Skip to content

Add system proxy fallback for login and startup requests - #46562

Merged
copyberry[bot] merged 1 commit into
mainfrom
copyberry/codex-internal-to-codex-oss/854eeeac186bb4865218ce645019c1e4bff85425
Sep 19, 2026
Merged

copyberry[bot] merged 1 commit into
mainfrom
copyberry/codex-internal-to-codex-oss/854eeeac186bb4865218ce645019c1e4bff85425

Conversation

@copyberry

@copyberry copyberry Bot commented Sep 19, 2026 •

Copy link
Copy Markdown

Add system proxy fallback for login and startup requests

Why

Login and enterprise configuration bootstrap can fail when their endpoints are reachable only through the system proxy, before cloud configuration can enable respect_system_proxy.

What changed

  • Enable features.system_proxy_fallback by default, honor managed feature requirements, and prevent project configuration from changing it.
  • Retry account discovery and cloud configuration GETs through the system proxy after connection failures or timeouts, bounding the initial request and body read to five seconds.
  • Retry OAuth authorization-code exchange only on connection failures before any redirect, with a ten-second connection timeout. Reuse the successful client for the subsequent API-key exchange to avoid changing routes.
  • Increase workspace discovery and cloud configuration timeouts to 15 and 20 seconds, respectively, to accommodate fallback.

Testing

Add coverage for proxy-only browser login through the first completed turn, including cloud configuration enabling respect_system_proxy without a restart. Cover stalled GET bodies, preserved request headers, disabled fallback, managed requirements, and project configuration restrictions. Verify that OAuth HTTP errors, redirects followed by connection failures, and failures after sending the POST do not trigger proxy retries, while successful redirects remain supported.

## Why

Login and enterprise configuration bootstrap can fail when their endpoints are reachable only through the system proxy, before cloud configuration can enable `respect_system_proxy`.

## What changed

- Enable `features.system_proxy_fallback` by default, honor managed feature requirements, and prevent project configuration from changing it.
- Retry account discovery and cloud configuration GETs through the system proxy after connection failures or timeouts, bounding the initial request and body read to five seconds.
- Retry OAuth authorization-code exchange only on connection failures before any redirect, with a ten-second connection timeout. Reuse the successful client for the subsequent API-key exchange to avoid changing routes.
- Increase workspace discovery and cloud configuration timeouts to 15 and 20 seconds, respectively, to accommodate fallback.

## Testing

Add coverage for proxy-only browser login through the first completed turn, including cloud configuration enabling `respect_system_proxy` without a restart. Cover stalled GET bodies, preserved request headers, disabled fallback, managed requirements, and project configuration restrictions. Verify that OAuth HTTP errors, redirects followed by connection failures, and failures after sending the POST do not trigger proxy retries, while successful redirects remain supported.

GitOrigin-RevId: 854eeeac186bb4865218ce645019c1e4bff85425
@copyberry
copyberry Bot force-pushed the copyberry/codex-internal-to-codex-oss/854eeeac186bb4865218ce645019c1e4bff85425 branch from e808e9a to 3bb0a53 Compare September 19, 2026 01:37
@copyberry
copyberry Bot merged commit 3bb0a53 into main Sep 19, 2026
1 check passed
@copyberry
copyberry Bot deleted the copyberry/codex-internal-to-codex-oss/854eeeac186bb4865218ce645019c1e4bff85425 branch September 19, 2026 01:37
@github-actions github-actions Bot locked and limited conversation to collaborators Sep 19, 2026
@kwokpia
kwokpia deployed to issue-triage September 19, 2026 01:40 — with GitHub Actions Active
@kwokpia
kwokpia deployed to issue-triage September 19, 2026 01:40 — with GitHub Actions Active
@kwokpia
kwokpia deployed to issue-triage September 19, 2026 01:40 — with GitHub Actions Active
@kwokpia
kwokpia deployed to issue-triage September 19, 2026 01:41 — with GitHub Actions Active

This branch was successfully deployed

1 active deployment
issue-triage — 3bb0a530 Deployed Sep 19, 2026 by kwokpia via Identify potential duplicates (open issues fallback) #46667
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants