Repository navigation
fix(guardrails): treat an unknown straiker api_version as unset instead of skipping the guardrail - #43956
Conversation
…ad of skipping the guardrail Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
…ker api_version test Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
|
I'll fix CI failures and address comments from users with write access. I'll skip comments containing "(aside)".
|
|
bugbot run |
|
@greptileai review |
|
…te from the shared block marker Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
|
@greptileai review |
|
bugbot run |
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
There was a problem hiding this comment.
🔍 Devin Review: 1 flag
Not posted on this PR by your GitHub settings — view it in Devin Review. (Configure)
… integration tests Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
|
@greptileai review |
|
bugbot run |
|
@greptileai review latest head |
|
bugbot run |
There was a problem hiding this comment.
✅ Bugbot reviewed your changes and found no new issues!
Comment @cursor review or bugbot run to trigger another review on this PR
Reviewed by Cursor Bugbot for commit 0c27ce3. Configure here.
…ject_key_prefix * upstream/main: (62 commits) fix(guardrails): scan Responses API input in Azure Prompt Shield (BerriAI#43786) feat(lens): investigate sampled traces and retain batch results (BerriAI#43942) fix(proxy): restore pre-config-wins handling of pass-through endpoints (BerriAI#43962) fix(cost-map): raise baseten DeepSeek-V4.1-Flash max output to 262144 (BerriAI#43916) chore(cost-map): add deprecation date for anthropic claude-sonnet-4-5 (BerriAI#43898) chore(cost-map): add fireworks inkling priority prices from the prices api (BerriAI#43949) feat(guardrails): honor litellm_params.timeout in every HTTP guardrail (BerriAI#43134) test(e2e): typed per-test metadata for the e2e suite (BerriAI#42044) fix(caching): write the response-cache SET to Redis at once instead of on the post-call batch (BerriAI#43973) feat(ui): filter tags by name and description on the Tag Management page (BerriAI#42949) feat(providers): add Cortecs as an OpenAI-compatible provider (BerriAI#43872) feat(e2e): record each e2e test's steps, starting with ProxyClient (BerriAI#42393) test(ci): repair stale tests and move retired OpenAI text-completion fixtures (BerriAI#43958) feat(proxy): record in spend logs whether a request used a client-forwarded Anthropic OAuth token (BerriAI#43063) fix(azure_storage): keep the DataLakeServiceClient alive until its TTL elapses (BerriAI#43082) chore(deps): bump gitpython and tornado, extend diskcache osv ignore to Nov 1 (BerriAI#43961) fix(guardrails): treat an unknown straiker api_version as unset instead of skipping the guardrail (BerriAI#43956) fix(azure_storage): name Data Lake objects without base64 padding or slashes (BerriAI#43914) fix(grayswan): send request conversation and tool calls to post-call monitor (BerriAI#43770) chore(cost-map): sync openrouter prices from the models API (BerriAI#43950) ...
TLDR
Problem this solves:
api_versionis silently dropped at startupHow it solves it:
api_versionfrom config now logs a warning and counts as unsetsk_agt_keys go to v3, others to v1v1,v3and unset behave exactly as beforeUser Flow
Before: an admin whose Straiker config carries a leftover
api_version(for example"2024-09-01"copied from an Azure Content Safety block, or"") loses the guardrail without noticingapi_version: "2024-09-01"Skipping guardrail 'straiker': invalid configuration, proxy is starting WITHOUT this guardrailand the proxy comes up healthy"guardrails": ["straiker"]After: the same config keeps the guardrail on and the injection is blocked
api_version: "2024-09-01"api_versionis ignored and the route follows the key prefixAffected release
Regression since v1.104.0-dev.2 (#41880). Before that, Straiker never read
api_version, so a stray value was ignored. This also has to be re-picked onto the 1.101.x backport in #43943Pre-Submission checklist
Screenshots / Proof of Fix
The integration suite drives a real two-worker proxy with Postgres and Redis and an owned Straiker double, with two new guardrails: a v3 key with
api_version: "2024-09-01"and a v1 key withapi_version: ""Before (f553c80)
uv run pytest tests/integration/observability/test_straiker_v3_platform.py -k "stray_api_version or empty_api_version"assert 0 == 1on the detect-call count: the request returned 200 and Straiker was never called, because the guardrail was skipped at startupAfter (0c27ce3)
Type
🐛 Bug Fix
✅ Test
Caveats (if any)
Low
"V1"with ansk_agt_key now routes to v3 instead of failingStraikerGuardraildirectly in Python still rejects unknown values, only config input is lenientFinal Attestation
REVIEWER MUST KNOW BEFORE APPROVING
api_versionis anything other thanv1,v3or unset (for example"2024-09-01","","v2","V1")sk_agt_keys go to v3, other keys to v1)Link to Devin session: https://app.devin.ai/sessions/f91d93cb912644a58dcd961679a6d517
Open in Devin Desktop: https://app.devin.ai/desktop/session/f91d93cb912644a58dcd961679a6d517?variant=devin
Requested by: @yucheng-berri
Note
Medium Risk
Changes guardrail startup and API routing for misconfigured Straiker entries; mis-typed versions now follow key prefix instead of failing closed at boot, which restores protection but could surprise admins expecting a hard config error.
Overview
Fixes a regression where Straiker guardrails with a non-
v1/v3api_version(e.g."2024-09-01"or"") failed config validation at startup and were skipped entirely, so traffic never hit Straiker._V3Routingnow normalizes unknownapi_versionvalues to unset via a Pydanticfield_validator, logs averbose_proxy_loggerwarning, and leaves explicitv1/v3unchanged. Withapi_versionunset, routing still follows the API key prefix (sk_agt_→ v3, otherwise v1).Integration and unit tests cover stray/empty versions, warning behavior, and
init_guardrails_v2registration so enforcement and block paths still run on the correct detect endpoint.Reviewed by Cursor Bugbot for commit 0c27ce3. Bugbot is set up for automated code reviews on this repo. Configure here.