yassin
82eef2fcca
fix(proxy): scope agent permissions to invoking caller
...
An agent key that echoes the x-litellm-user-id / x-litellm-team-id headers
forwarded by /a2a is capped at that user's and team's models, MCP servers
and agents, on top of its own grants and access group ceiling. The echoed
ids only narrow, and nested A2A hops forward the original human caller
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-09-21 22:32:32 +00:00
yassin
d338d3f2d2
style(agents): tidy typing and docstring in access group ceiling helpers
...
LiteLLM Rust / rust-lint (push) Has been cancelled
LiteLLM Rust / rust-test (push) Has been cancelled
LiteLLM Rust / rust-wheel (push) Has been cancelled
Terraform Provider / gofmt, vet, build, test (push) Has been cancelled
Terraform Provider / Provider endpoints vs proxy OpenAPI schema (push) Has been cancelled
Terraform Modules / fmt, validate, test (aws) (push) Has been cancelled
Terraform Modules / fmt, validate, test (gcp) (push) Has been cancelled
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-09-20 09:40:46 +00:00
yassin
85da9cb588
Merge remote-tracking branch 'origin/main' into litellm_agent_access_groups
...
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-09-20 09:31:24 +00:00
yuneng-jiang
829963f86a
Merge pull request #42113 from BerriAI/litellm_unit_socket_block_at_import
...
test(unit): block external sockets at import time and add a socket policy regression test
2026-09-20 02:29:28 -07:00
yassin
31caa98a41
Merge remote-tracking branch 'origin/main' into litellm_agent_access_groups
...
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
# Conflicts:
# tests/test_litellm/proxy/auth/test_auth_checks.py
2026-09-20 08:52:45 +00:00
yuneng
99c2ef4d73
test(unit): block external sockets at import time and add a socket policy regression test
...
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-09-20 08:07:50 +00:00
yuneng-jiang
6ef7b86748
Merge pull request #42103 from BerriAI/litellm_test_unit_ci_wiring
...
ci(tests): wire tests/unit into CircleCI and keep draining GHA shards green
2026-09-20 00:50:00 -07:00
yuneng-jiang
776f8bc309
Merge pull request #40932 from BerriAI/litellm_v2_migration_startup
...
fix(proxy): coordinate v2 migration startup and qualify container recovery
2026-09-20 00:21:02 -07:00
yuneng
adadeac245
Revert "ci(tests): temporarily point one shard at an empty directory"
...
This reverts commit 3c094dbaaa .
2026-09-20 07:10:43 +00:00
yuneng
3c094dbaaa
ci(tests): temporarily point one shard at an empty directory
...
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-09-20 07:08:09 +00:00
yuneng
df7a3d2d1e
ci(tests): share the loopback allow list in the unit conftest
...
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-09-20 07:06:39 +00:00
yuneng
446bd1b250
ci(tests): wire tests/unit into CircleCI and drain legacy unit shards green
...
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-09-20 07:05:42 +00:00
Yuneng Jiang
e34fd201b3
Merge remote-tracking branch 'origin/main' into litellm_v2_migration_startup
2026-09-19 23:59:26 -07:00
yuneng-jiang
d5d12edbae
Merge pull request #42099 from BerriAI/litellm_test_tier_contract
...
docs(tests): define the tier contract for unit, integration and e2e
2026-09-19 23:29:15 -07:00
yuneng
3f4fe7db82
docs(tests): define the tier contract for unit, integration and e2e
...
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-09-20 06:24:06 +00:00
Mateo Wang
58065d46fd
Merge pull request #42071 from BerriAI/litellm_remove_dead_telemetry_flag
2026-09-19 21:48:02 -07:00
kerry-berri
d744fd1269
Merge pull request #42092 from BerriAI/litellm-providers/price-sync-openrouter
...
chore(prices): sync OpenRouter prices: 1 model
2026-09-19 21:42:53 -07:00
berriai-litellm-provider-info-sync[bot]
3619142a52
chore(prices): sync OpenRouter prices: 1 model
...
openrouter/z-ai/glm-5.2: input_cost_per_token, output_cost_per_token, cache_read_input_token_cost
2026-09-20 04:30:59 +00:00
kerry-berri
dd40137463
Merge pull request #42089 from BerriAI/litellm-providers/price-sync-openrouter
...
chore(prices): sync OpenRouter prices: 1 model
2026-09-19 21:12:54 -07:00
berriai-litellm-provider-info-sync[bot]
3720435638
chore(prices): sync OpenRouter prices: 1 model
...
openrouter/deepseek/deepseek-v4-flash: input_cost_per_token, output_cost_per_token, cache_read_input_token_cost
2026-09-20 04:00:57 +00:00
Mateo Wang
4011367b39
Merge pull request #40986 from BerriAI/litellm_lit_7346_multi_choice_stream_guardrails
...
fix(guardrails): scan each choice's tool-call arguments apart on n>1 streams and log why a rewrite was discarded
2026-09-19 20:34:05 -07:00
Mateo Wang
9d7f77988a
Merge pull request #41974 from BerriAI/litellm_fix_startup_view_creation_race
...
fix(proxy): wait for the spend-log table before creating startup views
2026-09-19 20:33:49 -07:00
mateo-berri
19d77e2442
test(guardrails): type the recorder hook's request_data as a Mapping
2026-09-19 20:21:37 -07:00
mateo
f7756d01cf
refactor(proxy): freeze the filtered worker config before initialize
...
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-09-20 03:21:01 +00:00
mateo
b2e123da43
fix(proxy): drop legacy telemetry key from persisted WORKER_CONFIG before initialize
...
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-09-20 03:14:11 +00:00
kerry-berri
4e55e995e1
Merge pull request #42082 from BerriAI/litellm-providers/price-sync-openrouter
...
chore(prices): sync OpenRouter prices: 7 models, 6 deprecated
2026-09-19 20:12:30 -07:00
Mateo Wang
ef7da9b49f
Merge pull request #42072 from BerriAI/litellm_mcp_cold_worker_tools_call
...
fix(mcp): tools/call no longer 404s on a worker that has not served tools/list
2026-09-19 20:04:33 -07:00
mateo-berri
327447bc10
Merge remote-tracking branch 'origin/main' into litellm_fix_startup_view_creation_race
...
# Conflicts:
# tests/test_litellm/proxy/test_proxy_server.py
2026-09-19 20:02:33 -07:00
berriai-litellm-provider-info-sync[bot]
2271c83731
chore(prices): sync OpenRouter prices: 7 models, 6 deprecated
...
openrouter/baidu/ernie-4.5-vl-424b-a47b: deprecation_date
openrouter/deepseek/deepseek-r1-distill-llama-70b: deprecation_date
openrouter/deepseek/deepseek-v3.1-terminus: deprecation_date
openrouter/deepseek/deepseek-v3.2: deprecation_date
openrouter/deepseek/deepseek-v3.2-exp: deprecation_date
openrouter/deepseek/deepseek-v4-flash: input_cost_per_token, output_cost_per_token, cache_read_input_token_cost
openrouter/minimax/minimax-m2.1: deprecation_date
2026-09-20 03:00:53 +00:00
joshua-berri
8df260a13d
Merge pull request #42051 from BerriAI/litellm_mcp_oauth_e2e_3467_rework
...
test(e2e): restore MCP OAuth happy-path coverage (LIT-3467)
2026-09-20 02:50:14 +00:00
mateo
fdd91a347a
test: drop narration comment from telemetry flag test
...
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-09-20 02:44:52 +00:00
Mateo Wang
b4447096e4
Merge pull request #42067 from BerriAI/litellm_genai_adapter_response_schema_tool_params
...
fix(google_genai): forward response schema and tool parameters through the generateContent adapter
2026-09-19 19:43:32 -07:00
kerry-berri
a8790db419
Merge pull request #42077 from BerriAI/litellm-providers/price-sync-openrouter
...
chore(prices): sync OpenRouter prices: 2 models
2026-09-19 19:42:00 -07:00
Mateo Wang
79e25d1e96
Merge pull request #42045 from BerriAI/litellm_lit_8201_notfound_retry_policy
...
fix(router): add NotFoundErrorRetries so a retry policy can pin 404 retries
2026-09-19 19:37:45 -07:00
mateo
8e530cf819
fix: keep --telemetry as a hidden no-op so existing start commands still parse
...
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-09-20 02:36:59 +00:00
berriai-litellm-provider-info-sync[bot]
344ce9328b
chore(prices): sync OpenRouter prices: 2 models
...
openrouter/~deepseek/deepseek-pro-latest: max_tokens, max_output_tokens, input_cost_per_token, output_cost_per_token, cache_read_input_token_cost
openrouter/deepseek/deepseek-v4-pro-0813: max_tokens, max_output_tokens, off_peak_pricing, input_cost_per_token, output_cost_per_token, cache_read_input_token_cost
2026-09-20 02:30:52 +00:00
mateo-berri
a3e9ed34fe
fix(mcp): gate the pre-call listing per tool, not per server
...
A tools/call on a cold worker listed the target server once and then never
again, so a later caller whose credentials expose a wider upstream catalog
got 404 for tools the first caller never had. Gate the pre-call listing on
whether this worker already exposes the requested tool, so callers with
different catalogs no longer mask each other. Removing the per-server guard
also drops the empty-listing case that re-listed on every call.
2026-09-19 19:29:33 -07:00
yuneng-jiang
09e14a485c
Merge pull request #42061 from BerriAI/litellm_fix_gcs_pub_sub_autorouter_golden
...
test(logging): add autorouter estimate keys to the GCS pub/sub spend-log golden
2026-09-19 19:22:41 -07:00
mateo-berri
5eb967d925
fix(google_genai): drop non-object tool parameters instead of forwarding them
2026-09-19 19:19:33 -07:00
Mateo Wang
5417abd586
Merge pull request #42011 from BerriAI/litellm_scrub_default_master_key
...
docs: stop advertising sk-1234 as the master key in shipped configs and examples
2026-09-19 19:05:31 -07:00
Mateo Wang
b6dd3d932c
Merge pull request #42019 from BerriAI/litellm_master_key_boot_enforcement
...
feat(proxy)!: refuse to start with an unset, empty, or publicly known master key
2026-09-19 19:04:02 -07:00
ryan-crabbe-berri
ecf17513fb
refactor(proxy): rename the local development override to dangerously_permit_weak_or_unset_master_key so the name says exactly what it permits
2026-09-19 18:53:14 -07:00
mateo-berri
2e83871d54
test(guardrails): type the recorder hook's logging_obj as object
2026-09-19 18:52:28 -07:00
mateo-berri
47ebfa10a0
fix(google_genai): reuse the shared key filter for Gemini-only schema keys
2026-09-19 18:52:00 -07:00
mateo-berri
92ff54f134
fix(mcp): list a never-listed server before its first tools/call
...
The startup tool-name fill skips servers whose upstream wants the caller's
own token (true_passthrough, OAuth discovery), and mcp 2 no longer runs the
list handler before an uncached tools/call, so every uvicorn worker that had
not served tools/list answered 404 "Tool not found" for prefixed tools/call
and the REST server_id route on those servers.
On a resolution miss, execute_mcp_tool now lists the prefix-matched (or
server_id-requested) server once, with the caller's credentials, through the
existing tools/list path, then resolves as before. Listing failures fall
through to the existing 404, a worker that already listed the server never
re-lists it, and a server outside the caller's allowed set is never listed.
2026-09-19 18:49:26 -07:00
mateo
f820472488
chore: remove the dead telemetry flag from the SDK, proxy CLI and configs
...
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
2026-09-20 01:44:10 +00:00
mateo-berri
810acdad97
chore(streaming): drop the redundant tool-call map comment and restore the OpenAPI snapshot
2026-09-19 18:35:11 -07:00
mateo-berri
fba179f2c0
fix(google_genai): forward response schema and tool parameters through the generateContent adapter
2026-09-19 18:31:09 -07:00
joshua-berri
daecea3eb8
Merge pull request #42050 from BerriAI/litellm_mcp_scoped_regressions_4506_rework
...
test(mcp): restore scoped execution and credential isolation regressions
2026-09-20 01:29:44 +00:00
Mateo Wang
93e39d5042
Merge pull request #42062 from BerriAI/litellm_pr38499_batch_retrieve_model_group
...
fix(router): stamp model_group when retrieving a batch, so batch tokens are attributable (internal copy of #38499 )
2026-09-19 18:23:06 -07:00