standardplugins

package
v0.1.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 5, 2026 License: Apache-2.0 Imports: 82 Imported by: 0

Documentation

Index

Constants

View Source
const (
	CustomOpenAILegacyCompatibleID    = "custom-openai-legacy-compatible"
	CustomOpenAIResponsesCompatibleID = "custom-openai-responses-compatible"
	CustomAnthropicCompatibleID       = "custom-anthropic-compatible"
)
View Source
const (
	ContinuityMarkerKey   = "lip.internal.openai_codex.reasoning_continuity.v1"
	ContinuityMarkerValue = `{"eligible":true,"dialect":"openai.responses.reasoning_item.v1"}`
)
View Source
const CustomOpenResponsesCompatibleID = "custom-openresponses-compatible"

CustomOpenResponsesCompatibleID is the stable built-in-compatible factory kind for the generic remote OpenResponses backend (Requirement 9.1).

View Source
const ProviderProfileKind = "provider-profile"

ProviderProfileKind is the declarative row kind used by the profile contribution. Keeping the identity in the composition source avoids a second provider-profile registry.

View Source
const ReasoningOutputPreservationFeatureID = reasoningpreservation.ID

ReasoningOutputPreservationFeatureID is the standard factory/instance id for reasoning-output-preservation. A matching disabled row is an explicit opt-out.

View Source
const ToolCallRepairFeatureID = toolcallrepair.ID

ToolCallRepairFeatureID is the standard factory/instance id for tool-call repair. Any features config row matching this ID (instance) or FactoryKind suppresses default standard-distribution injection. A present row without enabled: true is an explicit disabled opt-out under plain-bool PluginConfig.Enabled.

Variables

View Source
var ErrCustomBackendPrefix = errors.New("custom backend prefix")

Functions

func BuildProviderProfileBackend

func BuildProviderProfileBackend(
	profile providerprofiles.CompiledProfile,
	instanceID string,
	upstream *http.Client,
	deps pluginreg.BackendFactoryDeps,
) (execbackend.Backend, error)

BuildProviderProfileBackend applies one compiled profile through the existing family adapter strategy.

func CodexCompanionPolicy

func CodexCompanionPolicy() reasoningpreservation.CompanionPolicy

CodexCompanionPolicy returns the standard distribution companion policy. Exported for runtimebundle generation binding.

func CollectBuiltInBackendOwners

func CollectBuiltInBackendOwners(reg *pluginreg.Registry) []pluginreg.BackendOwner

CollectBuiltInBackendOwners returns generation-scoped owners for non-compatible builtin factory kinds. When reg is nil, owners are derived from the essential standard bundle IDs (check-config / pre-registry structural path).

func CollectBuiltinCompatibleKinds

func CollectBuiltinCompatibleKinds(reg *pluginreg.Registry) []string

CollectBuiltinCompatibleKinds returns registered factory ids with built-in-compatible provenance.

func CollectCompatibleAdmissionLimits

func CollectCompatibleAdmissionLimits(rows []config.PluginConfig) (compatibleadmission.Limits, error)

CollectCompatibleAdmissionLimits returns positive per-instance limits for enabled generic-compatible backends keyed by exact runtime backend instance ID.

func CollectEnabledCompatibleOwners

func CollectEnabledCompatibleOwners(rows []config.PluginConfig) ([]pluginreg.BackendOwner, error)

CollectEnabledCompatibleOwners extracts enabled generic-compatible owners and validates backend_prefix syntax. Disabled rows are omitted (enabled-row policy).

func CollectManifestKindOwners

func CollectManifestKindOwners(reg *pluginreg.Registry) []pluginreg.BackendOwner

CollectManifestKindOwners returns owners for discovered external factory kinds available from the registry catalog without process activation.

func CompatibleBackendInstanceRows

func CompatibleBackendInstanceRows(rows []diag.CompatibleBackendRow) []diag.InstanceDiagnostic

CompatibleBackendInstanceRows converts already-projected rows without decoding configuration again. Composition roots should use this when they expose both compatible_backends and instance_diagnostics.

func CompatibleBackendKinds

func CompatibleBackendKinds() []string

CompatibleBackendKinds returns the stable built-in compatible factory ids.

func CompileProviderProfile

func CompileProviderProfile(profile providerprofiles.Profile) (providerprofiles.CompiledProfile, error)

CompileProviderProfile validates and binds one profile to an existing family. It is pure data compilation: no credentials, network, process, or goroutine is involved. The returned binding is an immutable generation input.

func DecodeCompatibleBackendPrefix

func DecodeCompatibleBackendPrefix(kind string, row config.PluginConfig) (string, error)

DecodeCompatibleBackendPrefix returns the enabled-row backend_prefix for any built-in compatible factory kind, dispatching to the kind-specific strict decoder so prefix/instance ownership validation applies to the OpenResponses config surface as well.

func DefaultWireModel

func DefaultWireModel(backendID string) string

DefaultWireModel returns the canonical default upstream model id for a bundled backend factory id.

This mapping is intentionally separate from [*Registry]: the registry holds constructors and mounts; DefaultWireModel encodes standard-distribution routing defaults used when configs omit explicit route selectors (see config.EffectiveDefaultRouteSelector). Alternate bundles may supply a different config.WireModelForBackend via runtimebundle.BuildOptions.WireModel without changing registry factories. It must not be duplicated per frontend handler.

func DerivedViews

func DerivedViews() (contrib.Views, error)

func EnsureReasoningOutputPreservationInConfig

func EnsureReasoningOutputPreservationInConfig(cfg *config.Config, opts ReasoningOutputPreservationInjectOpts) error

EnsureReasoningOutputPreservationInConfig discovers eligible direct Codex instances, then delegates feature-schema mutation to the feature owner.

func EnsureToolCallRepairInConfig

func EnsureToolCallRepairInConfig(cfg *config.Config, opts ToolCallRepairInjectOpts) error

func EssentialBackendKinds

func EssentialBackendKinds() []string

EssentialBackendKinds derives the built-in allowlist from contributions. Optional connector identities never enter this view.

func ExpandProviderProfileRows

func ExpandProviderProfileRows(cfg *config.Config) (*config.Config, error)

ExpandProviderProfileRows resolves profile references into the existing compatible-family factory rows. Only rows explicitly using ProviderProfileKind are changed; arbitrary custom-compatible rows retain their exact config. The operation is deterministic and performs no provider activation.

func ExpandProviderProfileRowsWithCatalog

func ExpandProviderProfileRowsWithCatalog(cfg *config.Config, catalog *providerprofiles.Catalog) (*config.Config, error)

ExpandProviderProfileRowsWithCatalog resolves profile references against the provided catalog.

func InstallBundleOn

func InstallBundleOn(reg *pluginreg.Registry, b Bundle) error

InstallBundleOn registers b on reg. Tests and alternate composition roots can pass a custom bundle without mutating package-level globals.

func InstallEssentialBackendsOn

func InstallEssentialBackendsOn(reg *pluginreg.Registry, keys UpstreamAPIKeys) error

InstallEssentialBackendsOn registers only the final essential backend table on reg. Frontends and features remain on InstallStandardBundleOn.

func InstallStandardBackendsOn

func InstallStandardBackendsOn(reg *pluginreg.Registry, keys UpstreamAPIKeys) error

InstallStandardBackendsOn registers only bundled backend factories on reg (minimal partial bundles).

func InstallStandardBundleOn

func InstallStandardBundleOn(reg *pluginreg.Registry, keys UpstreamAPIKeys) error

InstallStandardBundleOn registers all standard bundled factories on reg (tests, alternate bundles). keys supplies default API key material when plugin YAML omits api_key (typically from ResolveUpstreamAPIKeysFromEnv at process startup); tests may pass a zero value.

func IsCustomCompatibleBackendKind

func IsCustomCompatibleBackendKind(kind string) bool

func IsEssentialBackendKind

func IsEssentialBackendKind(id string) bool

IsEssentialBackendKind reports whether id is in the final essential allowlist.

func IsOpenResponsesCompatibleBackendKind

func IsOpenResponsesCompatibleBackendKind(id string) bool

IsOpenResponsesCompatibleBackendKind reports whether id is the generic OpenResponses built-in-compatible factory kind.

func PersonalAuthFactoryKinds

func PersonalAuthFactoryKinds() []string

PersonalAuthFactoryKinds returns the sorted personal/subscription-auth factory table. It is read-only enumeration for architecture tests and diagnostics.

func PrepareProviderProfiles

func PrepareProviderProfiles(cfg *config.Config) (*config.Config, error)

func PrepareProviderProfilesWithCatalog

func PrepareProviderProfilesWithCatalog(cfg *config.Config, catalog *providerprofiles.Catalog) (*config.Config, error)

func ProfileConfigNode

func ProfileConfigNode(profile providerprofiles.Profile) (yaml.Node, error)

func ProjectCompatibleBackendInstanceRows

func ProjectCompatibleBackendInstanceRows(cfg *config.Config) []diag.InstanceDiagnostic

ProjectCompatibleBackendInstanceRows projects compatible backend rows as common instance diagnostics.

func ProjectCompatibleBackendRows

func ProjectCompatibleBackendRows(cfg *config.Config) []diag.CompatibleBackendRow

ProjectCompatibleBackendRows builds secret-safe diagnostics rows from config only. No provider requests, plugin activation, or credential value resolution occur.

func ProjectCompatibleBackendRowsLive

func ProjectCompatibleBackendRowsLive(cfg *config.Config, live CompatibleLiveInputs) []diag.CompatibleBackendRow

ProjectCompatibleBackendRowsLive merges config-derived compatible rows with live model-registry snapshots. No credential resolution or provider requests occur here.

func ProjectOpenResponsesFrontendRows

func ProjectOpenResponsesFrontendRows(cfg *config.Config) []diag.InstanceDiagnostic

ProjectOpenResponsesFrontendRows builds secret-safe diagnostics rows from config only. No provider requests, plugin activation, or credential resolution occur. Unknown or invalid frontend config rows surface a bounded ConfigError with instance identity.

func ProjectProviderProfileDiagnostics

func ProjectProviderProfileDiagnostics(cfg *config.Config) []diag.InstanceDiagnostic

func ProviderProfileCatalog

func ProviderProfileCatalog() (*providerprofiles.Catalog, error)

ProviderProfileCatalog is the immutable standard-distribution profile input. It is deliberately separate from user PluginConfig rows: private custom compatible instances remain accepted without entering this catalog.

func StandardContinuationWiringFactory

func StandardContinuationWiringFactory(_ *config.Config) lipsdk.ContinuationMountWiringFactory

StandardContinuationWiringFactory creates lifecycle-owned continuation resources for the standard OpenResponses frontend. The factory is kept in the composition root so the frontend plugin only consumes SDK ports.

func StandardContributions

func StandardContributions() contrib.ContributionSet

func StandardDiagnosticProjectors

func StandardDiagnosticProjectors() []diag.InstanceDiagnosticProjector

func StandardFrontendRouteClaims

func StandardFrontendRouteClaims() map[string]FrontendRouteClaims

StandardFrontendRouteClaims returns the owner-aware route-claims providers for standard frontends that declare route ownership. The generic OpenResponses frontend declares its config-derived claims (base_path, WebSocket); the legacy openai-responses frontend declares its fixed /v1 claims so canonical path takeover validation can detect base_path=/v1 collisions before any ServeMux handler is mounted. Frontends without a provider participate in no route-ownership validation.

func UsesOpenAINativeUsageMapper

func UsesOpenAINativeUsageMapper(kind string) bool

UsesOpenAINativeUsageMapper reports whether a backend factory kind produces provider usage through the OpenAI native usage mapper. Those kinds can emit native component measures (for example audio_token) for which stock V2 offers have no frozen compatibility proof, so stock V2 admission must fail closed. This is a pure factory-kind predicate: it never infers a family from the client operation or from an instance ID.

func ValidateCompatibleManifestOwnership

func ValidateCompatibleManifestOwnership(rows []config.PluginConfig, reg *pluginreg.Registry) error

ValidateCompatibleManifestOwnership validates the manifest-available ownership stage: built-ins, enabled generic prefixes, and (when reg is non-nil) discovered external factory kinds. It never activates plugin processes.

func ValidateProviderProfiles

func ValidateProviderProfiles() error

ValidateProviderProfiles performs startup/check-config validation only. It does not build adapters, resolve secrets, discover models, or start processes.

Types

type AuthErrorRendererRegistration

type AuthErrorRendererRegistration struct {
	WireID   string
	Renderer lipsdk.AuthErrorRenderer
}

AuthErrorRendererRegistration binds optional transport-auth error rendering to a wire frontend id.

type BackendRegistration

BackendRegistration is one explicit backend contribution to a bundle.

type Bundle

type Bundle struct {
	Frontends          []FrontendRegistration
	Backends           []BackendRegistration
	Features           []FeatureRegistration
	AuthErrorRenderers []AuthErrorRendererRegistration
}

Bundle is the standard distribution composition input. It is a value, not process-global registry state.

func EssentialBackendBundle

func EssentialBackendBundle(keys UpstreamAPIKeys) Bundle

EssentialBackendBundle returns only the five essential families plus approved dependency-free compatible modes.

func StandardBackendBundle

func StandardBackendBundle(keys UpstreamAPIKeys) Bundle

StandardDiagnosticProjectors returns the projectors owned by standard contributions in declaration order. StandardBackendBundle returns the essential built-in backend table. Optional connector kinds are discovered via closed manifests only.

func StandardBundle

func StandardBundle() Bundle

StandardBundle returns the concrete standard distribution table. The standard distribution may import bundled plugins here; core and SDK packages must continue to depend only on canonical/SDK contracts.

type CompatibleLiveInputs

type CompatibleLiveInputs struct {
	Backends map[string]execbackend.Backend
	Registry *modelregistry.Registry
	Runtime  *modelregistry.Runtime
}

CompatibleLiveInputs carries active-generation inventory state for live projection.

type FeatureRegistration

type FeatureRegistration struct {
	ID      string
	Factory pluginreg.FeatureFactory
}

FeatureRegistration is one explicit feature contribution to a bundle.

type FrontendRegistration

type FrontendRegistration struct {
	ID    string
	Mount pluginreg.FrontendMount
}

FrontendRegistration is one explicit frontend contribution to a bundle.

type FrontendRouteClaims

type FrontendRouteClaims = httpcontract.FrontendRouteClaims

FrontendRouteClaims computes the normalized owner-aware route claims for one enabled frontend instance. instanceID is the immutable owner identity used for the route-ownership registry; cfg is the plugin-local config subtree. Re-exported from the cycle-neutral composition contract.

type MultiUserBackendApproval

type MultiUserBackendApproval struct {
	// FactoryKind is the registered backend factory kind (plugin config `kind:`).
	FactoryKind string
	// CredentialClass records credential ownership for the shared deployment.
	CredentialClass MultiUserCredentialClass
	// ExecutionLocation records remote provider versus local process execution.
	ExecutionLocation MultiUserExecutionLocation
	// Reference is a short human-readable approval rationale / evidence pointer.
	Reference string
}

MultiUserBackendApproval is one typed entry of the host-owned approval policy. A factory without an entry is denied in multi_user; there is no boolean-only entry and no implicit approval path.

type MultiUserBackendPolicy

type MultiUserBackendPolicy struct {
	// contains filtered or unexported fields
}

MultiUserBackendPolicy is an immutable, enumerable multi-user approval policy. The zero value denies everything. Instances are produced only by HostMultiUserBackendPolicy; there is no mutation API, no public setter, and no connector-supplied variant.

func HostMultiUserBackendPolicy

func HostMultiUserBackendPolicy() MultiUserBackendPolicy

HostMultiUserBackendPolicy returns the standard distribution's approval policy. It is process-global authority, not process-global mutable state: callers only ever receive a value they cannot change.

func (MultiUserBackendPolicy) Approvals

Approvals returns the full approval table sorted by factory kind. The returned slice is a fresh copy; mutating it cannot affect the policy.

func (MultiUserBackendPolicy) IsApproved

func (p MultiUserBackendPolicy) IsApproved(factoryKind string) bool

IsApproved reports whether factoryKind is approved for multi_user. Unknown factories are denied.

func (MultiUserBackendPolicy) Lookup

Lookup reports the typed approval for factoryKind, if the host distribution approved it for shared multi-user operation.

type MultiUserCredentialClass

type MultiUserCredentialClass string

MultiUserCredentialClass records who owns the credential an approved factory uses in a shared deployment. It is the machine-readable half of an approval rationale.

const (
	// MultiUserCredentialOperatorStatic is an operator-configured static credential
	// such as a provider API key: it belongs to the deployment operator, not to any
	// individual downstream principal.
	MultiUserCredentialOperatorStatic MultiUserCredentialClass = "operator_static"
	// MultiUserCredentialWorkload is workload identity from the local runtime
	// environment (cloud IAM role, instance metadata, ...).
	MultiUserCredentialWorkload MultiUserCredentialClass = "workload"
	// MultiUserCredentialServiceAccount is a provider service-account credential.
	MultiUserCredentialServiceAccount MultiUserCredentialClass = "service_account"
	// MultiUserCredentialNone marks a deterministic backend that uses no upstream
	// credential at all.
	MultiUserCredentialNone MultiUserCredentialClass = "none"
)

type MultiUserExecutionLocation

type MultiUserExecutionLocation string

MultiUserExecutionLocation records where an approved factory runs its inference.

const (
	// MultiUserExecutionRemoteProvider is a remote provider HTTP inference adapter.
	MultiUserExecutionRemoteProvider MultiUserExecutionLocation = "remote_provider"
	// MultiUserExecutionLocalProcess runs a user-controlled inference process on the
	// host, reading user-local model state or trust material. No approval may use this
	// location.
	MultiUserExecutionLocalProcess MultiUserExecutionLocation = "local_process"
	// MultiUserExecutionDeterministicLocalStub is the synthetic local-stub connector.
	// It runs as a local process but is deterministic: it uses no upstream credential,
	// reads no user-local model state, no personal OAuth material, and no local trust
	// boundary, so it crosses no credential or isolation boundary a shared deployment
	// must protect. It is approved so the shipped single-user AND multi-user example
	// configurations (for example config/examples/secrets-guard-block-multi-user.yaml)
	// remain valid shared deployments.
	MultiUserExecutionDeterministicLocalStub MultiUserExecutionLocation = "deterministic_local_stub"
)

type ProviderProfileDiagnostic

type ProviderProfileDiagnostic struct {
	ID        string
	Family    string
	Endpoint  string
	Auth      bool
	Tokenizer string
}

ProviderProfileDiagnostics is the bounded, secret-safe source projection used by composition diagnostics. It intentionally reports identity, family, and endpoint origin only; it never includes credentials or raw profile data.

func ProviderProfileDiagnostics

func ProviderProfileDiagnostics() ([]ProviderProfileDiagnostic, error)

type ReasoningOutputPreservationInjectOpts

type ReasoningOutputPreservationInjectOpts struct {
	StandardDistribution bool
}

ReasoningOutputPreservationInjectOpts controls standard-distribution default injection.

type ToolCallRepairInjectOpts

type ToolCallRepairInjectOpts struct {
	StandardDistribution bool
}

type UpstreamAPIKeys

type UpstreamAPIKeys struct {
	OpenAI           []string
	Anthropic        []string
	AlibabaTokenPlan []string
	Gemini           []string
}

UpstreamAPIKeys carries default API key material resolved once at the composition root (typically from ResolveUpstreamAPIKeysFromEnv) when plugin YAML leaves api_key empty. Treat all string values as secrets: do not log them or include them in error text.

func ResolveUpstreamAPIKeysFromEnv

func ResolveUpstreamAPIKeysFromEnv() UpstreamAPIKeys

ResolveUpstreamAPIKeysFromEnv reads OPENAI_API_KEY, ANTHROPIC_API_KEY, ALIBABA_TOKEN_PLAN_API_KEY, and GEMINI_API_KEY plus numbered suffixes until the first missing or empty value. The bare env var fills the first slot; numbered suffixes start at _2. ALIBABA_TOKEN_PLAN_API_KEY additionally falls back to the persistent Windows environment, because a long-lived launcher can hand a stale process snapshot that omits a freshly-configured User env var. Migrated external connectors (OpenRouter, NVIDIA, Hugging Face, Ollama, local runtimes, OpenCode, Codex) receive credentials only via plugin config YAML / secrets. Call from the composition root and pass the result to InstallStandardBundleOn.

Directories

Path Synopsis
Package contrib contains immutable, metadata-only extension facets.
Package contrib contains immutable, metadata-only extension facets.
reasoning
Package reasoningcompose provides dedicated runtime composition for reasoning semantic compression.
Package reasoningcompose provides dedicated runtime composition for reasoning semantic compression.
sessionclassification
Package sessionclassification provides the standard featurehost's bounded process-local adapter for feature-owned session classification state.
Package sessionclassification provides the standard featurehost's bounded process-local adapter for feature-owned session classification state.
sessionpolicy
Package sessionpolicy provides the standard featurehost-owned, bounded policy store for terminal-decision session overrides.
Package sessionpolicy provides the standard featurehost-owned, bounded policy store for terminal-decision session overrides.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL