mirror of
https://github.com/ggml-org/llama.cpp.git
synced 2026-09-25 15:37:25 -05:00
In router mode, authentication belongs to the router. unset_reserved_args() already unset LLAMA_API_KEY, but did not unset LLAMA_ARG_API_KEY_FILE. When --api-key-file was passed, children re-validated against file keys only, causing clients using --api-key to 401 on chat completions (#28820). In addition, router internal calls without auth headers (such as POST /v1/streams/lookup and DELETE /v1/stream) were silently rejected with 401. Unset LLAMA_ARG_API_KEY_FILE in unset_reserved_args() so no API keys reach child instances. This keeps keys out of child argv, ensures all keys the router accepts work end-to-end, and prevents router internal stream calls from 401ing. Fixes #28820