tin-berri
252a0f1eac
Merge pull request #41617 from BerriAI/litellm_fuse_model_profile_presets
...
feat(router): add maintained Fuse model and harness presets
2026-09-19 16:17:19 -07:00
yucheng
431ddbdd22
test(team): exercise the member-add audit helper directly and drop its dead user_id None guard
...
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-09-19 23:17:18 +00:00
tin-berri
cc2c0d0f66
Merge pull request #42001 from BerriAI/litellm_heuristic_v2_scores
...
fix(auto-router): show heuristic v2 score estimates in routing details
2026-09-19 16:16:59 -07:00
yucheng
f63782f678
fix(otel v2): reject a langfuse_span_scope that conflicts with another callback entry on the same team or key
...
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-09-19 23:16:54 +00:00
tin-berri
1944d40097
Merge pull request #41177 from BerriAI/litellm_autorouter_baseline_cache
...
fix(proxy): estimate auto-router baseline costs from durable cache history
2026-09-19 16:16:29 -07:00
Yuneng Jiang
dd6a3558d5
Merge remote-tracking branch 'origin/main' into litellm_websearch_activation_status
2026-09-19 16:16:25 -07:00
Yuneng Jiang
c0bc45224c
feat(ui): report whether the serving proxy has applied the interception setting
...
The stored flag is the cluster's desired state and is what the form saves, so it
cannot also stand as proof that this process activated the callback: a pod that
lagged or failed to apply it would still read as on. Report the process's own
registration as a separate read-only field and warn on the page when the two
disagree, so a failed activation is visible instead of only logged.
2026-09-19 16:16:17 -07:00
Mateo Wang
af6a1798e2
Revert "test(e2e): cover MCP OAuth SSO and cold restart persistence"
2026-09-19 16:15:43 -07:00
Mateo Wang
57c757e9d7
Revert "test(mcp): verify scoped execution and OAuth credential isolation"
2026-09-19 16:10:47 -07:00
Mateo Wang
0058e1554b
Merge pull request #41909 from BerriAI/litellm_mcp_oauth_happy_path_e2e
...
test(e2e): cover MCP OAuth SSO and cold restart persistence
2026-09-19 16:08:51 -07:00
Yujong Lee
ad8ac449fc
style(rust): format renamed callback adapter
...
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-09-19 23:08:37 +00:00
Yujong Lee
df84fef96e
refactor(rust): rename legacy callback adapter crate
...
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-09-19 23:06:26 +00:00
Mateo Wang
43c0a267d5
Merge pull request #41731 from BerriAI/litellm_mcp_integration_regressions_4506
...
test(mcp): verify scoped execution and OAuth credential isolation
2026-09-19 16:05:56 -07:00
Mateo Wang
56408b3915
Merge pull request #42031 from BerriAI/litellm_internal_copy_41781
...
fix(azure): drop tool_choice when the request has no tools (internal copy of #41781 )
2026-09-19 16:03:32 -07:00
Joshua Valluru
7cd96e9c2d
test(mcp): assert redirect rejection without SDK wording
2026-09-19 16:01:42 -07:00
yuneng-jiang
5fc5afd595
Merge pull request #42007 from BerriAI/litellm_/web-search-autoship-scope-01a237
...
feat(ui): configure web search interception from the Admin UI
2026-09-19 15:54:03 -07:00
Joshua Valluru
064b7d10df
docs(mcp): clarify method-preserving redirect scope
2026-09-19 15:52:07 -07:00
Joshua Valluru
3fdc13ccef
test(mcp): cover SDK redirect compatibility
2026-09-19 15:51:01 -07:00
yucheng-berri
6afc807ae3
Merge pull request #42027 from BerriAI/litellm_stream_boundary_attr_forwarding
...
Co-authored-by: yucheng <yucheng@berri.ai>
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-09-19 15:47:54 -07:00
yucheng
cc41b80770
test(team): patch the scheduled member-add audit helper in the cache eviction test
...
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-09-19 22:46:37 +00:00
Mateo Wang
7651d6b550
Merge pull request #41942 from BerriAI/litellm_vllm_batch_runner
...
feat(batches): run hosted_vllm batches inside LiteLLM
2026-09-19 15:44:26 -07:00
Yuneng Jiang
4ea21cb75c
fix(ui): answer the interception panel from the stored flag, not the local pod
...
Deriving enabled from whether this process has the callback registered makes a
pod that has not polled yet report off while the cluster runs it, and the next
save writes that off back for every pod. The stored flag is the cluster's own
answer, so prefer it and fall back to local registration only when none is
stored, which is the config-activated case that has no flag to read.
2026-09-19 15:42:16 -07:00
yucheng
2ade97f80e
Merge remote-tracking branch 'origin/main' into litellm_team_audit_lifecycle
2026-09-19 22:41:02 +00:00
yucheng
181406e05f
fix(team): schedule membership audit writes after commit and lock the roster on role updates
...
The member add, delete and role-change audit rows were awaited on the
request path, so a slow audit sink held the response, and the roster was
serialized before checking whether audit logging is enabled at all.
Membership audit work is now scheduled after the transaction commits and
skipped outright when auditing is off.
member_update read the roster outside the team advisory lock and wrote
it back, so a concurrent add or delete could be lost. It now takes the
lock, rereads the roster, and builds the before and after snapshots from
that read.
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-09-19 22:33:22 +00:00
ryan-crabbe-berri
bdbb4e4610
Merge pull request #41681 from BerriAI/litellm_org_alias_from_team
...
fix(auth): inherit org alias, budget and rate limits for JWT and team-linked keys
2026-09-19 15:25:14 -07:00
ryan-crabbe-berri
370eacce12
Merge pull request #41997 from BerriAI/litellm_project_zero_budget_blocks
...
fix(proxy): block project requests when max_budget is 0
2026-09-19 15:24:18 -07:00
yuneng-jiang
b6dbf145cb
Merge pull request #42009 from BerriAI/litellm_config_store_qa_fixes
...
fix(proxy): close the config-ownership gaps QA found in the settings store
2026-09-19 15:20:13 -07:00
Joshua Valluru
d5ac850feb
test(e2e): isolate diagnostic reporter subprocess
2026-09-19 15:13:27 -07:00
Joshua Valluru
31b4405435
chore: merge main with shared E2E lockout fix
2026-09-19 15:10:55 -07:00
Joshua Valluru
5b9f3d4cdb
chore: merge latest main for MCP regression verification
2026-09-19 15:04:07 -07:00
yucheng
358e4ea27a
fix(otel v2): stop langfuse_span_scope tripping the family guard, normalize its spelling, and keep tenant routes on the full scope
...
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-09-19 22:00:02 +00:00
Joshua Valluru
90687ae597
test(e2e): detect fast upstream reauthorization on reconnect
2026-09-19 14:39:03 -07:00
yuneng-jiang
974e4f109c
Merge pull request #42025 from BerriAI/litellm_/release-version-bump-906e1d
...
chore: bump litellm-enterprise 0.1.68 -> 0.1.69, litellm-proxy-extras 0.4.99 -> 0.4.100
2026-09-19 14:38:35 -07:00
yucheng
540375cfeb
fix(proxy): forward stream attributes and merge logged guardrails
...
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-09-19 21:36:01 +00:00
yuneng-jiang
0b145ea149
Merge pull request #42008 from BerriAI/litellm_/litellm-e2e-buildkite-rc-694bbe
...
test(e2e): stop the config suite locking itself out of the shared proxy
2026-09-19 14:32:15 -07:00
Yuneng Jiang
8767f12794
bump: litellm-enterprise 0.1.68 -> 0.1.69, litellm-proxy-extras 0.4.99 -> 0.4.100
2026-09-19 14:27:21 -07:00
Yuneng Jiang
e7fd89fc02
fix(ui): narrow the web search settings response instead of asserting its shape
2026-09-19 14:27:10 -07:00
Yuneng Jiang
9c3a7133f1
test: cover the config-owned refusal on the email reset route
2026-09-19 14:25:52 -07:00
yucheng-berri
ac281507fd
Merge pull request #41991 from BerriAI/litellm_otel_v2_langfuse_responses_output
...
fix(otel v2): map Responses API output onto the Langfuse generation output
2026-09-19 14:23:59 -07:00
ryan-crabbe-berri
fdd614d759
fix(proxy): tell users with an already exported master key to replace it in place, because it wins over .env
2026-09-19 14:22:52 -07:00
Yuneng Jiang
e5398e7e30
test: drop two inert type: ignore comments
...
pyrightconfig.json sets enableTypeIgnoreComments to false and does not
include tests/, so neither comment suppressed anything.
2026-09-19 14:22:19 -07:00
ryan-crabbe-berri
3c9c860de7
test(proxy): set the unsafe-proxy override at the remaining test boot sites and isolate the boot test from a leaked scheduler
2026-09-19 14:16:52 -07:00
mateo-berri
0ae5d7c2fa
Merge remote-tracking branch 'origin/main' into litellm_pr41781_azure_tool_choice
...
# Conflicts:
# tests/test_litellm/llms/azure/chat/test_azure_chat_gpt_transformation.py
2026-09-19 14:15:19 -07:00
Yassin Kortam
884351168a
Merge pull request #42003 from BerriAI/litellm_fix_terraform_registry_docs_links
2026-09-19 14:02:05 -07:00
mateo-berri
a61bceb0cf
fix(files): read storage-backed managed files from their storage backend
...
The managed files hook's content read looped the file's model mappings and asked each deployment for the file. A file LiteLLM stored itself maps every model to its storage url, so the read sent that internal id to the upstream server, failed, and the batch rate limiter failed open: a key's TPM limit did not apply to a LiteLLM-executed batch. The hook now returns the stored bytes from the file's storage backend before it consults any deployment
2026-09-19 14:00:51 -07:00
ryan-crabbe-berri
0049a51f9b
fix(proxy): import assert_never from typing_extensions for Python 3.10 and keep the lazy OpenAPI snapshot as generated by CI's Python
2026-09-19 13:56:43 -07:00
ryan-crabbe-berri
186ba50bce
fix(proxy): point users who must rotate at the rotation guide before they save a new key
2026-09-19 13:49:32 -07:00
yujonglee
d675c1285b
Merge pull request #41987 from BerriAI/litellm_rust_fork_safety
...
fix(rust): refuse native routes in processes forked after the runtime started
2026-09-19 13:47:54 -07:00
ryan-crabbe-berri
0415382f9e
fix(proxy): word the config step so it also fits a config that already reads the environment
2026-09-19 13:45:11 -07:00
ryan-crabbe-berri
fe480533e8
feat(proxy)!: refuse to start with an unset, empty, or publicly known master key
...
The proxy used to boot with no master key (every request accepted without
authentication) and with sk-1234, the key every example used. It now stops at
startup, before it connects to the database, and prints how to fix it: where the
bad key came from, a copy-pastable command that generates a secure key, and,
when the public key is also encrypting a database, a link to the rotation guide
general_settings.dangerously_allow_unsafe_proxy: true or
LITELLM_DANGEROUSLY_ALLOW_UNSAFE_PROXY=true starts the proxy anyway, for local
development. CI and test boots that rely on sk-1234 or on no key set it
BREAKING CHANGE: deployments with no master key, an empty one, or sk-1234 no
longer start until they set a real key or opt in to the override
2026-09-19 13:44:00 -07:00