Documentation
¶
Overview ¶
Package lipsdk defines stable plugin-facing contracts used by official and external plugins. Hook interfaces live in the nested package lipsdk/hooks.
Authentication and backend security: [auth] has protocol-neutral request metadata, decisions, and event DTOs; BackendSecurityProfile declares backend credential posture for registry startup validation. Neither carries plugin-private config blobs—only registered metadata and stable enums.
Ownership: this tree holds plugin registration, hook contracts, and SDK-facing types, not application orchestration. Routing, recovery, and extension-stage policy stay in internal/core. Do not import internal packages, internal/stdhttp, or composition assembly packages from here; pkg/lipsdk/execview holds the canonical principal context key; pkg/lipsdk/transport/httpauth holds HTTP-native auth provider and error-render contracts. Factory registration for the standard distribution still happens in internal/pluginreg at the composition root, not from types defined here.
Backend, frontend, and feature factories for the reference distribution are registered in internal/pluginreg (RegisterBackend, RegisterFrontend, RegisterFeature) using opaque YAML nodes and FrontendMountOptions for frontend HTTP wiring; StandardDistributionRequirements lists ids validated at startup.
BackendBuild is intentionally opaque (see factory.go) so this package never depends on core runtime types.
HTTP seam: the root package is the sanctioned minimal net/http surface of this tree. It imports net/http only for FrontendMount wiring and the AuthErrorRenderer contracts (factory.go, auth_error_render.go); that placement is deliberate so internal/core can reference them without pulling pkg/lipsdk/transport into the orchestration dependency closure (see the comment on AuthErrorRenderInput). Every other subpackage must stay free of net/http; the sole exception is pkg/lipsdk/transport (including transport/httpauth), which owns HTTP-native auth provider and error-render contracts.
Index ¶
- Constants
- Variables
- func BearerCredential(raw string) string
- func FirstHeader(h http.Header, names []string) string
- func ValidateRegistrations(registrations []Registration, required []Requirement) error
- type AuthErrorRenderInput
- type AuthErrorRenderResult
- type AuthErrorRenderer
- type BackendAccessScope
- type BackendBuild
- type BackendCredentialMode
- type BackendExecutionClass
- type BackendExecutionProfile
- type BackendFactory
- type BackendSecurityProfile
- type ConfigPayload
- type ContinuationMountWiring
- type ContinuationMountWiringFactory
- type DecodeAdmission
- type DisabledMandatoryPluginError
- type DuplicateRegistrationError
- type ExecutorView
- type FrontendKeepaliveConfig
- type FrontendMount
- type FrontendMountOptions
- type HTTPHeaders
- func (h HTTPHeaders) ALegIDValue(hdr http.Header) string
- func (h HTTPHeaders) APIKeyFrom(hdr http.Header) string
- func (h HTTPHeaders) DiagnosticsSecretValue(hdr http.Header) string
- func (h HTTPHeaders) OrDefault() HTTPHeaders
- func (h HTTPHeaders) ResumeTokenValue(hdr http.Header) string
- func (h HTTPHeaders) RouteSelector(hdr http.Header) string
- func (h HTTPHeaders) SessionHintValue(hdr http.Header) string
- func (h HTTPHeaders) SessionIDValue(hdr http.Header) string
- func (h HTTPHeaders) TraceIDValue(hdr http.Header) string
- type MissingRequirementError
- type PluginKind
- type Registration
- type Requirement
- type RouteObserver
Examples ¶
Constants ¶
const ( HeaderAuthorization = "Authorization" HeaderAPIKey = "x-api-key" HeaderGoogleAPIKey = "x-goog-api-key" HeaderAzureAPIKey = "api-key" HeaderRoute = "X-LIP-Route" HeaderSessionID = "X-LIP-Session-Id" HeaderResumeToken = "X-LIP-Resume-Token" HeaderALegID = "X-LIP-A-Leg-Id" HeaderSessionHint = "X-LIP-Session-Hint" HeaderTraceID = "X-Trace-ID" HeaderDiagnosticsSecret = "X-LIP-Diagnostics-Secret" )
Default inbound HTTP header names accepted by the standard distribution. Configured aliases are additional accept names; these defaults stay first so existing clients keep winning when both a default and an alias are present.
Variables ¶
var ErrDuplicateRegistration = errors.New("lipsdk: duplicate plugin registration")
var ErrInvalidBackendExecutionClass = errors.New("lipsdk: invalid backend execution class")
ErrInvalidBackendExecutionClass indicates an unrecognized non-empty execution class.
Functions ¶
func BearerCredential ¶
BearerCredential returns the token when raw is a Bearer authorization value.
func FirstHeader ¶
First returns the first non-empty trimmed header value among names.
func ValidateRegistrations ¶
func ValidateRegistrations(registrations []Registration, required []Requirement) error
ValidateRegistrations checks duplicate IDs inside a kind and verifies mandatory entries. For each mandatory requirement, a matching registration must exist; if Kind is Frontend or Feature, Enabled must be true (reference config may list backends with enabled: false).
Example ¶
package main
import (
"fmt"
"github.com/matdev83/go-llm-interactive-proxy/pkg/lipsdk"
)
func main() {
registrations := []lipsdk.Registration{
{ID: "ui", Kind: lipsdk.PluginKindFrontend, Enabled: true},
}
required := []lipsdk.Requirement{
{Kind: lipsdk.PluginKindFrontend, ID: "ui"},
}
if err := lipsdk.ValidateRegistrations(registrations, required); err != nil {
fmt.Println("invalid:", err)
return
}
fmt.Println("ok")
}
Output: ok
Types ¶
type AuthErrorRenderInput ¶
type AuthErrorRenderInput struct {
FrontendID string
RequestPath string
Decision sdkauth.Decision
// DefaultStatus is the status suggested by the adapter (e.g. 401, 403, 503) before rendering.
DefaultStatus int
ChallengeHeaders http.Header
// Policy and trace fields are optional; default renderers use them for safe messaging only.
AccessMode sdkauth.AccessMode
HandlerKind sdkauth.HandlerKind
RequiredLevel sdkauth.RequiredLevel
TraceID string
RemoteAddr string
}
AuthErrorRenderInput carries semantic auth state plus transport-facing fields for mapping a decision to a safe client-visible HTTP response. Renderers must not re-authenticate or read raw bearer material.
Canonical definitions live in package lipsdk (not pkg/lipsdk/auth) so internal/core can reference FrontendMountOptions.AuthErrorRenderer without pulling pkg/lipsdk/transport into the orchestration dependency closure; github.com/matdev83/go-llm-interactive-proxy/pkg/lipsdk/transport/httpauth aliases these types for transport-only call sites.
type AuthErrorRenderResult ¶
AuthErrorRenderResult is a single terminal HTTP response (reject or challenge). Headers and Body must not include secrets or fine-grained existence-revealing key material.
type AuthErrorRenderer ¶
type AuthErrorRenderer interface {
RenderAuthError(ctx context.Context, in AuthErrorRenderInput) AuthErrorRenderResult
}
AuthErrorRenderer maps denied or challenged decisions into a safe transport response (implemented by the stdhttp layer and optional frontend hooks).
type BackendAccessScope ¶
type BackendAccessScope string
BackendAccessScope describes whether a backend is safe for shared multi-user deployments. Local-only backends may spawn local processes, read personal OAuth material, or otherwise depend on user-local trust boundaries.
const ( // BackendAccessAny means the backend may be enabled in single-user or multi-user mode, // subject to credential posture validation. // // This is the default applied when a backend is registered without an explicit // AccessScope. The default is safe for cloud/upstream HTTP backends but is UNSAFE for // process-spawning backends, backends that read personal OAuth material from the local // user context, or any backend that depends on a user-local trust boundary: such // backends MUST declare [BackendAccessLocalOnly] explicitly rather than relying on // this default, otherwise they would be permitted in multi-user deployments and bypass // the local-trust boundary. [internal/pluginreg] startup access-scope validation // rejects local-only backends in multi-user mode. BackendAccessAny BackendAccessScope = "any" // BackendAccessLocalOnly means the backend is only valid in single-user deployments. // Backends that spawn local subprocesses, read personal OAuth tokens from the user's // environment, or otherwise assume a single trusted local user MUST declare this // scope explicitly at registration time; do not rely on the [BackendAccessAny] // default for such backends. BackendAccessLocalOnly BackendAccessScope = "local_only" )
type BackendBuild ¶
type BackendBuild = any
BackendBuild is the opaque return type of BackendFactory. It aliases any on purpose: lipsdk must not import internal/core/runtime (AGENTS.md: core-owned types stay out of stable SDK surfaces). Official wiring in internal/pluginreg builds internal/core/execbackend.Backend values at the composition root; custom distributions may assert their own concrete backend wrapper instead. The alias documents that boundary while keeping registration signatures ergonomic for YAML-only factories.
type BackendCredentialMode ¶
type BackendCredentialMode string
BackendCredentialMode describes how a registered backend plugin obtains upstream credentials (startup metadata only; not plugin-private configuration values). CredentialNone marks adapters that do not use upstream credentials.
const ( // CredentialStatic uses operator-configured static credentials such as API keys. CredentialStatic BackendCredentialMode = "static" // CredentialWorkload uses workload identity from the local runtime environment. CredentialWorkload BackendCredentialMode = "workload" // CredentialOAuthUser uses user-scoped OAuth credentials; eligibility is validated against access mode. CredentialOAuthUser BackendCredentialMode = "oauth_user" // CredentialNone means the backend does not use upstream credentials (deterministic local adapters). CredentialNone BackendCredentialMode = "none" // CredentialUnknown means the factory did not declare a credential posture; validation may treat this conservatively. CredentialUnknown BackendCredentialMode = "unknown" )
type BackendExecutionClass ¶
type BackendExecutionClass string
BackendExecutionClass represents the declared execution semantics of a backend factory.
const ( // BackendExecutionUnknown indicates omitted or unclassified legacy metadata. BackendExecutionUnknown BackendExecutionClass = "" // BackendExecutionInference indicates an ordinary model-like inference service. BackendExecutionInference BackendExecutionClass = "inference" // BackendExecutionAgentRuntime indicates an agent or orchestration runtime with its own harness/state. BackendExecutionAgentRuntime BackendExecutionClass = "agent_runtime" )
type BackendExecutionProfile ¶
type BackendExecutionProfile struct {
Class BackendExecutionClass
}
BackendExecutionProfile holds stable startup execution semantics for backend registration.
func (BackendExecutionProfile) EffectiveClass ¶
func (p BackendExecutionProfile) EffectiveClass() BackendExecutionClass
EffectiveClass returns the normalized execution class, treating empty as unknown.
func (BackendExecutionProfile) Validate ¶
func (p BackendExecutionProfile) Validate() error
Validate checks that the execution class is empty (unknown) or one of the recognized classes.
type BackendFactory ¶
type BackendFactory func(n yaml.Node) (BackendBuild, error)
BackendFactory builds a backend adapter from opaque per-plugin YAML.
type BackendSecurityProfile ¶
type BackendSecurityProfile struct {
CredentialMode BackendCredentialMode
AccessScope BackendAccessScope
}
BackendSecurityProfile is stable startup metadata for backend credential posture. It is part of the public plugin registration contract and must not hold secret values.
type ConfigPayload ¶
ConfigPayload keeps plugin-private configuration opaque to the core.
type ContinuationMountWiring ¶
type ContinuationMountWiring struct {
Store lipcont.Store
Resolver lipcont.Resolver
Close func() error
}
ContinuationMountWiring supplies composition-root-owned continuation state to a frontend mount. Close is owned by the composition root and should be bound to the generation lifecycle by the mount coordinator.
type ContinuationMountWiringFactory ¶
type ContinuationMountWiringFactory func(frontendID, instanceID string, cfg yaml.Node) (ContinuationMountWiring, error)
ContinuationMountWiringFactory creates one independent wiring instance for a mounted frontend generation. The factory receives immutable plugin identity and opaque configuration so the composition root can apply plugin-specific bounds without making frontend plugins depend on core packages.
type DecodeAdmission ¶
type DecodeAdmission interface {
TryAcquire(ctx context.Context, weight int64) (release func(), ok bool, err error)
}
DecodeAdmission bounds concurrent frontend decode work and weighted in-flight decode bytes.
TryAcquire contract:
- ok=true, err=nil: capacity reserved; release is non-nil and must be called exactly once.
- ok=false, err=nil: saturated / rejected without waiting; release is nil and must not be called.
- ok=false, err!=nil: canceled, invalid weight, or overweight; release is nil and must not be called.
- ok=true with err!=nil is not a valid outcome.
Nil receivers / nil DecodeAdmission values mean unlimited (custom/minimal mounts).
type DisabledMandatoryPluginError ¶
type DisabledMandatoryPluginError struct {
Kind PluginKind
ID string
}
DisabledMandatoryPluginError reports a mandatory plugin ID listed but disabled.
func (*DisabledMandatoryPluginError) Error ¶
func (e *DisabledMandatoryPluginError) Error() string
type DuplicateRegistrationError ¶
type DuplicateRegistrationError struct {
Kind PluginKind
ID string
}
DuplicateRegistrationError reports a conflicting plugin identity.
func (*DuplicateRegistrationError) Error ¶
func (e *DuplicateRegistrationError) Error() string
func (*DuplicateRegistrationError) Unwrap ¶
func (e *DuplicateRegistrationError) Unwrap() error
type ExecutorView ¶
type ExecutorView interface {
// Execute requires a non-nil ctx (same as [context.Context] contract for all request paths).
Execute(ctx context.Context, call *lipapi.Call) (lipapi.EventStream, error)
// CancelALeg explicitly cancels a proxy-owned A-leg and its active B-legs.
CancelALeg(ctx context.Context, req lipapi.ALegCancelRequest) error
// WallClock returns the optional wall clock callback used for response metadata; nil means unset.
WallClock() func() time.Time
}
ExecutorView is the minimal inbound surface bundled FrontendMount handlers use to invoke core request execution. The public SDK cannot import the internal runtime package, so this narrow type is the supported compile-time seam. This follows introduce-hexagonal-architecture requirement 8.6: prefer concrete executor types where package boundaries allow, and add inbound interfaces only for a real module-boundary or multi-consumer need, not a generic "ports" layer. Widen the contract only when justified. The standard *runtime.Executor implements this interface.
type FrontendKeepaliveConfig ¶
type FrontendMount ¶
type FrontendMount func(mux *http.ServeMux, opts FrontendMountOptions) error
FrontendMount registers HTTP routes for one frontend plugin instance.
type FrontendMountOptions ¶
type FrontendMountOptions struct {
// PluginCfg is the opaque plugin-local YAML subtree for this frontend instance.
PluginCfg yaml.Node
// Exec is the runtime execution surface the mounted handler uses to submit canonical calls.
// Real frontend mounts require a non-nil Exec.
Exec ExecutorView
// DefaultRoute is the selector used when the frontend protocol omits a route/header override.
DefaultRoute string
// RoutePrefixes are backend route-selector prefixes accepted from protocol model fields.
RoutePrefixes []string
// MaxRequestBodyBytes caps inbound HTTP request size. Zero means the frontend should use its
// own default limit.
MaxRequestBodyBytes int64
// DecodeAdmission optionally bounds concurrent decode work and weighted in-flight decode bytes.
// Nil means unlimited for custom/minimal mounts.
DecodeAdmission DecodeAdmission
// Authorizer optionally performs frontend-local authentication for direct mounts.
// Standard HTTP composition authenticates in the outer transport middleware; a
// custom/direct mount should provide this seam when it is externally reachable.
Authorizer interface {
Authenticate(context.Context, sdkauth.InboundCallMeta) (sdkauth.Decision, error)
}
// AllowUnauthenticated explicitly opts a direct mount into anonymous access.
// It defaults to false; standard composition satisfies the default through its
// outer transport-auth context.
AllowUnauthenticated bool
// TrafficPorts optionally emits client→proxy raw bytes after body read (design §10).
TrafficPorts traffic.PortBundle
// PreRequestKeepalive optionally emits standards-compliant HTTP informational keepalives
// while streaming requests wait for pre-request admission to complete. It must not commit
// final response status or body bytes.
PreRequestKeepalive FrontendKeepaliveConfig
// AuthErrorRenderer is an optional per-frontend hook for safe HTTP error bodies on transport
// authentication failure (R4). When nil, the standard distribution uses the default safe JSON
// renderer. For the standard binary, prefer [pluginreg.Registry.RegisterAuthErrorRenderer] keyed
// by auth wire frontend id (see stdhttp/auth DefaultFrontendIDFromRequest); [runtimebundle.BuildOptions.AuthErrorRenderersByFrontend]
// overrides registry entries per key. This field remains for custom mounts outside pluginreg.
AuthErrorRenderer AuthErrorRenderer
// GenerationContext is the runtime-owned lifecycle context of the generation this
// frontend is mounted into. It cancels when the generation begins shutdown (quiesce
// during a reload, or full server shutdown) and stays alive for the generation's
// entire service life. Frontends that own long-lived transport state (WebSocket
// sessions) must observe it and close their owned resources exactly once so retired
// generations drain without leaks and new sessions never bind to a closing generation.
// A nil value means the mount is not generation-bound (tests, custom minimal mounts).
GenerationContext context.Context // ContinuationStore and ContinuationResolver are optional composition-root
// injections for frontends that expose proxy-owned response continuation.
// Minimal/direct mounts may omit them; the frontend then uses its bounded
// protocol-neutral fallback store.
ContinuationStore lipcont.Store
ContinuationResolver lipcont.Resolver
// ContinuationWiring is an already-created lifecycle-owned resource. It takes
// precedence over the factory when both are provided.
ContinuationWiring *ContinuationMountWiring
// ContinuationWiringFactory creates lifecycle-owned resources. The standard
// composition requires GenerationContext when this factory returns Close.
ContinuationWiringFactory ContinuationMountWiringFactory
// FrontendInstanceID is the immutable configured instance identity passed to
// ContinuationWiringFactory. Empty falls back to the factory ID.
FrontendInstanceID string
// HTTPHeaders is the resolved inbound header-name set (defaults plus aliases).
// Zero value uses [DefaultHTTPHeaders].
HTTPHeaders HTTPHeaders
// StreamKeepaliveInterval is the recovery SSE keepalive interval. Zero uses
// the stream package default (12s).
StreamKeepaliveInterval time.Duration
// LargePayload carries optional large-payload fast-path candidate configuration
// for supported frontends.
LargePayload any
}
FrontendMountOptions carries runtime wiring for FrontendMount beyond the http.ServeMux. Use composite literals with named fields at call sites.
type HTTPHeaders ¶
type HTTPHeaders struct {
APIKey []string
Route []string
SessionID []string
ResumeToken []string
ALegID []string
SessionHint []string
Trace []string
DiagnosticsSecret []string
}
HTTPHeaders is the resolved inbound header-name set for one frontend mount (defaults plus optional operator aliases). Zero value means DefaultHTTPHeaders.
func DefaultHTTPHeaders ¶
func DefaultHTTPHeaders() HTTPHeaders
DefaultHTTPHeaders returns the standard inbound header names in check order.
func (HTTPHeaders) ALegIDValue ¶
func (h HTTPHeaders) ALegIDValue(hdr http.Header) string
ALegIDValue returns the first non-empty A-leg-id header.
func (HTTPHeaders) APIKeyFrom ¶
func (h HTTPHeaders) APIKeyFrom(hdr http.Header) string
APIKeyFrom extracts the inbound API key. Authorization is Bearer-only; other names use the raw header value (Bearer prefix is still stripped when present).
func (HTTPHeaders) DiagnosticsSecretValue ¶
func (h HTTPHeaders) DiagnosticsSecretValue(hdr http.Header) string
DiagnosticsSecretValue returns the first non-empty diagnostics-secret header.
func (HTTPHeaders) OrDefault ¶
func (h HTTPHeaders) OrDefault() HTTPHeaders
OrDefault fills empty slices from DefaultHTTPHeaders.
func (HTTPHeaders) ResumeTokenValue ¶
func (h HTTPHeaders) ResumeTokenValue(hdr http.Header) string
ResumeTokenValue returns the first non-empty resume-token header.
func (HTTPHeaders) RouteSelector ¶
func (h HTTPHeaders) RouteSelector(hdr http.Header) string
RouteSelector returns the first non-empty route header.
func (HTTPHeaders) SessionHintValue ¶
func (h HTTPHeaders) SessionHintValue(hdr http.Header) string
SessionHintValue returns the first non-empty session-hint header.
func (HTTPHeaders) SessionIDValue ¶
func (h HTTPHeaders) SessionIDValue(hdr http.Header) string
SessionIDValue returns the first non-empty session-id header.
func (HTTPHeaders) TraceIDValue ¶
func (h HTTPHeaders) TraceIDValue(hdr http.Header) string
TraceIDValue returns the first non-empty trace header.
type MissingRequirementError ¶
type MissingRequirementError struct {
Kind PluginKind
ID string
}
MissingRequirementError reports a missing mandatory plugin.
func (*MissingRequirementError) Error ¶
func (e *MissingRequirementError) Error() string
type PluginKind ¶
type PluginKind string
PluginKind identifies a plugin family exposed through the composition root.
const ( PluginKindFrontend PluginKind = "frontend" PluginKindBackend PluginKind = "backend" PluginKindFeature PluginKind = "feature" )
type Registration ¶
type Registration struct {
// ID is the runtime instance identifier (routing / duplicate detection within PluginKind).
ID string
// FactoryKind selects the bundled registry factory (e.g. openai-responses). When empty,
// ID is used as the factory key for backward compatibility.
FactoryKind string
Kind PluginKind
Config ConfigPayload
Enabled bool
}
Registration describes a plugin available to the composition root.
func (Registration) RegistryFactoryKey ¶
func (r Registration) RegistryFactoryKey() string
RegistryFactoryKey returns the registry lookup key for this registration.
type Requirement ¶
type Requirement struct {
Kind PluginKind
// ID is the mandatory instance id for frontends and features (matches Registration.ID).
// For backends, ID is the required registry factory key unless RegistryFactoryID is set.
ID string
// RegistryFactoryID selects the bundled factory when it differs from ID.
// Empty means the factory key equals ID for ValidateBundledFactories and backend mandatory checks.
RegistryFactoryID string
}
Requirement defines a mandatory plugin that must exist in a bundle.
Example ¶
package main
import (
"fmt"
"github.com/matdev83/go-llm-interactive-proxy/pkg/lipsdk"
)
func main() {
r := lipsdk.Requirement{Kind: lipsdk.PluginKindFrontend, ID: "openairesponses"}
fmt.Println(string(r.Kind), r.ID)
}
Output: frontend openairesponses
func StandardDistributionRequirements ¶
func StandardDistributionRequirements() []Requirement
StandardDistributionRequirements lists plugin ids the reference cmd/lipstd distribution expects in configuration and registry factories. Single source for mandatory validation. Phase 7/8 migrated OpenAI-compatible hosted/local runtimes, OpenCode Go/Zen, and Codex (openai-codex / openai-codex-app-server) to external connectors; they are discovered via manifests and must not appear here.
type RouteObserver ¶
type RouteObserver interface {
ObserveRouteDecision(ctx context.Context, traceID, decision, detail string)
}
RouteObserver receives lightweight routing/orchestration notifications (hexagonal task 5.2). traceID correlates with diagnostics and traffic metadata; decision and detail are opaque, human-oriented labels (for example route planner outcomes). Values must not embed transport requests, provider payloads, or executor-private structs—only redacted or safe string summaries.
Implementations must be non-blocking or very fast; the executor invokes them on the hot path only when non-nil.
Source Files
¶
Directories
¶
| Path | Synopsis |
|---|---|
|
Package auth defines stable, protocol-neutral authentication data shapes and event schemas for the plugin SDK.
|
Package auth defines stable, protocol-neutral authentication data shapes and event schemas for the plugin SDK. |
|
Package authority defines public request- and attempt-level authority provider contracts, decisions, safe evidence, and concurrency lease DTOs.
|
Package authority defines public request- and attempt-level authority provider contracts, decisions, safe evidence, and concurrency lease DTOs. |
|
Package auxiliary defines the auxiliary internal request client facade (design §7, task 4.1).
|
Package auxiliary defines the auxiliary internal request client facade (design §7, task 4.1). |
|
Package backendplugin defines the public authoring, validation, and wire-conversion contracts for executable backend connector plugins.
|
Package backendplugin defines the public authoring, validation, and wire-conversion contracts for executable backend connector plugins. |
|
conformance
Package conformance defines advertised-capability-only checks for backend plugins.
|
Package conformance defines advertised-capability-only checks for backend plugins. |
|
host
Package host provides the supported public construction path for executable backend-plugin contract clients.
|
Package host provides the supported public construction path for executable backend-plugin contract clients. |
|
manifest
Package manifest defines the closed public v1 installation metadata model for executable backend plugins.
|
Package manifest defines the closed public v1 installation metadata model for executable backend plugins. |
|
Package billing defines the minimal typed external monetary host binding.
|
Package billing defines the minimal typed external monetary host binding. |
|
Package compaction defines the typed, fail-open observer seam for proxy-derived coding-agent session compaction lifecycle observations.
|
Package compaction defines the typed, fail-open observer seam for proxy-derived coding-agent session compaction lifecycle observations. |
|
Package completion defines the completion-gate extension contract (design §6, R8).
|
Package completion defines the completion-gate extension contract (design §6, R8). |
|
Package configreload is the dependency-neutral, secret-safe canonical reload contract.
|
Package configreload is the dependency-neutral, secret-safe canonical reload contract. |
|
Package continuation defines protocol-neutral proxy-owned response continuation contracts: opaque response IDs, scoped stores, persistence policy, terminal recording, and bounded materialization.
|
Package continuation defines protocol-neutral proxy-owned response continuation contracts: opaque response IDs, scoped stores, persistence policy, terminal recording, and bounded materialization. |
|
Package continuity defines the stable persistence contract for A-leg / B-leg continuity and attempt lineage used by documentation and optional external tooling.
|
Package continuity defines the stable persistence contract for A-leg / B-leg continuity and attempt lineage used by documentation and optional external tooling. |
|
Package contract contains dependency-neutral semantic TCK metadata shared by frontend, core, backend, and executable connector contract tests.
|
Package contract contains dependency-neutral semantic TCK metadata shared by frontend, core, backend, and executable connector contract tests. |
|
Package controlplane defines the stable, safe control-plane evidence and query contracts for the LLM Interactive Proxy runtime.
|
Package controlplane defines the stable, safe control-plane evidence and query contracts for the LLM Interactive Proxy runtime. |
|
Package controltool defines the provider-neutral SDK contract for one optional proxy-owned model control tool.
|
Package controltool defines the provider-neutral SDK contract for one optional proxy-owned model control tool. |
|
Package economics defines provider-neutral public contracts for money, independent customer/operator rating, conservative exposure assumptions, immutable version snapshot references, and versioned snapshot sources.
|
Package economics defines provider-neutral public contracts for money, independent customer/operator rating, conservative exposure assumptions, immutable version snapshot references, and versioned snapshot sources. |
|
Package execview holds stable, transport-agnostic identity and attempt views for feature plugins (design §2), plus WithPrincipal / PrincipalFromContext for the canonical principal in context.Context (set at the transport edge, read by the core).
|
Package execview holds stable, transport-agnostic identity and attempt views for feature plugins (design §2), plus WithPrincipal / PrincipalFromContext for the canonical principal in context.Context (set at the transport edge, read by the core). |
|
Package feature defines typed extension planes and the contribution lifecycle for feature plugins in Go-LIP.
|
Package feature defines typed extension planes and the contribution lifecycle for feature plugins in Go-LIP. |
|
Package genpin defines the narrow request-context contract for retaining runtime configuration generation ownership beyond an HTTP handler lease.
|
Package genpin defines the narrow request-context contract for retaining runtime configuration generation ownership beyond an HTTP handler lease. |
|
Package hooks defines stable plugin contracts for submit, part, and tool-reactor hooks.
|
Package hooks defines stable plugin contracts for submit, part, and tool-reactor hooks. |
|
Package localturn defines the trusted extension contract for generic proxy-local turn handling.
|
Package localturn defines the trusted extension contract for generic proxy-local turn handling. |
|
Package metering defines provider-neutral public contracts for dual-plane metering facts, quantities, and journal append/query ports.
|
Package metering defines provider-neutral public contracts for dual-plane metering facts, quantities, and journal append/query ports. |
|
Package modelinventory defines the backend-owned model inventory contract.
|
Package modelinventory defines the backend-owned model inventory contract. |
|
Package nonforwardable defines the trusted producer contract for tagging client-visible messages as never_backend.
|
Package nonforwardable defines the trusted producer contract for tagging client-visible messages as never_backend. |
|
Package policydecision defines the protocol-neutral policy decision vocabulary, record model, observer contracts, and bounded evidence normalization shared by core extension runners, diagnostics, and tests.
|
Package policydecision defines the protocol-neutral policy decision vocabulary, record model, observer contracts, and bounded evidence normalization shared by core extension runners, diagnostics, and tests. |
|
Package prerequest defines pre-routing admission handlers for canonical calls.
|
Package prerequest defines pre-routing admission handlers for canonical calls. |
|
Package promptcache defines the provider-neutral host/plugin contract for prompt-cache residency.
|
Package promptcache defines the provider-neutral host/plugin contract for prompt-cache residency. |
|
Package request defines the request-wide shaping stage contract (design §5, R12).
|
Package request defines the request-wide shaping stage contract (design §5, R12). |
|
Package response defines the final-canonical-stream observer contract.
|
Package response defines the final-canonical-stream observer contract. |
|
Package routehint defines advisory route-hint providers (design §12, R13).
|
Package routehint defines advisory route-hint providers (design §12, R13). |
|
Package runtimegen defines provider-neutral executable generation contributions.
|
Package runtimegen defines provider-neutral executable generation contributions. |
|
Package scope holds the authoritative, protocol-neutral principal/scope attribution snapshot for an accepted LLM Interactive Proxy request.
|
Package scope holds the authoritative, protocol-neutral principal/scope attribution snapshot for an accepted LLM Interactive Proxy request. |
|
Package secretguard defines opaque SDK contracts for the secrets-guard ingress stage.
|
Package secretguard defines opaque SDK contracts for the secrets-guard ingress stage. |
|
Package session holds session-scoped contracts and views for the feature SDK (design §2, §16).
|
Package session holds session-scoped contracts and views for the feature SDK (design §2, §16). |
|
Package sessionclassification defines bounded, provider-neutral evidence and classifier contracts for session classification.
|
Package sessionclassification defines bounded, provider-neutral evidence and classifier contracts for session classification. |
|
Package state defines the plugin-scoped state store facade (design §8, tasks 4.1, 6–6.1).
|
Package state defines the plugin-scoped state store facade (design §8, tasks 4.1, 6–6.1). |
|
Package steering defines the trusted producer contract for persistent backend-only steering overlays.
|
Package steering defines the trusted producer contract for persistent backend-only steering overlays. |
|
Package submission defines the provider-neutral trust boundary for customer submission identity.
|
Package submission defines the provider-neutral trust boundary for customer submission identity. |
|
Package terminal defines provider-neutral public contracts for single terminal ownership and durable terminal-work kinds/states.
|
Package terminal defines provider-neutral public contracts for single terminal ownership and durable terminal-work kinds/states. |
|
Package terminaldecision defines the provider-neutral SDK contract for bounded provisional-terminal decisions.
|
Package terminaldecision defines the provider-neutral SDK contract for bounded provisional-terminal decisions. |
|
Package toolcall declares the completed-call finalizer SDK seam (ADR 0007 / issue #152).
|
Package toolcall declares the completed-call finalizer SDK seam (ADR 0007 / issue #152). |
|
Package toolcatalog defines the tool catalog filter stage (design §4, R9).
|
Package toolcatalog defines the tool catalog filter stage (design §4, R9). |
|
Package toolpolicy defines provider-neutral policy hooks for model-emitted tool calls.
|
Package toolpolicy defines provider-neutral policy hooks for model-emitted tool calls. |
|
Package traffic defines four-leg observation, privileged raw capture, and redactor hooks (design §10–§11).
|
Package traffic defines four-leg observation, privileged raw capture, and redactor hooks (design §10–§11). |
|
transport
|
|
|
httpauth
Package httpauth defines transport-layer authentication contracts for the standard HTTP distribution (design §13, R4).
|
Package httpauth defines transport-layer authentication contracts for the standard HTTP distribution (design §13, R4). |
|
Package usage defines observer seams for token and accounting events.
|
Package usage defines observer seams for token and accounting events. |
|
Package workspace holds workspace resolution contracts and views (design §2, §9, §16).
|
Package workspace holds workspace resolution contracts and views (design §2, §9, §16). |