From 0f0b7a3f5046cbc8b6d9043fd1ec5fc5b7533c7e Mon Sep 17 00:00:00 2001 From: Julio Quinteros Pro Date: Sat, 14 Feb 2026 14:41:23 -0300 Subject: [PATCH] fix: preserve original behavior - always call PolicyResolver Remove early return when applied_policy_names is empty to preserve original behavior where PolicyResolver.resolve_guardrails_for_context() is always called. The resolver does its own independent matching and inheritance resolution, which can apply guardrails from parent policies even when child policies fail their conditions. This ensures no guardrails are silently dropped due to the refactoring. Addresses Greptile review feedback on behavioral change. --- litellm/proxy/litellm_pre_call_utils.py | 11 ++++------- 1 file changed, 4 insertions(+), 7 deletions(-) diff --git a/litellm/proxy/litellm_pre_call_utils.py b/litellm/proxy/litellm_pre_call_utils.py index 0171b7efd79..bafd473d209 100644 --- a/litellm/proxy/litellm_pre_call_utils.py +++ b/litellm/proxy/litellm_pre_call_utils.py @@ -1704,15 +1704,12 @@ def add_guardrails_from_policy_engine( f"key_alias={context.key_alias}, model={context.model}, tags={context.tags}" ) - # Match and track policies - applied_policy_names, _ = _match_and_track_policies( - data, context, request_body_policies - ) - - if not applied_policy_names: - return + # Match and track policies (may be empty, but resolution still happens) + _match_and_track_policies(data, context, request_body_policies) # Apply resolved guardrails to metadata + # Note: PolicyResolver does its own independent matching and inheritance resolution, + # so we always call it even if applied_policy_names is empty _apply_resolved_guardrails_to_metadata(data, metadata_variable_name, context)