Files
Aether/apps/aether-gateway/src/scheduler/candidate/runtime.rs
T

485 lines
16 KiB
Rust
Raw Normal View History

use std::collections::{BTreeMap, BTreeSet};
use aether_admin::provider::{
pool as admin_provider_pool_pure, status as admin_provider_status_pure,
};
use aether_data_contracts::repository::candidates::StoredRequestCandidate;
use aether_data_contracts::repository::provider_catalog::StoredProviderCatalogKey;
use aether_scheduler_core::{
auth_api_key_concurrency_limit_reached, build_provider_concurrent_limit_map,
candidate_is_selectable_with_runtime_state, candidate_runtime_skip_reason_with_state,
2026-06-22 00:07:26 +08:00
effective_provider_key_rpm_limit, CandidateRuntimeSelectabilityInput,
};
2026-05-07 11:28:44 +08:00
use std::time::{SystemTime, UNIX_EPOCH};
use crate::data::auth::GatewayAuthApiKeySnapshot;
use crate::GatewayError;
use super::{SchedulerMinimalCandidateSelectionCandidate, SchedulerRuntimeState};
pub(super) use aether_scheduler_core::should_skip_provider_quota;
pub(super) struct CandidateRuntimeSelectionSnapshot {
pub(super) recent_candidates: Vec<StoredRequestCandidate>,
pub(super) provider_concurrent_limits: BTreeMap<String, usize>,
pub(super) provider_key_rpm_states: BTreeMap<String, StoredProviderCatalogKey>,
2026-05-03 20:14:29 +08:00
pub(super) pool_provider_ids: BTreeSet<String>,
provider_quota_blocks_requests: BTreeMap<String, bool>,
key_account_quota_exhausted: BTreeMap<String, bool>,
key_oauth_invalid: BTreeMap<String, bool>,
provider_key_rpm_reset_ats: BTreeMap<String, Option<u64>>,
}
pub(super) async fn read_candidate_runtime_selection_snapshot(
state: &(impl SchedulerRuntimeState + ?Sized),
candidates: &[SchedulerMinimalCandidateSelectionCandidate],
2026-06-22 00:07:26 +08:00
auth_snapshot: Option<&GatewayAuthApiKeySnapshot>,
now_unix_secs: u64,
) -> Result<CandidateRuntimeSelectionSnapshot, GatewayError> {
let provider_concurrent_limits = read_provider_concurrent_limits(state, candidates).await?;
2026-05-03 20:14:29 +08:00
let provider_pool_state = read_provider_pool_state_map(state, candidates).await?;
let provider_skip_exhausted_accounts = provider_pool_state
.iter()
.map(|(provider_id, state)| (provider_id.clone(), state.skip_exhausted_accounts))
.collect::<BTreeMap<_, _>>();
let pool_provider_ids = provider_pool_state
.iter()
.filter_map(|(provider_id, state)| state.pool_enabled.then_some(provider_id.clone()))
.collect::<BTreeSet<_>>();
let provider_key_rpm_states = read_provider_key_rpm_states(state, candidates).await?;
2026-06-22 00:07:26 +08:00
let recent_candidates = if runtime_snapshot_requires_recent_candidates(
auth_snapshot,
&provider_concurrent_limits,
&provider_key_rpm_states,
now_unix_secs,
) {
state.read_recent_request_candidates(128).await?
} else {
Vec::new()
};
let key_account_quota_exhausted = read_key_account_quota_exhaustion_map(
candidates,
&provider_key_rpm_states,
&provider_skip_exhausted_accounts,
);
let key_oauth_invalid =
read_key_oauth_invalid_map(candidates, &provider_key_rpm_states, now_unix_secs);
let provider_quota_blocks_requests =
read_provider_quota_block_map(state, candidates, now_unix_secs).await?;
let provider_key_rpm_reset_ats =
read_provider_key_rpm_reset_at_map(state, candidates, now_unix_secs);
Ok(CandidateRuntimeSelectionSnapshot {
recent_candidates,
provider_concurrent_limits,
provider_key_rpm_states,
2026-05-03 20:14:29 +08:00
pool_provider_ids,
provider_quota_blocks_requests,
key_account_quota_exhausted,
key_oauth_invalid,
provider_key_rpm_reset_ats,
})
}
2026-06-22 00:07:26 +08:00
fn runtime_snapshot_requires_recent_candidates(
auth_snapshot: Option<&GatewayAuthApiKeySnapshot>,
provider_concurrent_limits: &BTreeMap<String, usize>,
provider_key_rpm_states: &BTreeMap<String, StoredProviderCatalogKey>,
now_unix_secs: u64,
) -> bool {
if auth_snapshot
.and_then(|snapshot| snapshot.api_key_concurrent_limit)
.is_some_and(|limit| limit > 0)
{
return true;
}
if provider_concurrent_limits.values().any(|limit| *limit > 0) {
return true;
}
provider_key_rpm_states.values().any(|key| {
key.concurrent_limit.is_some_and(|limit| limit > 0)
|| effective_provider_key_rpm_limit(key, now_unix_secs).is_some()
})
}
pub(super) fn auth_snapshot_concurrency_limit_reached(
auth_snapshot: Option<&GatewayAuthApiKeySnapshot>,
snapshot: &CandidateRuntimeSelectionSnapshot,
now_unix_secs: u64,
) -> bool {
auth_snapshot
.and_then(|snapshot| {
usize::try_from(snapshot.api_key_concurrent_limit?)
.ok()
.and_then(|limit| {
if limit == 0 {
return None;
}
Some((snapshot.api_key_id.as_str(), limit))
})
})
.is_some_and(|(api_key_id, limit)| {
auth_api_key_concurrency_limit_reached(
&snapshot.recent_candidates,
now_unix_secs,
api_key_id,
limit,
)
})
}
pub(super) fn is_candidate_selectable(
candidate: &SchedulerMinimalCandidateSelectionCandidate,
snapshot: &CandidateRuntimeSelectionSnapshot,
now_unix_secs: u64,
) -> bool {
2026-05-03 20:14:29 +08:00
let pool_group = snapshot
.pool_provider_ids
.contains(candidate.provider_id.as_str());
candidate_is_selectable_with_runtime_state(CandidateRuntimeSelectabilityInput {
candidate,
recent_candidates: &snapshot.recent_candidates,
provider_concurrent_limits: &snapshot.provider_concurrent_limits,
provider_key_rpm_states: &snapshot.provider_key_rpm_states,
now_unix_secs,
provider_quota_blocks_requests: snapshot
.provider_quota_blocks_requests
.get(candidate.provider_id.as_str())
.copied()
.unwrap_or(false),
2026-05-03 20:14:29 +08:00
account_quota_exhausted: !pool_group
&& snapshot
.key_account_quota_exhausted
.get(candidate.key_id.as_str())
.copied()
.unwrap_or(false),
oauth_invalid: !pool_group
&& snapshot
.key_oauth_invalid
.get(candidate.key_id.as_str())
.copied()
.unwrap_or(false),
enforce_key_circuit_breaker: !pool_group,
2026-05-03 20:14:29 +08:00
rpm_reset_at: (!pool_group)
.then(|| {
snapshot
.provider_key_rpm_reset_ats
.get(candidate.key_id.as_str())
.copied()
.flatten()
})
.flatten(),
})
}
pub(super) fn current_candidate_runtime_skip_reason(
candidate: &SchedulerMinimalCandidateSelectionCandidate,
snapshot: &CandidateRuntimeSelectionSnapshot,
now_unix_secs: u64,
) -> Option<&'static str> {
2026-05-03 20:14:29 +08:00
let pool_group = snapshot
.pool_provider_ids
.contains(candidate.provider_id.as_str());
let provider_quota_blocks_requests = snapshot
.provider_quota_blocks_requests
.get(candidate.provider_id.as_str())
.copied()
.unwrap_or(false);
2026-05-03 20:14:29 +08:00
let rpm_reset_at = (!pool_group)
.then(|| {
snapshot
.provider_key_rpm_reset_ats
.get(candidate.key_id.as_str())
.copied()
.flatten()
})
.flatten();
candidate_runtime_skip_reason_with_state(CandidateRuntimeSelectabilityInput {
candidate,
recent_candidates: &snapshot.recent_candidates,
provider_concurrent_limits: &snapshot.provider_concurrent_limits,
provider_key_rpm_states: &snapshot.provider_key_rpm_states,
now_unix_secs,
provider_quota_blocks_requests,
2026-05-03 20:14:29 +08:00
account_quota_exhausted: !pool_group
&& snapshot
.key_account_quota_exhausted
.get(candidate.key_id.as_str())
.copied()
.unwrap_or(false),
oauth_invalid: !pool_group
&& snapshot
.key_oauth_invalid
.get(candidate.key_id.as_str())
.copied()
.unwrap_or(false),
enforce_key_circuit_breaker: !pool_group,
rpm_reset_at,
})
}
pub(super) async fn read_provider_concurrent_limits(
state: &(impl SchedulerRuntimeState + ?Sized),
candidates: &[SchedulerMinimalCandidateSelectionCandidate],
) -> Result<BTreeMap<String, usize>, GatewayError> {
let provider_ids = candidates
.iter()
.map(|candidate| candidate.provider_id.clone())
.collect::<BTreeSet<_>>()
.into_iter()
.collect::<Vec<_>>();
if provider_ids.is_empty() {
return Ok(BTreeMap::new());
}
let providers = state
.read_provider_catalog_providers_by_ids(&provider_ids)
.await?;
Ok(build_provider_concurrent_limit_map(providers))
}
pub(super) async fn read_provider_key_rpm_states(
state: &(impl SchedulerRuntimeState + ?Sized),
candidates: &[SchedulerMinimalCandidateSelectionCandidate],
) -> Result<BTreeMap<String, StoredProviderCatalogKey>, GatewayError> {
let key_ids = candidates
.iter()
.map(|candidate| candidate.key_id.clone())
.collect::<BTreeSet<_>>()
.into_iter()
.collect::<Vec<_>>();
if key_ids.is_empty() {
return Ok(BTreeMap::new());
}
let keys = state.read_provider_catalog_keys_by_ids(&key_ids).await?;
Ok(keys
.into_iter()
.map(|key| (key.id.clone(), key))
.collect::<BTreeMap<_, _>>())
}
async fn read_provider_quota_block_map(
state: &(impl SchedulerRuntimeState + ?Sized),
candidates: &[SchedulerMinimalCandidateSelectionCandidate],
now_unix_secs: u64,
) -> Result<BTreeMap<String, bool>, GatewayError> {
let provider_ids = candidates
.iter()
.map(|candidate| candidate.provider_id.clone())
.collect::<BTreeSet<_>>()
.into_iter()
.collect::<Vec<_>>();
let mut quota_blocks = BTreeMap::new();
for provider_id in provider_ids {
let blocks_requests = state
.read_provider_quota_snapshot(&provider_id)
.await?
.as_ref()
.is_some_and(|quota| should_skip_provider_quota(quota, now_unix_secs));
quota_blocks.insert(provider_id, blocks_requests);
}
Ok(quota_blocks)
}
2026-05-03 20:14:29 +08:00
#[derive(Debug, Clone, Copy, Default)]
struct ProviderPoolState {
pool_enabled: bool,
skip_exhausted_accounts: bool,
}
async fn read_provider_pool_state_map(
state: &(impl SchedulerRuntimeState + ?Sized),
candidates: &[SchedulerMinimalCandidateSelectionCandidate],
2026-05-03 20:14:29 +08:00
) -> Result<BTreeMap<String, ProviderPoolState>, GatewayError> {
let provider_ids = candidates
.iter()
.map(|candidate| candidate.provider_id.clone())
.collect::<BTreeSet<_>>()
.into_iter()
.collect::<Vec<_>>();
if provider_ids.is_empty() {
return Ok(BTreeMap::new());
}
let providers = state
.read_provider_catalog_providers_by_ids(&provider_ids)
.await?;
Ok(providers
.into_iter()
.map(|provider| {
2026-05-03 20:14:29 +08:00
let pool_advanced = provider
.config
.as_ref()
2026-05-03 20:14:29 +08:00
.and_then(|value| value.get("pool_advanced"));
let skip_exhausted_accounts = pool_advanced
.and_then(serde_json::Value::as_object)
.and_then(|value| value.get("skip_exhausted_accounts"))
.and_then(serde_json::Value::as_bool)
.unwrap_or(false);
2026-05-03 20:14:29 +08:00
(
provider.id,
ProviderPoolState {
pool_enabled: pool_advanced.is_some(),
skip_exhausted_accounts,
},
)
})
.collect())
}
fn read_key_account_quota_exhaustion_map(
candidates: &[SchedulerMinimalCandidateSelectionCandidate],
provider_key_rpm_states: &BTreeMap<String, StoredProviderCatalogKey>,
provider_skip_exhausted_accounts: &BTreeMap<String, bool>,
) -> BTreeMap<String, bool> {
candidates
.iter()
.map(|candidate| {
let exhausted = provider_skip_exhausted_accounts
.get(candidate.provider_id.as_str())
.copied()
.unwrap_or(false)
&& provider_key_rpm_states
.get(candidate.key_id.as_str())
.is_some_and(|key| {
admin_provider_pool_pure::admin_pool_key_account_quota_exhausted(
key,
candidate.provider_type.as_str(),
)
});
(candidate.key_id.clone(), exhausted)
})
.collect()
}
fn read_key_oauth_invalid_map(
candidates: &[SchedulerMinimalCandidateSelectionCandidate],
provider_key_rpm_states: &BTreeMap<String, StoredProviderCatalogKey>,
now_unix_secs: u64,
) -> BTreeMap<String, bool> {
candidates
.iter()
.map(|candidate| {
let oauth_invalid = provider_key_rpm_states
.get(candidate.key_id.as_str())
.is_some_and(|key| {
key_requires_oauth_reauth(key, candidate.provider_type.as_str(), now_unix_secs)
});
(candidate.key_id.clone(), oauth_invalid)
})
.collect()
}
fn key_requires_oauth_reauth(
key: &StoredProviderCatalogKey,
provider_type: &str,
2026-05-07 11:28:44 +08:00
now_unix_secs: u64,
) -> bool {
if !key.auth_type.trim().eq_ignore_ascii_case("oauth") {
return false;
}
let invalid_reason = key
.oauth_invalid_reason
.as_deref()
.map(str::trim)
.unwrap_or_default();
if !invalid_reason.is_empty() {
2026-05-07 11:28:44 +08:00
return oauth_invalid_reason_blocks_scheduling(
key,
provider_type,
invalid_reason,
now_unix_secs,
);
}
2026-05-02 13:23:54 +08:00
false
}
2026-05-07 11:28:44 +08:00
fn oauth_invalid_reason_blocks_scheduling(
key: &StoredProviderCatalogKey,
provider_type: &str,
invalid_reason: &str,
2026-05-07 11:28:44 +08:00
now_unix_secs: u64,
) -> bool {
2026-05-07 11:28:44 +08:00
let trimmed_reason = invalid_reason.trim();
2026-05-07 03:23:20 +08:00
let account_state = admin_provider_status_pure::resolve_pool_account_state(
Some(provider_type),
key.upstream_metadata.as_ref(),
2026-05-07 11:28:44 +08:00
Some(trimmed_reason),
);
2026-05-07 11:28:44 +08:00
if account_state.blocked
2026-05-02 13:23:54 +08:00
&& !account_state.recoverable
&& account_state
.code
.as_deref()
.is_some_and(oauth_account_state_code_is_hard_block)
2026-05-07 11:28:44 +08:00
{
return true;
}
if oauth_invalid_reason_has_tag(trimmed_reason, "[REFRESH_FAILED]") {
return oauth_access_token_expired(key, now_unix_secs);
}
false
}
fn oauth_invalid_reason_has_tag(reason: &str, tag: &str) -> bool {
reason
.lines()
.map(str::trim)
.any(|line| line.starts_with(tag))
}
fn oauth_access_token_expired(key: &StoredProviderCatalogKey, now_unix_secs: u64) -> bool {
let now_unix_secs = if now_unix_secs == 0 {
SystemTime::now()
.duration_since(UNIX_EPOCH)
.ok()
.map(|duration| duration.as_secs())
.unwrap_or(0)
} else {
now_unix_secs
};
key.expires_at_unix_secs
.is_none_or(|expires_at| expires_at == 0 || expires_at <= now_unix_secs)
}
2026-05-02 13:23:54 +08:00
fn oauth_account_state_code_is_hard_block(code: &str) -> bool {
matches!(
code.trim().to_ascii_lowercase().as_str(),
"account_banned"
| "account_suspended"
| "account_disabled"
| "workspace_deactivated"
| "account_forbidden"
| "account_blocked"
| "account_verification"
2026-06-12 19:43:59 +08:00
| "oauth_token_invalid"
2026-05-02 13:23:54 +08:00
)
}
fn read_provider_key_rpm_reset_at_map(
state: &(impl SchedulerRuntimeState + ?Sized),
candidates: &[SchedulerMinimalCandidateSelectionCandidate],
now_unix_secs: u64,
) -> BTreeMap<String, Option<u64>> {
candidates
.iter()
.map(|candidate| {
(
candidate.key_id.clone(),
state.provider_key_rpm_reset_at(candidate.key_id.as_str(), now_unix_secs),
)
})
.collect::<BTreeMap<_, _>>()
}