mirror of
https://github.com/bytedance/deer-flow.git
synced 2026-08-06 12:59:09 +00:00
* feat(checkpoint): dual-mode checkpoint storage with LangGraph DeltaChannel
Add a restart-required database.checkpoint_channel_mode ("full" default,
"delta") that stores the messages channel via LangGraph 1.2 DeltaChannel,
cutting checkpoint storage from O(n^2) to O(n) for append-only history.
Existing full checkpoints seed delta state transparently; no data migration.
- config: mode schema + freeze-on-first-use with
CheckpointModeReconfigurationError; mode marker persisted in checkpoint
metadata; unsafe delta->full downgrade rejected fail-closed with
CheckpointModeMismatchError (run-level error, failed state read)
- state: delta message state schema; CheckpointStateAccessor centralizes
materialized reads for all consumers (threads API, branches,
regeneration, compaction, state updates, memory, goal workers)
- runtime: raw writers (run durations, interrupted title, thread goal)
parent their checkpoints to the checkpoint they derive from, preserving
delta ancestry; rollback forks the pre-run lineage through a state
mutation graph with Overwrite restores; InMemorySaver delta-history
override delegates to the base walk (fixes dropped first write after
migration, also present upstream)
- tests: conformance suite over {memory, sqlite, postgres} covering
migration replay, stable message IDs, storage shape and writer
preservation; conftest fixture isolates the frozen mode between tests;
stale config fakes refreshed
- ci: backend unit tests gain a postgres service
* fix(checkpoint): close materialization gaps in goal flow, guard public factory
- Route goal-continuation message reads through CheckpointStateAccessor:
raw channel_values reads see the delta sentinel in delta mode, which
disabled goal continuation (stand_down=no_durable_end_of_turn) after
durable assistant turns. Raw tuples remain for tuple-only metadata
(checkpoint id, pending_writes).
- Reject checkpoint_channel_mode='delta' + checkpointer in
create_deerflow_agent at construction: factory-built persisted graphs
bypass mode-marker injection and the fail-closed gate, reproducing
silent mixed-mode state loss. Delta without persistence stays allowed.
- Import the postgres saver lazily (pytest.importorskip in the fixture)
so the documented default install collects the suite; add a CI job
running pytest --collect-only on uv sync --group dev without extras.
- Fix test_checkpointer fallback test to patch get_app_config at its
use site (provider module), making it deterministic when a local
config.yaml selects a persistent backend.
* fix(gateway): preserve extension-owned channels in state mutations, bump config version
- build_state_mutation_graph / build_checkpoint_state_mutation_accessor
accept an explicit state_schema; branch and POST /state now compile the
mutation graph from the thread's effective schema
(graph_state_schema on the assistant graph). The base-ThreadState
fallback silently discarded channels contributed by custom
AgentMiddleware.state_schema on branch (data loss) and returned a
false-success 200 on POST /state.
- POST /state validates values keys against the mutation graph's
channels and rejects unknown fields with 422 instead of ignoring
them; reducer detection covers extension channels
(BinaryOperatorAggregate or DeltaChannel) so Overwrite replace
semantics work for middleware reducers in both modes.
- Endpoint regression: custom AgentMiddleware.state_schema value
survives branch, updates through POST /state, and an unknown field
receives 422.
- config_version 26 -> 27 for the new database.checkpoint_channel_mode
(example, Helm chart values + README, support-bundle fixture), so
existing installs get the outdated-config warning and
make config-upgrade merges the field; covered by a test driving the
real example file and the real config-upgrade script.
* fix(gateway): resolve assistant schema via one boundary, copy branch reducer values with Overwrite
GET /threads/{id}/state now resolves the thread's assistant_id through a
single reusable boundary (thread metadata -> assistant_id -> effective
graph), so channels contributed by a custom AgentMiddleware.state_schema
are materialized instead of dropped by the default lead schema. POST
/state uses the same boundary instead of resolving the schema ad hoc.
Branch writes wrap every copied reducer channel in Overwrite (derived
from the effective mutation graph: BinaryOperatorAggregate + DeltaChannel),
not just messages, so already-aggregated values are never re-merged.
Regression tests use a real AgentMiddleware.state_schema with a
non-identity reducer in both full and delta modes: GET /state returns the
extension value, POST /state replaces it, branch preserves it
byte-for-byte; the unknown-field 422 is a separate assertion.
* refactor(checkpoint): collapse read-path round-trips and ship dual-mode parity tests
Address review round 4 on PR #4292:
- Push ahistory/history limit through Pregel into checkpointer.alist
(SQL LIMIT) instead of materializing all rows and breaking in Python
- Fold the read-side mode-compat gate onto the returned snapshot's
metadata; only writes keep the pre-write tuple fetch (fail-closed)
- Cache factory-built accessor graphs per (assistant_id, mode) with
factory-identity revalidation; state reads no longer build a lead
agent per request
- get_thread: one snapshot fetch + one raw pending_writes fetch on the
resolved checkpoint (post-checkpoint __error__ writes never surface
in snapshot.tasks; verified empirically)
- DeerFlowClient.get_thread: single checkpointer.list walk collects
pending_writes per checkpoint instead of N get_tuple calls
- InMemorySaver delta-history patch: stand-down when the upstream
override disappears, try/except guard, validated-version warning,
guard tests
- make_lead_agent mode precedence: first freeze is owned by app_config
(client-supplied configurable key ignored); once frozen, injected
key/app_config must match or fail closed
- Rollback: lock in non-message channel restoration via fork
inheritance with a dedicated reducer-channel test
- Add tests/test_threads_checkpoint_mode.py and
tests/test_gateway_checkpoint_mode.py referenced by AGENTS.md and
the PR validation section: lifecycle parity (memory + sqlite),
per-step blob-count storage guard, gateway endpoint parity
Counted-saver tests pin checkpoint round-trips for aget/ahistory so
these regressions cannot silently return.
* fix(checkpoint): precise mode-mismatch HTTP mapping, gate E2E, and accessor resilience
- threads router: map CheckpointModeMismatchError to 409 (with cause and
thread id) and CheckpointModeReconfigurationError to 503 across all state
endpoints instead of swallowing both into a generic 500
- gate coverage: seed a real delta checkpoint into AsyncSqliteSaver and
assert aget/aupdate/ahistory fail closed; assert 409 at the HTTP boundary
through the real route stack
- rollback: compile the restore mutation graph with the thread's effective
state schema per the build_state_mutation_graph contract
- inheritance contract locks: rollback and manual compaction preserve
middleware-contributed channels via checkpoint fork cloning
- services: revalidate the accessor-graph cache against app_config identity
so config.yaml hot-reloads never serve a stale compiled graph
- services: degrade full-mode state reads to raw checkpointer reads when the
agent factory is unavailable (delta gate still applies; delta mode has no
fallback)
- deps: override websockets==16.0 (langgraph-sdk 0.4.2's <16 pin silently
downgraded 16.0 -> 15.0.1; pin is not grounded in any API incompatibility)
and bump the langchain lower bound to what the lockfile actually resolves
* fix(checkpoint): include anchor checkpoint in degraded history walk + cover get_thread
- _RawCheckpointReadAccessor.ahistory: alist(before=...) is exclusive while
pregel's get_state_history treats config.checkpoint_id as the inclusive
start; fetch the anchor explicitly so both read paths paginate identically
- extend the degraded-path gateway test: GET /thread returns raw values, and
POST /history with before starts at the anchor checkpoint
* fix(gateway): preserve degraded checkpoint timestamps
* fix(gateway): harden degraded checkpoint access
* fix(gateway): resolve assistants for checkpoint reads
---------
Co-authored-by: Willem Jiang <willem.jiang@gmail.com>
277 lines
12 KiB
Python
277 lines
12 KiB
Python
"""Dual-mode (full/delta) parity for the gateway thread-state endpoints.
|
|
|
|
Drives ``GET /api/threads/{id}``, ``GET /api/threads/{id}/state`` and
|
|
``POST /api/threads/{id}/history`` through the real route stack
|
|
(``build_thread_checkpoint_state_accessor`` -> factory-built graph ->
|
|
``CheckpointStateAccessor``) against a real ``InMemorySaver``, once per
|
|
checkpoint channel mode, and asserts the wire responses are identical apart
|
|
from checkpoint ids/timestamps. The delta storage layout must be invisible
|
|
to API consumers.
|
|
"""
|
|
|
|
from __future__ import annotations
|
|
|
|
import asyncio
|
|
from types import SimpleNamespace
|
|
from typing import Any
|
|
from unittest.mock import AsyncMock
|
|
|
|
import pytest
|
|
from _router_auth_helpers import make_authed_test_app
|
|
from fastapi.testclient import TestClient
|
|
from langchain_core.messages import AIMessage, HumanMessage
|
|
from langgraph.checkpoint.memory import InMemorySaver
|
|
from langgraph.graph import StateGraph
|
|
from langgraph.store.memory import InMemoryStore
|
|
|
|
from app.gateway import services as gateway_services
|
|
from app.gateway.routers import threads
|
|
from deerflow.agents.thread_state import get_thread_state_schema
|
|
from deerflow.config.app_config import AppConfig, reset_app_config, set_app_config
|
|
from deerflow.persistence.thread_meta.memory import MemoryThreadMetaStore
|
|
from deerflow.runtime.checkpoint_mode import checkpoint_metadata_uses_delta, inject_checkpoint_mode
|
|
|
|
_THREAD_ID = "thread-gateway-parity"
|
|
|
|
|
|
@pytest.fixture
|
|
def _stub_app_config():
|
|
set_app_config(AppConfig.model_validate({"sandbox": {"use": "deerflow.sandbox.local:LocalSandboxProvider"}}))
|
|
yield
|
|
reset_app_config()
|
|
|
|
|
|
def _build_reply_graph(mode: str, checkpointer: Any):
|
|
async def _reply(state: dict[str, Any]) -> dict[str, Any]:
|
|
n = len(state.get("messages") or [])
|
|
return {"messages": [AIMessage(content=f"answer-{n}", id=f"a{n}")]}
|
|
|
|
builder = StateGraph(get_thread_state_schema(mode))
|
|
builder.add_node("reply", _reply)
|
|
builder.set_entry_point("reply")
|
|
builder.set_finish_point("reply")
|
|
return builder.compile(checkpointer=checkpointer)
|
|
|
|
|
|
def _message_wire_shape(messages: list[dict[str, Any]]) -> list[tuple[str, str, str]]:
|
|
return [(message.get("type"), message.get("content"), message.get("id")) for message in messages]
|
|
|
|
|
|
def _run_gateway_flow(mode: str, monkeypatch: pytest.MonkeyPatch) -> dict[str, Any]:
|
|
app = make_authed_test_app()
|
|
store = InMemoryStore()
|
|
checkpointer = InMemorySaver()
|
|
app.state.store = store
|
|
app.state.checkpointer = checkpointer
|
|
app.state.thread_store = MemoryThreadMetaStore(store)
|
|
app.state.checkpoint_channel_mode = mode
|
|
app.state.run_event_store = SimpleNamespace()
|
|
app.include_router(threads.router)
|
|
|
|
graph = _build_reply_graph(mode, checkpointer)
|
|
monkeypatch.setattr(
|
|
gateway_services,
|
|
"resolve_agent_factory",
|
|
lambda assistant_id=None: lambda config: graph,
|
|
)
|
|
|
|
config: dict[str, Any] = {"configurable": {"thread_id": _THREAD_ID}}
|
|
inject_checkpoint_mode(config, mode)
|
|
for i in range(2):
|
|
asyncio.run(graph.ainvoke({"messages": [HumanMessage(content=f"question-{i}", id=f"h{i}")]}, config))
|
|
|
|
with TestClient(app) as client:
|
|
thread_response = client.get(f"/api/threads/{_THREAD_ID}")
|
|
state_response = client.get(f"/api/threads/{_THREAD_ID}/state")
|
|
history_response = client.post(f"/api/threads/{_THREAD_ID}/history", json={"limit": 10})
|
|
|
|
assert thread_response.status_code == 200, thread_response.text
|
|
assert state_response.status_code == 200, state_response.text
|
|
assert history_response.status_code == 200, history_response.text
|
|
|
|
thread_payload = thread_response.json()
|
|
state_payload = state_response.json()
|
|
history_payload = history_response.json()
|
|
|
|
return {
|
|
"thread_status": thread_payload["status"],
|
|
"thread_messages": _message_wire_shape(thread_payload["values"]["messages"]),
|
|
"state_messages": _message_wire_shape(state_payload["values"]["messages"]),
|
|
"history_messages": [_message_wire_shape(snapshot["values"].get("messages", [])) for snapshot in history_payload],
|
|
}
|
|
|
|
|
|
def test_thread_state_endpoints_are_mode_invariant(_stub_app_config, monkeypatch: pytest.MonkeyPatch) -> None:
|
|
full = _run_gateway_flow("full", monkeypatch)
|
|
monkeypatch.undo()
|
|
delta = _run_gateway_flow("delta", monkeypatch)
|
|
assert full == delta
|
|
# Guard against a vacuous pass: the flow must have observed real messages.
|
|
assert full["thread_messages"], "expected seeded messages in the thread response"
|
|
assert any(full["history_messages"]), "expected history snapshots with messages"
|
|
|
|
|
|
def test_full_mode_gateway_rejects_delta_thread_with_409(_stub_app_config, monkeypatch: pytest.MonkeyPatch) -> None:
|
|
"""Fail-closed gate at the HTTP boundary, against a real checkpointer.
|
|
|
|
A full-mode process opening a delta thread must get a precise 409 naming
|
|
the cause — not a generic 500 that forces operators to grep logs. Seeds a
|
|
real delta checkpoint through the delta graph (marker + LangGraph delta
|
|
counters land in checkpoint metadata), then exercises every state surface
|
|
of the threads router in full mode.
|
|
"""
|
|
app = make_authed_test_app()
|
|
store = InMemoryStore()
|
|
checkpointer = InMemorySaver()
|
|
app.state.store = store
|
|
app.state.checkpointer = checkpointer
|
|
app.state.thread_store.get = AsyncMock(return_value=None)
|
|
app.state.checkpoint_channel_mode = "full"
|
|
app.state.run_event_store = SimpleNamespace()
|
|
app.include_router(threads.router)
|
|
|
|
full_graph = _build_reply_graph("full", checkpointer)
|
|
monkeypatch.setattr(
|
|
gateway_services,
|
|
"resolve_agent_factory",
|
|
lambda assistant_id=None: lambda config: full_graph,
|
|
)
|
|
|
|
# Seed through the delta graph so the checkpoint carries the delta marker.
|
|
delta_graph = _build_reply_graph("delta", checkpointer)
|
|
config: dict[str, Any] = {"configurable": {"thread_id": _THREAD_ID}}
|
|
inject_checkpoint_mode(config, "delta")
|
|
asyncio.run(delta_graph.ainvoke({"messages": [HumanMessage(content="question", id="h0")]}, config))
|
|
latest = asyncio.run(checkpointer.aget_tuple({"configurable": {"thread_id": _THREAD_ID, "checkpoint_ns": ""}}))
|
|
assert checkpoint_metadata_uses_delta(latest.metadata), "seed did not produce a delta checkpoint"
|
|
|
|
with TestClient(app) as client:
|
|
state_response = client.get(f"/api/threads/{_THREAD_ID}/state")
|
|
assert state_response.status_code == 409, state_response.text
|
|
assert "requires delta mode" in state_response.json()["detail"]
|
|
assert _THREAD_ID in state_response.json()["detail"]
|
|
|
|
update_response = client.post(f"/api/threads/{_THREAD_ID}/state", json={"values": {"title": "x"}})
|
|
assert update_response.status_code == 409, update_response.text
|
|
assert "requires delta mode" in update_response.json()["detail"]
|
|
|
|
history_response = client.post(f"/api/threads/{_THREAD_ID}/history", json={"limit": 10})
|
|
assert history_response.status_code == 409, history_response.text
|
|
assert "requires delta mode" in history_response.json()["detail"]
|
|
|
|
thread_response = client.get(f"/api/threads/{_THREAD_ID}")
|
|
assert thread_response.status_code == 409, thread_response.text
|
|
assert "requires delta mode" in thread_response.json()["detail"]
|
|
|
|
|
|
def test_full_mode_state_reads_degrade_to_raw_checkpointer_when_factory_fails(_stub_app_config, monkeypatch: pytest.MonkeyPatch) -> None:
|
|
"""Full-mode read endpoints survive a broken agent factory.
|
|
|
|
Full-mode checkpoints persist complete channel_values, so when the agent
|
|
factory cannot build the graph (bad model config, MCP server down), state
|
|
reads degrade to raw checkpointer reads instead of 500ing. The fail-closed
|
|
delta gate must still apply on the degraded path.
|
|
"""
|
|
app = make_authed_test_app()
|
|
store = InMemoryStore()
|
|
checkpointer = InMemorySaver()
|
|
app.state.store = store
|
|
app.state.checkpointer = checkpointer
|
|
app.state.thread_store.get = AsyncMock(return_value=None)
|
|
app.state.checkpoint_channel_mode = "full"
|
|
app.state.run_event_store = SimpleNamespace()
|
|
app.include_router(threads.router)
|
|
|
|
full_graph = _build_reply_graph("full", checkpointer)
|
|
config: dict[str, Any] = {"configurable": {"thread_id": _THREAD_ID}}
|
|
inject_checkpoint_mode(config, "full")
|
|
for i in range(2):
|
|
asyncio.run(full_graph.ainvoke({"messages": [HumanMessage(content=f"question-{i}", id=f"h{i}")]}, config))
|
|
latest = asyncio.run(checkpointer.aget_tuple(config))
|
|
assert latest is not None
|
|
latest_created_at = latest.checkpoint["ts"]
|
|
|
|
def _broken_factory(assistant_id=None):
|
|
def _factory(config):
|
|
raise RuntimeError("model config broken")
|
|
|
|
return _factory
|
|
|
|
monkeypatch.setattr(gateway_services, "resolve_agent_factory", _broken_factory)
|
|
|
|
with TestClient(app) as client:
|
|
state_response = client.get(f"/api/threads/{_THREAD_ID}/state")
|
|
assert state_response.status_code == 200, state_response.text
|
|
values = state_response.json()["values"]
|
|
assert state_response.json()["created_at"] == latest_created_at
|
|
assert state_response.json()["checkpoint"]["ts"] == latest_created_at
|
|
assert _message_wire_shape(values["messages"]) == [
|
|
("human", "question-0", "h0"),
|
|
("ai", "answer-1", "a1"),
|
|
("human", "question-1", "h1"),
|
|
("ai", "answer-3", "a3"),
|
|
]
|
|
# next/tasks are not derivable without the compiled graph.
|
|
assert state_response.json()["next"] == []
|
|
|
|
history_response = client.post(f"/api/threads/{_THREAD_ID}/history", json={"limit": 10})
|
|
assert history_response.status_code == 200, history_response.text
|
|
entries = history_response.json()
|
|
assert len(entries) >= 2
|
|
assert all(entry["created_at"] for entry in entries)
|
|
|
|
# History pagination: config.checkpoint_id is the *inclusive* anchor
|
|
# (pregel semantics), so the degraded path must include it too.
|
|
anchor_id = entries[1]["checkpoint_id"]
|
|
paged_response = client.post(f"/api/threads/{_THREAD_ID}/history", json={"limit": 10, "before": anchor_id})
|
|
assert paged_response.status_code == 200, paged_response.text
|
|
assert paged_response.json()[0]["checkpoint_id"] == anchor_id
|
|
|
|
app.state.thread_store.get = AsyncMock(
|
|
return_value={
|
|
"thread_id": _THREAD_ID,
|
|
"assistant_id": None,
|
|
"status": "interrupted",
|
|
"created_at": latest_created_at,
|
|
"updated_at": latest_created_at,
|
|
"metadata": {},
|
|
}
|
|
)
|
|
thread_response = client.get(f"/api/threads/{_THREAD_ID}")
|
|
assert thread_response.status_code == 200, thread_response.text
|
|
assert thread_response.json()["status"] == "interrupted"
|
|
assert _message_wire_shape(thread_response.json()["values"]["messages"]) == [
|
|
("human", "question-0", "h0"),
|
|
("ai", "answer-1", "a1"),
|
|
("human", "question-1", "h1"),
|
|
("ai", "answer-3", "a3"),
|
|
]
|
|
|
|
# The fail-closed gate still applies on the degraded path: a delta
|
|
# checkpoint is a precise 409, never silently served as partial state.
|
|
delta_graph = _build_reply_graph("delta", checkpointer)
|
|
delta_config: dict[str, Any] = {"configurable": {"thread_id": "thread-degraded-delta"}}
|
|
inject_checkpoint_mode(delta_config, "delta")
|
|
asyncio.run(delta_graph.ainvoke({"messages": [HumanMessage(content="q", id="h0")]}, delta_config))
|
|
delta_response = client.get("/api/threads/thread-degraded-delta/state")
|
|
assert delta_response.status_code == 409, delta_response.text
|
|
assert "requires delta mode" in delta_response.json()["detail"]
|
|
|
|
|
|
def test_mutation_accessor_fails_closed_when_thread_metadata_lookup_fails(monkeypatch: pytest.MonkeyPatch) -> None:
|
|
app = make_authed_test_app()
|
|
app.state.thread_store.get = AsyncMock(side_effect=RuntimeError("metadata store unavailable"))
|
|
resolve_factory = AsyncMock()
|
|
monkeypatch.setattr(gateway_services, "resolve_agent_factory", resolve_factory)
|
|
|
|
with pytest.raises(RuntimeError, match="metadata store unavailable"):
|
|
asyncio.run(
|
|
gateway_services.build_thread_checkpoint_state_mutation_accessor(
|
|
SimpleNamespace(app=app),
|
|
thread_id="custom-assistant-thread",
|
|
as_node="manual_state_update",
|
|
)
|
|
)
|
|
|
|
resolve_factory.assert_not_called()
|