🤖 fix: version-lock mux compat package to v0.30.0 - #4354
Merged
Merged
Conversation
The v0.30.0 release commit bumped only the root package.json, leaving packages/mux-compat at 0.29.0. productIdentity.test.ts asserts the forwarding package is version-locked to @coder/xum, so Test / Unit is red on main and on every PR's merge commit. _Generated with `xum` • Model: `coder:anthropic/claude-fable-5-1` • Thinking: `xhigh` • Cost: `$174.60`_ <!-- mux-attribution: model=coder:anthropic/claude-fable-5-1 thinking=xhigh costs=174.60 -->
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
This was referenced Sep 22, 2026
github-merge-queue
Bot
removed this pull request from the merge queue due to failed status checks
Sep 22, 2026
yermakoffivan
pushed a commit
to yermakoffivan/mux
that referenced
this pull request
Sep 24, 2026
… correct their Codex context cap (coder#4259) ## Summary Follow-up to coder#4350 (landed as `7358fa80`), which makes a *requested* `reasoning_effort: "none"` reach the wire for GPT-6 Sol/Luna. This PR closes the three gaps left after coder#4348 and coder#4350: headless tool loops that request no effort at all, Coder-scoped aliases on `openai-compat` instances, and the assumed 372K Codex OAuth context cap (272K in the pinned Codex catalog). ## Background - Sol/Luna Chat Completions accepts function calling only with `reasoning_effort: "none"`; an omitted effort defaults to `medium`. `buildProviderOptions` clamps agent turns (coder#4348) and coder#4350 makes that clamp serialize, but Dream consolidation, memory harvest, refine and sidebar-status generation call `streamText` with tools and **no provider options**, so nothing requests `none` and their tool calls are rejected on Chat Completions routes (direct `wireFormat: chatCompletions`, Coder `openai-compat` instances). Raised by Codex on the earlier revision of this PR; the Coder alias case is its round-6 finding. - Codex catalog pin: [openai/codex@04fc75ad `codex-rs/models-manager/models.json`](https://github.com/openai/codex/blob/04fc75adbe67a612a1cb0fc469533f24b24fa499/codex-rs/models-manager/models.json) — `gpt-6-sol` / `gpt-6-luna` `context_window: 272000`. `main` copies Astra's 372K with an "assumed" comment. ## Implementation - `clampGpt6ChatCompletionsToolReasoning` (providerModelFactory.ts): a `transformParams` middleware that sets `reasoningEffort: "none"` when the request carries tools **and no effort was requested**, for Sol/Luna capability identities on Chat Completions. Explicit caller efforts are preserved (this keeps coder#4350's "requested `high` stays `high`" contract intact). It wraps *outside* `createOpenAIModelWithPreservedOptions` so the injected `none` is seen by that wrapper's body patch instead of being stripped by the SDK. - Applied on the direct OpenAI path (Chat Completions wire only) and the Coder gateway Chat path, where the capability identity is `resolveModelForMetadata(coder:<instance>/<model>)` so scoped "Treat as" aliases are clamped too. - `CODEX_OAUTH_CONTEXT_WINDOW_OVERRIDES`: `gpt-6-sol` / `gpt-6-luna` 372K → 272K with the pin cited inline; Astra and the GPT-5.6 family are unchanged (coder#4347). Dropped from earlier revisions: catalog/aliases/pricing/labels/migration/docs (landed in coder#4348), the `@ai-sdk/openai` Bun patch (Bun `patchedDependencies` never reach npm installs of `@coder/xum`; coder#4350's runtime rewrite is the right fix), and the `hasTools` plumbing through `buildProviderOptions`. ## Validation Repo-pinned Bun 1.3.5, on `main` + this commit with a freshly reinstalled, unpatched `@ai-sdk/openai` (so a green body assertion proves the composition with coder#4350's wrapper). - `providerModelFactory.test.ts` › "clamps %s tool requests … at the model boundary" (Sol raw id, mapped `team-luna`, Astra control, Responses control) and › "clamps %s tool requests through a Coder openai-compat instance" (`coder:chat-proxy/team-luna` mapped, `coder:chat-proxy/gpt-6-sol` raw, `team-astra` control). Red proof: with the clamp disabled, exactly the four Sol/Luna Chat Completions cases fail (`Expected "none" / Received undefined`); coder#4350's 11 wire cases are unaffected. Reverting the Coder capability argument to the raw `originModelId` fails exactly the mapped `team-luna` case. - `codexOAuth.test.ts` asserts Astra (372K) and Sol/Luna (272K) separately. `contextLimit`, `tokenMeterUtils`, `thinking`, `turnRequestBuilder`, `providerOptions` suites pass. `make static-check` green. ## Risks - The middleware fires only for Sol/Luna capability identities, Chat Completions wire, a non-empty `tools` array, and no requested effort. Responses, tool-free requests, explicit efforts, Astra, GPT-5.6 and non-OpenAI providers are untouched. - Lower Codex OAuth cap (272K) starts limit-driven compaction earlier for OAuth-routed Sol/Luna; API-key routes keep the public limits. ## Readiness and follow-ups - Originally stacked on coder#4350; rebased onto `main` after coder#4350 landed (`7358fa80`). The residual diff is unchanged (+183/−21). - `main` unblock for `Test / Unit` (release commit left `packages/mux-compat` at 0.29.0): coder#4354 standalone, also folded into coder#4350; whichever becomes empty is closed. - Round-6 security finding (budget accounting ignores priority-tier pricing) is pre-existing/generic → coder#4352. coder#4347 tracks GPT-5.6 Sol promotional pricing and Astra's Codex cap. <details> <summary>Preserved review and delivery record — fifteen Codex executions including this head, one code-advisor pass</summary> | Round | Reviewed head (before rebase / re-scope) | Executions | Findings / disposition | | --- | --- | --- | --- | | 1 | `01ca053` | Codex code + security | Hidden-model compaction exposure and zero pricing bypassing CLI budget; fixed in `252bba9` / `cb5ac4b`, replied and resolved | | 2 | `cb5ac4b` | Codex code + security | Migration-marker flip and hiding prior opt-ins; fixed in `64169a3`, replied and resolved | | 3 | `64169a3` | Codex code + security | Clean completion on both loops | | 4, renewed authorization | `40e4b2a6` | Automatic Codex code + security on undraft | Security clean; code P2 Chat Completions default-effort issue → fixed in `ce20ecd0`, replied and resolved | | 5, explicit "get it merged" authorization | `bfc0906f` (superseding `ce20ecd0`) | Automatic Codex code review on undraft | P2: headless tool loops bypass provider options → fixed in `a4c7c156`, replied and resolved | | 6 | `a4c7c156` | Explicit `@codex review` (code + security) | Code P2: Coder aliases not resolved before clamping → fixed, replied and resolved. Security P2: priority-tier budget accounting → pre-existing/generic, coder#4352, replied and resolved | | 7 | `2c4803c0` (residual on `main` after coder#4348) | Explicit `@codex review` (code + security) | Both clean ("Didn't find any major issues" / "No security issues") | | 8 | `c9a0f572` (stacked on coder#4350; rebased onto `main` without changes) | Explicit `@codex review` (code + security) | Both clean ("Didn't find any major issues" 21:57Z / "No security issues" 21:59Z, 👍) | | 9 | `76bff932` (rebased onto `main` after coder#4350 landed) | Explicit `@codex review` (code + security) | Both clean; merge blocked by the repo-wide `compaction1MRetry` content-filter failure (coder#4398), fixed by coder#4401 | | 10 | `bde7c0fe` (rebased onto `main` after coder#4401 landed; diff unchanged) | Explicit `@codex review` (code + security) | Security clean. Code P3: stale Astra comment claimed the catalog couples Astra and Sol → fixed in `7deeea6e`, replied and resolved | | 11 | this head (`7deeea6e`, comment-only fix) | Explicit `@codex review` (code + security) | Pending | | Advisory | — | One independent advisor | Recommended scope reduction and accuracy fixes before official release. Scope reduction realised by coder#4348 and coder#4350 landing first; this PR is the residual. | Post-cap work, retained in order: `f04892f`→`fcf5d0f` budget-comment accuracy; `782cca6`→`04bad77` maintainer-authorized provisional estimate; `d24d776` rebase integration; `870259a` official Sol launch + authorized Luna expansion; `40e4b2a6` verified Codex defaults, labels, route/pricing regressions, docs; `ce20ecd0` tool-aware `none` clamp + SDK patch; `bfc0906f` Nix hash refresh; `a4c7c156` model-boundary clamp; `2c4803c0` residual on `main` (SDK patch + clamp + Coder alias + Codex cap). Other rebase mappings: `01ca053`→`c47ba9c`, `252bba9`→`5363ca0`, `cb5ac4b`→`a866d96`, `64169a3`→`c0d5def`. The cap did not reset on rebase, handoff, scope expansion or re-scope. Backups of superseded heads: `a4c7c15635f3a865baa4b937618da17459b48209`, `2c4803c0c9481924ad682f969542a7a6db71e9e7`. Historical stop reason: implementation and validation were complete for both models, but the final head lacked review coverage under the exhausted cap. The later direct conditional merge instruction reopened delivery for one automatic final-head pair; its findings were then fixed under the user's explicit "get it merged" authorization through the normal gated merge path. When coder#4348 and then coder#4350 landed the same work first, this PR was reduced to the residual fixes above rather than closed. </details> --- _Generated with `xum` • Model: `anthropic:claude-opus-5-5` • Thinking: `xhigh` • Cost: `$281.40`_ <!-- mux-attribution: model=anthropic:claude-opus-5-5 thinking=xhigh costs=281.40 -->
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Bumps
packages/mux-compat/package.json(versionand the@coder/xumdependency pin) from 0.29.0 to 0.30.0 to match the root package after therelease: v0.30.0commit (81b0b744), which bumped only the rootpackage.json.Background
src/common/compat/productIdentity.test.ts› "keeps the published mux forwarding package version-locked to @coder/xum" assertslegacyPackageJson.version === packageJson.version. Since the release commit it fails onmain(run 35783501719) and on every PR's merge commit (e.g. #4259 run 35785546631, #4350), soRequiredis red repo-wide and the merge queue cannot admit anything. Same fix as #4048 for v0.28.3; release commits since (e.g. v0.28.5, #4175) bumped both files together.@coder/xum@0.30.0is already published (Publish to NPM run 35783501943), so the new pin resolves.Validation
bun test src/common/compat/productIdentity.test.tson this branch: 8 pass (the version-lock case fails onmainwithout it).Generated with
xum• Model:coder:anthropic/claude-fable-5-1• Thinking:xhigh• Cost:$174.60