Skip to main content

supercode_runtime/
provider.rs

1//! The model transport.
2//!
3//! [`OpenAiProvider`] speaks the OpenAI chat-completions wire format and
4//! defaults to OpenRouter, so a single implementation reaches Claude, GPT,
5//! Gemini, Llama, and anything else OpenRouter (or another OpenAI-compatible
6//! gateway) exposes. Streaming is used so callers can render tokens live.
7
8use std::collections::HashMap;
9use std::time::Duration;
10
11use async_trait::async_trait;
12use futures::StreamExt;
13use serde::{Deserialize, Serialize};
14
15use supercode_interchange::{ChatMessage, FunctionCall, Role, ToolCall};
16
17use crate::{CachePlan, ChatRequest, Result, RuntimeError as Error, ToolSchema, Usage};
18
19/// Bounds TCP/TLS establishment for the provider HTTP client. Matches
20/// `doctor`'s 10 s timeout (`crates/cli/src/main.rs`) for consistency.
21const CONNECT_TIMEOUT: Duration = Duration::from_secs(10);
22
23/// Per-read-operation idle timeout. Resets on every received chunk, so a live
24/// SSE stream emitting deltas is never killed — only a silent connection (no
25/// bytes for the window, including a server that accepts but never sends
26/// response headers) errors out. Generous enough for slow time-to-first-token,
27/// small enough to unstick a dead connection well within one agent turn.
28const READ_IDLE_TIMEOUT: Duration = Duration::from_secs(120);
29
30/// Maximum number of retries for the *initial* request (so at most
31/// `MAX_RETRIES + 1` attempts total). Only connection-level failures and 5xx
32/// responses are retried; once SSE streaming has begun, errors propagate as-is.
33const MAX_RETRIES: u32 = 2;
34
35/// Base backoff between retries; the delay for attempt `n` (0-indexed) is
36/// `RETRY_BACKOFF_BASE * 2^n` (no jitter — not needed at this scale).
37const RETRY_BACKOFF_BASE: Duration = Duration::from_millis(500);
38
39/// Crate-internal knobs for the provider's HTTP client and retry behavior.
40/// `connect_timeout`/`read_idle_timeout` stay test-only overrides (no
41/// `Config`/CLI surface); `max_retries`/`retry_backoff_base` gained one via
42/// [`Self::from_retry_config`] (P4b, §1.1/§3.1 `core.retry`) — see that
43/// constructor's doc comment.
44#[derive(Debug, Clone, Copy)]
45#[doc(hidden)]
46pub struct HttpOptions {
47    pub(crate) connect_timeout: Duration,
48    pub(crate) read_idle_timeout: Duration,
49    pub(crate) max_retries: u32,
50    pub(crate) retry_backoff_base: Duration,
51}
52
53impl Default for HttpOptions {
54    fn default() -> Self {
55        HttpOptions {
56            connect_timeout: CONNECT_TIMEOUT,
57            read_idle_timeout: READ_IDLE_TIMEOUT,
58            max_retries: MAX_RETRIES,
59            retry_backoff_base: RETRY_BACKOFF_BASE,
60        }
61    }
62}
63
64impl HttpOptions {
65    /// P4b (design §5.2 "P4", §1.1/§3.1 `core.retry`, pi§3 naming
66    /// precedent): derive the transport's retry behavior from
67    /// [`crate::Config`]'s `retry_*` fields, keeping every other
68    /// [`HttpOptions`] field at its built-in default. `enabled = false`
69    /// (a NEW capability — today's transport retry has no off-switch) forces
70    /// `max_retries` to `0`; `enabled = true` (the [`crate::Config`] default,
71    /// matching today's always-on behavior) keeps retrying, using
72    /// `max_retries`/`base_delay_ms` to OVERRIDE the built-in
73    /// [`MAX_RETRIES`]/[`RETRY_BACKOFF_BASE`] when `Some`, else leaving them
74    /// untouched — so a `Config` that sets none of the three `retry_*`
75    /// fields (today's only reachable shape, pre-P4b) produces an
76    /// [`HttpOptions`] byte-identical to [`HttpOptions::default`].
77    #[doc(hidden)]
78    pub fn from_retry_config(
79        enabled: bool,
80        max_retries: Option<u32>,
81        base_delay_ms: Option<u64>,
82    ) -> HttpOptions {
83        let base = HttpOptions::default();
84        HttpOptions {
85            max_retries: if enabled {
86                max_retries.unwrap_or(base.max_retries)
87            } else {
88                0
89            },
90            retry_backoff_base: base_delay_ms
91                .map(Duration::from_millis)
92                .unwrap_or(base.retry_backoff_base),
93            ..base
94        }
95    }
96}
97
98/// BP-7 (catalog §4a "Auto-retry on transient provider errors"): one
99/// transient failure the transport retried.
100///
101/// The retry loop itself is unchanged and pre-existing; before BP-7 it was
102/// simply SILENT — the ledger row's residue was "no retry record is
103/// persisted, so a retried request is invisible to the event stream, the
104/// transcript, and `--trace`". A notice is recorded the moment the loop
105/// decides to sleep and try again.
106#[derive(Debug, Clone, PartialEq, Eq)]
107pub struct RetryNotice {
108    /// 0-based index of the attempt that FAILED (attempt 0 is the first try).
109    pub attempt: u32,
110    /// Backoff slept before the next attempt, milliseconds.
111    pub delay_ms: u64,
112    /// One-line reason — an HTTP status line or a transport error.
113    pub reason: String,
114}
115
116/// A shared, drainable buffer of [`RetryNotice`]s.
117///
118/// Wired as an `Arc` the agent and the provider both hold, rather than a
119/// callback on the [`Provider`] trait: the provider is built inside
120/// `Agent::new`, long before an event sink is installed, and every mock
121/// provider in the test suite would otherwise have to grow a method it does
122/// not use. The agent drains this after each `complete()` call, so notices
123/// always attach to the round-trip that produced them.
124#[derive(Debug, Default)]
125pub struct RetryLog {
126    notices: std::sync::Mutex<Vec<RetryNotice>>,
127}
128
129impl RetryLog {
130    /// Record one retry.
131    pub fn record(&self, notice: RetryNotice) {
132        self.notices
133            .lock()
134            .unwrap_or_else(std::sync::PoisonError::into_inner)
135            .push(notice);
136    }
137
138    /// Take everything recorded so far, leaving the log empty.
139    pub fn drain(&self) -> Vec<RetryNotice> {
140        std::mem::take(
141            &mut *self
142                .notices
143                .lock()
144                .unwrap_or_else(std::sync::PoisonError::into_inner),
145        )
146    }
147}
148
149/// Build the JSON request body for an OpenAI-compatible chat-completions call.
150/// Exposed (crate-internal) so the wire shape can be unit-tested without a
151/// network round-trip.
152pub(crate) fn build_request_body(req: &ChatRequest, stream: bool) -> serde_json::Value {
153    use serde_json::json;
154    let mut body = json!({
155        "model": req.model,
156        "messages": req.messages,
157        "stream": stream,
158    });
159    let obj = body.as_object_mut().unwrap();
160    if !req.tools.is_empty() {
161        obj.insert(
162            "tools".into(),
163            serde_json::to_value(req.tools.iter().map(WireTool::from).collect::<Vec<_>>()).unwrap(),
164        );
165    }
166    if let Some(t) = req.temperature {
167        obj.insert("temperature".into(), json!(t));
168    }
169    if let Some(m) = req.max_tokens {
170        obj.insert("max_tokens".into(), json!(m));
171    }
172    if let Some(e) = &req.effort {
173        obj.insert("reasoning_effort".into(), json!(e));
174    }
175    if let Some(rf) = &req.response_format {
176        obj.insert("response_format".into(), rf.clone());
177    }
178    // BP-13 (D9 "Fast mode / service tiers"): the priority/fast variant
179    // toggle, sent as the OpenAI-compatible `service_tier` field.
180    if let Some(tier) = &req.service_tier {
181        obj.insert("service_tier".into(), json!(tier));
182    }
183    // BP-13 (D9 "Reasoning effort / thinking budgets"): the BUDGET half.
184    // `reasoning_effort` above carries the LEVEL; the token cap rides the
185    // unified `reasoning` object, which is how an OpenAI-compatible gateway
186    // spells Anthropic's `thinking.budget_tokens` and OpenAI's reasoning
187    // cap under one name. Merged into any `reasoning` object a caller
188    // already placed via `extra_body` (which still wins last, below).
189    if let Some(budget) = req.thinking_budget {
190        let entry = obj
191            .entry("reasoning".to_string())
192            .or_insert_with(|| json!({}));
193        if let Some(o) = entry.as_object_mut() {
194            o.insert("max_tokens".into(), json!(budget));
195        }
196    }
197    if stream {
198        obj.insert("stream_options".into(), json!({"include_usage": true}));
199    }
200    // Provider-native passthrough wins last (lets callers override anything).
201    for (k, v) in &req.extra_body {
202        obj.insert(k.clone(), v.clone());
203    }
204    body
205}
206
207/// SPEC.md B7: annotate a CLONE of `messages` with Anthropic-style
208/// `cache_control: {"type":"ephemeral"}` prompt-cache breakpoints, message-level
209/// (never the top-level `extra_body` passthrough `build_request_body` supports
210/// for other provider knobs — OpenRouter's Anthropic cache keys off per-message
211/// `cache_control` inside the `content` array, so only this placement can say
212/// where the stable prefix ends).
213///
214/// `imported_prefix_len` counts leading messages of `messages` (from index 0,
215/// inclusive of the system message) that make up the stable, byte-identical-
216/// across-turns prefix — a caller's own leading system message plus every
217/// message of a previously-imported session (`Agent::load_session`). Under
218/// [`CachePlan::ImportedPrefix`], two breakpoints are placed (Anthropic allows
219/// up to 4): `messages[0]` (the system message) and
220/// `messages[imported_prefix_len - 1]` (the LAST message of the imported
221/// prefix) — deduplicated when they're the same index. Each target message's
222/// `content` moves into `content_parts` form with a trailing
223/// `{"type":"text","text":…,"cache_control":{"type":"ephemeral"}}` part; an
224/// already-multimodal message gets the annotation on its LAST existing text
225/// part instead of growing a new one.
226///
227/// [`CachePlan::Off`] (or a missing/zero `imported_prefix_len`) returns an
228/// unannotated clone. Either way this never mutates `messages` in place — the
229/// purity requirement (SPEC.md B7-AC2) that `Agent::history` and the sidecar
230/// never see `cache_control` depends on this being a read-only projection over
231/// a caller-owned copy, never the retained history itself.
232#[doc(hidden)]
233pub fn apply_cache_plan(
234    messages: &[ChatMessage],
235    plan: CachePlan,
236    imported_prefix_len: Option<usize>,
237) -> Vec<ChatMessage> {
238    let mut out = messages.to_vec();
239    if !matches!(plan, CachePlan::ImportedPrefix) {
240        return out;
241    }
242    let Some(len) = imported_prefix_len.filter(|&n| n > 0) else {
243        return out;
244    };
245    let last = len - 1;
246    let mut targets = vec![0usize];
247    if last != 0 {
248        targets.push(last);
249    }
250    for idx in targets {
251        if let Some(msg) = out.get_mut(idx) {
252            annotate_cache_breakpoint(msg);
253        }
254    }
255    out
256}
257
258/// Move `msg`'s text content into an ephemeral-cache-annotated
259/// `content_parts` entry — see [`apply_cache_plan`].
260fn annotate_cache_breakpoint(msg: &mut ChatMessage) {
261    let cache_control = serde_json::json!({"type": "ephemeral"});
262    if let Some(parts) = msg.content_parts.as_mut() {
263        // Already multimodal: annotate the LAST existing text part.
264        if let Some(text_part) = parts
265            .iter_mut()
266            .rev()
267            .find(|p| p.get("type").and_then(serde_json::Value::as_str) == Some("text"))
268        {
269            if let Some(obj) = text_part.as_object_mut() {
270                obj.insert("cache_control".to_string(), cache_control);
271            }
272        }
273        return;
274    }
275    let text = msg.content.take().unwrap_or_default();
276    msg.content_parts = Some(vec![serde_json::json!({
277        "type": "text",
278        "text": text,
279        "cache_control": cache_control,
280    })]);
281}
282
283/// TR-8 (T5): whether the advertised tool-schema tier configuration changed
284/// since the last request this agent built. Under [`CachePlan::ImportedPrefix`]
285/// this is a cache-bust event: the `tools` array sent alongside `messages` is
286/// part of the cache key on the prompt-caching implementations this plan
287/// targets, so a byte-identical imported-message prefix does not, on its
288/// own, guarantee a cache hit once the advertised schema set has been
289/// reshaped by a tier change.
290///
291/// `previous` is `None` on an agent's very first request (nothing to have
292/// busted yet), so this only ever fires from the second request onward, and
293/// only for the one request immediately after the change — the caller
294/// (`Agent::build_request_messages`) is expected to record the new signature
295/// right after consulting this, so the NEXT request (same tier) is not
296/// flagged again.
297#[doc(hidden)]
298pub fn tier_change_is_cache_bust(previous: Option<u64>, current: u64) -> bool {
299    previous.is_some_and(|p| p != current)
300}
301
302/// UX-26 (B7-warn): Anthropic's default ephemeral prompt-cache TTL, in
303/// seconds. Every breakpoint supercode places
304/// ([`annotate_cache_breakpoint`]) is `{"type":"ephemeral"}` — never the
305/// extended 1-hour-beta `ttl` field — so 5 minutes is the correct assumption
306/// for every cache-annotated request this binary sends (Anthropic's
307/// documented default TTL for an ephemeral breakpoint with no `ttl` set).
308pub(crate) const CACHE_TTL_SECS: i64 = 300;
309
310/// UX-26: cache-read ratio below which a completed, reuse-expected turn is
311/// treated as an unexpected miss rather than provider-side rounding/paging
312/// noise. Anthropic bills cache reads as an exact token count (not an
313/// estimate), so a genuine warm hit reports at or near 100% of the
314/// protected prefix's tokens; anything under 10% reflects a real miss.
315pub(crate) const CACHE_MISS_RATIO_THRESHOLD: f64 = 0.10;
316
317/// UX-26 T1 (accuracy fold-in): cache-read ratio at/above which a completed
318/// turn's OWN `usage` is strong enough evidence to override an
319/// idle-time-based [`CacheColdReason::Stale`] verdict. `idle_secs` is a
320/// cross-process, timestamp-derived signal (see `cache_cold_reason`'s doc
321/// comment) that can be stale itself — e.g. a sibling process re-resumes the
322/// SAME original session file (whose on-disk timestamps never advance) and
323/// warms the identical prefix within the TTL; this process's `idle_secs`
324/// still reads as "past the TTL" even though the provider just proved
325/// otherwise. Deliberately the exact mirror of
326/// [`CACHE_MISS_RATIO_THRESHOLD`] (`1.0 -` that bar) rather than reusing it
327/// directly: reusing 10% (i.e. "disprove whenever it's not already a Miss")
328/// would let a merely-ambiguous ratio — e.g. 50%, no stronger evidence of
329/// warmth than of staleness — silently swallow a genuinely cold turn. 90%
330/// demands the same "at or near 100%" standard the Miss check already uses
331/// to call a hit warm, applied in the opposite direction, so a turn only
332/// suppresses `Stale` when its own usage affirmatively looks warm — not
333/// merely "not obviously a miss."
334pub(crate) const CACHE_STALE_DISPROVE_RATIO_THRESHOLD: f64 = 1.0 - CACHE_MISS_RATIO_THRESHOLD;
335
336/// UX-26 T2 (accuracy fold-in): whether `model` is Anthropic-family, i.e.
337/// whether [`CacheColdReason::message`]'s Anthropic-shaped wording (a fixed
338/// 5-minute ephemeral TTL, cache-read ratio semantics) actually describes
339/// the provider this request is going to. Every resolved model slug this
340/// binary sends is either an OpenRouter-style `vendor/model` slug — see
341/// `userconfig::alias_table` and [`KNOWN_MODEL_CONTEXT_LIMITS`], which both
342/// use the exact same `"anthropic/…"` shape as the one and only Anthropic
343/// prefix — or, for a caller pointed directly at Anthropic's own API via
344/// `--base-url`, a bare `claude-…` slug with no vendor prefix at all (that
345/// endpoint doesn't use OpenRouter's vendor-prefixed naming). Both forms are
346/// unambiguous: no other vendor slug in this codebase starts with `claude`.
347///
348/// This is intentionally narrower than "could plausibly be Anthropic" — an
349/// unrecognized custom slug is NOT assumed Anthropic (mirrors
350/// [`model_context_limit`]'s "unknown is never assumed favorable" stance) —
351/// so this only ever narrows the warning, never broadens it past what T1's
352/// accuracy bar already allows.
353#[doc(hidden)]
354pub fn is_anthropic_family_model(model: &str) -> bool {
355    model.starts_with("anthropic/") || model.starts_with("claude-") || model.starts_with("claude/")
356}
357
358/// UX-26 (B7-warn): why a completed, reuse-expected turn likely paid a
359/// full-price prompt-cache miss. See [`cache_cold_reason`].
360#[derive(Debug, Clone, Copy, PartialEq)]
361#[doc(hidden)]
362pub enum CacheColdReason {
363    /// This turn was sent `idle_secs` after the cache entry was last
364    /// established/refreshed — at or beyond [`CACHE_TTL_SECS`], so the
365    /// provider has almost certainly already evicted it. Computable
366    /// pre-send (doesn't need `usage`).
367    Stale {
368        /// Seconds since the cache entry was last known warm.
369        idle_secs: i64,
370    },
371    /// The provider's own usage reported `cached_tokens` out of
372    /// `prompt_tokens` — below [`CACHE_MISS_RATIO_THRESHOLD`] despite reuse
373    /// being expected, and NOT already explained by [`Self::Stale`] (this
374    /// turn was sent inside the TTL window).
375    Miss {
376        /// Tokens the provider reports as served from cache.
377        cached_tokens: u64,
378        /// Total prompt (input) tokens for this turn.
379        prompt_tokens: u64,
380    },
381}
382
383impl CacheColdReason {
384    /// Render as the ready-to-print stderr line (no trailing newline).
385    #[doc(hidden)]
386    pub fn message(&self) -> String {
387        match self {
388            CacheColdReason::Stale { idle_secs } => format!(
389                "cache likely cold — this turn was sent {}m{:02}s after the cache was last \
390                 refreshed (Anthropic's ephemeral prompt cache expires after 5m idle) — this \
391                 turn likely paid full input cost for the cached prefix",
392                idle_secs / 60,
393                idle_secs % 60,
394            ),
395            CacheColdReason::Miss {
396                cached_tokens,
397                prompt_tokens,
398            } => format!(
399                "unexpected cache miss — only {cached_tokens}/{prompt_tokens} prompt tokens \
400                 were served from cache this turn even though reuse was expected — this turn \
401                 likely paid full input cost for the cached prefix",
402            ),
403        }
404    }
405}
406
407/// UX-26 (B7-warn, dev/01+dev/02): whether a completed turn likely paid a
408/// full-price cache miss.
409///
410/// Takes two INDEPENDENT preconditions rather than one combined
411/// "reuse expected" flag, because they cover genuinely different turns:
412///
413/// - `will_annotate`: THIS request actually carries a
414///   [`CachePlan::ImportedPrefix`] `cache_control` breakpoint (not a
415///   same-turn tool-schema-tier bust, not `CachePlan::Off`). Gates BOTH
416///   checks below — with no annotation there was never anything to reuse,
417///   by construction.
418/// - `cache_established`: a PRIOR request already placed that same
419///   breakpoint (in THIS process, or inferred from `idle_secs` having a
420///   value at all — see below). Gates ONLY the [`CacheColdReason::Miss`]
421///   check: on the very FIRST annotated request for a prefix, the provider
422///   legitimately reports ~0 cached tokens (it's establishing the entry,
423///   not reusing it) — reporting that as a "miss" would be a false
424///   positive on every resume's opening turn.
425///
426/// [`CacheColdReason::Stale`] deliberately does NOT require
427/// `cache_established`: `idle_secs` itself is derived (by the caller,
428/// `Agent::build_request_messages`) from the RESUMED SESSION's own last
429/// message timestamp when this agent has never sent a request yet — a
430/// cross-process signal of how long the prefix has sat untouched by ANY
431/// tool. That is precisely the flagship case (`docs/jcode-ux-parity.md`
432/// §6c.1): a session idle for 20 minutes, resumed, and its very first turn
433/// in supercode is a foregone cold read — which is exactly when the user
434/// most needs the heads-up, not only on turn 2+. `idle_secs` is `None`
435/// whenever no such signal exists (a session with no parseable timestamp),
436/// so this never guesses.
437///
438/// Checks [`CacheColdReason::Stale`] before [`CacheColdReason::Miss`] (needs
439/// the completed `usage`, so only consulted once elapsed time is inside the
440/// TTL window) so a genuinely stale turn is never double-reported.
441///
442/// UX-26 T1 (accuracy fold-in): `Stale` is nominally computable pre-send
443/// (from `idle_secs` alone), but `usage` — for the very turn about to be
444/// reported `Stale` — is always in hand by the time this fn actually runs
445/// (the caller only has a completed `usage` to give it). When that usage
446/// affirmatively PROVES the turn was warm (cache-read ratio at/above
447/// [`CACHE_STALE_DISPROVE_RATIO_THRESHOLD`] — see its doc comment for why
448/// that bar, not [`CACHE_MISS_RATIO_THRESHOLD`], is used here), the
449/// idle-clock-based `Stale` verdict is disproven and suppressed: a stale
450/// *clock* reading doesn't mean a stale *cache* when the provider's own
451/// billed usage says otherwise. Usage that's absent, unparseable, or merely
452/// ambiguous (below the disprove bar but not a `Miss` either) offers no such
453/// disproof, so `Stale` still fires exactly as before.
454#[doc(hidden)]
455pub fn cache_cold_reason(
456    will_annotate: bool,
457    cache_established: bool,
458    idle_secs: Option<i64>,
459    usage: &Usage,
460) -> Option<CacheColdReason> {
461    if !will_annotate {
462        return None;
463    }
464    if let Some(idle_secs) = idle_secs {
465        if idle_secs >= CACHE_TTL_SECS {
466            let disproven_by_usage = usage
467                .prompt_tokens_details
468                .filter(|_| usage.prompt_tokens > 0)
469                .is_some_and(|details| {
470                    details.cached_tokens as f64 / usage.prompt_tokens as f64
471                        >= CACHE_STALE_DISPROVE_RATIO_THRESHOLD
472                });
473            if !disproven_by_usage {
474                return Some(CacheColdReason::Stale { idle_secs });
475            }
476        }
477    }
478    if !cache_established {
479        // First annotated request for this prefix: a legitimate cold WRITE,
480        // never a "miss" — nothing to compare `usage` against.
481        return None;
482    }
483    let details = usage.prompt_tokens_details?;
484    if usage.prompt_tokens == 0 {
485        // Nothing was actually read as prompt input this turn (unusual, but
486        // possible for a degenerate request) — no signal either way.
487        return None;
488    }
489    let ratio = details.cached_tokens as f64 / usage.prompt_tokens as f64;
490    if ratio < CACHE_MISS_RATIO_THRESHOLD {
491        return Some(CacheColdReason::Miss {
492            cached_tokens: details.cached_tokens,
493            prompt_tokens: usage.prompt_tokens,
494        });
495    }
496    None
497}
498
499/// The transport abstraction. Implement this to back the agent with something
500/// other than an OpenAI-compatible HTTP endpoint (a local model, a mock, etc.).
501#[async_trait]
502pub trait Provider: Send + Sync {
503    /// Run one completion. `on_delta` is called with each text chunk as it
504    /// streams in. Returns the fully assembled assistant message and usage.
505    async fn complete(
506        &self,
507        req: &ChatRequest,
508        on_delta: &(dyn for<'a> Fn(&'a str) + Send + Sync),
509    ) -> Result<(ChatMessage, Usage)>;
510}
511
512/// An OpenAI-compatible HTTP provider. The composition layer supplies its
513/// endpoint, credentials, and headers from runtime configuration.
514pub struct OpenAiProvider {
515    client: reqwest::Client,
516    base_url: String,
517    api_key: String,
518    extra_headers: HashMap<String, String>,
519    http_options: HttpOptions,
520    /// BP-7: where [`Self::send_with_retry`] reports the retries it makes.
521    /// `None` (the default for every constructor caller that does not opt
522    /// in) keeps the loop byte-identical to its pre-BP-7 behavior.
523    retry_log: Option<std::sync::Arc<RetryLog>>,
524}
525
526impl OpenAiProvider {
527    /// Construct a provider for the given endpoint and key.
528    pub fn new(
529        base_url: impl Into<String>,
530        api_key: impl Into<String>,
531        extra_headers: HashMap<String, String>,
532    ) -> Self {
533        Self::new_with_options(base_url, api_key, extra_headers, HttpOptions::default())
534    }
535
536    /// Same as [`Self::new`] but with crate-internal HTTP timeout/retry
537    /// options — used by tests to shrink timeouts and backoff so they run
538    /// fast. Not part of the public API (no `Config`/CLI surface for these
539    /// knobs).
540    #[doc(hidden)]
541    pub fn new_with_options(
542        base_url: impl Into<String>,
543        api_key: impl Into<String>,
544        extra_headers: HashMap<String, String>,
545        http_options: HttpOptions,
546    ) -> Self {
547        OpenAiProvider {
548            client: reqwest::Client::builder()
549                .connect_timeout(http_options.connect_timeout)
550                .read_timeout(http_options.read_idle_timeout)
551                .build()
552                .expect("static reqwest client config cannot fail"),
553            base_url: base_url.into(),
554            api_key: api_key.into(),
555            extra_headers,
556            http_options,
557            retry_log: None,
558        }
559    }
560
561    /// BP-7: report every retry this provider makes into `log`, which the
562    /// caller drains after each completion (see [`RetryLog`]).
563    pub fn with_retry_log(mut self, log: std::sync::Arc<RetryLog>) -> Self {
564        self.retry_log = Some(log);
565        self
566    }
567
568    fn endpoint(&self) -> String {
569        format!("{}/chat/completions", self.base_url.trim_end_matches('/'))
570    }
571
572    /// Send the initial request, retrying connection-level failures and 5xx
573    /// responses with backoff. 4xx (and any other non-success, non-5xx)
574    /// statuses return immediately, unretried. Once a 2xx response is
575    /// received it is returned as-is for the caller to stream; this loop
576    /// never runs again for the lifetime of that response (no mid-stream
577    /// retry/resume).
578    async fn send_with_retry(&self, wire: &serde_json::Value) -> Result<reqwest::Response> {
579        let mut attempt = 0u32;
580        loop {
581            let mut builder = self
582                .client
583                .post(self.endpoint())
584                .bearer_auth(&self.api_key)
585                .header("Content-Type", "application/json");
586            for (k, v) in &self.extra_headers {
587                builder = builder.header(k, v);
588            }
589
590            let sent = builder.json(wire).send().await;
591            let (retryable, result): (bool, Result<reqwest::Response>) = match sent {
592                Err(e) => (true, Err(Error::from(e))),
593                Ok(resp) => {
594                    let status = resp.status();
595                    if status.is_success() {
596                        (false, Ok(resp))
597                    } else if status.is_server_error() {
598                        let body = resp.text().await.unwrap_or_default();
599                        (
600                            true,
601                            Err(Error::Provider {
602                                status: status.as_u16(),
603                                body: truncate(&body, 2000),
604                            }),
605                        )
606                    } else {
607                        let body = resp.text().await.unwrap_or_default();
608                        (
609                            false,
610                            Err(Error::Provider {
611                                status: status.as_u16(),
612                                body: truncate(&body, 2000),
613                            }),
614                        )
615                    }
616                }
617            };
618
619            if !retryable || attempt >= self.http_options.max_retries {
620                return result;
621            }
622            let backoff = self.http_options.retry_backoff_base * 2u32.pow(attempt);
623            // BP-7: recorded at the decision point — after "this is
624            // retryable and we have attempts left", before the sleep — so
625            // the notice exists even if the process dies during the
626            // backoff.
627            if let Some(log) = &self.retry_log {
628                log.record(RetryNotice {
629                    attempt,
630                    delay_ms: backoff.as_millis() as u64,
631                    reason: match &result {
632                        Err(e) => e.to_string(),
633                        Ok(_) => String::new(),
634                    },
635                });
636            }
637            tokio::time::sleep(backoff).await;
638            attempt += 1;
639        }
640    }
641}
642
643#[async_trait]
644impl Provider for OpenAiProvider {
645    async fn complete(
646        &self,
647        req: &ChatRequest,
648        on_delta: &(dyn for<'a> Fn(&'a str) + Send + Sync),
649    ) -> Result<(ChatMessage, Usage)> {
650        let wire = build_request_body(req, true);
651
652        let resp = self.send_with_retry(&wire).await?;
653
654        let mut acc = Accumulator::default();
655        // Buffer raw bytes, not a lossy-decoded String: network chunks split at
656        // arbitrary byte offsets, so decoding each chunk independently would turn
657        // any multi-byte UTF-8 scalar straddling a boundary into replacement
658        // characters. We only decode *complete* SSE lines (terminated by '\n',
659        // an ASCII byte that can never fall inside a multi-byte sequence).
660        let mut buf: Vec<u8> = Vec::new();
661        let mut deltas: Vec<String> = Vec::new();
662        let mut stream = resp.bytes_stream();
663        while let Some(chunk) = stream.next().await {
664            let bytes = chunk?;
665            buf.extend_from_slice(&bytes);
666            drain_sse_lines(&mut buf, &mut acc, &mut deltas)?;
667            for d in deltas.drain(..) {
668                on_delta(&d);
669            }
670        }
671        // Flush any trailing buffered line (no terminating newline).
672        let tail = String::from_utf8_lossy(&buf);
673        if !tail.trim().is_empty() {
674            handle_sse_line(tail.trim(), &mut acc, &mut deltas)?;
675            for d in deltas.drain(..) {
676                on_delta(&d);
677            }
678        }
679
680        Ok((acc.to_message(), acc_usage(&acc)))
681    }
682}
683
684// ---- streaming assembly ---------------------------------------------------
685
686#[derive(Default)]
687struct Accumulator {
688    content: String,
689    tool_calls: Vec<ToolCallAccum>,
690    usage: Usage,
691    /// BP-13 (D9 "Model-served-vs-requested provenance"): the `model` field
692    /// the PROVIDER put on its own response frames — the model that actually
693    /// answered, which a gateway is free to make differ from the one asked
694    /// for (aliasing, routing, a silently pinned snapshot).
695    served_model: Option<String>,
696}
697
698#[derive(Default)]
699struct ToolCallAccum {
700    id: String,
701    name: String,
702    arguments: String,
703}
704
705impl Accumulator {
706    fn ensure(&mut self, index: usize) -> &mut ToolCallAccum {
707        while self.tool_calls.len() <= index {
708            self.tool_calls.push(ToolCallAccum::default());
709        }
710        &mut self.tool_calls[index]
711    }
712
713    fn to_message(&self) -> ChatMessage {
714        let calls: Vec<ToolCall> = self
715            .tool_calls
716            .iter()
717            .filter(|c| !c.id.is_empty() || !c.name.is_empty())
718            .map(|c| ToolCall {
719                id: c.id.clone(),
720                kind: "function".to_string(),
721                function: FunctionCall {
722                    name: c.name.clone(),
723                    arguments: c.arguments.clone(),
724                },
725            })
726            .collect();
727        ChatMessage {
728            role: Role::Assistant,
729            content: (!self.content.is_empty()).then(|| self.content.clone()),
730            content_parts: None,
731            tool_calls: (!calls.is_empty()).then_some(calls),
732            tool_call_id: None,
733            name: None,
734            metadata: match &self.served_model {
735                Some(model) => {
736                    let mut m = std::collections::BTreeMap::new();
737                    m.insert(SERVED_MODEL_KEY.to_string(), model.clone());
738                    m
739                }
740                None => Default::default(),
741            },
742        }
743    }
744}
745
746/// Metadata key carrying the model the PROVIDER said served a response —
747/// distinct from `"model"`, which every caller sets to the model it
748/// REQUESTED. Present only when the response actually reported one.
749pub const SERVED_MODEL_KEY: &str = "served_model";
750
751fn acc_usage(acc: &Accumulator) -> Usage {
752    acc.usage.clone()
753}
754
755fn drain_sse_lines(
756    buf: &mut Vec<u8>,
757    acc: &mut Accumulator,
758    deltas: &mut Vec<String>,
759) -> Result<()> {
760    while let Some(pos) = buf.iter().position(|&b| b == b'\n') {
761        let line: Vec<u8> = buf.drain(..=pos).collect();
762        let line = String::from_utf8_lossy(&line);
763        handle_sse_line(line.trim(), acc, deltas)?;
764    }
765    Ok(())
766}
767
768fn handle_sse_line(line: &str, acc: &mut Accumulator, deltas: &mut Vec<String>) -> Result<()> {
769    let Some(data) = line.strip_prefix("data:") else {
770        return Ok(());
771    };
772    let data = data.trim();
773    if data.is_empty() || data == "[DONE]" {
774        return Ok(());
775    }
776    let chunk: StreamChunk = match serde_json::from_str(data) {
777        Ok(c) => c,
778        Err(_) => return Ok(()), // tolerate keep-alive / partial frames
779    };
780    if let Some(u) = chunk.usage {
781        acc.usage = u;
782    }
783    if let Some(model) = chunk.model {
784        if !model.is_empty() {
785            acc.served_model = Some(model);
786        }
787    }
788    for choice in chunk.choices {
789        if let Some(text) = choice.delta.content {
790            if !text.is_empty() {
791                acc.content.push_str(&text);
792                deltas.push(text);
793            }
794        }
795        for tc in choice.delta.tool_calls.unwrap_or_default() {
796            let slot = acc.ensure(tc.index);
797            if let Some(id) = tc.id {
798                slot.id = id;
799            }
800            if let Some(f) = tc.function {
801                if let Some(name) = f.name {
802                    slot.name.push_str(&name);
803                }
804                if let Some(args) = f.arguments {
805                    slot.arguments.push_str(&args);
806                }
807            }
808        }
809    }
810    Ok(())
811}
812
813fn truncate(s: &str, max: usize) -> String {
814    if s.len() <= max {
815        s.to_string()
816    } else {
817        // Walk back to a char boundary so we never slice mid-codepoint (which
818        // would panic) — provider error bodies can contain non-ASCII text.
819        let mut end = max;
820        while end > 0 && !s.is_char_boundary(end) {
821            end -= 1;
822        }
823        format!("{}…", &s[..end])
824    }
825}
826
827// ---- wire types -----------------------------------------------------------
828
829#[derive(Serialize)]
830struct WireTool<'a> {
831    #[serde(rename = "type")]
832    kind: &'static str,
833    function: WireFunction<'a>,
834}
835
836#[derive(Serialize)]
837struct WireFunction<'a> {
838    name: &'a str,
839    description: &'a str,
840    parameters: &'a serde_json::Value,
841}
842
843impl<'a> From<&'a ToolSchema> for WireTool<'a> {
844    fn from(t: &'a ToolSchema) -> Self {
845        WireTool {
846            kind: "function",
847            function: WireFunction {
848                name: &t.name,
849                description: &t.description,
850                parameters: &t.parameters,
851            },
852        }
853    }
854}
855
856#[derive(Deserialize)]
857struct StreamChunk {
858    #[serde(default)]
859    choices: Vec<StreamChoice>,
860    #[serde(default)]
861    usage: Option<Usage>,
862    /// The model the provider says produced this frame (BP-13 D9
863    /// served-vs-requested provenance).
864    #[serde(default)]
865    model: Option<String>,
866}
867
868#[derive(Deserialize)]
869struct StreamChoice {
870    delta: Delta,
871}
872
873#[derive(Deserialize)]
874struct Delta {
875    #[serde(default)]
876    content: Option<String>,
877    #[serde(default)]
878    tool_calls: Option<Vec<ToolCallDelta>>,
879}
880
881#[derive(Deserialize)]
882struct ToolCallDelta {
883    #[serde(default)]
884    index: usize,
885    #[serde(default)]
886    id: Option<String>,
887    #[serde(default)]
888    function: Option<FnDelta>,
889}
890
891#[derive(Deserialize)]
892struct FnDelta {
893    #[serde(default)]
894    name: Option<String>,
895    #[serde(default)]
896    arguments: Option<String>,
897}