Route Copilot auto requests to Codex-compatible Responses models - #9422
Conversation
Co-authored-by: lpcox <15877973+lpcox@users.noreply.github.com>
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Policy handling can bypass routing, and disabled Copilot models can be selected.
Review effort: Balanced
Findings: 2
Open (2)
What changed in this PR
Routes native Copilot Responses auto requests to an eligible Codex model while preserving Chat Completions and custom-target behavior.
Changes:
- Adds inventory- and policy-aware Responses model selection.
- Refreshes inventory before returning an explicit 503.
- Documents behavior and adds focused tests.
| File | Description |
|---|---|
docs/troubleshooting.md |
Clarifies native OpenAI versus Copilot auto. |
docs/api-proxy-sidecar.md |
Documents Copilot Responses routing. |
containers/api-proxy/server.js |
Enables routing for native Copilot targets. |
containers/api-proxy/model-config.js |
Integrates resolution and refresh behavior. |
containers/api-proxy/model-body-rewriter.js |
Selects and rewrites eligible Codex models. |
containers/api-proxy/copilot-auto-responses.test.js |
Tests routing, refresh, failure, and exclusions. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| .filter(record => record && | ||
| /(?:^|[-.])codex(?:$|[-.])/i.test(record.id) && | ||
| Array.isArray(record.supportedEndpoints) && | ||
| record.supportedEndpoints.some(endpoint => ['/responses', '/v1/responses', 'responses'].includes(endpoint)) && |
|
@copilot merge main and address review feedback |
Co-authored-by: lpcox <15877973+lpcox@users.noreply.github.com>
Co-authored-by: lpcox <15877973+lpcox@users.noreply.github.com>
Merged main in e83418e and addressed both findings in 8a985da: disabled inventory models are excluded, and policy is enforced against resolved concrete models rather than literal |
Documentation PreviewDocumentation has been built for this PR. To view locally:
Built from commit db00bbb |
|
🛡️ Smoke Copilot Network Isolation confirmed the egress allowlist is enforced. ✅
|
|
❌ Smoke Copilot BYOK AOAI (api-key) reports failed. AOAI BYOK (api-key) mode investigation needed...
|
|
✅ Smoke Claude passed
|
|
✅ Build Test Suite completed successfully!
|
|
❌ Smoke Gemini reports failed. Facets need polishing...
|
|
Chroot tests passed! Smoke Chroot - All security and functionality tests succeeded.
|
|
🔌 Smoke Services — All services reachable! ✅
|
|
📰 VERDICT: Smoke Copilot has concluded. All systems operational. This is a developing story. 🎤
|
|
✨ The prophecy is fulfilled... Smoke Codex has completed its mystical journey. The stars align. 🌟
|
|
✅ Smoke Copilot BYOK completed. Copilot BYOK mode operational. 🔓
|
|
📡 Smoke OTel Tracing completed. All tracing scenarios validated. ✅
|
|
✅ Security Guard completed successfully! Security review complete: PR #9422 adds Copilot auto-to-Codex routing with proper model policy enforcement, authentication gating, and defensive input validation. No security weakening detected. Changes are feature-gated behind native Copilot environment checks and model policy guards.
|
|
Smoke Cloud Hypervisor completed. Cloud Hypervisor + Copilot passed.
|
|
❌ Smoke Copilot BYOK AOAI (Entra) reports failed. AOAI BYOK (Entra) mode investigation needed...
|
Smoke Test: Claude Engine Validation
Overall result: PASS
|
|
Smoke Copilot: PASS ✅
|
|
✅ Smoke Test: Copilot BYOK (Direct) Mode
Overall: PASS
|
|
EGRESS_RESULT allow=pass deny=pass
cc
|
Smoke Test: Cloud Hypervisor + Copilot
Note: outbound
|
|
OTEL smoke test (re-verified locally)
|
|
| Metric | Base | PR | Delta |
|---|---|---|---|
| Lines | 92.91% | 92.91% | ➡️ +0.00% |
| Statements | 91.38% | 91.38% | ➡️ +0.00% |
| Functions | 89.55% | 89.55% | ➡️ +0.00% |
| Branches | 85.04% | 85.03% | 📉 -0.01% |
📁 Per-file Coverage Changes (2 files)
| File | Lines (Before → After) | Statements (Before → After) |
|---|---|---|
src/nvx/one-shot-adapter.ts |
83.5% → 82.9% (-0.60%) | 80.3% → 79.8% (-0.56%) |
src/log-directory-setup.ts |
96.8% → 100.0% (+3.18%) | 96.9% → 100.0% (+3.13%) |
Coverage comparison generated by scripts/ci/compare-coverage.ts
|
Smoke services: ✅ Redis PONG · ✅ pg_isready accepting connections · ✅ SELECT 1 → 1. PASS
|
Chroot Version Comparison
Result: Not all tests passed (Node.js mismatch), so the
|
🏗️ Build Test Suite Results
Overall: 5/8 ecosystems passed — FAIL Failures:
All 8 repos cloned successfully. The
|
|
Merged PR lookup: ❌
|

Copilot
autoworks on Chat Completions, but Responses requests send the unsupported literalautoand fail before inference. Codex needs a concrete model that supports both Responses and its tool surface, without changing provider or credentials.{"model":"copilot/auto","input":"..."}On
/responses, the proxy rewritesmodelto an eligible inventory model, such asgpt-5.3-codex.