0ef5fcb1c5
Security / Dependency audit (pip-audit) (push) Has been cancelled
Security / CodeQL (javascript-typescript) (push) Has been cancelled
Security / CodeQL (python) (push) Has been cancelled
Security / Secret scan (gitleaks) (push) Has been cancelled
rust / test (ubuntu) (push) Has been cancelled
rust / simulator e2e (macos-latest) (push) Has been cancelled
rust / simulator e2e (ubuntu-latest) (push) Has been cancelled
rust / simulator e2e (windows-latest) (push) Has been cancelled
rust / wheels (aarch64-apple-darwin) (push) Has been cancelled
rust / wheels (x86_64-unknown-linux-gnu) (push) Has been cancelled
rust / wheels (x86_64-apple-darwin) (push) Has been cancelled
rust / audit (push) Has been cancelled
rust / parity (nightly, allowed to fail during Phase 0) (push) Has been cancelled
CI / commitlint (push) Has been skipped
Dev Containers / validate (.devcontainer/devcontainer.json, default) (push) Failing after 0s
Dev Containers / validate (.devcontainer/memory-stack/devcontainer.json, memory-stack) (push) Failing after 0s
Dev Containers / validate-worktree (push) Failing after 0s
CI / changes (push) Failing after 4s
Deploy Documentation / validate (push) Has been skipped
Deploy Documentation / deploy (push) Failing after 1s
Init Native E2E / init-native (ubuntu-latest, claude) (push) Failing after 1s
Init Native E2E / init-native (ubuntu-latest, codex) (push) Failing after 1s
Install Native E2E / install-native (ubuntu-latest) (push) Failing after 1s
OpenCode Plugin / typecheck + build + test (push) Failing after 1s
Init Native E2E / init-native (ubuntu-latest, copilot) (push) Failing after 1s
Release Please / release-please (push) Failing after 1s
Wrap E2E / docker-wrap-e2e (push) Failing after 1s
Wrap Native E2E / wrap-native (ubuntu-latest) (push) Failing after 1s
Init E2E / docker-init-e2e (push) Failing after 4s
Merge Conflicts / merge-conflicts (push) Failing after 4s
CI / lint (push) Has been cancelled
CI / build-wheel (push) Has been cancelled
CI / build-wheel-windows (push) Has been cancelled
CI / prefetch-model (push) Has been cancelled
CI / test-dashboard-ui (push) Has been cancelled
CI / test (1) (push) Has been cancelled
CI / test (2) (push) Has been cancelled
CI / test (3) (push) Has been cancelled
CI / test (4) (push) Has been cancelled
CI / test-extras (push) Has been cancelled
CI / test-agno (push) Has been cancelled
CI / build (push) Has been cancelled
CI / workflow-validation (push) Has been cancelled
CI / docker-native-e2e (push) Has been cancelled
CI / windows-native-wrapper (push) Has been cancelled
CI / macos-native-wrapper (push) Has been cancelled
Docker / docker-build (map[name:arm64 platform:linux/arm64 runs_on:ubuntu-24.04-arm], map[bake_target:runtime-code-nonroot name:code-nonroot]) (push) Has been cancelled
Docker / docker-build (map[name:arm64 platform:linux/arm64 runs_on:ubuntu-24.04-arm], map[bake_target:runtime-code-slim name:code-slim]) (push) Has been cancelled
Docker / docker-build (map[name:arm64 platform:linux/arm64 runs_on:ubuntu-24.04-arm], map[bake_target:runtime-code-slim-nonroot name:code-slim-nonroot]) (push) Has been cancelled
Docker / docker-build (map[name:arm64 platform:linux/arm64 runs_on:ubuntu-24.04-arm], map[bake_target:runtime-nonroot name:nonroot]) (push) Has been cancelled
Docker / docker-build (map[name:arm64 platform:linux/arm64 runs_on:ubuntu-24.04-arm], map[bake_target:runtime-slim name:slim]) (push) Has been cancelled
Docker / docker-build (map[name:arm64 platform:linux/arm64 runs_on:ubuntu-24.04-arm], map[bake_target:runtime-slim-nonroot name:slim-nonroot]) (push) Has been cancelled
Docker / docker-manifest (map[bake_target:runtime name:]) (push) Has been cancelled
Docker / docker-manifest (map[bake_target:runtime-code name:code]) (push) Has been cancelled
Docker / docker-manifest (map[bake_target:runtime-code-nonroot name:code-nonroot]) (push) Has been cancelled
Docker / docker-manifest (map[bake_target:runtime-code-slim name:code-slim]) (push) Has been cancelled
Docker / docker-manifest (map[bake_target:runtime-code-slim-nonroot name:code-slim-nonroot]) (push) Has been cancelled
Docker / docker-manifest (map[bake_target:runtime-nonroot name:nonroot]) (push) Has been cancelled
Docker / docker-manifest (map[bake_target:runtime-slim name:slim]) (push) Has been cancelled
Docker / docker-manifest (map[bake_target:runtime-slim-nonroot name:slim-nonroot]) (push) Has been cancelled
Docker / docker-build (map[name:amd64 platform:linux/amd64 runs_on:ubuntu-24.04], map[bake_target:runtime name:]) (push) Has been cancelled
Docker / docker-build (map[name:amd64 platform:linux/amd64 runs_on:ubuntu-24.04], map[bake_target:runtime-code name:code]) (push) Has been cancelled
Docker / docker-build (map[name:amd64 platform:linux/amd64 runs_on:ubuntu-24.04], map[bake_target:runtime-code-nonroot name:code-nonroot]) (push) Has been cancelled
Docker / docker-build (map[name:amd64 platform:linux/amd64 runs_on:ubuntu-24.04], map[bake_target:runtime-code-slim name:code-slim]) (push) Has been cancelled
Docker / docker-build (map[name:amd64 platform:linux/amd64 runs_on:ubuntu-24.04], map[bake_target:runtime-code-slim-nonroot name:code-slim-nonroot]) (push) Has been cancelled
Docker / docker-build (map[name:amd64 platform:linux/amd64 runs_on:ubuntu-24.04], map[bake_target:runtime-nonroot name:nonroot]) (push) Has been cancelled
Docker / docker-build (map[name:amd64 platform:linux/amd64 runs_on:ubuntu-24.04], map[bake_target:runtime-slim name:slim]) (push) Has been cancelled
Docker / docker-build (map[name:amd64 platform:linux/amd64 runs_on:ubuntu-24.04], map[bake_target:runtime-slim-nonroot name:slim-nonroot]) (push) Has been cancelled
Docker / docker-build (map[name:arm64 platform:linux/arm64 runs_on:ubuntu-24.04-arm], map[bake_target:runtime name:]) (push) Has been cancelled
Docker / docker-build (map[name:arm64 platform:linux/arm64 runs_on:ubuntu-24.04-arm], map[bake_target:runtime-code name:code]) (push) Has been cancelled
Docker / promote-latest (push) Has been cancelled
Init Native E2E / init-native (macos-latest, claude) (push) Has been cancelled
Init Native E2E / init-native (macos-latest, codex) (push) Has been cancelled
Init Native E2E / init-native (macos-latest, copilot) (push) Has been cancelled
Install Native E2E / install-native (macos-latest) (push) Has been cancelled
Wrap Native E2E / wrap-native (macos-latest) (push) Has been cancelled
263 lines
8.7 KiB
Python
263 lines
8.7 KiB
Python
"""HTTP-level tests for CCR retrieve-tool interception on /v1/responses (#1877).
|
|
|
|
`handle_openai_responses` previously had zero CCR/headroom_retrieve wiring:
|
|
a `headroom_retrieve` function_call in a Responses API reply passed straight
|
|
through to the client, which typically can't resolve it (see issue #1877).
|
|
These tests exercise the new interception mirrored from the chat-completions
|
|
backend path (`handle_openai_chat` ~2775-2848) — see
|
|
tests/test_proxy/test_openai_backend_path.py for that precedent.
|
|
"""
|
|
|
|
from __future__ import annotations
|
|
|
|
import json
|
|
|
|
import pytest
|
|
|
|
fastapi = pytest.importorskip("fastapi")
|
|
httpx = pytest.importorskip("httpx")
|
|
|
|
from unittest.mock import AsyncMock, MagicMock # noqa: E402
|
|
|
|
from fastapi.testclient import TestClient # noqa: E402
|
|
|
|
from headroom.cache.compression_store import reset_compression_store # noqa: E402
|
|
from headroom.ccr.tool_injection import CCR_TOOL_NAME # noqa: E402
|
|
from headroom.proxy.loopback_guard import require_loopback # noqa: E402
|
|
from headroom.proxy.server import ProxyConfig, create_app # noqa: E402
|
|
|
|
_RETRIEVE_TOOL = {
|
|
"type": "function",
|
|
"name": CCR_TOOL_NAME,
|
|
"description": "Retrieve original content.",
|
|
"parameters": {
|
|
"type": "object",
|
|
"properties": {"hash": {"type": "string"}},
|
|
"required": ["hash"],
|
|
},
|
|
}
|
|
|
|
|
|
@pytest.fixture(autouse=True)
|
|
def _reset_store():
|
|
reset_compression_store()
|
|
yield
|
|
reset_compression_store()
|
|
|
|
|
|
def _make_app():
|
|
config = ProxyConfig(
|
|
optimize=False,
|
|
cache_enabled=False,
|
|
rate_limit_enabled=False,
|
|
cost_tracking_enabled=False,
|
|
)
|
|
app = create_app(config)
|
|
app.dependency_overrides[require_loopback] = lambda: None
|
|
return app
|
|
|
|
|
|
def _tool_call_response(url: str, hash_key: str = "abc123def456abc123def456") -> httpx.Response:
|
|
return httpx.Response(
|
|
200,
|
|
json={
|
|
"id": "resp_1",
|
|
"object": "response",
|
|
"status": "completed",
|
|
"output": [
|
|
{
|
|
"type": "function_call",
|
|
"id": "fc_1",
|
|
"call_id": "call_1",
|
|
"name": CCR_TOOL_NAME,
|
|
"arguments": json.dumps({"hash": hash_key}),
|
|
},
|
|
],
|
|
"usage": {"input_tokens": 50, "output_tokens": 10},
|
|
},
|
|
request=httpx.Request("POST", url),
|
|
)
|
|
|
|
|
|
def _final_response(url: str) -> httpx.Response:
|
|
return httpx.Response(
|
|
200,
|
|
json={
|
|
"id": "resp_2",
|
|
"object": "response",
|
|
"status": "completed",
|
|
"output": [
|
|
{
|
|
"type": "message",
|
|
"role": "assistant",
|
|
"content": [{"type": "output_text", "text": "Resolved!"}],
|
|
}
|
|
],
|
|
"usage": {"input_tokens": 60, "output_tokens": 5},
|
|
},
|
|
request=httpx.Request("POST", url),
|
|
)
|
|
|
|
|
|
def _install_two_call_retry(app, hash_key: str = "abc123def456abc123def456"):
|
|
"""First upstream call returns a headroom_retrieve function_call, second the resolved reply."""
|
|
server = app.state.proxy
|
|
calls: list[dict] = []
|
|
|
|
async def fake_retry(method, url, headers, body, stream=False, **kwargs):
|
|
calls.append({"method": method, "url": url, "headers": dict(headers), "body": body})
|
|
if len(calls) == 1:
|
|
return _tool_call_response(url, hash_key)
|
|
return _final_response(url)
|
|
|
|
server._retry_request = fake_retry
|
|
return calls
|
|
|
|
|
|
def test_non_streaming_ccr_tool_call_is_intercepted_and_resolved():
|
|
"""A headroom_retrieve function_call in a non-streaming reply is resolved server-side."""
|
|
app = _make_app()
|
|
with TestClient(app) as client:
|
|
server = app.state.proxy
|
|
calls = _install_two_call_retry(app)
|
|
|
|
recording_handler = MagicMock()
|
|
recording_handler.has_ccr_tool_calls = MagicMock(return_value=True)
|
|
recording_handler.handle_response = AsyncMock(
|
|
return_value={
|
|
"id": "resp_2",
|
|
"object": "response",
|
|
"status": "completed",
|
|
"output": [
|
|
{
|
|
"type": "message",
|
|
"role": "assistant",
|
|
"content": [{"type": "output_text", "text": "Resolved!"}],
|
|
}
|
|
],
|
|
}
|
|
)
|
|
server.ccr_response_handler = recording_handler
|
|
|
|
resp = client.post(
|
|
"/v1/responses",
|
|
json={
|
|
"model": "gpt-5-codex",
|
|
"input": "please look this up",
|
|
"tools": [_RETRIEVE_TOOL],
|
|
"stream": False,
|
|
},
|
|
headers={"Authorization": "Bearer sk-test"},
|
|
)
|
|
|
|
assert resp.status_code == 200, resp.text
|
|
# Only the initial upstream call happened — continuation is owned by
|
|
# the (mocked) handle_response, not a second real _retry_request call.
|
|
assert len(calls) == 1
|
|
recording_handler.handle_response.assert_awaited_once()
|
|
_args, kwargs = recording_handler.handle_response.call_args
|
|
assert kwargs.get("provider") == "openai_responses"
|
|
body = resp.json()
|
|
assert body["output"][0]["content"][0]["text"] == "Resolved!"
|
|
# The unresolved function_call must not leak to the client.
|
|
assert not any(item.get("type") == "function_call" for item in body["output"])
|
|
|
|
|
|
def test_ccr_intercept_exception_is_reraised_not_swallowed():
|
|
"""CCR resolution failure -> 502, NOT a silent fallback to the unresolved tool_call body."""
|
|
app = _make_app()
|
|
with TestClient(app) as client:
|
|
server = app.state.proxy
|
|
_install_two_call_retry(app)
|
|
|
|
failing_handler = MagicMock()
|
|
failing_handler.has_ccr_tool_calls = MagicMock(return_value=True)
|
|
failing_handler.handle_response = AsyncMock(side_effect=RuntimeError("ccr-store-blew-up"))
|
|
server.ccr_response_handler = failing_handler
|
|
|
|
resp = client.post(
|
|
"/v1/responses",
|
|
json={
|
|
"model": "gpt-5-codex",
|
|
"input": "please look this up",
|
|
"tools": [_RETRIEVE_TOOL],
|
|
"stream": False,
|
|
},
|
|
headers={"Authorization": "Bearer sk-test"},
|
|
)
|
|
|
|
failing_handler.handle_response.assert_awaited_once()
|
|
assert resp.status_code == 502, resp.text
|
|
body = resp.json()
|
|
assert "function_call" not in json.dumps(body)
|
|
|
|
|
|
def test_streaming_request_with_retrieve_tool_buffers_upstream_and_streams_final_result():
|
|
"""stream:true + headroom_retrieve in tools -> forced buffered stream:false upstream."""
|
|
app = _make_app()
|
|
with TestClient(app) as client:
|
|
server = app.state.proxy
|
|
calls = _install_two_call_retry(app)
|
|
|
|
async def _unexpected_stream_response(*args, **kwargs):
|
|
raise AssertionError(
|
|
"_stream_response should not be called when headroom_retrieve "
|
|
"forces the buffered CCR path"
|
|
)
|
|
|
|
server._stream_response = _unexpected_stream_response
|
|
|
|
resp = client.post(
|
|
"/v1/responses",
|
|
json={
|
|
"model": "gpt-5-codex",
|
|
"input": "please look this up",
|
|
"tools": [_RETRIEVE_TOOL],
|
|
"stream": True,
|
|
},
|
|
headers={"Authorization": "Bearer sk-test"},
|
|
)
|
|
|
|
assert resp.status_code == 200, resp.text
|
|
assert resp.headers["content-type"].startswith("text/event-stream")
|
|
# Both upstream calls (initial + CCR continuation) went out with
|
|
# stream forced False so the retrieval round-trip could complete.
|
|
assert len(calls) == 2
|
|
assert calls[0]["body"]["stream"] is False
|
|
assert calls[1]["body"]["stream"] is False
|
|
assert "response.completed" in resp.text
|
|
assert "Resolved!" in resp.text
|
|
|
|
|
|
def test_streaming_request_without_retrieve_tool_uses_normal_stream_path():
|
|
"""No headroom_retrieve in tools -> unaffected, still goes through _stream_response."""
|
|
app = _make_app()
|
|
with TestClient(app) as client:
|
|
server = app.state.proxy
|
|
|
|
stream_called = {"value": False}
|
|
|
|
async def fake_stream_response(*args, **kwargs):
|
|
stream_called["value"] = True
|
|
from fastapi.responses import StreamingResponse
|
|
|
|
async def _gen():
|
|
yield b"data: {}\n\n"
|
|
|
|
return StreamingResponse(_gen(), media_type="text/event-stream")
|
|
|
|
server._stream_response = fake_stream_response
|
|
|
|
resp = client.post(
|
|
"/v1/responses",
|
|
json={
|
|
"model": "gpt-5-codex",
|
|
"input": "hello",
|
|
"stream": True,
|
|
},
|
|
headers={"Authorization": "Bearer sk-test"},
|
|
)
|
|
|
|
assert resp.status_code == 200, resp.text
|
|
assert stream_called["value"] is True
|