Skip to content

feat(logger): dispatch Python logging through the Rust diagnostics processor - #42616

Merged
yujonglee-berri merged 13 commits into
mainfrom
litellm_rust_logger
Sep 23, 2026
Merged

yujonglee-berri merged 13 commits into
mainfrom
litellm_rust_logger

Conversation

@devin-ai-integration

@devin-ai-integration devin-ai-integration Bot commented Sep 22, 2026 •

Copy link
Copy Markdown
Contributor

TLDR

Problem this solves:

  • Log redaction and truncation run entirely in Python on every record
  • Rust callers have no shared diagnostic processor to reuse

How it solves it:

  • Adds a litellm-logger crate owning credential redaction and diagnostic processing
  • Exposes NativeDiagnosticProcessor through the pyo3 bridge
  • litellm/_logging.py dispatches through it under LITELLM_RUST, Python fallback otherwise

User Flow

Before: an operator cannot route verbose log redaction through the native diagnostics processor

  1. They set LITELLM_RUST=true, start the proxy, and emit a log line containing a credential
  2. The line is redacted by the Python filters; no native processor exists to pick up

After: the same operator sees the record processed by the Rust diagnostics processor

  1. They set LITELLM_RUST=true, start the proxy, and emit a log line containing a credential
  2. The line comes back REDACTED from NativeDiagnosticProcessor, falling back to Python on any failure

Relevant issues

Affected release

Linear ticket

Pre-Submission checklist

Please complete all items before asking a LiteLLM maintainer to review your PR

  • I have added meaningful tests
  • The focused suites pass locally: cargo test -p litellm-logger and pytest tests/test_litellm/rust_bridge/ tests/test_litellm/test_logging.py tests/test_litellm/test_secret_redaction.py
  • My PR passes all required CI/CD checks
  • My PR's scope is as isolated as possible
  • I have received a current-tip Greptile confidence score of at least 4/5

Screenshots / Proof of Fix

Before (dd32715)

  1. Run uv run python -c "from litellm.rust_bridge.diagnostics import PROCESSOR"
  2. Python prints ModuleNotFoundError: No module named 'litellm.rust_bridge.diagnostics'

After (319f686)

  1. Run a script that builds the processor and filters a record carrying api_key=sk-live-abcdefghijklmnop12345
  2. With no LITELLM_RUST the catalog decides Decision.PYTHON; with LITELLM_RUST=true it decides Decision.RUST_WITH_FALLBACK
  3. The filtered record's message comes back REDACTED, and native.redact_text("key=sk-...") returns key=REDACTED

Type

New Feature

Caveats (if any)

Low

  • Native path is opt-in only: LITELLM_RUST unset keeps Decision.PYTHON
  • Every native call wraps in RUST_WITH_FALLBACK, so a bridge failure silently reverts to Python
  • Sets inside log extras serialize to sorted lists after processing

Validation

cargo test -p litellm-logger passed, including parity cases generated against the Python redactor. pytest tests/test_litellm/rust_bridge/ tests/test_litellm/test_logging.py tests/test_litellm/test_secret_redaction.py passed 1941 tests with one teardown error in test_level_routing_handler_falls_back_to_stderr_when_stdout_is_unusable that reproduces identically on the merge base. cargo check -p litellm-logger is clean. Cargo.lock was regenerated after a rebase conflict against litellm-model-catalog

Final Attestation

  • The tests cover the redaction parity between native and Python paths and the access-log scrubbing contract

Note

Medium Risk
Touches credential redaction and all main log filters; behavior is gated and falls back to Python, but parity bugs could leak secrets or change log shape (e.g. sets in extras sorted to lists).

Overview
Introduces a shared litellm-tracing Rust crate and wires it into Python so log redaction, truncation, and native tracing events can use one diagnostics pipeline when LITELLM_RUST is enabled (catalog LoggerContext, Python fallback on failure).

Rust: Secret redaction moves out of core-utils into litellm-tracing (SecretRedactor, Processor for batch message/exception/stack/extra scrubbing, base64 collapse, access-arg scrubbing). A Logger + Sink layer forwards litellm_* events without a global subscriber. The python-bridge adds NativeDiagnosticProcessor, a PythonSink to litellm.rust_bridge.logger, and logger::run_* / LoggedMachine so cache, routes, HTTP warnings, and secrets crates emit through that sink instead of ad hoc Python warn calls.

Python: DiagnosticProcessingFilter replaces the old split between stdout truncation and inline secret scrubbing via _process_record, delegating to the native processor through rust_bridge.diagnostics.run. secret_redaction and access-log filters use the same path. rust_bridge/logger.py receives native emits with correlation IDs and existing filters.

CI: The Rust test job installs the repo Python env (uv sync) so bridge logger integration tests can import litellm.

Reviewed by Cursor Bugbot for commit 89cc062. Bugbot is set up for automated code reviews on this repo. Configure here.

@devin-ai-integration

devin-ai-integration Bot commented Sep 22, 2026 •

Copy link
Copy Markdown
Contributor Author

I'll fix CI failures and address comments from users with write access. I'll skip comments containing "(aside)".

  • Disable automatic comment, CI, and merge conflict monitoring

yujonglee-berri and others added 2 commits September 22, 2026 23:16
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
@codecov

codecov Bot commented Sep 22, 2026 •

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 67.85714% with 63 lines in your changes missing coverage. Please review.

Files with missing lines Patch % Lines
litellm/_logging.py 67.50% 39 Missing ⚠️
litellm/rust_bridge/logger.py 47.82% 12 Missing ⚠️
litellm/rust_bridge/diagnostics.py 63.33% 11 Missing ⚠️
litellm/litellm_core_utils/secret_redaction.py 92.30% 1 Missing ⚠️

📢 Thoughts on this report? Let us know!

@greptile-apps

greptile-apps Bot commented Sep 22, 2026 •

Copy link
Copy Markdown
Contributor

RetriggerConfidence Score: 5/5

The PR appears safe to merge, with no outstanding correctness or repository-rule violations identified.

Findings

  1. P2 Bridge test silently passes ▶

Summary

This PR introduces a shared Rust diagnostics processor for log redaction and truncation, exposes it through the Python bridge, and routes native tracing events into LiteLLM’s existing Python logging infrastructure.

  • Adds the litellm-tracing crate and native diagnostic processing bindings.
  • Integrates native logging context across bridge execution and route machines.
  • Retains Python processing as the fallback when native processing is unavailable.
  • Updates Rust CI to install Python dependencies so the end-to-end bridge test executes rather than silently skipping.

Reviews (3) · Last reviewed commit: "ci(rust): install python deps so the log..."

yujonglee-berri and others added 2 commits September 22, 2026 23:22
…absent

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
@codspeed

codspeed Bot commented Sep 22, 2026 •

Copy link
Copy Markdown
Contributor

Merging this PR will not alter performance

✅ 31 untouched benchmarks


Comparing litellm_rust_logger (89cc062) with main (b4ccb5b)1

Open in CodSpeed

Footnotes

  1. No successful run was found on main (38f0eb8) during the generation of this report, so b4ccb5b was used instead as the comparison base. There might be some changes unrelated to this pull request in this report. ↩

yujonglee-berri and others added 4 commits September 22, 2026 23:29
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
…ilter

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
@mateo-berri

Copy link
Copy Markdown
Contributor

bugbot run

@cursor cursor Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale Bugbot comment from a previous run.

Comment thread litellm/_logging.py Outdated
…ey pattern

The blanket REDACTED for a changed msg/color template discarded lines
whose rendered form was already redacted by the same pipeline, e.g.
'password=%s' became 'REDACTED' instead of 'password=REDACTED'. Only
fall back to REDACTED when the rendered form did not change either,
which is where interpolation can mangle the key pattern the scrub
would otherwise see.

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
@mateo-berri

Copy link
Copy Markdown
Contributor

bugbot run

@mateo-berri

Copy link
Copy Markdown
Contributor

@greptileai

Comment on lines +184 to +186
if !importable {
eprintln!("SKIP: litellm package dependencies are not importable in this interpreter");
return;

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Bridge test silently passes

When dotenv is unavailable, this test returns successfully. The Rust CI job does not install the Python package dependencies, so its only end-to-end logger bridge test passes without checking event delivery, correlation, level mapping, or handler failures. Please install the dependencies for this test or make their absence fail visibly

Note: If this suggestion doesn't match your team's coding style, reply to this and let me know. I'll remember it for next time!

@cursor cursor Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale Bugbot comment from a previous run.

The end-to-end bridge test skipped silently when litellm's Python deps
were absent. uv sync --no-install-project installs them without a
maturin build, and PYTHONPATH makes them visible to the embedded
interpreter

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
@mateo-berri

Copy link
Copy Markdown
Contributor

bugbot run

@mateo-berri

Copy link
Copy Markdown
Contributor

@greptileai

@cursor cursor Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Bugbot reviewed your changes and found no new issues!

Comment @cursor review or bugbot run to trigger another review on this PR

Reviewed by Cursor Bugbot for commit 89cc062. Configure here.

@yujonglee-berri
yujonglee-berri merged commit b0ac23d into main Sep 23, 2026
98 of 99 checks passed
@yujonglee-berri
yujonglee-berri deleted the litellm_rust_logger branch September 23, 2026 01:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants