    - "accounts.google.com"
    - "android.clients.google.com"
    - "api.github.com"
    - "clients2.google.com"
    - "collector.github.com"
    - "contentautofill.googleapis.com"
    - "github.com"
    - "github.githubassets.com"
    - "msfeed25.pkgs.visualstudio.com"
    - "update.googleapis.com"
    - "www.google.com"
    - "www.gstatic.com"

See Network Configuration for more information.

🔮 The oracle has spoken through Smoke Codex

@github-actions

github-actions Bot commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

📡 Smoke OTel Tracing completed. All tracing scenarios validated. ✅

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • o205451.ingest.us.sentry.io

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "o205451.ingest.us.sentry.io"

See Network Configuration for more information.

📡 OTel tracing validated by Smoke OTel Tracing

@github-actions

Copy link
Copy Markdown
Contributor

Smoke Test: Cloud Hypervisor + Copilot

  1. list_pull_requests (github/gh-aw-firewall): PASS
  2. curl https://github.com → 200: PASS
  3. Write/read /tmp/gh-aw/agent/smoke-cloud-hypervisor-...txt: PASS
  4. curl (example.com/redacted) blocked → 000: PASS

Result: ALL CHECKS PASSED

Warning

Firewall blocked 2 domains

The following domains were blocked by the firewall during workflow execution:

  • example.com
  • github.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "example.com"
    - "github.com"

See Network Configuration for more information.

Cloud Hypervisor + Copilot smoke test by Smoke Cloud Hypervisor
Add label ready-for-aw to run again

@github-actions

Copy link
Copy Markdown
Contributor

EGRESS_RESULT allow=pass deny=pass

✅ Allowed domain (github.com) reachable — HTTP 200
✅ Blocked domain (example.com) denied — SSL/connection error

Overall status: PASS

@lpcox network isolation egress enforcement working as expected.

Warning

Firewall blocked 2 domains

The following domains were blocked by the firewall during workflow execution:

  • api.github.com
  • example.com

[!TIP]
api.github.com is blocked because GitHub API access uses the built-in GitHub tools by default. Instead of adding api.github.com to network.allowed, use tools.github.mode: gh-proxy for direct pre-authenticated GitHub CLI access without requiring network access to api.github.com:

tools:
  github:
    mode: gh-proxy

See GitHub Tools for more information on gh-proxy mode.

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "api.github.com"
    - "example.com"

See Network Configuration for more information.

🛡️ Egress verdict from Smoke Copilot Network Isolation
Add label ready-for-aw to run again

@github-actions

Copy link
Copy Markdown
Contributor

Smoke Test: Claude Engine Validation

Check Status
API ✅ PASS
gh CLI ✅ PASS
File access ✅ PASS

Overall result: PASS

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • api.anthropic.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "api.anthropic.com"

See Network Configuration for more information.

Generated by Smoke Claude for #9005 · claude · haiku45 · 56.4 AIC · ⊞ 4.7K · ◷
Add label ready-for-aw to run again

@github-actions

Copy link
Copy Markdown
Contributor

Smoke Test: Copilot Engine — @lpcox

Overall: PASS

📰 BREAKING: Report filed by Smoke Copilot
Add label ready-for-aw to run again

@github-actions

Copy link
Copy Markdown
Contributor

Smoke Test: Copilot BYOK (Direct) Mode — PASS ✅

Test Result
GitHub MCP connectivity ✅ 2 merged PRs
GitHub.com HTTP ✅ 200
File write/read ✅ Confirmed
BYOK inference (agent → api-proxy → api.githubcopilot.com) ✅ Active

Running in direct BYOK mode with COPILOT_PROVIDER_API_KEY forwarded to api-proxy sidecar. Agent inference path verified.

🔑 BYOK report filed by Smoke Copilot BYOK
Add label ready-for-aw to run again

@lpcox
lpcox deployed to aoai-model September 25, 2026 23:50 — with GitHub Actions Active
@github-actions

Copy link
Copy Markdown
Contributor

Smoke Test: Services Connectivity

  • Redis PING: ✅ (PONG)
  • Postgres pg_isready: ✅ (accepting connections)
  • Postgres SELECT 1: ✅ (1)

Overall: PASS

🔌 Service connectivity validated by Smoke Services
Add label ready-for-aw to run again

@github-actions

Copy link
Copy Markdown
Contributor

🏗️ Build Test Suite Results

Ecosystem Project Build/Install Tests Status
Bun elysia ✅ 1/1 passed ✅ PASS
Bun hono ✅ 1/1 passed ✅ PASS
C++ fmt ✅ N/A ✅ PASS
C++ json ✅ N/A ✅ PASS
Deno oak N/A 1/1 passed ✅ PASS
Deno std N/A 1/1 passed ✅ PASS
.NET hello-world ✅ N/A ✅ PASS
.NET json-parse ✅ N/A ✅ PASS
Go color ✅ ok ✅ PASS
Go env ✅ ok ✅ PASS
Go uuid ✅ ok ✅ PASS
Java gson ✅ 1/1 passed ✅ PASS
Java caffeine ✅ 1/1 passed ✅ PASS
Node.js clsx ✅ passed ✅ PASS
Node.js execa ✅ passed ✅ PASS
Node.js p-limit ✅ passed ✅ PASS
Rust fd ✅ 1/1 passed ✅ PASS
Rust zoxide ✅ 1/1 passed ✅ PASS

Overall: 8/8 ecosystems passed — PASS ✅

All repositories cloned successfully and all 18 project builds/tests completed without errors.

Note: Java initially failed with LocalRepositoryNotAccessibleException because ~/.m2 was owned by root (pre-existing environment permission issue, unrelated to the firewall). Worked around by pointing localRepository in settings.xml to a writable path (/tmp/gh-aw/agent/m2-repo); after that, both gson and caffeine compiled and passed all tests through the Squid proxy.

Warning

Firewall blocked 8 domains

The following domains were blocked by the firewall during workflow execution:

  • api.nuget.org
  • bun.sh
  • dc.services.visualstudio.com
  • deno.land
  • dl.deno.land
  • github.com
  • releaseassets.githubusercontent.com
  • repo.maven.apache.org

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "api.nuget.org"
    - "bun.sh"
    - "dc.services.visualstudio.com"
    - "deno.land"
    - "dl.deno.land"
    - "github.com"
    - "releaseassets.githubusercontent.com"
    - "repo.maven.apache.org"

See Network Configuration for more information.

Generated by Build Test Suite for #9005 · copilot · auto · 47 AIC · ⊞ 11.8K · ◷
Add label ready-for-aw to run again

@github-actions

Copy link
Copy Markdown
Contributor

Chroot Version Comparison Results

Runtime Host Version Chroot Version Match?
Python Python 3.12.14 Python 3.12.14 ✅ YES
Node.js v24.21.0 v22.23.2 ❌ NO
Go go1.22.12 go1.22.12 ✅ YES

Overall: FAILED — Node.js version mismatch between host and chroot environments (smoke-chroot label not applied).

Tested by Smoke Chroot
Add label ready-for-aw to run again

@github-actions

Copy link
Copy Markdown
Contributor

Smoke Test

  • fix: tolerate benign VMM thread churn in confinement re-verification
  • feat: add NVX build-test smoke workflow
  • GitHub reads ✅
  • Playwright title ✅
  • File write/read ✅
  • Build (npm ci && npm run build) ✅
  • Overall: PASS

Warning

Firewall blocked 13 domains

The following domains were blocked by the firewall during workflow execution:

  • ab.chatgpt.com
  • accounts.google.com
  • android.clients.google.com
  • api.github.com
  • clients2.google.com
  • collector.github.com
  • contentautofill.googleapis.com
  • github.com
  • github.githubassets.com
  • msfeed25.pkgs.visualstudio.com
  • update.googleapis.com
  • www.google.com
  • www.gstatic.com

[!TIP]
api.github.com is blocked because GitHub API access uses the built-in GitHub tools by default. Instead of adding api.github.com to network.allowed, use tools.github.mode: gh-proxy for direct pre-authenticated GitHub CLI access without requiring network access to api.github.com:

tools:
  github:
    mode: gh-proxy

See GitHub Tools for more information on gh-proxy mode.

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "ab.chatgpt.com"
    - "accounts.google.com"
    - "android.clients.google.com"
    - "api.github.com"
    - "clients2.google.com"
    - "collector.github.com"
    - "contentautofill.googleapis.com"
    - "github.com"
    - "github.githubassets.com"
    - "msfeed25.pkgs.visualstudio.com"
    - "update.googleapis.com"
    - "www.google.com"
    - "www.gstatic.com"

See Network Configuration for more information.

🔮 The oracle has spoken through Smoke Codex
Add label ready-for-aw to run again

@github-actions

Copy link
Copy Markdown
Contributor

📡 OTel Tracing Smoke Test Results

Scenario Result
1. Module Loading ✅ otel.js loaded, isEnabled: true, exports 14 functions incl. startRequestSpan, setTokenAttributes, setBudgetAttributes, endSpan, shutdown
2. Test Suite ✅ 3 suites / 68 tests passed (otel.test.js, otel-fanout.test.js, otel-workload-identity.test.js)
3. Env Var Forwarding ✅ Agent passthrough has GITHUB_AW_OTEL_TRACE_ID/GITHUB_AW_OTEL_PARENT_SPAN_ID; api-proxy config has GH_AW_OTLP_ENDPOINTS, OTEL_EXPORTER_OTLP_ENDPOINT, and both trace-context vars
4. Token Tracker Integration ✅ onUsage callback present in token-tracker-http.js
5. OTEL Diagnostics ⚪ No otel.jsonl span file found this run (only token-usage.jsonl, 9 records) — expected since no OTLP endpoint was actively exporting spans in this sandbox session

Summary: All core OTEL integration points (module, tests, env wiring, token-tracker hook) validated successfully. No span export observed this run, consistent with no active OTLP collector traffic — not a regression.

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • o205451.ingest.us.sentry.io

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "o205451.ingest.us.sentry.io"

See Network Configuration for more information.

📡 OTel tracing validated by Smoke OTel Tracing
Add label ready-for-aw to run again

@lpcox
lpcox merged commit 723bff7 into main Sep 26, 2026
156 of 162 checks passed
@lpcox
lpcox deleted the copilot/fix-api-proxy-gpt-6-errors branch September 26, 2026 03:01
github-actions Bot added a commit that referenced this pull request Sep 27, 2026
…o all providers

PR #9005 extended the redundant <provider>/ model-prefix strip
(stripRedundantModelPrefixInBody / stripRedundantProviderPrefix) from
Copilot-only to every provider route, so an OpenAI-bound LiteLLM-style
openai/gpt-6-sol model ID is normalized before forwarding. Prior docs
described this normalization as Copilot-specific.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
lpcox added a commit that referenced this pull request Sep 27, 2026
…ed in PR #9005 (#9062)

* docs: document that redundant provider-prefix stripping now applies to all providers

PR #9005 extended the redundant <provider>/ model-prefix strip
(stripRedundantModelPrefixInBody / stripRedundantProviderPrefix) from
Copilot-only to every provider route, so an OpenAI-bound LiteLLM-style
openai/gpt-6-sol model ID is normalized before forwarding. Prior docs
described this normalization as Copilot-specific.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* docs: address provider prefix review feedback

Co-authored-by: lpcox <15877973+lpcox@users.noreply.github.com>

---------

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: lpcox <15877973+lpcox@users.noreply.github.com>

This branch was successfully deployed

1 active deployment
aoai-model — 86fa3190 Deployed Sep 25, 2026 by lpcox via conclusion #1773
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

4 participants