Skip to content

fix(live): keep query parameters out of WebSocket endpoint paths - #3972

Merged
markstuart-oai merged 3 commits into
mainfrom
codex/sdk-1011-live-role-contract
Sep 27, 2026
Merged

markstuart-oai merged 3 commits into
mainfrom
codex/sdk-1011-live-role-contract

Conversation

@markstuart-oai

Copy link
Copy Markdown
Contributor

Stacked on #3971, which fixes base URL normalization. Once that is merged, this PR can be retargeted to main.

Live WebSocket primary, fork and sideband managers appended their endpoint after the base URL query. For example, /v1/customer?tenant=sample dialed /v1/customer instead of the Live endpoint. Append the path before the query in all six sync/async managers.

Tests cover the actual WebSocket upgrade, preserved query parameters and escaped session IDs, caller-initiated primary and fork starts, immediate sideband events without waiting for session.started, follow-up updates and clean close.

Validation: all six query cases failed and six plain cases passed before the fix. After it, all 363 affected tests and 12 base URL tests passed on both Pydantic v1 and v2. Full Ruff, mypy and Pyright passed. No hosted-service or stored-fork-eligibility claims.

@markstuart-oai
markstuart-oai requested a review from a team as a code owner September 27, 2026 18:19
@github-actions

github-actions Bot commented Sep 27, 2026 •

Copy link
Copy Markdown
Contributor

Castiron custom code

✅ No new custom-code files detected.

47 mixed files remain; 3 existing customizations changed.

Compared f7bd4a703cad → 652ab1677ca3. Generated baselines verified.

File Result Current custom patch
src/openai/resources/live/forks.py Existing customization changed +67 / −31
src/openai/resources/live/live.py Existing customization changed +65 / −27
src/openai/resources/live/sideband.py Existing customization changed +67 / −31
44 existing customizations unchanged
  • api.md
  • scripts/castiron/README.md
  • scripts/castiron/custom_code_report.py
  • scripts/castiron/test_custom_code_report.py
  • src/openai/init.py
  • src/openai/_client.py
  • src/openai/resources/audio/transcriptions.py
  • src/openai/resources/audio/translations.py
  • src/openai/resources/beta/agents/sessions/sessions.py
  • src/openai/resources/beta/beta.py
  • src/openai/resources/beta/responses/responses.py
  • src/openai/resources/beta/threads/runs/runs.py
  • src/openai/resources/beta/threads/threads.py
  • src/openai/resources/chat/completions/completions.py
  • src/openai/resources/embeddings.py
  • src/openai/resources/files.py
  • src/openai/resources/realtime/api.md
  • src/openai/resources/realtime/realtime.py
  • src/openai/resources/responses/responses.py
  • src/openai/resources/uploads/uploads.py
  • src/openai/resources/vector_stores/file_batches.py
  • src/openai/resources/vector_stores/files.py
  • src/openai/resources/videos.py
  • src/openai/resources/webhooks/init.py
  • src/openai/resources/webhooks/webhooks.py
  • src/openai/types/beta/agent_session_message.py
  • src/openai/types/chat/init.py
  • src/openai/types/chat/chat_completion_message_tool_call.py
  • src/openai/types/fine_tuning/fine_tuning_job_integration.py
  • src/openai/types/realtime/conversation_item_input_audio_transcription_delta_event.py
  • src/openai/types/realtime/realtime_error_event.py
  • src/openai/types/responses/init.py
  • src/openai/types/responses/response.py
  • src/openai/types/responses/response_function_web_search.py
  • src/openai/types/responses/response_function_web_search_param.py
  • src/openai/types/responses/responses_client_event.py
  • src/openai/types/responses/responses_client_event_param.py
  • src/openai/types/responses/tool.py
  • src/openai/types/responses/tool_param.py
  • src/openai/types/webhooks/init.py

4 more in the full report.

A changed generated baseline means this report cannot reliably identify which handwritten lines changed.

Inspect the custom-code diff

Download the exact patch produced by this run (requires repository access):

gh run download 36343414524 --repo openai/openai-python \
  --name castiron-custom-code-36343414524-1 --dir /tmp/castiron-custom-code-36343414524-1
git apply --stat /tmp/castiron-custom-code-36343414524-1/custom-code.patch
cat /tmp/castiron-custom-code-36343414524-1/custom-code.patch

Or reproduce it from an SDK checkout containing the vendored reporter:

git fetch --no-tags origin f7bd4a703cad904e4f5d91ec9d7abac70d8c0bd6 652ab1677ca3e6b57bcea95e11b96c7f78f23b0b
python3 scripts/castiron/custom_code_report.py report \
  --base f7bd4a703cad904e4f5d91ec9d7abac70d8c0bd6 \
  --head 652ab1677ca3e6b57bcea95e11b96c7f78f23b0b --fetch --require-head-hash --public \
  --out /tmp/castiron-custom-code-652ab1677ca3
cat /tmp/castiron-custom-code-652ab1677ca3/custom-code.patch

This is the current full custom patch for mixed files, not an attribution of only the handwritten lines changed by this PR.

Full report and patch

@jbeckwith-oai jbeckwith-oai left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed 6665a3e against a5a6f80. No blocking findings in this stacked diff.

All six sync/async primary, fork and sideband URL builders now append the endpoint before the query while retaining path-template escaping. The 12 loopback cases exercise role-specific paths, special-character session IDs, base/extra query parameters, sideband graceful_close, caller-owned session.start, event correlation and clean shutdown.

Validation: 192 controlled cases using the exact extracted Live URL methods passed with installed HTTPX 0.28.1 and synthetic client/path-template fixtures; all four changed Python files compile in memory. These are isolated URL-method probes, not a local SDK suite. Exact-head hosted Python 3.10/3.14, HTTPX2, lint/build and Castiron baseline checks passed; no live API calls.

Merge ordering: this remains stacked on #3971. Retarget it to main after #3971 merges and confirm the resulting main-based checks before merging this PR.

Base automatically changed from codex/sdk-1006-realtime-wire-contract to main September 27, 2026 18:59
@openai-sdks

openai-sdks Bot commented Sep 27, 2026 •

Copy link
Copy Markdown
Contributor

OkTest Summary

✅ 236/236 SDK tests passed in 9.16s for Python SDK PR #3972.

Test results — 42 files
Test Result Time
tests/chat-completions-complex-body.test.ts ✅ Passed 109ms
tests/chat-completions-create.test.ts ✅ Passed 285ms
tests/chat-completions-stream.test.ts ✅ Passed 129ms
tests/files-content-binary.test.ts ✅ Passed 184ms
tests/files-create-multipart.test.ts ✅ Passed 168ms
tests/files-list-pagination.test.ts ✅ Passed 117ms
tests/initialize-config.test.ts ✅ Passed 110ms
tests/instance-isolation.test.ts ✅ Passed 133ms
tests/models-list.test.ts ✅ Passed 118ms
tests/responses-background-lifecycle.test.ts ✅ Passed 129ms
tests/responses-body-method-errors.test.ts ✅ Passed 253ms
tests/responses-cancel-timeout.test.ts ✅ Passed 216ms
tests/responses-cancel.test.ts ✅ Passed 176ms
tests/responses-compact-retries.test.ts ✅ Passed 224ms
tests/responses-compact.test.ts ✅ Passed 246ms
tests/responses-create-advanced-stream.test.ts ✅ Passed 342ms
tests/responses-create-advanced.test.ts ✅ Passed 190ms
tests/responses-create-disconnect.test.ts ✅ Passed 1.168s
tests/responses-create-errors.test.ts ✅ Passed 184ms
tests/responses-create-malformed-api-responses.test.ts ✅ Passed 97ms
tests/responses-create-retries.test.ts ✅ Passed 167ms
tests/responses-create-stream-failures.test.ts ✅ Passed 93ms
tests/responses-create-stream-timeout.test.ts ✅ Passed 182ms
tests/responses-create-stream-wire.test.ts ✅ Passed 2.696s
tests/responses-create-stream.test.ts ✅ Passed 118ms
tests/responses-create-terminal-states.test.ts ✅ Passed 203ms
tests/responses-create-timeout.test.ts ✅ Passed 196ms
tests/responses-create.test.ts ✅ Passed 409ms
tests/responses-delete.test.ts ✅ Passed 137ms
tests/responses-input-items-errors.test.ts ✅ Passed 355ms
tests/responses-input-items-list.test.ts ✅ Passed 251ms
tests/responses-input-items-options.test.ts ✅ Passed 213ms
tests/responses-input-tokens-count-timeout.test.ts ✅ Passed 211ms
tests/responses-input-tokens-count.test.ts ✅ Passed 153ms
tests/responses-malformed-inputs.test.ts ✅ Passed 1.871s
tests/responses-not-found-errors.test.ts ✅ Passed 189ms
tests/responses-parse.test.ts ✅ Passed 185ms
tests/responses-retrieve-retries.test.ts ✅ Passed 148ms
tests/responses-retrieve.test.ts ✅ Passed 145ms
tests/responses-stored-method-errors.test.ts ✅ Passed 499ms
tests/retry-behavior.test.ts ✅ Passed 3.317s
tests/sdk-error-shape.test.ts ✅ Passed 261ms

View OkTest run #36343390240

SDK merge (6facff514850) · head (652ab1677ca3) · base (f7bd4a703cad) · OkTest (f9111d4e2fcd)

@markstuart-oai
markstuart-oai added this pull request to the merge queue Sep 27, 2026
Merged via the queue into main with commit f9c458b Sep 27, 2026
26 checks passed
@markstuart-oai
markstuart-oai deleted the codex/sdk-1011-live-role-contract branch September 27, 2026 19:19
@openai-sdks openai-sdks Bot mentioned this pull request Sep 27, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants