Commit Graph

78 Commits

Author SHA1 Message Date
Luis Pater
c9a06ba6f2 fix(interceptors): avoid cloning request body for read-only interceptors
- Share request payload reference during session identity enrichment when original request is unset
- Avoid cloning request payload when interceptors do not mutate the body
- Pass request body directly to handler and conductor interceptors

Closes: #6101
2026-09-25 00:34:17 +08:00
sususu
107d7f76c9 fix(translator,auth): avoid synthetic bypass on unsigned text parts and reduce stream rewrite log noise
- In gemini_openai-responses_request.go, do not attach 'skip_thought_signature_validator' to visibleText or thought parts when there is no genuine signature to replay.
- In response_model_rewriter.go, track rewritten model paths per stream to emit a single start debug log and a final summary upon stream completion, avoiding hot-path per-chunk log flooding.
2026-09-24 18:59:13 +08:00
Luis Pater
c404af96eb fix(auth): preserve file priority across plugin auth refreshes
- Introduce `AttributeFilePriority` and helper to track priority inherited from auth files
- Preserve file-configured priority attributes and metadata in plugin host during auth refresh
- Apply file priority metadata consistently across synthesizer, token filestore, and management handlers

Closes: #6089
2026-09-24 08:09:21 +08:00
Luis Pater
855a722349 feat(pluginhost): add host http operation bridge and lifecycle scoping
- Introduce `hostHTTPOperationBridge` to manage, claim, and cancel host HTTP operations with scoped cleanups
- Scope HTTP operations and streams to specific plugin instances to isolate lifecycles and prevent cross-plugin access
- Add RPC handlers for `MethodHostHTTPOperationOpen` and `MethodHostHTTPCancel`
- Link operation cancellation and resource cleanup to host callback contexts and stream termination

Closes: #6085
2026-09-24 06:08:51 +08:00
Luis Pater
2fe9932bb9 feat(usage): track execution request ID and trace ID across usage records
- Add `RequestID` (unique execution UUID) and `TraceID` (inbound request ID) fields to usage records and plugin API
- Generate unique UUIDs per model attempt in `UsageReporter` while linking to parent trace context
- Expose `execution_id` and `trace_id` in Redis queue usage payloads while preserving legacy `request_id`
2026-09-23 19:31:39 +08:00
Luis Pater
d582067c06 feat(executor): support execution-scoped request proxy overrides
- Add context helpers to manage execution-scoped proxy overrides
- Prioritize request proxy over credential and global proxy settings across HTTP and uTLS clients
- Propagate request proxy in conductor execution and plugin host adapters
- Isolate Codex WebSocket connection reuse by proxy endpoint

Closes: #6013
2026-09-22 03:54:34 +08:00
Luis Pater
ac3849e5d9 feat(pluginapi): propagate response model, service tier, and stream flag to usage plugins
- Add `ResponseServiceTier`, `ResponseModel`, and `Stream` fields to `pluginapi.UsageRecord`
- Propagate upstream response model, service tier, and stream status in usage translation adapter

Closes: #6008
2026-09-21 21:47:59 +08:00
Luis Pater
1c87874966 fix(pluginhost): preserve http status codes in host callback and execution errors
- Introduce `modelExecutionStatusError` to retain explicit HTTP status codes on model execution errors
- Propagate HTTP status codes from callback errors across Unix and Windows host callback dispatchers
- Update `marshalRPCError` to encode HTTP status codes into error envelopes using `pluginabi.NewErrorEnvelope`

Closes: #5970
2026-09-20 00:23:42 +08:00
Luis Pater
b715526add feat(plugin): support scheduling across priorities
- Add `SchedulerAcrossPriorities` capability to allow plugin schedulers to receive candidates across all priority tiers.
- Propagate scheduler priority preferences through the plugin host and RPC capabilities.
- Update auth manager selection logic to supply candidates across all priorities when the scheduler opts in.

Closes: #5894
2026-09-17 21:21:56 +08:00
Luis Pater
748d576731 feat(pluginhost): propagate forced provider and auth ID in host model execution
- Add `ForcedProvider` and `AuthID` fields to `HostModelExecutionRequest` and `ModelExecutionRequest`.
- Pin credentials via `WithPinnedAuthID` and forward forced provider options during model execution and streaming.
- Forward forced provider and auth ID from plugin host callbacks to model execution handlers.

Closes: #5814
2026-09-14 21:59:32 +08:00
Luis Pater
6ba444557c feat(pluginabi): support HTTP status code propagation in plugin error envelopes
- Add `Error.Error`, `Error.StatusCode`, `NewError`, and `NewErrorEnvelope` helpers in `sdk/pluginabi`.
- Support extracting and forwarding HTTP status codes in Go plugin executor examples and generator script.
- Document plugin executor error handling and client HTTP status mapping conventions.

Closes: #5809
2026-09-14 18:44:04 +08:00
Luis Pater
b8477c7181 fix(pluginhost): keep request and method buffers alive during native call
- Ensure `methodBytes` and `request` are kept alive across dynamic library invocation on Windows to prevent premature garbage collection.

Closes: #5807
2026-09-14 17:32:33 +08:00
sususu
0719520f2a feat(api-call): support $TOKEN$ replacement in request body data 2026-09-14 09:20:03 +08:00
Luis Pater
3c3938feb1 feat(plugins): forward query parameters as metadata in auth provider start login
- Accept optional metadata parameters in SDK and internal plugin host `StartLogin` methods.
- Clone and pass metadata to the auth provider's `AuthLoginStartRequest`.
- Convert management auth URL query parameters into metadata before initiating plugin login flows.

Closes: #5760
2026-09-12 20:05:34 +08:00
Luis Pater
b192f6550c feat(management): add plugin quota and declarative probe endpoints
- Add endpoints to list quota providers and fetch or reset credential quotas via plugins.
- Support declarative metadata quota probes with token substitution and response mapping.
- Clear core routing quota state when provider quota reset succeeds.

Closes: #5752
2026-09-12 19:07:43 +08:00
Luis Pater
c8f723e0fb feat(usage): propagate upstream base_url across usage records and plugin auth
- Add `BaseURL` field to usage records and host auth file entries.
- Extract `base_url` from auth attributes and metadata during usage reporting.
- Propagate `base_url` through plugin usage adapters and runtime auth callbacks.

Closes: #5693
2026-09-11 00:25:17 +08:00
Luis Pater
0796d6d133 feat(plugin): add host session affinity lookup callback
- Decode and validate host affinity lookup requests for provider, model, and session ID.
- Query the active auth manager for session affinity bindings and status.
- Return lookup responses containing the auth index, observation timestamp, and credential availability state.

Closes: #5604
2026-09-09 03:25:42 +08:00
Luis Pater
c6327a86c9 feat(plugin): preserve raw json in management responses on schema version 6
- Bump plugin ABI `SchemaVersion` to 6 and add `SchemaVersionRawManagementResponse`.
- Skip HTML entity escaping for plugin management JSON responses on schema version 6 and above.
- Retain legacy HTML escaping behavior for plugins with schema versions prior to 6.

Closes: #5605
2026-09-09 00:45:45 +08:00
Luis Pater
00c63a5669 feat(pluginhost): expose outbound HTTP wire profile to plugin requests
- Add HTTPWireProfile to sdk/pluginapi on HTTPRequest with wire_profile JSON tag
- Decode wire_profile in host callbacks for flat and nested RPC payloads
- Match header casing in httpwire ordered_conn and allow non-HTTP handshakes
- Apply wire profile settings (HTTP/1.1 enforcement, auto compression disable, header ordering) in plugin host HTTP client
- Preserve proxy configuration, custom TLS dialers, redirect handling, and connection lifecycle

Closes: #5062
2026-09-06 20:41:58 +08:00
sususu
580df36423 feat(usage): propagate session and parent session hierarchy to usage reporting queue
- Reuse coresession.ExtractSessionInfo across HTTP headers and request payloads to unify canonical session prefix namespaces with the scheduler.
- Extract hierarchical session identities in two phases: initial extraction from request headers on entry, and authoritative deep extraction once request payloads and metadata are available.
- Support Claude Code multi-level subagents (X-Claude-Code-Agent-Id, metadata.agent_id) and Codex thread fork lineages.
- Propagate SessionID and ParentSessionID across ClientRequestMetadata, UsageReporter, and coreusage.Record without root_session_id.
- Include session_id and parent_session_id in queuedUsageDetail for Home LPushUsage forwarding and Redis consumption with self-loop guards.
- Add comprehensive test coverage for canonical headers, body extraction, ghost parent elimination, and self-referential loop guards.
2026-09-06 10:45:32 +08:00
Luis Pater
649a8bdb6f feat(plugin): omit stream chunk history on payload chunks for schema v5
- Bump plugin schema version to 5 and introduce `SchemaVersionStreamChunkOmitHistory`.
- Omit `HistoryChunks` on payload stream chunks for schema version 5+ to avoid per-chunk cloning and serialization overhead.
- Conditionally accumulate and clone history chunks only when legacy plugins with schema version < 5 are active.

Closes: #5451
2026-09-04 01:19:50 +08:00
Luis Pater
02c02cda50 fix: harden concurrent session handling, listener lifecycle, and token accounting
- Use `context.AfterFunc` and buffered delivery in websocket relay sessions to avoid per-request goroutine leaks.
- Synchronize in-flight puts and drain queued connections upon mux listener close.
- Ensure home streaming log writer goroutines terminate cleanly when the log client is unhealthy.
- Prevent integer arithmetic overflow in token breakdown validations and calculations.
- Clone request headers in logging middleware to prevent concurrent mutation issues.
- Implement standard `io.WriterTo` return signature for file body sources.

Closes: #4709
2026-09-02 20:02:42 +08:00
Luis Pater
d31b15916d feat(executor): support token usage parsing for plugin executors
- Add `ParsePluginExecutorResponseUsage` to extract token usage from non-streaming plugin responses across Claude, Gemini, Interactions, Antigravity, and OpenAI/Codex protocols.
- Add `ObservePluginExecutorStreamUsage` to observe and aggregate token usage across streaming chunks.

Closes: #5340
2026-08-30 14:51:08 +08:00
hkfires
6a489fa84d fix(auth): prefer errors from upstream attempts
Track when executor calls cross an upstream transport boundary and use that
signal to keep model/provider errors from being replaced by later local
preparation, selection, or internal failures.

Mark HTTP, websocket, relay, and usage-tracked transports as upstream
attempts, while avoiding marks for local validation, logging, missing
sessions, and successful websocket handshakes before request send.

Parse relative auth expiry metadata and adjust Antigravity refresh timing.
2026-08-29 12:50:46 +08:00
Luis Pater
4b5f1eab25 feat(plugin): support observing upstream websocket response events
- Introduce `WebSocketResponseObserver` capability and bump plugin ABI schema version to 4.
- Forward upstream WebSocket response frames from Codex and xAI executors to configured observers.
- Wire `WebSocketResponseObserver` across API handlers and plugin host dispatchers.

Closes: #5248
2026-08-27 05:30:19 +08:00
Luis Pater
b7f6c15f83 fix(pluginhost): detach context and log rpc failures in usage handling
- Detach cancellation from context before dispatching usage records to plugins.
- Log debug messages when RPC `usage.handle` calls fail.

Closes: #5244
2026-08-27 04:35:51 +08:00
Luis Pater
ba510f85a2 fix(pluginhost): add plugin quiesce handling with safe rollback during hot reload
- Add new `plugin.quiesce` ABI method and propagate RPC error codes from plugin call failures.
- Invoke quiesce on the replaced plugin before loading a new version, then only activate replacement after quiesce succeeds.
- Improve hot-reload safety by serializing lifecycle transitions, cleaning up failed/canceled loads, and rolling back to the previous plugin state when replacement fails or is canceled.

Closes: #5134
2026-08-25 01:32:57 +08:00
hkfires
e04d620cc1 feat(auth): normalize credential metadata keys
Canonicalize legacy config-style credential keys across stores,
management handlers, plugin auth, and file synthesis while preserving
explicit canonical values. Expose per-auth request_retry in auth file
management and add max-retry-credentials management routes.
2026-08-22 12:01:06 +08:00
Luis Pater
e0b4956242 fix(openai): ensure Responses usage includes token detail fields
- add shared `EnsureResponsesUsageDetails` helper to patch `usage` objects with:
  - `output_tokens_details.reasoning_tokens = 0`
  - `input_tokens_details.cached_tokens = 0`
  - for both plain JSON and SSE `data:` frames, including multi-line frames
- apply the helper to OpenAI Response format outputs in non-stream and stream paths across executors/plugins so translated payloads consistently include required usage details
- update websocket/completion payload builders to emit default `usage` detail fields for prewarm/finish responses

Closes: #4985
2026-08-15 15:00:19 +08:00
Luis Pater
ba5ab795a2 feat(plugin): add schema-v3 stream chunk contract to omit payload request bodies
- Bump plugin schema to version 3 and introduce `SchemaVersionStreamChunkOmitRequestBody`.
- Treat missing plugin schema versions as legacy during RPC registration (`0 -> 1`) and expose schema on plugin descriptors.
- In stream interception, keep request headers/bodies on header-init chunk and stop re-sending them on payload chunks for schema-v3+ plugins, with per-chunk cloning for legacy plugins.

Closes: #4876
2026-08-11 04:32:20 +08:00
Luis Pater
01a21b77f4 fix(cliproxy): delegate OpenAI-compatible OAuth refresh to plugin auth providers
- Added a plugin refresh-compat executor wrapper that forwards normal OpenAI-compat execution paths while routing `Refresh` to plugin `AuthProvider`/Home refresh logic.
- Updated refresh lookup to use the effective executor key from auth metadata so namespaced compatibility providers can resolve their refresh executors correctly.
- Changed OpenAI-compat registration to wrap built-in executors with the plugin-refresh wrapper when a matching plugin auth provider exists, while preserving bare executors otherwise.
- Made `OpenAICompatExecutor.Refresh` fail fast for OAuth-style credentials (with refresh tokens) instead of silently returning unchanged auth.

Closes: #4719
2026-08-08 06:08:23 +08:00
Luis Pater
5dcca50fd9 feat(auth): introduce weighted round-robin scheduler and credential weight validation
- Added support for weighted round-robin authentication scheduling strategy.
- Implemented credential weight validation for attributes and metadata, with strict error handling for invalid weights.
- Enhanced scheduler with smooth weighted state handling and proportional selection logic.
- Introduced tests for credential weight parsing, validation, and weighted round-robin behavior.
- Updated configuration to include `weight` field for credentials with range validation.

Closes: #4470
2026-07-28 14:23:23 +08:00
Luis Pater
30efd7c4fd feat(plugin): add request lifecycle plugin with interception and termination capabilities
- Implemented a Go-based dynamic library plugin for request lifecycle management.
- Added concurrency controls, keyword-based request termination, and response handling.
- Supported optional capabilities for request interception and active lifecycle termination.
- Included tests for schema compatibility, concurrency limits, and policy-based termination.
- Added build instructions and configuration details in README.
- Updated host support for lifecycle plugin RPC methods.

Closes: #4568
2026-07-28 03:22:18 +08:00
adityavkk
96f4b0019c fix(sdk): preserve custom executors during auth sync 2026-07-26 08:33:46 -04:00
Luis Pater
fe4ae4989c chore(pluginhost): refactor and remove unused interceptors and executor methods
- Removed deprecated interceptor and executor-related methods, including `callRequestInterceptor`, `callResponseInterceptor`, and `callStreamChunkInterceptor`.
- Consolidated unused logic and pruned redundant imports to streamline `adapters.go`.
- No functional changes.
2026-07-26 14:31:45 +08:00
yueziji
520cfa1026 fix(pluginhost): stabilize Windows plugin response buffer 2026-07-24 20:10:14 +08:00
Luis Pater
b30e7d992a Merge branch 'credential-concurrency' into dev
# Conflicts:
#	internal/api/server.go
2026-07-23 13:53:11 +08:00
Luis Pater
3ecd4afe80 feat: add Home credential concurrency support 2026-07-23 13:42:08 +08:00
KorenKrita
119debe1f2 fix(pluginhost): honor accepted emit results 2026-07-21 19:21:20 +08:00
KorenKrita
3e7e0815aa fix(pluginhost): prevent stream close/send panic (#4480) 2026-07-21 19:08:17 +08:00
Luis Pater
768b4c49fd feat(usage): track generate flag with backward-compatible defaults
Propagate client generate metadata through usage records while keeping
legacy callers that omit the field enabled by default. Preserve an
existing context generate=false when metadata does not set the value,
and normalize omission to true only at publishing boundaries.
2026-07-15 21:30:09 +08:00
Luis Pater
35a5f06612 feat(config): resolve plugin directory paths and handle tilde expansion
- Added `ResolvePluginsDir` to normalize plugin directory paths, including tilde (`~`) expansion.
- Integrated directory resolution into config loading, runtime setup, and plugin management flows.
- Updated tests across components to validate correct handling of unresolved and expanded plugin paths.
- Added error handling for invalid or unresolved plugin directories to prevent runtime issues.

Closes: #4313
2026-07-15 16:53:02 +08:00
hkfires
c48516c5d6 feat(tests): refactor snapshot handling in model registration tests for improved clarity and consistency 2026-06-29 11:54:26 +08:00
hkfires
1f16e87e1a feat(pluginstore): introduce support for direct install type and version management
- Added Manifest struct to encapsulate plugin metadata and installation details.
- Implemented ManifestFromRelease and ManifestFromPlugin functions for creating manifests from releases and plugins.
- Enhanced Plugin struct to include Versions and InstallPlan for direct installations.
- Introduced validation for direct install type, ensuring artifacts are correctly specified.
- Updated registry validation to support new schema version and direct install requirements.
- Added tests for parsing and validating direct install plugins, ensuring correct artifact handling.
2026-06-28 21:19:34 +08:00
hkfires
6a59d645b5 feat(pluginhost): enhance plugin version management and logging for hot reload 2026-06-26 12:05:07 +08:00
hkfires
192888f9b1 feat(pluginhost): enhance logging with plugin name and path fields 2026-06-25 20:51:20 +08:00
Supra4E8C
810abe5e2a feat(pluginhost): add OAuthProvider field to plugin metadata and update related functionality 2026-06-25 17:35:17 +08:00
Luis Pater
b53d1e9569 refactor(pluginhost): replace Snapshot().records with activeRecords for improved filtering
- Introduced `activeRecords` and `activeRecordsFromSnapshot` to filter current plugin records more efficiently.
- Updated all instances of `Snapshot().records` across code and tests to use `activeRecords`.
- Added additional checks for `recordCurrent` and plugin identity validation in several plugin capability calls.
- Enhanced test logic to validate `activeRecords` usage and ensure consistent behavior.
2026-06-25 01:24:44 +08:00
hkfires
df10a5b1c7 feat(pluginhost): add shadow plugin management and cleanup functionality 2026-06-24 21:29:13 +08:00
Luis Pater
70053beadb feat(auth): refactor credential kind detection and add dynamic source classification
- Introduced `AuthKind` and `AuthSourceKind` methods for improved credential type and source classification.
- Replaced legacy fallback logic with normalized attribute-based handling in `AuthKind`.
- Consolidated metadata inspection for both API key and OAuth attributes.
- Updated calls to replace direct `AccountInfo` usage with `AuthKind` and `AuthSourceKind`.
- Enhanced unit tests to validate explicit and fallback credential resolution scenarios.
2026-06-23 23:21:33 +08:00