Repository navigation
fix(openai): allow disabling WebSocket proxy discovery - #28
Merged
Merged
Conversation
danielkov
added this pull request to stack #30
September 30, 2026 13:19
danielkov
added a commit
that referenced
this pull request
Sep 30, 2026
…atim text through input (#29) ## Summary Makes the Responses WebSocket transport as resilient as HTTP/SSE and keeps prompt-cache hits across sessions that share a cache key. Also makes the Runlet compose tool steer text that would need escaping into `input`, and moves it to runlet 0.6.1. Stacked on #28 and based on its branch; GitHub retargets this PR to `main` when #28 merges. Both provider changes ship together as `agentkit-provider-openai` 0.10.12. `agentkit-tool-compose` goes to 0.10.12. ## Provider (`agentkit-provider-openai`) - **Resend after visible output.** A WebSocket that drops, stalls or times out after output has streamed used to fail the turn, while HTTP retried and superseded the attempt. With `store: false` and response-attempt supersession enabled, the adapter now emits `ResponseAttemptSuperseded` and resends the full request on a fresh socket. Without supersession, visible output is still never replayed. - **Progress-based stall detection.** `with_progress_timeouts(first, gap)` bounds an attempt by response progress, so keepalive and metadata traffic can no longer hold a stalled attempt open until the attempt timeout. - **Cache routing.** `session-id` follows the request's prompt cache key, and `thread-id` and `x-codex-routing-hint` are sent. Requests that share a key reach the backend holding their prefix, instead of starting cold. - **Turn-state.** Captured from `codex.response.metadata`, which can arrive before `response.created`. It is scoped per session and reset on a new user message or an authentication change. - **No warmup request.** It cost a round trip and added a failure mode without improving cache hits. ## Compose (`agentkit-tool-compose`) - `input` comes before `script` in the schema and is described as verbatim. Text that would need escaping in a string literal, such as file contents or code with quotes or backslashes, goes in `input` and is referenced from the script. - The primer's JSON-parse example is replaced with a code edit that writes `input` unchanged, and it uses runlet 0.6.1 single-quoted strings. - Requires runlet 0.6.1, which adds raw newlines and single quotes in strings, verbatim unknown escapes, and separate binding and callable namespaces. ## Impact No API removals. New: `OpenAIResponsesConfig::with_progress_timeouts`. Consumers that opt into response-attempt supersession now receive superseded attempts on WebSocket as well as HTTP.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Add
OpenAIResponsesConfig::with_websocket_no_proxy(bool)so applications can disable environment and system proxy discovery for Responses WebSocket upgrades. Bumpagentkit-provider-openaifrom 0.10.11 to 0.10.12.Motivation
The dedicated WebSocket client does not inherit the network policy of a caller-supplied HTTP client. Applications that explicitly disable HTTP proxies need an equivalent setting before enabling automatic WebSocket transport; otherwise an unavailable or incompatible proxy can break previously working direct inference.
Impact
Proxy discovery remains enabled by default. Opting out applies to both
WebSocketandAutoupgrades; HTTP/SSE fallback retains its independently configured client policy.Technical details
The dedicated client retains HTTP/1, TLS verification, disabled redirects and implicit retries, and existing handshake timeouts. This exposes only the proxy-discovery policy rather than accepting an arbitrary client that could weaken those safeguards.