fix(sse): restore maxQueueDepth=0 as unbounded, sanitize refusals at the write, drain the 09-18 base-reds - #14101
Merged
Conversation
…y, inventory, webpack externals Reproduced on the clean tip 7cc454d before touching anything. Five of the failures trace to one commit, #12905 (b7192b7): it gated thinking-block emission on `requestedThinking === true` in the streaming translator, while its own non-streaming path documents `undefined` as the legacy caller shape that keeps "always a thinking block". The two paths disagreed on the same input, and the streaming side also synthesized the reasoning into a TEXT block for that legacy shape. chatCore always resolves a boolean, so production never sends `undefined` — but every direct caller and the older #5786 suites do. Aligned the streaming gate to the documented tri-state: `false` suppresses, `true` and `undefined` relay, and the fix-B text synthesis fires only on an explicit opt-out. The #12905 test that asserted suppression used a bare createState() (`undefined`) to mean "client did not request thinking"; it now passes `requestedThinking: false`, which is what that sentence resolves to in production. The whole thinking family — dsml, adapter, translator, non-stream parity, #13620, #5786, markdown boundary — is 77/77. #12864 added requestRejectedFailure.ts with a getProviderConnectionById read that seeds the refusal streak across restarts; inventoried as a connection state read next to the family-cooldown site it resembles. #13909 made machineToken.ts import ./dataPaths; the isolated webpack compile has no repo tree, so it joins the sibling externals. The free-tier budget card SVG was one wave behind again (482 -> 491 models). Refs #13866
…the write, drain the rest Part 2 of the 09-18 base-red drain. Two of the remaining failures were not stale tests but production defects the tests had caught. #12911 taught accountSemaphore to read `maxQueueSize: 0` as "reject when the slot is busy", which is what its Codex WS lease wants. But chatCore forwards `resilienceSettings.requestQueue.maxQueueDepth` into that option, and that setting's documented default since #6593 is `0 = disabled`. Under default settings every request that found its account slot occupied was answered 429 "Semaphore queue full (0)" instead of waiting — the managed-lease routing test saw exactly that. `0` (and any non-positive value) is unbounded again; the lease gets an explicit `failFast` option and its four tests stay green, so the #12911 behaviour is preserved where it was meant to apply. A contract test pins the #6593 semantics on the semaphore itself. #12864 moved two providerFailure persistence branches out of chatCore into requestRejectedFailure.ts and the sanitization did not travel with them: three `lastError` writes stored the message as received. The only caller already hands in the projected persistentMessage, so nothing leaks today, but a persistence branch must be safe at its own write (docs/security/ ERROR_SANITIZATION.md) rather than trust whoever calls it. The module now sanitizes on entry, and the public-boundary guard — which caught this by counting sanitized writes in chatCore and coming up two short — covers the extracted module too, verified by mutating one write back to raw. The rest are tests that had fallen behind legitimate changes: - #12905 inserted `requestedThinking` as the 14th positional argument of createSSETransformStreamWithLogger; two tests passed customToolNames or the buffer budget at their old positions. Both production callers were already correct. - #12754 added a per-connection reset-card fetch after the quota fetch; the spacing test now marks a chunk at the quota request only. - #13910 renamed `error` to `errorMetadata` in the timeout classification; the probe matches the identifier with a backreference and still fails when BodyTimeoutError is removed from both sites. Refs #13866
… keep acquireMany under the complexity ceiling The #12905 gate-restore suite encoded 'requestedThinking absent' as opt-out, the same undefined-means-false shape its non-streaming twin documents the other way and that the two-month-old #5786 suites contradict. The three opt-out cases now set the flag explicitly, which is what chatCore resolves for an opted-out client; the two opt-in cases already did. Both suites pass together (27/27). The failFast branch pushed acquireMany over the complexity ceiling it already sat on; the admission policy (fail-fast / bounded / unbounded queue) moves to findQueueRejection() and the new-code ratchet is back at its base. Refs #13866
…e-v3.8.51-basereds-0918
… budget card The 57 commits merged since the previous validation moved two things. #13295 changed how an unknown-root path with an ambiguous tail is answered: where `Provider failed at /custom/internal secret directory` used to become `Provider failed at <path>` it now ships verbatim. The #12506 boundary guard caught it. Two candidate fixes were tried and each breaks one of the two live contracts — #12506's fail-closed swallow, or #13144's rule that a route in prose must survive — so the choice is the owner's (#14110). The one contested assertion is suspended inline with the exact line and the issue; the other nine stay active. The isolated-child harness requires tests == pass, which is why it is a comment and not a todo. The free-tier budget card was one wave behind again (491 -> 489 models). Refs #13866, #14110
#13957 typed the mock global as `typeof globalThis & Record<string, unknown>`. The api-route typecheck loads lib.dom, so that intersection carries the real Window / HTMLCanvasElement / document signatures — every stub assignment fails against a DOM constructor, and `delete g.window` narrows the object to `never` (13 diagnostics, the API Route Typecheck base-red on the tip). The function exists to overwrite those globals with stubs; it is now typed as the plain record it manipulates. 29/29 tinycms tests unchanged. Refs #13866
…e-v3.8.51-basereds-0918
This was referenced Sep 19, 2026
mario03690
added a commit
to mario03690/OmniRoute
that referenced
this pull request
Sep 19, 2026
…iegosouzapw#14101) Resolves the gateways.ts baseline entry (1520 -> 1539, +19 data lines for the ainetcafe gateway entry) against the 2026-09-18 merge-train rebaseline.
diegosouzapw
added a commit
that referenced
this pull request
Sep 22, 2026
…ll, TS2677, ESLint (Refs #13866) (#14331) * fix(build): ship httpClientAbortGuard.mjs in the pack artifact; validate input_tokens with Zod Wave five of the release/v3.8.51 base-reds, part 1 — the two that matter. #14064 restored server-ws.mjs's import of ./httpClientAbortGuard.mjs and the assembleStandalone copy, but not the two pack-artifact policy entries that were lost with it. Without APP_STAGING_ALLOWED_EXACT_PATHS the prepublish prune deletes the file; without PACK_ARTIFACT_REQUIRED_PATHS nothing notices. Every boot of the published package would die with ERR_MODULE_NOT_FOUND — the 3.8.47 head-response-guard class. Both closure suites (9/9) now enforce it. #13910's /v1/responses/input_tokens read request.json() behind a hand-rolled typeof check. Hard Rule #7 wants the boundary on Zod; the t06 guard caught it. Same passthrough envelope the catch-all Responses route uses, since the counters below already walk the fields defensively. 9/9 on the route's suite. Five no-unused-vars left behind by the wave (cliRuntime execFileSync, arena test symbols and a type, compression rmSync, waitForServer req) are removed. The 'openwa routes removed without deprecation' entry from the #14101 run was an artifact of that PR trailing its base — the gate is clean on the tip. Refs #13866 * fix(compression): let anchored file-pack rules see the transformed text; align wave-5 guards Wave five of the release/v3.8.51 base-reds, part 2. One production defect. #12825 (Hungarian Caveman pack) stopped gating file-pack rules with the English keyword list and tested the rule's own regex instead — against `lowerResult`, a lower-cased copy of the ORIGINAL text that the loop never refreshed. An anchored pattern like leader_phrases' `^(?:i will|…)` therefore ran its prefilter on "sure, i will…", failed the anchor, and was skipped; the rule that strips "I will " from every English response was dead since the merge. The prefilter now sees the text as the rules so far have left it. New test fails on the tip and passes here; all Caveman suites, Hungarian included, are 95/95. A frozen no-unused-vars suppression on caveman.ts no longer had a target and is pruned. Two more TS2677 predicates of the kind #14101 fixed: #13910 (rerankProviderNodes.ts, `n is RerankProviderNodeRow` on a Record row) and #13957's mitm catalog (antigravity.ts, `c is DynamicCatalogModel` on a literal-or-null). Both narrow by NonNullable of the element's own type; the api-route typecheck was 285 against a baseline of 283 on the pristine tip. The rest are guards trailing legitimate changes: - #12663 made gemini-3.8-flash the catalog head; T28 pinned 3.7. - #13863 put mimo-v2.5 into the shared vision heuristic on purpose (the base model is multimodal, only the Pro variants are text-only). The safety test now asserts the real invariant: base and :free aliases yes, -pro no. - #12565 moved npm-prefix detection into cliRuntimeNpmPrefix.ts with a process-lifetime cache that importFresh() does not reset; the case resets it. #12565 also builds Windows candidates with path.win32 on purpose; the qodercli test compared against POSIX path.join. - #13990 (the 2 GB Docker image) copies better-sqlite3 with --chown; the guard matched the flag order literally. Now flag-order tolerant, still fails when --from=builder is removed. - #13378 reintroduced public/openference.svg under a name #11750 retired for missing provenance and swapped the Cerebras showcase cell for it. The cell is back and the asset is gone; whether the new drawing counts as provenance is the owner's call. Refs #13866 * fix(i18n): translate the 7 sidebar-pin and Claude low-priority keys into all 65 locales #7f1b4a5e (sidebar pinned items) and #1b2349de (Claude OAuth lower-priority / auto-reset) landed with their 7 new keys in en.json only, which the vi and pt-BR parity suites flag. Translated with the repo's own sync-ui-keys --translate-markers against the .113 i18n instance (codex/gpt-5.6-sol-low): +446 lines across 65 catalogs, zero __MISSING__ markers, placeholders intact. vi.json also has two keys reordered to mirror en.json; values unchanged. Refs #13866 * chore(quality): list the 8 covering tests the sixth wave added in stryker tap.testFiles 30 commits landed on release/v3.8.51 while wave five drained; eight new unit tests cover mutated modules and were not in tap.testFiles, so their mutant kills did not count and check:mutation-test-coverage --strict failed on the merged tree. Appended at the end of the list, nothing reordered. Refs #13866 * docs: document the five env vars of the 09-18 wave; regenerate the version-manager skill for the open-wa routes check:docs-all: BRIDGE_PORT, ROUTER_URL and CERT_DIR (bin/antigravity-bridge.mjs, #c74cea3d), OPENWA_SERVICE_PORT (src/lib/services/bootstrap.ts, #1e8c913c) and NEXT_PUBLIC_PORT (src/shared/hooks/useDisplayBaseUrl.ts, #d715190b) were read in code but absent from .env.example and docs/reference/ENVIRONMENT.md. Added next to their neighbours, with the defaults the code actually uses (open-wa is 8323, not the 201xx range the other services sit in). check:agent-skills-sync: the open-wa feature added eight /api/services/openwa/* routes to docs/openapi.yaml without regenerating skills/omni-version-manager/ SKILL.md. Regenerated with the repo generator; the diff is exactly those eight route sections. Refs #13866 * test: register the crash guard in the pack snapshot; inventory #13874's refresh-lane row read pack-artifact-policy pins the list of root runtime files check:pack-artifact must find in the tarball; dist/httpClientAbortGuard.mjs joined PACK_ARTIFACT_REQUIRED_PATHS in this PR and the snapshot follows. #13874 re-reads the connection row inside the Claude refresh lane so a queued health check does not POST a refresh token a Layer 2 refresh already rotated — a state read, inventoried like the family-cooldown lookup (tokenHealthCheck.ts 2 -> 3). Refs #13866 * chore(quality): list native-codex-auto-resume test in stryker tap.testFiles (#13180 landed without it) * fix(release): drain the seventh base-red wave of release/v3.8.51 (9 tests + pack-policy + dashboard-typecheck) Three production defects the tests caught: - rateLimitManager: maxWaitMs=0 (the #12902 disable sentinel) hit #12715's queue-budget gate as "0 ms left" and 503'd every protected request. - emergencyFallback: #14006 silently switched the budget-exhaustion target provider nvidia -> groq against ENVIRONMENT.md and the NIM snapshot; restored. - claudeConnectionFields.ts vs ClaudeConnectionFields.tsx (#13074) differed only by casing; helpers renamed to claudeConnectionFieldValues.ts. Guards realigned to legitimate changes: #13874 rotation map (distinct token in the error test), #13350 origin-IP denylist, #13318 shared-catalog growth (counts by invariant), comboTargetKeyPolicy import in the telegram stub, the 22 README mirrors that #13940/#14106 stamped with the retired openference.svg (translated Cerebras cells recovered from history, hashes re-stamped), bin/antigravity-bridge.mjs allowed in the pack policy, and the two dashboard typecheck regressions (typed pinned section, ComponentProps cast). Refs #13866. * test: type the #13848 Gemini pairing tests (no-explicit-any) and inventory the semantic-cache embedding picker's connection read Both arrived with the tip merge: #13848 added 13 explicit any casts to translator-openai-to-gemini.test.ts (no-explicit-any is an error under tests/), and 7a92129's embeddingOptions.ts reads provider connections once without a hard-session-lease inventory entry. Stale suppression count pruned for the test file only. Refs #13866. * test: split the #13848 turn-pairing cases out of translator-openai-to-gemini.test.ts The file sits exactly at its frozen size cap; typing the pairing tests (no-explicit-any) pushed it 14 lines over. The two cases are a coherent regression suite of their own, so they move to translator-openai-to-gemini-turn-pairing-13848.test.ts (registered in stryker tap.testFiles) instead of widening the baseline. * docs(env): document BRIDGE_PORT, ROUTER_URL, CERT_DIR, OPENWA_SERVICE_PORT and NEXT_PUBLIC_PORT (Refs #13866) check:env-doc-sync has been red on the release tip since these five vars reached code without their .env.example / ENVIRONMENT.md entries: bin/antigravity-bridge.mjs (BRIDGE_PORT, ROUTER_URL, CERT_DIR — #14006), src/lib/services/bootstrap.ts + api/services/openwa/_lib.ts (OPENWA_SERVICE_PORT) and src/shared/hooks/useDisplayBaseUrl.ts (NEXT_PUBLIC_PORT — #13533). Defaults and source files copied from the reads themselves. * chore(skills): regenerate omni-version-manager for the open-wa service routes (Refs #13866) check:agent-skills-sync (Merge integrity job) has been red on the tip since the open-wa embedded-service routes reached docs/openapi.yaml without the generated SKILL.md being refreshed. Output of scripts/skills/generate-agent-skills.mjs --apply, no hand edits: the eight /api/services/openwa/* operations. * fix(types): make the two TS2677 type predicates sound (Refs #13866) check:api-typecheck has been red on the tip with two "type predicate's type must be assignable to its parameter's type" errors: - src/app/api/v1/_shared/rerankProviderNodes.ts (#13733): the read cache hands back `Record<string, unknown> | null`, and an interface whose members are all optional is not assignable to an index-signature type. Narrow to the non-null record and assert the row shape afterwards. - src/mitm/handlers/antigravity.ts (#14006): the map callback returned `{ displayName: string }` while DynamicCatalogModel declares it optional, so the predicate could not be proven. Type the callback's return explicitly and filter on `!== null`. No runtime change; rerank-remote-provider-nodes / rerank-local-node-shapes / mitm-handler-antigravity stay green. * fix(lint): clear the 92 ESLint errors the lint gate reports on the tip (Refs #13866) - tests/unit/translator-openai-to-gemini.test.ts: #13848 / #13318 added 13 `any` casts/params on top of the 74 frozen for the file, so ESLint reported all 87. Typed them (GeminiRequestWithContents / GeminiToolPart, and the existing GeminiRequestWithConfig) and pruned the file's suppression to the new count of 71 — nothing else in eslint-suppressions.json changes. - no-unused-vars: execFileSync import (src/shared/services/cliRuntime.ts, #12565), getArenaEloSyncStatus + makeLeaderboardMap + ArenaLeaderboardMap (tests/unit/arena-elo-sync-redesign.test.ts, #13446), rmSync (compressionAnalyticsWriterFlatRate.test.ts, #13446), `req` → `_req` (waitForServer-slow-first-response.test.mjs). translator-openai-to-gemini 48/48; arena-elo-sync-redesign, compressionAnalyticsWriterFlatRate, waitForServer-slow-first-response green. * fix(compression): stop skipping anchored Caveman rules that only match after earlier rules #12825 (Hungarian pack) replaced the English keyword prefilter with a `rule.pattern.test(lowerText)` pre-check for every file-based rule, including the default `en` pack. `lowerText` is the ORIGINAL message, so anchored rules such as `leader_phrases` (`^i will …`) — which only match after `pleasantries` strips "Sure, " — were dropped before they could run. `caveman-v379` caught the regression ("I will ensure …" survived at full intensity). Tag file-based rules with their pack language in ruleLoader and let the keyword prefilter apply to `en`/built-in rules only; non-English packs (which reuse English rule names) simply run their localized regex, which is what the pre-test cost anyway. Drops the now-unused CAVEMAN_RULES import and prunes the already-stale `caveman.ts` no-unused-vars suppression (0 violations on the tip) that blocked the pre-commit hook for any change to this file. Refs #13866 * test(models): align catalog and vision-heuristic guards with the tip's intended contracts Three base-reds where the production change was deliberate and the pinned guard was simply not bumped by the PR that changed the contract: - agy-antigravity-shared-catalog-12724: #13318 added the three Gemini 3.8 Flash tiers (high/medium/low, no "-tiered" endpoint for 3.8) to the shared Antigravity/AGY base, 10 -> 13. Pin the new size in one constant and make the buildSurfaceCatalog delta assertions relative to it. - t28-model-catalog-updates: #12663 (issue #12638) registered gemini-3.8-flash at the head of the AI Studio fallback catalog as the current Flash default; assert 3.8 first and keep 3.7 present. - command-code-mimo-v2-5-safety: #13863 (issue #13847) added an explicit "mimo-v2.5" fragment to the shared vision heuristic so provider-qualified and `-free` aliases keep their vision flag. The guard's real concern (the "mimo-vl" fragment must not cover "mimo-v2.5") is asserted on the fragment itself; the bare id is now vision by heuristic on purpose, and the Pro text-only sibling stays excluded. Refs #13866 * test(cli): follow the #12565 cliRuntime module split in the npm-prefix and qodercli guards #12565 (issue #12563) moved the npm global-prefix cache out of cliRuntime.ts into cliRuntimeNpmPrefix.ts and built the Windows known-bin candidates with `path.win32` (cliRuntimeWindowsNode.ts) so they stay Windows-shaped when `process.platform` is mocked on a POSIX runner. Two pre-existing guards depended on the old layout: - cli-runtime-extended "resolves known binaries from npm global prefix": importFresh() only re-evaluates cliRuntime.ts; the prefix cache now lives in a module that stays shared across cases, so a real `npm config get prefix` from an earlier case was cached and the mocked execFileSync never ran. Reset the cache with the helper #12565 exported for exactly this in afterEach. - qodercli-windows-resolve-6263: compare against `path.win32.join` — identical to `path.join` on a real Windows host, which is the behaviour under test. Production behaviour is unchanged on both platforms. Refs #13866 * test(auto-update): write the source-mode log inside the test's own temp dir The launchAutoUpdate case pointed AUTO_UPDATE_LOG_PATH at a fixed, world-shared `/tmp/auto-update-source.log`. On the .113 runner the suite executes both as `root` and as `runner` (uid 1001): the file survives owned by whoever ran first (`-rw-r--r-- root root`), and the next `openSync(logPath, "a")` fails with EACCES for the other user. Reproduced locally by making the shared file read-only; production code is untouched (autoUpdate.ts last changed in #9354). Use a per-test mkdtemp path for the source-mode log and clean the whole temp root in the existing finally block. Refs #13866 * fix(dashboard): rename claudeConnectionFields.ts so it no longer case-collides with ClaudeConnectionFields.tsx #13074 added two modules to the provider-detail modals directory whose names differ only by casing: `ClaudeConnectionFields.tsx` (the component) and `claudeConnectionFields.ts` (the value/patch helpers). On a case-insensitive filesystem the pair breaks the webpack build (#6584 guard), and esbuild's resolver already picks the `.tsx` for the extension-less `./claudeConnectionFields` specifier, so the provider-detail client entry failed to bundle ("No matching export ... for import claudeConnectionFieldPatch"). Rename the helper module to `claudeConnectionFieldValues.ts` (the same naming the sibling `quotaScrapingFieldValues.ts` uses) and point the only importer, EditConnectionModal.tsx, at the new name. Greens tests/unit/case-collision-6584.test.ts and tests/unit/media-page-client-browser-bundle.test.ts. Refs #13866 * fix(build): allowlist dist/httpClientAbortGuard.mjs so the published tarball keeps the server-ws crash guard #14064 (re-land of #13636) made scripts/dev/standalone-server-ws.mjs import ./httpClientAbortGuard.mjs and taught assembleStandalone to copy the shared implementation next to dist/server-ws.mjs — but never registered the file in scripts/build/pack-artifact-policy.ts. The prepublish prune deletes anything outside APP_STAGING_ALLOWED_EXACT_PATHS, and check:pack-artifact only fails on PACK_ARTIFACT_REQUIRED_PATHS entries, so the next `omniroute` tarball would boot straight into ERR_MODULE_NOT_FOUND (the #7065 / tls-options class the closure tests exist to catch). Add the bare and dist/ entries to both lists and extend the required-paths snapshot in tests/unit/pack-artifact-policy.test.ts. Greens tests/unit/pack-artifact-entrypoint-closures.test.ts and tests/unit/pack-artifact-server-ws-closure.test.ts. Refs #13866 * test(docker): accept --chown=node:node on the better-sqlite3 runner COPY #14010 deliberately changed the runner-stage COPYs to `COPY --chown=node:node --from=builder ...` (ownership at copy time instead of a second ~2 GB `chown -R` overlay layer). The Dockerfile contract test still matched the old `COPY --from=builder /app/node_modules/better-sqlite3` prefix and went red on the tip even though the native-addon guard it protects is intact. Tolerate the optional --chown flag; every other assertion (node-gyp rebuild, both `test -f .../better_sqlite3.node` checks) is unchanged. Refs #13866 * fix(api): validate /v1/responses/input_tokens bodies with Zod (t06) #13167 added the local Responses token-count route with hand-rolled `typeof` checks on `request.json()`. Hard Rule #7 and the t06 gate (scripts/check/check-route-validation.mjs, mirrored by tests/unit/route-body-validation-t06.test.ts) require every route that reads request.json() to go through validateBody()/safeParse(), so the tip was red. Add `v1ResponsesInputTokensSchema` (pins the wire types the counter reads — model/instructions strings, input string-or-array, tools array — and lets unknown keys through since they are counted, never forwarded) and run the body through validateBody(); a type mismatch is now a 400 naming the field instead of a silently ignored key. Regression test added to tests/unit/responses-input-tokens-local-route.test.ts. Refs #13866 * fix(docs): drop the retired openference.svg asset reintroduced by #13378 `openference.svg` is one of the 78 provider assets retired for missing provenance (tests/unit/provider-assets-generic-fallback.test.mjs freezes that list and forbids any tracked surface from referencing a retired name). #13378 added a new hand-drawn `public/openference.svg` outside the manifest-audited public/providers/ tree and pointed the README free-tier table (plus the 22 i18n mirrors that carry the row) at it, which put the retired name back on a tracked surface and left an unaudited asset in the package. Use the generic fallback icon (`public/providers/cli-generic.svg`) the other provenance-less providers already use, delete the unaudited file, and adopt the mechanical README edit into .i18n-state.json (`i18n:run -- --adopt --files=README.md`, no API calls) so the i18n drift gate does not flag README.md as source-changed. Refs #13866 * test(lease): classify the two connection-query sites added by #14159 and #13874 The hard-lease bypass inventory froze every getProviderConnections / getProviderConnectionById site with a class; two landed on the tip without a golden update: - src/app/api/settings/cache-config/embeddingOptions.ts (#14159, re-land of #12630): read-only listing that feeds the semantic-cache embedding dropdown, same shape as the qdrant embedding-models route — class C. - src/lib/tokenHealthCheck.ts 2 -> 3 (#13874): re-reads the row by id after an unrecoverable refresh error to detect credentials rotated by a concurrent Layer 2 refresh before deactivating — a state read, not dispatch; stays C. Refs #13866 * fix(sse): restore nvidia as the emergency budget-fallback provider #14006 (Antigravity MITM catalog injection) flipped EMERGENCY_FALLBACK_CONFIG.provider from "nvidia" to "groq" in one line, without touching ENVIRONMENT.md, .env.example, the chat.ts comment or the NVIDIA hosted-model snapshot, all of which still promise nvidia/openai/gpt-oss-120b. Operators without a Groq connection got the original 402 back instead of the free reroute, and chat-route-coverage ("uses the emergency fallback model on budget exhaustion" / "returns the primary budget error when emergency fallback also fails") went red on the tip. Put the documented default back; the #14006 bridge tests exercise bin/antigravity-bridge.mjs and do not read this config. Refs #13866 * fix(resilience): keep maxWaitMs=0 a "no queue deadline" sentinel #12902 released requestQueue.maxWaitMs=0 as the sentinel that disables the queue-wait deadline, but the #12715 queue-budget gate in withRateLimit() (`if (queueRemainingMs <= 0) throw`) read 0 as "budget spent" and rejected every request on a protected connection with an immediate 503 queue-budget error — the exact opposite of what the setting promises. rate-limit-maxwaitms-disable-execution ("400ms job completes without 504") was red on the tip. When no caller budget is passed and the configured queue budget is 0, skip the gate, never arm the queue-wait timer and hand awaitProviderDefaultSlot no budget (it falls back to the window). Execution stays bounded by executionMaxWaitMs and the upstream fetch-start timeout, as before. Refs #13866 * test: align three fixtures with the #13874, #13861 and #13350 contracts Three base-reds that are deliberate contract changes, not defects: - executor-default-base "refreshCredentials swallows refresh errors": #13874 records rotations on the Layer 2 (no connectionId) refresh path too, so the "refresh-me" token the previous case already rotated was served from the rotation map without the network POST the test wanted to fail. Use a token nobody rotated. - telegram-keycache-bounded-13165: #13861 made comboTargetKeyPolicy import isModelBlockedByPatterns from db/apiKeys; the loader-stubbed module lacked it and the suite died at module load. Export an honest "not blocked" stub (the test has no blocked models). - upstream-headers-proxy-auth "ordinary headers are still allowed": #13350 forbids the whole origin-IP forwarding set upstream (covered by upstream-headers-sanitize). Swap x-forwarded-for for x-request-id. Refs #13866
muhamadgalihsaputra
pushed a commit
to niyatna/NiyatnaRoute
that referenced
this pull request
Sep 27, 2026
…the write, drain the 09-18 base-reds (diegosouzapw#14101) * fix(quality): drain the 09-18 base-reds, part 1 — thinking gate parity, inventory, webpack externals Reproduced on the clean tip 7784784 before touching anything. Five of the failures trace to one commit, diegosouzapw#12905 (8b5f4dd): it gated thinking-block emission on `requestedThinking === true` in the streaming translator, while its own non-streaming path documents `undefined` as the legacy caller shape that keeps "always a thinking block". The two paths disagreed on the same input, and the streaming side also synthesized the reasoning into a TEXT block for that legacy shape. chatCore always resolves a boolean, so production never sends `undefined` — but every direct caller and the older diegosouzapw#5786 suites do. Aligned the streaming gate to the documented tri-state: `false` suppresses, `true` and `undefined` relay, and the fix-B text synthesis fires only on an explicit opt-out. The diegosouzapw#12905 test that asserted suppression used a bare createState() (`undefined`) to mean "client did not request thinking"; it now passes `requestedThinking: false`, which is what that sentence resolves to in production. The whole thinking family — dsml, adapter, translator, non-stream parity, diegosouzapw#13620, diegosouzapw#5786, markdown boundary — is 77/77. diegosouzapw#12864 added requestRejectedFailure.ts with a getProviderConnectionById read that seeds the refusal streak across restarts; inventoried as a connection state read next to the family-cooldown site it resembles. diegosouzapw#13909 made machineToken.ts import ./dataPaths; the isolated webpack compile has no repo tree, so it joins the sibling externals. The free-tier budget card SVG was one wave behind again (482 -> 491 models). Refs diegosouzapw#13866 * fix(sse): restore maxQueueDepth=0 as unbounded, sanitize refusals at the write, drain the rest Part 2 of the 09-18 base-red drain. Two of the remaining failures were not stale tests but production defects the tests had caught. diegosouzapw#12911 taught accountSemaphore to read `maxQueueSize: 0` as "reject when the slot is busy", which is what its Codex WS lease wants. But chatCore forwards `resilienceSettings.requestQueue.maxQueueDepth` into that option, and that setting's documented default since diegosouzapw#6593 is `0 = disabled`. Under default settings every request that found its account slot occupied was answered 429 "Semaphore queue full (0)" instead of waiting — the managed-lease routing test saw exactly that. `0` (and any non-positive value) is unbounded again; the lease gets an explicit `failFast` option and its four tests stay green, so the diegosouzapw#12911 behaviour is preserved where it was meant to apply. A contract test pins the diegosouzapw#6593 semantics on the semaphore itself. diegosouzapw#12864 moved two providerFailure persistence branches out of chatCore into requestRejectedFailure.ts and the sanitization did not travel with them: three `lastError` writes stored the message as received. The only caller already hands in the projected persistentMessage, so nothing leaks today, but a persistence branch must be safe at its own write (docs/security/ ERROR_SANITIZATION.md) rather than trust whoever calls it. The module now sanitizes on entry, and the public-boundary guard — which caught this by counting sanitized writes in chatCore and coming up two short — covers the extracted module too, verified by mutating one write back to raw. The rest are tests that had fallen behind legitimate changes: - diegosouzapw#12905 inserted `requestedThinking` as the 14th positional argument of createSSETransformStreamWithLogger; two tests passed customToolNames or the buffer budget at their old positions. Both production callers were already correct. - diegosouzapw#12754 added a per-connection reset-card fetch after the quota fetch; the spacing test now marks a chunk at the quota request only. - diegosouzapw#13910 renamed `error` to `errorMetadata` in the timeout classification; the probe matches the identifier with a backreference and still fails when BodyTimeoutError is removed from both sites. Refs diegosouzapw#13866 * fix(test): pin the opt-out thinking cases to requestedThinking=false; keep acquireMany under the complexity ceiling The diegosouzapw#12905 gate-restore suite encoded 'requestedThinking absent' as opt-out, the same undefined-means-false shape its non-streaming twin documents the other way and that the two-month-old diegosouzapw#5786 suites contradict. The three opt-out cases now set the flag explicitly, which is what chatCore resolves for an opted-out client; the two opt-in cases already did. Both suites pass together (27/27). The failFast branch pushed acquireMany over the complexity ceiling it already sat on; the admission policy (fail-fast / bounded / unbounded queue) moves to findQueueRejection() and the new-code ratchet is back at its base. Refs diegosouzapw#13866 * fix(test): suspend the diegosouzapw#14110 redaction assertion inline; refresh the budget card The 57 commits merged since the previous validation moved two things. diegosouzapw#13295 changed how an unknown-root path with an ambiguous tail is answered: where `Provider failed at /custom/internal secret directory` used to become `Provider failed at <path>` it now ships verbatim. The diegosouzapw#12506 boundary guard caught it. Two candidate fixes were tried and each breaks one of the two live contracts — diegosouzapw#12506's fail-closed swallow, or diegosouzapw#13144's rule that a route in prose must survive — so the choice is the owner's (diegosouzapw#14110). The one contested assertion is suspended inline with the exact line and the issue; the other nine stay active. The isolated-child harness requires tests == pass, which is why it is a comment and not a todo. The free-tier budget card was one wave behind again (491 -> 489 models). Refs diegosouzapw#13866, diegosouzapw#14110 * fix(providers): type the TinyCMS DOM stub global as a loose record diegosouzapw#13957 typed the mock global as `typeof globalThis & Record<string, unknown>`. The api-route typecheck loads lib.dom, so that intersection carries the real Window / HTMLCanvasElement / document signatures — every stub assignment fails against a DOM constructor, and `delete g.window` narrows the object to `never` (13 diagnostics, the API Route Typecheck base-red on the tip). The function exists to overwrite those globals with stubs; it is now typed as the plain record it manipulates. 29/29 tinycms tests unchanged. Refs diegosouzapw#13866 * fix(test): pin the last opt-out thinking sibling to requestedThinking=false translator-reasoning-gate-502-repro is the third diegosouzapw#12905 test that encoded a bare state as opt-out; the previous sweep matched files by glob and missed it. The family is now enumerated by grep on requestedThinking (7 files) plus the two pre-diegosouzapw#12905 suites: 83/83 together. Refs diegosouzapw#13866
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Drena os base-reds de
release/v3.8.51reabertos em #13866 — 12 testes nos 4 shards doUnit Tests fast-path, todos reproduzidos no tip puro7cc454d9(que é a própria PR #14082, "repair the unit-test base-reds left by the merge wave") e idênticos entre PRs de conteúdo disjunto antes de qualquer alteração.Dois dos doze não eram testes velhos — eram defeitos de produção que os testes pegaram.
Regressão de produção:
maxQueueDepth = 0virou "rejeitar"resilienceSettings.requestQueue.maxQueueDepthtem o default documentado desde #6593 como0 = disabled(fila sem limite), echatCorerepassa esse valor direto comomaxQueueSizedo semáforo de conta. O #12911 redefiniu0dentro deaccountSemaphorecomo "rejeitar se o slot estiver ocupado" — o que o lease WS do Codex quer.Efeito: sob configuração padrão, toda request que encontrava o slot de conta ocupado recebia
429 Semaphore queue full (0)em vez de esperar. Reproduzido com o teste de roteamento de lease gerenciado, que capturou exatamente esse corpo.Correção:
0(e qualquer valor não-positivo) volta a ser ilimitado; o lease recebe uma opção explícitafailFast. Os 4 testes do #12911 continuam verdes — a intenção dele está preservada onde deveria valer. Um teste de contrato fixa a semântica #6593 no próprio semáforo.Segurança: sanitização não acompanhou a extração
O #12864 moveu dois branches de persistência de
providerFailuredochatCorepararequestRejectedFailure.ts, e a sanitização ficou para trás: três writes delastErrorgravavam a mensagem como recebida. Hoje não vaza porque o único caller já passapersistentMessage, mas um branch de persistência tem que ser seguro no próprio ponto de escrita (docs/security/ERROR_SANITIZATION.md), não confiar em quem chama.O guard de fronteira pública pegou isso por contagem (esperava ≥11 writes sanitizados no
chatCore, achou 9). O módulo agora sanitiza na entrada e o guard cobre o módulo extraído — provado por mutação (voltando um write a cru, cai).Divergência interna do #12905 sobre thinking
O streaming (
openai-to-claude.ts) só emitia thinking block comrequestedThinking === true; o non-streaming (responseTranslator.ts), do mesmo commit, documentaundefinedcomo "caller legado, sempre retransmite". Os dois caminhos discordavam sobre o mesmo input, e o streaming ainda jogava o reasoning como texto para o caso legado. Em produçãochatCoresempre resolve boolean, então isso só atingia callers diretos e as suítes #5786 — mas eram três falhas.Alinhado ao tri-estado documentado:
falsesuprime,trueeundefinedretransmitem, e a síntese de texto do fix-B só dispara no opt-out explícito. O teste do #12905 que afirmava supressão usavacreateState()vazio (undefined) para significar "cliente não pediu"; passa a usarrequestedThinking: false, que é o que essa frase vira em produção. A família inteira de thinking — dsml, adapter, translator, paridade non-stream, #13620, #5786, markdown boundary — está 77/77.Testes que ficaram para trás de mudanças legítimas
requestedThinkingcomo 14º posicional decreateSSETransformStreamWithLoggererror→errorMetadatana classificação de timeoutBodyTimeoutErrorsai dos dois sitesmachineToken.tsimporta./dataPathsValidação
npm run typecheck:coreconfig/quality/eslint-suppressions.jsonNenhuma asserção foi removida ou enfraquecida; os três guards reescritos foram provados por mutação.
Refs #13866.
2af688a9with no changes, and every item is in code this PR does not touch (Vietnamese locale, caveman, cliRuntime Windows, pack-artifact, openwa routes, 5 unused-var warnings). Inventory in the #13866 comment. Not chasing a fifth wave inside this PR: it already carries 15 resolved causes incl. the #12911 and #12864 production defects.