8324dd19ca
The custom ``httpx.HTTPTransport(socket_options=[SO_KEEPALIVE, ...])`` in ``_build_keepalive_http_client()`` was introduced to fix CLOSE-WAIT socket accumulation on long-lived connections (#10324). That approach broke streaming for providers behind reverse proxies (OpenResty, Cloudflare, etc.) because the custom socket options conflict with the proxy's chunked-transfer handling (#54049, #12952). It also stripped TCP_NODELAY, stalling TLS handshakes and SSE encoding. Narrow per-provider bypasses were added for Copilot (#50298), Codex (#36623, #12953), but the root cause remained. The fix moves connection lifecycle management from the socket layer to the HTTP pool layer: - ``httpx.Limits(keepalive_expiry=20.0)`` tells httpx to close idle pooled connections at 20 s, before a reverse proxy's typical 30-60 s timeout drops them and causes CLOSE-WAIT accumulation. - The default httpx transport preserves OS TCP defaults (including TCP_NODELAY), so TLS handshakes and SSE chunked encoding work correctly. - ``trust_env=False`` prevents httpx from double-dipping on env vars (we handle proxy detection ourselves via ``_get_proxy_for_base_url`` which respects NO_PROXY). - The Copilot host bypass (line 3632) is no longer needed since all providers now use the same standard httpx.Client. Closes #54049. Supersedes #12010, #36623, #12953, #50298.