Support native Anthropic BYOK endpoints - #63
Conversation
There was a problem hiding this comment.
Gate: failed
Review metadata
- Model:
deepseek/deepseek-v4-pro -> mistralai/mistral-small-3.2-24b-instruct -> google/gemma-3-27b-it -> qwen/qwen3-32b - Review duration: 419.12 s
- Commit:
7ed6235 - Dashboard run: View in Postil
- Tokens: 0 prompt, 0 completion
There was a problem hiding this comment.
Gate: failed
The diff introduces a usage receipt feature for postil respond and refactors the answer method to return structured data. A potential issue exists where failed model attempts with zero token usage are silently excluded from the receipt, which may be intentional but could mask cost-relevant failures. The receipt file is created with create_new(true), which will fail if the path already exists, potentially breaking idempotent retries.
Usage receipt creation fails if path already exists · severity:
warn· confidence 0.70 · kind: humanEscalationFailed model attempts with zero token usage are excluded from receipt · severity:
warn· confidence 0.60 · kind: humanEscalation
1 finding(s) suppressed by policy (confidence/severity/ignore).
Review metadata
- Model:
deepseek/deepseek-v4-pro - Review duration: 27.89 s
- Commit:
b129ccf - Dashboard run: View in Postil
- Tokens: 11879 prompt, 1962 completion
- Scorer:
openai/gpt-5-mini(2 disagreement(s))
| ); | ||
| let file = OpenOptions::new() | ||
| .write(true) | ||
| .create_new(true) |
There was a problem hiding this comment.
Usage receipt creation fails if path already exists
warn · confidence 0.70 · kind: humanEscalation
OpenOptions::new().create_new(true) will return an error if the file at POSTIL_USAGE_RECEIPT_PATH already exists. This breaks idempotent retries: if postil respond is re-run with the same receipt path (e.g., after a transient network error before the receipt is written), it will fail immediately instead of overwriting or appending. Consider using .create(true).truncate(true) to allow overwriting, or document that the caller must delete the file before retrying.
| if model_usage.prompt_tokens > 0 || model_usage.completion_tokens > 0 { | ||
| add_usage(&mut usage, model_usage); | ||
| models.push(ModelUsage { | ||
| model: model.clone(), | ||
| usage: model_usage, | ||
| }); | ||
| } |
There was a problem hiding this comment.
Failed model attempts with zero token usage are excluded from receipt
warn · confidence 0.60 · kind: humanEscalation
When a model in the cascade fails and its model_usage has zero prompt_tokens and zero completion_tokens, the attempt is silently omitted from the models array in the Answer struct. This means the usage receipt will not record that the model was tried at all. If the provider charges for failed attempts (e.g., rate-limit or authentication errors that still consume tokens), this data is lost. Verify with the Anthropic and OpenAI billing models whether zero-token failures can incur costs, and if so, always push a ModelUsage entry for every attempt regardless of token counts.
|
@postil approve bb5c6049e18ea1a54bec04eeafcfb6a3e7d5ea986833a80000a7e4cc71316262 -- Sequential retries exclusively borrow stack-local state; no concurrent mutation exists. |
|
@postil approve 33435f21cf9f06bdf3979d64276772e4dd705d65f42981fa475621b64c87ec21 -- Sequential retries exclusively borrow stack-local state; no concurrent mutation exists. |
|
@postil approve 414724469941df86ae6072c0a74b1e22767e83ce3e86478c9c80af82cdd9ca05 -- Sequential retries exclusively borrow stack-local state; no concurrent mutation exists. |
|
Approval rejected: that finding is absent, already approved, revoked, or no longer kind-blocking. |
|
@postil approve 88ff043473956711a683ecf5be71c9ccd8c6737e882bb6db2baf6bb8551c1c41 -- Sequential retries exclusively borrow stack-local state; no concurrent mutation exists. |
|
Approval rejected: that finding is absent, already approved, revoked, or no longer kind-blocking. |
|
@postil approve d2a87b0289dc688320b9b76798bbc1bafe12cae5cb86426a35a5bc50eedb8a8e -- The temporary file is created with explicit mode 0600 and create_new fails closed. |
|
Approval rejected: that finding is absent, already approved, revoked, or no longer kind-blocking. |
|
@postil approve 8d914169bfba7ae8f465626fb4d51b321fb8fe38a71f0d543a66ffa8cb4c2617 -- Receipt contents are sync_all committed, atomically renamed, and the parent directory is synced before output or delivery. |
|
Approval rejected: that finding is absent, already approved, revoked, or no longer kind-blocking. |
|
@postil approve 561a0bba4cf6c8b6ea5dc20791ee2648afea243f72e3953edce023edd4da1545 -- Receipt contents are sync_all committed, atomically renamed, and the parent directory is synced before output or delivery. |
|
Approval rejected: that finding is absent, already approved, revoked, or no longer kind-blocking. |
2 similar comments
|
Approval rejected: that finding is absent, already approved, revoked, or no longer kind-blocking. |
|
Approval rejected: that finding is absent, already approved, revoked, or no longer kind-blocking. |
Adds native Anthropic Messages support, sealed custom endpoint authentication, and the updated hosted model roster. Provider connections reject private targets, pin validated DNS results, and never follow redirects; native Anthropic scoring uses only compatible explicit scorer configuration. Review and reply receipts attribute per-model usage and conservatively flag incomplete provider accounting across retries and fallbacks. The release version is 0.5.0.