A delegated child with an explicit base_url (e.g. an Azure OpenAI resource under provider "openai") shared the parent's "openai" credential pool on bare provider equality, and _lease_child_credential bound whatever entry acquire_lease() picked. _swap_credential adopts the entry's base_url as well, so the child was silently rebound to https://api.openai.com/v1, sent the Azure key there, got HTTP 401 and only then fell back (#68237). _resolve_child_credential_pool now requires endpoint coherence on top of provider identity (credential_pool_matches_provider + at least one entry whose base_url matches the child's) for both the shared parent pool and the provider's loaded pool; a mismatched pool is not attached and the child keeps its fixed credential. _lease_child_credential validates the leased entry against the child's base_url and, on a mixed pool, releases the wrong-host lease and leases an endpoint-matching entry by id instead. Entries and adapters without endpoint metadata cannot rebind and are accepted unchanged. Salvaged from #68240 (@oferlaor); the acquire_lease/leased_entry filter parameters and the extra pool-level helper were reduced to the two small delegate-side predicates.
2 lines
9 B
Plaintext
2 lines
9 B
Plaintext
oferlaor
|