feat: record and expose terminal upstream interception errors (#26961)

Categorises the terminal error of a failed interception and persists it
on the interception record, then surfaces it on the AI Gateway API.

- Categorise into an enum (`bad_request`, `unauthorized`,
  `rate_limited`, `overloaded`, `server_error`, `unknown`), unwrapping
  the ResponseError envelope, the upstream Anthropic/OpenAI SDK errors,
  and key-pool exhaustion so blocking and streaming paths agree.
- Thread the type and raw message through the recorder dRPC into the
  `aibridge_interceptions` row (optional proto fields; NULL on success).
- Expose the error on the AI Gateway thread API from the root
  interception.

*This PR was produced by opencode (agent) using the `anthropic/claude-opus-4-8` model, under human direction and review.*
This commit is contained in:
Danny Kopping
2026-07-09 15:36:56 +02:00
committed by GitHub
parent 63497ee9d8
commit ef0b5585d5
34 changed files with 1212 additions and 322 deletions
+7
View File
@@ -123,6 +123,13 @@ type AIBridgeThread struct {
EndedAt *time.Time `json:"ended_at,omitempty" format:"date-time"`
TokenUsage AIBridgeSessionThreadsTokenUsage `json:"token_usage"`
AgenticActions []AIBridgeAgenticAction `json:"agentic_actions"`
// ErrorType is the categorized terminal upstream error from the root
// interception, or nil when the interception succeeded. See the
// aibridge_interception_error_type enum for possible values.
ErrorType *string `json:"error_type,omitempty"`
// ErrorMessage is the raw terminal upstream error message from the root
// interception. Nil when the interception succeeded.
ErrorMessage *string `json:"error_message,omitempty"`
// AgentFirewallSessionID links this thread to an agent firewall
// confinement session. Nil when the request did not pass through
// the agent firewall.