0ef5fcb1c5
Security / Dependency audit (pip-audit) (push) Has been cancelled
Security / CodeQL (javascript-typescript) (push) Has been cancelled
Security / CodeQL (python) (push) Has been cancelled
Security / Secret scan (gitleaks) (push) Has been cancelled
rust / test (ubuntu) (push) Has been cancelled
rust / simulator e2e (macos-latest) (push) Has been cancelled
rust / simulator e2e (ubuntu-latest) (push) Has been cancelled
rust / simulator e2e (windows-latest) (push) Has been cancelled
rust / wheels (aarch64-apple-darwin) (push) Has been cancelled
rust / wheels (x86_64-unknown-linux-gnu) (push) Has been cancelled
rust / wheels (x86_64-apple-darwin) (push) Has been cancelled
rust / audit (push) Has been cancelled
rust / parity (nightly, allowed to fail during Phase 0) (push) Has been cancelled
CI / commitlint (push) Has been skipped
Dev Containers / validate (.devcontainer/devcontainer.json, default) (push) Failing after 0s
Dev Containers / validate (.devcontainer/memory-stack/devcontainer.json, memory-stack) (push) Failing after 0s
Dev Containers / validate-worktree (push) Failing after 0s
CI / changes (push) Failing after 4s
Deploy Documentation / validate (push) Has been skipped
Deploy Documentation / deploy (push) Failing after 1s
Init Native E2E / init-native (ubuntu-latest, claude) (push) Failing after 1s
Init Native E2E / init-native (ubuntu-latest, codex) (push) Failing after 1s
Install Native E2E / install-native (ubuntu-latest) (push) Failing after 1s
OpenCode Plugin / typecheck + build + test (push) Failing after 1s
Init Native E2E / init-native (ubuntu-latest, copilot) (push) Failing after 1s
Release Please / release-please (push) Failing after 1s
Wrap E2E / docker-wrap-e2e (push) Failing after 1s
Wrap Native E2E / wrap-native (ubuntu-latest) (push) Failing after 1s
Init E2E / docker-init-e2e (push) Failing after 4s
Merge Conflicts / merge-conflicts (push) Failing after 4s
CI / lint (push) Has been cancelled
CI / build-wheel (push) Has been cancelled
CI / build-wheel-windows (push) Has been cancelled
CI / prefetch-model (push) Has been cancelled
CI / test-dashboard-ui (push) Has been cancelled
CI / test (1) (push) Has been cancelled
CI / test (2) (push) Has been cancelled
CI / test (3) (push) Has been cancelled
CI / test (4) (push) Has been cancelled
CI / test-extras (push) Has been cancelled
CI / test-agno (push) Has been cancelled
CI / build (push) Has been cancelled
CI / workflow-validation (push) Has been cancelled
CI / docker-native-e2e (push) Has been cancelled
CI / windows-native-wrapper (push) Has been cancelled
CI / macos-native-wrapper (push) Has been cancelled
Docker / docker-build (map[name:arm64 platform:linux/arm64 runs_on:ubuntu-24.04-arm], map[bake_target:runtime-code-nonroot name:code-nonroot]) (push) Has been cancelled
Docker / docker-build (map[name:arm64 platform:linux/arm64 runs_on:ubuntu-24.04-arm], map[bake_target:runtime-code-slim name:code-slim]) (push) Has been cancelled
Docker / docker-build (map[name:arm64 platform:linux/arm64 runs_on:ubuntu-24.04-arm], map[bake_target:runtime-code-slim-nonroot name:code-slim-nonroot]) (push) Has been cancelled
Docker / docker-build (map[name:arm64 platform:linux/arm64 runs_on:ubuntu-24.04-arm], map[bake_target:runtime-nonroot name:nonroot]) (push) Has been cancelled
Docker / docker-build (map[name:arm64 platform:linux/arm64 runs_on:ubuntu-24.04-arm], map[bake_target:runtime-slim name:slim]) (push) Has been cancelled
Docker / docker-build (map[name:arm64 platform:linux/arm64 runs_on:ubuntu-24.04-arm], map[bake_target:runtime-slim-nonroot name:slim-nonroot]) (push) Has been cancelled
Docker / docker-manifest (map[bake_target:runtime name:]) (push) Has been cancelled
Docker / docker-manifest (map[bake_target:runtime-code name:code]) (push) Has been cancelled
Docker / docker-manifest (map[bake_target:runtime-code-nonroot name:code-nonroot]) (push) Has been cancelled
Docker / docker-manifest (map[bake_target:runtime-code-slim name:code-slim]) (push) Has been cancelled
Docker / docker-manifest (map[bake_target:runtime-code-slim-nonroot name:code-slim-nonroot]) (push) Has been cancelled
Docker / docker-manifest (map[bake_target:runtime-nonroot name:nonroot]) (push) Has been cancelled
Docker / docker-manifest (map[bake_target:runtime-slim name:slim]) (push) Has been cancelled
Docker / docker-manifest (map[bake_target:runtime-slim-nonroot name:slim-nonroot]) (push) Has been cancelled
Docker / docker-build (map[name:amd64 platform:linux/amd64 runs_on:ubuntu-24.04], map[bake_target:runtime name:]) (push) Has been cancelled
Docker / docker-build (map[name:amd64 platform:linux/amd64 runs_on:ubuntu-24.04], map[bake_target:runtime-code name:code]) (push) Has been cancelled
Docker / docker-build (map[name:amd64 platform:linux/amd64 runs_on:ubuntu-24.04], map[bake_target:runtime-code-nonroot name:code-nonroot]) (push) Has been cancelled
Docker / docker-build (map[name:amd64 platform:linux/amd64 runs_on:ubuntu-24.04], map[bake_target:runtime-code-slim name:code-slim]) (push) Has been cancelled
Docker / docker-build (map[name:amd64 platform:linux/amd64 runs_on:ubuntu-24.04], map[bake_target:runtime-code-slim-nonroot name:code-slim-nonroot]) (push) Has been cancelled
Docker / docker-build (map[name:amd64 platform:linux/amd64 runs_on:ubuntu-24.04], map[bake_target:runtime-nonroot name:nonroot]) (push) Has been cancelled
Docker / docker-build (map[name:amd64 platform:linux/amd64 runs_on:ubuntu-24.04], map[bake_target:runtime-slim name:slim]) (push) Has been cancelled
Docker / docker-build (map[name:amd64 platform:linux/amd64 runs_on:ubuntu-24.04], map[bake_target:runtime-slim-nonroot name:slim-nonroot]) (push) Has been cancelled
Docker / docker-build (map[name:arm64 platform:linux/arm64 runs_on:ubuntu-24.04-arm], map[bake_target:runtime name:]) (push) Has been cancelled
Docker / docker-build (map[name:arm64 platform:linux/arm64 runs_on:ubuntu-24.04-arm], map[bake_target:runtime-code name:code]) (push) Has been cancelled
Docker / promote-latest (push) Has been cancelled
Init Native E2E / init-native (macos-latest, claude) (push) Has been cancelled
Init Native E2E / init-native (macos-latest, codex) (push) Has been cancelled
Init Native E2E / init-native (macos-latest, copilot) (push) Has been cancelled
Install Native E2E / install-native (macos-latest) (push) Has been cancelled
Wrap Native E2E / wrap-native (macos-latest) (push) Has been cancelled
112 lines
3.7 KiB
Python
112 lines
3.7 KiB
Python
"""Byte-faithful outbound request body forwarding policy.
|
|
|
|
This module owns the small algebra used by Python proxy forwarders to decide
|
|
which bytes leave Headroom:
|
|
|
|
* unmutated body with original bytes -> byte-for-byte passthrough
|
|
* mutated body or missing original bytes -> canonical JSON bytes
|
|
* explicit rollback mode -> legacy httpx-style JSON bytes
|
|
"""
|
|
|
|
from __future__ import annotations
|
|
|
|
import json
|
|
import os
|
|
from dataclasses import dataclass
|
|
from typing import Any, Literal
|
|
|
|
from headroom.proxy import python_forwarder_mode_policy
|
|
|
|
_PYTHON_FORWARDER_MODE_ENV = python_forwarder_mode_policy.PYTHON_FORWARDER_MODE_ENV
|
|
|
|
PythonForwarderMode = python_forwarder_mode_policy.PythonForwarderMode
|
|
OutboundBodySource = Literal["passthrough", "canonical", "legacy"]
|
|
|
|
_PYTHON_FORWARDER_MODE_DEFAULT = python_forwarder_mode_policy.PYTHON_FORWARDER_MODE_DEFAULT
|
|
|
|
|
|
@dataclass(frozen=True, slots=True)
|
|
class OutboundBody:
|
|
"""Concrete outbound body bytes plus their provenance."""
|
|
|
|
content: bytes
|
|
source: OutboundBodySource
|
|
|
|
|
|
def get_python_forwarder_mode() -> PythonForwarderMode:
|
|
"""Return the active Python-forwarder mode.
|
|
|
|
Read at request time. Unknown values raise loudly per the no-silent-
|
|
fallback build constraint. The ``legacy_json_kwarg`` value is an
|
|
explicit operator opt-in for emergency rollback, not a fallback.
|
|
"""
|
|
return python_forwarder_mode_policy.resolve_python_forwarder_mode(
|
|
os.environ.get(_PYTHON_FORWARDER_MODE_ENV)
|
|
)
|
|
|
|
|
|
def serialize_body_canonical(body: dict[str, Any]) -> bytes:
|
|
"""Re-serialize a request body deterministically with cache-stable formatting."""
|
|
return json.dumps(body, separators=(",", ":"), ensure_ascii=False).encode("utf-8")
|
|
|
|
|
|
class BodyMutationTracker:
|
|
"""Records whether a request body was mutated and why."""
|
|
|
|
__slots__ = ("_mutated", "_reasons")
|
|
|
|
def __init__(self) -> None:
|
|
self._mutated: bool = False
|
|
self._reasons: list[str] = []
|
|
|
|
def mark_mutated(self, reason: str) -> None:
|
|
"""Mark the body as mutated and record the stable aggregation reason."""
|
|
if not reason:
|
|
raise ValueError("BodyMutationTracker.mark_mutated: reason must be non-empty")
|
|
self._mutated = True
|
|
if reason not in self._reasons:
|
|
self._reasons.append(reason)
|
|
|
|
@property
|
|
def mutated(self) -> bool:
|
|
return self._mutated
|
|
|
|
@property
|
|
def reasons(self) -> list[str]:
|
|
return list(self._reasons)
|
|
|
|
|
|
def select_outbound_body(
|
|
*,
|
|
body: dict[str, Any],
|
|
original_body_bytes: bytes | None,
|
|
body_mutated: bool,
|
|
forwarder_mode: PythonForwarderMode | None = None,
|
|
) -> OutboundBody:
|
|
"""Select the exact bytes to forward upstream."""
|
|
mode = forwarder_mode if forwarder_mode is not None else get_python_forwarder_mode()
|
|
if mode == "legacy_json_kwarg":
|
|
content = json.dumps(body, separators=(", ", ": "), ensure_ascii=True).encode("utf-8")
|
|
return OutboundBody(content=content, source="legacy")
|
|
|
|
if body_mutated or original_body_bytes is None:
|
|
return OutboundBody(content=serialize_body_canonical(body), source="canonical")
|
|
return OutboundBody(content=original_body_bytes, source="passthrough")
|
|
|
|
|
|
def prepare_outbound_body_bytes(
|
|
*,
|
|
body: dict[str, Any],
|
|
original_body_bytes: bytes | None,
|
|
body_mutated: bool,
|
|
forwarder_mode: PythonForwarderMode | None = None,
|
|
) -> tuple[bytes, OutboundBodySource]:
|
|
"""Compatibility tuple wrapper around :func:`select_outbound_body`."""
|
|
outbound = select_outbound_body(
|
|
body=body,
|
|
original_body_bytes=original_body_bytes,
|
|
body_mutated=body_mutated,
|
|
forwarder_mode=forwarder_mode,
|
|
)
|
|
return outbound.content, outbound.source
|