Skip to content

fix: set ConnectionClosed flag before closing stream on cancellation - #3733

Merged
akshaydeo merged 1 commit into
devfrom
05-25-fix_set_connectionclosed_flag_before_closing_stream_on_cancellation
May 25, 2026
Merged

fix: set ConnectionClosed flag before closing stream on cancellation#3733
akshaydeo merged 1 commit into
devfrom
05-25-fix_set_connectionclosed_flag_before_closing_stream_on_cancellation

Conversation

@TejasGhatte

@TejasGhatte TejasGhatte commented May 25, 2026

Copy link
Copy Markdown
Collaborator

Summary

Fixes a race condition in SetupStreamCancellation where BifrostContextKeyConnectionClosed was set after calling Close() on the body stream. Because Close() immediately unblocks any in-progress Read (which may panic due to a force-closed connection), the recover block in idleTimeoutReader.Read could run before the flag was set — causing it to re-panic instead of returning ErrStreamClosed.

Additionally, idleTimeoutReader.Read was returning (0, nil) when the connection was already marked closed, which is incorrect. It now returns the appropriate closed-stream error via closedReadError().

Changes

  • SetupStreamCancellation now sets BifrostContextKeyConnectionClosed before calling Close() or CloseWithError() in all four call sites, eliminating the race window where a panicking Read could recover before the flag was visible.
  • idleTimeoutReader.Read now returns r.closedReadError() instead of (0, nil) when the connection is already closed, ensuring callers receive a meaningful error rather than a silent empty read.
  • Added syncedPanicBody, a deterministic test helper that reproduces the exact race: Close() triggers a panic in Read and then blocks, holding SetupStreamCancellation inside Close() so the flag is guaranteed to be unset when the recover block runs under the unfixed code.
  • Added TestSetupStreamCancellation_NoPanicOnCancelledContext which fails against the unfixed code and passes after the fix.

Type of change

  • Bug fix

Affected areas

  • Core (Go)
  • Transports (HTTP)

How to test

go test ./core/providers/utils/... -race -count=1 -run TestSetupStreamCancellation_NoPanicOnCancelledContext
go test ./core/providers/utils/... -race -count=1

The new test should pass without any detected data races or re-panics.

Breaking changes

  • No

Security considerations

None. This is a stability fix for stream teardown on context cancellation.

Checklist

  • I read docs/contributing/README.md and followed the guidelines
  • I added/updated tests where appropriate
  • I updated documentation where needed
  • I verified builds succeed (Go and UI)
  • I verified the CI pipeline passes locally if applicable

@coderabbitai

coderabbitai Bot commented May 25, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

📝 Walkthrough

Summary by CodeRabbit

  • Bug Fixes

    • Resolved potential panic when cancelling in-flight stream operations during context cancellation
    • Improved error handling for reads on closed streams to properly return error responses
  • Tests

    • Added regression test for context cancellation behavior with active stream operations

Walkthrough

This PR prevents panic during context cancellation in stream handling by establishing flag-before-close ordering: SetupStreamCancellation now sets BifrostContextKeyConnectionClosed before closing the upstream stream in both cancellation paths, and idleTimeoutReader.Read returns a proper closed error instead of nil. A deterministic regression test validates the fix.

Changes

Stream Cancellation Safety

Layer / File(s) Summary
Flag-before-close in stream cancellation and error handling
core/providers/utils/utils.go
SetupStreamCancellation sets BifrostContextKeyConnectionClosed to true before closing the stream in both the ctx.Done() branch and the case <-done branch when context is cancelled. idleTimeoutReader.Read now returns closedReadError() instead of nil when the stream is already marked closed, ensuring callers observe the proper closed state.
Regression test with synchronization helper
core/providers/utils/idle_timeout_reader_test.go
syncedPanicBody provides a deterministic io.ReadCloser that blocks in Read until Close() is called, then panics. TestSetupStreamCancellation_NoPanicOnCancelledContext cancels the context during in-flight reads and verifies that reads do not panic and return ErrStreamClosed instead.

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

Possibly related PRs

  • maximhq/bifrost#3677: Both PRs modify core/providers/utils/utils.go around the idleTimeoutReader closed-read and no-panic behavior with test coverage.
  • maximhq/bifrost#3582: Both PRs adjust stream-cancellation behavior by checking/setting schemas.BifrostContextKeyConnectionClosed before close handling to prevent bad cleanup and panics.
  • maximhq/bifrost#3495: Both PRs modify SetupStreamCancellation and idleTimeoutReader close behavior in the stream-timeout/cancellation path.

Suggested reviewers

  • danpiths
  • akshaydeo

Poem

🐰 When contexts cancel in the streaming night,
A flag set first prevents the panic fright,
No double-close, no re-entrant despair—
Just tidy errors floating through the air!

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 50.00% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly and concisely describes the main fix: setting the ConnectionClosed flag before closing the stream during cancellation.
Description check ✅ Passed The PR description is comprehensive and well-structured, covering summary, changes, type, affected areas, testing instructions, and security considerations.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch 05-25-fix_set_connectionclosed_flag_before_closing_stream_on_cancellation

Warning

There were issues while running some tools. Please review the errors and either fix the tool's configuration or disable the tool if it's a critical failure.

🔧 golangci-lint (2.12.2)

level=error msg="[linters_context] typechecking error: pattern ./...: directory prefix . does not contain main module or its selected dependencies"


Comment @coderabbitai help to get the list of available commands and usage tips.

@CLAassistant

Copy link
Copy Markdown

CLA assistant check
Thank you for your submission! We really appreciate it. Like many open source projects, we ask that you sign our Contributor License Agreement before we can accept your contribution.


tejas ghatte seems not to be a GitHub user. You need a GitHub account to be able to sign the CLA. If you have already a GitHub account, please add the email address used for this commit to your account.
You have signed the CLA already but the status is still pending? Let us recheck it.

TejasGhatte commented May 25, 2026

Copy link
Copy Markdown
Collaborator Author

This stack of pull requests is managed by Graphite. Learn more about stacking.

@TejasGhatte
TejasGhatte marked this pull request as ready for review May 25, 2026 12:24
@coderabbitai
coderabbitai Bot requested review from akshaydeo and danpiths May 25, 2026 12:25
@greptile-apps

greptile-apps Bot commented May 25, 2026

Copy link
Copy Markdown
Contributor

Confidence Score: 5/5

Safe to merge — the changes are narrow, well-tested, and address a real stream teardown crash with no API surface changes.

Both changes are targeted: reordering two lines to fix a flag-visibility race, and replacing a silent (0, nil) return with a proper error. The new test deterministically reproduces the race condition and the defer ordering in the test is correct. No existing callers are broken since ErrStreamClosed/ErrStreamIdleTimeout were already the established error values for this path.

No files require special attention.

Important Files Changed

Filename Overview
core/providers/utils/utils.go Fixes the race in SetupStreamCancellation (flag now set before Close/CloseWithError in all 4 sites) and fixes idleTimeoutReader.Read returning (0, nil) when connection is already closed — both are targeted, correct changes.
core/providers/utils/idle_timeout_reader_test.go Adds syncedPanicBody (deterministic race reproducer) and TestSetupStreamCancellation_NoPanicOnCancelledContext; defer ordering and channel synchronization are correct and the test will reliably fail against the old code.

Reviews (1): Last reviewed commit: "fix: set ConnectionClosed flag before cl..." | Re-trigger Greptile

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🧹 Nitpick comments (1)
core/providers/utils/idle_timeout_reader_test.go (1)

426-488: ⚡ Quick win

Add a companion regression for the done + cancelled-context path.

This test only drives the <-ctx.Done() branch. The PR also changes the <-done branch in SetupStreamCancellation, and that ordering bug is subtle enough that it’s worth pinning with a second test as well.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@core/providers/utils/idle_timeout_reader_test.go` around lines 426 - 488, Add
a second regression test mirroring
TestSetupStreamCancellation_NoPanicOnCancelledContext but exercising the
"<-done" branch: create a test (e.g.,
TestSetupStreamCancellation_NoPanicOnDoneClose) that uses NewIdleTimeoutReader,
SetupStreamCancellation and the same synced panic body, spawn a Read() goroutine
that recovers and reports panics/errors, then trigger the done path by closing
the body's done channel (instead of cancelling the context) and assert that Read
does not re-panic and returns ErrStreamClosed; reference the same helper symbols
(NewIdleTimeoutReader, SetupStreamCancellation, the synced panic body fields
like allowReturn/done) so the subtle ordering bug for the done-branch is pinned.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Nitpick comments:
In `@core/providers/utils/idle_timeout_reader_test.go`:
- Around line 426-488: Add a second regression test mirroring
TestSetupStreamCancellation_NoPanicOnCancelledContext but exercising the
"<-done" branch: create a test (e.g.,
TestSetupStreamCancellation_NoPanicOnDoneClose) that uses NewIdleTimeoutReader,
SetupStreamCancellation and the same synced panic body, spawn a Read() goroutine
that recovers and reports panics/errors, then trigger the done path by closing
the body's done channel (instead of cancelling the context) and assert that Read
does not re-panic and returns ErrStreamClosed; reference the same helper symbols
(NewIdleTimeoutReader, SetupStreamCancellation, the synced panic body fields
like allowReturn/done) so the subtle ordering bug for the done-branch is pinned.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: caf8c37c-252c-4a13-8f8d-6e8638b04738

📥 Commits

Reviewing files that changed from the base of the PR and between 584816b and 282430b.

📒 Files selected for processing (2)
  • core/providers/utils/idle_timeout_reader_test.go
  • core/providers/utils/utils.go

akshaydeo commented May 25, 2026

Copy link
Copy Markdown
Contributor

Merge activity

  • May 25, 4:28 PM UTC: A user started a stack merge that includes this pull request via Graphite.
  • May 25, 4:29 PM UTC: @akshaydeo merged this pull request with Graphite.

@akshaydeo
akshaydeo merged commit 1912d14 into dev May 25, 2026
14 of 15 checks passed
@akshaydeo
akshaydeo deleted the 05-25-fix_set_connectionclosed_flag_before_closing_stream_on_cancellation branch May 25, 2026 16:29
akshaydeo pushed a commit that referenced this pull request May 26, 2026
…3733)

## Summary

Fixes a race condition in `SetupStreamCancellation` where `BifrostContextKeyConnectionClosed` was set *after* calling `Close()` on the body stream. Because `Close()` immediately unblocks any in-progress `Read` (which may panic due to a force-closed connection), the recover block in `idleTimeoutReader.Read` could run before the flag was set — causing it to re-panic instead of returning `ErrStreamClosed`.

Additionally, `idleTimeoutReader.Read` was returning `(0, nil)` when the connection was already marked closed, which is incorrect. It now returns the appropriate closed-stream error via `closedReadError()`.

## Changes

- `SetupStreamCancellation` now sets `BifrostContextKeyConnectionClosed` **before** calling `Close()` or `CloseWithError()` in all four call sites, eliminating the race window where a panicking `Read` could recover before the flag was visible.
- `idleTimeoutReader.Read` now returns `r.closedReadError()` instead of `(0, nil)` when the connection is already closed, ensuring callers receive a meaningful error rather than a silent empty read.
- Added `syncedPanicBody`, a deterministic test helper that reproduces the exact race: `Close()` triggers a panic in `Read` and then blocks, holding `SetupStreamCancellation` inside `Close()` so the flag is guaranteed to be unset when the recover block runs under the unfixed code.
- Added `TestSetupStreamCancellation_NoPanicOnCancelledContext` which fails against the unfixed code and passes after the fix.

## Type of change

- [x] Bug fix

## Affected areas

- [x] Core (Go)
- [x] Transports (HTTP)

## How to test

```sh
go test ./core/providers/utils/... -race -count=1 -run TestSetupStreamCancellation_NoPanicOnCancelledContext
go test ./core/providers/utils/... -race -count=1
```

The new test should pass without any detected data races or re-panics.

## Breaking changes

- [x] No

## Security considerations

None. This is a stability fix for stream teardown on context cancellation.

## Checklist

- [ ] I read `docs/contributing/README.md` and followed the guidelines
- [x] I added/updated tests where appropriate
- [ ] I updated documentation where needed
- [x] I verified builds succeed (Go and UI)
- [ ] I verified the CI pipeline passes locally if applicable
@akshaydeo akshaydeo mentioned this pull request May 26, 2026
akshaydeo added a commit that referenced this pull request May 26, 2026
## ✨ Features

- **Azure v1 API Migration** — Migrated Azure provider to the v1 API:
removed the `api-version` query parameter and the
`/openai/deployments/{model}/...` URL pattern in favor of
`/openai/v1/{operation}`; the `api_version` field has been dropped from
`AzureKeyConfig` (#3661, #3756)
- **EnvVar Support for OTEL & Prometheus Configs** — `CollectorURL`,
`MetricsEndpoint`, headers, push gateway URL, and basic auth credentials
can now be sourced from environment variables (e.g.,
`env.OTEL_COLLECTOR_URL`); added a new `ConfigMarshallerPlugin`
interface that lets plugins control storage/redaction round-trips
(#3651)
- **OTel Extra Header Forwarding** — `x-bf-eh-*` extra headers forwarded
to upstream providers are now also emitted on the request span under
`gen_ai.request.extra_header.*` for end-to-end tracing (#3730)
- **OTel Semantic Conventions** — Aligned OTel attribute keys with the
OpenTelemetry GenAI spec (canonical `gen_ai.*` and new `bifrost.*`
attributes); legacy attributes are retained in parallel to avoid
breaking existing dashboards (#3732)
- **VK Quota with Provider Configs** — `GetVirtualKeyQuotaByValue` and
the `getVirtualKeyQuota` HTTP response now include `provider_configs`
with their budgets and rate limits (#3721)
- **MCP Temp Token Non-Auth Toggle** — Added
`mcp_enable_temp_token_auth` client config flag to gate short-lived MCP
token minting for non-authenticated users (#3720)
- **Responses Stream in JSON Parser** — `jsonparser` plugin now handles
OpenAI Responses API streaming (`ResponsesStreamRequest`) in addition to
chat completions (#3749)
- **Session API Rework** — Logout now calls both the password-based
session logout and OAuth logout endpoints and resets all RTK Query cache
state (#3698)

## 🐞 Fixed

- **Streaming Latency for Observability** — Deferred root span
termination to the trace completer callback for streaming requests so
request latency is no longer inflated by header-flush time (#3762)
- **Stream Cancellation Race** — Set `BifrostContextKeyConnectionClosed`
before closing the stream and short-circuit `idleTimeoutReader.Read`
when the connection is already closed to avoid panics and hangs on
cancellation (#3733)
- **Bedrock Cache Points** — Strip cache points from Bedrock requests
for models that do not support prompt caching (e.g., GLM, Llama) to
avoid Converse API errors (#3754)
- **Bedrock Empty Text Blocks** — Skip empty/nil text blocks during
Bedrock response conversion to avoid invalid messages (#3747)
- **Bedrock Reasoning + Tools** — Preserve reasoning content blocks on
assistant turns that also contain tool calls in the Bedrock chat
converter (#3690)
- **Bedrock Search Content & Video** — Restored search content and video
parts that were being dropped from Bedrock-native passthrough requests
(#3729)
- **Structured Output Stop Reason** — Fixed an incorrect `tool_calls`
finish reason when structured output is combined with extended-thinking
tools (#3685)
- **Gemini Tool Schema Passthrough** — Forward full tool parameter
schemas via `parametersJsonSchema` instead of the lossy `parameters`
form; corrected tool response role to `user`; resolved structured output
+ tools conflict (#3761)
- **Anthropic Stop Reason & Tool Versions** — Normalized stop reason
mapping (`end_turn` to `stop`, `tool_use` to `tool_calls`, `max_tokens`
to `length`) and upgraded `text_editor_20250124`/`str_replace_editor` to
`text_editor_20250728` for computer-use tools (#3761)
- **Azure Endpoint Redaction** — Fixed a panic when
`AzureKeyConfig.Endpoint` is a literal value rather than an env
reference (#3761)
- **Auth Middleware Path Match** — Match temp-token auth middleware
whitelist against the request path only, not the full URI with query
parameters (#3737)
- **Governance Blocked Models UI** — Restored the missing Blocked Models
create/edit UI in the VK provider config sheet (#3750)
- **Logging Plugin Cleanup Drain** — Fixed a shutdown race where
`batchWriter` could drop in-flight log entries; `Cleanup` now drains
both the recovered batch and remaining queue within a 30-second budget
(#3717)
- **Model Rankings Empty Entries** — Excluded entries with empty `model`
values from model rankings matview queries so blank rows no longer
surface in the UI (#3758)
- **User Filter Duplicates** — Recreated `mv_filter_users` matview to
require non-empty `user_name`, eliminating duplicate filter dropdown
entries (#3764)
- **User Filter Display Name** — Use `user_name` instead of `user_id` as
the display label for users in logging filters (#3691)
- **Large Numeric ID Precision** — Preserve large numeric IDs in URL
search params by skipping JSON parsing for plain strings (#3692)

## 🔧 Refactors & Chores

- **Error Propagation for GetAvailable\* APIs** — `GetAvailable*`
methods on `LoggerPlugin`/`LogManager` now return wrapped errors instead
of silently logging and returning empty slices (#3759)
- **Governance Blocklist Matching** — Use `slices.Contains` for VK
blocked-model matching for clearer code with identical semantics (#3727)
- **Exported `ResolvePeriod`** — Renamed `resolvePeriod` to
`ResolvePeriod` so external packages can reuse the period parsing
(#3763)

## 📚 Docs

- **OTEL Env Var Documentation** — Documented `env.VAR_NAME` support for
`collector_url`, `metrics_endpoint`, and headers in OTEL/Prometheus
plugin docs
- **OTEL OSS Features & Examples** — Added OTEL documentation to the OSS
features list with usage examples (#3731)
- **Anthropic Auth Recommendation** — Recommend `ANTHROPIC_AUTH_TOKEN`
over `ANTHROPIC_CUSTOM_HEADERS` for Claude Code authentication (#3686)
@akshaydeo akshaydeo mentioned this pull request May 27, 2026
18 tasks
akshaydeo added a commit that referenced this pull request May 27, 2026
## Summary

This PR releases Bifrost OSS `v1.5.5` and Enterprise `v1.4.4`, bumping all module pins from `v1.5.12`/`v1.3.12` to `v1.5.13`/`v1.3.13` across core, framework, and all plugins. It also hardens the Docker manifest shell scripts, expands CI egress allowlists, and updates documentation to reflect the new SCIM-based user provisioning feature.

## Changes

- **Module version bumps**: All `go.mod`/`go.sum` files updated from `core v1.5.12` → `v1.5.13`, `framework v1.3.12` → `v1.3.13`, and all plugin versions incremented accordingly (`compat`, `governance`, `jsonparser`, `logging`, `maxim`, `mocker`, `otel`, `prompts`, `semanticcache`, `telemetry`).
- **Docker manifest scripts**: Added `#!/usr/bin/env bash` shebang and `set -euo pipefail` to `create-docker-manifest.sh` and `create-docker-manifest-ubi9.sh`; quoted all variable expansions and switched `jq -r` to `jq -er` to fail on null digests.
- **CI egress allowlist**: Added `production.cloudfront.docker.com:443` to Docker-related job allowlists, and added `_https._tcp.dl.google.com:443` and `motd.ubuntu.com:443` to the Ubuntu package job allowlist.
- **Changelog files**: Cleared per-module `changelog.md` files (content moved into the new versioned docs). Added `docs/changelogs/v1.5.5.mdx` and `docs/changelogs/ent-v1.4.4.mdx` with full release notes, and registered both in `docs/docs.json`.
- **Documentation**: Replaced the SSO Integration link with a User Provisioning (SCIM) link in both `README.md` and `transports/README.md`.
- **Enterprise v1.4.4 highlights** (documented): Kafka and Google Cloud Pub/Sub observability sinks, chunked streaming with a 100 MB inter-node message ceiling, BigQuery custom labels via env vars using the new `ConfigMarshallerPlugin` interface, temporary access token expiry extensions, and a multi-node cluster integration harness.
- **OSS v1.5.5 highlights** (documented): Azure v1 API migration, env-var support for OTel/Prometheus configs, OTel extra-header forwarding and semantic-convention alignment, virtual key quota including provider configs, Responses API streaming in `jsonparser`, and a batch of Bedrock, Gemini, Anthropic, Azure, and logging plugin fixes.

## Type of change

- [ ] Bug fix
- [x] Feature
- [ ] Refactor
- [x] Documentation
- [x] Chore/CI

## Affected areas

- [x] Core (Go)
- [x] Transports (HTTP)
- [x] Providers/Integrations
- [x] Plugins
- [ ] UI (React)
- [x] Docs

## How to test

```sh
# Core/Transports
go version
go test ./...

# Verify Docker manifest scripts exit on error
bash -n .github/workflows/scripts/create-docker-manifest.sh
bash -n .github/workflows/scripts/create-docker-manifest-ubi9.sh
```

Validate that the new changelog pages (`changelogs/v1.5.5` and `changelogs/ent-v1.4.4`) render correctly in the docs site.

## Screenshots/Recordings

N/A

## Breaking changes

- [x] Yes
- [ ] No

The Azure provider no longer accepts `api_version` in `AzureKeyConfig` and has migrated to the `/openai/v1/{operation}` URL pattern. See the [v1.4.0 Migration Guide](https://docs.getbifrost.ai/enterprise/migration-guides/v1.4.0) for full details.

## Related issues

#3661, #3756, #3651, #3730, #3732, #3754, #3747, #3690, #3729, #3685, #3733, #3761, #3735, #3721, #3720, #3749, #3698, #3762, #3750, #3727, #3717, #3759, #3758, #3764, #3691, #3692, #3737, #3763

## Security considerations

- The `ConfigMarshallerPlugin` interface redacts secrets (OTel collector URLs, Prometheus push gateway credentials, BigQuery labels) at config storage time and rehydrates them at load time, preventing plaintext secret persistence.
- Docker manifest scripts now use `set -euo pipefail`, preventing silent failures that could result in malformed or missing image manifests being pushed.

## Checklist

- [x] I read `docs/contributing/README.md` and followed the guidelines
- [x] I added/updated tests where appropriate
- [x] I updated documentation where needed
- [x] I verified builds succeed (Go and UI)
- [x] I verified the CI pipeline passes locally if applicable
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants