Base hygiene — gates de CI pré-existentes (glm typecheck, migrations count, merge-integrity, sanitizer de paths) - #4
Merged
Conversation
createSSETransformStreamWithLogger tem 15 parâmetros; glm.ts passava um 16º (um hint de buffer 64KB) que a função nunca consumia — só disparava TS2554 no gate API Route Typecheck. Removido; comportamento inalterado (o arg era ignorado em runtime). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
O código tem 170 migrations SQL; README.md, AGENTS.md e llm.txt ainda diziam 169, quebrando o check:docs-counts-sync. Atualizado para 170. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
- changelog.d/fixes/reset-aware-model-family.md não começava com bullet "- " (check-changelog-integrity). - skills/cli-tunnel/SKILL.md estava dessincronizado com o gerador (check:agent-skills-sync exit 2); regenerado via generate-agent-skills.mjs --apply. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
|
Important
This repository does not receive automatic reviews because it has fewer than 10 stars. ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
…ed stack paths redactUnquotedAbsolutePathSpans treated text after an absolute path as an unresolved fragment and, in fail-closed mode, collapsed the rest of the line into <path>. For a line like: Upstream failed at /srv/.../provider.ts:42:9 Authorization: Bearer <secret> api_key=<key> that swallowed the "Authorization: ... api_key=..." tail into <path>, so the downstream redactSensitiveErrorText never saw it and the public message lost its `Authorization: [REDACTED]` marker (only `Upstream failed at <path>` remained). A `file.ts:line:col` extension endpoint is an unambiguous terminal stack location — no filesystem path legitimately continues past the numeric coordinate suffix. Track that coordinate-terminated endpoint and, in the hasUnresolvedFragments fail-closed branch, return it instead of consuming the rest of the line. Paths without a coordinate suffix still fail closed exactly as before. Fixes tests/unit/stream-handler-public-error-boundary (was red on base b345c7f). Verified regression-free: full sanitization/path suite (217 files, 1703 tests) run with and without this change via git stash — every remaining failure is pre-existing on base; no new failures introduced. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
LMPrado-DZ23
pushed a commit
that referenced
this pull request
Sep 9, 2026
…ted evidence Records the final state after merging PR #4 (base hygiene + path sanitizer) and PR #3 (8 security findings) into release/v3.8.51 (31c6f44), with integrated validation evidence: 64/64 regression tests pass, open-sse typecheck clean, API-route baseline gate PASS (0 regressions), docs/changelog/env gates green. Honestly scopes out remaining work (authenticated smoke needs operator credential; Phase 2/3 and any release/publish need explicit authorization). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Base hygiene — corrige gates de CI PRÉ-EXISTENTES da
release/v3.8.51Estes gates já estavam vermelhos na base
b345c7f(reproduzidos num checkout limpo, semnenhuma outra mudança). Este PR corrige os 4 que são seguros e contidos, para destravar o CI da
branch. Nenhuma mudança funcional/de comportamento além do estritamente necessário.
Corrigidos
open-sse/executors/glm.tschamavacreateSSETransformStreamWithLogger(15 params) com um 16º arg (65536, hint de buffer) que a função nunca consumia →TS2554changelog.d/fixes/reset-aware-model-family.mdsem bullet-inicial;skills/cli-tunnel/SKILL.mddessincronizado com o gerador-; SKILL regenerado (generate-agent-skills.mjs --apply)tests/unit/stream-handler-public-error-boundaryUpstream failed at /srv/.../provider.ts:42:9 Authorization: Bearer <secret> api_key=<key>,redactUnquotedAbsolutePathSpans(emopen-sse/utils/errorPathRedaction.ts) tratava o texto após o path como fragmento não resolvido e, no modo fail-closed, colapsava o resto da linha inteira em<path>— descartando o trechoAuthorization: …que oredactSensitiveErrorTextmarcaria como[REDACTED]. Resultado:Upstream failed at <path>(sem o marcador).arquivo.ts:linha:col(coordenada de stack) é um limite terminal inequívoco — nenhum caminho de filesystem continua depois dele. O fix passa a preferir esse endpoint terminado em coordenada em vez de falhar fechado, então o path vira<path>e oAuthorization: …/api_key=…sobrevivem para o redator de credenciais marcá-los. Cirúrgico: só altera o ramo fail-closed dehasUnresolvedFragments; paths sem coordenada continuam falhando fechado como antes.Verificação (local)
tsc -p tsconfig.typecheck-api.json: o erro deglm.tssumiu.check:docs-counts-sync: migrations agora batem (170) em README/AGENTS/llm.txt.check:changelog-integrity: exit 0.check:agent-skills-sync: exit 0 (em sync).inteira (217 arquivos, 1703 testes) com e sem o fix, com o meu commit isolado via
git stash. Base: 10 fails; com o fix: 8 fails. Ostream-handler-public-error-boundarypassou a passar (era o alvo). Todo teste que falha com o fix também falha na base — as
falhas remanescentes (
provider-translate-path-golden,error-sanitizer-sk-key-qv45,tunnel-routes, isolamento HuggingChat,#7774, cobertura de rotas/api/plugins) sãodívida pré-existente, sem relação com paths. A oscilação Grok/HuggingChat entre execuções é
flakiness dos testes com processo isolado (passam em
--test-concurrency=1), não regressão.🤖 Generated with Claude Code