mirror of
https://github.com/BerriAI/litellm.git
synced 2026-09-28 01:32:17 +00:00
* ci: run the unit_selection.sh shard files on every event instead of only fork pull requests Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com> * ci: rename fork-flag to unit-flag now that it applies on every event * test: move tests/test_litellm root and small trees into tests/unit Pure renames, no content changes. Follow-up commits in this PR fix references, merge the three files that already existed in tests/unit, keep live-provider tests in tests/test_litellm and wire CI. * test: carry tests/test_litellm conftest isolation into tests/unit Callback lists, routing fallbacks, cached HTTP clients, logger state, AWS, proxy-URL and keychain env, and session-end client cleanup now reset for unit tests too. The environment isolation owns its MonkeyPatch so a test's own monkeypatch is undone before the model-cost teardown runs. * test: merge, split and prune the moved root and small-tree tests Merge batches/test_batch_utils.py and the chat_completions and messages dispatch tests into the files that already existed in tests/unit. Keep the live Gemini interactions tests, the async image-fetch format test and the OpenAI embedding scorer test in tests/test_litellm since they need real network or keys. Put test_router.py under tests/unit/test_router so the existing package no longer shadows it. Delete eight tests the audit found superseded by stronger ones kept in this move. * ci: run the moved root and small-tree tests under their legacy flags Add the misc and responses-caching-types flags to unit_selection.sh and CircleCI, extend enterprise-routing and mcp-integration, and point the legacy GHA shards, Makefile, redis-compat workflow, merge smoke manifest and change classifier at the new paths. * test: make the new tests/unit directories packages tests/unit/test_package_layout.py requires every directory to carry an __init__.py, and without one the moved and retained test_litellm_responses_bridge.py modules collide on import. * test: scope the unit socket block to tests/unit in shared sessions The GHA shards collect the legacy test-path and the unit selection in one pytest session. The unit conftest's loopback-only block leaked into legacy modules that reach the network at import. The legacy conftest now lifts the restriction at collect and setup time, and the unit conftest re-applies it when collecting its own modules. * test: give the shard-script tests their own GITHUB_OUTPUT They only passed where the runner set it. The CircleCI unit job's env allowlist drops it, so the script's redirect failed there. * test: point the router and module-deletion checks at tests/unit router_code_coverage and code_qa_check_tests only searched tests/test_litellm, so the moved router tests no longer counted. The two silent-experiment tests the audit deleted were the only direct callers of those methods; they are replaced with tests that assert the forwarded shadow request and the recursion guard. --------- Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
52 lines
2.4 KiB
Python
52 lines
2.4 KiB
Python
from pathlib import Path
|
|
|
|
import pytest
|
|
|
|
from scripts.check_mcp_operation_boundary import main, violations
|
|
|
|
|
|
@pytest.mark.parametrize(
|
|
"source",
|
|
(
|
|
"from mcp.server.auth.middleware.auth_context import auth_context_var as hidden",
|
|
"from litellm.proxy._experimental.mcp_server.mcp_context import _mcp_proxy_mode as mode",
|
|
"caller = legacy.get_active_auth_context()",
|
|
"owners = transport._stateful_session_owners",
|
|
"from weakref import WeakKeyDictionary",
|
|
"from litellm.proxy._experimental.mcp_server.server import get_auth_context",
|
|
),
|
|
)
|
|
def test_shared_operation_boundary_rejects_ambient_state(source):
|
|
assert violations(Path("operations.py"), source)
|
|
|
|
|
|
def test_legacy_adapter_may_resolve_context_but_policy_must_receive_it():
|
|
source = "from litellm.proxy._experimental.mcp_server.mcp_context import _mcp_proxy_mode"
|
|
assert violations(Path("server.py"), source) == ()
|
|
assert violations(Path("legacy_callbacks.py"), source) == ()
|
|
assert violations(Path("operations.py"), "def execute(context):\n return context.client_ip") == ()
|
|
assert violations(Path("mcp_server_manager.py"), "def _mcp_registry_key(server):\n return server.name") == ()
|
|
|
|
|
|
def test_boundary_command_rejects_shared_state_and_accepts_explicit_context(tmp_path, monkeypatch, capsys):
|
|
import subprocess
|
|
import sys
|
|
|
|
package = tmp_path / "litellm/proxy/_experimental/mcp_server"
|
|
package.mkdir(parents=True)
|
|
module = package / "operations.py"
|
|
module.write_text("from mcp.server.auth.middleware.auth_context import auth_context_var as hidden\n")
|
|
command = [sys.executable, str(Path(__file__).resolve().parents[2] / "scripts/check_mcp_operation_boundary.py")]
|
|
monkeypatch.chdir(tmp_path)
|
|
assert main() == 1
|
|
assert "operations.py:1:" in capsys.readouterr().err
|
|
rejected = subprocess.run(command, cwd=tmp_path, capture_output=True, text=True, check=False)
|
|
assert rejected.returncode == 1
|
|
assert "operations.py:1: MCP request/session state belongs in a legacy adapter" in rejected.stderr
|
|
|
|
module.write_text("def execute(context):\n return context.client_ip\n")
|
|
assert main() == 0
|
|
assert "MCP operation boundary: passed" in capsys.readouterr().out
|
|
accepted = subprocess.run(command, cwd=tmp_path, capture_output=True, text=True, check=False)
|
|
assert accepted.returncode == 0
|
|
assert "MCP operation boundary: passed" in accepted.stdout
|