Skip to content

[fix]: map upstream connection failures to 502 instead of 400 - #3929

Merged
akshaydeo merged 5 commits into
maximhq:devfrom
chris-colinsky:fix/upstream-connection-failures-502
Jun 5, 2026
Merged

[fix]: map upstream connection failures to 502 instead of 400#3929
akshaydeo merged 5 commits into
maximhq:devfrom
chris-colinsky:fix/upstream-connection-failures-502

Conversation

@chris-colinsky

@chris-colinsky chris-colinsky commented May 31, 2026

Copy link
Copy Markdown
Contributor

Description

When the upstream provider fails to return a response body (connection reset before the first byte, DNS lookup failure, connection refused), makeRequestWithDoFunc in core/providers/utils/utils.go returned a BifrostError with StatusCode: nil and IsBifrostError: false. In SendBifrostError that fell through to HTTP 400, misleading downstream consumers into treating a retriable upstream connectivity failure as a non-retriable client bad-request.

This mirrors the timeout-mapping fix in #2412 / #2413, applied to the connection-failure branches that weren't covered there. 502 (Bad Gateway) is the right semantic: Bifrost successfully dispatched to the upstream; the upstream just failed to respond.

Type of Change

  • Bug fix
  • New feature
  • Breaking change
  • Documentation update
  • Refactoring

Affected Packages

  • core/schemas/ — new ProviderConnectionFailed error type constant
  • core/providers/utils/ — new NewBifrostUpstreamConnectionError constructor; two branches in makeRequestWithDoFunc updated; tests added

Changes Made

  • Added ProviderConnectionFailed = "provider_connection_failed" to the existing error-type const block in core/schemas/bifrost.go.
  • Added NewBifrostUpstreamConnectionError(message, err) in core/providers/utils/utils.go, mirroring NewBifrostTimeoutError from fix timeout status code #2413. Sets StatusCode: 502, Error.Type: ProviderConnectionFailed. IsBifrostError: false because the upstream is the cause.
  • Replaced both StatusCode-less return paths in makeRequestWithDoFunc with the new constructor:
    • The *net.OpError / *net.DNSError branch (uses schemas.ErrProviderNetworkError).
    • The generic do-error catch-all (uses schemas.ErrProviderDoRequest) — this is the branch that catches the "server closed connection before returning the first response byte" case from fasthttp.
  • Added TestNewBifrostUpstreamConnectionError in core/providers/utils/makerequest_test.go (mirrors TestNewBifrostTimeoutError).
  • Updated TestMakeRequestWithContext_ClientError to assert StatusCode == 502 and Error.Type == ProviderConnectionFailed.
  • Added a changelog entry at the top of core/changelog.md.

Total: 4 files, +53 / -16.

Testing

  • Unit tests added/updated
  • make test-all run locally — Go toolchain not available in my environment; relying on CI. The change is mechanical (replaces inline struct literals with a constructor call of identical shape) and the new test assertions mirror the precedent's TestNewBifrostTimeoutError.

Checklist

  • Code follows the project's code style (mirrors NewBifrostTimeoutError precedent)
  • Tests are passing locally (make test-all) — see note above
  • Documentation is updated where needed (changelog entry; constructor has docstring)
  • No breaking changes
  • Commit message follows the format: [type]: description
  • All affected packages are mentioned in commit messages

Related Issues

Closes #3927
References #2412 / #2413 (precedent: timeout → 504 mapping)

Summary by CodeRabbit

  • New Features

    • Interactive CLI UI: tab command popup with full keyboard navigation and numeric tab jump, tmux-safe alternate prefix, interactive summary with arrow-key navigation and inline editable/masked fields, mandatory update prompt, improved post-harness flow, and model chooser enhancements.
  • Bug Fixes

    • Upstream provider connection failures are now returned as HTTP 502 (Bad Gateway) with a standardized provider-connection-failed error classification for clearer diagnostics.

akshaydeo and others added 3 commits May 31, 2026 13:59
## Summary

Removes the redundant changelog header and version label from `cli/changelog.md` and fixes a missing newline at the end of the file.

## Changes

- Removed the `# Bifrost CLI Changelog` heading and `## v0.10.5` version label from the top of the changelog
- Added a trailing newline to the final line of the file to resolve the "no newline at end of file" issue

## Type of change

- [ ] Bug fix
- [ ] Feature
- [ ] Refactor
- [ ] Documentation
- [x] Chore/CI

## Affected areas

- [ ] Core (Go)
- [ ] Transports (HTTP)
- [ ] Providers/Integrations
- [ ] Plugins
- [ ] UI (React)
- [x] Docs

## How to test

Verify the changelog renders correctly and that no trailing newline warning appears in diff tooling.

```sh
cat -A cli/changelog.md | tail -5
```

The last line should end with `$` (indicating a proper newline terminator).

## Screenshots/Recordings

N/A

## Breaking changes

- [ ] Yes
- [x] No

## Related issues

N/A

## Security considerations

None.

## Checklist

- [ ] I read `docs/contributing/README.md` and followed the guidelines
- [ ] I added/updated tests where appropriate
- [x] I updated documentation where needed
- [x] I verified builds succeed (Go and UI)
- [ ] I verified the CI pipeline passes locally if applicable

<!-- This is an auto-generated comment: release notes by coderabbit.ai -->

## Summary by CodeRabbit

## Release Notes

* **Documentation**
  * Updated changelog to document CLI command overlay improvements enabling arrow key navigation in tab popups.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
When the upstream provider fails to return a response body
(connection reset before the first byte, DNS lookup failure,
connection refused), makeRequestWithDoFunc returned a
BifrostError with StatusCode: nil and IsBifrostError: false.
In SendBifrostError that fell through to HTTP 400, misleading
downstream consumers into treating a retriable upstream
connectivity failure as a non-retriable client bad-request.

Mirrors the timeout-mapping fix in maximhq#2412 / maximhq#2413 applied to
the connection-failure branches.

Changes:

- core/schemas/bifrost.go - new ProviderConnectionFailed error
  type constant ("provider_connection_failed"), alongside the
  existing RequestCancelled / RequestTimedOut.
- core/providers/utils/utils.go - new NewBifrostUpstreamConnectionError
  constructor mirroring NewBifrostTimeoutError; sets StatusCode
  to 502 (Bad Gateway) and Error.Type to ProviderConnectionFailed.
  IsBifrostError is false (the upstream is the cause).
  Replaced both StatusCode-less return paths in
  makeRequestWithDoFunc with the new constructor:
  the net.OpError / net.DNSError branch, and the generic
  do-error branch.
- core/providers/utils/makerequest_test.go - new
  TestNewBifrostUpstreamConnectionError; updated
  TestMakeRequestWithContext_ClientError to assert 502 +
  ProviderConnectionFailed.
- core/changelog.md - entry at top.

Closes maximhq#3927
References maximhq#2412 / maximhq#2413 (precedent: timeout -> 504 mapping)
@CLAassistant

CLAassistant commented May 31, 2026

Copy link
Copy Markdown

CLA assistant check
All committers have signed the CLA.

@akshaydeo akshaydeo self-assigned this May 31, 2026
@coderabbitai

coderabbitai Bot commented May 31, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

Caution

Review failed

The pull request is closed.

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro

Run ID: adb6665d-23de-4f99-b450-9ced55803c12

📥 Commits

Reviewing files that changed from the base of the PR and between 4ef9875 and 44331d8.

📒 Files selected for processing (4)
  • cli/changelog.md
  • core/changelog.md
  • core/providers/utils/utils.go
  • core/schemas/bifrost.go

📝 Walkthrough

Walkthrough

Maps upstream connectivity failures to HTTP 502 (provider_connection_failed), adds ProviderConnectionFailed constant and NewBifrostUpstreamConnectionError helper, updates request classification to use the helper, adds/updates tests to assert 502/type, and updates changelogs.

Changes

Upstream Connection Error Handling

Layer / File(s) Summary
Error type constant and upstream connection error helper
core/schemas/bifrost.go, core/providers/utils/utils.go
Adds ProviderConnectionFailed constant and NewBifrostUpstreamConnectionError(message string, err error) which constructs a BifrostError with HTTP 502, ProviderConnectionFailed type, and IsBifrostError=false.
Request error classification and validation tests
core/providers/utils/utils.go, core/providers/utils/makerequest_test.go
makeRequestWithDoFunc now returns NewBifrostUpstreamConnectionError for DNS/network and non-timeout do() failures. Tests updated: TestMakeRequestWithContext_ClientError asserts HTTP 502 and ProviderConnectionFailed; new TestNewBifrostUpstreamConnectionError verifies the helper's fields.
Changelog documentation
core/changelog.md, cli/changelog.md
Core changelog documents mapping upstream connection failures to 502 and dependency bump; CLI changelog adds multiple interactive UI entries.

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

Possibly related issues

Suggested reviewers

  • akshaydeo
  • danpiths

Poem

🐰 Hops of joy through error flows,
502 now when connection goes,
Networks falter, messages clear,
Errors labeled, handlers steer,
A tiny hop — then back to cheer! 🥕

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 57.14% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly and specifically identifies the main change: mapping upstream connection failures to HTTP 502 instead of 400.
Description check ✅ Passed The PR description includes all key sections: a clear problem statement, detailed changes made across all affected files, testing notes, and a comprehensive checklist.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Warning

There were issues while running some tools. Please review the errors and either fix the tool's configuration or disable the tool if it's a critical failure.

🔧 golangci-lint (2.12.2)

level=error msg="[linters_context] typechecking error: pattern ./...: directory prefix . does not contain main module or its selected dependencies"


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

akshaydeo
akshaydeo previously approved these changes May 31, 2026
@akshaydeo

Copy link
Copy Markdown
Contributor

❤️ for the PR @chris-colinsky - should go with our next release

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@core/changelog.md`:
- Line 1: Update the changelog entry "[fix]: map upstream connection failures to
502 instead of 400 [`@chris-colinsky`]" to include the PR number in the same
format as other entries by appending " (`#3929`)" to the end of the line so it
matches the existing pattern (e.g., include the PR identifier next to the author
handle).
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro

Run ID: 36aef3e7-b9fc-48bc-aeab-61c22d2d8aaf

📥 Commits

Reviewing files that changed from the base of the PR and between d4c96b8 and e35fec6.

📒 Files selected for processing (4)
  • core/changelog.md
  • core/providers/utils/makerequest_test.go
  • core/providers/utils/utils.go
  • core/schemas/bifrost.go

Comment thread core/changelog.md Outdated
@greptile-apps

greptile-apps Bot commented May 31, 2026

Copy link
Copy Markdown
Contributor

Confidence Score: 4/5

The core code change is correct and safe; the changelog files contain accidental content that should be fixed before merging.

The utils.go and schemas changes are a clean, well-tested mechanical replacement — two inline struct literals replaced with a constructor, verified by new and updated unit tests. The concern is in the changelog files: core/changelog.md loses five previously-recorded entries by overwriting rather than prepending, and cli/changelog.md gains twelve unrelated CLI-feature entries that appear to have been accidentally carried in from another branch.

core/changelog.md and cli/changelog.md — the former drops five existing entries and the latter adds twelve unrelated CLI entries; both appear to be rebase/merge artifacts.

Important Files Changed

Filename Overview
core/schemas/bifrost.go Adds ProviderConnectionFailed constant to the error-type const block alongside RequestCancelled and RequestTimedOut; no other changes.
core/providers/utils/utils.go Adds NewBifrostUpstreamConnectionError constructor (StatusCode 502, IsBifrostError false) and replaces two inline struct literals in makeRequestWithDoFunc with it; clean mechanical change.
core/providers/utils/makerequest_test.go Adds TestNewBifrostUpstreamConnectionError unit test and extends TestMakeRequestWithContext_ClientError with StatusCode 502 and ProviderConnectionFailed type assertions.
core/changelog.md Five existing changelog entries deleted and replaced with two new ones; prior entries are lost rather than prepended.
cli/changelog.md Previously empty file now contains 12 CLI-feature changelog entries unrelated to this PR (tab commands, Ctrl+B, Ctrl+G, etc.).

Reviews (3): Last reviewed commit: "Merge branch 'dev' into fix/upstream-con..." | Re-trigger Greptile

Comment thread core/providers/utils/utils.go
Addresses review feedback — matches the existing entry format
(e.g. `(maximhq#3900)`) for traceability.

Changes:
- core/changelog.md - append (maximhq#3929) to the upstream connection
  failures entry.
Signed-off-by: Akshay Deo <akshay@akshaydeo.com>
@akshaydeo
akshaydeo merged commit 5aac1e0 into maximhq:dev Jun 5, 2026
4 of 5 checks passed
@akshaydeo akshaydeo mentioned this pull request Jun 5, 2026
18 tasks
akshaydeo added a commit that referenced this pull request Jun 6, 2026
## Summary

This PR bumps the Go toolchain version from `1.26.3` to `1.26.4` across all modules and CI workflows, and cuts a new release (`core` v1.5.17, `framework` v1.3.17, `transports` v1.5.9, `plugins/compat` v0.1.16, `plugins/governance` v1.5.17, and associated plugin versions) incorporating a large batch of features and fixes accumulated since the previous release.

## Changes

- **Go 1.26.4** — Updated `go-version` in all GitHub Actions workflows (`e2e-tests`, `helm-release`, `pr-tests`, `release-cli`, `release-pipeline`, `snyk`) and all `go.mod` files (core, framework, transports, cli, all plugins, examples, and test modules).
- **Core (v1.5.17)** — OpenAI compaction support, multi-customer logs and usage tracking, multiple team/business unit support, `request_headers` wildcard pattern capture for OTel and Maxim plugins, xAI `x_search` tool, fetch URL validation with SSRF hardening, `file://` pricing URL scheme, virtual key provider fan-out filtering, and a broad set of fixes including Anthropic prompt cache key, empty thinking block stripping, OpenAI stream usage event cleanup, Gemini numeric schema constraints, stale connection retries, Azure Claude diagnostic strip, and passthrough budget handling.
- **Framework (v1.3.17)** — Scope-aware budgets and limits wired from model configs, provider-level governance, multiple customer budget support with `calendar_aligned` windows, paginated virtual key fetch, `config.json` source-of-truth flow, FTS index cap reduction, sync worker drift fix, cascade deletes for model configs, and high-scale virtual key flow improvements.
- **Transports (v1.5.9)** — Full changelog covering all of the above plus UI improvements (log navigation, customer detail sheet, `BudgetDisplay` component, inline loading shell, materialized view alias), SCIM provisioning fields, Helm/config schema additions (`roles`, `per_user_oauth`), client IP resolution from forwarded headers, and dependency upgrades (`recharts` to 3.8.1, `golang.org/x` CVE remediation).
- **Plugins** — `governance` v1.5.17 adds team budget/rate-limit exporters, ghost node reconciliation fix, and VK double usage counting fix; `logging` v1.5.17 adds wildcard header capture and file attachment rendering; `otel` v1.2.17 adds `disable_content_logging` and multiple collectors support; `maxim` v1.6.17 adds `request_headers` wildcard capture; `compat` v0.1.16 fixes `max_tokens` preservation during param filtering.

## Type of change

- [ ] Bug fix
- [x] Feature
- [ ] Refactor
- [ ] Documentation
- [x] Chore/CI

## Affected areas

- [x] Core (Go)
- [x] Transports (HTTP)
- [x] Providers/Integrations
- [x] Plugins
- [x] UI (React)
- [ ] Docs

## How to test

```sh
# Verify Go version
go version  # should report go1.26.4

# Run core tests
cd core && go test ./...

# Run framework tests
cd framework && go test ./...

# Run transports tests
cd transports && go test ./...

# Run plugin tests
cd plugins/governance && go test ./...
cd plugins/logging && go test ./...
cd plugins/otel && go test ./...

# UI
cd ui
pnpm i
pnpm build
pnpm test
```

## Breaking changes

- [ ] Yes
- [x] No

## Related issues

#4053, #4066, #4041, #4012, #3976, #3947, #3991, #4045, #3957, #3938, #3937, #3939, #3981, #3998, #3997, #4092, #4091, #4079, #4080, #4086, #3929, #3994, #4028, #3970, #3919, #3861, #3664, #3999, #4088, #4070, #4051, #4043, #4057, #4023, #3941, #3955, #4024, #3956, #3967, #3925, #3992, #3900

## Security considerations

- Fetch URL validation hardened against SSRF by tightening IP checks for private networks and link-local addresses (#4092, #3947, #3991).
- Transitive `golang.org/x` dependencies (crypto, net, sys, text) bumped to address Docker Scout CVEs (#3900).

## Checklist

- [x] I read `docs/contributing/README.md` and followed the guidelines
- [x] I added/updated tests where appropriate
- [x] I updated documentation where needed
- [x] I verified builds succeed (Go and UI)
- [x] I verified the CI pipeline passes locally if applicable

<!-- This is an auto-generated comment: release notes by coderabbit.ai -->
## Summary by CodeRabbit

* **New Features**
  * OpenAI compaction, multi-customer/team logstore support, request-header wildcard capture, enhanced governance (provider-level & scope-aware limits), disable-content-logging option, support for multiple OpenTelemetry collectors, SSRF hardening and URL validation.

* **Chores**
  * Bumped Go toolchain across modules and updated component/plugin version releases.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
@akshaydeo akshaydeo mentioned this pull request Jun 7, 2026
akshaydeo added a commit that referenced this pull request Jun 7, 2026
* changelogs

* [fix]: map upstream connection failures to 502 instead of 400

When the upstream provider fails to return a response body
(connection reset before the first byte, DNS lookup failure,
connection refused), makeRequestWithDoFunc returned a
BifrostError with StatusCode: nil and IsBifrostError: false.
In SendBifrostError that fell through to HTTP 400, misleading
downstream consumers into treating a retriable upstream
connectivity failure as a non-retriable client bad-request.

Mirrors the timeout-mapping fix in #2412 / #2413 applied to
the connection-failure branches.

Changes:

- core/schemas/bifrost.go - new ProviderConnectionFailed error
  type constant ("provider_connection_failed"), alongside the
  existing RequestCancelled / RequestTimedOut.
- core/providers/utils/utils.go - new NewBifrostUpstreamConnectionError
  constructor mirroring NewBifrostTimeoutError; sets StatusCode
  to 502 (Bad Gateway) and Error.Type to ProviderConnectionFailed.
  IsBifrostError is false (the upstream is the cause).
  Replaced both StatusCode-less return paths in
  makeRequestWithDoFunc with the new constructor:
  the net.OpError / net.DNSError branch, and the generic
  do-error branch.
- core/providers/utils/makerequest_test.go - new
  TestNewBifrostUpstreamConnectionError; updated
  TestMakeRequestWithContext_ClientError to assert 502 +
  ProviderConnectionFailed.
- core/changelog.md - entry at top.

Closes #3927
References #2412 / #2413 (precedent: timeout -> 504 mapping)

* [chore]: add PR number to changelog entry

Addresses review feedback — matches the existing entry format
(e.g. `(#3900)`) for traceability.

Changes:
- core/changelog.md - append (#3929) to the upstream connection
  failures entry.

---------

Signed-off-by: Akshay Deo <akshay@akshaydeo.com>
Co-authored-by: akshaydeo <akshay@akshaydeo.com>
akshaydeo added a commit that referenced this pull request Jun 7, 2026
## ✨ Features

- **OpenAI Compaction** — Added OpenAI conversation compaction support
across core, framework, logging, and the API surface (#4053)
- **Multi-Customer & Org Hierarchy** — Logs and usage tracking now
support multiple customers, teams, and business units, including
business unit CRUD, team assignment, and governance endpoints in the
OpenAPI spec (#4066, #4041, #4082)
- **Provider-Level Governance** — Budgets & limits are now scope-aware
and can be applied at the virtual-key top level and per provider, wired
from the model configs table, with UI filters for scope and providers
(#3938, #3937, #3939, #3981, #3962)
- **Customer Budgets** — Customers support multiple budgets and
`calendar_aligned` budget windows (#3998, #3997)
- **Virtual Key Attribution & Controls** — Added a `created_by` user
attribution column and a `blacklisted_models` column for virtual key
provider configs (#3672, #3653)
- **Request Header Capture** — OTel and Maxim observability plugins
capture `request_headers` by pattern, with wildcard support (e.g.
`x-custom-*`); logging gained the same wildcard header capture (#4012,
#3958)
- **OTel Content Controls & Collectors** — New `disable_content_logging`
option drops message/tool content from exported spans, plus support for
multiple OTel collectors (#4064, #3894)
- **xAI x_search** — Added xAI `x_search` tool support (#3976)
- **URL Validation** — Added fetch URL validation with private-network
configuration and link-local blocking (#3947, #3991)
- **File Scheme Pricing URLs** — Pricing source URLs now accept the
`file://` scheme for air-gapped and self-hosted deployments (#4045)
- **Paginated Virtual Keys** — Virtual key fetching is paginated to
handle deployments with very large numbers of keys (#3957)
- **Client IP Resolution** — Resolve client IP from
`X-Forwarded-For`/`X-Real-IP` headers
- **SCIM Provisioning** — Added `attributeType`/`attributeValue` SCIM
provisioning fields
- **Helm/Config Schema** — Added `roles` RBAC governance config and
`per_user_oauth` MCP auth to the Helm chart and config schema (#4004,
#4009)
- **Log Navigation UI** — Added a "View logs" menu item to customer,
team, and virtual key tables, clickable links in log detail views, a
customer detail sheet, and a reusable `BudgetDisplay` component (#4073,
#4054, #4026, #4055)
- **Faster First Paint** — Added an inline loading shell to `#root`
before React mounts (#4063)
- **Materialized View Alias** — Added an `alias` column to the
materialized view with filter support (#4078)

## 🐞 Fixed

- **Fetch URL IP Checks** — Hardened fetch URL IP checks against SSRF
(#4092)
- **Mantle Model Matching** — Broadened Mantle model matching to all
`gpt` variants (#4091)
- **Empty Thinking Blocks** — Strip thinking blocks when the signature
is empty (#4079)
- **OpenAI Stream Usage** — Removed usage from the `responses.created`
event in the OpenAI stream (#4080)
- **Prompt Cache Key** — Set the prompt cache key from the Anthropic
integration (#4086)
- **Upstream Failure Status** — Map upstream connection failures to 502
instead of 400 (#3929) (thanks
[@chris-colinsky](https://github.com/chris-colinsky)!)
- **Gemini Schema Constraints** — Accept numeric schema integer
constraints for Gemini (#3994) (thanks
[@yanhao98](https://github.com/yanhao98)!)
- **Files Provider Param** — Accept the `?provider=` query param on `GET
/v1/files` (#3971) (thanks [@alexef](https://github.com/alexef)!)
- **Optional Batch Model** — Made the `model` field optional on `POST
/v1/batches` (#3973) (thanks [@alexef](https://github.com/alexef)!)
- **Helm Azure Config** — Added missing `azure_key_config` fields to the
Helm schema (#3996) (thanks
[@axelray-dev](https://github.com/axelray-dev)!)
- **Text Completion Chunk Model** — Added the missing `Model` field to
`TextCompletionChunkResponse` (#3970) (thanks
[@kuishou68](https://github.com/kuishou68)!)
- **MCP Inline stdio Env** — MCP stdio server configs accept inline
environment variable assignments (#3861) (thanks
[@Shushmitaaaa](https://github.com/Shushmitaaaa)!)
- **Orphaned Tool Results** — Orphaned tool results in the OpenAI to
Anthropic conversion flow are no longer rejected by the Anthropic API
(#3919)
- **Node Usage Reconciliation** — Added a monotonic `inc_number` log
cursor so node usage reconciliation does not skip late async log writes
(#3664)
- **Bedrock Output Assessments** — Corrected the type of
`outputAssessments` in Bedrock responses (#4028)
- **Model Pool Pricing Reloads** — Preserve non-pricing model pool
entries across pricing reloads (#3999)
- **Ghost Node Reconciliation** — Replicate the VK hierarchy flow for
ghost node reconciliation (#4088)
- **VK Double Usage Counting** — Fixed double usage counting when
creating a virtual key (#4070)
- **Model Config Lifecycle** — Cascade deletes for model configs and
removal of stale in-memory model configs (#4051, #4043)
- **FTS Index Cap** — Reduced the FTS index `left()` cap from 800k to
250k chars to stay within the tsvector limit (#4057)
- **Sync Worker Drift** — Reduced the sync worker ticker period to 5m to
prevent threshold drift (#4023)
- **Passthrough** — Fixed passthrough budgets, gated passthrough models
per VK, model extraction for Azure passthrough, and restricted
fallbacks/provider selection to the VK boundary (#3941, #3988, #3983,
#3924)
- **Provider Response Headers** — Strip provider response headers and
add a content-type filter (#3955, #4024)
- **Stream Handling** — Drain non-SSE stream readers and retry stale
connections (#3956, #3967)
- **Azure Claude** — Strip Azure diagnostic property for Claude models
(#3925)
- **Compat max_tokens** — Preserve chat `max_tokens` during param
filtering (#3992)
- **Raw Request Flag** — Removed the raw request flag from providers
that don't support it (#4058)
- **UI Fixes** — Standardized page container layout, virtual key model
configs UI, and dashboard chart tooltips (#4046, #4052, #4044)

## 🔧 Maintenance

- **Dependency Upgrades** — Bumped transitive `golang.org/x`
dependencies (crypto, net, sys, text) for Docker Scout CVE remediation
and `recharts` to 3.8.1; cascaded version bumps across all modules
(#3900, #4003)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[bug]: upstream connection failures surface as HTTP 400 instead of 502

3 participants