Skip to content

fix(responses): reject lifecycle events from another response - #2485

Open
HAYDEN-OAI wants to merge 9 commits into
mainfrom
fix/responses-lifecycle-identity-20260826-clfraikh
Open

fix(responses): reject lifecycle events from another response#2485
HAYDEN-OAI wants to merge 9 commits into
mainfrom
fix/responses-lifecycle-identity-20260826-clfraikh

Conversation

@HAYDEN-OAI

Copy link
Copy Markdown
Contributor

Summary

  • Keep response snapshots bound to the same response across every lifecycle event.
  • Reject foreign or malformed response identities before exposing data or updating stream state.
  • Cover all six lifecycle events, hostile getters, and the public streaming API.

Test plan

  • Node 22.23.0 and 26.7.0: 6,556 handwritten and 556 generated tests per runtime.
  • Lint, strict type checking, CommonJS/ESM builds, and published TypeScript 4.9/6 checks.
  • Package lint and an actually packed, installed public CommonJS/ESM consumer.

@HAYDEN-OAI
HAYDEN-OAI requested a review from a team as a code owner August 26, 2026 19:45
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Aug 26, 2026

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review Completed 2026-08-26T22:08:11.971554Z 4bd7d4d New commits
🔒 Security Review Completed 2026-08-26T22:08:22.757887Z 4bd7d4d New commits
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@openai-sdks

openai-sdks Bot commented Aug 26, 2026

Copy link
Copy Markdown
Contributor

OkTest Summary

237/237 SDK tests passed in 10.96s for Node SDK PR #2485.

Test results — 42 files
Test Result Time
tests/chat-completions-complex-body.test.ts ✅ Passed 149ms
tests/chat-completions-create.test.ts ✅ Passed 204ms
tests/chat-completions-stream.test.ts ✅ Passed 361ms
tests/files-content-binary.test.ts ✅ Passed 132ms
tests/files-create-multipart.test.ts ✅ Passed 176ms
tests/files-list-pagination.test.ts ✅ Passed 206ms
tests/initialize-config.test.ts ✅ Passed 180ms
tests/instance-isolation.test.ts ✅ Passed 113ms
tests/models-list.test.ts ✅ Passed 192ms
tests/responses-background-lifecycle.test.ts ✅ Passed 227ms
tests/responses-body-method-errors.test.ts ✅ Passed 308ms
tests/responses-cancel-timeout.test.ts ✅ Passed 194ms
tests/responses-cancel.test.ts ✅ Passed 239ms
tests/responses-compact-retries.test.ts ✅ Passed 264ms
tests/responses-compact.test.ts ✅ Passed 257ms
tests/responses-create-advanced-stream.test.ts ✅ Passed 126ms
tests/responses-create-advanced.test.ts ✅ Passed 234ms
tests/responses-create-disconnect.test.ts ✅ Passed 1.261s
tests/responses-create-errors.test.ts ✅ Passed 222ms
tests/responses-create-malformed-api-responses.test.ts ✅ Passed 212ms
tests/responses-create-retries.test.ts ✅ Passed 272ms
tests/responses-create-stream-failures.test.ts ✅ Passed 269ms
tests/responses-create-stream-timeout.test.ts ✅ Passed 2.211s
tests/responses-create-stream-wire.test.ts ✅ Passed 2.705s
tests/responses-create-stream.test.ts ✅ Passed 87ms
tests/responses-create-terminal-states.test.ts ✅ Passed 188ms
tests/responses-create-timeout.test.ts ✅ Passed 215ms
tests/responses-create.test.ts ✅ Passed 210ms
tests/responses-delete.test.ts ✅ Passed 227ms
tests/responses-input-items-errors.test.ts ✅ Passed 373ms
tests/responses-input-items-list.test.ts ✅ Passed 265ms
tests/responses-input-items-options.test.ts ✅ Passed 116ms
tests/responses-input-tokens-count-timeout.test.ts ✅ Passed 219ms
tests/responses-input-tokens-count.test.ts ✅ Passed 245ms
tests/responses-malformed-inputs.test.ts ✅ Passed 2.336s
tests/responses-not-found-errors.test.ts ✅ Passed 243ms
tests/responses-parse.test.ts ✅ Passed 164ms
tests/responses-retrieve-retries.test.ts ✅ Passed 231ms
tests/responses-retrieve.test.ts ✅ Passed 231ms
tests/responses-stored-method-errors.test.ts ✅ Passed 590ms
tests/retry-behavior.test.ts ✅ Passed 3.039s
tests/sdk-error-shape.test.ts ✅ Passed 287ms

View OkTest run #33018170391

SDK merge (4c47f746f75e) · head (4bd7d4dfb110) · base (e4afdb7c0875) · OkTest (2b1bdfd25e98)

@github-actions

github-actions Bot commented Aug 26, 2026

Copy link
Copy Markdown
Contributor

Castiron custom code

✅ No new custom-code files detected.

32 mixed files remain; 0 existing customizations changed.

Compared e4afdb7c08754bd7d4dfb110. Generated baselines verified.

32 existing customizations unchanged
  • api.md
  • scripts/castiron/README.md
  • scripts/castiron/custom_code_report.py
  • scripts/castiron/test_custom_code_report.py
  • src/client.ts
  • src/resources/audio/transcriptions.ts
  • src/resources/audio/translations.ts
  • src/resources/beta/assistants.ts
  • src/resources/beta/beta.ts
  • src/resources/beta/index.ts
  • src/resources/beta/responses/internal-base.ts
  • src/resources/beta/responses/responses.ts
  • src/resources/beta/threads/index.ts
  • src/resources/beta/threads/runs/index.ts
  • src/resources/beta/threads/runs/runs.ts
  • src/resources/beta/threads/threads.ts
  • src/resources/chat/completions/completions.ts
  • src/resources/chat/completions/index.ts
  • src/resources/conversations/index.ts
  • src/resources/embeddings.ts
  • src/resources/files.ts
  • src/resources/fine-tuning/checkpoints/permissions.ts
  • src/resources/images.ts
  • src/resources/responses/internal-base.ts
  • src/resources/responses/responses.ts
  • src/resources/skills/skills.ts
  • src/resources/skills/versions/versions.ts
  • src/resources/vector-stores/file-batches.ts
  • src/resources/vector-stores/files.ts
  • src/resources/webhooks/index.ts
  • src/resources/webhooks/webhooks.ts
  • tests/lib/data-residency.test.ts

A changed generated baseline means this report cannot reliably identify which handwritten lines changed.

Inspect the custom-code diff

Download the exact patch produced by this run (requires repository access):

gh run download 33018431562 --repo openai/openai-node \
  --name castiron-custom-code-33018431562-1 --dir /tmp/castiron-custom-code-33018431562-1
git apply --stat /tmp/castiron-custom-code-33018431562-1/custom-code.patch
cat /tmp/castiron-custom-code-33018431562-1/custom-code.patch

Or reproduce it from an SDK checkout containing the vendored reporter:

git fetch --no-tags origin e4afdb7c0875b3e0d730a163d9a67dc676b72061 4bd7d4dfb110e1f2454dca2ececa711345c2be52
python3 scripts/castiron/custom_code_report.py report \
  --base e4afdb7c0875b3e0d730a163d9a67dc676b72061 \
  --head 4bd7d4dfb110e1f2454dca2ececa711345c2be52 --fetch --require-head-hash --public \
  --out /tmp/castiron-custom-code-4bd7d4dfb110
cat /tmp/castiron-custom-code-4bd7d4dfb110/custom-code.patch

This is the current full custom patch for mixed files, not an attribution of only the handwritten lines changed by this PR.

Full report and patch

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: ee2ffbd91b

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread src/internal/responses/response-accumulator.ts Outdated
Comment thread src/internal/responses/response-accumulator.ts Outdated
Comment thread src/internal/responses/response-accumulator.ts

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 075a28bc54

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread src/internal/responses/response-accumulator.ts Outdated

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 8492ba5bca

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread src/internal/responses/response-accumulator.ts Outdated
Comment thread src/internal/responses/response-accumulator.ts Outdated
Comment thread src/internal/responses/response-accumulator.ts Outdated

@jbeckwith-oai jbeckwith-oai left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Please resolve the existing exact-head P1 thread at response-accumulator.ts:344 before merging. A lifecycle response getter can mutate the raw event's type after sanitization; the detached descriptor copy then inherits that unvalidated type, ResponseStream falls back to the original getter-bearing event, and listeners can receive a different response/customer payload. Pin the already-validated lifecycle type into the detached event and add a hostile-getter regression. The existing reflective-trap diagnostic leak and replay-cloning threads should also be addressed. Independently validated; no duplicate inline comments added.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 8788d5abcd

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread src/lib/responses/ResponseStream.ts Outdated
Comment thread src/internal/responses/response-accumulator.ts Outdated

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 9e2d50271d

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread src/internal/responses/response-accumulator.ts

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: f5d23d7759

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread src/lib/responses/ResponseStream.ts Outdated
Comment thread src/internal/responses/response-accumulator.ts Outdated

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 1c0759d09f

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread src/internal/responses/response-accumulator.ts Outdated
Comment thread src/lib/responses/ResponseStream.ts Outdated
Comment thread src/internal/responses/response-accumulator.ts

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 6e3ea0ad4a

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread src/internal/responses/response-accumulator.ts
Comment thread src/internal/responses/response-accumulator.ts Outdated
Comment thread src/lib/responses/ResponseStream.ts Outdated
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants