Files
hermes-agent/hermes_cli
rjshrjndrn 7034628c92 fix(codex): proxy override survives credential rotation and model.base_url is honoured
HERMES_CODEX_BASE_URL was applied at pool resolution and on the auxiliary
clients, but two paths still sent the openai-codex provider back to the
default ChatGPT backend:

- credential rotation: client_lifecycle._swap_credential adopts
  PooledCredential.runtime_base_url, which for openai-codex was the pool
  row's stored canonical URL, so the first 401/429 rotation silently left
  the proxy. The override now lives in runtime_base_url, the one place every
  reader of a Codex pool row (resolution and rotation) goes through.
- model.base_url: the openai-codex branch of _pool_entry_mode_and_url
  returned before the generic model.base_url block. It now honours
  model.base_url under model.provider: openai-codex when the pool row still
  carries the canonical URL (env override keeps precedence).

Slim port of #40924 onto the current layout (the original patched
run_agent._swap_credential, the pool seeder and a new auth.py helper; the
seeder half landed in b62bb2a3d5, the helper is replaced by the
profile-scoped get_secret_str read the landed fixes already use).

Fixes #40913
2026-09-19 10:33:08 -07:00
..
…
…
…
…
…
…
…