Skip to content

Upgrade the managed network proxy from Rama 0.3.0-alpha.4 to 0.3.0 #39557

Description

@TyceHerrman

Summary

Codex's managed network proxy pins Rama to =0.3.0-alpha.4. In that release, Rama initializes its global DNS resolver once as HickoryDns::default(), so a long-running proxy can retain resolver configuration from before a network, VPN, or DNS change.

Stable Rama 0.3.0 defaults to AppleDnsResolver on macOS and performs lookups through DNSServiceQueryRecord. Upgrading is therefore a likely fix for stale DNS in long-running Codex sessions, although it should be confirmed with an A/B reproducer.

This surfaced when Tycho/P2 downloads failed through Codex's managed proxy after the effective network/DNS environment changed. Maven's proxy setting was not the controlling transport.

Proposed change

  • Upgrade the Rama dependencies from alpha.4 to stable 0.3.0.
  • Migrate the connector stack to stable Rama's DnsConnector; stable Rama separates DNS resolution from the TCP connector, so this is not only a version bump.
  • Preserve domain allowlisting and private-address rejection for every resolved candidate.
  • Add a test that keeps one proxy process alive, changes the effective DNS configuration, and verifies that the next lookup uses the new configuration.
  • Re-evaluate the Hickory advisory exceptions added in #20627.

References

Metadata

Metadata

Assignees

No one assigned

    Labels

    CLIIssues related to the Codex CLIbugSomething isn't workingconnectivityIssues involving networking or endpoint connectivity problems (disconnections)

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions