Skip to content

Draft: encrypted-reasoning entitlement probe (split from #18) - #19

Draft
BlockedPath wants to merge 3 commits into
mainfrom
deferred/meta-encrypted-reasoning-probe
Draft

BlockedPath wants to merge 3 commits into
mainfrom
deferred/meta-encrypted-reasoning-probe

Conversation

@BlockedPath

@BlockedPath BlockedPath commented Sep 18, 2026 •

Copy link
Copy Markdown
Owner

Static Badge

Deferred work split from #18 — not ready to merge

Preserves Antonio Correa's three encrypted-reasoning commits (with original authorship) separately from the Pi 0.85 compatibility update merged in #18. Rebased onto main after that merge, preserving #13's max-effort support.

This draft contains only:

  • the encrypted-reasoning entitlement probe and request hook changes;
  • the associated tests;
  • the prompt-cache/encrypted-reasoning documentation.

The compatibility fix is already on main and is not part of this diff.

Required before leaving draft

  • Handle incompatible historical reasoning replay safely. Removing include: ["reasoning.encrypted_content"] alone does not remove historical input[].encrypted_content produced from Pi thinking signatures. Add multi-turn/resumed-session wire tests, preserving ordinary messages and tool calls.
  • Scope probe results and retry cooldowns per API key. The current global lastAttemptAt suppresses probing a newly selected key for five minutes after the previous key. Add immediate key-rotation, transient-error, and hook-level tests.
  • Re-review probe lifecycle, billable-request behavior, and documentation claims against the resulting implementation.
  • Run typechecking and hermetic tests after the fixes. Live Meta probes are billable and should not run in CI.

The issues above were demonstrated using mocked requests during review of #18; they have deliberately NOT been fixed or approved in this preservation-only split. Original review: #18 (review)

Signing in through /login meta and calling the API returned
HTTP 400 "reasoning `encrypted_content` was not issued to this caller":
keys minted via /muse-code/key are not entitled to encrypted reasoning
replay, but pi injects include: ["reasoning.encrypted_content"] for
reasoning models.

applyMetaResponsesCacheHints now filters it out of the responses payload
(keeping any other include entries and the 24h prompt-cache retention).
Keys minted through /muse-code/key are not always entitled to
reasoning.encrypted_content; requesting it when unentitled is a fatal
HTTP 400, but the current key is entitled and carries cross-turn
reasoning continuity (the docs-recommended behavior). Hard-coding either
outcome is wrong.

The provider now probes each key once per process (tiny /v1/responses
call with the include and max_output_tokens 16): 200 = entitled, 400
mentioning encrypted_content = not entitled, anything else = inconclusive
(retried after a cooldown). The before_provider_request hook keeps the
include when the key is entitled and strips it otherwise, so requests
never 400 while keeping reasoning replay whenever Meta allows it.
@coderabbitai

coderabbitai Bot commented Sep 18, 2026

Copy link
Copy Markdown

Important

Draft PR not reviewed

Draft PRs are not automatically reviewed by default.

  • Trigger a manual review

To automatically review draft PRs, update your CodeRabbit configuration:

reviews:
  auto_review:
    drafts: true

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants