litellm/litellm-rust/crates/python-bridge/AGENTS.md
Yujong Lee 63d994ade4 refactor(rust): run OCR through a route-neutral callback contract and a legacy Logging adapter
Extracted from #41733 without the router loop, the cache machine layer, streaming, or the
error, timeout and route-pruning work that moved to #41745

litellm-callbacks holds the contract a native call and its host share: Machine, HostOp,
CallEvent, the in-process run loop, and Passthrough, which is built only by comparing the
caller's inputs with the body the route sends, so a route can never mark a key it rewrote.
litellm-host-python (formerly python-interop) owns the CPython driver and the Execution
handle, and litellm-callbacks-legacy is the @client wrapper as the native call sees it:
function_setup, the deployment hooks, pre_call and post_call, the success and failure fan-out
and the deferred proxy release. OCR is the one route on it, and the old core and bridge
lifecycles are gone

The passthrough rule is the structural fix for the bug #41719 patched in core and #41716
reworks: an inlined remote document no longer counts as the caller's value, so the legacy
adapter never hands the caller's URL back into the body. core/tests/ocr/passthrough.rs pins
it for every route and document source, including that unchanged values stay passthrough,
and callbacks-legacy/tests/payload.rs pins the adapter side with a real pre_call callback

Python OCR integration tests that only exercised core behavior now live as Rust tests, so
tests/test_litellm_rust keeps the cases that need the full Python stack
2026-09-17 21:13:16 -07:00

5.5 KiB

  • Target invariants, not completion claims; these supersede older conflicting bridge guidance
  • Keep this crate the product-specific PyO3 consumer of litellm-host-python
    • Own registration, input projection, the route host and the caller callables it answers operations with (file readers, token providers), public response/error construction and the per-call composition of machine, route host and callback contract
    • Legacy callback sharing (the caller's args, kwargs and request object, body/header roots, passthrough_fields re-aliasing) lives in litellm-callbacks-legacy behind PublicCall and run_legacy_call; the bridge hands the public call over and keeps no copy
    • Value-oriented execution, sync waiting, nested-runtime checks, signal polling and panic containment live in litellm-host-python; native async work uses pyo3-async-runtimes, Serde output uses Pythonized<T>
    • Core owns typed native state, the route machine, provider preparation/I/O and normalization; the host driver owns terminal events; the legacy adapter in litellm-callbacks-legacy owns Logging dispatch policy
    • Python, Rust SDK and gateway use one lifecycle-bearing core route entrypoint; provider helpers stay private, never bridge-accessible transport drivers
    • Built-in provider/config/secret/auth/document preparation stays in Rust; caller-authored callbacks and focused Python-file reads run only at core-selected points
  • Target GIL-enabled CPython explicitly with #[pymodule(gil_used = true)]; detach Rust-only work
    • Free-threading requires separate runtime/concurrency validation; omitting the attribute does not opt out on PyO3 0.28+
  • Preserve public argument binding and Python object provenance
    • Project only consumed fields at reference read points; no eager whole-graph serialization or equality-based alias reconstruction
    • Preserve provider-specific upload/submission/poll observation and encoding boundaries; signed/build-captured bytes must not be silently reserialized
  • Conversion errors and every failure after the call starts are terminal
    • Disabled/unavailable native execution may select legacy once; callback exceptions never authorize fallback or replay
  • Use one ordinary inline async def driver in litellm/rust_bridge/lifecycle.py, with the native handle and call driver in litellm-host-python
    • Contract: start, resume_value, resume_error, idempotent close; explicitly tagged Await/Complete preserve awaitable final values
    • Validate Created/Running/Suspended/Closed protocol states; the machine yields ops, the driver emits one terminal event, the adapter chooses dispatch policy
    • Defer effectful setup/context reads/timestamps until start; unstarted-handle destruction releases inputs independently of Python finally
    • Catch only the selected await's errors; start/resume errors propagate, GeneratorExit closes without further awaits
    • Inline hooks preserve caller task/thread/loop and context writes; into_future creates a separate task and cannot satisfy this contract
  • Finalize fallible public response/error construction, replacements and metadata before terminal dispatch
  • Make ownership safe across suspension, re-entry, cancellation and GC
    • Keep native provider state typed in core; do not shuttle it through opaque Python transport/response classes
    • Prefer one retained Py<PyBaseException> via PyErr::into_value(py); reconstruct transient PyErrs, preserving identity, traceback, cause and context
    • Traverse every owned Python edge, including duplicate references; traversal cannot call Python
    • Take state out and mark Running under a short borrow, release borrows/locks before Python invocation, publish terminal state before finalizer-capable drops
    • Close/GC/deferred release are idempotent and re-entry-safe, including during Rust unwinding; release only owned references, never clear caller containers or mask the selected error
    • The machine owns its in-flight provider future; interrupt drops it synchronously, so provider captures are released before the driver returns and no task outlives the call
  • Verify behavior through a fresh, provenance-checked installed extension and positive native execution evidence before replacing the custom coroutine
    • Cover admitted provider workflows, binding/read-point/identity behavior, failure continuation, finalization, no replay, deferred gates, re-entry, GC and cancellation termination
    • Measure real conversion/copy costs before optimizing; preserve input contracts and capture lifetimes with PyBackedBytes, and lookup timing when interning names
    • Ship accurate _native.pyi declarations and typing markers; distinguish Future-returning bindings from coroutine-returning bindings
  • References: ownership, GC, exception transfer, re-entry