Repository navigation
fix(anthropic): backport #42152 and #42288 to stable/1.100.x for v1.100.2 - #42532
Conversation
… beta to Bedrock Invoke and Vertex on /v1/messages Backport of #42288 to stable/1.100.x. Cherry-picked from merge commit fc82f6e (litellm_safeguards_bedrock_vertex_messages). The line has no bedrock_mantle beta-header mapping and no Mantle /v1/messages route, so the Mantle mapping, its test file, and the bedrock_mantle test parameter are left out.
…ine's budgets The picked TypedDict fields use read-only Sequence[Mapping[str, object]] annotations and the picked Vertex test carries a test-quality-ok marker, so stable/1.100.x's LIT001, LIT012 and TQ008 budgets hold. Static typing only, no runtime change.
|
I'll fix CI failures and address comments from users with write access. I'll skip comments containing "(aside)".
|
|
|
Backport of #42048 to stable/1.100.x. Cherry-picked from 7966f50 (main). The safeguards backport maps the dangerous-tool-use-2026-09-03 beta for Bedrock, which Claude Opus 4.5 on Bedrock Invoke rejects as an invalid beta flag, so the all-beta-headers Bedrock cases run on Claude Fable 5.1 as they do on main.
|
| finally: | ||
| monkeypatch.delenv("LITELLM_LOCAL_ANTHROPIC_BETA_HEADERS", raising=False) |
There was a problem hiding this comment.
Deleting local mode before reloading triggers an unmocked GitHub request and leaves cached beta configuration inconsistent after environment restoration
Rule Used: What: prevent any tests from being added here that make real network calls - only mock tests can be added to this folder. Exception: tests/e2e folder, this folder can contain network calls. Why: ensure it runs correctly on github ci/cd + for all d... (source)
Note: If this suggestion doesn't match your team's coding style, reply to this and let me know. I'll remember it for next time!
| def test_bedrock_messages_forwards_safeguards_with_dangerous_tool_use_beta(local_beta_headers_config, client_beta_header): | ||
| """ | ||
| Claude Code's server-side auto-mode classifier sends `safeguards` alongside the | ||
| dangerous-tool-use-2026-09-03 beta. Bedrock Invoke accepts the pair, answers | ||
| "safeguards: Extra inputs are not permitted" for the field alone, and returns | ||
| `safeguard_results: []` for the beta alone, so the field reaches it unchanged | ||
| and the beta rides along whether or not the client sent it, as every other | ||
| body-driven beta does here. |
There was a problem hiding this comment.
Prohibited explanatory comments
This test adds ordinary explanatory prose, violating the repository directive limiting comments. The same pattern appears elsewhere and must be removed before merging
Context Used: CLAUDE.md (source)
Note: If this suggestion doesn't match your team's coding style, reply to this and let me know. I'll remember it for next time!
TLDR
Problem this solves:
safeguardsfield on/v1/messagessafeguard_resultsHow it solves it:
stable/1.100.xwith their testssafeguardspasses through to Anthropic, Bedrock and Vertex,safeguard_resultscomes backUser Flow
Before: a developer running Claude Code through a LiteLLM gateway on this release line cannot use auto mode, because the gateway drops the field Claude Code needs for it
claudewithANTHROPIC_BASE_URL=https://litellm-domainand switch to auto mode (--permission-mode auto, or shift+tab)safeguardsarray in the body asking for the server-side classifiersafeguard_results, so/statusshowsAuto mode server: Disabledand every tool call is judged by the billed client-side classifier insteadAfter: the same developer gets auto mode through the gateway, with the classifier answers coming back from the provider
claudewithANTHROPIC_BASE_URL=https://litellm-domainand switch to auto mode (--permission-mode auto, or shift+tab)safeguardsarray in the body asking for the server-side classifiersafeguard_results(type: evaluated,outcome: not_flaggedper tool call), so/statusshowsAuto mode server: Enabledand the server-side classifier judges every tool callRelevant issues
Backport of #42152 and #42288
Affected release
Linear ticket
Resolves LIT-8336
Pre-Submission checklist
Please complete all items before asking a LiteLLM maintainer to review your PR
uv run pytest tests/test_litellm/<your_test_file>.py -v. Leave the suites (make test-unit-*,make test-unit) to CI: it finishes in ~15 minutes where a laptop takes an hour or more@greptileaito re-request a review after pushing changes)Backport checklist
3469a82da8fix(anthropic): forward safeguards and anthropic-beta unchanged on native /v1/messages #42152 fix(anthropic): pass through thesafeguardsfield Claude Code sends (cherry-picked frome912ebe999, original author kept)0d95fba73cfix(anthropic): forward Claude Code safeguards and dangerous-tool-use beta to Bedrock Invoke and Vertex on /v1/messages #42288 fix(anthropic): returnsafeguard_resultson Bedrock and Vertex too (cherry-picked fromfc82f6e8fa, original author kept). Its Mantle pieces are left out, that surface does not exist on this lineeb23cee8ffPrerequisite: thelocal_beta_headers_configtest fixture from47b2479c94, which the picked test file needs and this line lacks8ccfd6a84eBudget follow-up: the picked TypedDict fields use read-onlySequence[Mapping[str, object]]annotations and the picked Vertex test carries a# test-quality-okmarker, so the line's LIT001, LIT012 and TQ008 budgets hold. Static typing only, no runtime change, andmainkeeps its own annotations4438739b46Test-only port of fix(test): unbreak the integration-cost and proxy_e2e_anthropic_messages CircleCI jobs on main #42048 (7966f50c34, original author kept): the picked beta-header map addsdangerous-tool-use-2026-09-03for Bedrock, which Claude Opus 4.5 on Bedrock Invoke rejects as an invalid beta flag, so the all-beta-headers Bedrock e2e cases run on Claude Fable 5.1 as they do onmain. Touchestests/proxy_e2e_anthropic_messages_tests/onlyDelays in PR merge?
If you're seeing a delay in your PR being merged, ping the LiteLLM Team on Slack (#pr-review).
Screenshots / Proof of Fix
Before (44d3c4f)
Proxy booted from
44d3c4f290with--num_workers 2on port 54616, no DB; Claude Code v2.1.280 started withANTHROPIC_BASE_URL=http://localhost:54616and--permission-mode auto, modelanthropic-sonnet-5Claude Code auto mode through the gateway
Read and Bash tool calls run in auto mode, but
/statusreportsAuto mode server: Disabled: the gateway dropped thesafeguardsfield, so Claude Code falls back to its billed client-side classifierPOST /v1/messages with
safeguards(non-streaming and streaming, three providers)All six runs answer 200 with
safeguard_results: []: the beta header reached Anthropic but thesafeguardsfield did notAfter (8ccfd6a)
Proxy booted from
8ccfd6a84ewith--num_workers 2on port 20049, no DB; Claude Code v2.1.280 started withANTHROPIC_BASE_URL=http://localhost:20049and--permission-mode auto, modelanthropic-sonnet-5Claude Code auto mode through the gateway
The same Read and Bash tool calls run in auto mode and
/statusreportsAuto mode server: Enabled: the server-side classifier answers inside the main requestPOST /v1/messages with
safeguards(non-streaming and streaming, three providers)All six runs answer 200 with one
dangerous_tool_useentry whosestatus.typeisavailableand whose per-call result isevaluatedThe QA proof above ran at
8ccfd6a84e. The only commit since,4438739b46(the #42048 test port), touchestests/proxy_e2e_anthropic_messages_tests/only, so it cannot change runtime behavior and the proof stands at that hashType
🐛 Bug Fix
Caveats (if any)
4438739b46):test_bedrock_invoke_messages_with_all_beta_headers[bedrock-claude-opus-4.5-bedrock]failed on the first CircleCI run. The picked beta-header map addsdangerous-tool-use-2026-09-03for Bedrock, and Claude Opus 4.5 on Bedrock Invoke rejects it as an invalid beta flag.mainhas run those cases on Claude Fable 5.1 since fix(test): unbreak the integration-cost and proxy_e2e_anthropic_messages CircleCI jobs on main #42048 (7966f50c34), ported here as4438739b46; the CircleCI run at the tip no longer lists itllm_translation_testing,local_testing_part1andlocal_testing_part2fail on the TogetherAI cases only (the 18tests/llm_translation/test_together_ai.pycases,test_completion_custom_provider_model_name,test_completion_together_ai_stream,test_customprompt_together_ai,test_async_text_completion_together_ai). TogetherAI retired the serverlessopenai/gpt-oss-20bthose tests pin (itsdeprecation_dateis 2026-09-14), so they fail the same way at this line's base;mainfixed the suites in1aa2e19ee4,8c046e13bd,b478131701,515bf8c9d5and02ced74540. Nothing in this PR touches TogetherAIe2e_ui_testinguploads no junit results and fails ontests/e2e/ui/tests/mcp/mcpTools.spec.ts(the MCP Tools tab no longer lists theask_questioncard the spec hardcodes).mainrewrote the spec to check against the upstream's owntools/listin test(e2e-ui): check the MCP Tools tab against the upstream's own tools/list #42397 (b96842f62c). No dashboard code changes heretest_completion_bedrock_httpx_models[...-bedrock/cohere.command-r-plus-v1:0](both parametrizations) andtest_parallel_streaming_requests[cohere.command-r-plus-v1:0-False]fail because Bedrock retired that Cohere model.maindropped the cases in test(bedrock): drop EOL cohere.command-r-plus-v1:0 from local_testing #39608 (f87b9097ea). Unrelated to this changetest_bad_request_errorintests/openai_endpoints_tests/test_e2e_openai_responses_api.pystill expects a 400 for an unknown model on/v1/responses; OpenAI returns a 404 now andmainrewrote the test ind33fe95d19. The route is untouched by this PRtest_timeout_streamingandtest_router_timeoutare the known flaky timeout tests, green onmainthe same day and untouched by this PRstable/**ruleset requires one approving review and has no required status checks, so the inherited CircleCI reds above do not gate the merge and are recorded here instead of mergingmaininto the line; every GitHub Actions check is green at the tipFinal Attestation