修正 API Key app-server 的启动级 remote-control 禁用
使用 Codex 内部启动环境变量提前禁用 remote-control 删除无效的 remoteControl/disable RPC 更新 fixture、测试和技术文档
This commit is contained in:
@@ -11,6 +11,8 @@ use tokio::sync::{mpsc, oneshot, Mutex};
|
||||
|
||||
const GAME_CREATOR_CODEX_APP_SERVER_PROVIDER_ID: &str = "genarrative_agc";
|
||||
const GAME_CREATOR_CODEX_APP_SERVER_API_KEY_ENV: &str = "GENARRATIVE_AGC_CODEX_API_KEY";
|
||||
const GAME_CREATOR_CODEX_APP_SERVER_REMOTE_CONTROL_DISABLED_ENV: &str =
|
||||
"CODEX_INTERNAL_APP_SERVER_REMOTE_CONTROL_DISABLED";
|
||||
const GAME_CREATOR_CODEX_AUTH_BRIDGE_API_BASE_URL: &str = "https://api.openai.com/v1";
|
||||
const GAME_CREATOR_CODEX_APP_SERVER_PROTOCOL: &str = "genarrative-codex-app-server.v3";
|
||||
const GAME_CREATOR_CODEX_APP_SERVER_LINE_MAX_BYTES: usize = 4 * 1024 * 1024;
|
||||
@@ -1566,8 +1568,12 @@ impl CodexAppServerConnection {
|
||||
game_creator_codex_cli_minimal_environment(&mut command);
|
||||
if remote_control_disable_reason.is_some() {
|
||||
// API-key and provider-proxy sessions have no ChatGPT auth.json.
|
||||
// Keep expected remote-control startup diagnostics out of the
|
||||
// child log after the protocol-level disable below succeeds.
|
||||
// Disable remote-control before its websocket task can enter the
|
||||
// authentication retry loop.
|
||||
command.env(
|
||||
GAME_CREATOR_CODEX_APP_SERVER_REMOTE_CONTROL_DISABLED_ENV,
|
||||
"1",
|
||||
);
|
||||
command.env("RUST_LOG", "warn");
|
||||
}
|
||||
if let Some(tool_bridge) = tool_bridge.as_ref() {
|
||||
@@ -1656,10 +1662,6 @@ impl CodexAppServerConnection {
|
||||
.await
|
||||
.map_err(platform_llm::LlmError::Transport)?;
|
||||
if let Some(reason) = remote_control_disable_reason {
|
||||
connection
|
||||
.request("remoteControl/disable", serde_json::json!({}))
|
||||
.await
|
||||
.map_err(platform_llm::LlmError::Transport)?;
|
||||
eprintln!("agent.codex_app_server.remote_control disabled reason={reason}");
|
||||
}
|
||||
if let Some(skill_root) = connection.inner._skill_root.as_ref() {
|
||||
@@ -3723,6 +3725,7 @@ case "$GENARRATIVE_AGC_CODEX_API_KEY" in
|
||||
agc-provider-session-*) ;;
|
||||
*) exit 81 ;;
|
||||
esac
|
||||
[ "$CODEX_INTERNAL_APP_SERVER_REMOTE_CONTROL_DISABLED" = "1" ] || exit 90
|
||||
[ "$GENARRATIVE_AGC_CODEX_API_KEY" != "fixture-secret" ] || exit 82
|
||||
case " $* " in *"fixture-secret"*) exit 83 ;; esac
|
||||
case " $* " in *'--disable hooks'*) ;; *) exit 84 ;; esac
|
||||
@@ -3731,15 +3734,12 @@ case "$initialize" in *'"method":"initialize"'*) ;; *) exit 85 ;; esac
|
||||
printf '%s\n' '{"id":1,"result":{"codexHome":"/tmp","platformFamily":"unix","platformOs":"linux","userAgent":"fixture"}}'
|
||||
IFS= read -r initialized
|
||||
case "$initialized" in *'"method":"initialized"'*) ;; *) exit 86 ;; esac
|
||||
IFS= read -r remote_control_disable
|
||||
case "$remote_control_disable" in *'"method":"remoteControl/disable"'*) ;; *) exit 89 ;; esac
|
||||
printf '%s\n' '{"id":2,"result":{}}'
|
||||
IFS= read -r extra_roots
|
||||
case "$extra_roots" in *'"method":"skills/extraRoots/set"'*) ;; *) exit 87 ;; esac
|
||||
printf '%s\n' '{"id":3,"result":{}}'
|
||||
printf '%s\n' '{"id":2,"result":{}}'
|
||||
IFS= read -r skills_list
|
||||
case "$skills_list" in *'"method":"skills/list"'*) ;; *) exit 88 ;; esac
|
||||
printf '%s\n' '{"id":4,"result":{"data":[{"skills":[{"name":"agc-browser-playtest"},{"name":"agc-client-projection"},{"name":"agc-project-structure"},{"name":"agc-web-game-development"},{"name":"taonier-art-assets"}],"errors":[]}]}}'
|
||||
printf '%s\n' '{"id":3,"result":{"data":[{"skills":[{"name":"agc-browser-playtest"},{"name":"agc-client-projection"},{"name":"agc-project-structure"},{"name":"agc-web-game-development"},{"name":"taonier-art-assets"}],"errors":[]}]}}'
|
||||
while IFS= read -r line; do :; done
|
||||
"#,
|
||||
)
|
||||
@@ -4048,7 +4048,7 @@ while IFS= read -r line; do :; done
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn remote_control_is_disabled_when_the_isolated_home_has_no_chatgpt_auth() {
|
||||
fn remote_control_disable_policy_matches_the_credential_boundary() {
|
||||
let api_key = CodexAppServerCredential::AppDataKey {
|
||||
fingerprint: "api-key".to_string(),
|
||||
};
|
||||
@@ -4203,15 +4203,12 @@ case "$initialize" in *'"method":"initialize"'*) ;; *) exit 43 ;; esac
|
||||
printf '%s\n' '{"id":1,"result":{"codexHome":"/tmp","platformFamily":"unix","platformOs":"linux","userAgent":"fixture"}}'
|
||||
IFS= read -r initialized
|
||||
case "$initialized" in *'"method":"initialized"'*) ;; *) exit 44 ;; esac
|
||||
IFS= read -r remote_control_disable
|
||||
case "$remote_control_disable" in *'"method":"remoteControl/disable"'*) ;; *) exit 47 ;; esac
|
||||
printf '%s\n' '{"id":2,"result":{}}'
|
||||
IFS= read -r thread_start
|
||||
case "$thread_start" in *'"method":"thread/start"'*'"modelProvider":"genarrative_agc"'*) ;; *) exit 45 ;; esac
|
||||
printf '%s\n' '{"id":3,"result":{"thread":{"id":"thread-1"}}}'
|
||||
printf '%s\n' '{"id":2,"result":{"thread":{"id":"thread-1"}}}'
|
||||
IFS= read -r turn_start
|
||||
case "$turn_start" in *'"method":"turn/start"'*'"outputSchema"'*) ;; *) exit 46 ;; esac
|
||||
printf '%s\n' '{"id":4,"result":{"turn":{"id":"turn-1","items":[],"status":"inProgress"}}}'
|
||||
printf '%s\n' '{"id":3,"result":{"turn":{"id":"turn-1","items":[],"status":"inProgress"}}}'
|
||||
printf '%s\n' '{"method":"turn/started","params":{"threadId":"thread-1","turn":{"id":"turn-1","items":[],"status":"inProgress"}}}'
|
||||
printf '%s\n' '{"method":"item/fileChange/patchUpdated","params":{"threadId":"thread-1","turnId":"turn-1","itemId":"change-1","patch":"*** SECRET PATCH /private/project"}}'
|
||||
printf '%s\n' '{"method":"item/commandExecution/outputDelta","params":{"threadId":"thread-1","turnId":"turn-1","itemId":"command-1","delta":"Bearer secret-command-output"}}'
|
||||
@@ -4327,17 +4324,14 @@ case "$initialize" in *'"method":"initialize"'*) ;; *) exit 70 ;; esac
|
||||
printf '%s\n' '{"id":1,"result":{"codexHome":"/tmp","platformFamily":"unix","platformOs":"linux","userAgent":"fixture"}}'
|
||||
IFS= read -r initialized
|
||||
case "$initialized" in *'"method":"initialized"'*) ;; *) exit 71 ;; esac
|
||||
IFS= read -r remote_control_disable
|
||||
case "$remote_control_disable" in *'"method":"remoteControl/disable"'*) ;; *) exit 76 ;; esac
|
||||
printf '%s\n' '{"id":2,"result":{}}'
|
||||
IFS= read -r thread_start
|
||||
case "$thread_start" in *'"method":"thread/start"'*'"approvalPolicy":"never"'*'"sandbox":"read-only"'*) ;; *) exit 72 ;; esac
|
||||
case "$thread_start" in *'workspace-write'*|*'workspaceWrite'*|*'writableRoots'*) exit 73 ;; esac
|
||||
printf '%s\n' '{"id":3,"result":{"thread":{"id":"home-thread"}}}'
|
||||
printf '%s\n' '{"id":2,"result":{"thread":{"id":"home-thread"}}}'
|
||||
IFS= read -r turn_start
|
||||
case "$turn_start" in *'"method":"turn/start"'*'"approvalPolicy":"never"'*) ;; *) exit 74 ;; esac
|
||||
case "$turn_start" in *'"sandboxPolicy"'*|*'workspaceWrite'*|*'writableRoots'*) exit 75 ;; esac
|
||||
printf '%s\n' '{"id":4,"result":{"turn":{"id":"home-turn","items":[],"status":"inProgress"}}}'
|
||||
printf '%s\n' '{"id":3,"result":{"turn":{"id":"home-turn","items":[],"status":"inProgress"}}}'
|
||||
printf '%s\n' '{"method":"item/completed","params":{"threadId":"home-thread","turnId":"home-turn","item":{"id":"item-1","type":"fileChange"}}}'
|
||||
while IFS= read -r line; do :; done
|
||||
"#,
|
||||
@@ -4389,18 +4383,15 @@ while IFS= read -r line; do :; done
|
||||
IFS= read -r initialize
|
||||
printf '%s\n' '{"id":1,"result":{"codexHome":"/tmp","platformFamily":"unix","platformOs":"linux","userAgent":"fixture"}}'
|
||||
IFS= read -r initialized
|
||||
IFS= read -r remote_control_disable
|
||||
case "$remote_control_disable" in *'"method":"remoteControl/disable"'*) ;; *) exit 77 ;; esac
|
||||
printf '%s\n' '{"id":2,"result":{}}'
|
||||
IFS= read -r thread_start
|
||||
printf '%s\n' '{"id":3,"result":{"thread":{"id":"thread-cancel"}}}'
|
||||
printf '%s\n' '{"id":2,"result":{"thread":{"id":"thread-cancel"}}}'
|
||||
IFS= read -r turn_start
|
||||
sleep 0.2
|
||||
printf '%s\n' '{"id":4,"result":{"turn":{"id":"turn-cancel","items":[],"status":"inProgress"}}}'
|
||||
printf '%s\n' '{"id":3,"result":{"turn":{"id":"turn-cancel","items":[],"status":"inProgress"}}}'
|
||||
IFS= read -r interrupt
|
||||
case "$interrupt" in *'"method":"turn/interrupt"'*'"turnId":"turn-cancel"'*) ;; *) exit 51 ;; esac
|
||||
: > "$HOME/interrupt-seen"
|
||||
printf '%s\n' '{"id":5,"result":{}}'
|
||||
printf '%s\n' '{"id":4,"result":{}}'
|
||||
while IFS= read -r line; do :; done
|
||||
"#,
|
||||
)
|
||||
@@ -4454,13 +4445,10 @@ while IFS= read -r line; do :; done
|
||||
IFS= read -r initialize
|
||||
printf '%s\n' '{"id":1,"result":{"codexHome":"/tmp","platformFamily":"unix","platformOs":"linux","userAgent":"fixture"}}'
|
||||
IFS= read -r initialized
|
||||
IFS= read -r remote_control_disable
|
||||
case "$remote_control_disable" in *'"method":"remoteControl/disable"'*) ;; *) exit 78 ;; esac
|
||||
printf '%s\n' '{"id":2,"result":{}}'
|
||||
IFS= read -r thread_start
|
||||
printf '%s\n' '{"id":3,"result":{"thread":{"id":"thread-timeout"}}}'
|
||||
printf '%s\n' '{"id":2,"result":{"thread":{"id":"thread-timeout"}}}'
|
||||
IFS= read -r turn_start
|
||||
printf '%s\n' '{"id":4,"result":{"turn":{"id":"turn-timeout","items":[],"status":"inProgress"}}}'
|
||||
printf '%s\n' '{"id":3,"result":{"turn":{"id":"turn-timeout","items":[],"status":"inProgress"}}}'
|
||||
while IFS= read -r line; do :; done
|
||||
"#,
|
||||
)
|
||||
|
||||
Reference in New Issue
Block a user