fix(api): fail-closed ASCII name charset on tools and json_schema - #687
fix(api): fail-closed ASCII name charset on tools and json_schema#687seonghobae wants to merge 16 commits into
Conversation
…closed otherwise Chat history: message-level audio and legacy function_call are null/empty omit no-ops; non-empty fail closed with named errors (including tools passthrough). Tip substrate from #577 assistant refusal/annotations honesty. Local full unit: 940 passed.
…ed otherwise OpenAI fine-tune style message weight is not applied on this gateway. Accept null/0/1 as honest no-ops; reject other types and values with invalid_message_weight. Tip substrate from #578. Local full unit: 943 passed.
…ion role Reject unsupported message keys with named unknown_message_fields (not silent strip or tools-passthrough smuggle). Reject legacy function role with invalid_message_role migration to tool. Tip substrate from #579. Local full unit: 947 passed.
OpenAI partial-assistant prefix flag is not applied on this gateway. null/false are honest no-ops; true and non-booleans fail closed with invalid_message_prefix. Tip substrate from #580. Local full unit: 950 passed.
…therwise Named invalid_max_tool_calls on /v1/chat/completions instead of opaque unknown_fields. Aligns with Responses max_tool_calls honesty; gateway has no multi-step tool loop.
…losed otherwise Legacy /v1/completions treated max_tool_calls as unknown_fields. Accept the key for named invalid_max_tool_calls (null/empty/whitespace omit-equivalent), matching chat/Responses honesty so SDKs get a clear migration path.
SDK clients often send include_usage/include_obfuscation as JSON null. Drop null flag values before validation so null (and null+false mixes) match omit / all-false no-ops on chat, Completions, and Responses. True flags remain fail-closed with invalid_stream_options.
…or Responses parallel true SDK optional defaults often send function.strict and json_schema.strict as null — treat as omit rather than type errors. Align Responses parallel_tool_calls=true with chat by requiring a non-empty tools array.
SDK optional defaults often send description and parameters as JSON null. Treat null as omit rather than type errors; non-null non-string/object values remain fail-closed with invalid_tools.
OpenAI-style tool descriptions are at most 1024 characters. Over-long descriptions fail closed with named invalid_tools so SDKs never believe a truncated description was accepted.
SDK optional participant name blanks ("" / whitespace) are omit-equivalent
like JSON null. Non-string, over-long, and invalid charset names remain
fail-closed with invalid_message_name.
SDK optional defaults serialize omitted tool.function description/parameters/strict as JSON null. Accepting those keys without popping them is not omit-equivalent: proxy_completion forwards the body and several providers reject null parameters. Pop in place so passthrough matches omit; keep non-null wrong types on invalid_tools. Also pop response_format.json_schema.strict null. Tip substrate from #614. Local full unit: 989 passed.
Null flag values on allowed keys (include_usage / include_obfuscation) stay
omit-equivalent. Dropping nulls before the allow-list made {unknown: null}
look empty and silently omit — dishonest for buyers. Fail closed with
invalid_stream_options on chat, Completions, and Responses. Tip substrate
from #638. Local full unit: 996 passed.
…ix/mode/metadata) Parallel tip #653 lacked later omit seams. Restore top_logprobs empty-string omit, tool_calls arguments null→empty string, Responses instructions blank omit, Completions whitespace suffix omit, mode strip, and metadata null value key-omit. Fail-closed paths for nonzero/non-string remain.
#668 restored accept-path 200s but left omit-equivalent keys on the proxied body. Write back empty tool_calls arguments, pop blank Responses instructions, persist cleaned metadata, and hoist chat logprobs/top_logprobs before tools passthrough so providers see the omit-equivalent payload. Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>
str.isalnum() accepted Unicode letters and digits (café, 名前,
Arabic-Indic digits), so the documented [a-zA-Z0-9_-]{1,64} check still
forwarded illegal names and buyers saw an opaque provider 400.
Require name.isascii() on tool.function.name, tool_calls function.name,
message name, and response_format.json_schema.name (plus 64-char cap on
json_schema.name). HTTP honesty locks Unicode reject and legal keep on
chat and Responses. Request-body fuzz exercises both validators.
Re-lands parallel tip #685/#669 seams onto the highest #686 substrate.
|
Bugbot is not enabled for your account, so this pull request was not reviewed. Enable Bugbot in the Cursor dashboard to get automatic reviews on future PRs. |
|
Important Review skippedToo many files! This PR contains 151 files, which is 51 over the limit of 100. To get a review, reduce the PR to 100 files or fewer by splitting it into smaller PRs or changing its base branch. Upgrade to a paid plan to raise the limit. This review couldn't start because sufficient usage credits or metered capacity aren't available. Add credits or update usage-based reviews in the billing tab, then retry. ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Plus Run ID: 📒 Files selected for processing (151)
You can disable this status message by setting the Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Pull request was closed
Summary
Re-lands parallel tip #685 / #669 ASCII name charset fail-closed onto the highest tip substrate #686 (≥ #668 floor).
str.isalnum()accepted Unicode letters and digits (café,名前, Arabic-Indic digits), so the documented[a-zA-Z0-9_-]{1,64}check still forwarded illegal names and buyers saw an opaque provider 400.Changes
tools[].function.namerequiresname.isascii()before alnum/_/-response_format.json_schema.namegets 64-char cap + same ASCII charsetnameandtool_calls[].function.namePrefer this tip over merging the 145-file honesty stack onto
main. Land the unique charset slice after an independent non-author APPROVE.Test plan
python3 tests/test_tool_function_name_charset_http_honesty.pypython3 tests/test_json_schema_name_charset_http_honesty.pypython3 tests/test_tip_reland_sdk_omit_persist_http_honesty.pyBuyer next action
Send Unicode or punctuated
tools[].function.name/json_schema.name. Expect namedinvalid_tools/invalid_response_format(not a provider 400). Legal ASCII names up to 64 chars are kept on mockecho.