Skip to content

feat(upstream): import v3.8.51 Pass 2 core alignment (18 PRs) - #19

Merged
claw-io merged 1 commit into
mainfrom
fix/v3.8.51-pass2-core-imports
Oct 5, 2026
Merged

claw-io merged 1 commit into
mainfrom
fix/v3.8.51-pass2-core-imports

Conversation

@claw-io

@claw-io claw-io commented Oct 5, 2026

Copy link
Copy Markdown
Collaborator

Summary

Phase 2 upstream alignment for OmniRoute-Slim against upstream release v3.8.51 (c1e30b7676), importing 18 clean direct core PRs across security, SSE stream reliability, tool metadata preservation, compression worker hardening, usage metering, and health checks.

Postponed: 31 complex surgical candidates are segregated into Phase 3.

Upstream PRs Imported

  • Security & Authorization:

    • #15050: Use constant-time comparison for API keys and secrets (timingSafeCompare).
    • #15038: Filter trusted proxy peers based on connection IP instead of forged X-Forwarded-For, controlled by OMNIROUTE_TRUSTED_PROXIES.
    • #15067: Guard model ID path safety against traversal (hasUnsafeModelIdSyntax).
  • Egress & Marker Hygiene:

    • #14252, #13355: Strip internal _omniroute* markers and un-expandable session handoff keys at shared pre-executor boundary.
  • Streaming & Cancellation:

    • #14790: Replay bounded cancel chunks in open-sse JSON body.
    • #14806: Mark terminal response incomplete status on client disconnection.
  • Tool Call & Protocol Identity:

    • #12839: Support namespaced tool calls while preserving provider aliases.
    • #14751: Preserve Gemini custom tool call roundtrips with qualified wire names.
  • Compression Worker Hardening:

    • #14391, #13637, #13093: Accept structured-clone-safe values, fallback in-process on worker spawn failure, use safe URL worker spawn.
    • #15037: Prevent lite compression from truncating current-turn tool results.
    • #14633: Guard against ReDoS in session-dedup.
    • #13521: Skip RTK file content dedup for non-shell tool results.
    • #14983: Guard fuzzy session-dedup against client capability mismatches.
  • Provider Routing & Usage Estimation:

    • #12826: Support Gemini custom-model URL rewriting and forward thinkingLevel.
    • #12151, #12828: Passthrough usage estimation on silent upstreams and trailing usage chunk emission in translate streams.
    • #14776: Cross-evidence promotion in proxy health sweeps.

Verification

  • Core typecheck: npm run typecheck:core — PASS
  • Open-SSE typecheck: npm run check:open-sse-typecheck — PASS
  • Security unit test suite: npm run test:security — 5/5 suites PASS
  • Pre-push leak gate: local-ops/scripts/github-pre-push-gate.sh origin — PASS
  • Live UAT on Dev Stack (omniroute-slim-dev): 100% PASS (image gitea.ext.ben.io/homelab/omniroute-slim:lab-077e35f8-pass2-uat)

@claw-io
claw-io force-pushed the fix/v3.8.51-pass2-core-imports branch from 077e35f to 62ccedc Compare October 5, 2026 03:54
…security updates

Import 18 clean direct core PRs from upstream v3.8.51 (c1e30b7676):
- Security & Auth: constant-time secret comparison (#15050), trusted proxy peer filtering (#15038), model-ID path traversal guard (#15067)
- Hygiene & Egress: strip internal _omniroute* markers & session keys (#14252, #13355)
- Streaming: bounded replay cancel (#14790), terminal incomplete status on disconnect (#14806)
- Tool Identity: namespaced tool calls (#12839), Gemini custom tool roundtrips (#14751)
- Compression Hardening: worker clone-safety (#14391), spawn URL & fallback (#13637, #13093), current-turn preservation (#15037), ReDoS protection (#14633), shell-only RTK (#13521), CCR retrieval guard (#14983)
- Routing & Metering: Gemini custom-model URL & thinkingLevel (#12826), passthrough usage estimation & trailing chunks (#12151, #12828), proxy health cross-evidence (#14776)
- Documentation: synchronize OMNIROUTE_TRUSTED_PROXIES in ENVIRONMENT.md
@claw-io
claw-io force-pushed the fix/v3.8.51-pass2-core-imports branch from 62ccedc to 8af4bed Compare October 5, 2026 04:01
@claw-io
claw-io merged commit f888e48 into main Oct 5, 2026
11 of 12 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants