HERMES_CODEX_BASE_URL was applied at pool resolution and on the auxiliary
clients, but two paths still sent the openai-codex provider back to the
default ChatGPT backend:
- credential rotation: client_lifecycle._swap_credential adopts
PooledCredential.runtime_base_url, which for openai-codex was the pool
row's stored canonical URL, so the first 401/429 rotation silently left
the proxy. The override now lives in runtime_base_url, the one place every
reader of a Codex pool row (resolution and rotation) goes through.
- model.base_url: the openai-codex branch of _pool_entry_mode_and_url
returned before the generic model.base_url block. It now honours
model.base_url under model.provider: openai-codex when the pool row still
carries the canonical URL (env override keeps precedence).
Slim port of #40924 onto the current layout (the original patched
run_agent._swap_credential, the pool seeder and a new auth.py helper; the
seeder half landed in b62bb2a3d5, the helper is replaced by the
profile-scoped get_secret_str read the landed fixes already use).
Fixes #40913
Contributor email → GitHub login mappings
This directory replaces appending entries to AUTHOR_MAP in
scripts/release.py. The old dict caused constant merge conflicts when
several salvage PRs landed at once — every PR edited the same lines of the
same file. Here, each mapping is its own file, and file additions never
conflict.
Adding a mapping
One file per commit-author email, under emails/:
python3 scripts/add_contributor.py <email> <github-login>
# or by hand:
echo "<github-login>" > contributors/emails/<email>
- File name = the exact commit-author email (as shown by
git log --format='%ae'). - File content = the GitHub login on the first non-comment line.
Lines starting with
#are comments (use them for the PR reference).
Example — contributors/emails/jane.doe@example.com:
janedoe
# PR #12345 salvage (gateway: fix session key routing)
Rules
- Do NOT add new entries to
AUTHOR_MAPinscripts/release.py. That dict is frozen legacy data; the release tooling merges it with this directory (directory entries win on duplicates). - GitHub noreply emails (
<id>+<login>@users.noreply.github.comand<login>@users.noreply.github.com) auto-resolve — no file needed. - The
Contributor Attribution CheckCI job fails a PR whose commits carry an unmapped email; the failure message prints the exact command to run.