mirror of
https://github.com/BerriAI/litellm.git
synced 2026-10-04 02:31:27 +00:00
fix(deps): raise aiohttp floor to 3.14.2 to clear pooled-connection timeouts
aiohttp 3.14.0 and 3.14.1 re-arm the sock_read timer on a keep-alive
connection after it has already been returned to the idle pool. The stray
timer stamps a SocketTimeoutError on the pooled connection without closing
it, so the pool keeps handing it out and the next request to pick it up
fails instantly on an error left behind by an earlier, unrelated request.
Because a single pool is shared across providers, the failures appear
simultaneously across Vertex AI, Bedrock, Anthropic and OpenAI-compatible
deployments as sub-millisecond "Connection timed out" errors.
uv.lock resolved aiohttp 3.14.1 and the published images install via
`uv sync --frozen`, so every image built from that lock shipped the
regression. The wheel's own metadata declared `aiohttp>=3.10,<4.0`, which
also left pip consumers free to resolve into the same broken window, so
both the runtime floor and the uv constraint move to >=3.14.2.
Upstream fixed this in aio-libs/aiohttp#12954, released in aiohttp 3.14.2;
the lock now resolves 3.14.3. Raising the floor rather than capping below
3.14 keeps the advisories that the existing 3.14.1 floor cleared, so no
osv-scanner ignores are needed. litellm requires Python >=3.10 and aiohttp
3.14.2 requires >=3.10, so no supported interpreter loses support.
Both new tests fail on the previous pins and pass on these.
(cherry picked from commit ffd6ac52c5)
This commit is contained in:
parent
eadbcc7625
commit
e96c2722c9
3 changed files with 78 additions and 5 deletions
|
|
@ -23,7 +23,7 @@ dependencies = [
|
|||
"tokenizers>=0.21.0,<1.0",
|
||||
"click>=8.0.0,<9.0",
|
||||
"jinja2>=3.1.6,<4.0",
|
||||
"aiohttp>=3.10,<4.0",
|
||||
"aiohttp>=3.14.2,<4.0",
|
||||
"pydantic>=2.10.0,<3.0.0",
|
||||
"jsonschema>=4.0.0,<5.0",
|
||||
]
|
||||
|
|
@ -233,7 +233,7 @@ build-backend = "uv_build"
|
|||
[tool.uv]
|
||||
constraint-dependencies = [
|
||||
"tornado>=6.5.6",
|
||||
"aiohttp>=3.14.1,<4.0",
|
||||
"aiohttp>=3.14.2,<4.0",
|
||||
]
|
||||
override-dependencies = [
|
||||
"cryptography>=50.0.0,<51.0",
|
||||
|
|
|
|||
|
|
@ -201,3 +201,76 @@ def test_litellm_proxy_server_config_no_general_settings_v2_resolver():
|
|||
with the v1 variant when they share a database.
|
||||
"""
|
||||
_run_proxy_server_smoke_test(extra_proxy_args=["--use_v2_migration_resolver"])
|
||||
|
||||
|
||||
AIOHTTP_POOL_POISONING_RANGE = ">=3.14.0,<3.14.2"
|
||||
AIOHTTP_POOL_POISONING_RELEASES = ("3.14.0", "3.14.1")
|
||||
|
||||
|
||||
def _load_toml(path):
|
||||
try:
|
||||
import tomllib as tomli
|
||||
except ImportError:
|
||||
try:
|
||||
import tomli
|
||||
except ImportError:
|
||||
pytest.skip("tomli/tomllib not available - skipping dependency check")
|
||||
|
||||
with open(path, "rb") as f:
|
||||
return tomli.load(f)
|
||||
|
||||
|
||||
def _declared_aiohttp_specifier():
|
||||
from packaging.requirements import Requirement
|
||||
|
||||
pyproject = _load_toml(os.path.join(PROJECT_ROOT, "pyproject.toml"))
|
||||
for requirement in pyproject["project"]["dependencies"]:
|
||||
parsed = Requirement(requirement)
|
||||
if parsed.name.lower() == "aiohttp":
|
||||
return parsed.specifier
|
||||
pytest.fail("aiohttp is no longer a declared runtime dependency of litellm")
|
||||
|
||||
|
||||
def _locked_aiohttp_version():
|
||||
lock = _load_toml(os.path.join(PROJECT_ROOT, "uv.lock"))
|
||||
for package in lock["package"]:
|
||||
if package["name"].lower() == "aiohttp":
|
||||
return package["version"]
|
||||
pytest.fail("aiohttp is missing from uv.lock")
|
||||
|
||||
|
||||
def test_declared_aiohttp_floor_excludes_pool_poisoning_releases():
|
||||
"""aiohttp 3.14.0/3.14.1 re-arm the sock_read timer on a keep-alive connection
|
||||
after it is back in the idle pool, so the next request to reuse it fails
|
||||
instantly with a bogus timeout (aio-libs/aiohttp#12953, fixed in 3.14.2).
|
||||
|
||||
The wheel's own metadata is what pip resolves against, so the floor declared
|
||||
here - not just the lockfile - has to exclude that range.
|
||||
"""
|
||||
specifier = _declared_aiohttp_specifier()
|
||||
|
||||
admitted = [v for v in AIOHTTP_POOL_POISONING_RELEASES if specifier.contains(v)]
|
||||
assert not admitted, (
|
||||
f"litellm declares aiohttp{specifier}, which still admits {admitted}. "
|
||||
"Those releases poison pooled keep-alive connections and cause "
|
||||
"cross-provider sub-millisecond 'Connection timed out' failures; "
|
||||
"keep the floor at >=3.14.2."
|
||||
)
|
||||
|
||||
|
||||
def test_locked_aiohttp_version_is_not_pool_poisoning():
|
||||
"""uv.lock is what the published Docker images install (uv sync --frozen), so a
|
||||
lock that drifts back onto 3.14.0/3.14.1 ships the regression regardless of
|
||||
what pyproject.toml declares.
|
||||
"""
|
||||
from packaging.specifiers import SpecifierSet
|
||||
|
||||
locked = _locked_aiohttp_version()
|
||||
|
||||
assert not SpecifierSet(AIOHTTP_POOL_POISONING_RANGE).contains(locked), (
|
||||
f"uv.lock resolves aiohttp {locked}, which is inside the pool-poisoning "
|
||||
f"range {AIOHTTP_POOL_POISONING_RANGE} (aio-libs/aiohttp#12953). "
|
||||
"Re-run `uv lock` against an aiohttp>=3.14.2 floor."
|
||||
)
|
||||
|
||||
|
||||
|
|
|
|||
6
uv.lock
generated
6
uv.lock
generated
|
|
@ -9,7 +9,7 @@ resolution-markers = [
|
|||
]
|
||||
|
||||
[options]
|
||||
exclude-newer = "2026-08-05T07:40:35.209598Z"
|
||||
exclude-newer = "2026-08-05T07:44:13.302644Z"
|
||||
exclude-newer-span = "P3D"
|
||||
|
||||
[manifest]
|
||||
|
|
@ -19,7 +19,7 @@ members = [
|
|||
"litellm-proxy-extras",
|
||||
]
|
||||
constraints = [
|
||||
{ name = "aiohttp", specifier = ">=3.14.1,<4.0" },
|
||||
{ name = "aiohttp", specifier = ">=3.14.2,<4.0" },
|
||||
{ name = "tornado", specifier = ">=6.5.6" },
|
||||
]
|
||||
overrides = [{ name = "cryptography", specifier = ">=50.0.0,<51.0" }]
|
||||
|
|
@ -3468,7 +3468,7 @@ proxy-dev = [
|
|||
[package.metadata]
|
||||
requires-dist = [
|
||||
{ name = "a2a-sdk", marker = "extra == 'extra-proxy'", specifier = ">=0.3.24,<1.0" },
|
||||
{ name = "aiohttp", specifier = ">=3.10,<4.0" },
|
||||
{ name = "aiohttp", specifier = ">=3.14.2,<4.0" },
|
||||
{ name = "anthropic", extras = ["vertex"], marker = "extra == 'proxy-runtime'", specifier = ">=0.84.0,<1.0" },
|
||||
{ name = "apscheduler", marker = "extra == 'proxy'", specifier = ">=3.11.2,<4.0" },
|
||||
{ name = "audioread", marker = "extra == 'stt-nvidia-riva'", specifier = ">=3.0.1" },
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue