Skip to content

fix: preserve system prompt injection through upstream extproc filter - #2745

Open
steffen-karlsson wants to merge 3 commits into
theagentrouter:mainfrom
steffen-karlsson:fix/preserve-system-prompt-
Open

steffen-karlsson wants to merge 3 commits into
theagentrouter:mainfrom
steffen-karlsson:fix/preserve-system-prompt-

Conversation

@steffen-karlsson

@steffen-karlsson steffen-karlsson commented Sep 26, 2026 •

Copy link
Copy Markdown

Description

When multiple ext_proc filters are chained (e.g. a custom filter that modifies the request body, followed by the AI Gateway upstream filter), the upstream filter clobbers any body mutations made by earlier filters.

The upstream filter used request_body_mode: NONE, so it captured originalRequestBodyRaw in ProcessRequestHeaders before any other HTTP-level filter had a chance to run. It then issued CONTINUE_AND_REPLACE with that stale snapshot whenever modelNameOverride, forceBodyMutation, or httpBodyMutation was active — silently replacing the body that earlier filters had modified.

Additionally, the header_mutation filter (which appended content-length from dynamic metadata) was redundant: content-length is already set directly in the BodyMutation response when the body changes.

Fix

  • RequestBodyMode: BUFFERED — the upstream filter now receives the actual request body (after all HTTP-level filters have processed it) in ProcessRequestBody, instead of replaying a stale snapshot from ProcessRequestHeaders.

  • Split headers and body processing — ProcessRequestHeaders now does header-level mutations only (path rewrite, auth, route header mutations, sensitive header stripping). Body-level mutations (translator RequestBody, httpBodyMutation) are deferred to ProcessRequestBody.

  • Moved backend auth to ProcessRequestBody — auth handlers like AWS SigV4 need the final body for payload signing. With the body no longer available in ProcessRequestHeaders, auth is performed in ProcessRequestBody where the actual (possibly translated/mutated) body is available.

  • Removed forceBodyMutation in router processor — the stream_options.include_usage mutation is applied immediately via BodyMutation + CONTINUE_AND_REPLACE in the router's ProcessRequestBody, so the upstream filter no longer needs to force-replace the body.

  • Removed header_mutation filter — content-length is set directly on the BodyMutation response, making the dynamic-metadata-based header_mutation filter unnecessary.

Testing

  • All existing unit tests pass (internal/extproc/..., internal/extensionserver/...)
  • Tests updated to call ProcessRequestBody after ProcessRequestHeaders and assert that body mutations and auth headers are in the body response

Related Issues/PRs (if applicable)
#2671 and #2720

Special notes for reviewers (if applicable)
N/A

@steffen-karlsson
steffen-karlsson requested a review from a team as a code owner September 26, 2026 16:02
@netlify

netlify Bot commented Sep 26, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for theagentrouter ready!

Name Link
🔨 Latest commit ec748b0
🔍 Latest deploy log https://app.netlify.com/projects/theagentrouter/deploys/6abb5dadb383ec0008a7d6ae
😎 Deploy Preview https://deploy-preview-2745--theagentrouter.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify project configuration.

@merlau

merlau commented Sep 27, 2026

Copy link
Copy Markdown

Hi @steffen-karlsson, from my understanding, this is related to issue #2671 and #2720

Signed-off-by: Steffen Karlsson <steffen.karlsson@gmail.com>
…arge bodies

Envoy 1.37.1's ext_proc filter has a null-pointer dereference when the
UDS send buffer hits the high watermark (data_deferred_ +
pending_send_buffer_high_watermark). This occurs when the request body
exceeds the HTTP2 per-stream window size (default 64KB).

Increase the InitialStreamWindowSize from 64KB to 16MB on the UDS
cluster's HTTP2 protocol options. This allows large request bodies to
be sent to the extproc without triggering the high watermark condition.

Keep BUFFERED mode for the upstream extproc filter (needed for correct
auth signing with the mutated body). Also add RequestTrailers handling
in the server for future compatibility with FULL_DUPLEX_STREAMED mode.

Signed-off-by: Steffen Karlsson <steffen.karlsson@gmail.com>
@steffen-karlsson
steffen-karlsson force-pushed the fix/preserve-system-prompt- branch from 9207f10 to 034af14 Compare September 29, 2026 06:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants