Skip to content

Base hygiene — gates de CI pré-existentes (glm typecheck, migrations count, merge-integrity, sanitizer de paths) - #4

Merged
LMPrado-DZ23 merged 4 commits into
release/v3.8.51from
chore/base-hygiene-v3.8.51
Sep 9, 2026
Merged

LMPrado-DZ23 merged 4 commits into
release/v3.8.51from
chore/base-hygiene-v3.8.51

Conversation

@LMPrado-DZ23

@LMPrado-DZ23 LMPrado-DZ23 commented Sep 9, 2026 •

Copy link
Copy Markdown
Owner

Base hygiene — corrige gates de CI PRÉ-EXISTENTES da release/v3.8.51

Estes gates já estavam vermelhos na base b345c7f (reproduzidos num checkout limpo, sem
nenhuma outra mudança). Este PR corrige os 4 que são seguros e contidos, para destravar o CI da
branch. Nenhuma mudança funcional/de comportamento além do estritamente necessário.

Corrigidos

Gate Problema (pré-existente) Correção
API Route Typecheck open-sse/executors/glm.ts chamava createSSETransformStreamWithLogger (15 params) com um 16º arg (65536, hint de buffer) que a função nunca consumia → TS2554 removido o arg morto (runtime inalterado)
Docs Gates (docs-counts) código tem 170 migrations; README.md/AGENTS.md/llm.txt diziam "169" atualizado para 170
Merge integrity changelog.d/fixes/reset-aware-model-family.md sem bullet - inicial; skills/cli-tunnel/SKILL.md dessincronizado com o gerador adicionado o - ; SKILL regenerado (generate-agent-skills.mjs --apply)
tests/unit/stream-handler-public-error-boundary o sanitizador de paths engolia a credencial: numa linha como Upstream failed at /srv/.../provider.ts:42:9 Authorization: Bearer <secret> api_key=<key>, redactUnquotedAbsolutePathSpans (em open-sse/utils/errorPathRedaction.ts) tratava o texto após o path como fragmento não resolvido e, no modo fail-closed, colapsava o resto da linha inteira em <path> — descartando o trecho Authorization: … que o redactSensitiveErrorText marcaria como [REDACTED]. Resultado: Upstream failed at <path> (sem o marcador). um endpoint arquivo.ts:linha:col (coordenada de stack) é um limite terminal inequívoco — nenhum caminho de filesystem continua depois dele. O fix passa a preferir esse endpoint terminado em coordenada em vez de falhar fechado, então o path vira <path> e o Authorization: …/api_key=… sobrevivem para o redator de credenciais marcá-los. Cirúrgico: só altera o ramo fail-closed de hasUnresolvedFragments; paths sem coordenada continuam falhando fechado como antes.

Verificação (local)

  • tsc -p tsconfig.typecheck-api.json: o erro de glm.ts sumiu.
  • check:docs-counts-sync: migrations agora batem (170) em README/AGENTS/llm.txt.
  • check:changelog-integrity: exit 0. check:agent-skills-sync: exit 0 (em sync).
  • Line-endings normalizados para LF (evitado ruído CRLF em 45 SKILL.md que só diferiam por EOL).
  • Sanitizador — regressão zero, evidência comparativa: rodei a suíte de sanitização/paths
    inteira (217 arquivos, 1703 testes) com e sem o fix, com o meu commit isolado via
    git stash. Base: 10 fails; com o fix: 8 fails. O stream-handler-public-error-boundary
    passou a passar (era o alvo). Todo teste que falha com o fix também falha na base — as
    falhas remanescentes (provider-translate-path-golden, error-sanitizer-sk-key-qv45,
    tunnel-routes, isolamento HuggingChat, #7774, cobertura de rotas /api/plugins) são
    dívida pré-existente, sem relação com paths. A oscilação Grok/HuggingChat entre execuções é
    flakiness dos testes com processo isolado (passam em --test-concurrency=1), não regressão.

🤖 Generated with Claude Code

zodyprado-web and others added 3 commits September 9, 2026 09:54
createSSETransformStreamWithLogger tem 15 parâmetros; glm.ts passava um 16º (um hint de buffer
64KB) que a função nunca consumia — só disparava TS2554 no gate API Route Typecheck. Removido;
comportamento inalterado (o arg era ignorado em runtime).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
O código tem 170 migrations SQL; README.md, AGENTS.md e llm.txt ainda diziam 169, quebrando o
check:docs-counts-sync. Atualizado para 170.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
- changelog.d/fixes/reset-aware-model-family.md não começava com bullet "- " (check-changelog-integrity).
- skills/cli-tunnel/SKILL.md estava dessincronizado com o gerador (check:agent-skills-sync exit 2);
  regenerado via generate-agent-skills.mjs --apply.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Sep 9, 2026 •

Copy link
Copy Markdown

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 5a27f0a2-cfbc-415e-8aa1-f091bc946111


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

…ed stack paths

redactUnquotedAbsolutePathSpans treated text after an absolute path as an
unresolved fragment and, in fail-closed mode, collapsed the rest of the line
into <path>. For a line like:

  Upstream failed at /srv/.../provider.ts:42:9 Authorization: Bearer <secret> api_key=<key>

that swallowed the "Authorization: ... api_key=..." tail into <path>, so the
downstream redactSensitiveErrorText never saw it and the public message lost
its `Authorization: [REDACTED]` marker (only `Upstream failed at <path>` remained).

A `file.ts:line:col` extension endpoint is an unambiguous terminal stack
location — no filesystem path legitimately continues past the numeric coordinate
suffix. Track that coordinate-terminated endpoint and, in the hasUnresolvedFragments
fail-closed branch, return it instead of consuming the rest of the line. Paths
without a coordinate suffix still fail closed exactly as before.

Fixes tests/unit/stream-handler-public-error-boundary (was red on base b345c7f).
Verified regression-free: full sanitization/path suite (217 files, 1703 tests)
run with and without this change via git stash — every remaining failure is
pre-existing on base; no new failures introduced.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@LMPrado-DZ23 LMPrado-DZ23 changed the title Base hygiene — corrige gates de CI pré-existentes (glm typecheck, migrations count, merge-integrity) Base hygiene — gates de CI pré-existentes (glm typecheck, migrations count, merge-integrity, sanitizer de paths) Sep 9, 2026
@LMPrado-DZ23
LMPrado-DZ23 merged commit d4e96a5 into release/v3.8.51 Sep 9, 2026
9 of 14 checks passed
LMPrado-DZ23 pushed a commit that referenced this pull request Sep 9, 2026
…ted evidence

Records the final state after merging PR #4 (base hygiene + path sanitizer) and
PR #3 (8 security findings) into release/v3.8.51 (31c6f44), with integrated
validation evidence: 64/64 regression tests pass, open-sse typecheck clean,
API-route baseline gate PASS (0 regressions), docs/changelog/env gates green.
Honestly scopes out remaining work (authenticated smoke needs operator
credential; Phase 2/3 and any release/publish need explicit authorization).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants