🍞 feat: Start Standalone Bun and Hono RAG Service - #330
lia-by-librechat[bot] wants to merge 6 commits into
Conversation
|
Ready for review at pushed head This is a disabled-by-default DOCX Verification on this head: 323 non-container tests passed, 6 skipped; Black, compilation, pip compatibility, and diff checks passed. Container-backed PostgreSQL verification was attempted but blocked by an inaccessible localhost port from the sandbox; the CI lane will exercise it. Subsystem review covered parser refusal before fallback, bounded input/output and admission, media-omission signaling, auth gates, worker crash/timeout/cancellation and temp cleanup, legacy |
|
Ready for review at new pushed head Follow-up to the first working pass: the opt-in extraction router is now absent at startup unless The real HTTP DOCX/worker contract checks pass (21 tests). The complete non-container suite has been dispatched on this head. The prior head passed GitHub CI including its configured database lane, but that CI result does not cover this follow-up commit; the new CI run is the authoritative one. The sandbox cannot reach its own Docker-published localhost port, so local SQL assertions remain unverified. |
|
Ready for review at exact pushed head This head starts the standalone Bun/Hono service, not the prior Python extension. It removes the branch's Python application, dependency and CI additions, preserving those paths exactly as on The exact Markdown fixture is preserved. Real native tests cover auth denial, partial media, unsafe input/output, crash/deadline/cancellation/retry, bounded FIFO and actual Bun HTTP disconnect cleanup. A separately built Python-free container passed its real HTTP/health/native DOCX smoke. Exact-head local checks and both CI lanes are running, together with an independent read-only review. Results of the old Python implementation are not reused as evidence for this head. |
|
Ready for review at exact pushed head The independent first-round review returned three P2 findings, all supported and fixed in this commit:
Two self-check findings are also fixed: cancel unread body producers before releasing their reader lock (assertion fails against previous head), and disable Bun dotenv loading in native children (canary regression). Metadata XML refuses DTDs and external main-part targets. These changes preserve the old Python app and its requirements/CI unchanged. The expanded local suite passed 28 tests before this push. Exact-head tests, typecheck, formatting, runtime dependency audit and Python-free container/native smoke are now dispatched alongside both CI lanes. A fresh independent review targets this SHA; the first-round review does not cover the new head. |
Summary
Start the new standalone Bun/Hono RAG service, under
service/, with an opt-in DOCXPOST /v1/extractprofile. This replaces the earlier Python implementation on this PR branch. It is not a Hono proxy: extraction runs through the Node AnyDoc native binding in killable Bun child processes.The base-to-head diff contains no changes to Python application code, its requirements, its existing CI job, database schema, ingestion or
/text. The old service remains the compatibility and rollback path. No LibreChat caller is cut over yet, and the new service does not yet implement retrieval, embeddings, reranking or PDF/OCR support. Do not repoint LibreChat's existingRAG_API_URLuntil its migration and remaining endpoint contracts are implemented.Mechanism
RAG_JWT_SECRET, expiry/subject/issuer/audience validation andrag:documents; inference-only and legacy session tokens are refused. Startup refuses using the application session key as the service key.document-v1response shape and exact Markdown output are preserved on Marco's DOCX fixture. Parser provenance is pinned to AnyDoc 0.1.3. Package relationships and content types detect embedded artwork/objects even without an image filename extension, and mark the result partial; thumbnail artwork does not. The root OPC relationship resolves the main document, including nonconventional package locations. No hosted OCR or fallback occurs inside the endpoint.Verification
tsc --noEmit)git diff --checkTests preserve the Python prototype's golden DOCX contract and cover partial media, auth and scope denial, disabled-route behavior, MIME/profile routing, malformed/duplicate multipart, chunked input ceilings, archive size and entry refusals, empty extraction, IPC overproduction, crash/malformed child output, timeout, cancellation/retry, admission-before-body reads, FIFO queued cancellation, and real Bun HTTP disconnects. Only crash/hang/overproduction programs are injected; successful extraction uses the real pinned native binding.
The first independent review returned three P2 findings (non-image artwork filenames, listener idle timeout, relocated main document), all fixed in
c967dee985ea26d1de7dd77fcd1b37cbd05f8c4dwith regressions. Two additional self-check P2 findings (body producer cancellation and child dotenv loading) are fixed in the same head. No findings were rejected. A fresh independent review of that exact pushed head is running alongside CI. Neither old CI results nor Python prototype tests are presented as covering the new Bun implementation.Deliberate boundaries
This is the first service slice, not a complete Python replacement. No performance benchmark, browser/LibreChat integration, reranking-quality evaluation, PDF fidelity run or traffic cutover is part of this head. Strict scoped RAG token minting must be wired in the forthcoming LibreChat adapter.
completenessis conservative known-omission reporting, not a universal proof of inspectability. Concurrency limits are per process, not billing quotas.EXTRACTION.mdrecords the independent install/image commands, config, wire contract, error taxonomy, compatibility limits and next slice. Keep raw text, semantic extraction, rich HTML preview and complete content inspection distinct as consumers migrate.Graph checks used
rag_api/lia/document-extraction-contractat15d84b85443f8cf4e23d083c4af6b135ce3f5344for removing the old Python additions, supplemented by source/string inspection. The newservice/sources were local-only during those checks. Full graph dependency closure was not computed.