Skip to content

Add a native gRPC client for cloud thread resume and attach - #50113

Merged
copyberry[bot] merged 1 commit into
mainfrom
copyberry/codex-internal-to-codex-oss/55db70438bb5e59272c6995c67a46ced5fa28ff4
Oct 1, 2026
Merged

copyberry[bot] merged 1 commit into
mainfrom
copyberry/codex-internal-to-codex-oss/55db70438bb5e59272c6995c67a46ced5fa28ff4

Conversation

@copyberry

@copyberry copyberry Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

Add a native gRPC client for cloud thread resume and attach

What changed

Add codex-cloud-client, a reusable Rust client for ThreadService.Resume and live ThreadService.Attach over HTTP/2. Callers supply the native gRPC origin, bearer token, account ID, and HttpClientFactory.

  • Reuse shared proxy, custom CA, and network policy handling for HTTPS. Reject redirects and allow plaintext HTTP only on direct loopback with unrestricted, unmanaged policy.
  • Preserve notification and server-request protobuf payloads as opaque bytes and expose native gRPC status details while redacting credentials, payloads, and error details from diagnostics.
  • Bound resume and attach setup to 150 seconds without retrying requests or imposing an idle deadline on live streams. Attach ends on its first error and provides no history or automatic reconnect.
  • Select Rustls in HttpClientBuilder::http2_prior_knowledge() so HTTPS advertises h2 through ALPN.

Include a standalone attach example and documentation of admission semantics and stream behavior.

Testing

Add HTTP/2 fixture tests for protobuf framing, authentication metadata, status trailers, event preservation, malformed responses, stream cancellation, redirect rejection, and diagnostic redaction. Add checks for unsafe origins, network policy restrictions, and TLS h2 advertisement.

## What changed

Add `codex-cloud-client`, a reusable Rust client for `ThreadService.Resume` and live `ThreadService.Attach` over HTTP/2. Callers supply the native gRPC origin, bearer token, account ID, and `HttpClientFactory`.

- Reuse shared proxy, custom CA, and network policy handling for HTTPS. Reject redirects and allow plaintext HTTP only on direct loopback with unrestricted, unmanaged policy.
- Preserve notification and server-request protobuf payloads as opaque bytes and expose native gRPC status details while redacting credentials, payloads, and error details from diagnostics.
- Bound resume and attach setup to 150 seconds without retrying requests or imposing an idle deadline on live streams. Attach ends on its first error and provides no history or automatic reconnect.
- Select Rustls in `HttpClientBuilder::http2_prior_knowledge()` so HTTPS advertises `h2` through ALPN.

Include a standalone attach example and documentation of admission semantics and stream behavior.

## Testing

Add HTTP/2 fixture tests for protobuf framing, authentication metadata, status trailers, event preservation, malformed responses, stream cancellation, redirect rejection, and diagnostic redaction. Add checks for unsafe origins, network policy restrictions, and TLS `h2` advertisement.

GitOrigin-RevId: 55db70438bb5e59272c6995c67a46ced5fa28ff4
@copyberry
copyberry Bot force-pushed the copyberry/codex-internal-to-codex-oss/55db70438bb5e59272c6995c67a46ced5fa28ff4 branch from 4973d78 to b707714 Compare October 1, 2026 22:32
@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor


Thank you for your submission, we really appreciate it. Like many open-source projects, we ask that you sign our Contributor License Agreement before we can accept your contribution. You can sign the CLA by just posting a Pull Request Comment same as the below format.


I have read the CLA Document and I hereby sign the CLA


You can retrigger this bot by commenting recheck in this Pull Request. Posted by the CLA Assistant Lite bot.

@copyberry
copyberry Bot merged commit b707714 into main Oct 1, 2026
1 check failed
@copyberry
copyberry Bot deleted the copyberry/codex-internal-to-codex-oss/55db70438bb5e59272c6995c67a46ced5fa28ff4 branch October 1, 2026 22:32
@github-actions github-actions Bot locked and limited conversation to collaborators Oct 1, 2026
@GuilhermeP96
GuilhermeP96 deployed to issue-triage October 1, 2026 22:42 — with GitHub Actions Active
@GuilhermeP96
GuilhermeP96 deployed to issue-triage October 1, 2026 22:42 — with GitHub Actions Active
@GuilhermeP96
GuilhermeP96 deployed to issue-triage October 1, 2026 22:42 — with GitHub Actions Active
@stansult
stansult deployed to issue-triage October 1, 2026 22:47 — with GitHub Actions Active
@stansult
stansult deployed to issue-triage October 1, 2026 22:47 — with GitHub Actions Active
@stansult
stansult deployed to issue-triage October 1, 2026 22:47 — with GitHub Actions Active
@CCcolab
CCcolab deployed to issue-triage October 1, 2026 22:53 — with GitHub Actions Active
@CCcolab
CCcolab deployed to issue-triage October 1, 2026 22:53 — with GitHub Actions Active
@CCcolab
CCcolab deployed to issue-triage October 1, 2026 22:53 — with GitHub Actions Active
@karappo-kara
karappo-kara deployed to issue-triage October 1, 2026 23:09 — with GitHub Actions Active
@karappo-kara
karappo-kara deployed to issue-triage October 1, 2026 23:09 — with GitHub Actions Active
@karappo-kara
karappo-kara deployed to issue-triage October 1, 2026 23:09 — with GitHub Actions Active
@karappo-kara
karappo-kara deployed to issue-triage October 1, 2026 23:10 — with GitHub Actions Active
@MikeSilvis
MikeSilvis deployed to issue-triage October 1, 2026 23:40 — with GitHub Actions Active
@MikeSilvis
MikeSilvis deployed to issue-triage October 1, 2026 23:40 — with GitHub Actions Active
@MikeSilvis
MikeSilvis deployed to issue-triage October 1, 2026 23:40 — with GitHub Actions Active
@debuggerone
debuggerone deployed to issue-triage October 1, 2026 23:55 — with GitHub Actions Active
@debuggerone
debuggerone deployed to issue-triage October 1, 2026 23:55 — with GitHub Actions Active
@debuggerone
debuggerone deployed to issue-triage October 1, 2026 23:55 — with GitHub Actions Active
@Shaisolaris
Shaisolaris deployed to issue-triage October 1, 2026 23:57 — with GitHub Actions Active
@Shaisolaris
Shaisolaris deployed to issue-triage October 1, 2026 23:57 — with GitHub Actions Active
@Shaisolaris
Shaisolaris deployed to issue-triage October 1, 2026 23:57 — with GitHub Actions Active
@debuggerone
debuggerone deployed to issue-triage October 1, 2026 23:58 — with GitHub Actions Active
@debuggerone
debuggerone deployed to issue-triage October 2, 2026 00:00 — with GitHub Actions Active
@debuggerone
debuggerone deployed to issue-triage October 2, 2026 00:00 — with GitHub Actions Active
@debuggerone
debuggerone deployed to issue-triage October 2, 2026 00:00 — with GitHub Actions Active
@onigirito
onigirito deployed to issue-triage October 2, 2026 00:07 — with GitHub Actions Active
@onigirito
onigirito deployed to issue-triage October 2, 2026 00:07 — with GitHub Actions Active
@onigirito
onigirito deployed to issue-triage October 2, 2026 00:07 — with GitHub Actions Active
@qalvinapp
qalvinapp deployed to issue-triage October 2, 2026 00:07 — with GitHub Actions Active
@qalvinapp
qalvinapp deployed to issue-triage October 2, 2026 00:07 — with GitHub Actions Active
@qalvinapp
qalvinapp deployed to issue-triage October 2, 2026 00:07 — with GitHub Actions Active
@qalvinapp
qalvinapp deployed to issue-triage October 2, 2026 00:08 — with GitHub Actions Active
@harryshawk
harryshawk deployed to issue-triage October 2, 2026 00:21 — with GitHub Actions Active
@harryshawk
harryshawk deployed to issue-triage October 2, 2026 00:21 — with GitHub Actions Active
@harryshawk
harryshawk deployed to issue-triage October 2, 2026 00:21 — with GitHub Actions Active

This branch was successfully deployed

1 active deployment
issue-triage — b707714a Deployed Oct 2, 2026 by harryshawk via Translate non-English issue #16755
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.