Codex: no web search tool for Responses Lite models
With the Codex engine, tools.web-search + network.hosted-web gives a Responses Lite model (e.g. gpt-5.6-terra) no search tool. The agent says web search is unavailable, and the log has no web_search item.
The docs make no exception for models or providers (engines/codex.md, reference/network.md).
Versions: gh-aw v0.91.5, AWF v0.28.44, codex 0.159.3.
engine:
id: codex
model: gpt-5.6-terra
network:
allowed: [defaults]
hosted-web:
allowed: [docs.example.com]
tools:
web-search:
Analysis
This analysis was done with an agent and checked against the source at the tags above.
- codex gives Responses Lite models no hosted
web_search tool. Their only search tool is the standalone web.run (spec_plan.rs).
web.run is registered only if the provider is OpenAI, uses actor authorization, or sets supports_standalone_web_search (extension.rs).
- The generated
openai-proxy provider meets none of these (codex_config.go). This is still the case in v0.91.6 and on main.
Setting the flag through engine.config makes the agent call web.run:
[model_providers.openai-proxy]
supports_standalone_web_search = true
The calls then fail at the AWF api-proxy with 400 codex_hosted_web_shape_invalid. That part is reported in github/gh-aw-firewall#9744.
Implementation Plan
- Provider config. In
pkg/workflow/codex_config.go, set supports_standalone_web_search = true on openai-proxy when Codex hosted web is enabled and the upstream is OpenAI.
- This affects only Responses Lite models, because codex's
StandaloneWebSearch feature is off by default.
max-uses. AWF rejects standalone search when max-uses is set (codex_hosted_web_max_uses_unsupported). Reject or warn about that combination at compile time instead of dropping the limit silently.
- Tests. Add a unit test in
pkg/workflow covering the flag with and without hosted-web.
- Docs. Note the behaviour in
docs/src/content/docs/engines/codex.md.
- Finish. Run
make agent-finish.
Acceptance criteria
- A Codex workflow with
tools.web-search and network.hosted-web compiles to a config whose [model_providers.openai-proxy] has supports_standalone_web_search = true, and a test asserts it.
- Without
hosted-web, the flag is not set.
Codex: no web search tool for Responses Lite models
With the Codex engine,
tools.web-search+network.hosted-webgives a Responses Lite model (e.g.gpt-5.6-terra) no search tool. The agent says web search is unavailable, and the log has noweb_searchitem.The docs make no exception for models or providers (engines/codex.md, reference/network.md).
Versions: gh-aw v0.91.5, AWF v0.28.44, codex 0.159.3.
Analysis
This analysis was done with an agent and checked against the source at the tags above.
web_searchtool. Their only search tool is the standaloneweb.run(spec_plan.rs).web.runis registered only if the provider is OpenAI, uses actor authorization, or setssupports_standalone_web_search(extension.rs).openai-proxyprovider meets none of these (codex_config.go). This is still the case in v0.91.6 and onmain.Setting the flag through
engine.configmakes the agent callweb.run:The calls then fail at the AWF api-proxy with
400 codex_hosted_web_shape_invalid. That part is reported in github/gh-aw-firewall#9744.Implementation Plan
pkg/workflow/codex_config.go, setsupports_standalone_web_search = trueonopenai-proxywhen Codex hosted web is enabled and the upstream is OpenAI.StandaloneWebSearchfeature is off by default.max-uses. AWF rejects standalone search whenmax-usesis set (codex_hosted_web_max_uses_unsupported). Reject or warn about that combination at compile time instead of dropping the limit silently.pkg/workflowcovering the flag with and withouthosted-web.docs/src/content/docs/engines/codex.md.make agent-finish.Acceptance criteria
tools.web-searchandnetwork.hosted-webcompiles to a config whose[model_providers.openai-proxy]hassupports_standalone_web_search = true, and a test asserts it.hosted-web, the flag is not set.