Shell tool allowlist network policy broken
Maintainer thường phản hồi trong vòng 1 ngày
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 4/5
- Thời gian dự kiến
- 3-5 ngày
- Mức phù hợp với người mới
- 30/100
Hướng nghiên cứu
Bắt đầu bằng cách tái hiện lỗi thông qua responses.create với shell tool và network_policy allowlist được nêu trong issue, so sánh với trường hợp network policy bị vô hiệu hóa. Truy vết đường đi của request trong thư viện Python đối với payload này và sử dụng server_error cùng request ID được báo cáo để phân biệt lỗi serialization phía client với lỗi phía API. Hoàn tất khi request có allowlist không còn trả về HTTP 500.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
Confirm this is an issue with the Python library and not an underlying OpenAI API
- This is an issue with the Python library
Describe the bug
I get this error when I add allowlist network policy with our production domains to an agent with a shell tool:
An error occurred while processing your request. You can retry your request, or contact us through our help center at [help.openai.com](http://help.openai.com/) if the error persists. Please include the request ID req_3b0917dca27342dda56901e1a1c05306 in your message.
It does not occur when network policy is disabled. The domains in allowed_domains are in Container network mode in the data controls in platform.openai.com. Another thing to note is that it was still working on Feb 26.
To Reproduce
- Add a domain (e.g. "google.com" as in the code snippet) to platform.openai.com > Data control > Hosted tools > Container network mode > allowlist
- Run the included code snippet
- Result:
Error code: 500 - {'error': {'message': 'An error occurred while processing your request. You can retry your request, or contact us through our help center at help.openai.com if the error persists. Please include the request ID req_XXXXX in your message.', 'type': 'server_error', 'param': None, 'code': 'server_error'}}
Code snippets
from openai import APIStatusError, OpenAI
client = OpenAI()
try:
response = client.responses.create(
model="gpt-5.2",
input="Use shell tool and run: curl google.com",
tools=[
{
"type": "shell",
"environment": {
"type": "container_auto",
"network_policy": {
"type": "allowlist",
"allowed_domains": ["google.com"],
},
},
}
],
)
print("response_id:", response.id)
print("status:", response.status)
print("output_text:", response.output_text)
except APIStatusError as e:
print("http_status:", e.status_code)
print("request_id:", e.request_id)
print("error:", e)
OS
Ubuntu 24.04
Python version
Python v3.13.3
Library version
openai v2.24.0
- Ngôn ngữ chính
- Python
- Star
- 31.7k
- Fork
- 6.8k
- Merge trung bình
- 1 ngày 5 giờ
- Pull request đã merge (30 ngày)
- 128
Chuẩn bị môi trường
Khởi chạy dev container của dự án ngay trên trình duyệt, bằng tài khoản GitHub của bạn.
- Không có Dockerfile hay tệp Docker Compose
- Có mẫu pull request
- Đọc hướng dẫn đóng góp
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của openai/openai-python
-
sdk-breaking-change v4
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 86/100
openai/openai-python#3837 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 68/100
openai/openai-python#3556 · 3 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
bug
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 68/100
openai/openai-python#2927 · 7 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
bug openapi
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
openai/openai-python#2502 · 7 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
bug
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 62/100
openai/openai-python#2486 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
Tất cả issue của openai/openai-python
Issue tương tự
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 88/100
BasedHardware/omi#20271 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 92/100
openai/openai-cookbook#3153 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
cvss-severity:high devguard l3montree-cybersecurity/devguard/devguard pkg:golang/github.com/l3montree-dev/devguard risk:low state:open
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 65/100
l3montree-dev/devguard#3146 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 76/100
-
bug confirmed issue
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 76/100
open-webui/open-webui#31849 · 2 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày