Skip to content

feat: import upstream v3.8.51 retained-core routing, translation, and security updates - #17

Merged
claw-io merged 2 commits into
mainfrom
feat/v3.8.51-pass1-core
Oct 4, 2026
Merged

claw-io merged 2 commits into
mainfrom
feat/v3.8.51-pass1-core

Conversation

@claw-io

@claw-io claw-io commented Oct 4, 2026 •

Copy link
Copy Markdown
Collaborator

Overview

Imports 68 selected, verified upstream pull requests from the v3.8.51 release tranche into OmniRoute-Slim retained core, plus preserves the deployed Flash-Lite thinking budget hotfix (7d587efd / bde3756e) and fixes upstream issue #14165 (/v1beta format detection via PR #14185).

Key Changes

  1. Protocol Translators & Routing:

    • Upstream #14185: Route /v1beta ingress bodies as OpenAI format rather than misidentifying as Claude (#14165).
    • Upstream #12191: Handle falsy tool results (false, 0, "") without 400 rejection.
    • Upstream #12386: Strip empty and undefined signatures from Claude thinking blocks.
    • Upstream #13333: Preserve tool_choice: "none" across Claude <-> OpenAI translations.
    • Upstream #13573: Ensure Gemini turns never open with functionCall without preceding user turn.
    • Upstream #14093, #14153, #14205, #14673: OpenAI Responses API continuation, tool call indexes, and token usage mapping.
  2. Security & Isolation (P0):

    • Upstream #14916: Middleware hook isolation in fresh VM realm (GHSA-9p9m-h9rj-rhhg).
    • Upstream #15128: Caller-scoped idempotency key namespacing.
    • Upstream #15039: Block link-local metadata (169.254.x.x) and IPv4-mapped IPv6 in outbound URL guard.
    • Upstream #15046: GHE custom endpoint private-network SSRF guard.
    • Upstream #15042: Enforce CSRF state parameter on Trae OAuth callbacks.
    • Upstream #15119: Refuse directory traversal in Codex /v1/responses subpath.
    • Upstream #15066: Linear-time parsing for unclosed web tool and agent markup tags.
  3. Schema Sanitization & Tools:

    • Upstream #12310: Preserve response-schema nullability across union flattening.
    • Upstream #12540, #12872: Strip nested prefixItems and additionalItems from Gemini tool schemas.
    • Upstream #13738: Sanitize Gemini tool names starting with a leading digit.
    • Upstream #14279: Strip tilde-prefixed Standard Schema optional keys (~optional).
  4. SSE & Streaming Lifecycle:

    • Upstream #12189: Liveness-aware readiness timeout.
    • Upstream #13171: Release upstream body stream on JSON-to-SSE sniff timeout.
    • Upstream #13272: TLS first-byte watchdog for stalled upstream TCP/TLS handshakes.
    • Upstream #13285: Surface fast client error for truly empty Claude streaming bodies.
  5. Memory Mitigations & Context Compression:

    • Upstream #11844: OOM mitigations for compression hashing, result memoization, and token estimation.
    • Upstream #13523: Preserve <system-reminder> and instruction blocks from lossy compression.
    • Upstream #13768: LLMLingua compression engine preserves casing, tags, and negations.

Verification & Validation

  • Unit & Security Matrix: 100% pass across all unit tests and zero-cost security suites.
  • Typechecks: npm run typecheck:core and npm run check:open-sse-typecheck pass.
  • Pre-Push Integrity Gate: All leak rules, forbidden path checks, and sync checks pass.
  • Live UAT: Fully validated across 21 test cases (S1-S4, F1-F13, SEC 1-8) on omniroute-slim-dev.
  • Production Status: Tested image deployed and serving live production traffic on stack omniroute on docker.dfw.

@claw-io
claw-io merged commit af57243 into main Oct 4, 2026
11 of 12 checks passed
@claw-io
claw-io deleted the feat/v3.8.51-pass1-core branch October 4, 2026 06:57
claw-io pushed a commit that referenced this pull request Oct 4, 2026
…#13481

PR #17 (upstream #13481) keyed persisted call_logs rows on the chatCore
traceId instead of the pending-request id, but the list endpoint still
deduped the finalized in-memory detail against persisted rows by id only.
The two id spaces are disjoint (`${now}-${uuid6}` vs a 6-char trace id), so
every request emitted a duplicate row sharing its correlationId: the log UI
showed a bogus "· 2 attempts" badge, and a genuine 2-attempt retry showed
"4 attempts". The same split made the detail modal lose the in-memory
request/response payloads for persisted rows when detailed logging is off.

Carry the chatCore traceId onto the pending detail as `callLogId` so the
in-memory copy shares the persisted row's id space, and match in-memory
copies on `callLogId` with a correlation-key fallback
(correlationId + model + provider, deliberately excluding connectionId
because the in-memory copy keeps the starting account while the persisted
row keeps the post-rotation one). Only in-memory copies are ever skipped, so
persisted rows sharing a correlationId — real retries — all survive.

The persisted write (`id: traceId`) is unchanged.
claw-io added a commit that referenced this pull request Oct 5, 2026
…#13481 (#18)

PR #17 (upstream #13481) keyed persisted call_logs rows on the chatCore
traceId instead of the pending-request id, but the list endpoint still
deduped the finalized in-memory detail against persisted rows by id only.
The two id spaces are disjoint (`${now}-${uuid6}` vs a 6-char trace id), so
every request emitted a duplicate row sharing its correlationId: the log UI
showed a bogus "· 2 attempts" badge, and a genuine 2-attempt retry showed
"4 attempts". The same split made the detail modal lose the in-memory
request/response payloads for persisted rows when detailed logging is off.

Carry the chatCore traceId onto the pending detail as `callLogId` so the
in-memory copy shares the persisted row's id space, and match in-memory
copies on `callLogId` with a correlation-key fallback
(correlationId + model + provider, deliberately excluding connectionId
because the in-memory copy keeps the starting account while the persisted
row keeps the post-rotation one). Only in-memory copies are ever skipped, so
persisted rows sharing a correlationId — real retries — all survive.

The persisted write (`id: traceId`) is unchanged.

Co-authored-by: b3nw <189466+b3nw@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants