mirror of
https://github.com/diegosouzapw/OmniRoute.git
synced 2026-08-16 04:03:02 +03:00
Compare commits
1 Commits
fix/10225-
...
fix/10348-
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
c7ff45b602 |
@@ -1 +0,0 @@
|
||||
- **fix(combo):** defer the known-context-overflow hard rejection for compressible requests so compression runs before the final context gate, instead of a raw-body estimate 400'ing generic Responses clients targeting a large model before OmniRoute can shrink it ([#10225](https://github.com/diegosouzapw/OmniRoute/issues/10225))
|
||||
1
changelog.d/fixes/10348-default-logs-redact-client.md
Normal file
1
changelog.d/fixes/10348-default-logs-redact-client.md
Normal file
@@ -0,0 +1 @@
|
||||
- fix(backend): redact client IPs and account prefixes from default proxy logs (#10348)
|
||||
@@ -591,8 +591,6 @@ export async function handleComboChat({
|
||||
nesting = null,
|
||||
hiddenModelsByProvider = getHiddenModelsByProvider(),
|
||||
clientManagedResponsesContext = false,
|
||||
deferContextOverflowWhenCompressible = false,
|
||||
compressionExclusions,
|
||||
}: HandleComboChatOptions): Promise<Response> {
|
||||
const comboCtx = createComboContext({ body, combo, settings, relayOptions, log });
|
||||
const {
|
||||
@@ -653,8 +651,6 @@ export async function handleComboChat({
|
||||
signal,
|
||||
apiKeyAllowedConnections,
|
||||
hiddenModelsByProvider,
|
||||
deferContextOverflowWhenCompressible,
|
||||
compressionExclusions,
|
||||
runCombo: handleComboChat,
|
||||
});
|
||||
if (fusionDispatch) return fusionDispatch;
|
||||
@@ -704,8 +700,6 @@ export async function handleComboChat({
|
||||
signal,
|
||||
apiKeyAllowedConnections,
|
||||
hiddenModelsByProvider,
|
||||
deferContextOverflowWhenCompressible,
|
||||
compressionExclusions,
|
||||
runCombo: handleComboChat,
|
||||
});
|
||||
if (runtimeUnitDispatch) return runtimeUnitDispatch;
|
||||
@@ -729,8 +723,6 @@ export async function handleComboChat({
|
||||
signal,
|
||||
hiddenModelsByProvider,
|
||||
clientManagedResponsesContext,
|
||||
deferContextOverflowWhenCompressible,
|
||||
compressionExclusions,
|
||||
relayOptions,
|
||||
});
|
||||
}
|
||||
@@ -758,8 +750,6 @@ export async function handleComboChat({
|
||||
buildAutoCandidates,
|
||||
hiddenModelsByProvider,
|
||||
clientManagedResponsesContext,
|
||||
deferContextOverflowWhenCompressible,
|
||||
compressionExclusions,
|
||||
});
|
||||
if ("earlyResponse" in targetResolution) return targetResolution.earlyResponse;
|
||||
const { stickyWeightedLimit, getWeightedStepKeyForTarget, preScreenMap } = targetResolution;
|
||||
@@ -2451,8 +2441,6 @@ async function handleRoundRobinCombo({
|
||||
nesting = null,
|
||||
hiddenModelsByProvider = getHiddenModelsByProvider(),
|
||||
clientManagedResponsesContext,
|
||||
deferContextOverflowWhenCompressible = false,
|
||||
compressionExclusions,
|
||||
relayOptions,
|
||||
}: HandleRoundRobinOptions): Promise<Response> {
|
||||
const config = settings
|
||||
@@ -2510,8 +2498,6 @@ async function handleRoundRobinCombo({
|
||||
const evalRankedTargets = orderTargetsByEvalScores(tagFilteredTargets, config.evalRouting, log);
|
||||
const knownContextOverflow = getKnownContextOverflow(evalRankedTargets, body, {
|
||||
clientManagedResponsesContext,
|
||||
deferContextOverflowWhenCompressible,
|
||||
compressionExclusions,
|
||||
});
|
||||
if (knownContextOverflow) {
|
||||
return errorResponseWithComboDiagnostics(
|
||||
|
||||
@@ -76,10 +76,6 @@ type PreludeBaseOptionArgs = {
|
||||
apiKeyAllowedConnections?: string[] | null;
|
||||
hiddenModelsByProvider?: HiddenModelsByProvider;
|
||||
clientManagedResponsesContext?: boolean;
|
||||
/** #10225 — defer the hard context-overflow preflight when compression is enabled. */
|
||||
deferContextOverflowWhenCompressible?: boolean;
|
||||
/** Server-side compression exclusions (#8034). */
|
||||
compressionExclusions?: import("../compression/exclusions.ts").CompressionExclusions;
|
||||
};
|
||||
|
||||
/** Rebuild handleComboChat's option bag verbatim for a recursive dispatch. */
|
||||
@@ -97,8 +93,6 @@ function buildBaseOptions(a: PreludeBaseOptionArgs): HandleComboChatOptions {
|
||||
apiKeyAllowedConnections: a.apiKeyAllowedConnections,
|
||||
hiddenModelsByProvider: a.hiddenModelsByProvider,
|
||||
clientManagedResponsesContext: a.clientManagedResponsesContext,
|
||||
deferContextOverflowWhenCompressible: a.deferContextOverflowWhenCompressible,
|
||||
compressionExclusions: a.compressionExclusions,
|
||||
};
|
||||
}
|
||||
|
||||
@@ -372,8 +366,6 @@ export async function tryFusionDispatch(args: {
|
||||
signal?: AbortSignal | null;
|
||||
apiKeyAllowedConnections?: string[] | null;
|
||||
hiddenModelsByProvider?: HiddenModelsByProvider;
|
||||
deferContextOverflowWhenCompressible?: boolean;
|
||||
compressionExclusions?: import("../compression/exclusions.ts").CompressionExclusions;
|
||||
runCombo: RunCombo;
|
||||
}): Promise<Response | null> {
|
||||
const { cfg, combo, config, strategy, log } = args;
|
||||
@@ -597,8 +589,6 @@ export async function tryRuntimeUnitDispatch(args: {
|
||||
signal?: AbortSignal | null;
|
||||
apiKeyAllowedConnections?: string[] | null;
|
||||
hiddenModelsByProvider?: HiddenModelsByProvider;
|
||||
deferContextOverflowWhenCompressible?: boolean;
|
||||
compressionExclusions?: import("../compression/exclusions.ts").CompressionExclusions;
|
||||
runCombo: RunCombo;
|
||||
}): Promise<Response | null> {
|
||||
const { body, combo, config, strategy, allCombos, log, settings } = args;
|
||||
|
||||
@@ -17,7 +17,6 @@
|
||||
*/
|
||||
|
||||
import { getResolvedModelCapabilities } from "../modelCapabilities.ts";
|
||||
import { isCompressionExcluded, type CompressionExclusions } from "../compression/exclusions.ts";
|
||||
import { deriveRequestCompatibilityRequirements } from "./comboStructure.ts";
|
||||
import type { ResolvedComboTarget } from "./types.ts";
|
||||
|
||||
@@ -29,19 +28,6 @@ export type KnownContextOverflow = {
|
||||
targetCount: number;
|
||||
};
|
||||
|
||||
export type KnownContextOverflowOptions = {
|
||||
clientManagedResponsesContext?: boolean;
|
||||
/**
|
||||
* When prompt compression is enabled for this request (global compression switch
|
||||
* AND not API-key opted-out), defer the hard preflight so chatCore's compression
|
||||
* pipeline runs before the final context gate — instead of a raw-body estimate
|
||||
* rejecting a compressible request up front. (#10225)
|
||||
*/
|
||||
deferContextOverflowWhenCompressible?: boolean;
|
||||
/** Server-side compression exclusions (#8034) — targets matching one cannot run compression. */
|
||||
compressionExclusions?: CompressionExclusions;
|
||||
};
|
||||
|
||||
// #7177: an empty array/object (e.g. a default `messages: []` some combo entrypoints inject
|
||||
// when the caller sent none) has no real content — counting it would charge a few phantom
|
||||
// "structural" tokens (JSON.stringify braces/brackets) toward the estimate, which is enough
|
||||
@@ -83,7 +69,7 @@ export function getKnownContextLimit(
|
||||
export function getKnownContextOverflow(
|
||||
targets: ResolvedComboTarget[],
|
||||
body: Record<string, unknown>,
|
||||
options: KnownContextOverflowOptions = {}
|
||||
options: { clientManagedResponsesContext?: boolean } = {}
|
||||
): KnownContextOverflow | null {
|
||||
if (targets.length === 0) return null;
|
||||
// Native Codex Responses clients compact their own item history. Let the concrete
|
||||
@@ -99,31 +85,6 @@ export function getKnownContextOverflow(
|
||||
) {
|
||||
return null;
|
||||
}
|
||||
// #10225: a conservative raw-body context estimate must not be treated as proof
|
||||
// that a compression-enabled request cannot fit. When compression is available
|
||||
// for this request AND at least one target can actually run it, defer the hard
|
||||
// rejection so handleChatCore runs proactive compression (chatCore.ts) and its
|
||||
// post-compression enforceOutputTokenBudget becomes the final context gate —
|
||||
// returning a local `context_length_exceeded` only if the compressed body still
|
||||
// cannot fit (no upstream dispatch). Each excluded/native-codex-passthrough
|
||||
// target is skipped; if no target can compress, the fast preflight is kept.
|
||||
if (
|
||||
options.deferContextOverflowWhenCompressible === true &&
|
||||
targets.some(
|
||||
(target) =>
|
||||
!isCompressionExcluded(
|
||||
{
|
||||
provider: target.provider,
|
||||
model: target.modelStr.includes("/")
|
||||
? target.modelStr.split("/").slice(1).join("/")
|
||||
: target.modelStr,
|
||||
},
|
||||
options.compressionExclusions
|
||||
)
|
||||
)
|
||||
) {
|
||||
return null;
|
||||
}
|
||||
const requirements = deriveRequestCompatibilityRequirements(body);
|
||||
if (requirements.requiredContextTokens <= 0) return null;
|
||||
|
||||
|
||||
@@ -115,10 +115,6 @@ export interface ResolveComboTargetPipelineDeps {
|
||||
hiddenModelsByProvider?: HiddenModelsByProvider;
|
||||
/** Native Responses clients (for example Codex CLI/Desktop) manage compaction themselves. */
|
||||
clientManagedResponsesContext?: boolean;
|
||||
/** #10225 — defer the hard context-overflow preflight when compression is enabled for this request. */
|
||||
deferContextOverflowWhenCompressible?: boolean;
|
||||
/** Server-side compression exclusions (#8034) — which targets can run compression. */
|
||||
compressionExclusions?: import("../compression/exclusions.ts").CompressionExclusions;
|
||||
}
|
||||
|
||||
export interface ResolvedComboTargetPipeline {
|
||||
@@ -734,8 +730,6 @@ export async function resolveComboTargetPipeline(
|
||||
|
||||
const overflow = getKnownContextOverflow(orderedTargets, body, {
|
||||
clientManagedResponsesContext: deps.clientManagedResponsesContext,
|
||||
deferContextOverflowWhenCompressible: deps.deferContextOverflowWhenCompressible,
|
||||
compressionExclusions: deps.compressionExclusions,
|
||||
});
|
||||
if (overflow) {
|
||||
return { earlyResponse: buildContextOverflowResponse(overflow, orderedTargets, log) };
|
||||
|
||||
@@ -6,7 +6,6 @@
|
||||
* — logic unchanged, re-exported from combo.ts for backward compatibility.
|
||||
*/
|
||||
|
||||
import type { CompressionExclusions } from "../compression/exclusions.ts";
|
||||
import type { ProviderCandidate } from "../autoCombo/scoring.ts";
|
||||
|
||||
export const RESET_WINDOW_NAMES = ["weekly", "session", "monthly"] as const;
|
||||
@@ -113,15 +112,6 @@ export type HandleComboChatOptions = {
|
||||
hiddenModelsByProvider?: HiddenModelsByProvider;
|
||||
/** Native Responses clients (for example Codex CLI/Desktop) manage compaction themselves. */
|
||||
clientManagedResponsesContext?: boolean;
|
||||
/**
|
||||
* #10225: request-scoped flag — prompt compression is enabled for this request
|
||||
* (global compression switch ON and not opted-out by the API key). When set, the
|
||||
* combo preflight defers its hard context-overflow rejection so chatCore's
|
||||
* compression runs before the final context gate.
|
||||
*/
|
||||
deferContextOverflowWhenCompressible?: boolean;
|
||||
/** Server-side compression exclusions (#8034) — used to check which targets can run compression. */
|
||||
compressionExclusions?: CompressionExclusions;
|
||||
};
|
||||
|
||||
export type HandleRoundRobinOptions = Omit<HandleComboChatOptions, "apiKeyAllowedConnections">;
|
||||
|
||||
@@ -105,6 +105,45 @@ function loadFromDb() {
|
||||
|
||||
loadFromDb();
|
||||
|
||||
// Default-off override that restores the verbose [ProxyEgress] console line (raw
|
||||
// client/egress IPs + account prefix). Kept OFF by default so the process log leaks
|
||||
// neither IPs nor the account prefix. Deliberately NOT coupled to debugMode
|
||||
// (src/lib/db/settings.ts defaults debugMode to true) — this verbosity is opt-in only.
|
||||
// Storage (in-memory ring buffer + SQLite) is untouched and always keeps full IPs.
|
||||
const PROXY_LOG_INCLUDE_IPS =
|
||||
process.env.PROXY_LOG_INCLUDE_IPS === "true" ||
|
||||
process.env.PROXY_LOG_INCLUDE_IPS === "1";
|
||||
|
||||
/**
|
||||
* Pure formatter for the [ProxyEgress] process-log line (#10348). At the default level it
|
||||
* emits a short, IP/prefix-free summary; when details are opted in it restores the full
|
||||
* verbose line including client/egress IPs and the account. Extracted as a separate
|
||||
* function so it is unit-testable without patching console.log and so the change never
|
||||
* grows logProxyEvent itself.
|
||||
*/
|
||||
export function formatProxyEgressConsoleLine(params: {
|
||||
provider: string | null;
|
||||
account: string | null;
|
||||
clientIp: string | null;
|
||||
egressIp: string | null;
|
||||
level: string;
|
||||
proxyHost: string | null | undefined;
|
||||
status: string;
|
||||
includeDetails?: boolean;
|
||||
}): string {
|
||||
const provider = params.provider || "-";
|
||||
const status = params.status;
|
||||
if (!params.includeDetails) {
|
||||
return `[ProxyEgress] ${provider} status=${status}`;
|
||||
}
|
||||
const proxy = params.proxyHost ? `:${params.proxyHost}` : "";
|
||||
return (
|
||||
`[ProxyEgress] ${provider}/${params.account || "-"} ` +
|
||||
`in=${params.clientIp || "?"} out=${params.egressIp || "?"} ` +
|
||||
`proxy=${params.level}${proxy} status=${status}`
|
||||
);
|
||||
}
|
||||
|
||||
// ──────────────── Log a proxy event ────────────────
|
||||
|
||||
export function logProxyEvent(entry: ProxyLogInput) {
|
||||
@@ -131,9 +170,16 @@ export function logProxyEvent(entry: ProxyLogInput) {
|
||||
// IP each account is entering (clientIp) and leaving (egressIp) by.
|
||||
if (log.proxy || log.egressIp) {
|
||||
console.log(
|
||||
`[ProxyEgress] ${log.provider || "-"}/${log.account || "-"} ` +
|
||||
`in=${log.clientIp || "?"} out=${log.egressIp || "?"} ` +
|
||||
`proxy=${log.level}${log.proxy ? `:${log.proxy.host}` : ""} status=${log.status}`
|
||||
formatProxyEgressConsoleLine({
|
||||
provider: log.provider,
|
||||
account: log.account,
|
||||
clientIp: log.clientIp,
|
||||
egressIp: log.egressIp,
|
||||
level: log.level,
|
||||
proxyHost: log.proxy?.host,
|
||||
status: log.status,
|
||||
includeDetails: PROXY_LOG_INCLUDE_IPS,
|
||||
})
|
||||
);
|
||||
}
|
||||
|
||||
|
||||
@@ -33,8 +33,6 @@ import type { SingleModelTarget } from "@omniroute/open-sse/services/combo/types
|
||||
import { mergeAbortSignals } from "@omniroute/open-sse/executors/base.ts";
|
||||
import { resolveRequestAutoControls } from "@omniroute/open-sse/services/autoCombo/requestControls.ts";
|
||||
import { isVerifiedNativeCodexRequest } from "@omniroute/open-sse/config/codexIdentity.ts";
|
||||
import { resolveCompressionSettings } from "@omniroute/open-sse/handlers/chatCore/compressionSettings.ts";
|
||||
import type { CompressionExclusions } from "@omniroute/open-sse/services/compression/exclusions.ts";
|
||||
import { resolveComboConfig } from "@omniroute/open-sse/services/comboConfig.ts";
|
||||
import { injectHandoffIntoBody } from "@omniroute/open-sse/services/contextHandoff.ts";
|
||||
import {
|
||||
@@ -211,31 +209,6 @@ let combosCacheTs = 0;
|
||||
let combosCacheVersionSnapshot = -1;
|
||||
const COMBOS_CACHE_TTL_MS = 10_000;
|
||||
|
||||
/**
|
||||
* #10225 — resolve whether this request's combo preflight should DEFER its hard
|
||||
* context-overflow rejection so chatCore's compression runs first.
|
||||
*
|
||||
* Mirrors handleChatCore's own enablement determination (chatCore.ts): defer only
|
||||
* when the global compression switch is ON and the API key has not opted out
|
||||
* (`apiKeyInfo.compressionEnabled !== false`). Per-target applicability (server-side
|
||||
* exclusions) is checked inside getKnownContextOverflow via the returned exclusions.
|
||||
* Fail closed (defer=false) on any lookup error — the existing hard preflight stays.
|
||||
*/
|
||||
async function resolveComboContextOverflowDeferral(
|
||||
logger: { warn?: (...args: unknown[]) => void } | null | undefined,
|
||||
apiKeyInfo: { compressionEnabled?: boolean } | null | undefined
|
||||
): Promise<{ defer: boolean; exclusions: CompressionExclusions | undefined }> {
|
||||
try {
|
||||
const compression = await resolveCompressionSettings(logger);
|
||||
return {
|
||||
defer: compression.enabled && apiKeyInfo?.compressionEnabled !== false,
|
||||
exclusions: compression.settings?.exclusions,
|
||||
};
|
||||
} catch {
|
||||
return { defer: false, exclusions: undefined };
|
||||
}
|
||||
}
|
||||
|
||||
async function getCombosCachedForChat(): Promise<unknown[]> {
|
||||
const now = Date.now();
|
||||
// Explicit non-null check: we intentionally cache and return the Promise
|
||||
@@ -851,13 +824,9 @@ async function handleChatImplementation(
|
||||
|
||||
// Context-relay keeps generation in combo.ts, but handoff injection lives here
|
||||
// because only this layer knows which connectionId was actually selected.
|
||||
const { defer: deferContextOverflowWhenCompressible, exclusions: compressionExclusions } =
|
||||
await resolveComboContextOverflowDeferral(log, apiKeyInfo);
|
||||
const response = await (handleComboChat as any)({
|
||||
body,
|
||||
combo,
|
||||
deferContextOverflowWhenCompressible,
|
||||
compressionExclusions,
|
||||
clientManagedResponsesContext:
|
||||
sourceFormat === "openai-responses" &&
|
||||
new URL(request.url).pathname.split("/").includes("responses") &&
|
||||
@@ -1134,13 +1103,9 @@ async function handleSingleModelChat(
|
||||
);
|
||||
log.info("ROUTING", `Auto-combo redirect from handleSingleModelChat for "${modelStr}"`);
|
||||
log.info("ROUTING", `Auto-combo redirect to combo flow for "${modelStr}"`);
|
||||
const { defer: sNetDefer, exclusions: sNetExclusions } =
|
||||
await resolveComboContextOverflowDeferral(log, apiKeyInfo);
|
||||
return handleComboChat({
|
||||
body,
|
||||
combo: redirectCombo,
|
||||
deferContextOverflowWhenCompressible: sNetDefer,
|
||||
compressionExclusions: sNetExclusions,
|
||||
clientManagedResponsesContext:
|
||||
detectFormatFromEndpoint(body, clientRawRequest?.endpoint || "") === "openai-responses" &&
|
||||
String(clientRawRequest?.endpoint || "")
|
||||
|
||||
@@ -1,173 +0,0 @@
|
||||
import test from "node:test";
|
||||
import assert from "node:assert/strict";
|
||||
import fs from "node:fs";
|
||||
import os from "node:os";
|
||||
import path from "node:path";
|
||||
|
||||
/**
|
||||
* #10225 — combo known-context-overflow must NOT hard-reject a compressible
|
||||
* request before OmniRoute's compression pipeline can run.
|
||||
*
|
||||
* Root cause: getKnownContextOverflow() estimates the RAW body (ceil(serializedChars/4)
|
||||
* over the whole Responses input[]) during combo target resolution, before any
|
||||
* compression. When every known target limit is below that raw estimate, both call
|
||||
* sites (round-robin + target-resolution) convert it into an immediate local 400
|
||||
* `context_length_exceeded` with attempted:0 — so chatCore's proactive compression
|
||||
* (which can shrink 294133→111529, 62% in the reporter's case) never runs. The only
|
||||
* existing bypass (clientManagedResponsesContext) is gated to VERIFIED native Codex
|
||||
* clients, so a generic Responses client (e.g. OpenCode) pointed at a codex model
|
||||
* still hits the hard gate.
|
||||
*
|
||||
* Fix: thread a request-scoped `deferContextOverflowWhenCompressible` flag (set when
|
||||
* the global compression switch is ON and not API-key opted-out). When set AND at
|
||||
* least one target can run compression, getKnownContextOverflow returns null so the
|
||||
* request reaches chatCore, whose post-compression enforceOutputTokenBudget becomes
|
||||
* the final context gate — a local 400 only if the compressed body still cannot fit.
|
||||
*/
|
||||
|
||||
const TEST_DATA_DIR = fs.mkdtempSync(path.join(os.tmpdir(), "omniroute-combo-overflow-compress-"));
|
||||
const ORIGINAL_DATA_DIR = process.env.DATA_DIR;
|
||||
process.env.DATA_DIR = TEST_DATA_DIR;
|
||||
|
||||
const core = await import("../../src/lib/db/core.ts");
|
||||
const { saveModelsDevCapabilities, clearModelsDevCapabilities } =
|
||||
await import("../../src/lib/modelsDevSync.ts");
|
||||
const { getKnownContextOverflow, handleComboChat } = await import(
|
||||
"../../open-sse/services/combo.ts"
|
||||
);
|
||||
|
||||
test.after(() => {
|
||||
core.resetDbInstance();
|
||||
if (ORIGINAL_DATA_DIR === undefined) {
|
||||
delete process.env.DATA_DIR;
|
||||
} else {
|
||||
process.env.DATA_DIR = ORIGINAL_DATA_DIR;
|
||||
}
|
||||
fs.rmSync(TEST_DATA_DIR, { recursive: true, force: true });
|
||||
});
|
||||
|
||||
test.beforeEach(() => {
|
||||
clearModelsDevCapabilities();
|
||||
});
|
||||
|
||||
function capabilityEntry(limitContext: number | null) {
|
||||
return {
|
||||
tool_call: true,
|
||||
reasoning: false,
|
||||
attachment: false,
|
||||
structured_output: true,
|
||||
temperature: true,
|
||||
modalities_input: JSON.stringify(["text"]),
|
||||
modalities_output: JSON.stringify(["text"]),
|
||||
knowledge_cutoff: null,
|
||||
release_date: null,
|
||||
last_updated: null,
|
||||
status: null,
|
||||
family: null,
|
||||
open_weights: false,
|
||||
limit_context: limitContext,
|
||||
limit_input: limitContext,
|
||||
limit_output: 4096,
|
||||
interleaved_field: null,
|
||||
};
|
||||
}
|
||||
|
||||
function target(modelStr: string) {
|
||||
return {
|
||||
kind: "model" as const,
|
||||
stepId: modelStr,
|
||||
executionKey: modelStr,
|
||||
modelStr,
|
||||
provider: modelStr.includes("/") ? modelStr.split("/")[0] : modelStr,
|
||||
providerId: null,
|
||||
connectionId: null,
|
||||
weight: 1,
|
||||
label: null,
|
||||
};
|
||||
}
|
||||
|
||||
// A generic Responses-API body whose estimate lands near `tokens` tokens (4 chars/token).
|
||||
// Uses `input:` (not `messages:`) to mirror the OpenCode/Codex Responses surface.
|
||||
function bigResponsesBody(tokens: number) {
|
||||
return { input: [["user", "x".repeat(tokens * 4)]] };
|
||||
}
|
||||
|
||||
const noopLog = { info() {}, warn() {}, error() {}, debug() {} };
|
||||
|
||||
test("#10225 getKnownContextOverflow defers the hard overflow when compression is available", () => {
|
||||
saveModelsDevCapabilities({ codex: { "gpt-5.6-terra": capabilityEntry(272_000) } });
|
||||
const body = bigResponsesBody(275_000);
|
||||
|
||||
// Compression enabled + target can compress -> defer (null).
|
||||
assert.equal(
|
||||
getKnownContextOverflow([target("codex/gpt-5.6-terra")], body, {
|
||||
deferContextOverflowWhenCompressible: true,
|
||||
}),
|
||||
null,
|
||||
"compressible request must defer so chatCore compression can run (#10225)"
|
||||
);
|
||||
|
||||
// Compression disabled -> the existing hard overflow is preserved (never lose #7177).
|
||||
const hard = getKnownContextOverflow([target("codex/gpt-5.6-terra")], body);
|
||||
assert.ok(hard);
|
||||
assert.ok(hard.requiredContextTokens > hard.maxKnownContextTokens);
|
||||
|
||||
// Compression enabled but EVERY target is excluded from compression -> keep the hard gate.
|
||||
const excluded = getKnownContextOverflow([target("codex/gpt-5.6-terra")], body, {
|
||||
deferContextOverflowWhenCompressible: true,
|
||||
compressionExclusions: ["gpt-5.6-terra"],
|
||||
});
|
||||
assert.ok(excluded, "fully-excluded targets must retain the hard preflight");
|
||||
});
|
||||
|
||||
test("#10225 combo does not early-400 a compressible over-limit request when deferral is on", async () => {
|
||||
saveModelsDevCapabilities({ codex: { "gpt-5.6-terra": capabilityEntry(272_000) } });
|
||||
let dispatches = 0;
|
||||
|
||||
const response = await handleComboChat({
|
||||
body: bigResponsesBody(275_000),
|
||||
combo: {
|
||||
name: "codex-compress-overflow",
|
||||
strategy: "priority",
|
||||
models: ["codex/gpt-5.6-terra"],
|
||||
},
|
||||
deferContextOverflowWhenCompressible: true,
|
||||
clientManagedResponsesContext: false,
|
||||
isModelAvailable: async () => true,
|
||||
handleSingleModel: async () => {
|
||||
dispatches += 1;
|
||||
return new Response("ok", { status: 200 });
|
||||
},
|
||||
log: noopLog,
|
||||
});
|
||||
|
||||
assert.notEqual(response.status, 400, "compression-enabled request must reach chatCore");
|
||||
assert.equal(dispatches, 1, "must dispatch so chatCore compaction runs first");
|
||||
});
|
||||
|
||||
test("#10225 combo keeps the fast 400 when compression is disabled", async () => {
|
||||
saveModelsDevCapabilities({ codex: { "gpt-5.6-terra": capabilityEntry(272_000) } });
|
||||
let dispatches = 0;
|
||||
|
||||
const response = await handleComboChat({
|
||||
body: bigResponsesBody(275_000),
|
||||
combo: {
|
||||
name: "codex-compress-disabled",
|
||||
strategy: "priority",
|
||||
models: ["codex/gpt-5.6-terra"],
|
||||
},
|
||||
deferContextOverflowWhenCompressible: false,
|
||||
clientManagedResponsesContext: false,
|
||||
isModelAvailable: async () => true,
|
||||
handleSingleModel: async () => {
|
||||
dispatches += 1;
|
||||
return new Response("ok", { status: 200 });
|
||||
},
|
||||
log: noopLog,
|
||||
});
|
||||
|
||||
assert.equal(response.status, 400);
|
||||
assert.equal(dispatches, 0, "#7177 anti-exhaustion guard must survive when compression is off");
|
||||
const body = await response.json();
|
||||
assert.equal(body.error.code, "context_length_exceeded");
|
||||
});
|
||||
60
tests/unit/proxy-10348-log-redaction.test.ts
Normal file
60
tests/unit/proxy-10348-log-redaction.test.ts
Normal file
@@ -0,0 +1,60 @@
|
||||
import test from "node:test";
|
||||
import assert from "node:assert/strict";
|
||||
import fs from "node:fs";
|
||||
import os from "node:os";
|
||||
import path from "node:path";
|
||||
|
||||
// Regression guard for #10348 — default process logs must not leak client/egress IPs
|
||||
// or the raw account prefix. Storage (in-memory ring buffer + SQLite) stays intact;
|
||||
// only the process-log emission changes.
|
||||
const TEST_DATA_DIR = fs.mkdtempSync(path.join(os.tmpdir(), "omniroute-proxy-10348-"));
|
||||
process.env.DATA_DIR = TEST_DATA_DIR;
|
||||
|
||||
const core = await import("../../src/lib/db/core.ts");
|
||||
const proxyLogger = await import("../../src/lib/proxyLogger.ts");
|
||||
|
||||
function resetStorage() {
|
||||
proxyLogger.clearProxyLogs();
|
||||
core.closeDbInstance();
|
||||
fs.rmSync(TEST_DATA_DIR, { recursive: true, force: true });
|
||||
fs.mkdirSync(TEST_DATA_DIR, { recursive: true });
|
||||
}
|
||||
|
||||
test.beforeEach(() => resetStorage());
|
||||
test.after(() => resetStorage());
|
||||
|
||||
test("[10348] default ProxyEgress console line redacts client IP, egress IP, and account prefix", () => {
|
||||
const captured: string[] = [];
|
||||
const origConsole = console.log;
|
||||
console.log = (...args: unknown[]) => {
|
||||
captured.push(args.map(String).join(" "));
|
||||
};
|
||||
try {
|
||||
proxyLogger.logProxyEvent({
|
||||
status: "error",
|
||||
provider: "codex",
|
||||
clientIp: "198.51.100.7",
|
||||
egressIp: "203.0.113.9",
|
||||
account: "aabbccdd",
|
||||
level: "account",
|
||||
});
|
||||
} finally {
|
||||
console.log = origConsole;
|
||||
}
|
||||
const line = captured.find((l) => l.includes("[ProxyEgress]"));
|
||||
assert.ok(line, "expected a [ProxyEgress] console line");
|
||||
assert.ok(line!.includes("codex"), "expected provider in the line");
|
||||
assert.ok(line!.includes("status=error"), "expected status=error in the line");
|
||||
assert.ok(
|
||||
!line!.includes("198.51.100.7"),
|
||||
"client IP must be redacted from the console line by default"
|
||||
);
|
||||
assert.ok(
|
||||
!line!.includes("203.0.113.9"),
|
||||
"egress IP must be redacted from the console line by default"
|
||||
);
|
||||
assert.ok(
|
||||
!line!.includes("aabbccdd"),
|
||||
"account prefix must be redacted from the console line by default"
|
||||
);
|
||||
});
|
||||
Reference in New Issue
Block a user