Skip to content

feat(models): add ERNIE 4.5 VL 424B A47B - #3586

Merged
steebchen merged 1 commit into
mainfrom
add-ernie-45-vl-424b
Aug 12, 2026
Merged

steebchen merged 1 commit into
mainfrom
add-ernie-45-vl-424b

Conversation

@steebchen

@steebchen steebchen commented Aug 12, 2026 •

Copy link
Copy Markdown
Member

Adds novita/ernie-4.5-vl-424b-a47b to the catalogue — Baidu's multimodal MoE model (424B total, 47B active), 123K context, 16K max output, $0.42/M in and $1.25/M out.

What the deployment actually does

Every flag here was checked against the live endpoint rather than the model card:

  • Tools and JSON output are off. Both are hard 400s upstream — model features function calling not support and does not support feature: structured-outputs.
  • Thinking is off by default and is toggled by the chat template, not by reasoning_effort. Sent on its own, reasoning_effort is ignored; sent alongside the chat-template flag it suppresses reasoning entirely. That is the same shape the DeepSeek V3.2 mapping on this provider already has, so the mapping declares chatTemplateThinkingKey: "enable_thinking" and deliberately keeps reasoning_effort out of supportedParameters.
  • Vision works, but the deployment's own URL fetch only decodes JPEG. A remote PNG comes back as a bare invalid request error (reproduced across three different hosts), while the exact same bytes are accepted as a data: URL. A remote JPEG works fine, and a control model on the same provider handles the same PNG URL without complaint, so this is specific to this deployment.

The gateway change

That last point needed a small change rather than a vision: false lie: a requiresBase64Images mapping flag that makes prepareRequestBody inline remote images as data URLs before the request goes out.

Every non-data: URL goes through processImageUrl with the SSRF guard left on (its default), which is what enforces https-only, blocks internal hostnames and private/reserved/metadata addresses, and refuses redirects. So an http:// URL is rejected outright instead of being quietly forwarded for the provider to fetch on our behalf — the failure mode that would otherwise turn this feature into an SSRF hole. AGENTS.md now states that rule explicitly so the next place that inlines user-supplied content follows it.

The flag is opt-in per mapping, so nothing else in the catalogue changes behaviour.

Verification

  • Scoped e2e green: TEST_MODELS="novita/ernie-4.5-vl-424b-a47b" pnpm test:e2e → 95 passed. The image case lives behind EXPERIMENTAL=true, so that was run too and passes.
  • The flag is load-bearing: with requiresBase64Images flipped off (and the cache flushed) the image e2e case fails with a 400, and passes with it on.
  • New unit spec prepare-request-body.images.spec.ts covers the inlining, the data-URL pass-through, the http rejection path, and the thinking-flag behaviour.
  • pnpm format, pnpm build and pnpm test:unit all run. Two unrelated unit failures reproduce on a clean tree without these changes (one is a hardcoded gateway port that clashes with a per-worktree stack, the other depends on local provider credentials).

🤖 Generated with Claude Code

Summary by CodeRabbit

  • New Features

    • Added support for Baidu’s ERNIE 4.5 VL vision model through the Novita provider.
    • Remote images are securely converted to base64 for models that require it.
    • Added Baidu to the model directory’s open-source filters.
    • Added support for configuring ERNIE reasoning behavior.
  • Bug Fixes

    • Blocked insecure HTTP image URLs and rejected unsafe remote content before forwarding requests.
    • Preserved existing data URLs and non-image content during request preparation.

Adds `novita/ernie-4.5-vl-424b-a47b` to the catalogue — Baidu's multimodal
MoE model (424B total, 47B active), 123K context, 16K max output, $0.42/M
in and $1.25/M out.

Everything was verified live against the provider:

- **Tools and JSON output are off.** Both are hard 400s upstream ("model
  features function calling not support" / "does not support feature:
  structured-outputs").
- **Thinking is off by default and toggled by the chat template.**
  `reasoning_effort` is ignored on its own and, sent alongside the flag,
  suppresses reasoning entirely — the same shape the DeepSeek V3.2 mapping
  on this provider already has. So the mapping declares
  `chatTemplateThinkingKey: "enable_thinking"` and keeps `reasoning_effort`
  out of `supportedParameters`.
- **Vision works, but the deployment's own URL fetch only decodes JPEG.** A
  remote PNG comes back as a bare "invalid request error" while the exact
  same bytes are accepted as a data URL.

That last one needed a small gateway change: a `requiresBase64Images`
mapping flag that makes `prepareRequestBody` inline remote images as data
URLs before the request goes out. Every non-`data:` URL goes through
`processImageUrl` with the SSRF guard left on, so https-only, no internal
hosts and no redirects — an `http://` URL is rejected rather than handed to
the provider to fetch on our behalf. AGENTS.md now spells that rule out so
the next place that inlines user content does the same thing.

Scoped e2e passes (95 tests), including the image case with
`EXPERIMENTAL=true`.
Copilot AI lite review requested due to automatic review settings August 12, 2026 22:22
@steebchen

Copy link
Copy Markdown
Member Author

/e2e

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@coderabbitai

coderabbitai Bot commented Aug 12, 2026 •

Copy link
Copy Markdown
Contributor

Review Change Stack

Walkthrough

Adds Baidu ERNIE 4.5 VL model support through Novita. Remote images are converted to validated base64 data URLs before upstream requests. Tests cover HTTPS, HTTP rejection, data URLs, text content, and reasoning settings.

Changes

Baidu ERNIE integration

Layer / File(s) Summary
Model catalog and provider capability
packages/models/src/models.ts, packages/models/src/models/baidu.ts, packages/shared/src/components/models-directory/model-category-filters.ts
Registers Baidu ERNIE 4.5 VL with Novita metadata, vision support, streaming, reasoning configuration, and base64 image requirements.
Validated image preparation and request behavior
packages/actions/src/prepare-request-body.ts, packages/actions/src/prepare-request-body.images.spec.ts, AGENTS.md
Converts remote image parts through processImageUrl, preserves data URLs and non-image content, rejects unsafe URLs, and tests ERNIE reasoning behavior.

Estimated code review effort: 3 (Moderate) | ~20 minutes

Mergeability Score: ⚪ Minimal · up to f6660

The PR adds the model mapping and narrowly scoped image handling without a remaining actionable merge-blocking risk; it is merge-ready after normal checks and review.

Sequence Diagram(s)

sequenceDiagram
  participant Client
  participant prepareRequestBody
  participant processImageUrl
  participant Novita
  Client->>prepareRequestBody: Submit ERNIE multimodal request
  prepareRequestBody->>processImageUrl: Process remote image URL
  processImageUrl-->>prepareRequestBody: Return validated base64 data URL
  prepareRequestBody->>Novita: Forward prepared request
Loading

Possibly related PRs

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely identifies the addition of the ERNIE 4.5 VL 424B A47B model, which is the main change.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch add-ernie-45-vl-424b

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🧹 Nitpick comments (1)
packages/actions/src/prepare-request-body.images.spec.ts (1)

10-17: 📐 Maintainability & Code Quality | 🔵 Trivial | ⚡ Quick win

Replace the dynamic test imports with static imports.

Use a non-dynamic mock or spy for processImageUrl, and preserve both processImageUrl and ImageSizeLimitError, which prepare-request-body.ts imports.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@packages/actions/src/prepare-request-body.images.spec.ts` around lines 10 -
17, Update the test setup around prepareRequestBody to use static imports
instead of importing prepare-request-body.js dynamically. Replace the async
vi.mock factory with a static-compatible mock or spy for processImageUrl, while
preserving the real processImageUrl and ImageSizeLimitError exports required by
prepare-request-body.ts.

Source: Coding guidelines

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Nitpick comments:
In `@packages/actions/src/prepare-request-body.images.spec.ts`:
- Around line 10-17: Update the test setup around prepareRequestBody to use
static imports instead of importing prepare-request-body.js dynamically. Replace
the async vi.mock factory with a static-compatible mock or spy for
processImageUrl, while preserving the real processImageUrl and
ImageSizeLimitError exports required by prepare-request-body.ts.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 25dd248e-4f9d-49bc-bfa2-831a5e51014a

📥 Commits

Reviewing files that changed from the base of the PR and between 53b111e and f6660a8.

📒 Files selected for processing (6)
  • AGENTS.md
  • packages/actions/src/prepare-request-body.images.spec.ts
  • packages/actions/src/prepare-request-body.ts
  • packages/models/src/models.ts
  • packages/models/src/models/baidu.ts
  • packages/shared/src/components/models-directory/model-category-filters.ts

@steebchen

Copy link
Copy Markdown
Member Author

/e2e

@steebchen
steebchen merged commit 3e603ed into main Aug 12, 2026
12 checks passed
@steebchen
steebchen deleted the add-ernie-45-vl-424b branch August 12, 2026 23:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants