feat: record and expose terminal upstream interception errors (#26961)

Categorises the terminal error of a failed interception and persists it
on the interception record, then surfaces it on the AI Gateway API.

- Categorise into an enum (`bad_request`, `unauthorized`,
  `rate_limited`, `overloaded`, `server_error`, `unknown`), unwrapping
  the ResponseError envelope, the upstream Anthropic/OpenAI SDK errors,
  and key-pool exhaustion so blocking and streaming paths agree.
- Thread the type and raw message through the recorder dRPC into the
  `aibridge_interceptions` row (optional proto fields; NULL on success).
- Expose the error on the AI Gateway thread API from the root
  interception.

*This PR was produced by opencode (agent) using the `anthropic/claude-opus-4-8` model, under human direction and review.*
This commit is contained in:
Danny Kopping
2026-07-09 15:36:56 +02:00
committed by GitHub
parent 63497ee9d8
commit ef0b5585d5
34 changed files with 1212 additions and 322 deletions
+11
View File
@@ -1281,6 +1281,17 @@ func buildAIBridgeThread(
n := rootIntc.AgentFirewallSequenceNumber.Int32
thread.AgentFirewallSequenceNumber = &n
}
// Surface the terminal upstream error from the root interception. The
// message is only meaningful alongside a type, so it is nested to avoid
// a half-populated error on the response.
if rootIntc.ErrorType.Valid {
errType := string(rootIntc.ErrorType.AIBridgeInterceptionErrorType)
thread.ErrorType = &errType
if rootIntc.ErrorMessage.Valid {
errMsg := rootIntc.ErrorMessage.String
thread.ErrorMessage = &errMsg
}
}
}
// Compute thread time bounds from interceptions.