From 2e1d40771174126eb091c23b0923bd9b39564dfd Mon Sep 17 00:00:00 2001 From: mateo-berri <277851410+mateo-berri@users.noreply.github.com> Date: Tue, 18 Aug 2026 20:49:12 -0700 Subject: [PATCH] test(e2e): pin the tag-routing denial to its actual cause The strict-denial pin only asserted a 401, so any unrelated 401 (a bad key, a deleted key) would have kept it green while tag routing silently broke. The harness now keeps the 401 response body, the way it already does for 429s, and the pin asserts the tag-routing denial message. --- tests/e2e/e2e_http.py | 4 +++- tests/e2e/router/test_auto_router_regressions_e2e.py | 4 ++++ 2 files changed, 7 insertions(+), 1 deletion(-) diff --git a/tests/e2e/e2e_http.py b/tests/e2e/e2e_http.py index f4db88b1e19..cb6fc7a01e5 100644 --- a/tests/e2e/e2e_http.py +++ b/tests/e2e/e2e_http.py @@ -75,6 +75,8 @@ class NetworkError(BaseModel): class UnauthorizedError(BaseModel): kind: Literal["unauthorized"] = "unauthorized" + # litellm 401s for key auth, model access, and tag routing alike, so keep the body to tell them apart. + body: str = "" class RateLimitedError(BaseModel): @@ -289,7 +291,7 @@ def _classify[R: BaseModel]( resp: requests.Response, response_type: type[R] ) -> Result[R]: if resp.status_code == 401: - return UnauthorizedError() + return UnauthorizedError(body=resp.text) if resp.status_code == 429: return RateLimitedError(body=resp.text) if not resp.ok: diff --git a/tests/e2e/router/test_auto_router_regressions_e2e.py b/tests/e2e/router/test_auto_router_regressions_e2e.py index c6ef9cda05d..35ba2c8d3d1 100644 --- a/tests/e2e/router/test_auto_router_regressions_e2e.py +++ b/tests/e2e/router/test_auto_router_regressions_e2e.py @@ -69,6 +69,7 @@ PLAIN_MODEL = "anthropic/claude-sonnet-5" CHEAP_MODEL = "anthropic/claude-haiku-4-5" STRONG_MODEL = "openai/gpt-5.6" MAX_TOKENS = 16 +TAG_DENIAL_MESSAGE = "Not allowed to access model due to tags configuration" PLAIN_SERVED = frozenset({PLAIN_MODEL, "claude-sonnet-5"}) CHEAP_SERVED = frozenset({CHEAP_MODEL, "claude-haiku-4-5"}) EMBEDDING_MODEL = "openai/text-embedding-3-small" @@ -442,6 +443,9 @@ class TestUntaggedTierDeployments: assert isinstance(result, UnauthorizedError), ( f"expected the tagged direct call to an untagged deployment to be denied with 401, got {result}" ) + assert TAG_DENIAL_MESSAGE in result.body, ( + f"expected the denial to come from tag routing, got a 401 reading {result.body[:300]}" + ) class TestResponsesApiTagRouting: