Skip to content

fix(ci): clear the release/v3.8.51 base-reds left by the 09-15 batch (stryker, CLI i18n, paid-target fixture, call-log traceId, Jina prefix, callLogStats import, gitleaks) - #13747

Merged
diegosouzapw merged 10 commits into
release/v3.8.51from
fix/release-v3.8.51-basereds-r4
Sep 16, 2026
Merged

diegosouzapw merged 10 commits into
release/v3.8.51from
fix/release-v3.8.51-basereds-r4

Conversation

@diegosouzapw

@diegosouzapw diegosouzapw commented Sep 15, 2026 •

Copy link
Copy Markdown
Owner

Why

Every PR into release/v3.8.51 pushed after #13635/#13678 still failed Fast Quality Gates and all four Unit Tests fast-path shards, on the same 16 tests (#13266, #13173, #13149, #13150, #13355, #13628, #13717 and #13720 fail on exactly this set). Each failure reproduces on the pure tip. All five come from yesterday's batch: none is a product defect, and no assertion is weakened.

Red Root cause Fix
FQG mutation-test-coverage noauth-model-lockout and local-token-budget-429-skips-cooldown (#13606) cover accountFallback.ts / auth.ts / comboPredicates.ts, but neither is in stryker.conf.json tap.testFiles add both entries
cli-i18n-catalog (1, then 2 parity) --ready-timeout calls t("serve.ready_timeout") with no catalog entry add the key to en, zh-CN, zh-TW (the parity-checked CLI locales)
paid-model-target-6540 (1) + paid-model-target-routes-6540 (3) #13407 removed Together's one-time credit, so together/… now classifies as unknown, and the save-time guard correctly lets it through the paid fixture is now gemini/gemini-3.1-pro-preview (Gemini's free tier recurs and does not include Pro), plus a precondition test that the fixtures still classify as paid/free/unknown
attempt-logging-early-keepalive-merge (3) + video-bridge-log-redaction (6, 30 s timeouts) #13546 keys the call-log row on traceId, but these tests poll by pendingRequestId baseCtx defaults traceId to pendingRequestId, the same pattern chatcore-attempt-logging got in #13546. The keepalive poll moves to the 30 s wall-clock deadline video-bridge already uses
API Route Typecheck + check:dashboard-typecheck the #13641 merge left ERROR_TYPE_CONTRACT imported twice in src/lib/db/callLogStats.ts (TS2300) drop the duplicate import
FQG secrets (ratchet 0 → 1) the Uzbek catalog from #13727 translates outputTokenDesc as "Yakunlash/javob tokenlari", which generic-api-key reads as a token value narrow regex allowlist entry in .gitleaks.toml, with the reason
dashboard-request-failed-redaction (1) the probe reads the persisted row by pendingRequestId; since #13546 the row is keyed by traceId read it by traceId (the two ids stay distinct, so the test still pins the key)
FQG file-size (PR mode) #13748 grew image-generation-handler.test.ts 2133→2235 and #13749 grew batch_api.test.ts 1345→1348. PR mode does not relax testFrozen against the base re-freeze both at the merged LOC, with a justification entry (same pattern as the 2026-09-02 base-red drain)
models-catalog-route Jina custom (1) #13403 switched the custom-row assertion to jina/, but custom rows keep the connection's provider id (jina-ai/). Only synced rows go through the jina alias, and the test above covers those restore jina-ai/ for custom rows

Refs #12732

Validation

On the merge with the tip (c8b24ffc). Rows 6–9 came from this PR's CI runs and were fixed in follow-up commits:

  • node scripts/check/check-mutation-test-coverage.mjs --strict: no drift
  • check-api-typecheck: FAIL before (callLogStats.ts TS2300), exit 0 after. check-secrets --ratchet: 0 findings. check:file-size --base-ref: OK.
  • check-test-discovery, check-changelog-integrity: OK. ESLint (with suppressions) and Prettier are clean on the changed files. Pre-commit hooks ran green.
  • node --test on each touched file, run in full: cli-i18n-catalog 11/11, paid-model-target-6540 10/10, paid-model-target-routes-6540 11/11, attempt-logging-early-keepalive-merge 4/4, video-bridge-log-redaction 7/7, models-catalog-route all pass. The covering tests noauth-model-lockout, local-token-budget-429-skips-cooldown and i18n-home-recent-requests-topology-legend also pass.
  • Redaction probe, checked both directions: reading by pendingRequestId asserts null; reading by traceId prints the probe result. Locally the probe takes ~60 s at load ~45, past the test's 30 s cap; CI is fine.
  • Checked both directions: with traceId removed from baseCtx, the keepalive merge test fails even with the 30 s deadline; with it restored, 4/4 pass.

Notes:

  • chatcore-attempt-logging (not touched) can miss its 2.4 s poll on a heavily loaded machine: 2 failures at load average ~45 locally, 7/7 with a larger budget. It does not fail in CI, so it stays out of scope here.
  • The custom-vs-synced Jina prefix mismatch (jina-ai/ vs jina/) is existing runtime behaviour. This PR only realigns the test; unifying the two prefixes would change user-visible model ids and belongs in its own change.

…— stryker coverage, CLI ready_timeout key, paid-target fixture, call-log traceId, Jina custom prefix

Every PR into release/v3.8.51 pushed after #13635/#13678 still failed Fast
Quality Gates and all four Unit fast-path shards on the same 16 tests. Each one
reproduces on the pure tip; none is a product defect:

- mutation-test-coverage: noauth-model-lockout and
  local-token-budget-429-skips-cooldown (#13606) were missing from
  stryker.conf.json tap.testFiles.
- cli-i18n-catalog: --ready-timeout calls t("serve.ready_timeout") with no
  catalog entry; added to en, zh-CN and zh-TW (the parity-checked locales).
- paid-model-target(-routes)-6540: #13407 removed Together's one-time credit
  from the free catalog, so "together/..." classifies as unknown and the
  save-time guard correctly lets it through. Fixture is now
  gemini/gemini-3.1-pro-preview, plus a precondition test on the fixtures.
- attempt-logging-early-keepalive-merge / video-bridge-log-redaction: #13546
  keys the call-log row on traceId; baseCtx now defaults traceId to
  pendingRequestId (same pattern as chatcore-attempt-logging). The keepalive
  test also moves to the 30s wall-clock poll deadline video-bridge uses.
- models-catalog-route: custom Jina rows keep the jina-ai/ prefix; #13403
  changed the custom assertion to jina/ (only synced rows use the alias).

Refs #12732
@diegosouzapw

Copy link
Copy Markdown
Owner Author

Confirmação independente e um dado que pode poupar uma caça a flake.

Cheguei às mesmas duas causas-raiz por conta própria, antes de ver esta PR — o que é boa validação dos consertos daqui:

Não vou abrir PR concorrente; esta chegou primeiro e cobre mais.

O dado novo: cold start do worker de artefato

Depois do conserto de traceId, um caso de video-bridge-log-redaction.test.ts continua sensível a carga: "persisted requestBody carries the placeholder and never the raw transcript when a redaction map is present". É o único que passa pelo caminho de artefato, e ele paga o cold start do worker no primeiro write.

Medido com timestamps dentro de saveCallLogOperation, carga do devbox em ~70:

A1 antes  de writeCallArtifactAsync   t=1517 ms
A2 depois de writeCallArtifactAsync   t=28789 ms   ← 27,3 s para um arquivo de 844 bytes
INSERT                                t=28789 ms
poll do teste                         30000 ms

Com carga ~70 passa por pouco; com ~107 estourou os 30 s e falhou isolado, de forma reproduzível. Não é defeito de lógica — o artefato é gravado e o insert acontece, só depois do prazo.

No CI da #13730 esse caso não apareceu entre as falhas deste arquivo (as de lá eram as de 30013/30018 ms, espera esgotada na chave errada), então provavelmente passa no runner. Se aparecer como flake, a correção de princípio é aquecer o writer no before(), para a espera medir a gravação e não o boot do worker — e não aumentar o prazo.

…ats duplicate import, Uzbek gitleaks false positive, redaction probe traceId, file-size

- src/lib/db/callLogStats.ts: the #13641 merge left ERROR_TYPE_CONTRACT
  imported twice (TS2300), failing API Route Typecheck and
  check:dashboard-typecheck on every PR.
- .gitleaks.toml: the Uzbek catalog from #13727 translates outputTokenDesc as
  "Yakunlash/javob tokenlari"; generic-api-key reads it as a token value.
- dashboard-request-failed-redaction-probe: reads the persisted row by
  traceId (#13546); with pendingRequestId it asserts null.
- models-catalog-route: drop the explanatory comment, which pushed the frozen
  file over its size cap; the rationale lives in the changelog fragment.

Refs #12732
@diegosouzapw diegosouzapw changed the title fix(ci): clear the release/v3.8.51 base-reds left by the 09-15 batch (stryker, CLI i18n, paid-target fixture, call-log traceId, Jina custom prefix) fix(ci): clear the release/v3.8.51 base-reds left by the 09-15 batch (stryker, CLI i18n, paid-target fixture, call-log traceId, Jina prefix, callLogStats import, gitleaks) Sep 15, 2026
…ile-size caps

PR-mode check:file-size relaxes source files against the base but not
testFrozen, so image-generation-handler.test.ts (2133->2235, #13748) and
batch_api.test.ts (1345->1348, #13749) failed Fast Quality Gates on every PR,
this one included. Caps set to the merged LOC, with the justification entry.

Refs #12732
…stFiles

#13645 landed a covering test for src/sse/services/auth.ts without the
stryker entry, so the strict mutation-test-coverage gate went red again.

Refs #12732
- stryker.conf.json: register daily-reset-tz-threading (#13440), which covers
  accountFallback.ts and rrState.ts.
- .gitleaks.toml: allowlist the PROTECTED_PRIORITY_INFRA_502_ENABLED flag id
  (#13439); generic-api-key reads its key: as a token (secrets ratchet 0 -> 1).

Refs #12732
diegosouzapw added a commit that referenced this pull request Sep 16, 2026
…d ERROR_TYPE_CONTRACT import left by the batch merges (#13816)

Merged with admin on local + CI evidence: `tests/unit/i18n-catalogs-no-duplicate-keys.test.ts` red on the tip (59 catalogs) → `pass 3 / fail 0` here; **API Route Typecheck passes on this PR** (it fails on every PR based on the current tip because of the duplicated `ERROR_TYPE_CONTRACT` import this removes); CodeQL, semgrep, Vitest fast-path, Docs gates, Change Classification pass. The remaining red checks (Fast Quality Gates, Merge integrity, Unit Tests fast-path 1/2/4) are the same inherited tip reds every PR on release/v3.8.51 shows right now — #13747 sweeps them. Both removed lines were byte-identical duplicates; nothing parsed or typed changes.
@diegosouzapw
diegosouzapw merged commit 8f55d85 into release/v3.8.51 Sep 16, 2026
21 checks passed
@diegosouzapw
diegosouzapw deleted the fix/release-v3.8.51-basereds-r4 branch September 16, 2026 01:48
diegosouzapw added a commit that referenced this pull request Sep 16, 2026
diegosouzapw added a commit that referenced this pull request Sep 16, 2026
diegosouzapw added a commit that referenced this pull request Sep 16, 2026
diegosouzapw added a commit that referenced this pull request Sep 16, 2026
diegosouzapw added a commit that referenced this pull request Sep 16, 2026
diegosouzapw added a commit that referenced this pull request Sep 16, 2026
diegosouzapw added a commit that referenced this pull request Sep 16, 2026
diegosouzapw added a commit that referenced this pull request Sep 16, 2026
diegosouzapw added a commit that referenced this pull request Sep 16, 2026
diegosouzapw added a commit that referenced this pull request Sep 16, 2026
diegosouzapw added a commit that referenced this pull request Sep 16, 2026
diegosouzapw added a commit that referenced this pull request Sep 16, 2026
diegosouzapw added a commit that referenced this pull request Sep 16, 2026
diegosouzapw added a commit that referenced this pull request Sep 16, 2026
diegosouzapw added a commit that referenced this pull request Sep 16, 2026
diegosouzapw added a commit that referenced this pull request Sep 16, 2026
diegosouzapw added a commit that referenced this pull request Sep 16, 2026
diegosouzapw added a commit that referenced this pull request Sep 16, 2026
diegosouzapw added a commit that referenced this pull request Sep 16, 2026
diegosouzapw added a commit that referenced this pull request Sep 16, 2026
diegosouzapw added a commit that referenced this pull request Sep 16, 2026
diegosouzapw added a commit that referenced this pull request Sep 16, 2026
diegosouzapw added a commit that referenced this pull request Sep 16, 2026
diegosouzapw added a commit that referenced this pull request Sep 16, 2026
diegosouzapw added a commit that referenced this pull request Sep 16, 2026
diegosouzapw added a commit that referenced this pull request Sep 16, 2026
diegosouzapw added a commit that referenced this pull request Sep 16, 2026
diegosouzapw added a commit that referenced this pull request Sep 16, 2026
diegosouzapw added a commit that referenced this pull request Sep 16, 2026
diegosouzapw added a commit that referenced this pull request Sep 16, 2026
diegosouzapw added a commit that referenced this pull request Sep 16, 2026
diegosouzapw added a commit that referenced this pull request Sep 16, 2026
diegosouzapw added a commit that referenced this pull request Sep 16, 2026
diegosouzapw added a commit to jackjinke/OmniRoute that referenced this pull request Sep 16, 2026
…51 merge

The prior merge commit's 3-way auto-merge silently dropped several
non-conflicting hunks from origin/release/v3.8.51 (997cd4d) even though
this branch had no competing change in those regions (ours == merge-base
for every affected file) — most visibly the diegosouzapw#13747 base-reds fixups
(call-log traceId keying, Jina custom-row provider prefix, CI workflow,
gitleaks config, stryker config, i18n retranslate work) and, in
src/i18n/messages/*.json, a set of duplicated keys where an older
Arabic/etc. translation and a newer untranslated English value for the
same key both survived (JSON.parse silently keeps the last one, masking
the duplication) plus 6 missing settings/featureFlags keys across 39
locales.

Fixed by:
- Restoring the 19 unrelated files (CI/gitleaks/stryker config, i18n
  tooling, and the traceId/Jina/paid-target/retranslate test files) to
  their exact origin/release/v3.8.51 content — this PR never touches any
  of them.
- Rebuilding all 42 src/i18n/messages/*.json files this PR legitimately
  touches from the clean tip content plus exactly this PR's own two-line
  diff per locale (add the "bigmodel" onboarding hint, fix the "zai" one)
  taken from jackjinke's original commit 04707b5, verified duplicate-key-
  free and with zero keys missing relative to the pinned tip (997cd4d).

Co-authored-by: diegosouzapw <8016841+diegosouzapw@users.noreply.github.com>
diegosouzapw added a commit to jackjinke/OmniRoute that referenced this pull request Sep 16, 2026
…3782 (2 commits, cde49c9)

The branch moved twice more while this PR was being reconciled. Merge the
remaining 2 commits from origin/release/v3.8.51: diegosouzapw#13747 (base-reds
cleanup, already reflected by the previous commit) and diegosouzapw#13782 (retranslate
every verbatim-English leaf across all 65 locale catalogs). Resolved the
resulting real conflicts in es.json and uk-UA.json by keeping the tip's
newly retranslated onboardingProviderDescriptions content and re-applying
this PR's own bigmodel/zai lines (already translated by jackjinke) on top.

Co-authored-by: diegosouzapw <8016841+diegosouzapw@users.noreply.github.com>
muhamadgalihsaputra pushed a commit to niyatna/NiyatnaRoute that referenced this pull request Sep 27, 2026
…d ERROR_TYPE_CONTRACT import left by the batch merges (diegosouzapw#13816)

Merged with admin on local + CI evidence: `tests/unit/i18n-catalogs-no-duplicate-keys.test.ts` red on the tip (59 catalogs) → `pass 3 / fail 0` here; **API Route Typecheck passes on this PR** (it fails on every PR based on the current tip because of the duplicated `ERROR_TYPE_CONTRACT` import this removes); CodeQL, semgrep, Vitest fast-path, Docs gates, Change Classification pass. The remaining red checks (Fast Quality Gates, Merge integrity, Unit Tests fast-path 1/2/4) are the same inherited tip reds every PR on release/v3.8.51 shows right now — diegosouzapw#13747 sweeps them. Both removed lines were byte-identical duplicates; nothing parsed or typed changes.
muhamadgalihsaputra pushed a commit to niyatna/NiyatnaRoute that referenced this pull request Sep 27, 2026
…(stryker, CLI i18n, paid-target fixture, call-log traceId, Jina prefix, callLogStats import, gitleaks) (diegosouzapw#13747)

* fix(ci): clear the release/v3.8.51 base-reds left by the 09-15 batch — stryker coverage, CLI ready_timeout key, paid-target fixture, call-log traceId, Jina custom prefix

Every PR into release/v3.8.51 pushed after diegosouzapw#13635/diegosouzapw#13678 still failed Fast
Quality Gates and all four Unit fast-path shards on the same 16 tests. Each one
reproduces on the pure tip; none is a product defect:

- mutation-test-coverage: noauth-model-lockout and
  local-token-budget-429-skips-cooldown (diegosouzapw#13606) were missing from
  stryker.conf.json tap.testFiles.
- cli-i18n-catalog: --ready-timeout calls t("serve.ready_timeout") with no
  catalog entry; added to en, zh-CN and zh-TW (the parity-checked locales).
- paid-model-target(-routes)-6540: diegosouzapw#13407 removed Together's one-time credit
  from the free catalog, so "together/..." classifies as unknown and the
  save-time guard correctly lets it through. Fixture is now
  gemini/gemini-3.1-pro-preview, plus a precondition test on the fixtures.
- attempt-logging-early-keepalive-merge / video-bridge-log-redaction: diegosouzapw#13546
  keys the call-log row on traceId; baseCtx now defaults traceId to
  pendingRequestId (same pattern as chatcore-attempt-logging). The keepalive
  test also moves to the 30s wall-clock poll deadline video-bridge uses.
- models-catalog-route: custom Jina rows keep the jina-ai/ prefix; diegosouzapw#13403
  changed the custom assertion to jina/ (only synced rows use the alias).

Refs diegosouzapw#12732

* fix(ci): clear the four reds the first r4 CI run surfaced — callLogStats duplicate import, Uzbek gitleaks false positive, redaction probe traceId, file-size

- src/lib/db/callLogStats.ts: the diegosouzapw#13641 merge left ERROR_TYPE_CONTRACT
  imported twice (TS2300), failing API Route Typecheck and
  check:dashboard-typecheck on every PR.
- .gitleaks.toml: the Uzbek catalog from diegosouzapw#13727 translates outputTokenDesc as
  "Yakunlash/javob tokenlari"; generic-api-key reads it as a token value.
- dashboard-request-failed-redaction-probe: reads the persisted row by
  traceId (diegosouzapw#13546); with pendingRequestId it asserts null.
- models-catalog-route: drop the explanatory comment, which pushed the frozen
  file over its size cap; the rationale lives in the changelog fragment.

Refs diegosouzapw#12732

* fix(ci): re-freeze the two test files diegosouzapw#13748/diegosouzapw#13749 grew past their file-size caps

PR-mode check:file-size relaxes source files against the base but not
testFrozen, so image-generation-handler.test.ts (2133->2235, diegosouzapw#13748) and
batch_api.test.ts (1345->1348, diegosouzapw#13749) failed Fast Quality Gates on every PR,
this one included. Caps set to the merged LOC, with the justification entry.

Refs diegosouzapw#12732

* fix(ci): register free-badge-provider-gate (diegosouzapw#13645) in stryker tap.testFiles

diegosouzapw#13645 landed a covering test for src/sse/services/auth.ts without the
stryker entry, so the strict mutation-test-coverage gate went red again.

Refs diegosouzapw#12732

* fix(ci): clear two more base-reds the diegosouzapw#13440/diegosouzapw#13439 merges added

- stryker.conf.json: register daily-reset-tz-threading (diegosouzapw#13440), which covers
  accountFallback.ts and rrState.ts.
- .gitleaks.toml: allowlist the PROTECTED_PRIORITY_INFRA_502_ENABLED flag id
  (diegosouzapw#13439); generic-api-key reads its key: as a token (secrets ratchet 0 -> 1).

Refs diegosouzapw#12732

* docs(changelog): tidy the stryker base-red fragment wording

Refs diegosouzapw#12732
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant