fix: harden model catalog projections
This commit is contained in:
@@ -14,6 +14,7 @@ const maxCatalogModels = 64
|
||||
|
||||
var catalogKeyPattern = regexp.MustCompile(`^[a-z][a-z0-9._-]{0,63}$`)
|
||||
var catalogModelIDPattern = regexp.MustCompile(`^[a-z][a-z0-9._-]{0,63}/[A-Za-z0-9][A-Za-z0-9._:-]{0,255}$`)
|
||||
var catalogUpstreamModelPattern = regexp.MustCompile(`^[A-Za-z0-9][A-Za-z0-9._:-]{0,255}$`)
|
||||
var catalogAPIVersionPattern = regexp.MustCompile(`^[A-Za-z0-9][A-Za-z0-9._-]{0,127}$`)
|
||||
|
||||
// ModelCatalog is the only operator-authored source for model identity and runtime eligibility.
|
||||
@@ -163,11 +164,23 @@ func (c ModelCatalog) Validate(environment map[string]string) error {
|
||||
return err
|
||||
}
|
||||
hasSession, providerHasMetadata := false, false
|
||||
upstreamModels := make(map[string]string)
|
||||
for modelID, model := range provider.Models {
|
||||
if !catalogKeyPattern.MatchString(modelID) {
|
||||
return fmt.Errorf("modelCatalog model %q/%q is invalid", providerID, modelID)
|
||||
}
|
||||
canonical := providerID + "/" + modelID
|
||||
upstream := model.UpstreamModel
|
||||
if upstream == "" {
|
||||
upstream = modelID
|
||||
}
|
||||
if !catalogUpstreamModelPattern.MatchString(upstream) {
|
||||
return fmt.Errorf("modelCatalog model %q upstreamModel is invalid", canonical)
|
||||
}
|
||||
if existing, duplicate := upstreamModels[upstream]; duplicate {
|
||||
return fmt.Errorf("modelCatalog models %q and %q use the same upstreamModel", existing, canonical)
|
||||
}
|
||||
upstreamModels[upstream] = canonical
|
||||
if model.Session == nil && model.MetadataGeneration == nil {
|
||||
return fmt.Errorf("modelCatalog model %q has no runtime use", canonical)
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user