From a4a7743507d6aacf9e7130c39eb456b3679634a2 Mon Sep 17 00:00:00 2001 From: MXAntian Date: Thu, 1 Oct 2026 15:34:01 +0800 Subject: [PATCH] docs(adapters/codex-recovery-proxy): say what the proxy does for source_host and quarantine MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The README only said the bearer is forwarded unchanged. It did not say what that buys, so a reader could not tell whether provenance and quarantine still apply to writes that arrive through the proxy. They do, and the proxy has no part in it. mcp-server.mjs resolves the host from the Authorization header when a session is created (auth.mjs resolveHost, MNEME_HOST_TOKENS), stamps source_host on writes from that session, and routes hosts listed in MNEME_QUARANTINE_HOSTS into memories_quarantine. The proxy opens a fresh session per call with the same bearer every time, so the host is re-derived from the token on each call and the server behaves exactly as it would for a direct connection. Add a short "Provenance 与 quarantine" section that states only that, plus the parts an operator can trip over: - MNEME_TOKEN_CODEX has to be the token MNEME_HOST_TOKENS maps to the codex host. An unknown token is served under soft/off but recorded as the default host, and rejected with 401 under enforce. - A fresh session is also opened for tools/list, so resolve_quarantine only appears when that session's host is the primary host. No code change. The fault-injection test passes unchanged against this tree (fresh sessions=60, calls=59, live sessions=0; both hanging-remote scenarios surface an error inside the timeout window). Co-Authored-By: 千夏 --- adapters/codex-recovery-proxy/README.md | 11 ++++++++++- 1 file changed, 10 insertions(+), 1 deletion(-) diff --git a/adapters/codex-recovery-proxy/README.md b/adapters/codex-recovery-proxy/README.md index ee78fad..3f5acb4 100644 --- a/adapters/codex-recovery-proxy/README.md +++ b/adapters/codex-recovery-proxy/README.md @@ -16,7 +16,7 @@ Codex Desktop 有一个未修复的上游 bug([openai/codex#32470](https://git - proxy 内部把每次 `tools/list` 或 `tools/call` 转成一次**独立的 HTTP session** 打到真 mneme server - 每次调用**结束即 DELETE session**,30 秒有界 timeout - **写调用绝不自动重试**(保 at-most-once 语义,不会导致重复 store_memory) -- `Authorization: Bearer ` header 逐调用透传,mneme server 看到的 bearer 与直连模式**完全一致**(proxy 不修改、不缓存、不加工 auth header) +- `Authorization: Bearer ` header 逐调用透传,mneme server 看到的 bearer 与直连模式**完全一致**(proxy 不修改、不缓存、不加工 auth header)。server 侧据此推导 `source_host`、决定写入是否进 quarantine 的逻辑,经 proxy 与直连时一致,见下方 [Provenance 与 quarantine](#provenance-与-quarantine) **架构效果**:单次 tool call 如果 wedge,只污染那一次;下次调用是全新 session,不受影响。 @@ -72,6 +72,15 @@ node adapters/codex-recovery-proxy/proxy.test.mjs | `MNEME_PROXY_TIMEOUT_MS` | `30000` | 单次请求 timeout | | `MNEME_PROXY_CLOSE_TIMEOUT_MS` | `2000` | 关闭 remote session 的 timeout | +## Provenance 与 quarantine + +proxy 自己不实现、也不改变这两层,只保证 bearer 原样到达 mneme server;其余都是 server 的既有行为,与 codex 直连时一样: + +- **`source_host` 来自 bearer,不来自 proxy 或客户端自报。** server 在**建立 session 时**用该请求的 bearer,按 `MNEME_HOST_TOKENS`(`host=token` 对,如 `cc=tok1,codex=tok2`)查出 host,这个 session 上的写入都打这个 host 的 `source_host`。proxy 每次调用都是新 session,所以 host 每次都按当次 bearer 重新推导。 +- **`MNEME_TOKEN_CODEX` 应填 `MNEME_HOST_TOKENS` 里映射给 codex 的那个 token。** token 命中该表时,任何模式下都映射为对应 host;没命中时由 server 的 `MNEME_AUTH` 决定:`soft`(配了 `MNEME_HOST_TOKENS` 时的默认)和 `off`(没配时的默认)仍然服务,但按默认 host(`MNEME_DEFAULT_HOST`,默认 `cc`)记账;`enforce` 返回 401。 +- **quarantine 按同一个 host 生效。** 如果 codex 的 host 列在 server 的 `MNEME_QUARANTINE_HOSTS` 里,经 proxy 的 `store_memory` 会写进 `memories_quarantine`(recall 看不到),等 primary host(`MNEME_PRIMARY_HOST`,默认同 `MNEME_DEFAULT_HOST`)用 `resolve_quarantine` 批准后才进主库。 +- **`tools/list` 也是用同一个 bearer 开的新 session**,所以 codex 看到的工具集与该 host 直连时一致:只有该 session 的 host(含上一条按默认 host 兜底的情况)恰好是 primary host 时,才会注册 `resolve_quarantine`。 + ## 归档策略(上游修好后) **这是补丁不是能力**。当 [openai/codex#32470](https://github.com/openai/codex/issues/32470) 修复且验证稳定后: