Draft: encrypted-reasoning entitlement probe (split from #18) - #19
Draft
BlockedPath wants to merge 3 commits into
Draft
BlockedPath wants to merge 3 commits into
BlockedPath wants to merge 3 commits into
Conversation
Signing in through /login meta and calling the API returned HTTP 400 "reasoning `encrypted_content` was not issued to this caller": keys minted via /muse-code/key are not entitled to encrypted reasoning replay, but pi injects include: ["reasoning.encrypted_content"] for reasoning models. applyMetaResponsesCacheHints now filters it out of the responses payload (keeping any other include entries and the 24h prompt-cache retention).
Keys minted through /muse-code/key are not always entitled to reasoning.encrypted_content; requesting it when unentitled is a fatal HTTP 400, but the current key is entitled and carries cross-turn reasoning continuity (the docs-recommended behavior). Hard-coding either outcome is wrong. The provider now probes each key once per process (tiny /v1/responses call with the include and max_output_tokens 16): 200 = entitled, 400 mentioning encrypted_content = not entitled, anything else = inconclusive (retried after a cooldown). The before_provider_request hook keeps the include when the key is entitled and strips it otherwise, so requests never 400 while keeping reasoning replay whenever Meta allows it.
|
Important Draft PR not reviewedDraft PRs are not automatically reviewed by default.
To automatically review draft PRs, update your CodeRabbit configuration: reviews:
auto_review:
drafts: trueThanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Deferred work split from #18 — not ready to merge
Preserves Antonio Correa's three encrypted-reasoning commits (with original authorship) separately from the Pi 0.85 compatibility update merged in #18. Rebased onto
mainafter that merge, preserving #13's max-effort support.This draft contains only:
The compatibility fix is already on
mainand is not part of this diff.Required before leaving draft
include: ["reasoning.encrypted_content"]alone does not remove historicalinput[].encrypted_contentproduced from Pi thinking signatures. Add multi-turn/resumed-session wire tests, preserving ordinary messages and tool calls.lastAttemptAtsuppresses probing a newly selected key for five minutes after the previous key. Add immediate key-rotation, transient-error, and hook-level tests.The issues above were demonstrated using mocked requests during review of #18; they have deliberately NOT been fixed or approved in this preservation-only split. Original review: #18 (review)