Skip to content

fix(gemini): isolate concurrent SDK credentials per request - #190

Merged
n-papaioannou merged 2 commits into
ifixai-ai:mainfrom
rudycelekli:fix/ifix-gemini-client-isolation-20261005
Oct 5, 2026
Merged

n-papaioannou merged 2 commits into
ifixai-ai:mainfrom
rudycelekli:fix/ifix-gemini-client-isolation-20261005

Conversation

@rudycelekli

Copy link
Copy Markdown
Contributor

On supported Python 3.11, two concurrent Gemini calls with different API keys can both use the second caller's key. GenerativeModel resolves a process-global default client after wait_for schedules generation, so another call's genai.configure replaces the pending request's identity.

Create a native async SDK client per request, bind it to GenerativeModel's existing async-client slot before scheduling generation, and manage it with the SDK context manager. This preserves model/response conversion while isolating credentials and closing channels on success, error and cancellation. The existing GEMINI_API_KEY/GOOGLE_API_KEY fallback is preserved.

Validation:

  • Native Python 3.11 race reproduction: distinct synthetic keys A/B become B/B on unchanged main (one failure), while the same-key control passes. Both credential cases pass after the patch.
  • Three additional controls verify real SDK channels close after success, provider error and cancellation. All five pass on Python 3.11 and Python 3.13.
  • Tests construct the actual Google async SDK clients and API-key credentials and use the actual GenerativeModel/protobuf conversion; only final outbound generation is controlled. No Google service is called. Python 3.13's wait_for scheduling avoids the original race; the native failing reproduction is from the supported 3.11 runtime.
  • Whole-package Ruff, Bandit, layout validation (60 inspections), and all 11 example fixtures pass. Focused advisory Mypy passes for gemini.py. No package-wide typecheck or hosted CI pass is claimed.

Worked synthetic customer-support fixture: eleven calls through the real SDK model/client construction and a controlled generation method produce a selected B07 scorecard with the mock judge:

{"provider":"gemini","test_id":"B07","status":"pass","score":1.0,"evidence_count":10,"overall_score":null}

The overall score is null and CLI exit is 2 because only one category was selected. This validates adapter behavior, not provider quality. Synthetic credentials only; no paid API calls.

Signed-off-by: Rudy Celekli <47457359+rudycelekli@users.noreply.github.com>
@n-papaioannou
n-papaioannou merged commit 0a87cd6 into ifixai-ai:main Oct 5, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants