Commit graph

45735 commits

Author SHA1 Message Date
devin-ai-integration[bot]
c872c815e5
Merge 55d1597645 into 90bd6e3de8 2026-10-03 05:11:20 -07:00
yuneng-jiang
90bd6e3de8
Merge pull request #44159 from BerriAI/litellm_chore_1c29d6
chore(release): backport #42643 to stable/1.100.x
2026-10-02 00:42:00 -07:00
yuneng-jiang
cb3e9fa710 chore(docker): bump wolfi-base digest to pick up glibc 2.44-r6 (#42643)
The pinned base's /etc/apk/world locks glibc-2.44=2.44-r1, so the apk upgrade in the runtime stage cannot move it. The new digest ships 2.44-r6 on amd64 and arm64

(cherry picked from commit bc911abdbb)
2026-10-02 07:24:10 +00:00
yuneng-jiang
a17acca84f
Merge pull request #44151 from BerriAI/litellm_chore_75e0ca
chore(release): backport #39590 to stable/1.100.x and cut 1.100.5
2026-10-02 00:02:36 -07:00
Yuneng Jiang
4673031cb9
chore: refresh uv.lock for 1.100.5 2026-10-01 22:15:59 -07:00
Yuneng Jiang
9493b98bde
bump: version 1.100.4 → 1.100.5 2026-10-01 22:15:49 -07:00
Yuneng Jiang
d6a2d5d7b0
chore: update Next.js build artifacts (2026-10-02 05:15 UTC, node v24.19.0) 2026-10-01 22:15:40 -07:00
Yuneng Jiang
10c97b7ec6
chore(deps): bump tornado to 6.5.9 2026-10-01 22:11:55 -07:00
Yuneng Jiang
78d65f63ec
chore(deps): bump urllib3 to 2.8.0 2026-10-01 22:11:55 -07:00
Yuneng Jiang
edfa762afd
chore(deps): bump pypdf to 6.19.0 2026-10-01 22:11:55 -07:00
Yuneng Jiang
b94f1d225b
chore(deps): bump pyjwt to 2.15.0 2026-10-01 22:11:55 -07:00
mateo
3651a47ee9
test: deflake JWT tamper assertions and fuzzy picker widget driver
Tamper tests rewrote the last two base64url characters of the signature,
which on roughly 1 in 250 RS256 tokens (1 in 1000 HS256) only touched
padding bits, so the decoded signature was unchanged and still verified.
Corrupt the decoded signature bytes instead.

The fuzzy picker driver sent keys after fixed sleeps, so a slow worker
could receive the filter text before the widget had highlighted the match.
Wait on the widget's highlighted choice instead.

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
(cherry picked from commit 25c5f0d993)
2026-10-01 22:11:55 -07:00
devin-ai-integration[bot]
e5f93c008a
feat(caching): add semantic_cache_scope to isolate semantic cache hits per end user (#39590)
Semantic cache keys omit the prompt, so every end user behind one virtual key
shares a bucket and can be served another user's semantically similar response.
Add an opt-in cache_params.semantic_cache_scope (key | end_user) that appends the
authenticated end-user id to the tenant scope, read from metadata and
litellm_metadata so /v1/chat/completions, /v1/responses and /v1/messages are all
covered, falling back to the key scope when no end-user id is present. Expose the
setting in the cache settings API and the Admin UI cache settings form

Co-authored-by: yassin <yassin@berri.ai>
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
(cherry picked from commit 16db51e2cf)
2026-10-01 22:01:11 -07:00
yuneng-jiang
dd2f80fdc3
Merge pull request #43821 from BerriAI/litellm_sync_stable_1_100_x
chore(release): sync stable/1.100.x to v1.100.4
2026-09-30 10:59:40 -07:00
yuneng-jiang
883282fb72
Merge pull request #10 from BerriAI/litellm_session_token_1_100_x
refactor(auth): bind UI/CLI session tokens to their own AES-GCM context (stable/1.100.x)
2026-09-29 15:39:06 -07:00
Yuneng Jiang
241abaec79
chore(lint): scope a TRY004 suppression to the bearer-token salt key check
This line's ruff strict budget has no headroom for the one TRY004 the
backport adds; the raise reports missing configuration, not a bad type.
2026-09-29 15:34:34 -07:00
Yuneng Jiang
f7cd90f09e
refactor(auth): bind UI/CLI session tokens to their own AES-GCM context
Backport of BerriAI/litellm-private#5 (12981f93d3) onto stable/1.100.x, applied as
the PR's net diff so main-only intermediate refactors stay out.

The dashboard and lite CLI SSO specs under tests/e2e/ui/oidc are left out
because this line has no OIDC e2e harness to run them.
2026-09-29 15:17:24 -07:00
yuneng-jiang
bdff5cb30c
Merge pull request #9 from BerriAI/litellm_bump_1_100_4
chore: bump litellm 1.100.3 -> 1.100.4
2026-09-28 17:05:44 -07:00
Yuneng Jiang
cd6eb1099f
bump: litellm 1.100.3 -> 1.100.4 2026-09-28 15:08:09 -07:00
yuneng-jiang
385266c14d
Merge pull request #43132 from BerriAI/litellm_backport_1_100_x_gpt6_budget_0924
chore(release): backport #39631, #39729, #40639 to stable/1.100.x and cut 1.100.3
2026-09-24 22:29:19 -07:00
Yuneng Jiang
04fcee8ff1
chore: refresh uv.lock for 1.100.3 2026-09-24 20:39:38 -07:00
Yuneng Jiang
5651c5a008
bump: version 1.100.2 → 1.100.3 2026-09-24 20:39:38 -07:00
Yuneng Jiang
78be1b7303
chore(deps): bump soupsieve to 2.9 2026-09-24 20:39:00 -07:00
Yuneng Jiang
559dce5c83
chore(deps): bump pypdf to 6.16.1 2026-09-24 20:39:00 -07:00
Yuneng Jiang
c18d0307da
chore(deps): bump tornado to 6.5.8 2026-09-24 20:39:00 -07:00
Yuneng Jiang
b830735f56
chore(deps): bump gitpython to 3.1.60 2026-09-24 20:39:00 -07:00
Yuneng Jiang
c8bc09ea51
chore(deps): bump anyio to 4.14.2 2026-09-24 20:39:00 -07:00
ryan-crabbe-berri
6b103ed064
fix(reset_budget_job): reset end users by budget link, not by user id (#40639)
Adapted for stable/1.100.x: added Final to the test module's typing import; upstream's test file already imported it.

(cherry picked from commit 8a4fae0e17)
2026-09-24 20:39:00 -07:00
amasen02
bc9712f045
fix(proxy): invalidate end-user spend counter and cache on budget reset (#39726)
Adapted for stable/1.100.x: reflowed one generator to this line's ruff format (upstream reformatted it in a later style commit).

Signed-off-by: amasen02 <amasen02@users.noreply.github.com>
(cherry picked from commit daced81f20)
2026-09-24 20:39:00 -07:00
Mateo Wang
b68fcee3ca
fix: treat gpt-6 names as the gpt-5 request family in OpenAI and Azure configs (#39631)
Adapted for stable/1.100.x: import-context conflict only (upstream's neighbouring custom_tools import is not on this line); the added and removed lines are identical to upstream.

(cherry picked from commit 025a3ca42f)
2026-09-24 20:38:59 -07:00
devin-ai-integration[bot]
55d1597645 revert(proxy): drop the member auto-router write-path port from stable/1.100.x
This reverts commits 54b42e3f05, 4864227716, 77915d43b8 and e39e1c8dea. Jev does not use the member auto-router write path and no other stable line ships it, so dropping the port leaves 1.100.x matching stable/1.101.x and stable/1.102.x

The classifier circuit breaker's litellm Timeout detection that 54b42e3f05 carried is kept, since main and the other lines have it

This reverts commit e39e1c8dea.
This reverts commit 77915d43b8.
This reverts commit 4864227716.
This reverts commit 54b42e3f05.
2026-09-23 14:25:39 +00:00
devin-ai-integration[bot]
e39e1c8dea fix(proxy): take the write-slot advisory lock before member name checks
Bugbot flagged that the member create path ran its name-collision check without any lock, so two concurrent creates of the same name could both pass. Take the same pg_advisory_xact_lock main takes at the top of the write transaction so member writes serialize before the checks run.
2026-09-23 06:40:40 +00:00
devin-ai-integration[bot]
77915d43b8 fix(proxy): port append_team_models for member auto-router create on stable/1.100.x
Greptile flagged that the member create path committed the router row inside the write slot and then failed on the endpoint-level authorization in team_model_add, leaving the router orphaned. Port append_team_models from main into team_endpoints and call it directly like main does, and widen the grant/view plumbing and write payload calls so the LIT001 and LIT002 gates stay within their ceilings.
2026-09-23 06:20:42 +00:00
devin-ai-integration[bot]
4864227716 test(proxy): restore the member-scope parametrization and cover team tpd_limit
The merged TestTeamMemberAutoRouterWrites class dropped the parametrize
decorator on test_admin_router_changes_release_member_scope, leaving the
test with an unsatisfiable endpoint fixture; this restores main's
patch/legacy x config/strategy/unrelated matrix. _full_team now sets
tpd_limit so the every-team-field grant coverage assertion sees the new
LiteLLM_VerificationTokenView field populated.
2026-09-23 06:07:40 +00:00
devin-ai-integration[bot]
54b42e3f05 fix(proxy): port the member auto-router write path and grant plumbing to stable/1.100.x
Bugbot on #42668 flagged that the backport's picks left the member
auto-router management path unwired on this line. This ports the pieces
that make it work, mirroring main: the member write slot in
model_management_endpoints (FOR UPDATE lock, team reload with the model
table include, identity and name-collision checks, post-commit config
publish), StoredAutoRouterIdentity wiring, the license feature helpers,
team tpd_limit, Router.config_deployments, the member_auto_router
ModelInfo flag, the _TEAM_GRANT_RELATIONS include on team lookups, and
the UserAPIKeyAuth fields the team_grants unpack needs. Test files were
rebuilt as line content plus the picks' own additions, and
ui_sso/test_team_grants carry the pick's grant assertions.

Gate-clearing edits stay local to what the picks added: prisma TypedDict
arguments replace mutable dict literals, remaining dict/mapping
arguments carry reasoned mutable-ok comments, test-quality-ok comments
mark the picks' internal-seam patches, and the regenerated dashboard api
types are staged. The only remaining make check failure is pre-existing
staging drift in untouched tests/test_litellm/test_router.py:2969.
2026-09-23 06:04:07 +00:00
Devin AI
a392f7bc66 fix(typing): clear the basedpyright errors the picks introduced
The type check gate flagged six new reportArgumentType errors and one reportGeneralTypeIssues error over base: an outcome Final rebinding in the fallback path, a Mapping handed to the dict-typed request_kwargs parameter, optional message sequences passed to a non-optional parameter, DatabaseClient where PrismaClient is expected on two access-group lookups, the effective-config helper object return passed to the Mapping-typed validator, the project row passed to can_project_access_model, and the Response or None from AsyncHTTPHandler.post. The flagged sites now pass the right shape or carry a rule-scoped pyright ignore with the reason.
2026-09-23 03:57:38 +00:00
Devin AI
46f81ba3e0 fix: place lint suppressions on the flagged annotation lines 2026-09-23 03:14:10 +00:00
Devin AI
8e4c26fea3 fix(ui): adapt the jev dashboard pieces to stable/1.100.x
Merge debris cleanup and 1.102.x-only imports fixed; usesClassifierContext re-exported, JEV custom-tier emission, and preset test adapted to the static preset registry.
2026-09-23 03:14:10 +00:00
devin-ai-integration[bot]
746686c34e feat(openrouter): price typesafe/jev-1.13 and add an openrouter decisions pass-through (#42301) 2026-09-23 03:14:10 +00:00
Devin AI
12ef369373 chore(backport): regenerate the openapi snapshot and dashboard api types for stable/1.100.x
The #41615 and #41757 picks brought litellm/proxy/_lazy_openapi_snapshot.json and ui/litellm-dashboard/src/lib/http/schema.d.ts verbatim from main. Both files were regenerated under Python 3.12.
2026-09-23 03:14:10 +00:00
mateo-berri
c3c466a5c1 fix(ui): adapt the jev dashboard pieces to stable/1.102.x
(cherry picked from commit 4bfac88281)
2026-09-23 03:14:10 +00:00
moe-berri
73e50a09cb feat(auto-router): add JEV classifier alongside LLM classifier
Backport of #41886 to stable/1.100.x.
Cherry-picked from a83773cfa5 (main).
2026-09-23 03:14:10 +00:00
moe-berri
4fa1e08fc2 fix(proxy): enforce virtual key budgets for JEV test routing
Backport of #41879 to stable/1.100.x.
Cherry-picked from 1e161f516c (main).
2026-09-23 03:14:10 +00:00
Yassin Kortam
d1bf6094be feat(guardrails): add TypeSafe Jev relevance-based compaction guardrail
Backport of #41757 to stable/1.100.x.
Cherry-picked from 2edda5aec3 (main).
2026-09-23 03:14:10 +00:00
yuneng-jiang
ded7f601d9 fix(proxy): forward every method on the typesafe pass-through route
Backport of #41723 to stable/1.100.x.
Cherry-picked from 34718f0da6 (main).
2026-09-23 03:14:10 +00:00
Mateo Wang
8bf252b397 feat(router): add TypeSafe Jev as a complexity router classifier
Backport of #41615 to stable/1.100.x.
Cherry-picked from cf42b607c3 (main).
2026-09-23 03:14:10 +00:00
moe-berri
d400ee2b7e feat(router): add classifier circuit breaker
Prerequisite for #41615 on stable/1.100.x.
Cherry-picked from 510424c86c (main).
2026-09-23 03:14:10 +00:00
Tin Chi Lo
44b7b48e46 feat(auto-router): allow opted-in team members to manage their routers
Prerequisite for #41615 and #41879 on stable/1.100.x.

Cherry-picked from 109ca70f66 (main).
2026-09-23 03:14:10 +00:00
ryan-crabbe-berri
61d725d55f fix(proxy): apply team model aliases on the JWT auth path
Prerequisite for #41615 on stable/1.100.x.

Cherry-picked from 7015bf37bb (main).
2026-09-23 03:14:10 +00:00
Mateo Wang
9c1216a427
Merge pull request #42597 from BerriAI/litellm_cherrypick_1_100_x
feat(typesafe): backport #41607 to stable/1.100.x for v1.100.2
2026-09-22 20:01:40 -07:00