Commit graph

45701 commits

Author SHA1 Message Date
devin-ai-integration[bot]
54b42e3f05 fix(proxy): port the member auto-router write path and grant plumbing to stable/1.100.x
Bugbot on #42668 flagged that the backport's picks left the member
auto-router management path unwired on this line. This ports the pieces
that make it work, mirroring main: the member write slot in
model_management_endpoints (FOR UPDATE lock, team reload with the model
table include, identity and name-collision checks, post-commit config
publish), StoredAutoRouterIdentity wiring, the license feature helpers,
team tpd_limit, Router.config_deployments, the member_auto_router
ModelInfo flag, the _TEAM_GRANT_RELATIONS include on team lookups, and
the UserAPIKeyAuth fields the team_grants unpack needs. Test files were
rebuilt as line content plus the picks' own additions, and
ui_sso/test_team_grants carry the pick's grant assertions.

Gate-clearing edits stay local to what the picks added: prisma TypedDict
arguments replace mutable dict literals, remaining dict/mapping
arguments carry reasoned mutable-ok comments, test-quality-ok comments
mark the picks' internal-seam patches, and the regenerated dashboard api
types are staged. The only remaining make check failure is pre-existing
staging drift in untouched tests/test_litellm/test_router.py:2969.
2026-09-23 06:04:07 +00:00
Devin AI
a392f7bc66 fix(typing): clear the basedpyright errors the picks introduced
The type check gate flagged six new reportArgumentType errors and one reportGeneralTypeIssues error over base: an outcome Final rebinding in the fallback path, a Mapping handed to the dict-typed request_kwargs parameter, optional message sequences passed to a non-optional parameter, DatabaseClient where PrismaClient is expected on two access-group lookups, the effective-config helper object return passed to the Mapping-typed validator, the project row passed to can_project_access_model, and the Response or None from AsyncHTTPHandler.post. The flagged sites now pass the right shape or carry a rule-scoped pyright ignore with the reason.
2026-09-23 03:57:38 +00:00
Devin AI
46f81ba3e0 fix: place lint suppressions on the flagged annotation lines 2026-09-23 03:14:10 +00:00
Devin AI
8e4c26fea3 fix(ui): adapt the jev dashboard pieces to stable/1.100.x
Merge debris cleanup and 1.102.x-only imports fixed; usesClassifierContext re-exported, JEV custom-tier emission, and preset test adapted to the static preset registry.
2026-09-23 03:14:10 +00:00
devin-ai-integration[bot]
746686c34e feat(openrouter): price typesafe/jev-1.13 and add an openrouter decisions pass-through (#42301) 2026-09-23 03:14:10 +00:00
Devin AI
12ef369373 chore(backport): regenerate the openapi snapshot and dashboard api types for stable/1.100.x
The #41615 and #41757 picks brought litellm/proxy/_lazy_openapi_snapshot.json and ui/litellm-dashboard/src/lib/http/schema.d.ts verbatim from main. Both files were regenerated under Python 3.12.
2026-09-23 03:14:10 +00:00
mateo-berri
c3c466a5c1 fix(ui): adapt the jev dashboard pieces to stable/1.102.x
(cherry picked from commit 4bfac88281)
2026-09-23 03:14:10 +00:00
moe-berri
73e50a09cb feat(auto-router): add JEV classifier alongside LLM classifier
Backport of #41886 to stable/1.100.x.
Cherry-picked from a83773cfa5 (main).
2026-09-23 03:14:10 +00:00
moe-berri
4fa1e08fc2 fix(proxy): enforce virtual key budgets for JEV test routing
Backport of #41879 to stable/1.100.x.
Cherry-picked from 1e161f516c (main).
2026-09-23 03:14:10 +00:00
Yassin Kortam
d1bf6094be feat(guardrails): add TypeSafe Jev relevance-based compaction guardrail
Backport of #41757 to stable/1.100.x.
Cherry-picked from 2edda5aec3 (main).
2026-09-23 03:14:10 +00:00
yuneng-jiang
ded7f601d9 fix(proxy): forward every method on the typesafe pass-through route
Backport of #41723 to stable/1.100.x.
Cherry-picked from 34718f0da6 (main).
2026-09-23 03:14:10 +00:00
Mateo Wang
8bf252b397 feat(router): add TypeSafe Jev as a complexity router classifier
Backport of #41615 to stable/1.100.x.
Cherry-picked from cf42b607c3 (main).
2026-09-23 03:14:10 +00:00
moe-berri
d400ee2b7e feat(router): add classifier circuit breaker
Prerequisite for #41615 on stable/1.100.x.
Cherry-picked from 510424c86c (main).
2026-09-23 03:14:10 +00:00
Tin Chi Lo
44b7b48e46 feat(auto-router): allow opted-in team members to manage their routers
Prerequisite for #41615 and #41879 on stable/1.100.x.

Cherry-picked from 109ca70f66 (main).
2026-09-23 03:14:10 +00:00
ryan-crabbe-berri
61d725d55f fix(proxy): apply team model aliases on the JWT auth path
Prerequisite for #41615 on stable/1.100.x.

Cherry-picked from 7015bf37bb (main).
2026-09-23 03:14:10 +00:00
Mateo Wang
9c1216a427
Merge pull request #42597 from BerriAI/litellm_cherrypick_1_100_x
feat(typesafe): backport #41607 to stable/1.100.x for v1.100.2
2026-09-22 20:01:40 -07:00
mateo-berri
1ebc488f07 feat(typesafe): add TypeSafe Jev passthrough with logging and cost tracking
Backport of #41607 to stable/1.100.x.
Cherry-picked from deb9d8aedd (main).

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-09-22 21:34:24 +00:00
Mateo Wang
35f5b7c1b3
Merge pull request #42532 from BerriAI/litellm_cherrypick_safeguards_1_100_x
fix(anthropic): backport #42152 and #42288 to stable/1.100.x for v1.100.2
2026-09-22 14:29:28 -07:00
kerry
4438739b46 fix(test): run the all-beta-headers bedrock cases on Claude Fable 5.1
Backport of #42048 to stable/1.100.x.
Cherry-picked from 7966f50c34 (main). The safeguards backport maps the dangerous-tool-use-2026-09-03 beta for Bedrock, which Claude Opus 4.5 on Bedrock Invoke rejects as an invalid beta flag, so the all-beta-headers Bedrock cases run on Claude Fable 5.1 as they do on main.
2026-09-22 12:55:12 -07:00
mateo-berri
8ccfd6a84e chore(types): keep the backported safeguards annotations within the line's budgets
The picked TypedDict fields use read-only Sequence[Mapping[str, object]] annotations and the picked Vertex test carries a test-quality-ok marker, so stable/1.100.x's LIT001, LIT012 and TQ008 budgets hold. Static typing only, no runtime change.
2026-09-22 11:42:39 -07:00
mateo-berri
eb23cee8ff test: add the local_beta_headers_config fixture the safeguards tests use
Hand-ported to stable/1.100.x from 47b2479c94 on main (fix(bedrock): gate Invoke tool search on the model map's supports_tool_search flag), the one prerequisite the #42288 handler tests need; the rest of that commit stays on main.
2026-09-22 10:38:07 -07:00
mateo-berri
0d95fba73c fix(anthropic): forward Claude Code safeguards and dangerous-tool-use beta to Bedrock Invoke and Vertex on /v1/messages
Backport of #42288 to stable/1.100.x.
Cherry-picked from merge commit fc82f6e8fa (litellm_safeguards_bedrock_vertex_messages).
The line has no bedrock_mantle beta-header mapping and no Mantle /v1/messages route, so the Mantle mapping, its test file, and the bedrock_mantle test parameter are left out.
2026-09-22 10:16:54 -07:00
Yassin Kortam
3469a82da8 fix(anthropic): forward safeguards and anthropic-beta unchanged on native /v1/messages
Backport of #42152 to stable/1.100.x.
Cherry-picked from merge commit e912ebe999 (litellm_claude_code_safeguards_passthrough).
2026-09-22 10:16:25 -07:00
Mateo Wang
44d3c4f290
Merge pull request #42000 from BerriAI/litellm_cherrypick_1_100_x
fix(bedrock): backport #41870 and the GPT-6 reasoning gate fix to stable/1.100.x for v1.100.2
2026-09-19 15:34:17 -07:00
mateo-berri
5545ca9e86 fix(bedrock): match any openai.gpt-<digit> model in the Converse reasoning gate
Backports the Converse part of fbc6fb56ae from main (PR #31884). The gate only matched
openai.gpt-5, so a GPT-6 model fell through to Anthropic's thinking block and Bedrock
rejected the first real turn after a Claude Code /model switch with 400 Unknown
parameter: 'thinking'. The Nova 2 tool_choice registry keys and the invoke json_mode
forwarding in that commit stay on main
2026-09-19 12:43:58 -07:00
mateo-berri
1a14aadd03 bump: version 1.100.2 2026-09-19 12:13:22 -07:00
mateo-berri
fff43dfc05 fix(bedrock): clamp maxTokens to the 16-token minimum for OpenAI GPT and xAI Grok models on Converse (#41870)
Backport of #41870 to stable/1.100.x. Cherry-picked from a6e3a72ed8 (main) with -m 1.

converse_transformation.py conflicted because this line has no `import re` and no
_is_openai_gpt_reasoning_model helper next to the insertion point. The resolution adds
exactly the four hunks #41870 merged: the import, the 16-token constant,
_requires_min_max_tokens, and the clamped maxTokens assignment. The test file applied clean.
2026-09-19 12:11:50 -07:00
Mateo Wang
b7d81e98b6
Merge pull request #41208 from BerriAI/litellm_backport_1_100_x_responses_content_policy_fallback
fix(responses): backport mid-stream content_policy_violation fallback routing to stable/1.100.x
2026-09-15 02:47:52 -07:00
mateo-berri
40f4fa2629 test(responses): import import_module in the error-events tests 2026-09-15 01:41:17 -07:00
mateo-berri
2e3a7f689d fix(responses): keep context-window events out of mid-stream fallback and fix stale exception assertions
(cherry picked from commit fff7a2cecf)
2026-09-15 01:16:38 -07:00
mateo-berri
2e44af6d20 fix(responses): import BaseLLMException lazily and collect stream chunks via anext
Move the BaseLLMException import into _map_error_event_exception so the
module no longer imports it at load time, clearing the module-level cyclic
import CodeQL flagged. The class is used only on the cold error path.

Replace the mutable list-append test collector with aiter/anext so the
regression tests read the stream immutably.

(cherry picked from commit c246372859)
2026-09-15 01:16:38 -07:00
mateo-berri
80b2c803bd fix(responses): route mid-stream error events through exception_type so content_policy_fallbacks fire
Mid-stream error events on the streaming Responses API were all raised as
APIError, so a content_policy_violation event never matched the router's
content-policy fallback dispatch and the client got the raw error instead
of the fallback model's answer. Map each error event's code and status
through the existing exception_type mapping, matching the non-streaming
path, and unwrap the typed ContentPolicyViolationError and
ContextWindowExceededError so the router routes them to the configured
content_policy_fallbacks and context_window_fallbacks.

(cherry picked from commit 073d4fe2b0)
2026-09-15 01:16:38 -07:00
Mateo Wang
1dba17b10d
Merge pull request #40495 from BerriAI/litellm_revert_1_100_x_spend_backports
revert: drop the spend attribution backports from stable/1.100.x
2026-09-09 18:10:35 -07:00
mateo-berri
dec2c2a72a Revert "fix(spend-tracking): keep batch spend keys joinable after v1.99 provenance gate (#39568)"
This reverts commit 803e0f736e.
2026-09-09 16:58:47 -07:00
mateo-berri
d7198f48c0 Revert "fix(spend-tracking): keep internal service-account key names readable in spend logs (#39572)"
This reverts commit c2e18a4320.
2026-09-09 16:58:46 -07:00
Mateo Wang
e4e811ce2b
Merge pull request #40455 from BerriAI/litellm_backport_1_100_x_retry_breadcrumb_growth
fix(router): backport #39491 to stable/1.100.x so retry breadcrumbs stop retaining every earlier request
2026-09-09 14:27:44 -07:00
mateo-berri
a9ea5713ab test(router): type the breadcrumb test helpers 2026-09-09 14:01:38 -07:00
mateo-berri
76b5fec1c5 fix(router): keep retry breadcrumbs per request and out of the request snapshot
Backport of #39491 to stable/1.100.x. Cherry-picked from 7bc2d0b06e (litellm_internal_staging), with the router hunk of 7c87451ead.
2026-09-09 13:21:09 -07:00
Mateo Wang
ecc04bf811
Merge pull request #40176 from BerriAI/litellm_backport_1_100_x_spend_key_hash
chore(release): backport #39568 and #39572 to stable/1.100.x and cut 1.100.1
2026-09-07 17:18:00 -07:00
mateo-berri
0b176c30de chore: refresh uv.lock for 1.100.1 2026-09-07 16:05:53 -07:00
mateo-berri
8b0ae0285f bump: version 1.100.0 -> 1.100.1 2026-09-07 16:05:47 -07:00
mateo-berri
c2e18a4320 fix(spend-tracking): keep internal service-account key names readable in spend logs (#39572)
Backport of #39572 to stable/1.100.x.
Cherry-picked from merge commit da09976c16 (litellm_internal_staging) with -m 1.
2026-09-07 16:00:13 -07:00
Mateo Wang
803e0f736e fix(spend-tracking): keep batch spend keys joinable after v1.99 provenance gate (#39568)
Backport of #39568 to stable/1.100.x.
Cherry-picked from merge commit 04a198e3e3 (litellm_internal_staging) with -m 1.
2026-09-07 16:00:01 -07:00
yuneng-jiang
e4f2526570
Merge pull request #39992 from BerriAI/litellm_rc-1.100.0-wolfi-glibc-2.44
fix(docker): bump wolfi-base for glibc 2.44 and pin apk python to 3.13 on rc/1.100.0 (cherry-pick #38917, #38973)
2026-09-05 18:45:39 -07:00
mateo-berri
13f98f83f3
fix(docker): bump wolfi-base for glibc 2.44 and pin apk python to 3.13 in migrations image
(cherry picked from commit 39473745dd)
2026-09-05 18:06:16 -07:00
mateo-berri
728dec258f
fix(docker): bump wolfi-base for glibc 2.44 and pin apk python to 3.13
(cherry picked from commit 14f392bb9b)
2026-09-05 18:06:16 -07:00
yuneng-jiang
10631eb834
Merge pull request #38805 from BerriAI/litellm_internal_staging
chore(ci): promote internal staging to main
2026-08-29 18:09:58 -07:00
yuneng-jiang
6b33d17563
Merge pull request #38850 from BerriAI/litellm_e2e_retry_transient_upstream
test(e2e): retry upstream-saturation failures in the claude CLI driver
2026-08-29 17:48:04 -07:00
yuneng-jiang
df848d85ff
Merge pull request #38833 from BerriAI/litellm_deflake_reliability_fallbacks
test(e2e): stop the reliability fallback tests flaking on gpt-5.5's reasoning budget
2026-08-29 17:44:30 -07:00
yucheng-berri
3c2fa5fafb
fix(otel/v2): detach credential-routed tenant spans into their own trace (#38847)
* fix(otel/v2): detach credential-routed tenant spans into their own trace

Multi-tenant OTel v2 routes a team or key's LLM-call span to that tenant's
own vendor account (New Relic, Arize, Langfuse, Weave) via dynamic OTLP
credential headers, while the request-root, auth, and db spans stay on the
operator's default backend. The span was still parented into the request
trace, so the tenant account received a child whose parent it never got,
and New Relic rendered it as a fragmented trace with a missing parent.

Detach a credential-routed span the same way a project-routed (Phoenix)
span already detaches: root a fresh trace in the tenant account and link
back to the request trace for correlation. Service-name routing keeps
parenting, since it only relabels service.name on the same operator
backend where the parent is present.

Guard the detach on the callback actually owning an OTLP exporter the
credentials can reach: a callback owning only a console or in_memory
exporter has nowhere to stamp them, so the span would export to the
default backend unchanged and detaching would orphan it on the very
backend that holds its parent. In that case warn once and keep the
default tracer.

* fix(otel/v2): derive tenant-route routability from resolved exporter transport

A denylist classified an owned exporter as routable whenever its kind was
not console/in_memory, so a typo'd or unavailable kind (e.g. "otlp",
"grcp") passed the check while _exporter_from_spec falls it back to a
header-ignoring console exporter. Detaching such a span would root a fresh
trace that only ever reaches the operator console, never the tenant
backend, orphaning it on both sides.

Route on a shared exporter_transport() predicate that resolves the kind the
same way _exporter_from_spec builds it (registered factories + otlp_http
aliases -> http, otlp_grpc aliases -> grpc, else headerless), so an
unresolvable kind is headerless and stays parented. Fixes the same latent
gap in project routability.
2026-08-29 17:41:25 -07:00