Skip to content

port(omniroute): #6908 - ship head-response-guard.cjs in the standalone CLI bundle - #286

Merged
bloodf merged 7 commits into
devfrom
port/omniroute-6908
Jul 16, 2026
Merged

bloodf merged 7 commits into
devfrom
port/omniroute-6908

Conversation

@bloodf

@bloodf bloodf commented Jul 16, 2026 •

Copy link
Copy Markdown
Owner

Summary

  • What changed: Ports OmniRoute PR #6908. The #6608 HEAD body-suppression guard was inline in custom-server.js, which lives OUTSIDE Next.js's standalone trace — nothing guaranteed a sidecar would travel with it, so the standalone CLI bundle could boot-crash with MODULE_NOT_FOUND. The guard is extracted into root sidecar head-response-guard.cjs (identical runtime semantics: body bytes dropped, status/headers preserved, real end invoked with exactly one callback, no Connection: close added); custom-server.js now require()s it. New cli/scripts/standaloneSidecars.js owns STANDALONE_SIDECARS + copyRequiredStandaloneSidecars() which copies each root sidecar into the CLI bundle and FAILS HARD when one is missing. cli/scripts/build-cli.js (step 3a) and scripts/build-app.mjs copy the sidecar into the bundle / .next/standalone.
  • Why it changed: Upstream's standalone CLI bundle crashed at boot because the packaging step had no entry copying the imported sidecar. DurinDoor has the same hazard shape.

Type

  • fix: — bug fix

Breaking changes

  • No

Testing

  • What was tested: sidecar copy completeness (helper copies every manifest entry, hard-fails on a missing one), a derived-require guard (every root-level relative require("./…") in custom-server.js — excluding generated server.js and the src/+open-sse/ trees — is present in STANDALONE_SIDECARS), the extracted guard's runtime semantics, and the mitm runtime lifecycle (assertion follows the helper call).
  • Commands run: cd tests && node node_modules/vitest/vitest.mjs run unit/standalone-sidecars-6908.test.js unit/mitm-runtime-lifecycle.test.js unit/api-hardening.test.js; npm run lint; npm run build; npm pack --dry-run --json against a temp CLI app dir staged by the helper.
  • Evidence: 3 files, 71/71 tests passed. Red-proof: removing head-response-guard.cjs from STANDALONE_SIDECARS fails 3 tests; restored → 71/71 green. Artifact proof: tarball contained app/custom-server.js + app/head-response-guard.cjs (2722 bytes). Lint exit 0, build exit 0 with .next/standalone/head-response-guard.cjs + custom-server.js verified present. Full test:ci was blocked by a host-level environment defect (better-sqlite3 resolves to the main-repo-root ABI-137/Node-24 binary → ERR_DLOPEN_FAILED under pinned Node 20; a stale ABI-137 binding already existed so .omc/gate.sh's existence guard skipped copy/rebuild; 3 of the 4 collection-failed suites also fail on clean origin/dev) — relying on CI's clean VM as the authoritative gate.

Checklist

  • Tests added or updated for behavioral changes
  • No new dependencies without explicit justification
  • Conventional commit used (port(omniroute): — commitlint-registered type)
  • CHANGELOG updated if this change is user-facing — not user-facing; documented in docs/ports/omniroute-6908.md (port-log doc artifact)
  • No secrets, keys, credentials, or tokens committed

Existing PRs

Searched open+closed PRs for 6908, head-response-guard, standalone sidecar — no duplicate or prior attempt found.

Source

diegosouzapw/OmniRoute#6908 — upstream sibling-fork PR being ported.

Disclosure

  • Model: durindoor/kimi/kimi-k2.7
  • Harness: Oh My Pi (omp) 16.5.0 (omp --version)
  • Installed plugins: superpowers, mattpocock-skills (skill libraries)
  • This is an agent-generated port produced by an automated upstream-import pipeline. Human approval: explicitly authorised by the user via batch sign-off for the 90-PR upstream-import cycle (per orchestrator Main).

@bloodf
bloodf merged commit 7580017 into dev Jul 16, 2026
3 checks passed
@bloodf
bloodf deleted the port/omniroute-6908 branch July 17, 2026 02:50
This was referenced Sep 4, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant