This reverts commits 54b42e3f05, 4864227716, 77915d43b8 and e39e1c8dea. Jev does not use the member auto-router write path and no other stable line ships it, so dropping the port leaves 1.100.x matching stable/1.101.x and stable/1.102.x
The classifier circuit breaker's litellm Timeout detection that 54b42e3f05 carried is kept, since main and the other lines have it
This reverts commit e39e1c8dea.
This reverts commit 77915d43b8.
This reverts commit 4864227716.
This reverts commit 54b42e3f05.
Bugbot flagged that the member create path ran its name-collision check without any lock, so two concurrent creates of the same name could both pass. Take the same pg_advisory_xact_lock main takes at the top of the write transaction so member writes serialize before the checks run.
Greptile flagged that the member create path committed the router row inside the write slot and then failed on the endpoint-level authorization in team_model_add, leaving the router orphaned. Port append_team_models from main into team_endpoints and call it directly like main does, and widen the grant/view plumbing and write payload calls so the LIT001 and LIT002 gates stay within their ceilings.
The merged TestTeamMemberAutoRouterWrites class dropped the parametrize
decorator on test_admin_router_changes_release_member_scope, leaving the
test with an unsatisfiable endpoint fixture; this restores main's
patch/legacy x config/strategy/unrelated matrix. _full_team now sets
tpd_limit so the every-team-field grant coverage assertion sees the new
LiteLLM_VerificationTokenView field populated.
Bugbot on #42668 flagged that the backport's picks left the member
auto-router management path unwired on this line. This ports the pieces
that make it work, mirroring main: the member write slot in
model_management_endpoints (FOR UPDATE lock, team reload with the model
table include, identity and name-collision checks, post-commit config
publish), StoredAutoRouterIdentity wiring, the license feature helpers,
team tpd_limit, Router.config_deployments, the member_auto_router
ModelInfo flag, the _TEAM_GRANT_RELATIONS include on team lookups, and
the UserAPIKeyAuth fields the team_grants unpack needs. Test files were
rebuilt as line content plus the picks' own additions, and
ui_sso/test_team_grants carry the pick's grant assertions.
Gate-clearing edits stay local to what the picks added: prisma TypedDict
arguments replace mutable dict literals, remaining dict/mapping
arguments carry reasoned mutable-ok comments, test-quality-ok comments
mark the picks' internal-seam patches, and the regenerated dashboard api
types are staged. The only remaining make check failure is pre-existing
staging drift in untouched tests/test_litellm/test_router.py:2969.
The type check gate flagged six new reportArgumentType errors and one reportGeneralTypeIssues error over base: an outcome Final rebinding in the fallback path, a Mapping handed to the dict-typed request_kwargs parameter, optional message sequences passed to a non-optional parameter, DatabaseClient where PrismaClient is expected on two access-group lookups, the effective-config helper object return passed to the Mapping-typed validator, the project row passed to can_project_access_model, and the Response or None from AsyncHTTPHandler.post. The flagged sites now pass the right shape or carry a rule-scoped pyright ignore with the reason.
Merge debris cleanup and 1.102.x-only imports fixed; usesClassifierContext re-exported, JEV custom-tier emission, and preset test adapted to the static preset registry.
The #41615 and #41757 picks brought litellm/proxy/_lazy_openapi_snapshot.json and ui/litellm-dashboard/src/lib/http/schema.d.ts verbatim from main. Both files were regenerated under Python 3.12.
Backport of #41607 to stable/1.100.x.
Cherry-picked from deb9d8aedd (main).
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Backport of #42048 to stable/1.100.x.
Cherry-picked from 7966f50c34 (main). The safeguards backport maps the dangerous-tool-use-2026-09-03 beta for Bedrock, which Claude Opus 4.5 on Bedrock Invoke rejects as an invalid beta flag, so the all-beta-headers Bedrock cases run on Claude Fable 5.1 as they do on main.
The picked TypedDict fields use read-only Sequence[Mapping[str, object]] annotations and the picked Vertex test carries a test-quality-ok marker, so stable/1.100.x's LIT001, LIT012 and TQ008 budgets hold. Static typing only, no runtime change.
Hand-ported to stable/1.100.x from 47b2479c94 on main (fix(bedrock): gate Invoke tool search on the model map's supports_tool_search flag), the one prerequisite the #42288 handler tests need; the rest of that commit stays on main.
Backport of #42288 to stable/1.100.x.
Cherry-picked from merge commit fc82f6e8fa (litellm_safeguards_bedrock_vertex_messages).
The line has no bedrock_mantle beta-header mapping and no Mantle /v1/messages route, so the Mantle mapping, its test file, and the bedrock_mantle test parameter are left out.
Backports the Converse part of fbc6fb56ae from main (PR #31884). The gate only matched
openai.gpt-5, so a GPT-6 model fell through to Anthropic's thinking block and Bedrock
rejected the first real turn after a Claude Code /model switch with 400 Unknown
parameter: 'thinking'. The Nova 2 tool_choice registry keys and the invoke json_mode
forwarding in that commit stay on main
Backport of #41870 to stable/1.100.x. Cherry-picked from a6e3a72ed8 (main) with -m 1.
converse_transformation.py conflicted because this line has no `import re` and no
_is_openai_gpt_reasoning_model helper next to the insertion point. The resolution adds
exactly the four hunks #41870 merged: the import, the 16-token constant,
_requires_min_max_tokens, and the clamped maxTokens assignment. The test file applied clean.
Move the BaseLLMException import into _map_error_event_exception so the
module no longer imports it at load time, clearing the module-level cyclic
import CodeQL flagged. The class is used only on the cold error path.
Replace the mutable list-append test collector with aiter/anext so the
regression tests read the stream immutably.
(cherry picked from commit c246372859)
Mid-stream error events on the streaming Responses API were all raised as
APIError, so a content_policy_violation event never matched the router's
content-policy fallback dispatch and the client got the raw error instead
of the fallback model's answer. Map each error event's code and status
through the existing exception_type mapping, matching the non-streaming
path, and unwrap the typed ContentPolicyViolationError and
ContextWindowExceededError so the router routes them to the configured
content_policy_fallbacks and context_window_fallbacks.
(cherry picked from commit 073d4fe2b0)