ren worker folder adding orig, mv new one into root
This commit is contained in:
@@ -23,6 +23,7 @@ import os
|
||||
import shlex
|
||||
import sys
|
||||
import tempfile
|
||||
import tomllib
|
||||
import uuid
|
||||
from pathlib import Path
|
||||
|
||||
@@ -85,6 +86,32 @@ _INSTALL_CMD = (
|
||||
)
|
||||
|
||||
|
||||
# codex reserves its built-in provider ids, so the call-origin header needs a provider of
|
||||
# our own. A trial's origin is a constant, so it is a static http_headers literal here
|
||||
# rather than the env-var indirection the containers need — nothing to plumb into a
|
||||
# sandbox, and no way for a missing var to lose the attribution.
|
||||
PROXY_PROVIDER_TOML = """\
|
||||
model_provider = "llm-proxy"
|
||||
|
||||
[model_providers.llm-proxy]
|
||||
name = "LLM proxy"
|
||||
base_url = "${OPENAI_BASE_URL}"
|
||||
env_key = "OPENAI_API_KEY"
|
||||
wire_api = "responses"
|
||||
http_headers = { "X-Surge-Client-Metadata" = '{"origin":"harbor-trial"}' }
|
||||
"""
|
||||
# A custom provider reads its key from env_key and never from auth.json, so the proxy
|
||||
# path must carry this even when an auth file was uploaded.
|
||||
PROXY_KEY_VAR = "OPENAI_API_KEY"
|
||||
|
||||
|
||||
def proxy_provider_config(openai_base_url: str) -> dict:
|
||||
"""PROXY_PROVIDER_TOML as harbor's config dict, pointed at this trial's URL."""
|
||||
return tomllib.loads(PROXY_PROVIDER_TOML.replace("${OPENAI_BASE_URL}", openai_base_url))
|
||||
|
||||
|
||||
|
||||
|
||||
class SystemNodeCodex(Codex):
|
||||
# Set by install()'s probe, read by build_cli_flags(). Mirrors the claude adapter.
|
||||
_has_browser = False
|
||||
@@ -101,6 +128,39 @@ class SystemNodeCodex(Codex):
|
||||
self._get_env("OPENAI_API_KEY") or "", remote_auth_path
|
||||
)
|
||||
|
||||
def _proxy_provider_flags(self) -> str:
|
||||
"""`-c` overrides putting the trial on our own provider — the only place codex
|
||||
can be told to send the call-origin header.
|
||||
|
||||
On the command line rather than in config.toml because harbor writes that file
|
||||
itself, differently per version (0.20 hardcodes the block inline), while these
|
||||
flags are ours in every version.
|
||||
"""
|
||||
base_url = self._get_env("OPENAI_BASE_URL") or ""
|
||||
if "/llm_proxy/" not in base_url:
|
||||
return ""
|
||||
# A custom provider ignores auth.json, so leave that flow on the built-in
|
||||
# provider: losing attribution beats breaking the run's auth.
|
||||
if self._resolve_auth_json_path():
|
||||
return ""
|
||||
config = proxy_provider_config(base_url)
|
||||
provider_id = config["model_provider"]
|
||||
parts = [f"-c model_provider={provider_id}"]
|
||||
for key, value in config["model_providers"][provider_id].items():
|
||||
for path, leaf in (
|
||||
[(f"{key}.{k}", v) for k, v in value.items()]
|
||||
if isinstance(value, dict)
|
||||
else [(key, value)]
|
||||
):
|
||||
# A TOML literal string, since the header value is JSON and carries its
|
||||
# own double quotes.
|
||||
quoted = f"'{leaf}'" if '"' in leaf else f'"{leaf}"'
|
||||
parts.append(
|
||||
"-c "
|
||||
+ shlex.quote(f"model_providers.{provider_id}.{path}={quoted}")
|
||||
)
|
||||
return " ".join(parts)
|
||||
|
||||
def _refuse_shell_hostile_key(self) -> None:
|
||||
"""Harbor's own Codex.run interpolates the key into a heredoc, so a key it cannot
|
||||
escape would 401 with no stated cause. Refuse up front instead."""
|
||||
@@ -127,6 +187,11 @@ class SystemNodeCodex(Codex):
|
||||
reductions = load_harness_registry().require("codex").agent_config_flags()
|
||||
if reductions:
|
||||
flags = f"{flags} {reductions}".strip()
|
||||
# Both run paths go through here, so this is where the trial picks up the
|
||||
# provider that carries the call-origin header.
|
||||
provider = self._proxy_provider_flags()
|
||||
if provider:
|
||||
flags = f"{flags} {provider}".strip()
|
||||
return f"{flags} {self._browser_flag()}".strip() if self._browser_flag() else flags
|
||||
|
||||
def _browser_flag(self) -> str:
|
||||
@@ -467,11 +532,16 @@ class NativeSnapshotCodex(SystemNodeCodex):
|
||||
)
|
||||
if openai_base_url := self._get_env("OPENAI_BASE_URL"):
|
||||
env["OPENAI_BASE_URL"] = openai_base_url
|
||||
# The provider that carries the origin header rides in on build_cli_flags,
|
||||
# so this stays harbor's plain root key.
|
||||
setup_command += (
|
||||
'\ncat >>"$CODEX_HOME/config.toml" <<TOML\n'
|
||||
'openai_base_url = "${OPENAI_BASE_URL}"\n'
|
||||
"TOML"
|
||||
)
|
||||
# env_key names this, and the provider cannot fall back to auth.json.
|
||||
if proxy_key := self._get_env(PROXY_KEY_VAR):
|
||||
env[PROXY_KEY_VAR] = proxy_key
|
||||
skills_command = self._build_register_skills_command()
|
||||
if skills_command:
|
||||
setup_command += f"\n{skills_command}"
|
||||
|
||||
Reference in New Issue
Block a user