Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
67 changes: 51 additions & 16 deletions core/changelog.md

Large diffs are not rendered by default.

2 changes: 1 addition & 1 deletion core/version
Original file line number Diff line number Diff line change
@@ -1 +1 @@
1.7.13
1.8.0
47 changes: 25 additions & 22 deletions framework/changelog.md
Original file line number Diff line number Diff line change
@@ -1,30 +1,33 @@
- feat: add `cost_per_request` flat-fee pricing field across DB, cost engine, overrides and docs (#6079)
- feat(modelcatalog): resolve pricing overrides for catalog rows (#6055)
- feat: add `use_idp_credentials` to token-exchange config (#6068)
- feat: bedrock vpc endpoints support (#6064)
- feat: add additional metadata in S3 log export (#6070)
- feat: make log recalculation task cancellable backend (#5801)
- feat: add `roots_only` filter to collapse fallback chains with child aggregates (#5737)
- feat: support matview_refresh_interval "off" to disable logstore matview maintenance (thanks [@jeremym-tanium](https://github.com/jeremym-tanium)!) (#5693)
- feat: persist and resync MCP tool discoveries uniformly across all client types via a hash-gated core callback
- feat: add VK and Users filters to the OAuth Grants and MCP Auth Sessions sidebars
- feat: generalize TokenRefreshWorker's auth-mode scope and allow gating OAuthTokenRefreshWorker sweeps
- feat(mcp-guardrails): add MCP log redaction changes (#5744)
- feat: add plugin logs to mcp logs (#5746)
- fix: combine `offline_access` with `<audience>/.default` for Entra OBO instead of replacing it (#6078)
- fix: don't treat a CAS loss to a still-active concurrent refresh as a dead credential
- fix: propagate ctx through headerCredentialCache.Fill and userTokenCache.Fill so a canceled request unblocks instead of waiting on an unrelated leader
- fix: add per-entry version to the LRU cache so a rejected stale Get cannot evict a concurrently-updated value
- fix: make the OAuth flow claim atomic against concurrent reauth, close a leaked sqlDB in flows-table perf setup
- fix: route pending token_exchange clients through the verify-exchange confirm dialog
- chore: dependabot dependency updates (#6040)
- feat: batch accounting: the `batch_jobs` table and its lifecycle store API (`UpsertBatchJob`, `GetBatchJob`, `ListDueBatchJobs`, `ClaimBatchJob`, `MarkBatchJobAggregateLogWritten`, `MarkBatchJobGovernanceReported`, `CompleteBatchJob`, `MarkBatchJobUnpriceable`, `FailBatchJob`) with runner fencing on `claimed_at` and `user_id`, `team_id`, `customer_id` and `source_log_id` attribution so settlement carries the creating request's identity; `batch_debug` on logs; batch pricing in the model catalog (`computeBatchTextCost` with catalog batch rates and a 0.5 default ratio, `CalculateBatchCostDetailsForUsage`, `BatchResultsRequest` routed through the batch path); and `persistRecalcOutcomes` shared by foreground and background recalculation (thanks [@SahilChoudhary22](https://github.com/SahilChoudhary22)!) (#5292, #5293, #6505)
- feat: input/output/additional cost split: denormalized `input_cost`, `output_cost` and `additional_cost` columns on logs, carried through matviews, ClickHouse, the hybrid store, cost recalculation and the quota API, populated on fallback billing paths, with semantic cache cost folded into additional cost
- feat: Bifrost overhead latency: `upstream_latency` and `overhead_latency` columns on logs with avg, p90, p95 and p99 overhead aggregates in `mv_logs_hourly`, ClickHouse, Postgres `percentile_cont` and the Go-side SQLite/MySQL histograms, the `overhead_breakdown` column for the per-span self-time decomposition, and `CompleteAndFlushTrace` handing connectors a copy of the trace without breakdown spans unless the plugin implements `OverheadSpanConsumer` (#5533, #5534, #6388, #6389)
- feat: `video_edit_input` column on logs for the new video edit request type (#6270)
- feat: new pricing columns and cost computation: megapixel-tier image fields (`output_cost_per_image_above_{4,8,16,32,64}_megapixels`) with a unified pixel-count tier ladder in `computeImageOutputCost`; per-size and joint size+quality image rates for 1024x1536 and 1536x1024 with a priority chain of size+quality, quality-only, size-only, then flat per-image rate, and `parseImageDimensions` so portrait and landscape sizes with equal pixel counts price correctly; `input_cost_per_query` for rerank; and `ultrafast` service tier rates (#6082, #6379, #6396)
- feat: notifications store: `TableNotification`, `NotificationStore`, `CreateNotification` and `ListNotifications` with JSON-serialized role IDs (#6207)
- feat: `gencache` generation-stamped memo cache, with `GetProvidersForModel` and `GetModelsForProvider` memoized until any backing store advances its write generation (#5641, #6224)
- feat: `DimensionScope` in `queryscope` and `applyDimensionCeiling` on rankings, histograms and key-pair queries so grouped analytics only expose organisation ids the caller may see; `getAvailableFilterData` no longer passes an empty id list to the redaction lookups, which returned every row (#6262)
- feat: `ObservabilityLimits` (per-plugin semaphore size and inject timeout) with context-bounded `Inject` calls and `DeadlineExceeded` accounting (#6341)
- feat: `GetSharedOauthTokensByConfigIDs` batch lookup on the config store so shared-OAuth MCP clients project `needs_reauth` when their token row is invalidated (#6429)
- feat: `mcp_library_sync_interval: 0` disables MCP library sync (`MCPLibrarySyncDisabled`), `file://` catalog URLs resolve through `datasheet.FilePathFromURL` without retry backoff, and `ResolveFrameworkPricingConfig` no longer backfills a zero interval (#6195)
- feat: `ReloadComplexityAnalyzerConfig` on `ServerCallbacks` for the routing handler (#6146)
- feat: `service_tier` copied from the processed stream response into `StreamAccumulatorResult` in `ProcessStreamingChunk` (#6236)
- fix: resolve runtime provider `together` (and variants such as `together_ai`, matched with `strings.Contains`) to the datasheet identity for catalog reads and price configured aliases through `AliasConfig.ModelName`, then `ModelID`, then the alias key (thanks [@dani29](https://github.com/dani29)!) (#6257, #6320)
- fix: escape every RediSearch special character in TAG query values in the Redis vector store, iterating bytes rather than runes (thanks [@AdityaPainuli](https://github.com/AdityaPainuli)!) (#5351)
- fix: redact sensitive and identity-aware-proxy request headers at `SetTraceRequestHeaders` so every connector (Datadog, OTEL, BigQuery, Kafka, Pub/Sub) receives redacted values (#6371)
- fix: `supports_none_reasoning_effort` datasheet flag wired through `extractSupportedParams` and `dropUnsupportedParams` so models that reason by default get `reasoning.effort: "none"` instead of losing `reasoning` (#6293)
- fix: reject negative `tool_sync_interval` at `UpdateMCPClientConfig` and on config file load, treat the value as whole minutes, and carry the stored global interval into `GetMCPConfig` (#6409, #6502)
- perf: `spanHandle` carries the `*Span` pointer so `EndSpan`, `SetAttribute` and `SpanFromHandle` skip the per-call trace and span scan, alongside bulk span attribute writes and reusable delivery timers in the tracing hot path (#5657, #5956, #6387)
- chore: remove legacy `gen_ai.*` attribute emission from the tracer in favor of the canonical `bifrost.*` keys (#6403)
- chore: close leaked Postgres pools and a stale hardcoded date in logstore tests (#6351)
- chore: build with Go 1.26.6 (#6269)
- chore: upgraded core to v1.8.0

<Warning>
This release adds 18 database migrations. `merge_oauth_token_tables`, `drop_oauth_config_pkce_columns`, `drop_oauth_config_token_id_column` and `mcp_tool_logs_add_redaction_mapping_column` are non-reversible. Back up your database before upgrading.
This release adds 13 database migrations (7 configstore, 6 logstore). All are additive and reversible: each rollback drops the column, table or index it created, and `logs_recreate_matviews_with_cost_breakdown` is a no-op both ways because `repairMatViewShapes` rebuilds `mv_logs_hourly` on the next startup.
</Warning>

<Warning>
**High-throughput deployments: run the logstore migrations during a low-activity window.**

All eight logstore migrations in this release alter `logs` or `mcp_tool_logs`, the two highest-insert tables in Bifrost, and several also build indexes on them. On a busy instance those index builds block concurrent log inserts until they complete. Schedule the upgrade for a low-traffic period, or expect elevated log-write latency while the migrations run.
Five of the six logstore migrations alter `logs`, the highest-insert table in Bifrost, and the hourly matview is rebuilt against the full table on the first boot after upgrading. Schedule the upgrade for a low-traffic period, or expect elevated log-write latency while the migrations run.
Comment thread
coderabbitai[bot] marked this conversation as resolved.
</Warning>
24 changes: 18 additions & 6 deletions framework/vectorstore/redis_test.go
Original file line number Diff line number Diff line change
Expand Up @@ -1515,16 +1515,28 @@ func TestRedisStore_VectorSearch(t *testing.T) {
require.NoError(t, err)
}

time.Sleep(500 * time.Millisecond)

// Poll rather than sleep a fixed interval: RediSearch makes a new document
// searchable slightly after the write returns, and under `go test ./...`
// (many packages sharing one Redis) a fixed 500ms was occasionally too short,
// so the search returned nothing. A query error still fails immediately,
// since an unescaped value produces a syntax error, not a delay.
for _, doc := range specialDocs {
queries := []Query{
{Field: "model", Operator: QueryOperatorEqual, Value: doc.model},
}
results, err := setup.Store.GetNearest(setup.ctx, TestNamespace, doc.embedding, queries, []string{"type", "model"}, 0.1, 10)
require.NoError(t, err, "search must not fail for model %q", doc.model)
require.Len(t, results, 1, "expected exactly the doc tagged %q", doc.model)
assert.Equal(t, doc.model, results[0].Properties["model"])
deadline := time.Now().Add(5 * time.Second)
for {
results, err := setup.Store.GetNearest(setup.ctx, TestNamespace, doc.embedding, queries, []string{"type", "model"}, 0.1, 10)
require.NoError(t, err, "search must not fail for model %q", doc.model)
if len(results) == 1 {
assert.Equal(t, doc.model, results[0].Properties["model"])
break
}
if time.Now().After(deadline) {
require.Failf(t, "tagged doc not searchable", "expected exactly the doc tagged %q, got %d results after 5s", doc.model, len(results))
}
time.Sleep(100 * time.Millisecond)
}
}
})
}
Expand Down
2 changes: 1 addition & 1 deletion framework/version
Original file line number Diff line number Diff line change
@@ -1 +1 @@
1.5.10
1.6.0
5 changes: 4 additions & 1 deletion plugins/compat/changelog.md
Original file line number Diff line number Diff line change
@@ -1 +1,4 @@
- chore: upgraded core to v1.7.11 and framework to v1.5.9
- fix: force `reasoning.effort` to `"none"` in `dropUnsupportedParams` when a model supports reasoning but not `reasoning_with_tool_calls` and advertises `supports_none_reasoning_effort`; models without the flag still have `reasoning` dropped (#6293)
- fix: clone `json.RawMessage` values (such as a raw `response_format`) in the request copier so the compat clone never shares a backing array with the original request (#6235)
- feat: add a no-op `HTTPTransportPreAuthHook` for the new pre-authentication transport phase (#6375)
- chore: upgraded core to v1.8.0 and framework to v1.6.0
Comment thread
Pratham-Mishra04 marked this conversation as resolved.
