Proxy: move or refuse prompts that do not fit the leased host's context

Implemented-By: OpenCode session (model recorded in docs/implementer-log.md)
This commit is contained in:
2026-09-25 09:56:46 -07:00
parent 959aec92f1
commit 2fe3b9c865
7 changed files with 352 additions and 6 deletions
+23
View File
@@ -194,6 +194,29 @@ func (t *Table) Acquire(k Key, candidates []string, now time.Time) (host string,
return host, false, nil
}
// Move relocates k to host, dropping any existing lease for k (on any host). It re-leases k onto
// host, deletes the old row, and records a ctx event carrying the old and new hosts. It returns an
// error only from the persister, rolling back the in-memory lease on save failure.
func (t *Table) Move(k Key, host string, now time.Time) error {
t.mu.Lock()
defer t.mu.Unlock()
var from string
if l, exists := t.leases[k]; exists {
from = l.Host
delete(t.leases, k)
_ = t.p.DeleteLease(k.Route, k.FP, k.Model)
}
l := &Lease{k, host, store.Active, now, now}
t.leases[k] = l
if err := t.save(l); err != nil {
delete(t.leases, k)
return fmt.Errorf("lease: %w", err)
}
t.event(now, k, store.ReasonCtx, from, host)
return nil
}
// Candidates records hosts as seen for route (idempotent), so Pin can accept a host the route
// is configured for before any request has used it. cmd/crossbar calls it for every route at
// start; the admin handler calls it before Pin.