Repository navigation
feat(routing): add exclusive managed session connection leases - #10362
diegosouzapw merged 4 commits into
Conversation
|
Thanks for this — it's a substantial, well-designed feature. The DB-level design (SQLite partial unique indexes for atomic global ownership fencing) is a solid approach to the "hard exclusive ownership" gap you identified relative to session affinity and OAuth occupancy, and the auth/scope gating, error sanitization, and test coverage are all in good shape. I ran Two things need fixing before this can merge, both stemming from the branch being a bit stale against
Optional/non-blocking: the outer catch in Once the migration number and rebase are sorted, this looks ready to go. |
…ate docs Resolves migration-number collision (153 taken by 153_radar_local_model_state.sql): renumber src/lib/db/migrations/153_exclusive_connection_leases.sql -> 154 and update the hardcoded 153 path/assertion in tests/unit/exclusive-connection-leases.test.ts. Merges current release/v3.8.50 tip and regenerates auto-generated doc/count files (AGENTS.md, README.md, llm.txt, docs/i18n/*/llm.txt, docs/reference/API_REFERENCE.md) so migration/tool/scope counts reflect the live tree. Co-authored-by: diegosouzapw <8016841+diegosouzapw@users.noreply.github.com>
|
Thanks for the review and for pushing the sync commit. I confirmed that the two blocking items are resolved:
I also updated the PR description to reflect migration I’ll keep the optional route logging and dashboard UI items as follow-up work so this PR stays focused on the generic lease core. Marking this ready for review. Thanks again. |
…sive-managed-session-leases Resolves conflicts against the release tip: renumbers the new 154_exclusive_connection_leases migration to 155 (collided with 154_call_logs_response_id from release), merges the api_keys insert statement to set both allowed_combos and allowed_connections, routes the chat dispatch through dispatchChatWithAffinityEviction while keeping managedLease plumbed through, and keeps both planSessionAffinityConnection and evictSessionAffinityOnComboTimeout in sessionAffinityPin.ts (independent additive functions). Regenerates the docs/i18n llm.txt mirrors from the merged root llm.txt via scripts/i18n/sync-llm-mirrors.mjs. Co-authored-by: diegosouzapw <8016841+diegosouzapw@users.noreply.github.com>
…sive-managed-session-leases # Conflicts: # src/lib/usage/providerLimits.ts # src/sse/handlers/chat.ts # src/sse/services/auth.ts
8acd799
into
diegosouzapw:release/v3.8.50
Two independently-merged PRs (#10263 agentic-conversation-tracking-v4 and #10362 exclusive-managed-session-leases) each picked migration slot 155 against different base states, landing a real collision on release/v3.8.50 (155_agentic_conversations.sql vs 155_exclusive_connection_leases.sql; #10263 also claimed 156 via 156_conversation_turn_nodes.sql). Renumbered #10362's migration to the next free slot (157) and updated its own regression test (exclusive-connection-leases.test.ts) that asserted the literal filename/slot. No retroactive guard needed: CREATE TABLE IF NOT EXISTS is idempotent under either number. Confirmed via check-migration-numbering.mjs (154 migrations, 0 duplicates) and the full exclusive-connection-leases test suite (11/11 pass).
…souzapw#10362) Co-authored-by: diegosouzapw <8016841+diegosouzapw@users.noreply.github.com>
Two independently-merged PRs (diegosouzapw#10263 agentic-conversation-tracking-v4 and diegosouzapw#10362 exclusive-managed-session-leases) each picked migration slot 155 against different base states, landing a real collision on release/v3.8.50 (155_agentic_conversations.sql vs 155_exclusive_connection_leases.sql; diegosouzapw#10263 also claimed 156 via 156_conversation_turn_nodes.sql). Renumbered diegosouzapw#10362's migration to the next free slot (157) and updated its own regression test (exclusive-connection-leases.test.ts) that asserted the literal filename/slot. No retroactive guard needed: CREATE TABLE IF NOT EXISTS is idempotent under either number. Confirmed via check-migration-numbering.mjs (154 migrations, 0 duplicates) and the full exclusive-connection-leases test suite (11/11 pass).
…souzapw#10362) Co-authored-by: diegosouzapw <8016841+diegosouzapw@users.noreply.github.com>
Two independently-merged PRs (diegosouzapw#10263 agentic-conversation-tracking-v4 and diegosouzapw#10362 exclusive-managed-session-leases) each picked migration slot 155 against different base states, landing a real collision on release/v3.8.50 (155_agentic_conversations.sql vs 155_exclusive_connection_leases.sql; diegosouzapw#10263 also claimed 156 via 156_conversation_turn_nodes.sql). Renumbered diegosouzapw#10362's migration to the next free slot (157) and updated its own regression test (exclusive-connection-leases.test.ts) that asserted the literal filename/slot. No retroactive guard needed: CREATE TABLE IF NOT EXISTS is idempotent under either number. Confirmed via check-migration-numbering.mjs (154 migrations, 0 duplicates) and the full exclusive-connection-leases test suite (11/11 pass).
Reuse the official managed lease authority for dashboard observability. Keep every active hard lease visible across idle/tool/build gaps, decorate it ACTIVE only while the bound connection has in-flight work, and preserve legacy session-fingerprint rows for unmanaged traffic. No lease/routing semantics, schema, quota, or client integration changes. Dashboard payloads intentionally exclude owner hashes, API-key ids, and fencing generations. Follow-up to diegosouzapw#10362; related to diegosouzapw#10514.
Summary Complete the dashboard/observability side of the exclusive managed session lease feature merged in diegosouzapw#10362. The existing Usage -> Active Sessions view now treats durable exclusive leases as first-class managed sessions: - every currently held exclusive lease remains visible while the client is idle, using tools, or doing local build work; - a leased session is decorated ACTIVE only while its bound connection has one or more in-flight requests; - an open lease with zero in-flight requests remains visible as IDLE; - releasing or expiring the lease removes it from the durable-session view; - legacy/unmanaged request-fingerprint sessions remain available, while a fingerprint row on a currently leased connection is de-duplicated in the UI so one managed client is not rendered twice. The lease table remains the lifecycle authority. Existing pending-request accounting is used only as an activity signal; it never creates, renews, releases, or extends a lease. Duplicate / prior-art check Before preparing this change, the public OmniRoute issues and PR history were searched for combinations of: exclusive lease, exclusive managed session, session leases, lease occupancy, SessionsTab, active sessions, dashboard, UI, and observability. The core request diegosouzapw#10514 and merged implementation diegosouzapw#10362 were found, but no public issue or PR requesting or implementing this dashboard binding. diegosouzapw#10362 explicitly states: "There is no dashboard or UI scope." This is therefore a follow-up to the merged core, not a second lease implementation. If maintainers have an internal/private backlog item for the same UI gap, it can be linked and this PR can be reconciled to that scope. Architecture Reuse existing OmniRoute authorities only: 1. getExclusiveLeaseConnectionIds() derives the managed candidate set from active API-key policy. 2. getExclusiveLeaseOccupancy() reads current durable lease occupancy from the official SQLite lease authority. 3. getPendingRequests().byAccount provides the existing in-flight request count per connection. 4. /api/sessions returns exclusiveCount and exclusiveSessions additively while preserving count, sessions, and byApiKey. 5. SessionsTab renders exclusive rows first and suppresses an older fingerprint row only when it refers to the same currently leased connection. No raw lease SQL is added to the route. No new store, table, cache, daemon, router, or account pool is introduced. ACTIVE vs IDLE ACTIVE means the durable lease exists and the bound connection currently has in-flight work. IDLE means the durable lease still exists, but no request is in flight right now. Request activity may come and go while exclusive ownership remains held for the client lifecycle. Privacy / fencing hygiene The dashboard projection intentionally does not expose lease_owner_hash, API-key IDs, lease generations, credentials, or tokens. It exposes only the connection binding, display activity state, recent request telemetry, and lease expiry. Scope In scope: - additive exclusive-session observability in /api/sessions; - ACTIVE/IDLE rendering in the existing Sessions UI; - de-duplication of legacy fingerprint rows on leased connections; - focused zero-model regression coverage. Out of scope: - lease acquisition/renew/release semantics; - routing, retry/fallback, health/cooldown, quota, or affinity behavior; - database schema or migrations; - API-key policy semantics; - client/launcher-specific integration; - provider-topology semantics. Validation Focused Node tests cover idle lease visibility, ACTIVE decoration from in-flight work, privacy of owner/fencing material, reuse of existing lease/pending authorities without raw lease SQL, and UI de-duplication. EXTERNAL_PROVIDER_MODEL_CALLS=0 by design. Broad build/unit validation is intentionally left to PR CI for the draft. Related: follow-up to diegosouzapw#10362; background diegosouzapw#10514.
Complete the dashboard observability follow-up for Exclusive Managed Session Leasing from diegosouzapw#10362 without changing lease or routing semantics. Behavior: - every currently valid exclusive lease remains visible in the existing Sessions view across idle, tool, and build gaps; - a leased connection with in-flight work receives the existing localized Active label; - an idle lease remains visible but is not mislabeled inactive; - release or TTL expiry removes the durable lease row through the official lease authority; - legacy/unmanaged session-fingerprint rows remain visible, with duplicate rows suppressed when the same connection is currently leased. Upstream alignment: - diegosouzapw#10362 deliberately excluded dashboard/UI scope; - the maintainer review on diegosouzapw#10362 explicitly identified dashboard UI as a useful follow-up; - public issue/PR searches found no separate implementation of this Sessions/lease integration. Architecture: - reuse getExclusiveLeaseConnectionIds() for the managed candidate set; - reuse getExclusiveLeaseOccupancy() as the durable lease authority; - reuse existing pending-request accounting only to decorate a valid lease as active; - extend the existing /api/sessions response and SessionsTab rather than adding a new store, route family, router, pool, daemon, or migration; - never expose lease owner hashes, API-key IDs, generations, credentials, or tokens. UI/i18n: - use the existing common.active translation instead of hardcoded status text; - keep idle lease rows present without inventing a new untranslated IDLE label across the 43-locale UI surface. Validation included: - pure projection tests for ACTIVE versus idle visibility; - real SQLite lease acquire/occupancy/release lifecycle coverage with zero model calls; - privacy/fencing-material assertions; - a jsdom rendering regression proving idle rows remain visible, duplicate legacy rows are removed, and only in-flight leases receive the localized Active badge; - a changelog fragment for PR diegosouzapw#11389. EXTERNAL_PROVIDER_MODEL_CALLS=0 by design. Refs diegosouzapw#10514 Follow-up to diegosouzapw#10362
Reuse the official exclusive-lease authority for durable idle visibility, and use pending-request accounting only for the localized active indication. Preserve legacy session fields and rows while de-duplicating leased connections and withholding lease ownership and fencing data. Refs diegosouzapw#10514 Follow-up to diegosouzapw#10362
…11389) Merged into release/v3.8.51 via batch validation: exclusive-session-observability unit+UI suites green on the combined tree, static gates green. Nice additive observability layer over the #10362 lease backend — thanks @KaspaPulse!
…souzapw#10362) Co-authored-by: diegosouzapw <8016841+diegosouzapw@users.noreply.github.com>
Two independently-merged PRs (diegosouzapw#10263 agentic-conversation-tracking-v4 and diegosouzapw#10362 exclusive-managed-session-leases) each picked migration slot 155 against different base states, landing a real collision on release/v3.8.50 (155_agentic_conversations.sql vs 155_exclusive_connection_leases.sql; diegosouzapw#10263 also claimed 156 via 156_conversation_turn_nodes.sql). Renumbered diegosouzapw#10362's migration to the next free slot (157) and updated its own regression test (exclusive-connection-leases.test.ts) that asserted the literal filename/slot. No retroactive guard needed: CREATE TABLE IF NOT EXISTS is idempotent under either number. Confirmed via check-migration-numbering.mjs (154 migrations, 0 duplicates) and the full exclusive-connection-leases test suite (11/11 pass).
…iegosouzapw#11389) Merged into release/v3.8.51 via batch validation: exclusive-session-observability unit+UI suites green on the combined tree, static gates green. Nice additive observability layer over the diegosouzapw#10362 lease backend — thanks @KaspaPulse!
Summary
lease:exclusiveand anexplicit non-empty
allowedConnections.connection for its lease lifecycle using SQLite-backed atomic ownership and exact generation
fencing.
allowedConnections, quota/health/cooldown logic,routing strategy, retry/fallback, and session affinity.
429 LEASE_CAPACITY_UNAVAILABLEwithWAITING_FOR_CAPACITYandRetry-Afteronlywhen ordinary eligible candidates exist but every one is occupied by a foreign active lease.
integration is included.
Why
Session affinity provides soft locality and continuity, but not exclusive lifetime ownership.
OAuth occupancy and the account semaphore address different request- or process-local concerns.
Long-lived managed clients sometimes need hard one-session/one-connection ownership across idle,
tool, and build periods. This change adds that opt-in authority without creating a second router
or account pool.
Contract
lease:exclusivescope and an explicit non-emptyallowedConnectionslist.POST /api/v1/session-leasesprovides the acquire, renew, and release lifecycle endpoint.X-OmniRoute-Lease-OwnerandX-OmniRoute-Lease-Generation.ID.
ACTIVEuniqueness applies to both owner and connection.429 LEASE_CAPACITY_UNAVAILABLE,WAITING_FOR_CAPACITY, andRetry-Afterindicate thatordinary eligible candidates exist but all are occupied by foreign active leases.
Related Work
Architecture precedents include #7650 for generic session affinity across providers, #8940 for
active OAuth-session occupancy and account availability, and #10149 for account-scoped
concurrency. This PR is a distinct opt-in hard lifecycle-ownership primitive.
Validation
typecheck:core: PASS.PASS.
EXTERNAL_PROVIDER_MODEL_CALLS=0.Contribution Golden Path.
The current-upstream
typecheck:noimplicit:corefindings remain only in unchangedopen-sse/utils/usageTracking.tsandsrc/shared/services/cliRuntime.ts; no feature file isimplicated.
Tests Added Or Updated
tests/unit/api-key-scope-validation.test.tstests/unit/chat-managed-lease-routing.test.tstests/unit/chatcore-executor-client-headers.test.tstests/unit/chatcore-translation-paths.test.tstests/unit/codex-ws-policy-enforcement-6564.test.tstests/unit/cors/origins.test.tstests/unit/exclusive-connection-leases.test.tstests/unit/exclusive-lease-api-key-policy.test.tstests/unit/exclusive-lease-auxiliary-isolation.test.tstests/unit/exclusive-lease-connection-test-isolation.test.tstests/unit/exclusive-lease-managed-set.test.tstests/unit/hard-session-lease-bypass-inventory.test.tstests/unit/hard-session-lease-zero-model-gates.test.tstests/unit/lease-context.test.tstests/unit/pick-internal-api-key-6372.test.tstests/unit/quota-auto-ping.test.tstests/unit/request-logger-endpoints.test.tstests/unit/session-leases-route.test.tstests/unit/sse-auth-exclusive-leases.test.tstests/unit/warmupScheduler.test.tsCoverage Notes
The focused tests cover DB and migration lease authority; the API-key policy mutation invariant;
acquire, renew, and release; exact generation fencing and cross-key replay prevention; routing,
foreign-top skip, and next-free selection; capacity waiting with zero dispatch; client, provider,
and model neutrality; CORS and privacy; and auxiliary/bypass inventory. PR CI supplies broad
coverage.
Reviewer Notes
154_exclusive_connection_leases.sqlmigration; its number wascollision-free at publication preflight.