Skip to content

chore(providers): retire Felo Web on provenance hold - #11698

Merged
diegosouzapw merged 20 commits into
release/v3.8.51from
fix/v3850-retire-felo-web
Aug 28, 2026
Merged

diegosouzapw merged 20 commits into
release/v3.8.51from
fix/v3850-retire-felo-web

Conversation

@diegosouzapw

@diegosouzapw diegosouzapw commented Aug 26, 2026 •

Copy link
Copy Markdown
Owner

Summary

Retires the Felo Web integration from the v3.8.50 release while its GPL-derived provenance/licensing remains on HOLD. This PR is self-contained: it removes executable/catalog surfaces, rejects stale runtime references before every known bypass, permanently tombstones restored database rows, preserves audit history, and refreshes the public provider counts and zero-config examples.

No merge, automerge, tag, release, or deployment is performed by this PR.

Provenance disposition

Item Evidence Classification Disposition
Upstream implementation xtekky/gpt4free Felo.py at 8ab8e053 Explicit dependency: PROVEN; expressive adaptation: PROBABLE HOLD
Upstream license GPL-3.0 at the same pinned SHA PROVEN Do not ship the derived integration until provenance/licensing is resolved
Wording The upstream is licensed; the unresolved question is compatibility/provenance for this integration PROVEN Use “provenance/licensing HOLD”, never “unlicensed”

Runtime and persisted-state behavior

Surface Before After
Executor dispatch Removing only the specialized executor let unknown Felo ids fall through to DefaultExecutor/OpenAI felo-web and felo fail closed before executor fallback
Proxy overrides A per-connection CLIProxy/Dario override could replace the provider executor first Retirement is checked before any proxy executor override
Compatible nodes A custom node could reuse the removed felo-web/felo prefix and erase the retired identity Both ids remain permanently reserved and raw prefixes are rejected before node remapping
stripModelPrefix Prefix stripping could turn felo-web/gpt-4o into a healthy provider/model Raw provider identity is checked before stripping
Persisted model aliases felo-web/gpt-4o -> openai/gpt-4o could rewrite the request before the tombstone Slashful caller input is rejected before alias mutation; an unrelated bare alias named felo remains legitimate
Direct chat errors HTTP 410 used the generic code model_shutdown All direct retirement responses use HTTP 410, type=provider_error, code=PROVIDER_RETIRED, and a fixed sanitized message
messages/count_tokens Retirement was swallowed by the generic fallback and returned a local estimate with HTTP 200 Retirement returns the same typed/sanitized 410; ordinary provider failures still fall back locally
Exclusive session leases Retirement was converted to retryable 503 LEASE_SERVICE_UNAVAILABLE Retirement returns typed/sanitized 410 before credential/lease materialization
Credential selection A restored active connection could become eligible after the one-shot migration The runtime tombstone rejects it before selection and invalidates request-mode managed leases
Existing DB rows Connections and leases could remain active Migration 163 soft-retires connections and invalidates active leases while preserving ids, generations, usage, calls, quotas, and audit history
Future imports/PATCHes Old imports or administrative updates could reactivate or repurpose retired rows Idempotent triggers cover INSERT/UPDATE/lease restore ordering and block Felo-id repurposing, including INSERT OR REPLACE
API-key allowlists Removing ids could turn an empty list into unrestricted access allowed_connections is preserved byte-for-byte; Felo-only allowlists stay non-empty and fail closed
Public catalog Felo appeared in provider, no-auth, free-model, auto-combo, snapshots, quickstarts, and generated docs Executable surfaces are removed; quickstarts use provider-independent auto; historical changelog references remain intact

TDD evidence

Area RED evidence GREEN evidence
Removal/runtime baseline Registry, executor, model and source references remained; pure removal fell through to DefaultExecutor; active restored rows remained selectable Retirement/runtime contract 6/6 PASS
Prefix and resolver bypasses Compatible-node reuse and stripModelPrefix erased the retired identity Reserved-prefix/schema suite 16/16 PASS; runtime suite 6/6 PASS
Proxy bypass Connection override reached CLIProxy/Dario before the tombstone Executor proxy suite 10/10 PASS
Alias ordering and false positives Persisted slashful alias rewrote to OpenAI; an over-broad guard then rejected the valid bare alias felo Slashful alias returns 410 with zero upstream fetches; bare alias control returns 200
Persisted tombstones Create/dedup/update returned pre-trigger active objects; leases preserved stale ended_at; retired connection ids could be repurposed Migration 1/1 PASS; runtime DB paths included in 6/6 PASS
Unicode normalization SQLite trim() did not cover tabs/newlines or the complete ECMAScript whitespace set Migration/probe covers all 25 ECMAScript whitespace/line terminators and three non-whitespace controls
Token counting Retired Felo returned HTTP 200 local estimate RED 200 != 410 -> GREEN regression; full route suite 8/8 PASS
Session leases Retired Felo returned retryable HTTP 503 RED 503 != 410 -> GREEN regression; full route suite 7/7 PASS
Error contract Chat returned model_shutdown while other endpoints returned PROVIDER_RETIRED RED 0/2 -> GREEN 2/2, uniformly preserving the typed error classification
Legitimate route controls Risk of regressions in chat aliases/cache/streaming and custom model prefixes Chat route edges 9/9 PASS; model overrides/prefix controls 11/11 PASS

Independent final review re-ran Felo runtime, count-tokens, session-leases, and error-sanitization suites in temporary data directories: 57/57 PASS, exit 0. Both the runtime reviewer and DB reviewer returned explicit APPROVE.

Measured branch facts

Denominator Value
Canonical providers 351
Providers with hasFree: true 153
Chat registry 269 providers / 2,587 provider-model pairs / 1,315 raw model ids
Free-model catalog 451 total / 444 active / 7 discontinued
Recurring pools 39
Keyless pools 14
Recurring/keyless free-forever providers 55
Distinct tos: avoid providers 14
Physical migrations 160

Validation

Gate Classification Evidence
Felo runtime PASS 6/6
Migration PASS 1/1; idempotency, restore ordering, row identity and audit-history controls
Executor proxy PASS 10/10
Reserved prefix/schema PASS 16/16
Count-tokens route PASS 8/8
Session-leases route PASS 7/7
Chat route edge controls PASS 9/9
Model override/prefix controls PASS 11/11
Independent final runtime/error review PASS 57/57
Focused Vitest regressions PASS 20/20
Generic no-auth/auto-combo/executor/provider goldens PASS 27/27
npm run typecheck:core PASS exit 0 after the final patch
ESLint with official suppressions PASS full branch-diff scan plus final touched-path scan
Prettier + git diff --check PASS all changed TypeScript and final diff
npm run check:docs-all PASS sync/counts/env/versions/links/fabricated-docs; only pre-existing soft warnings
npm run check:migration-numbering PASS 160 migrations, 3 known gaps, 0 duplicate numbers on this branch
Provider consistency, npm/Bun wrapper INFRA-RED local Bun package postinstall was not run; no code verdict inferred
Provider consistency, same script via Node + TSX PASS 269 registry entries / 351 canonical providers / 0 known exceptions
npm run check:tracked-artifacts PASS no forbidden tracked artifacts
npm run check:changelog-integrity with exact base SHA PASS no changelog bullets lost
npm run check:test-masking with exact base SHA PASS 11 modified / 1 deleted / no weakening; five report-only heuristic warnings
Full unit + full Vitest matrices PENDING / CI Affected lanes are green; remote CI remains authoritative for the complete matrix

Exact comparison base used for local attribution: 091589089cd134a94df9f6cdab9ba562b2cefd18 (release/v3.8.50).

Known HOLD / DRIFT

  • Migration-number collision DRIFT: sibling open PRs, including chore(providers): retire GPL-derived Raycast and Hailuo integrations #11691, fix(providers): retire Qwen Web pending provenance review #11713 and fix(sse): retire Microsoft Designer Web runtime #11720, independently use migration 163 against the same release base. These PRs remain self-contained and do not depend on one another. Whichever integrates after another migration must rebase and renumber its migration, matching test filename and migration assertions, exactly once immediately before merge.
  • General i18n state HOLD: .i18n-state.json is absent on the release base, so the broad translation writer was intentionally not run. The 42 strict llm.txt mirrors pass check:docs-sync; Italian/Turkish current Felo claims were removed directly. Historical localized changelogs were preserved.
  • The root PROVIDER_REFERENCE.md was an orphaned duplicate not written by the generator; the canonical generated document remains docs/reference/PROVIDER_REFERENCE.md.
  • Remote CI restarted for commit d00d1531b0 and is currently queued/in progress. The PR intentionally remains OPEN and DRAFT.

Comment thread open-sse/utils/error.ts Dismissed
backryun and others added 4 commits August 28, 2026 01:19
…utor assertions for v3.8.51

- src/lib/db/migrations: 163 collided with radar_feed_cache_generated_at
  already merged into release/v3.8.51; renumbered to 165 (164 already
  claimed by the Designer Web retirement in this same batch).
- tests/unit/felo-web-retirement.test.ts: getExecutor became async on
  v3.8.51 (#11220 lazy-loading refactor); switched assert.throws to
  assert.rejects.
- tests/unit/chatcore-executor-proxy.test.ts: missing await on
  getExecutor("cliproxyapi") compared an executor instance against a
  raw Promise.
- docs/reference/PROVIDER_REFERENCE.md: regenerated via
  npm run gen:provider-reference.
@diegosouzapw
diegosouzapw force-pushed the fix/v3850-retire-felo-web branch from d00d153 to 6ab670a Compare August 28, 2026 04:24
@diegosouzapw
diegosouzapw changed the base branch from release/v3.8.50 to release/v3.8.51 August 28, 2026 04:24
diegosouzapw and others added 16 commits August 28, 2026 01:57
…#11712)

Obrigado! Correção honesta e bem documentada — só comentário, nenhuma mudança de lógica.

- Corrige a alegação de que omitir `tenantId` do digest evita o falso-positivo do CodeQL `js/insufficient-password-hash`; documenta que o alerta #874 já foi levantado no `createHash` de qualquer forma e foi dispensado por HR#14 (documentação de segurança, não código).
- Deixa explícito por que não "consertar" com um KDF: quebraria o determinismo de que o dedup depende.
Merged via /merge-batch (v3.8.51 provenance sweep). Boarded and validated together with the batch's other provenance/asset-cleanup PRs in a combined worktree (typecheck:core, lint red-discriminator vs the pure release tip, complexity/cognitive-complexity ratchets, file-size, changelog-integrity, and the full focused test suite for every touched area all green). Static-asset-only cleanup, no runtime code changes. Thank you for the careful provenance audit.
Merged via /merge-batch (v3.8.51 provenance sweep). Boarded and validated together with the batch's other provenance PRs in a combined worktree — full gate suite green (typecheck:core, lint red-discriminator, complexity/cognitive-complexity ratchets, file-size, changelog-integrity, focused tests). THIRD_PARTY_NOTICES.md additive merge, no runtime code changes. Thank you.
Merged via /merge-batch (v3.8.51 provenance sweep). Boarded and validated together with the batch's other provenance/asset-cleanup PRs in a combined worktree — full gate suite green. Static-asset-only cleanup, no runtime code changes. Thank you for the provenance audit.
Merged via /merge-batch (v3.8.51 provenance sweep). Boarded and validated together with the batch's other provenance/asset-cleanup PRs in a combined worktree — full gate suite green. Static-asset-only cleanup, no runtime code changes. Thank you.
Merged via /merge-batch (v3.8.51). Boarded and validated in a combined worktree alongside the batch's other in-flight PRs — full gate suite green (typecheck:core, lint, complexity/cognitive-complexity, file-size, changelog-integrity, focused tests including the video-bridge fusion/transcript suites). Thank you.
Merged via /merge-batch (v3.8.51 provenance sweep). Boarded and validated together with the batch's other provenance PRs in a combined worktree — full gate suite green. This PR's THIRD_PARTY_NOTICES.md addition (LobeHub + theSVG provenance sections) conflicted with #11726's own addition (blackwell-systems/gcf-typescript + lipis/flag-icons) landing first; reconciled additively (both sections kept), re-validated with this PR's own 3 focused tests, and pushed before merge. Thank you.
Merged via /merge-batch (v3.8.51 provenance sweep). Boarded and validated together with the batch's other provider/provenance PRs in a combined worktree — full gate suite green. Thank you.
Merged via /merge-batch (v3.8.51 provenance sweep). Boarded and validated together with the batch's other provenance PRs in a combined worktree — full gate suite green, including the new provider-asset-provenance gate/manifest introduced here. Thank you.
Merged via /merge-batch (v3.8.51 provenance sweep). Boarded and validated together with the batch's other provenance/retirement PRs in a combined worktree — full gate suite green, including the video/image regression suites and the new gemini-web-image-retirement test file (fixed a getExecutor async-signature drift found during the combined validation pass; Gemini Web chat and legitimate Gemini image providers unaffected). Thank you.
…test (#11868)

Direct follow-up fixing a bug my own /merge-batch process introduced. Test-only change, focused test passing.
Merged via /merge-batch (v3.8.51 provenance sweep). Boarded and validated together with the batch's other provenance/dependency PRs in a combined worktree — full gate suite green. Thank you.
Merged via /merge-batch (v3.8.51 provenance sweep). Boarded and validated together with the batch's other provenance/retirement PRs in a combined worktree — full gate suite green, including the audio/speech-combo regression suites. Thank you.
Merged via /merge-batch (v3.8.51 provenance sweep). Boarded and validated together with the batch's other retirement PRs in a combined worktree — full gate suite green. This PR's own conflicts (against #11711's EdgeTTS retirement, both touching test-masking-allowlist.json and the "Image / video / audio generation" README bullet) were reconciled additively/subtractively (both retirements now correctly reflected), re-validated with this PR's own 62 focused tests, and pushed before merge. Thank you.
…1750)

Merged via /merge-batch (v3.8.51 provenance sweep). Boarded and validated together with the batch's other provenance PRs in a combined worktree — full gate suite green. Reconciled against 3 sibling PRs (#11735, #11736, #11711) that landed first and independently retired 6 further unproven assets this PR never targeted, in both the README media-badge row and the "148 non-target assets" golden count (now the real 142, computed not guessed). This PR's own 23 node:test + 91 vitest focused tests all pass. Thank you for the careful provenance/generic-fallback work.
@diegosouzapw
diegosouzapw marked this pull request as ready for review August 28, 2026 08:03
@diegosouzapw
diegosouzapw merged commit 84504e3 into release/v3.8.51 Aug 28, 2026
6 of 12 checks passed
diegosouzapw added a commit that referenced this pull request Aug 28, 2026
Rebased onto the current release/v3.8.51 tip as part of a combined provider-retirement/provenance merge batch (Designer Web, Felo Web, Runtime, GPL-derived removal, Qwen Web already landed). Large conflict set (this is the biggest PR in the batch — the common ChatGPT Web provider touches chat, images, count-tokens, session leases, and combos). Conflicts resolved:

- `open-sse/config/providers/registry/chatgpt-web/*`, `open-sse/executors/chatgpt-web*`, `open-sse/handlers/imageGeneration/providers/chatgptWeb.ts`, and their tests: kept deleted, matching the PR's stated scope.
- `open-sse/config/providers/registry/minimax/web/index.ts`, `open-sse/handlers/imageGeneration/providers/geminiWeb.ts`, `open-sse/executors/gemini-web.ts`'s stale image-mode branch: base-drift collisions against already-merged sibling retirements (#11691, #11708) — kept deleted / dropped the dead code, since this PR's own branch forked before those merged.
- `src/shared/constants/reservedProviderPrefixes.ts`, `open-sse/executors/index.ts`, `executorProxy.ts`, `virtualFactory.ts`, `autoStrategy.ts`, `src/lib/db/providers.ts`, `src/sse/handlers/chat.ts`: combined the Designer + Runtime (Felo/Qwen) + common-ChatGPT-Web retirement guard calls at each shared chokepoint — compute-once-then-OR pattern, consistent with prior combinations in this batch.
- `src/sse/services/model.ts` / `src/sse/handlers/chatHelpers.ts`: adopted this PR's new `getModelInfoOrRetirementResponse()` central wrapper (a real improvement over ad-hoc try/catch), and extended it to also catch the Designer + Runtime retirement errors it didn't originally cover, so the consolidation doesn't regress the other two mechanisms.
- `src/app/api/v1/images/edits/route.ts`: this PR moved the retirement check earlier (before `enforceApiKeyPolicy`) but left the old later call+catch block in place from base drift — removed the now-redundant duplicate `resolveImageRouteModel()` call and merged the Designer catch into the earlier one.
- `open-sse/config/imageRegistry.ts`, `tests/snapshots/executors/executor-map.json` (`keyCount` recomputed to 133), `tests/snapshots/provider/translate-path.json`: same "both sides inserted a different retired provider at the same slot" pattern — resolved by dropping both.
- `tests/unit/chatcore-executor-proxy.test.ts`, `provider-node-reserved-prefix.test.ts`, `combo-auto-candidate-expansion.test.ts`, `messages-count-tokens-route.test.ts`, `virtual-auto-combo.test.ts`: split into independent per-mechanism test blocks (established pattern); `virtual-auto-combo.test.ts`'s old "includes cookie web-session providers" positive-inclusion test (which used chatgpt-web as its example) was retired along with the provider and replaced by this PR's negative-exclusion test for the same slot.
- `docs/architecture/ARCHITECTURE.md`, `CODEBASE_DOCUMENTATION.md` (+ 4 i18n mirrors), `README.md`, `FREE-TIERS-GUIDE.md`, `docs/diagrams/free-tier-budget.svg`, `docs/screenshots/free-tier-budget-card.svg`, `docs/reference/PROVIDER_REFERENCE.md`: recomputed every stale count from the real merged state — 104 executors (`countFiles` gate logic), 351 providers (regenerated via `gen:provider-reference`), 152/351 `hasFree` entries, 445/438/7 free-tier catalog rows, 13 ToS-avoid providers, budget-card regenerated via its real generator script. One doc conflict (`oauth/` module list) needed picking HEAD's side specifically — theirs still listed the already-removed `raycast` module instead of the real `openference`.
- `config/quality/test-masking-allowlist.json`: additive merge of the PR's 17 `_deletedWithReplacement` entries alongside the batch's existing ones (one real duplicate-key mistake in my first pass, caught and fixed via a `object_pairs_hook` duplicate-key check before finalizing).

Also fixed two real, unrelated-to-my-merge issues surfaced by the focused suite:
- `tests/unit/resolve-web-provider-host.test.ts`: the PR's own test had a typo — it asserted `perplexity-web`'s resolved host as `"perplexity.ai"`, but the provider's registered `website` is `"https://www.perplexity.ai"` and the resolver returns the URL's `host` verbatim (no www-stripping), so the correct value is `"www.perplexity.ai"` (consistent with the same test's own `url` assertion).
- `tests/unit/hard-session-lease-bypass-inventory.test.ts`: this golden call-site inventory was already stale on the pristine post-#11713 tip (confirmed via a throwaway probe worktree) — `src/lib/db/providers.ts`'s 3 connection-fallback sites and a third `src/app/api/providers/route.ts` site were never added to the golden list by the earlier-merged #11698/#11720 PRs. Updated it to the real current inventory (dated inline comments explain each delta and which PR introduced it), plus this PR's own legitimate deltas (image-edits duplicate-call removal, `ChatGptWebExecutor.execute()` site removed).

Focused suite green (433/433 across executor-proxy, reserved-prefix, hard-session-lease-bypass-inventory, resolve-web-provider-host, retirement/runtime-block/source-retirement/management-retirement/image-handler-retirement, migration-168, combo-auto-candidate-expansion, virtual-auto-combo, executor-map-golden and siblings), plus `typecheck:core`, `check-file-size`, and `check-changelog-integrity` clean. Thanks for the thorough provenance-hold retirement work — appreciated.
muhamadgalihsaputra pushed a commit to niyatna/NiyatnaRoute that referenced this pull request Sep 27, 2026
)

Merged via /merge-batch (v3.8.51 provenance sweep). Boarded and validated together with the batch's other retirement PRs in a combined worktree — full gate suite green. This PR's conflicts (against diegosouzapw#11720's Designer retirement, both introducing a retirement-guard mechanism across executors/index.ts, executorProxy.ts, providers.ts, reservedProviderPrefixes.ts, auth.ts, chat.ts, chatHelpers.ts, model.ts) were reconciled by combining both guards at every chokepoint, with the shared reserved-prefix count recomputed (not guessed) at 400. Re-validated with this PR's own 72 node:test + 20 vitest focused tests, all passing, and pushed before merge. Thank you.
muhamadgalihsaputra pushed a commit to niyatna/NiyatnaRoute that referenced this pull request Sep 27, 2026
Rebased onto the current release/v3.8.51 tip as part of a combined provider-retirement/provenance merge batch (Designer Web, Felo Web, Runtime, GPL-derived removal, Qwen Web already landed). Large conflict set (this is the biggest PR in the batch — the common ChatGPT Web provider touches chat, images, count-tokens, session leases, and combos). Conflicts resolved:

- `open-sse/config/providers/registry/chatgpt-web/*`, `open-sse/executors/chatgpt-web*`, `open-sse/handlers/imageGeneration/providers/chatgptWeb.ts`, and their tests: kept deleted, matching the PR's stated scope.
- `open-sse/config/providers/registry/minimax/web/index.ts`, `open-sse/handlers/imageGeneration/providers/geminiWeb.ts`, `open-sse/executors/gemini-web.ts`'s stale image-mode branch: base-drift collisions against already-merged sibling retirements (diegosouzapw#11691, diegosouzapw#11708) — kept deleted / dropped the dead code, since this PR's own branch forked before those merged.
- `src/shared/constants/reservedProviderPrefixes.ts`, `open-sse/executors/index.ts`, `executorProxy.ts`, `virtualFactory.ts`, `autoStrategy.ts`, `src/lib/db/providers.ts`, `src/sse/handlers/chat.ts`: combined the Designer + Runtime (Felo/Qwen) + common-ChatGPT-Web retirement guard calls at each shared chokepoint — compute-once-then-OR pattern, consistent with prior combinations in this batch.
- `src/sse/services/model.ts` / `src/sse/handlers/chatHelpers.ts`: adopted this PR's new `getModelInfoOrRetirementResponse()` central wrapper (a real improvement over ad-hoc try/catch), and extended it to also catch the Designer + Runtime retirement errors it didn't originally cover, so the consolidation doesn't regress the other two mechanisms.
- `src/app/api/v1/images/edits/route.ts`: this PR moved the retirement check earlier (before `enforceApiKeyPolicy`) but left the old later call+catch block in place from base drift — removed the now-redundant duplicate `resolveImageRouteModel()` call and merged the Designer catch into the earlier one.
- `open-sse/config/imageRegistry.ts`, `tests/snapshots/executors/executor-map.json` (`keyCount` recomputed to 133), `tests/snapshots/provider/translate-path.json`: same "both sides inserted a different retired provider at the same slot" pattern — resolved by dropping both.
- `tests/unit/chatcore-executor-proxy.test.ts`, `provider-node-reserved-prefix.test.ts`, `combo-auto-candidate-expansion.test.ts`, `messages-count-tokens-route.test.ts`, `virtual-auto-combo.test.ts`: split into independent per-mechanism test blocks (established pattern); `virtual-auto-combo.test.ts`'s old "includes cookie web-session providers" positive-inclusion test (which used chatgpt-web as its example) was retired along with the provider and replaced by this PR's negative-exclusion test for the same slot.
- `docs/architecture/ARCHITECTURE.md`, `CODEBASE_DOCUMENTATION.md` (+ 4 i18n mirrors), `README.md`, `FREE-TIERS-GUIDE.md`, `docs/diagrams/free-tier-budget.svg`, `docs/screenshots/free-tier-budget-card.svg`, `docs/reference/PROVIDER_REFERENCE.md`: recomputed every stale count from the real merged state — 104 executors (`countFiles` gate logic), 351 providers (regenerated via `gen:provider-reference`), 152/351 `hasFree` entries, 445/438/7 free-tier catalog rows, 13 ToS-avoid providers, budget-card regenerated via its real generator script. One doc conflict (`oauth/` module list) needed picking HEAD's side specifically — theirs still listed the already-removed `raycast` module instead of the real `openference`.
- `config/quality/test-masking-allowlist.json`: additive merge of the PR's 17 `_deletedWithReplacement` entries alongside the batch's existing ones (one real duplicate-key mistake in my first pass, caught and fixed via a `object_pairs_hook` duplicate-key check before finalizing).

Also fixed two real, unrelated-to-my-merge issues surfaced by the focused suite:
- `tests/unit/resolve-web-provider-host.test.ts`: the PR's own test had a typo — it asserted `perplexity-web`'s resolved host as `"perplexity.ai"`, but the provider's registered `website` is `"https://www.perplexity.ai"` and the resolver returns the URL's `host` verbatim (no www-stripping), so the correct value is `"www.perplexity.ai"` (consistent with the same test's own `url` assertion).
- `tests/unit/hard-session-lease-bypass-inventory.test.ts`: this golden call-site inventory was already stale on the pristine post-diegosouzapw#11713 tip (confirmed via a throwaway probe worktree) — `src/lib/db/providers.ts`'s 3 connection-fallback sites and a third `src/app/api/providers/route.ts` site were never added to the golden list by the earlier-merged diegosouzapw#11698/diegosouzapw#11720 PRs. Updated it to the real current inventory (dated inline comments explain each delta and which PR introduced it), plus this PR's own legitimate deltas (image-edits duplicate-call removal, `ChatGptWebExecutor.execute()` site removed).

Focused suite green (433/433 across executor-proxy, reserved-prefix, hard-session-lease-bypass-inventory, resolve-web-provider-host, retirement/runtime-block/source-retirement/management-retirement/image-handler-retirement, migration-168, combo-auto-candidate-expansion, virtual-auto-combo, executor-map-golden and siblings), plus `typecheck:core`, `check-file-size`, and `check-changelog-integrity` clean. Thanks for the thorough provenance-hold retirement work — appreciated.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants