Merge pull request #38403 from BerriAI/litellm_lit3373_valkey_acl

fix(caching): require the namespace delimiter when checking already-namespaced redis keys
This commit is contained in:
Mateo Wang 2026-08-26 14:04:51 -07:00 • committed by GitHub
commit f57e4b812c
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
2 changed files with 26 additions and 1 deletions

View file

@ -435,7 +435,7 @@ class RedisCache(BaseCache):
"""
if key is None:
return key
if self.namespace is not None and not key.startswith(self.namespace):
if self.namespace and not key.startswith(self.namespace + ":"):
key = self.namespace + ":" + key
return key

View file

@ -17,6 +17,31 @@ def redis_no_ping():
yield
@pytest.mark.parametrize(
("namespace", "key", "expected"),
[
("litellm", "litellm_spend_update_buffer", "litellm:litellm_spend_update_buffer"),
("litellm", "litellm_config:param:general_settings", "litellm:litellm_config:param:general_settings"),
("litellm", "litellm:3997c4abcdef", "litellm:3997c4abcdef"),
("litellm", "spend:key:3997c4abcdef", "litellm:spend:key:3997c4abcdef"),
(None, "litellm_spend_update_buffer", "litellm_spend_update_buffer"),
("", "litellm_spend_update_buffer", "litellm_spend_update_buffer"),
],
)
def test_check_and_fix_namespace_prefixes_keys_sharing_the_namespace_prefix(
namespace, key, expected, monkeypatch, redis_no_ping
):
"""A key whose name merely begins with the namespace string (e.g.
litellm_spend_update_buffer under namespace "litellm") is not namespaced
yet and must still get the "namespace:" prefix; only a key already carrying
the delimited prefix is left alone. Without this, spend update buffers and
litellm_config:param:* keys reach Redis unprefixed and NOPERM under an ACL
scoped to the namespace pattern."""
monkeypatch.setenv("REDIS_HOST", "https://my-test-host")
redis_cache = RedisCache(namespace=namespace)
assert redis_cache.check_and_fix_namespace(key=key) == expected
@pytest.mark.parametrize("namespace", [None, "litellm"])
@pytest.mark.asyncio
async def test_async_delete_cache_applies_namespace(