Skip to content

fix(openai): allow disabling WebSocket proxy discovery - #28

Merged
danielkov merged 1 commit into
mainfrom
fix/openai-websocket-proxy-policy
Sep 30, 2026
Merged

danielkov merged 1 commit into
mainfrom
fix/openai-websocket-proxy-policy

Conversation

@danielkov

Copy link
Copy Markdown
Owner

Summary

Add OpenAIResponsesConfig::with_websocket_no_proxy(bool) so applications can disable environment and system proxy discovery for Responses WebSocket upgrades. Bump agentkit-provider-openai from 0.10.11 to 0.10.12.

Motivation

The dedicated WebSocket client does not inherit the network policy of a caller-supplied HTTP client. Applications that explicitly disable HTTP proxies need an equivalent setting before enabling automatic WebSocket transport; otherwise an unavailable or incompatible proxy can break previously working direct inference.

Impact

Proxy discovery remains enabled by default. Opting out applies to both WebSocket and Auto upgrades; HTTP/SSE fallback retains its independently configured client policy.

Technical details

The dedicated client retains HTTP/1, TLS verification, disabled redirects and implicit retries, and existing handshake timeouts. This exposes only the proxy-discovery policy rather than accepting an arbitrary client that could weaken those safeguards.

@kit-code-agent kit-code-agent Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found. The changes look good to merge.

@danielkov
danielkov merged commit 6b55970 into main Sep 30, 2026
2 checks passed
danielkov added a commit that referenced this pull request Sep 30, 2026
…atim text through input (#29)

## Summary
Makes the Responses WebSocket transport as resilient as HTTP/SSE and
keeps prompt-cache hits across sessions that share a cache key. Also
makes the Runlet compose tool steer text that would need escaping into
`input`, and moves it to runlet 0.6.1.

Stacked on #28 and based on its branch; GitHub retargets this PR to
`main` when #28 merges. Both provider changes ship together as
`agentkit-provider-openai` 0.10.12. `agentkit-tool-compose` goes to
0.10.12.

## Provider (`agentkit-provider-openai`)
- **Resend after visible output.** A WebSocket that drops, stalls or
times out after output has streamed used to fail the turn, while HTTP
retried and superseded the attempt. With `store: false` and
response-attempt supersession enabled, the adapter now emits
`ResponseAttemptSuperseded` and resends the full request on a fresh
socket. Without supersession, visible output is still never replayed.
- **Progress-based stall detection.** `with_progress_timeouts(first,
gap)` bounds an attempt by response progress, so keepalive and metadata
traffic can no longer hold a stalled attempt open until the attempt
timeout.
- **Cache routing.** `session-id` follows the request's prompt cache
key, and `thread-id` and `x-codex-routing-hint` are sent. Requests that
share a key reach the backend holding their prefix, instead of starting
cold.
- **Turn-state.** Captured from `codex.response.metadata`, which can
arrive before `response.created`. It is scoped per session and reset on
a new user message or an authentication change.
- **No warmup request.** It cost a round trip and added a failure mode
without improving cache hits.

## Compose (`agentkit-tool-compose`)
- `input` comes before `script` in the schema and is described as
verbatim. Text that would need escaping in a string literal, such as
file contents or code with quotes or backslashes, goes in `input` and is
referenced from the script.
- The primer's JSON-parse example is replaced with a code edit that
writes `input` unchanged, and it uses runlet 0.6.1 single-quoted
strings.
- Requires runlet 0.6.1, which adds raw newlines and single quotes in
strings, verbatim unknown escapes, and separate binding and callable
namespaces.

## Impact
No API removals. New: `OpenAIResponsesConfig::with_progress_timeouts`.
Consumers that opt into response-attempt supersession now receive
superseded attempts on WebSocket as well as HTTP.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant