mirror of
https://github.com/router-for-me/CLIProxyAPI.git
synced 2026-09-06 16:15:50 +08:00
A caller can put a {"role":"system"} turn inside messages. Models older than
the role=system turn reject it outright, verified against api.anthropic.com on
both /v1/messages and /v1/messages/count_tokens:
400 role 'system' is not supported on this model
claude-haiku-4-5, claude-sonnet-4-5, claude-sonnet-4-6 and claude-opus-4-6
answer that way, while claude-sonnet-5 and claude-opus-5 accept the turn.
claudeLegacySystemReminderModels already enumerates that boundary, which is why
claudeCodeCLIBetas withholds mid-conversation-system-2026-04-07 for those
models, but caller-provided turns were forwarded unchanged and always spent an
upstream call on a guaranteed rejection.
The native client does not produce the pairing either: it gates the turn on the
model. In 314 captured native requests the turn appears only on
claude-opus-5 and claude-sonnet-5, and on none of the 43 requests addressed to
a model in that set. That is an observation about the captures rather than a
proof about the upstream, so it only corroborates the measured rejection.
Validate the finished body, and only inside the evidence that produced the
rule:
- The check runs after the body is finalized and before
http.NewRequestWithContext. Payload rules can rewrite model and messages long
after translation, so an earlier check would not describe what is sent.
- Only Anthropic's first-party origin is covered, matching the reasoning
shouldUseClaudeUpstreamTokenCount already applies to count_tokens. A
third-party gateway may map these model IDs onto something that accepts the
turn and therefore decides for itself.
- A confirmed native caller keeps the passthrough. It gates the turn itself, so
its body is forwarded untouched and the upstream error reaches it unchanged.
- Unknown and future model IDs stay optimistic and are forwarded, matching how
checkSystemInstructions treats them.
- rebuild_mid_system_message still folds caller turns into the system slot; the
final check therefore preserves the explicit escape hatch.
Cloaking adds one extra ordering case: it can place a caller's top-level system
prompt into a role=system turn for a modern model before a payload rule changes
the model to legacy. Track only the exact contiguous turns that CPA inserted,
using both their position and the corresponding message-count increase as
provenance. After payload rules settle the model, replay those turns through the
existing legacy <system-reminder> path. Pre-existing caller turns, even if they
have identical content, remain caller-owned and are still rejected. If payload
rules also rewrite the tracked messages, reconciliation fails closed and final
validation returns 400 rather than guessing provenance.
The 400 is request-scoped like claudeCallerSystemBlockError: the invalid
body/model pairing is independent of first-party credential health, so no
credential is cooled or retried.
Translated requests never carry the pairing, because every non-Claude source
format hoists system content into the top-level system field. Tests pin that for
OpenAI, Gemini, Responses and Interactions, and separately drive Execute,
ExecuteStream and CountTokens through an injected first-party transport.
327 lines
14 KiB
Go
327 lines
14 KiB
Go
package executor
|
|
|
|
import (
|
|
"bytes"
|
|
"context"
|
|
"fmt"
|
|
"io"
|
|
"net/http"
|
|
|
|
"github.com/router-for-me/CLIProxyAPI/v7/internal/runtime/executor/helps"
|
|
"github.com/router-for-me/CLIProxyAPI/v7/internal/thinking"
|
|
cliproxyauth "github.com/router-for-me/CLIProxyAPI/v7/sdk/cliproxy/auth"
|
|
cliproxyexecutor "github.com/router-for-me/CLIProxyAPI/v7/sdk/cliproxy/executor"
|
|
sdktranslator "github.com/router-for-me/CLIProxyAPI/v7/sdk/translator"
|
|
log "github.com/sirupsen/logrus"
|
|
"github.com/tidwall/gjson"
|
|
)
|
|
|
|
func (e *ClaudeExecutor) Execute(ctx context.Context, auth *cliproxyauth.Auth, req cliproxyexecutor.Request, opts cliproxyexecutor.Options) (resp cliproxyexecutor.Response, err error) {
|
|
if opts.Alt == "responses/compact" {
|
|
return resp, statusErr{code: http.StatusNotImplemented, msg: "/responses/compact not supported"}
|
|
}
|
|
baseModel := thinking.ParseSuffix(req.Model).ModelName
|
|
upstreamModel := e.upstreamModel(baseModel)
|
|
|
|
apiKey, baseURL := claudeCreds(auth)
|
|
if baseURL == "" {
|
|
baseURL = "https://api.anthropic.com"
|
|
}
|
|
url := fmt.Sprintf("%s/v1/messages?beta=true", baseURL)
|
|
oauthToken := isClaudeOAuthToken(apiKey)
|
|
cchSigning := claudeCCHSigningEnabled(apiKey, claudeCCHUpstreamAnthropic, url)
|
|
|
|
reporter := helps.NewExecutorUsageReporter(ctx, e, baseModel, auth)
|
|
defer reporter.TrackFailure(ctx, &err)
|
|
from := opts.SourceFormat
|
|
responseFormat := cliproxyexecutor.ResponseFormatOrSource(opts)
|
|
to := sdktranslator.FromString("claude")
|
|
var replayScope claudeThinkingReplayScope
|
|
if claudeThinkingReplayEnabled(auth, req, opts) {
|
|
req, replayScope = prepareClaudeThinkingReplayRequest(ctx, auth, req, opts)
|
|
}
|
|
defer func() {
|
|
if err != nil && replayScope.replayApplied && shouldClearKimiThinkingReplayAfterError(err) {
|
|
clearClaudeThinkingReplayContent(ctx, replayScope)
|
|
}
|
|
}()
|
|
// Use an upstream stream whenever the downstream response needs translation
|
|
// from Claude events. Native Claude responses use the JSON response path.
|
|
upstreamStream := responseFormat != to
|
|
originalPayloadSource := req.Payload
|
|
if len(opts.OriginalRequest) > 0 {
|
|
originalPayloadSource = opts.OriginalRequest
|
|
}
|
|
originalPayload := originalPayloadSource
|
|
incomingHeaders, claudeCodeDetection := detectIncomingClaudeCodeRequest(ctx, opts.Headers, originalPayload, false, e.cfg)
|
|
confirmedClaudeCode := claudeCodeDetection.Confirmed
|
|
claudeSessionID := ""
|
|
if oauthToken {
|
|
claudeSessionID = helps.ClaudeAgentSessionUUIDForRequest(incomingHeaders, originalPayload, req.Payload, confirmedClaudeCode, opts.Metadata, req.Metadata)
|
|
}
|
|
originalTranslated := helps.TranslateRequestWithAPIKeyModelCompatibility(ctx, opts.Headers, e.cfg, from, to, baseModel, originalPayload, upstreamStream, helps.APIKeyModelIsCompat(req))
|
|
body := helps.TranslateRequestWithAPIKeyModelCompatibility(ctx, opts.Headers, e.cfg, from, to, baseModel, req.Payload, upstreamStream, helps.APIKeyModelIsCompat(req))
|
|
body = helps.SetStringIfDifferent(body, "model", upstreamModel)
|
|
|
|
body, err = helps.ApplyRequestThinking(body, req, opts, from.String(), to.String(), e.Identifier())
|
|
if err != nil {
|
|
return resp, err
|
|
}
|
|
if rebuildMidSystemMessageEnabled(e.cfg, auth) {
|
|
body = rebuildMidSystemMessagesToTopLevel(body)
|
|
}
|
|
|
|
// Apply cloaking (system prompt injection, fake user ID, sensitive word obfuscation)
|
|
// based on client type and configuration.
|
|
bodyBeforeCloaking := body
|
|
var cloaked bool
|
|
body, cloaked, err = applyCloaking(
|
|
ctx,
|
|
e.cfg,
|
|
auth,
|
|
body,
|
|
apiKey,
|
|
confirmedClaudeCode,
|
|
cchSigning,
|
|
)
|
|
if err != nil {
|
|
return resp, err
|
|
}
|
|
systemPlacementState := captureClaudeCodeSystemPlacement(bodyBeforeCloaking, body, cloaked)
|
|
// Only the Messages endpoint on Anthropic itself was captured; count_tokens
|
|
// keeps its own shape and other gateways never see this field.
|
|
diagnosticsState := claudeDiagnosticsRequestState{}
|
|
contextManagementState := claudeCodeContextManagementState{
|
|
eligible: cloaked && isAnthropicUpstreamBase(baseURL),
|
|
callerOwned: gjson.GetBytes(body, "context_management").Exists(),
|
|
}
|
|
if contextManagementState.eligible {
|
|
body, contextManagementState.automaticallyInjected = injectClaudeCodeContextManagement(body)
|
|
if oauthToken {
|
|
body, diagnosticsState = injectClaudeDiagnostics(body, auth, claudeSessionID)
|
|
}
|
|
}
|
|
|
|
requestedModel := helps.PayloadRequestedModel(opts, req.Model)
|
|
requestPath := helps.PayloadRequestPath(opts)
|
|
body, contextManagementState.payloadRuleTouched = helps.ApplyPayloadConfigWithRequestTracked(e.cfg, baseModel, to.String(), from.String(), "", body, originalTranslated, requestedModel, requestPath, opts.Headers, "context_management")
|
|
body = reconcileClaudeCodeSystemPlacementAfterPayload(body, systemPlacementState)
|
|
body = ensureModelMaxTokens(body, baseModel)
|
|
|
|
// Disable thinking if tool_choice forces tool use (Anthropic API constraint)
|
|
body = disableThinkingIfToolChoiceForced(body)
|
|
body = reconcileClaudeCodeContextManagement(body, contextManagementState)
|
|
body = normalizeClaudeSamplingForUpstream(body, confirmedClaudeCode)
|
|
|
|
// Default cache_control for translated entrypoints (Responses/Chat/Gemini) and other
|
|
// non-native callers. Confirmed native Claude Code owns its marker placement and must
|
|
// not be rewritten. Cloaked requests always run section-independent ensure so cloaking's
|
|
// first-user marker cannot suppress system/latest-user breakpoints.
|
|
// cloaked and confirmedClaudeCode are mutually exclusive: resolveClaudeWirePolicy
|
|
// forces Cloak off for a confirmed native client.
|
|
cpaOwnsCacheControl := shouldEnsureCacheControl(body, cloaked, confirmedClaudeCode)
|
|
if cpaOwnsCacheControl {
|
|
body = ensureCacheControl(body)
|
|
}
|
|
|
|
// Enforce Anthropic's cache_control block limit (max 4 breakpoints per request).
|
|
// Cloaking and ensureCacheControl may push the total over 4 when the client
|
|
// already sends multiple cache_control blocks.
|
|
body = enforceCacheControlLimit(body, 4)
|
|
|
|
// Native selects the 1h cache pool only for OAuth credentials and pairs it with
|
|
// extended-cache-ttl-2025-04-11, which claudeCodeCLIBetas emits on exactly the
|
|
// same credential condition. Upgrading after placement is settled mirrors the
|
|
// native ttl helper.
|
|
//
|
|
// This runs only while CPA owns placement, and it then owns the ttl of every
|
|
// breakpoint it can reach: a marker carrying no ttl is the wire default, not an
|
|
// opt-in to 5m, so a cloaked caller's bare {"type":"ephemeral"} is upgraded too.
|
|
// Only a ttl the caller wrote out explicitly survives, because
|
|
// upgradeClaudeCacheControlTTL skips any block that already has one.
|
|
if cpaOwnsCacheControl && claudeCredentialUsesOAuth(auth, apiKey) {
|
|
body = upgradeClaudeCacheControlTTL(body, claudeCacheControlTTL1h)
|
|
}
|
|
|
|
// Normalize TTL values to prevent ordering violations under prompt-caching-scope-2026-01-05.
|
|
// A 1h-TTL block must not appear after a 5m-TTL block in evaluation order (tools→system→messages).
|
|
body = normalizeCacheControlTTL(body)
|
|
// Payload rules and other request processing may rewrite stream. Keep the
|
|
// upstream body, transport headers, and response parser on one authority.
|
|
// Native non-stream Haiku helper requests omit stream rather than sending
|
|
// false, so preserve that measured wire shape when the transport agrees.
|
|
streamField := gjson.GetBytes(body, "stream")
|
|
if !claudeCodeDetection.HelperProfile || streamField.Exists() || upstreamStream {
|
|
body = helps.SetBoolIfDifferent(body, "stream", upstreamStream)
|
|
}
|
|
|
|
// Extract betas from body and convert to header
|
|
var extraBetas []string
|
|
extraBetas, body = extractAndRemoveBetas(body)
|
|
bodyForTranslation := body
|
|
bodyForUpstream := body
|
|
var oauthToolNamesReverseMap map[string]string
|
|
if oauthToken && cloaked {
|
|
mcpAliases := resolveClaudeMCPAliasOptions(ctx)
|
|
bodyForUpstream, oauthToolNamesReverseMap = prepareClaudeOAuthToolNamesForUpstream(bodyForUpstream, mcpAliases)
|
|
}
|
|
bodyForUpstream = sanitizeClaudeMessagesForClaudeUpstreamWithDebug(ctx, bodyForUpstream, baseModel, helps.APIKeyModelIsCompat(req))
|
|
if oauthToken {
|
|
bodyForUpstream, _, err = helps.ApplyClaudeCredentialMetadata(bodyForUpstream, auth, claudeSessionID)
|
|
if err != nil {
|
|
return resp, fmt.Errorf("apply Claude credential metadata: %w", err)
|
|
}
|
|
}
|
|
cchBilling := ""
|
|
if cchSigning {
|
|
if !claudeCodeDetection.HelperProfile || claudeBodyNeedsBillingFallback(bodyForUpstream) {
|
|
cchBilling = claudeCCHFallbackBillingHeader(ctx, e.cfg, bodyForUpstream, claudeCodeDetection.Entrypoint)
|
|
}
|
|
bodyForUpstream, err = finalizeAnthropicMessagesBodyCCH(bodyForUpstream, cchBilling)
|
|
if err != nil {
|
|
return resp, fmt.Errorf("finalize Claude CCH: %w", err)
|
|
}
|
|
}
|
|
// Runs on the finished body: payload rules can rewrite model and messages
|
|
// long after translation, so an earlier check would not describe the request
|
|
// that is about to be sent.
|
|
if errMidSystem := validateClaudeMidSystemMessageModel(bodyForUpstream, confirmedClaudeCode, isAnthropicUpstreamBase(baseURL)); errMidSystem != nil {
|
|
return resp, errMidSystem
|
|
}
|
|
reporter.SetTranslatedReasoningEffort(bodyForUpstream, to.String())
|
|
httpReq, err := http.NewRequestWithContext(ctx, http.MethodPost, url, bytes.NewReader(bodyForUpstream))
|
|
if err != nil {
|
|
return resp, err
|
|
}
|
|
if errHeaders := applyClaudeHeadersWithNativeProfile(
|
|
httpReq,
|
|
auth,
|
|
apiKey,
|
|
upstreamStream,
|
|
extraBetas,
|
|
bodyForUpstream,
|
|
e.cfg,
|
|
incomingHeaders,
|
|
confirmedClaudeCode && !cloaked,
|
|
claudeCodeDetection.HelperProfile,
|
|
claudeSessionID,
|
|
); errHeaders != nil {
|
|
return resp, errHeaders
|
|
}
|
|
fastRequest := isAnthropicUpstreamBase(baseURL) && claudeRequestIsFast(httpReq, bodyForUpstream)
|
|
authID, authLabel, authType, authValue := claudeAuthLogIdentity(auth)
|
|
helps.RecordAPIRequest(ctx, e.cfg, helps.UpstreamRequestLog{
|
|
URL: url,
|
|
Method: http.MethodPost,
|
|
Headers: httpReq.Header.Clone(),
|
|
Body: bodyForUpstream,
|
|
Provider: e.upstreamRequestLogProvider(),
|
|
AuthID: authID,
|
|
AuthLabel: authLabel,
|
|
AuthType: authType,
|
|
AuthValue: authValue,
|
|
})
|
|
|
|
httpClient := helps.NewUtlsHTTPClient(ctx, e.cfg, auth, 0)
|
|
httpClient = reporter.TrackHTTPClient(httpClient)
|
|
httpResp, err := doClaudeUpstreamRequest(httpClient, httpReq)
|
|
if err != nil {
|
|
helps.RecordAPIResponseError(ctx, e.cfg, err)
|
|
return resp, wrapClaudeFastRequestError(fastRequest, 0, err)
|
|
}
|
|
helps.RecordAPIResponseMetadata(ctx, e.cfg, httpResp.StatusCode, httpResp.Header.Clone())
|
|
if httpResp.StatusCode < 200 || httpResp.StatusCode >= 300 {
|
|
// Decompress error responses — pass the Content-Encoding value (may be empty)
|
|
// and let decodeResponseBody handle both header-declared and magic-byte-detected
|
|
// compression. This keeps error-path behaviour consistent with the success path.
|
|
errBody, decErr := decodeResponseBody(httpResp.Body, claudeResponseContentEncoding(httpResp.Header))
|
|
if decErr != nil {
|
|
helps.RecordAPIResponseError(ctx, e.cfg, decErr)
|
|
msg := fmt.Sprintf("failed to decode error response body: %v", decErr)
|
|
helps.LogWithRequestID(ctx).Warn(msg)
|
|
return resp, wrapClaudeFastRequestError(fastRequest, httpResp.StatusCode, statusErr{code: httpResp.StatusCode, msg: msg})
|
|
}
|
|
b, readErr := io.ReadAll(errBody)
|
|
if readErr != nil {
|
|
helps.RecordAPIResponseError(ctx, e.cfg, readErr)
|
|
msg := fmt.Sprintf("failed to read error response body: %v", readErr)
|
|
helps.LogWithRequestID(ctx).Warn(msg)
|
|
b = []byte(msg)
|
|
}
|
|
helps.AppendAPIResponseChunk(ctx, e.cfg, b)
|
|
helps.LogWithRequestID(ctx).Debugf("request error, error status: %d, error message: %s", httpResp.StatusCode, helps.SummarizeErrorBody(httpResp.Header.Get("Content-Type"), b))
|
|
if errClose := errBody.Close(); errClose != nil {
|
|
log.Errorf("response body close error: %v", errClose)
|
|
}
|
|
if fastRequest {
|
|
return resp, newClaudeFastDirectResponseError(httpResp, b)
|
|
}
|
|
return resp, classifyClaudeUpstreamError(httpResp.StatusCode, b)
|
|
}
|
|
decodedBody, err := decodeResponseBody(httpResp.Body, claudeResponseContentEncoding(httpResp.Header))
|
|
if err != nil {
|
|
helps.RecordAPIResponseError(ctx, e.cfg, err)
|
|
if errClose := httpResp.Body.Close(); errClose != nil {
|
|
log.Errorf("response body close error: %v", errClose)
|
|
}
|
|
return resp, wrapClaudeFastRequestError(fastRequest, httpResp.StatusCode, err)
|
|
}
|
|
defer func() {
|
|
if errClose := decodedBody.Close(); errClose != nil {
|
|
log.Errorf("response body close error: %v", errClose)
|
|
}
|
|
}()
|
|
data, err := io.ReadAll(decodedBody)
|
|
if err != nil {
|
|
helps.RecordAPIResponseError(ctx, e.cfg, err)
|
|
return resp, wrapClaudeFastRequestError(fastRequest, httpResp.StatusCode, err)
|
|
}
|
|
helps.AppendAPIResponseChunk(ctx, e.cfg, data)
|
|
if upstreamStream {
|
|
if errValidate := validateClaudeStreamingResponse(data); errValidate != nil {
|
|
helps.RecordAPIResponseError(ctx, e.cfg, errValidate)
|
|
return resp, wrapClaudeFastRequestError(fastRequest, httpResp.StatusCode, errValidate)
|
|
}
|
|
commitClaudeDiagnostics(diagnosticsState, claudeMessageIDFromSSE(data))
|
|
lines := bytes.Split(data, []byte("\n"))
|
|
for i, line := range lines {
|
|
if detail, ok := helps.ParseClaudeStreamUsage(line); ok {
|
|
reporter.Publish(ctx, detail)
|
|
}
|
|
restoredLine, errRestore := restoreClaudeOAuthToolNamesFromStreamLine(line, oauthToolNamesReverseMap)
|
|
if errRestore != nil {
|
|
errRestore = fmt.Errorf("restore Claude OAuth tool name from streaming response: %w", errRestore)
|
|
helps.RecordAPIResponseError(ctx, e.cfg, errRestore)
|
|
return resp, wrapClaudeFastRequestError(fastRequest, httpResp.StatusCode, errRestore)
|
|
}
|
|
lines[i] = restoredLine
|
|
}
|
|
data = bytes.Join(lines, []byte("\n"))
|
|
} else {
|
|
commitClaudeDiagnostics(diagnosticsState, claudeMessageIDFromResponse(data))
|
|
reporter.Publish(ctx, helps.ParseClaudeUsage(data))
|
|
var errRestore error
|
|
data, errRestore = restoreClaudeOAuthToolNamesFromResponse(data, oauthToolNamesReverseMap)
|
|
if errRestore != nil {
|
|
errRestore = fmt.Errorf("restore Claude OAuth tool name from response: %w", errRestore)
|
|
helps.RecordAPIResponseError(ctx, e.cfg, errRestore)
|
|
return resp, wrapClaudeFastRequestError(fastRequest, httpResp.StatusCode, errRestore)
|
|
}
|
|
}
|
|
data = e.restoreResponseModel(data, req.Model)
|
|
cacheClaudeThinkingReplayResponse(ctx, replayScope, data)
|
|
var param any
|
|
out := sdktranslator.TranslateNonStream(
|
|
ctx,
|
|
to,
|
|
responseFormat,
|
|
req.Model,
|
|
opts.OriginalRequest,
|
|
bodyForTranslation,
|
|
data,
|
|
¶m,
|
|
)
|
|
resp = cliproxyexecutor.Response{Payload: out, Headers: httpResp.Header.Clone()}
|
|
return resp, nil
|
|
}
|