2 changes: 1 addition & 1 deletion plugins/compat/version
Original file line number Diff line number Diff line change
@@ -1 +1 @@
0.1.36
0.2.0
8 changes: 5 additions & 3 deletions plugins/governance/changelog.md
Original file line number Diff line number Diff line change
@@ -1,3 +1,5 @@
- fix: skip list models call for budgets and rate-limits (#6051)
- feat: honor the auth-skip context path in the governance resolver
- chore: upgraded core to v1.7.11 and framework to v1.5.9
- feat: routing rules and the complexity router are extracted into the dedicated `routing` plugin: governance now runs at priority 4 and routing at 5, `PublishRoutingAllowlist` and `LoadBalanceProvider` are exported on `GovernancePlugin` and `BaseGovernancePlugin` and are called from the routing plugin after rule evaluation instead of from governance's `PreRequestHook`, `runPreRequestRouting` is removed, and `ReloadRoutingRule`, `RemoveRoutingRule` and the routing rule and complexity analyzer handlers leave `GovernanceManager` and `GovernanceHandler` for `RoutingHandler` under `/api/routing/*` (with deprecated `/api/governance/*` aliases) (#6144, #6145, #6146)
- feat: batch usage reporting: `ReportBatchUsage` applies settled batch cost, tokens and requests to every budget and rate limit on a `BatchUsageReport` exactly once per request ID via a claim/release marker with a 7-day TTL, and charges the creating user's tiers when `UserID` is present; `BumpBudgetUsage` and `BumpRateLimitUsage` are added to `GovernanceStore`; governance IDs, including VK-scoped, user-scoped and global wildcard budgets and rate limits, are collected for batch-create requests that carry no model (thanks [@SahilChoudhary22](https://github.com/SahilChoudhary22)!) (#5295, #6410, #6505)
- feat: honor `BifrostContextKeySkipModelCheck` in `EvaluateVirtualKeyRequest` so evaluate-only requests such as `/inspect` bypass the model allowlist while budgets, rate limits and provider checks still apply (#6479)
- feat: add a no-op `HTTPTransportPreAuthHook` for the new pre-authentication transport phase (#6375)
- chore: upgraded core to v1.8.0 and framework to v1.6.0
2 changes: 1 addition & 1 deletion plugins/governance/version
Original file line number Diff line number Diff line change
@@ -1 +1 @@
1.6.14
1.7.0
3 changes: 2 additions & 1 deletion plugins/jsonparser/changelog.md
Original file line number Diff line number Diff line change
@@ -1 +1,2 @@
- chore: upgraded core to v1.7.11 and framework to v1.5.9
- feat: add a no-op `HTTPTransportPreAuthHook` for the new pre-authentication transport phase (#6375)
- chore: upgraded core to v1.8.0 and framework to v1.6.0
2 changes: 1 addition & 1 deletion plugins/jsonparser/version
Original file line number Diff line number Diff line change
@@ -1 +1 @@
1.5.37
1.6.0
15 changes: 8 additions & 7 deletions plugins/logging/changelog.md
Original file line number Diff line number Diff line change
@@ -1,7 +1,8 @@
- feat: make log recalculation task cancellable backend (#5801)
- feat: add `roots_only` filter to collapse fallback chains with child aggregates (#5737)
- feat: add plugin logs in mcp logs (#5746)
- feat(mcp-guardrails): add MCP log redaction changes (#5744)
- feat: video requests info in logs ui (#5946)
- feat: cost for prompt guardrails (#4931)
- chore: upgraded core to v1.7.11 and framework to v1.5.9
- feat: batch accounting: `recordBatchJobLifecycle` persists batch state on create and retrieve, `accountBatchResults` settles costs inline on the `/results` path under a 30-second bound, `StartBatchAccountingSweeper` re-drives jobs that timed out with a per-runner ownership identity, `EmitBatchAggregateLog` writes the aggregate cost entry with the creating request's identity and a `bifrost/<version>` user agent, `calculateBatchAggregateCost` reprices `Model="mixed"` rows per model breakdown during cost recalculation (foreground and background, via the shared `persistRecalcOutcomes`), and `batch_debug` is included in list queries; `Init` takes a `batchStore` (nil disables batch accounting) (thanks [@SahilChoudhary22](https://github.com/SahilChoudhary22)!) (#5296, #6121, #6474, #6505)
- feat: input/output/additional cost split persisted on every log and surfaced as `cost_breakdown` in the log detail API, with cached-read, reasoning, guardrail, MCP and semantic cache detail; fallback billing paths, speech, transcription and OCR usages populate the split, and legacy total-only rows are attributed to input cost (#6511)
- feat: Bifrost overhead latency: `upstream_latency` and `overhead_latency` forwarded from `PostLLMHook` and backfilled from the root span's authoritative attributes in `Inject`, stamped only on the terminal entry per trace; `computeOverheadBreakdown` walks the span tree, computes self-time per span, groups overhead-side spans into buckets (serialization, middleware, plugins, queue wait, key selection, convertor, networking, client delivery, scheduling, worker hand-off, provider-internal) and persists them to `overhead_breakdown`, with streaming traces folding parse, convert, backpressure, transport CPU and client-write time into their own buckets and using the measured sum as overhead; `ConsumesOverheadSpans` returns true so the plugin keeps receiving breakdown spans that other connectors no longer see (#5533, #6388, #6389, #6433, #6470, #6495)
- feat: `service_tier` from streamed Anthropic responses flows through `convertToProcessedStreamResponse` into the log entry so repricing uses the served tier (#6236)
- feat: video edit requests are logged with their input (#6270)
- perf: identity and governance context reads are deferred past the non-final-chunk gate in `PostLLMHook`, and JSON encoding in HTTP helpers uses sonic (#5957, #6268)
- feat: add a no-op `HTTPTransportPreAuthHook` for the new pre-authentication transport phase (#6375)
- chore: upgraded core to v1.8.0 and framework to v1.6.0
2 changes: 1 addition & 1 deletion plugins/logging/version
Original file line number Diff line number Diff line change
@@ -1 +1 @@
1.6.10
1.7.0
5 changes: 4 additions & 1 deletion plugins/maxim/changelog.md
Original file line number Diff line number Diff line change
@@ -1 +1,4 @@
- chore: upgraded core to v1.7.11 and framework to v1.5.9
- feat: `addLatencyTags` forwards `upstream_latency_ms` and `overhead_latency_ms` as tags on both the generation and the trace, leaving unmeasured values unreported (#6345)
- fix: sensitive and identity-aware-proxy request headers are redacted in `PostLLMHook` before export (#6371)
- feat: add a no-op `HTTPTransportPreAuthHook` for the new pre-authentication transport phase (#6375)
- chore: upgraded core to v1.8.0 and framework to v1.6.0
2 changes: 1 addition & 1 deletion plugins/maxim/version
Original file line number Diff line number Diff line change
@@ -1 +1 @@
1.6.37
1.7.0
3 changes: 2 additions & 1 deletion plugins/mocker/changelog.md
Original file line number Diff line number Diff line change
@@ -1 +1,2 @@
- chore: upgraded core to v1.7.11 and framework to v1.5.9
- feat: add a no-op `HTTPTransportPreAuthHook` for the new pre-authentication transport phase (#6375)
- chore: upgraded core to v1.8.0 and framework to v1.6.0
2 changes: 1 addition & 1 deletion plugins/mocker/version
Original file line number Diff line number Diff line change
@@ -1 +1 @@
1.5.37
1.6.0
2 changes: 1 addition & 1 deletion plugins/modelcatalogresolver/changelog.md
Original file line number Diff line number Diff line change
@@ -1 +1 @@
- chore: upgraded core to v1.7.11 and framework to v1.5.9
- chore: upgraded core to v1.8.0 and framework to v1.6.0
2 changes: 1 addition & 1 deletion plugins/modelcatalogresolver/version
Original file line number Diff line number Diff line change
@@ -1 +1 @@
1.0.18
1.1.0
10 changes: 7 additions & 3 deletions plugins/otel/changelog.md
Original file line number Diff line number Diff line change
@@ -1,3 +1,7 @@
- feat: add separate headers support for traces and metrics in OTEL collector (#5940)
- feat: add support for a separate metrics tab independent of traces for OTEL (#5939)
- chore: upgraded core to v1.7.11 and framework to v1.5.9
- feat: `bifrost_overhead_latency_microseconds` histogram derived from the root span's overhead attribute, with a microsecond-scale bucket set (#6345)
- chore: remove the legacy `gen_ai.*`-namespaced Bifrost-internal attributes, `gen_ai.usage.prompt_tokens`/`completion_tokens` and the nanosecond `time_to_first_token` attribute; `buildSpanAttrs` and `entitySetFromAttrs` read the canonical `bifrost.*` keys and `time_to_first_chunk` directly (#6403)
<Warning>
Dashboards and alerts that read the legacy `gen_ai.*` Bifrost-internal attributes or the nanosecond TTFT attribute must migrate to the `bifrost.*` keys and `time_to_first_chunk` (seconds).
</Warning>
- feat: add a no-op `HTTPTransportPreAuthHook` for the new pre-authentication transport phase (#6375)
- chore: upgraded core to v1.8.0 and framework to v1.6.0
2 changes: 1 addition & 1 deletion plugins/otel/version
Original file line number Diff line number Diff line change
@@ -1 +1 @@
1.4.9
1.5.0
3 changes: 2 additions & 1 deletion plugins/prompts/changelog.md
Original file line number Diff line number Diff line change
@@ -1 +1,2 @@
- chore: upgraded core to v1.7.11 and framework to v1.5.9
- feat: add a no-op `HTTPTransportPreAuthHook` for the new pre-authentication transport phase (#6375)
- chore: upgraded core to v1.8.0 and framework to v1.6.0
2 changes: 1 addition & 1 deletion plugins/prompts/version
Original file line number Diff line number Diff line change
@@ -1 +1 @@
1.0.37
1.1.0
2 changes: 2 additions & 0 deletions plugins/routing/changelog.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,2 @@
- feat: initial release: the routing rules engine (`rules/`) and the complexity router (`complexity/`) are extracted from the governance plugin into a dedicated routing plugin that depends on governance through a small `Governance` interface; it runs at priority 5, after governance has stamped the virtual key scope, and calls `PublishRoutingAllowlist` and `LoadBalanceProvider` after rule evaluation so both act on the post-rule model (the `HasRules` early return moved into `applyRoutingRules` so provider materialization still runs with no rules configured); routing rules and complexity analyzer config endpoints are served by `RoutingHandler` at `/api/routing/rules` and `/api/routing/complexity-analyzer-config`, with the legacy `/api/governance/*` paths registered as deprecated aliases on the same handlers (#6144, #6145, #6146)
- feat: complexity routing extracts text from mixed-modality user turns (text plus image, file or audio blocks) instead of skipping the turn, and still produces no input for turns with no text at all (#6253)
4 changes: 2 additions & 2 deletions plugins/semanticcache/changelog.md
Original file line number Diff line number Diff line change
@@ -1,2 +1,2 @@
- feat: account for prompt guardrail cost in cache search (#4931)
- chore: upgraded core to v1.7.11 and framework to v1.5.9
- feat: add a no-op `HTTPTransportPreAuthHook` for the new pre-authentication transport phase (#6375)
- chore: upgraded core to v1.8.0 and framework to v1.6.0
2 changes: 1 addition & 1 deletion plugins/semanticcache/version
Original file line number Diff line number Diff line change
@@ -1 +1 @@
1.5.37
1.6.0
Loading
Loading