The pinned base's /etc/apk/world locks glibc-2.44=2.44-r1, so the apk upgrade in the runtime stage cannot move it. The new digest ships 2.44-r6 on amd64 and arm64
(cherry picked from commit bc911abdbb)
Tamper tests rewrote the last two base64url characters of the signature,
which on roughly 1 in 250 RS256 tokens (1 in 1000 HS256) only touched
padding bits, so the decoded signature was unchanged and still verified.
Corrupt the decoded signature bytes instead.
The fuzzy picker driver sent keys after fixed sleeps, so a slow worker
could receive the filter text before the widget had highlighted the match.
Wait on the widget's highlighted choice instead.
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
(cherry picked from commit 25c5f0d993)
Semantic cache keys omit the prompt, so every end user behind one virtual key
shares a bucket and can be served another user's semantically similar response.
Add an opt-in cache_params.semantic_cache_scope (key | end_user) that appends the
authenticated end-user id to the tenant scope, read from metadata and
litellm_metadata so /v1/chat/completions, /v1/responses and /v1/messages are all
covered, falling back to the key scope when no end-user id is present. Expose the
setting in the cache settings API and the Admin UI cache settings form
Co-authored-by: yassin <yassin@berri.ai>
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
(cherry picked from commit 16db51e2cf)
Backport of BerriAI/litellm-private#5 (12981f93d3) onto stable/1.100.x, applied as
the PR's net diff so main-only intermediate refactors stay out.
The dashboard and lite CLI SSO specs under tests/e2e/ui/oidc are left out
because this line has no OIDC e2e harness to run them.
Adapted for stable/1.100.x: added Final to the test module's typing import; upstream's test file already imported it.
(cherry picked from commit 8a4fae0e17)
Adapted for stable/1.100.x: reflowed one generator to this line's ruff format (upstream reformatted it in a later style commit).
Signed-off-by: amasen02 <amasen02@users.noreply.github.com>
(cherry picked from commit daced81f20)
Adapted for stable/1.100.x: import-context conflict only (upstream's neighbouring custom_tools import is not on this line); the added and removed lines are identical to upstream.
(cherry picked from commit 025a3ca42f)
This reverts commits 54b42e3f05, 4864227716, 77915d43b8 and e39e1c8dea. Jev does not use the member auto-router write path and no other stable line ships it, so dropping the port leaves 1.100.x matching stable/1.101.x and stable/1.102.x
The classifier circuit breaker's litellm Timeout detection that 54b42e3f05 carried is kept, since main and the other lines have it
This reverts commit e39e1c8dea.
This reverts commit 77915d43b8.
This reverts commit 4864227716.
This reverts commit 54b42e3f05.
Bugbot flagged that the member create path ran its name-collision check without any lock, so two concurrent creates of the same name could both pass. Take the same pg_advisory_xact_lock main takes at the top of the write transaction so member writes serialize before the checks run.
Greptile flagged that the member create path committed the router row inside the write slot and then failed on the endpoint-level authorization in team_model_add, leaving the router orphaned. Port append_team_models from main into team_endpoints and call it directly like main does, and widen the grant/view plumbing and write payload calls so the LIT001 and LIT002 gates stay within their ceilings.
The merged TestTeamMemberAutoRouterWrites class dropped the parametrize
decorator on test_admin_router_changes_release_member_scope, leaving the
test with an unsatisfiable endpoint fixture; this restores main's
patch/legacy x config/strategy/unrelated matrix. _full_team now sets
tpd_limit so the every-team-field grant coverage assertion sees the new
LiteLLM_VerificationTokenView field populated.
Bugbot on #42668 flagged that the backport's picks left the member
auto-router management path unwired on this line. This ports the pieces
that make it work, mirroring main: the member write slot in
model_management_endpoints (FOR UPDATE lock, team reload with the model
table include, identity and name-collision checks, post-commit config
publish), StoredAutoRouterIdentity wiring, the license feature helpers,
team tpd_limit, Router.config_deployments, the member_auto_router
ModelInfo flag, the _TEAM_GRANT_RELATIONS include on team lookups, and
the UserAPIKeyAuth fields the team_grants unpack needs. Test files were
rebuilt as line content plus the picks' own additions, and
ui_sso/test_team_grants carry the pick's grant assertions.
Gate-clearing edits stay local to what the picks added: prisma TypedDict
arguments replace mutable dict literals, remaining dict/mapping
arguments carry reasoned mutable-ok comments, test-quality-ok comments
mark the picks' internal-seam patches, and the regenerated dashboard api
types are staged. The only remaining make check failure is pre-existing
staging drift in untouched tests/test_litellm/test_router.py:2969.
The type check gate flagged six new reportArgumentType errors and one reportGeneralTypeIssues error over base: an outcome Final rebinding in the fallback path, a Mapping handed to the dict-typed request_kwargs parameter, optional message sequences passed to a non-optional parameter, DatabaseClient where PrismaClient is expected on two access-group lookups, the effective-config helper object return passed to the Mapping-typed validator, the project row passed to can_project_access_model, and the Response or None from AsyncHTTPHandler.post. The flagged sites now pass the right shape or carry a rule-scoped pyright ignore with the reason.
Merge debris cleanup and 1.102.x-only imports fixed; usesClassifierContext re-exported, JEV custom-tier emission, and preset test adapted to the static preset registry.
The #41615 and #41757 picks brought litellm/proxy/_lazy_openapi_snapshot.json and ui/litellm-dashboard/src/lib/http/schema.d.ts verbatim from main. Both files were regenerated under Python 3.12.