From f93705ed94bec7bf8372bfd403c954e274dba592 Mon Sep 17 00:00:00 2001 From: zodyp Date: Wed, 9 Sep 2026 09:54:39 -0300 Subject: [PATCH 1/4] fix(types): remove dead 16th arg em glm.ts (TS2554 no api-typecheck) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit createSSETransformStreamWithLogger tem 15 parâmetros; glm.ts passava um 16º (um hint de buffer 64KB) que a função nunca consumia — só disparava TS2554 no gate API Route Typecheck. Removido; comportamento inalterado (o arg era ignorado em runtime). Co-Authored-By: Claude Opus 4.8 --- open-sse/executors/glm.ts | 8 ++++---- skills/cli-tunnel/SKILL.md | 4 ++-- 2 files changed, 6 insertions(+), 6 deletions(-) diff --git a/open-sse/executors/glm.ts b/open-sse/executors/glm.ts index ef9f3706699..0f6e0f44665 100644 --- a/open-sse/executors/glm.ts +++ b/open-sse/executors/glm.ts @@ -223,8 +223,9 @@ export function translateSseResponse( suppressThinkClose: boolean = false ): Response { if (!response.body) return response; - // GLM is a high-throughput provider — use a larger stream buffer (64KB) to - // keep provider → client pacing ahead of the model's token emission rate. + // GLM is a high-throughput provider. (A previous extra positional arg here — an intended 64KB + // buffer hint — was silently ignored: createSSETransformStreamWithLogger takes 15 params and + // never consumed it, so passing it only tripped TS2554. Removed; behavior is unchanged.) const transform = createSSETransformStreamWithLogger( FORMATS.CLAUDE, FORMATS.OPENAI, @@ -240,8 +241,7 @@ export function translateSseResponse( false, suppressThinkClose, undefined, - undefined, - 65536 + undefined ); const headers = cloneHeaders(response.headers); headers.set("content-type", "text/event-stream"); diff --git a/skills/cli-tunnel/SKILL.md b/skills/cli-tunnel/SKILL.md index 4d7388bb7b7..d62aab6abb1 100644 --- a/skills/cli-tunnel/SKILL.md +++ b/skills/cli-tunnel/SKILL.md @@ -37,12 +37,12 @@ omniroute tunnel omniroute tunnel list ``` -### `tunnel create [type]` +### `tunnel create` **Example:** ```bash -omniroute tunnel create [type] +omniroute tunnel create ``` ### `tunnel stop ` From 18462aef1c0de5937d7340efce330c7275980bc0 Mon Sep 17 00:00:00 2001 From: zodyp Date: Wed, 9 Sep 2026 09:54:40 -0300 Subject: [PATCH 2/4] docs: corrige contagem de migrations 169 -> 170 (docs-counts-sync) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit O código tem 170 migrations SQL; README.md, AGENTS.md e llm.txt ainda diziam 169, quebrando o check:docs-counts-sync. Atualizado para 170. Co-Authored-By: Claude Opus 4.8 --- AGENTS.md | 2 +- README.md | 2 +- llm.txt | 8 ++++---- 3 files changed, 6 insertions(+), 6 deletions(-) diff --git a/AGENTS.md b/AGENTS.md index 6e7ad18f2fc..63ed258c82c 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -56,7 +56,7 @@ Repository map and Reference Documentation sections below. | Translators | `open-sse/translator/` | Format conversion (OpenAI↔Claude↔Gemini) | | Transformer | `open-sse/transformer/` | Responses API ↔ Chat Completions | | Services | `open-sse/services/` | Combo routing, rate limits, caching, etc | -| Database | `src/lib/db/` | SQLite domain modules (169 migrations) | +| Database | `src/lib/db/` | SQLite domain modules (170 migrations) | | Domain/Policy | `src/domain/` | Policy engine, cost rules, fallback logic | | MCP Server | `open-sse/mcp-server/` | 110 tools (45 canonical + memory/skill/GitHub/pool/gamification/plugin/Notion/Obsidian/local-corpus/RTK modules), 3 transports (stdio / SSE / Streamable HTTP), 33 scopes | | A2A Server | `src/lib/a2a/` | JSON-RPC 2.0 agent protocol | diff --git a/README.md b/README.md index b64f3dc543f..519a64682f7 100644 --- a/README.md +++ b/README.md @@ -1244,7 +1244,7 @@ Métricas canônicas em 2026-08-24: **1.029 vídeos únicos** · **11.132.922 vi RuntimeNode.js 22.x / 24.x LTS — >=22.22.2 <23 || >=24.0.0 <27 LanguageTypeScript 6.0 — 100% TypeScript across src/ and open-sse/ (zero any in core since v2.0) FrameworkNext.js 16 + React 19 + Tailwind CSS 4 - Databasebetter-sqlite3 (SQLite, WAL journaling) + LowDB (JSON legacy) — 122 domain modules, 169 migrations + Databasebetter-sqlite3 (SQLite, WAL journaling) + LowDB (JSON legacy) — 122 domain modules, 170 migrations MemorySQLite FTS5 full-text + int8-quantized vector embeddings, typed decay SchemasZod 4 — MCP tool I/O validation + API contracts ProtocolsMCP (stdio / HTTP / SSE) + A2A v0.3 (JSON-RPC 2.0 + SSE) diff --git a/llm.txt b/llm.txt index 3748b084320..e5c68d9d3a6 100644 --- a/llm.txt +++ b/llm.txt @@ -14,7 +14,7 @@ OmniRoute solves the problem of managing multiple AI provider subscriptions, quo - **Runtime:** Node.js `>=22.22.2 <23 || >=24.0.0 <27`, ES Modules (`"type": "module"`) - **Framework:** Next.js 16 (App Router) with TypeScript 6 -- **Database:** SQLite via better-sqlite3 (local, zero-config, 169 migrations) +- **Database:** SQLite via better-sqlite3 (local, zero-config, 170 migrations) - **State management:** Zustand (client), SQLite (server persistence) - **UI:** React 19, Tailwind CSS 4, Recharts for analytics, @lobehub/icons for 130+ provider SVG icons - **Auth:** OAuth 2.0 (PKCE) for providers, bcrypt for local user auth @@ -124,7 +124,7 @@ OmniRoute solves the problem of managing multiple AI provider subscriptions, quo │ │ │ ├── secrets.ts # Secrets management │ │ │ ├── stateReset.ts # State reset utilities │ │ │ ├── migrationRunner.ts # Schema migration runner -│ │ │ └── migrations/ # 169 versioned SQL migration files +│ │ │ └── migrations/ # 170 versioned SQL migration files │ │ ├── evals/ # Eval runner and scheduler │ │ ├── memory/ # Persistent conversational memory │ │ │ ├── extraction.ts # Memory extraction from conversations @@ -389,7 +389,7 @@ diagnostics) plus **memory**, **skill**, **agentSkill**, **githubSkill**, **pool 8. **ProviderIcon component:** Unified icon system using `@lobehub/icons` (130+ SVG) with PNG fallback and generic icon fallback chain. Used on providers, dashboard, and agents pages. -9. **DB architecture:** `localDb.ts` is a re-export layer only — real logic lives in 122 `src/lib/db/` modules with 169 SQL migrations. +9. **DB architecture:** `localDb.ts` is a re-export layer only — real logic lives in 122 `src/lib/db/` modules with 170 SQL migrations. 10. **Upstream headers:** Custom headers merged in executors after default auth; same header name replaces executor value. Forbidden header names in `src/shared/constants/upstreamHeaders.ts`. @@ -433,7 +433,7 @@ diagnostics) plus **memory**, **skill**, **agentSkill**, **githubSkill**, **pool 4. **Environment variables:** All configuration is in `.env` (from `.env.example`). Key vars: `PORT`, `NEXT_PUBLIC_BASE_URL`, `API_KEY`, `ADMIN_PASSWORD`. -5. **Database layer:** Operations go through `src/lib/db/` modules (122 domain-specific files, 169 migrations). `localDb.ts` is re-exports only — add new functions to the proper `db/*.ts` module. +5. **Database layer:** Operations go through `src/lib/db/` modules (122 domain-specific files, 170 migrations). `localDb.ts` is re-exports only — add new functions to the proper `db/*.ts` module. 6. **Tests** use Node.js built-in test runner + Vitest. Run `npm test`. Vitest for MCP/autoCombo (`npm run test:vitest`). Playwright for E2E (`npm run test:e2e`). Coverage gate: ratchet vs `quality-baseline.json`, absolute floor 60% statements/lines/functions/branches. From 28bbecded5ceb0f6c3b660af7c50f56e22a467cd Mon Sep 17 00:00:00 2001 From: zodyp Date: Wed, 9 Sep 2026 09:54:40 -0300 Subject: [PATCH 3/4] chore: corrige merge-integrity (fragmento changelog + agent-skills sync) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit - changelog.d/fixes/reset-aware-model-family.md não começava com bullet "- " (check-changelog-integrity). - skills/cli-tunnel/SKILL.md estava dessincronizado com o gerador (check:agent-skills-sync exit 2); regenerado via generate-agent-skills.mjs --apply. Co-Authored-By: Claude Opus 4.8 --- changelog.d/fixes/reset-aware-model-family.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/changelog.d/fixes/reset-aware-model-family.md b/changelog.d/fixes/reset-aware-model-family.md index 75b65e7613f..09fa6631826 100644 --- a/changelog.d/fixes/reset-aware-model-family.md +++ b/changelog.d/fixes/reset-aware-model-family.md @@ -1 +1 @@ -Keep Antigravity Gemini usable when the same connection's Claude weekly quota is empty; generic quota cache stays per-connection for every other provider. +- Keep Antigravity Gemini usable when the same connection's Claude weekly quota is empty; generic quota cache stays per-connection for every other provider. From 12cacb538a1314ee463627f3516a44a56195b28a Mon Sep 17 00:00:00 2001 From: zodyp Date: Wed, 9 Sep 2026 10:22:15 -0300 Subject: [PATCH 4/4] fix(sanitizer): preserve credential markers after coordinate-terminated stack paths MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit redactUnquotedAbsolutePathSpans treated text after an absolute path as an unresolved fragment and, in fail-closed mode, collapsed the rest of the line into . For a line like: Upstream failed at /srv/.../provider.ts:42:9 Authorization: Bearer api_key= that swallowed the "Authorization: ... api_key=..." tail into , so the downstream redactSensitiveErrorText never saw it and the public message lost its `Authorization: [REDACTED]` marker (only `Upstream failed at ` remained). A `file.ts:line:col` extension endpoint is an unambiguous terminal stack location — no filesystem path legitimately continues past the numeric coordinate suffix. Track that coordinate-terminated endpoint and, in the hasUnresolvedFragments fail-closed branch, return it instead of consuming the rest of the line. Paths without a coordinate suffix still fail closed exactly as before. Fixes tests/unit/stream-handler-public-error-boundary (was red on base b345c7f). Verified regression-free: full sanitization/path suite (217 files, 1703 tests) run with and without this change via git stash — every remaining failure is pre-existing on base; no new failures introduced. Co-Authored-By: Claude Opus 4.8 --- open-sse/utils/errorPathRedaction.ts | 23 +++++++++++++++++++++++ 1 file changed, 23 insertions(+) diff --git a/open-sse/utils/errorPathRedaction.ts b/open-sse/utils/errorPathRedaction.ts index 2b372af583b..006d0bafb0e 100644 --- a/open-sse/utils/errorPathRedaction.ts +++ b/open-sse/utils/errorPathRedaction.ts @@ -343,6 +343,17 @@ function findTokenEnd(value: string, start: number): number { return end; } +// A resolved `.ext:line:col` (or `.ext:line`) endpoint is an unambiguous +// terminal stack location: a filesystem path never legitimately continues past +// the numeric coordinate suffix. Detect it by walking back over the trailing +// `:` immediately preceding the resolved extension end. +function extensionEndHasLineColumnSuffix(value: string, extensionEnd: number): boolean { + let index = extensionEnd; + if (index <= 0 || !isAsciiDigit(value.charCodeAt(index - 1))) return false; + while (index > 0 && isAsciiDigit(value.charCodeAt(index - 1))) index--; + return index > 0 && value.charCodeAt(index - 1) === 0x3a; +} + function findExtensionEndInToken(value: string, start: number, end: number): number { let lastExtensionEnd = -1; for (let index = start; index < end; index++) { @@ -461,11 +472,17 @@ function findUnquotedPathEnd( let firstTrimmedTokenEnd = -1; let lastPathTokenEnd = -1; let resolvedExtensionEnd = -1; + let resolvedCoordinateEnd = -1; let hasFilesystemEvidence = false; let hasUnresolvedFragments = false; const resolveEndpoint = (): number => { if (hasUnresolvedFragments) { + // A coordinate-terminated stack location (`file.ts:42:9`) is a definite + // endpoint: prefer it over failing closed so trailing prose such as + // "Authorization: Bearer " is not swallowed into and can + // still be redacted independently by the sensitive-text pass. + if (resolvedCoordinateEnd >= 0) return resolvedCoordinateEnd; return failClosedAmbiguity || hasFilesystemEvidence ? value.length : -1; } if (resolvedExtensionEnd >= 0) return resolvedExtensionEnd; @@ -514,10 +531,16 @@ function findUnquotedPathEnd( if (extensionEnd < 0 && containsExtensionEvidence) { resolvedExtensionEnd = trimmedTokenEnd; } + if (extensionEnd >= 0 && extensionEndHasLineColumnSuffix(value, extensionEnd)) { + resolvedCoordinateEnd = extensionEnd; + } } else if (extensionEnd >= 0) { resolvedExtensionEnd = extensionEnd; hasFilesystemEvidence = true; hasUnresolvedFragments = false; + if (extensionEndHasLineColumnSuffix(value, extensionEnd)) { + resolvedCoordinateEnd = extensionEnd; + } } else if (containsExtensionEvidence) { resolvedExtensionEnd = trimmedTokenEnd; hasFilesystemEvidence = true;