Skip to content

fix(auth): close transport after workload cleanup failure - #1146

Open
dpiet-oai wants to merge 2 commits into
mainfrom
castiron/promotions/pr-181
Open

dpiet-oai wants to merge 2 commits into
mainfrom
castiron/promotions/pr-181

Conversation

@dpiet-oai

Copy link
Copy Markdown
Contributor

When workload-identity authentication cleanup throws, the HTTP transport is now still closed. The first failure is preserved, with a distinct transport failure attached as a suppressed exception.

Fixes #882

Adapted from #883 by @sylvesterkaczmarek, with additional tests for delegate-only failure and identical exceptions.

Validation: 12 focused cleanup tests passed; security-focused and adversarial reviews found no blocking issues.

Castiron-Internal-PR: openai/openai-java-internal#181
Castiron-Source-SHA: 99d7b3139cef86814ebf1f3f98f1965333cbae2e
Castiron-Public-Base-SHA: 362468e
@github-actions

github-actions Bot commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

Castiron custom code

Evaluated main: 362468ef61b3605dda827c2b0492258eaf9edb50.

✅ No new custom-code files detected.

91 mixed files remain; 0 existing customizations changed.

Compared 362468ef61b3 → 73a523eecf12. Generated baselines verified.

91 existing customizations unchanged
  • openai-java-core/src/main/kotlin/com/openai/models/audio/AudioResponseFormat.kt
  • openai-java-core/src/main/kotlin/com/openai/models/beta/agents/vaults/credentials/CredentialAuth.kt
  • openai-java-core/src/main/kotlin/com/openai/models/beta/agents/vaults/credentials/CredentialAuthCreateParam.kt
  • openai-java-core/src/main/kotlin/com/openai/models/beta/agents/vaults/credentials/CredentialAuthRotateParam.kt
  • openai-java-core/src/main/kotlin/com/openai/models/beta/responses/BetaResponse.kt
  • openai-java-core/src/main/kotlin/com/openai/models/beta/responses/BetaResponseStreamEvent.kt
  • openai-java-core/src/main/kotlin/com/openai/models/beta/responses/BetaResponsesServerEvent.kt
  • openai-java-core/src/main/kotlin/com/openai/models/chat/completions/ChatCompletionCreateParams.kt
  • openai-java-core/src/main/kotlin/com/openai/models/chat/completions/ChatCompletionMessageFunctionToolCall.kt
  • openai-java-core/src/main/kotlin/com/openai/models/chat/completions/ChatCompletionToolMessageParam.kt
  • openai-java-core/src/main/kotlin/com/openai/models/embeddings/Embedding.kt
  • openai-java-core/src/main/kotlin/com/openai/models/embeddings/EmbeddingCreateParams.kt
  • openai-java-core/src/main/kotlin/com/openai/models/responses/Response.kt
  • openai-java-core/src/main/kotlin/com/openai/models/responses/ResponseCreateParams.kt
  • openai-java-core/src/main/kotlin/com/openai/models/responses/ResponseFunctionToolCall.kt
  • openai-java-core/src/main/kotlin/com/openai/models/responses/ResponseFunctionWebSearch.kt
  • openai-java-core/src/main/kotlin/com/openai/models/responses/ResponseInputItem.kt
  • openai-java-core/src/main/kotlin/com/openai/models/responses/ResponseStreamEvent.kt
  • openai-java-core/src/main/kotlin/com/openai/models/responses/ResponseTextConfig.kt
  • openai-java-core/src/main/kotlin/com/openai/models/responses/ResponsesServerEvent.kt
  • openai-java-core/src/main/kotlin/com/openai/models/videos/Video.kt
  • openai-java-core/src/main/kotlin/com/openai/models/webhooks/UnwrapWebhookEvent.kt
  • openai-java-core/src/main/kotlin/com/openai/models/webhooks/WebhookEndpointWithSecret.kt
  • openai-java-core/src/main/kotlin/com/openai/services/async/BetaServiceAsync.kt
  • openai-java-core/src/main/kotlin/com/openai/services/async/BetaServiceAsyncImpl.kt
  • openai-java-core/src/main/kotlin/com/openai/services/async/ImageServiceAsyncImpl.kt
  • openai-java-core/src/main/kotlin/com/openai/services/async/ResponseServiceAsync.kt
  • openai-java-core/src/main/kotlin/com/openai/services/async/ResponseServiceAsyncImpl.kt
  • openai-java-core/src/main/kotlin/com/openai/services/async/SkillServiceAsyncImpl.kt
  • openai-java-core/src/main/kotlin/com/openai/services/async/VideoServiceAsyncImpl.kt
  • openai-java-core/src/main/kotlin/com/openai/services/async/WebhookServiceAsync.kt
  • openai-java-core/src/main/kotlin/com/openai/services/async/WebhookServiceAsyncImpl.kt
  • openai-java-core/src/main/kotlin/com/openai/services/async/audio/TranscriptionServiceAsyncImpl.kt
  • openai-java-core/src/main/kotlin/com/openai/services/async/audio/TranslationServiceAsyncImpl.kt
  • openai-java-core/src/main/kotlin/com/openai/services/async/audio/VoiceServiceAsyncImpl.kt
  • openai-java-core/src/main/kotlin/com/openai/services/async/beta/agents/SessionServiceAsync.kt
  • openai-java-core/src/main/kotlin/com/openai/services/async/beta/agents/SessionServiceAsyncImpl.kt
  • openai-java-core/src/main/kotlin/com/openai/services/async/chat/ChatCompletionServiceAsync.kt
  • openai-java-core/src/main/kotlin/com/openai/services/async/finetuning/checkpoints/PermissionServiceAsyncImpl.kt
  • openai-java-core/src/main/kotlin/com/openai/services/async/skills/VersionServiceAsyncImpl.kt

51 more in the full report.

A changed generated baseline means this report cannot reliably identify which handwritten lines changed.

Inspect the custom-code diff

Download the exact patch produced by this run (requires repository access):

gh run download 37361400022 --repo openai/openai-java \
  --name castiron-custom-code-37361400022-1 --dir /tmp/castiron-custom-code-37361400022-1
git apply --stat /tmp/castiron-custom-code-37361400022-1/custom-code.patch
cat /tmp/castiron-custom-code-37361400022-1/custom-code.patch

Or reproduce it from an SDK checkout containing the vendored reporter:

git fetch --no-tags origin 362468ef61b3605dda827c2b0492258eaf9edb50 73a523eecf12b3654033b95bfd5c2011eb94643f
python3 scripts/castiron/custom_code_report.py report \
  --base 362468ef61b3605dda827c2b0492258eaf9edb50 \
  --head 73a523eecf12b3654033b95bfd5c2011eb94643f --fetch --require-head-hash --public \
  --out /tmp/castiron-custom-code-73a523eecf12
cat /tmp/castiron-custom-code-73a523eecf12/custom-code.patch

This is the current full custom patch for mixed files, not an attribution of only the handwritten lines changed by this PR.

Full report and patch

@jbeckwith-oai jbeckwith-oai left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed all three changed files at eaa076913ab1f7597f0932d6286d573295778811.

The cleanup fix itself looks correct: both resources are attempted, the first failure is preserved, a distinct second failure is suppressed, and identical exceptions avoid self-suppression. The added tests cover those cases; request authentication and token handling are unchanged.

Requesting changes for the unrelated generation metadata retargeting. This handwritten cleanup does not include the generated-source changes represented by the new snapshot, so it relabels a large set of unchanged model/service files as custom or no longer generated. Please retain main's existing metadata for this fix; details are inline.

Source review and git diff --check completed. Hosted baseline integrity, lint and support-matrix checks passed; the broader CI run is still in progress. I did not execute the SDK or tests locally.

Comment thread .castiron.stats.yml Outdated

@markstuart-oai markstuart-oai left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed the full three-file change at eaa076913ab1f7597f0932d6286d573295778811. The cleanup code and added tests look sound. The existing generation metadata finding still needs correction.

I independently confirmed that ChatModel.kt is unchanged from base and matches the old generated snapshot. The new checkpoint selects a different version. The trusted report now counts 144 untouched files as newly customized. Please retain the base version of .castiron.stats.yml for this cleanup fix. I am referencing the existing finding to avoid a duplicate inline comment.

The close path preserves the first failure and still attempts transport cleanup. It handles distinct and shared exception objects and follows the existing retry-client pattern. I found no additional issue in the authentication cleanup boundary.

Source review only; no local workloads were run. Hosted lint, baseline consistency, and version-support checks pass. The custom-code budget check fails; the build and downstream checks remain pending.

@dpiet-oai
dpiet-oai marked this pull request as ready for review October 5, 2026 19:05
@dpiet-oai
dpiet-oai requested a review from a team as a code owner October 5, 2026 19:05
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-05T19:09:52.586954Z 73a523e New commits
🔒 Security Review ✅ Completed 2026-10-05T19:10:34.961883Z 73a523e New commits
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@openai-sdks

openai-sdks Bot commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

OkTest Summary

✅ 236/236 SDK tests passed in 16.122s for Java SDK PR #1146.

Test results — 42 files
Test Result Time
tests/chat-completions-complex-body.test.ts ✅ Passed 260ms
tests/chat-completions-create.test.ts ✅ Passed 477ms
tests/chat-completions-stream.test.ts ✅ Passed 392ms
tests/files-content-binary.test.ts ✅ Passed 249ms
tests/files-create-multipart.test.ts ✅ Passed 251ms
tests/files-list-pagination.test.ts ✅ Passed 218ms
tests/initialize-config.test.ts ✅ Passed 167ms
tests/instance-isolation.test.ts ✅ Passed 144ms
tests/models-list.test.ts ✅ Passed 305ms
tests/responses-background-lifecycle.test.ts ✅ Passed 234ms
tests/responses-body-method-errors.test.ts ✅ Passed 527ms
tests/responses-cancel-timeout.test.ts ✅ Passed 195ms
tests/responses-cancel.test.ts ✅ Passed 188ms
tests/responses-compact-retries.test.ts ✅ Passed 373ms
tests/responses-compact.test.ts ✅ Passed 279ms
tests/responses-create-advanced-stream.test.ts ✅ Passed 328ms
tests/responses-create-advanced.test.ts ✅ Passed 1.456s
tests/responses-create-disconnect.test.ts ✅ Passed 1.206s
tests/responses-create-errors.test.ts ✅ Passed 354ms
tests/responses-create-malformed-api-responses.test.ts ✅ Passed 204ms
tests/responses-create-retries.test.ts ✅ Passed 208ms
tests/responses-create-stream-failures.test.ts ✅ Passed 1.309s
tests/responses-create-stream-timeout.test.ts ✅ Passed 226ms
tests/responses-create-stream-wire.test.ts ✅ Passed 6.102s
tests/responses-create-stream.test.ts ✅ Passed 119ms
tests/responses-create-terminal-states.test.ts ✅ Passed 404ms
tests/responses-create-timeout.test.ts ✅ Passed 198ms
tests/responses-create.test.ts ✅ Passed 327ms
tests/responses-delete.test.ts ✅ Passed 258ms
tests/responses-input-items-errors.test.ts ✅ Passed 292ms
tests/responses-input-items-list.test.ts ✅ Passed 357ms
tests/responses-input-items-options.test.ts ✅ Passed 394ms
tests/responses-input-tokens-count-timeout.test.ts ✅ Passed 233ms
tests/responses-input-tokens-count.test.ts ✅ Passed 274ms
tests/responses-malformed-inputs.test.ts ✅ Passed 4.879s
tests/responses-not-found-errors.test.ts ✅ Passed 517ms
tests/responses-parse.test.ts ✅ Passed 464ms
tests/responses-retrieve-retries.test.ts ✅ Passed 256ms
tests/responses-retrieve.test.ts ✅ Passed 249ms
tests/responses-stored-method-errors.test.ts ✅ Passed 1.048s
tests/retry-behavior.test.ts ✅ Passed 3.726s
tests/sdk-error-shape.test.ts ✅ Passed 462ms

View OkTest run #37361239860

SDK merge (90f86b645cdd) · head (73a523eecf12) · base (362468ef61b3) · OkTest (505ac0e34283)

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

WorkloadIdentityHttpClient can leak its delegate when auth cleanup throws

3 participants