Skip to content

Route Copilot auto requests to Codex-compatible Responses models - #9422

Merged
lpcox merged 4 commits into
mainfrom
copilot/awf-route-copilot-auto-to-codex
Oct 3, 2026
Merged

lpcox merged 4 commits into
mainfrom
copilot/awf-route-copilot-auto-to-codex

Conversation

Copilot AI commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

Copilot auto works on Chat Completions, but Responses requests send the unsupported literal auto and fail before inference. Codex needs a concrete model that supports both Responses and its tool surface, without changing provider or credentials.

  • Responses routing: For native Copilot requests, select the highest-version available Codex model whose inventory entry advertises Responses support; respect the configured model policy.
  • Fail closed: Refresh the inventory once, then return an explicit 503 if no eligible model is available.
  • Preserve behavior and observability: Leave Chat Completions and custom Copilot targets unchanged; log the requested and resolved model.
{"model":"copilot/auto","input":"..."}

On /responses, the proxy rewrites model to an eligible inventory model, such as gpt-5.3-codex.

Co-authored-by: lpcox <15877973+lpcox@users.noreply.github.com>
Copilot AI changed the title [WIP] Route Copilot auto to a Codex-compatible Responses model Route Copilot auto requests to Codex-compatible Responses models Oct 3, 2026
Copilot AI requested a review from lpcox October 3, 2026 17:26
@lpcox
lpcox marked this pull request as ready for review October 3, 2026 17:28
Copilot AI balanced review requested due to automatic review settings October 3, 2026 17:28

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Policy handling can bypass routing, and disabled Copilot models can be selected.

Review effort: Balanced
Findings: 2 Medium severity

Open (2)
What changed in this PR

Routes native Copilot Responses auto requests to an eligible Codex model while preserving Chat Completions and custom-target behavior.

Changes:

  • Adds inventory- and policy-aware Responses model selection.
  • Refreshes inventory before returning an explicit 503.
  • Documents behavior and adds focused tests.
File Description
docs/​troubleshooting.md Clarifies native OpenAI versus Copilot auto.
docs/​api-proxy-sidecar.md Documents Copilot Responses routing.
containers/​api-proxy/​server.js Enables routing for native Copilot targets.
containers/​api-proxy/​model-config.js Integrates resolution and refresh behavior.
containers/​api-proxy/​model-body-rewriter.js Selects and rewrites eligible Codex models.
containers/​api-proxy/​copilot-auto-responses.test.js Tests routing, refresh, failure, and exclusions.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment on lines +106 to +109
.filter(record => record &&
/(?:^|[-.])codex(?:$|[-.])/i.test(record.id) &&
Array.isArray(record.supportedEndpoints) &&
record.supportedEndpoints.some(endpoint => ['/responses', '/v1/responses', 'responses'].includes(endpoint)) &&
Comment thread containers/api-proxy/model-config.js
@lpcox

lpcox commented Oct 3, 2026

Copy link
Copy Markdown
Collaborator

@copilot merge main and address review feedback

Copilot AI and others added 2 commits October 3, 2026 17:39
Co-authored-by: lpcox <15877973+lpcox@users.noreply.github.com>
Co-authored-by: lpcox <15877973+lpcox@users.noreply.github.com>

Copilot AI commented Oct 3, 2026

Copy link
Copy Markdown
Contributor Author

@copilot merge main and address review feedback

Merged main in e83418e and addressed both findings in 8a985da: disabled inventory models are excluded, and policy is enforced against resolved concrete models rather than literal auto. Added regression coverage; all 2,142 API proxy tests pass. CodeQL found no alerts, and a fallback read-only review found no issues (the automated reviewer’s configured model was unavailable).

@lpcox
lpcox enabled auto-merge (squash) October 3, 2026 18:02
@github-actions

github-actions Bot commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

Documentation Preview

Documentation has been built for this PR.

Download preview artifact

To view locally:

  1. Download the docs-preview-pr-9422 artifact from the workflow run
  2. Unzip and open index.html in your browser

Built from commit db00bbb

@github-actions

github-actions Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

🛡️ Smoke Copilot Network Isolation confirmed the egress allowlist is enforced. ✅

🛡️ Egress verdict from Smoke Copilot Network Isolation

@github-actions

github-actions Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

❌ Smoke Copilot BYOK AOAI (api-key) reports failed. AOAI BYOK (api-key) mode investigation needed...

🔑 BYOK (AOAI api-key) report filed by Smoke Copilot BYOK AOAI (api-key)

@github-actions

github-actions Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

✅ Smoke Claude passed

Generated by Smoke Claude for #9422

@github-actions

github-actions Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

✅ Build Test Suite completed successfully!

Generated by Build Test Suite for #9422

@github-actions

github-actions Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

❌ Smoke Gemini reports failed. Facets need polishing...

💎 Faceted by Smoke Gemini

@github-actions

github-actions Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

Chroot tests passed! Smoke Chroot - All security and functionality tests succeeded.

Tested by Smoke Chroot

@github-actions

github-actions Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

🔌 Smoke Services — All services reachable! ✅

🔌 Service connectivity validated by Smoke Services

@github-actions

github-actions Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

📰 VERDICT: Smoke Copilot has concluded. All systems operational. This is a developing story. 🎤

📰 BREAKING: Report filed by Smoke Copilot

@github-actions

github-actions Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

✨ The prophecy is fulfilled... Smoke Codex has completed its mystical journey. The stars align. 🌟

🔮 The oracle has spoken through Smoke Codex

@github-actions

github-actions Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

✅ Smoke Copilot BYOK completed. Copilot BYOK mode operational. 🔓

🔑 BYOK report filed by Smoke Copilot BYOK

@github-actions

github-actions Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

📡 Smoke OTel Tracing completed. All tracing scenarios validated. ✅

📡 OTel tracing validated by Smoke OTel Tracing

@github-actions

github-actions Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

✅ Security Guard completed successfully!

Security review complete: PR #9422 adds Copilot auto-to-Codex routing with proper model policy enforcement, authentication gating, and defensive input validation. No security weakening detected. Changes are feature-gated behind native Copilot environment checks and model policy guards.

Generated by Security Guard for #9422

@github-actions

github-actions Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

Smoke Cloud Hypervisor completed. Cloud Hypervisor + Copilot passed.

Cloud Hypervisor + Copilot smoke test by Smoke Cloud Hypervisor

@github-actions

github-actions Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

❌ Smoke Copilot BYOK AOAI (Entra) reports failed. AOAI BYOK (Entra) mode investigation needed...

🪪 BYOK (AOAI Entra) report filed by Smoke Copilot BYOK AOAI (Entra)

@github-actions

github-actions Bot commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

Smoke Test: Claude Engine Validation

  • API status: ✅ PASS
  • GitHub check: ✅ PASS
  • File status: ✅ PASS

Overall result: PASS

Generated by Smoke Claude for #9422 · claude · haiku45 · 24.3 AIC · ⊞ 6.2K · ◷
Add label ready-for-aw to run again

@github-actions

github-actions Bot commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

Smoke Copilot: PASS ✅

  • MCP: ✅ (last merged: "[WIP] Fix Squid crashes with assertion failure in Claude inference")
  • github.com: ✅ (HTTP 200)
  • File write/read: ✅
    Author: @Copilot · Assignees: @lpcox @Copilot

📰 BREAKING: Report filed by Smoke Copilot
Add label ready-for-aw to run again

@github-actions

github-actions Bot commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

✅ Smoke Test: Copilot BYOK (Direct) Mode

Overall: PASS

🔑 BYOK report filed by Smoke Copilot BYOK
Add label ready-for-aw to run again

@github-actions github-actions Bot added smoke-copilot-byok smoke-copilot-network-isolation Copilot network-isolation egress smoke test labels Oct 3, 2026
@github-actions

github-actions Bot commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

EGRESS_RESULT allow=pass deny=pass

  • ✅ Allowed domain (api.github.com): HTTP 200
  • ✅ Blocked domain (example.com): blocked (curl failed with a TLS error: self-signed certificate)
  • Overall: PASS

cc @lpcox

🛡️ Egress verdict from Smoke Copilot Network Isolation
Add label ready-for-aw to run again

@github-actions

github-actions Bot commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

Smoke Test: Cloud Hypervisor + Copilot

  1. list_pull_requests (github/gh-aw-firewall): PASS — returned PR Route Copilot auto requests to Codex-compatible Responses models #9422.
  2. curl https://github.com: FAIL — blocked at sandbox permission layer (no HTTP status obtained, not 200/301).
  3. Write/read /tmp/gh-aw/agent/smoke-cloud-hypervisor-*.txt: PASS.
  4. curl (example.com/redacted) (expect block): FAIL — blocked at sandbox permission layer, not a 000/403 from curl itself.

Note: outbound curl is denied by the sandbox before execution, so checks 2 and 4 could not be validated via actual HTTP response codes.

Cloud Hypervisor + Copilot smoke test by Smoke Cloud Hypervisor
Add label ready-for-aw to run again

@github-actions

github-actions Bot commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

OTEL smoke test (re-verified locally)

  • ✅ S1 Module: otel.js loads, isEnabled()=true; exports startRequestSpan, setTokenAttributes, setBudgetAttributes, endSpan, endSpanError, shutdown, isEnabled, etc.
  • ✅ S2 Tests: 3 suites, 68/68 passed
  • ✅ S3 Env forwarding: trace/parent-span IDs in env-passthrough.ts and api-proxy-env-config.ts; OTLP endpoint in api-proxy-env-config.ts
  • ✅ S4 Token tracker: onUsage hook present in token-tracker-http.js
  • ⚠️ S5 Diagnostics: no api-proxy otel.jsonl span file in this run (api-proxy not exercised; not treated as a failure)

📡 OTel tracing validated by Smoke OTel Tracing
Add label ready-for-aw to run again

@github-actions

github-actions Bot commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

⚠️ Coverage Regression Detected

This PR decreases test coverage. Please add tests to maintain coverage levels.

Overall Coverage

Metric Base PR Delta
Lines 92.91% 92.91% ➡️ +0.00%
Statements 91.38% 91.38% ➡️ +0.00%
Functions 89.55% 89.55% ➡️ +0.00%
Branches 85.04% 85.03% 📉 -0.01%
📁 Per-file Coverage Changes (2 files)
File Lines (Before → After) Statements (Before → After)
src/nvx/one-shot-adapter.ts 83.5% → 82.9% (-0.60%) 80.3% → 79.8% (-0.56%)
src/log-directory-setup.ts 96.8% → 100.0% (+3.18%) 96.9% → 100.0% (+3.13%)

Coverage comparison generated by scripts/ci/compare-coverage.ts

@github-actions

github-actions Bot commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

Smoke services: ✅ Redis PONG · ✅ pg_isready accepting connections · ✅ SELECT 1 → 1. PASS

🔌 Service connectivity validated by Smoke Services
Add label ready-for-aw to run again

@github-actions

github-actions Bot commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

Chroot Version Comparison

Runtime Host Version Chroot Version Match?
Python Python 3.12.14 Python 3.12.14 ✅ YES
Node.js v24.21.0 v2.98.0 ❌ NO
Go go1.22.12 go1.22.12 ✅ YES

Result: Not all tests passed (Node.js mismatch), so the smoke-chroot label was not added.

Tested by Smoke Chroot
Add label ready-for-aw to run again

@github-actions

github-actions Bot commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

🏗️ Build Test Suite Results

Ecosystem Project Build/Install Tests Status
Bun elysia ❌ N/A ❌ FAIL
Bun hono ❌ N/A ❌ FAIL
C++ fmt ✅ N/A ✅ PASS
C++ json ✅ N/A ✅ PASS
Deno oak ❌ N/A ❌ FAIL
Deno std ❌ N/A ❌ FAIL
.NET hello-world ✅ N/A ✅ PASS
.NET json-parse ✅ N/A ✅ PASS
Go color ✅ 1/1 pkg passed ✅ PASS
Go env ✅ 1/1 pkg passed ✅ PASS
Go uuid ✅ 1/1 pkg passed ✅ PASS
Java gson ❌ N/A ❌ FAIL
Java caffeine ❌ N/A ❌ FAIL
Node.js clsx ✅ all passed ✅ PASS
Node.js execa ✅ all passed ✅ PASS
Node.js p-limit ✅ all passed ✅ PASS
Rust fd ✅ 1/1 passed ✅ PASS
Rust zoxide ✅ 1/1 passed ✅ PASS

Overall: 5/8 ecosystems passed — FAIL

Failures:

  • Bun / Deno: the install scripts (curl ... | bash/sh) were denied by the sandbox ("Permission denied and could not request permission"), so bun/deno were not installed and the tests were not run.
  • Java: Maven failed with Could not create local repository at /home/runner/.m2/repository (LocalRepositoryNotAccessibleException) for both projects.

All 8 repos cloned successfully. The build-test label was not added because of the failures.

Generated by Build Test Suite for #9422 · copilot · auto · 19.3 AIC · ⊞ 11.8K · ◷
Add label ready-for-aw to run again

@lpcox
lpcox deployed to aoai-model October 3, 2026 18:07 — with GitHub Actions Active
@github-actions

github-actions Bot commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

Merged PR lookup: ❌
PR detail lookup: ❌
Playwright title check: ❌
Smoke file write/read: ✅
AWF build: ❌
Overall: FAIL

🔮 The oracle has spoken through Smoke Codex
Add label ready-for-aw to run again

@lpcox
lpcox deployed to aoai-model October 3, 2026 18:07 — with GitHub Actions Active
@lpcox
lpcox merged commit 140c4fa into main Oct 3, 2026
129 of 135 checks passed
@lpcox
lpcox deleted the copilot/awf-route-copilot-auto-to-codex branch October 3, 2026 18:14

This branch was successfully deployed

1 active deployment
aoai-model — 8a985da7 Deployed Oct 3, 2026 by lpcox via conclusion #1868
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[awf] Route Copilot auto to a Codex-compatible Responses model

3 participants