Skip to content

feat(sse): add STRICT_ZERO_COST opt-in free-access policy - #10965

Merged
diegosouzapw merged 5 commits into
diegosouzapw:release/v3.8.50from
mymusicmyspace:feat/strict-zero-cost
Aug 21, 2026
Merged

diegosouzapw merged 5 commits into
diegosouzapw:release/v3.8.50from
mymusicmyspace:feat/strict-zero-cost

Conversation

@mymusicmyspace

Copy link
Copy Markdown
Contributor

Summary

Adds an opt-in, off-by-default freeAccessPolicy: "strict" that verifies auto-combo candidates against live quota state and per-connection economic safety before dispatch.

This goes beyond hidePaidModels, which is based on static catalog classification.

The policy is fail-closed: candidates are excluded when their free-access state cannot be verified safely.

Safety guarantees

  • Keyless models are accepted only when they come from the genuine synthetic no-auth connection path.
  • A credentialed database connection cannot use the keyless shortcut.
  • Multi-account candidates are restricted to the exact allowedConnectionIds that were independently verified as SAFE.
  • Dispatch cannot select an account that was not verified.
  • Unknown, stale, errored, unsupported, or incomplete quota states are excluded.
  • Missing hardStopGuaranteed metadata is treated as unsafe.
  • No provider or model names are hardcoded in the policy.

excludeTosAvoid is provided as a separate opt-in guard for models/providers whose curated ToS metadata is marked avoid.

Backward compatibility

The feature is disabled by default:

freeAccessPolicy: "off"

Therefore existing OmniRoute behavior is unchanged unless the policy is explicitly enabled.

Design

The policy uses existing OmniRoute catalog and usage infrastructure:

  • curated free-model metadata
  • provider usage adapters
  • per-connection quota state
  • hardStopGuaranteed
  • existing auto-combo candidate discovery

Future providers/models can become eligible automatically when OmniRoute has enough metadata to verify them safely.

See:

docs/routing/STRICT_ZERO_COST.md

Tests

82 targeted tests passing, including:

  • strict zero-cost filtering
  • automatic provider/model discovery
  • genuine no-auth enforcement
  • credentialed keyless rejection
  • multi-account connection isolation
  • allowed connection enforcement
  • auto-combo regressions

Also verified:

  • ESLint clean on modified files
  • Prettier clean
  • npm run typecheck:core passing
  • documentation checks passing

Known limitation

Quota-based providers without both:

  1. a usable live usage adapter, and
  2. hardStopGuaranteed: true

remain UNKNOWN and are excluded.

This is intentional fail-closed behavior rather than a fallback to potentially billable traffic.

hidePaidModels only checks whether a model is documented free in
FREE_MODEL_BUDGETS at catalog-curation time; it says nothing about
whether a recurring/one-time free allowance has since been exhausted,
or whether exceeding it is a guaranteed hard stop versus silent
pay-as-you-go billing. STRICT_ZERO_COST (settings.freeAccessPolicy,
default "off") adds both checks per candidate, before ranking and
before dispatch: keyless candidates pass immediately (no credential
exists to bill), every other freeType requires a curated
hardStopGuaranteed:true declaration plus a live, cached, fresh SAFE
quota state from the existing getUsageForProvider()/
USAGE_FETCHER_PROVIDERS registry. Unknown metadata always excludes,
never defaults to safe.

Also adds excludeTosAvoid, independent of economic safety, reusing the
existing curated `tos` field.

No provider or model name is hardcoded anywhere in the filter; a
future provider with correct metadata is picked up automatically (see
the autodiscovery test suite using injectable catalog fixtures).
Two gaps found reviewing 5d4f881 as if it were an incoming PR:

- The `keyless` shortcut matched on catalog freeType alone, so a
  catalogued-keyless provider/model reached through a real DB connection
  (not the no-auth sentinel) would incorrectly bypass all quota checks.
  `evaluateCandidateConnections()` now requires
  `connectionId === SYNTHETIC_NOAUTH_CONNECTION_ID` for the shortcut; any
  other connection falls through to the normal hardStopGuaranteed+quota
  path, where real `keyless` catalog rows (which never set
  hardStopGuaranteed) correctly fail closed.

- A multi-account candidate's economic safety was checked against one
  connection while `allowedConnectionIds` still exposed every account to
  dispatch, so a verified-SAFE account could authorize traffic that
  actually lands on a different, unverified one. The filter now checks
  every connection in the allowlist independently and rewrites
  `allowedConnectionIds` to exactly the SAFE subset, relying on the
  existing allowlist intersection in autoStrategy.ts to guarantee dispatch
  never selects a connection this filter didn't itself verify.

Also drops the dead `catalog` field from `StrictZeroCostOptions` (was
never read; `findBudgetEntry()` already takes its own catalog override)
and threads the real per-connection resolver into virtualFactory.ts
instead of a candidate-level closure that collapsed multi-account
candidates onto one arbitrary connection.
- Cap concurrent background quota refreshes (MAX_CONCURRENT_REFRESHES=4):
  a cold cache after a process restart previously fired one
  getUsageForProvider() call per distinct (provider, connection) pair in
  the same tick. A skipped refresh just leaves that candidate UNKNOWN
  (excluded, fail-closed) until a later pool build retries.
- Add a hard eviction sweep (piggybacked on resolveFreeAccessState calls,
  not a timer) for cache entries whose connection was removed and never
  gets a normal stale-triggered refresh again.
…idates

Reads each live candidate's real connectionId (previously ignored) and
uses the updated evaluateCandidateConnections() API, so the ad-hoc
before/after report also exercises the connection-safety fix against
live data — a keyless-catalogued model reached via a real connection is
now reported as its own distinct exclusion reason.
Update STRICT_ZERO_COST.md with the keyless-shortcut connection
requirement and the new "Connection safety" section describing how
multi-account candidates are verified per-connection and their
allowedConnectionIds narrowed to the SAFE subset. Refresh "What passes
today" with current live numbers (7 candidates strict+ToS=false, 0
strict+ToS=true) confirmed against real connectionIds. Add the
Unreleased CHANGELOG entry for the feature.
@diegosouzapw
diegosouzapw merged commit 3caa591 into diegosouzapw:release/v3.8.50 Aug 21, 2026
3 checks passed
Sa3id23 pushed a commit to Sa3id23/OmniRoute that referenced this pull request Aug 21, 2026
…pw#10965)

⭐5 — freeAccessPolicy "strict" opt-in (default off): verifica candidatos de auto-combo contra estado de quota ao vivo + segurança econômica por conexão antes do dispatch (fail-closed — estado desconhecido/stale/incompleto é excluído). Zero mudança de comportamento com o default "off". 82 testes focados, eslint/prettier/typecheck limpos, docs em docs/routing/STRICT_ZERO_COST.md.
jonlwheat2-gif added a commit to jonlwheat2-gif/OmniRoute that referenced this pull request Aug 21, 2026
…e test

- open-sse-typecheck: sync frozen baseline to the merged-tree reality —
  clientUsageBuffer/stream.ts errors no longer exist, and virtualFactory
  TS2362 is inherited from base diegosouzapw#10965 (STRICT_ZERO_COST block lands after
  this branch's fork point; maintainers reverted the block on their newer
  base, so this is base-owned drift, not a PR regression)
- systemd-notify: messages travel over a dgram socket so arrival order is
  racy (STOPPING=1 can beat WATCHDOG=1 under load); compare order-free
jonlwheat2-gif added a commit to jonlwheat2-gif/OmniRoute that referenced this pull request Aug 21, 2026
…e test

- open-sse-typecheck: sync frozen baseline to the merged-tree reality —
  clientUsageBuffer/stream.ts errors no longer exist, and virtualFactory
  TS2362 is inherited from base diegosouzapw#10965 (STRICT_ZERO_COST block lands after
  this branch's fork point; maintainers reverted the block on their newer
  base, so this is base-owned drift, not a PR regression)
- systemd-notify: messages travel over a dgram socket so arrival order is
  racy (STOPPING=1 can beat WATCHDOG=1 under load); compare order-free
@diegosouzapw diegosouzapw mentioned this pull request Aug 23, 2026
muhamadgalihsaputra pushed a commit to niyatna/NiyatnaRoute that referenced this pull request Sep 27, 2026
…pw#10965)

⭐5 — freeAccessPolicy "strict" opt-in (default off): verifica candidatos de auto-combo contra estado de quota ao vivo + segurança econômica por conexão antes do dispatch (fail-closed — estado desconhecido/stale/incompleto é excluído). Zero mudança de comportamento com o default "off". 82 testes focados, eslint/prettier/typecheck limpos, docs em docs/routing/STRICT_ZERO_COST.md.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants