Skip to content

Define model provider validation once - #522

Merged
SaladDay merged 1 commit into
aos/cutoverfrom
aos/r2b-model-provider
Oct 7, 2026
Merged

SaladDay merged 1 commit into
aos/cutoverfrom
aos/r2b-model-provider

Conversation

@SaladDay

@SaladDay SaladDay commented Oct 7, 2026 •

Copy link
Copy Markdown
Collaborator

internal/modelprovider owns the only model-provider rule, and Core and the Runtime both apply it.

  • Provider.Validate(loopbackHTTP bool) checks the base URL (HTTPS with the IDNA host rule moved from v1, plus the anthropic base path), protocol, API key and token limits, and returns a typed *FieldError. Only the Harness preparation of the credential gateway's listener passes true. Core admission, agent-host admission and the gateway's upstream relay all reject plain http.
  • v1.ModelProviderInput.Validate maps the rejected field to the existing public codes and messages. model_provider_admission.go, Protocol.ValidBasePath, Registry.SupportsProtocol and the Codex config writer's re-check are deleted.
  • model-execution.md (+zh) states the rule once, and core-errors.md links to it.

Not a wire change, so proto.Version stays the same. The TypeScript copies in packages/agents-client and Web stay for main's audit item 30-P2.

Checks: modelprovider table test (each rule, both loopback modes), v1, harnessconfig, gateway, codex, agenthost, Core api (TestCoreErrorCatalog) and execution; darwin/windows daemon builds; make check-names check-docs check-ci. Coordinator review (small lane).


View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

internal/modelprovider's Provider.Validate is now the only provider rule. It owns the base URL check, including the HTTPS and IDNA host rule that contracts/agents-api/v1 kept separately, the anthropic base path, the protocol vocabulary, the API key and the token limits, and returns a typed FieldError naming the rejected field. One parameter admits plain http to a loopback IP address: Core and the agent host's upstream admission and gateway reject it, and harnessconfig.Prepare accepts it for the credential gateway listener a view hands its Harness.

v1.ModelProviderInput.Validate maps the field to its existing public code and message, so the error catalog is unchanged. Deleted: v1's model_provider_admission.go and its copies of the key and limit checks, Protocol.ValidBasePath, Registry.SupportsProtocol, the Codex adapter's re-check of a validated provider, and the literal 16384 in the Core error details, which now reads modelprovider.MaxAPIKeyLength. model-execution.md states the rule once, including the loopback http mode, and core-errors.md links to it.
@SaladDay
SaladDay merged commit df44168 into aos/cutover Oct 7, 2026
@SaladDay
SaladDay deleted the aos/r2b-model-provider branch October 7, 2026 18:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant