Commit d85b4e3
committed
fix: Address code review on the tool-prune series
Correctness and privacy:
- snapshot.go: gjson's String() on an object or array returns that node's RAW
JSON, so a structured error.type put response body content — anything the
provider quoted from the request — into the unauthenticated session store,
defeating the reason error.message is excluded. Now accepts only a JSON
string or number. A test plants a credential in a structured value.
- toolprune: modelRates.rateFor reports whether a usable rate exists.
set() ORs three fields, so a model configured with only a cache-read rate
resolved as priced and then charged a cache-write request zero — vanishing
from the total with no `requests unpriced` row.
- toolprune: the built-in per-model table now precedes the flat fallback. The
flat fields are documented as covering models "absent from pricing", and a
model in the table is not absent; one flat rate shadowing every per-model
default reintroduced flat-rate mispricing, silently, and claimed to be
operator-configured.
- toolprune: forcedToolChoice replaces forcedToolName. An object tool_choice
naming nothing recognisable (Bedrock Converse nests it as tool.name) now
declines to prune rather than reading it as "nothing forced" and risking
removal of the one required tool.
- abctl: a response carrying a RequestID that fails to pair exactly — a retry,
or a stream recorded twice — no longer falls through to the adjacency
heuristic, where it could claim an unrelated earlier request. The same guard
gates pricing, since a mismatched response supplies the wrong cache tier and
the tiers are 12.5x apart.
- toolscan: PatchConfig writes via temp file + Sync + rename. os.WriteFile
truncates in place, so a crash left a truncated config with no recovery copy,
and the proxy's fsnotify reloader could observe the partial file.
- demo.go: writeDemoConfig keeps an existing demo.yaml. It runs before any port
binds, so an unconditional write meant a --demo start that then failed on a
port clash destroyed the operator's edits — including a prune list written by
`abctl tools scan --write`, which the config's own comment recommends.
sparc declared WritesRequestBody but calls pctx.SetBody nowhere; the flag was
stale from the undirected capability and occupied the single request-mutator
slot, so [sparc, tool-prune] could not build. Dropped — which is the payoff
this series was arguing for, now pinned by a test.
Tests: real byte-exactness for the prune (reconstructing expected output from
the original bytes, covering first/middle/last element and validating with
encoding/json — the old test asserted only fragments and a shorter length, and
never removed a first or last element); tool_choice string forms; OpenAI-dialect
all-removed; and a reflection-driven clone check that fails if a future
slice/map capability is aliased.
Also: bytes.Contains on the scan hot path; names_unresolved distinguished from
no_configured_tool_present; an in-flight guard so the 2s refresh tick cannot
stack fetches against a 10s timeout; the dead crypto/rand fallback removed
(cannot fail as of Go 1.24); and docs corrected — WritesResponseBody added to
the capability snippet, the duplicated rate-derivation section removed, the
"ships with on_error: observe" claim replaced with the empty remove list that
is the actual guard, counters noted as resetting on hot-reload too, the
BodyAccess changelog line marked as since-removed, and the README's 20-25%
figure attributed to the traffic it was measured on.
Signed-off-by: Hai Huang <huang195@gmail.com>1 parent 1fc8cf6 commit d85b4e3
23 files changed
Lines changed: 568 additions & 91 deletions
File tree
- authbridge
- authlib
- pipeline
- plugins
- sparc
- toolprune
- cmd
- abctl
- toolscan
- tui
- authbridge-proxy
- docs
- docs/proposals
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
40 | 40 | | |
41 | 41 | | |
42 | 42 | | |
43 | | - | |
44 | | - | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
45 | 46 | | |
46 | 47 | | |
47 | 48 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
163 | 163 | | |
164 | 164 | | |
165 | 165 | | |
| 166 | + | |
| 167 | + | |
| 168 | + | |
| 169 | + | |
| 170 | + | |
| 171 | + | |
| 172 | + | |
| 173 | + | |
| 174 | + | |
| 175 | + | |
| 176 | + | |
| 177 | + | |
| 178 | + | |
| 179 | + | |
| 180 | + | |
| 181 | + | |
| 182 | + | |
| 183 | + | |
| 184 | + | |
| 185 | + | |
| 186 | + | |
| 187 | + | |
| 188 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | 1 | | |
2 | 2 | | |
3 | | - | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
4 | 7 | | |
5 | 8 | | |
6 | 9 | | |
| |||
75 | 78 | | |
76 | 79 | | |
77 | 80 | | |
| 81 | + | |
| 82 | + | |
| 83 | + | |
| 84 | + | |
| 85 | + | |
| 86 | + | |
| 87 | + | |
| 88 | + | |
| 89 | + | |
| 90 | + | |
| 91 | + | |
| 92 | + | |
| 93 | + | |
| 94 | + | |
| 95 | + | |
| 96 | + | |
| 97 | + | |
| 98 | + | |
| 99 | + | |
| 100 | + | |
| 101 | + | |
| 102 | + | |
| 103 | + | |
| 104 | + | |
| 105 | + | |
| 106 | + | |
| 107 | + | |
| 108 | + | |
| 109 | + | |
| 110 | + | |
| 111 | + | |
| 112 | + | |
| 113 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
3 | 3 | | |
4 | 4 | | |
5 | 5 | | |
6 | | - | |
7 | | - | |
8 | 6 | | |
9 | 7 | | |
10 | | - | |
11 | | - | |
12 | | - | |
13 | | - | |
14 | | - | |
15 | 8 | | |
16 | 9 | | |
17 | 10 | | |
| |||
20 | 13 | | |
21 | 14 | | |
22 | 15 | | |
23 | | - | |
24 | | - | |
25 | | - | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
26 | 19 | | |
27 | 20 | | |
28 | 21 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
165 | 165 | | |
166 | 166 | | |
167 | 167 | | |
168 | | - | |
| 168 | + | |
| 169 | + | |
| 170 | + | |
| 171 | + | |
| 172 | + | |
| 173 | + | |
| 174 | + | |
169 | 175 | | |
170 | | - | |
| 176 | + | |
171 | 177 | | |
172 | 178 | | |
173 | 179 | | |
| |||
177 | 183 | | |
178 | 184 | | |
179 | 185 | | |
| 186 | + | |
| 187 | + | |
| 188 | + | |
| 189 | + | |
| 190 | + | |
| 191 | + | |
| 192 | + | |
| 193 | + | |
| 194 | + | |
| 195 | + | |
| 196 | + | |
| 197 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
60 | 60 | | |
61 | 61 | | |
62 | 62 | | |
63 | | - | |
64 | | - | |
| 63 | + | |
| 64 | + | |
| 65 | + | |
| 66 | + | |
| 67 | + | |
| 68 | + | |
| 69 | + | |
| 70 | + | |
| 71 | + | |
| 72 | + | |
| 73 | + | |
| 74 | + | |
| 75 | + | |
| 76 | + | |
| 77 | + | |
| 78 | + | |
| 79 | + | |
| 80 | + | |
| 81 | + | |
| 82 | + | |
| 83 | + | |
| 84 | + | |
| 85 | + | |
| 86 | + | |
| 87 | + | |
| 88 | + | |
| 89 | + | |
| 90 | + | |
| 91 | + | |
| 92 | + | |
| 93 | + | |
| 94 | + | |
| 95 | + | |
| 96 | + | |
| 97 | + | |
65 | 98 | | |
66 | 99 | | |
67 | 100 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
209 | 209 | | |
210 | 210 | | |
211 | 211 | | |
212 | | - | |
213 | | - | |
214 | | - | |
215 | | - | |
| 212 | + | |
| 213 | + | |
| 214 | + | |
| 215 | + | |
| 216 | + | |
| 217 | + | |
| 218 | + | |
| 219 | + | |
216 | 220 | | |
217 | 221 | | |
218 | 222 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
335 | 335 | | |
336 | 336 | | |
337 | 337 | | |
| 338 | + | |
| 339 | + | |
| 340 | + | |
| 341 | + | |
| 342 | + | |
338 | 343 | | |
339 | 344 | | |
340 | | - | |
341 | | - | |
| 345 | + | |
| 346 | + | |
| 347 | + | |
| 348 | + | |
| 349 | + | |
| 350 | + | |
| 351 | + | |
| 352 | + | |
| 353 | + | |
342 | 354 | | |
343 | 355 | | |
344 | 356 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
119 | 119 | | |
120 | 120 | | |
121 | 121 | | |
122 | | - | |
| 122 | + | |
123 | 123 | | |
124 | 124 | | |
125 | 125 | | |
| |||
0 commit comments