ren worker folder adding orig, mv new one into root

This commit is contained in:
2026-09-25 10:34:29 -04:00
parent 10f0668e32
commit 5b010039d7
1308 changed files with 44597 additions and 1511 deletions

View File

@@ -23,6 +23,7 @@ import os
import shlex
import sys
import tempfile
import tomllib
import uuid
from pathlib import Path
@@ -85,6 +86,32 @@ _INSTALL_CMD = (
)
# codex reserves its built-in provider ids, so the call-origin header needs a provider of
# our own. A trial's origin is a constant, so it is a static http_headers literal here
# rather than the env-var indirection the containers need — nothing to plumb into a
# sandbox, and no way for a missing var to lose the attribution.
PROXY_PROVIDER_TOML = """\
model_provider = "llm-proxy"
[model_providers.llm-proxy]
name = "LLM proxy"
base_url = "${OPENAI_BASE_URL}"
env_key = "OPENAI_API_KEY"
wire_api = "responses"
http_headers = { "X-Surge-Client-Metadata" = '{"origin":"harbor-trial"}' }
"""
# A custom provider reads its key from env_key and never from auth.json, so the proxy
# path must carry this even when an auth file was uploaded.
PROXY_KEY_VAR = "OPENAI_API_KEY"
def proxy_provider_config(openai_base_url: str) -> dict:
"""PROXY_PROVIDER_TOML as harbor's config dict, pointed at this trial's URL."""
return tomllib.loads(PROXY_PROVIDER_TOML.replace("${OPENAI_BASE_URL}", openai_base_url))
class SystemNodeCodex(Codex):
# Set by install()'s probe, read by build_cli_flags(). Mirrors the claude adapter.
_has_browser = False
@@ -101,6 +128,39 @@ class SystemNodeCodex(Codex):
self._get_env("OPENAI_API_KEY") or "", remote_auth_path
)
def _proxy_provider_flags(self) -> str:
"""`-c` overrides putting the trial on our own provider — the only place codex
can be told to send the call-origin header.
On the command line rather than in config.toml because harbor writes that file
itself, differently per version (0.20 hardcodes the block inline), while these
flags are ours in every version.
"""
base_url = self._get_env("OPENAI_BASE_URL") or ""
if "/llm_proxy/" not in base_url:
return ""
# A custom provider ignores auth.json, so leave that flow on the built-in
# provider: losing attribution beats breaking the run's auth.
if self._resolve_auth_json_path():
return ""
config = proxy_provider_config(base_url)
provider_id = config["model_provider"]
parts = [f"-c model_provider={provider_id}"]
for key, value in config["model_providers"][provider_id].items():
for path, leaf in (
[(f"{key}.{k}", v) for k, v in value.items()]
if isinstance(value, dict)
else [(key, value)]
):
# A TOML literal string, since the header value is JSON and carries its
# own double quotes.
quoted = f"'{leaf}'" if '"' in leaf else f'"{leaf}"'
parts.append(
"-c "
+ shlex.quote(f"model_providers.{provider_id}.{path}={quoted}")
)
return " ".join(parts)
def _refuse_shell_hostile_key(self) -> None:
"""Harbor's own Codex.run interpolates the key into a heredoc, so a key it cannot
escape would 401 with no stated cause. Refuse up front instead."""
@@ -127,6 +187,11 @@ class SystemNodeCodex(Codex):
reductions = load_harness_registry().require("codex").agent_config_flags()
if reductions:
flags = f"{flags} {reductions}".strip()
# Both run paths go through here, so this is where the trial picks up the
# provider that carries the call-origin header.
provider = self._proxy_provider_flags()
if provider:
flags = f"{flags} {provider}".strip()
return f"{flags} {self._browser_flag()}".strip() if self._browser_flag() else flags
def _browser_flag(self) -> str:
@@ -467,11 +532,16 @@ class NativeSnapshotCodex(SystemNodeCodex):
)
if openai_base_url := self._get_env("OPENAI_BASE_URL"):
env["OPENAI_BASE_URL"] = openai_base_url
# The provider that carries the origin header rides in on build_cli_flags,
# so this stays harbor's plain root key.
setup_command += (
'\ncat >>"$CODEX_HOME/config.toml" <<TOML\n'
'openai_base_url = "${OPENAI_BASE_URL}"\n'
"TOML"
)
# env_key names this, and the provider cannot fall back to auth.json.
if proxy_key := self._get_env(PROXY_KEY_VAR):
env[PROXY_KEY_VAR] = proxy_key
skills_command = self._build_register_skills_command()
if skills_command:
setup_command += f"\n{skills_command}"