Skip to content

fix(compression,build,api): revive anchored Caveman rules, ship the crash guard, drain the wave-5 base-reds - #14164

Merged
diegosouzapw merged 13 commits into
release/v3.8.51from
fix/release-v3.8.51-basereds-0919
Sep 21, 2026
Merged

diegosouzapw merged 13 commits into
release/v3.8.51from
fix/release-v3.8.51-basereds-0919

Conversation

@diegosouzapw

@diegosouzapw diegosouzapw commented Sep 19, 2026 •

Copy link
Copy Markdown
Owner

Drena a quinta onda de base-reds de release/v3.8.51 (#13866) — 16 testes + os gates No new ESLint warnings e mutation-test-coverage — mais a sexta que chegou durante a drenagem (30 commits). Tudo reproduzido no tip puro antes de qualquer alteração; 7/7 amostrados falharam em 2af688a9 e os 2 TS2677 em f6bafe4b.

Uma regressão de produção

#12825 (pack húngaro do Caveman) matou a regra leader_phrases de todo o inglês. O commit trocou o prefilter por palavra-chave das regras de arquivo por um teste do próprio regex da regra — contra lowerResult, uma cópia em minúsculas do texto original que o laço nunca atualizava. Um padrão ancorado como ^(?:i will|…) rodava o prefilter sobre "sure, i will…", falhava a âncora e era pulado antes de ver o texto que pleasantries já tinha limpado. Teste novo falha no tip e passa aqui; todas as suítes Caveman, húngaro incluído, 95/95.

Um buraco de empacotamento

#14064 restaurou o crash guard, mas não as duas entradas de política do pack-artifact. Sem APP_STAGING_ALLOWED_EXACT_PATHS o prepublish apaga httpClientAbortGuard.mjs; sem PACK_ARTIFACT_REQUIRED_PATHS nada percebe. Todo boot do pacote publicado morreria com ERR_MODULE_NOT_FOUND — a classe do incidente 3.8.47 (head-response-guard). Os dois closure suites (9/9) agora exigem.

Segurança e tipos

Guards que ficaram para trás de mudanças legítimas

Causa Testes Ajuste
#12663 fez gemini-3.8-flash a cabeça do catálogo 1 T28 fixava 3.7
#13863 pôs mimo-v2.5 na heurística de visão (base é multimodal; só o Pro é text-only) 1 afirma o invariante real: base e :free sim, -pro não
#12565 extraiu getNpmGlobalPrefix para módulo próprio com cache de processo 1 importFresh() não reseta; o caso reseta o cache
#12565 monta caminhos Windows com path.win32 deliberadamente 1 teste comparava com path.join POSIX
#13990 (imagem Docker de 2 GB) copia better-sqlite3 com --chown 1 guard tolerante à ordem das flags; cai sem --from=builder (mutação)
5 no-unused-vars da onda gate imports/símbolos mortos removidos; supressão congelada obsoleta em caveman.ts podada
8 testes novos fora de tap.testFiles gate acrescentados ao fim da lista
#13180 (cd4c6f69, sétima onda) entrou com native-codex-auto-resume.test.ts fora de tap.testFiles gate acrescentado

Falso item: as "4 rotas POST /api/services/openwa/* removidas sem deprecação" do CI da #14101 eram artefato daquela PR estar atrás da base — check-openapi-breaking dá 0 breaking no tip.

i18n — 7 chaves × 65 locales

#7f1b4a5e (sidebar pinned) e #1b2349de (Claude low-priority) entraram só em en.json. A sessão do i18n-mirror-refresh (b61ff773) traduziu as mesmas 7 chaves em paralelo; no merge fiquei com a redação que já está na base — 0 locales sem as chaves, 0 __MISSING__. Traduzidas com o sync-ui-keys --translate-markers do repositório contra a instância i18n da .113 (codex/gpt-5.6-sol-low, ~4 s/request): +446 linhas, zero __MISSING__, placeholders intactos. Amostras: he "הצמד פריט", ja "項目をピン留めする", ne "वस्तु पिन गर्नुहोस्".

A .113 estava há 7 dias presa em 503 resource_pressure com host ocioso — reiniciada pelo procedimento documentado (achar pelo socket, kill, nohup setsid).

Sétima onda (tip 7a921299, chegou durante a drenagem — 9 testes + 2 gates, todos reproduzidos no tip puro)

Três defeitos de produção de novo:

Causa Testes/gates Ajuste
#13874 passou a registrar rotações de refresh também na lane sem connectionId 1 teste de erro usa token próprio, não reapresenta o já consumido
#13350 proíbe x-forwarded-for & cia upstream (endurecimento deliberado) 1 guard troca o exemplo "ordinário" e fixa a denylist de IP
#13318 cresceu a base compartilhada agy/antigravity (10 → 13) 4 contagens relativas a ANTIGRAVITY_SHARED_MODELS.length
2f6b5b18 importa isModelBlockedByPatterns em comboTargetKeyPolicy 1 stub de db/apiKeys do teste do telegram alinhado
#13940/#14106 espelharam a célula Openference em 22 READMEs 1 célula Cerebras traduzida recuperada do histórico de cada espelho (el localizado à mão); hashes re-carimbados no .i18n-state.json
#14006 criou bin/antigravity-bridge.mjs sem entrada na policy gate pack-policy liberado (só node:*); nota "development only" que eu tinha escrito corrigida
#13074 seção "pinned" sintetizada sem tipo; {...(x as never)} no teste de proxy gate dashboard-typecheck tipada como elemento de visibleSections; cast para ComponentProps

Crédito e issues que esta PR fecha

Decisão editorial que devolvo ao dono

#13378 trocou a célula da Cerebras (1M tokens/dia) pela Openference no showcase do README e reintroduziu public/openference.svg — nome que #11750 (seu sweep de procedência) aposentou. Restaurei a célula e removi o asset; se o desenho novo conta como procedência, é decisão sua. A mesma PR também trocou "Agent Deck" (ícone genérico) por "deyin.ai" com outro SVG novo (public/deyin.svg), que o guard não cobre porque a lista é estática.

Validação (árvore mergeada com o tip 3fd1265d)

Gate Resultado
30 arquivos de teste tocados/relacionados, juntos 174 / 174
check-api-typecheck.mjs OK — 283, dentro do baseline
npm run typecheck:core limpo
check-deps, check-file-size (ambos os modos), mutation-test-coverage OK
ESLint com supressões congeladas limpo nos arquivos tocados

Nenhuma asserção removida ou enfraquecida; os guards reescritos foram provados por mutação.

Refs #13866.


⚠️ base-red inherited: #13866 — the remaining red checks are the SIXTH wave (30 commits that landed while this drained the fifth): 10/10 sampled tests and the dashboard-typecheck reproduce on the pristine tip cd4c6f69, all in code this PR does not touch (#12724 catalog, case-collision, chat budget fallback, telegram keyCache, browser-bundle, 4 no-explicit-any in translator-openai-to-gemini.test.ts, Sidebar/proxySaveRefresh typecheck). Inventory in the #13866 comment.

…ate input_tokens with Zod

Wave five of the release/v3.8.51 base-reds, part 1 — the two that matter.

#14064 restored server-ws.mjs's import of ./httpClientAbortGuard.mjs and the
assembleStandalone copy, but not the two pack-artifact policy entries that
were lost with it. Without APP_STAGING_ALLOWED_EXACT_PATHS the prepublish
prune deletes the file; without PACK_ARTIFACT_REQUIRED_PATHS nothing notices.
Every boot of the published package would die with ERR_MODULE_NOT_FOUND — the
3.8.47 head-response-guard class. Both closure suites (9/9) now enforce it.

#13910's /v1/responses/input_tokens read request.json() behind a hand-rolled
typeof check. Hard Rule #7 wants the boundary on Zod; the t06 guard caught it.
Same passthrough envelope the catch-all Responses route uses, since the
counters below already walk the fields defensively. 9/9 on the route's suite.

Five no-unused-vars left behind by the wave (cliRuntime execFileSync, arena
test symbols and a type, compression rmSync, waitForServer req) are removed.
The 'openwa routes removed without deprecation' entry from the #14101 run was
an artifact of that PR trailing its base — the gate is clean on the tip.

Refs #13866
…xt; align wave-5 guards

Wave five of the release/v3.8.51 base-reds, part 2.

One production defect. #12825 (Hungarian Caveman pack) stopped gating file-pack
rules with the English keyword list and tested the rule's own regex instead —
against `lowerResult`, a lower-cased copy of the ORIGINAL text that the loop
never refreshed. An anchored pattern like leader_phrases' `^(?:i will|…)`
therefore ran its prefilter on "sure, i will…", failed the anchor, and was
skipped; the rule that strips "I will " from every English response was dead
since the merge. The prefilter now sees the text as the rules so far have left
it. New test fails on the tip and passes here; all Caveman suites, Hungarian
included, are 95/95. A frozen no-unused-vars suppression on caveman.ts no
longer had a target and is pruned.

Two more TS2677 predicates of the kind #14101 fixed: #13910
(rerankProviderNodes.ts, `n is RerankProviderNodeRow` on a Record row) and
#13957's mitm catalog (antigravity.ts, `c is DynamicCatalogModel` on a
literal-or-null). Both narrow by NonNullable of the element's own type; the
api-route typecheck was 285 against a baseline of 283 on the pristine tip.

The rest are guards trailing legitimate changes:

- #12663 made gemini-3.8-flash the catalog head; T28 pinned 3.7.
- #13863 put mimo-v2.5 into the shared vision heuristic on purpose (the base
  model is multimodal, only the Pro variants are text-only). The safety test
  now asserts the real invariant: base and :free aliases yes, -pro no.
- #12565 moved npm-prefix detection into cliRuntimeNpmPrefix.ts with a
  process-lifetime cache that importFresh() does not reset; the case resets it.
  #12565 also builds Windows candidates with path.win32 on purpose; the qodercli
  test compared against POSIX path.join.
- #13990 (the 2 GB Docker image) copies better-sqlite3 with --chown; the guard
  matched the flag order literally. Now flag-order tolerant, still fails when
  --from=builder is removed.
- #13378 reintroduced public/openference.svg under a name #11750 retired for
  missing provenance and swapped the Cerebras showcase cell for it. The cell is
  back and the asset is gone; whether the new drawing counts as provenance is
  the owner's call.

Refs #13866
…nto all 65 locales

#7f1b4a5e (sidebar pinned items) and #1b2349de (Claude OAuth lower-priority /
auto-reset) landed with their 7 new keys in en.json only, which the vi and
pt-BR parity suites flag. Translated with the repo's own sync-ui-keys
--translate-markers against the .113 i18n instance (codex/gpt-5.6-sol-low):
+446 lines across 65 catalogs, zero __MISSING__ markers, placeholders intact.
vi.json also has two keys reordered to mirror en.json; values unchanged.

Refs #13866
…yker tap.testFiles

30 commits landed on release/v3.8.51 while wave five drained; eight new unit
tests cover mutated modules and were not in tap.testFiles, so their mutant
kills did not count and check:mutation-test-coverage --strict failed on the
merged tree. Appended at the end of the list, nothing reordered.

Refs #13866
…rsion-manager skill for the open-wa routes

check:docs-all: BRIDGE_PORT, ROUTER_URL and CERT_DIR (bin/antigravity-bridge.mjs,
#c74cea3d), OPENWA_SERVICE_PORT (src/lib/services/bootstrap.ts, #1e8c913c) and
NEXT_PUBLIC_PORT (src/shared/hooks/useDisplayBaseUrl.ts, #d715190b) were read
in code but absent from .env.example and docs/reference/ENVIRONMENT.md. Added
next to their neighbours, with the defaults the code actually uses (open-wa is
8323, not the 201xx range the other services sit in).

check:agent-skills-sync: the open-wa feature added eight /api/services/openwa/*
routes to docs/openapi.yaml without regenerating skills/omni-version-manager/
SKILL.md. Regenerated with the repo generator; the diff is exactly those eight
route sections.

Refs #13866
…s refresh-lane row read

pack-artifact-policy pins the list of root runtime files check:pack-artifact
must find in the tarball; dist/httpClientAbortGuard.mjs joined
PACK_ARTIFACT_REQUIRED_PATHS in this PR and the snapshot follows.

#13874 re-reads the connection row inside the Claude refresh lane so a queued
health check does not POST a refresh token a Layer 2 refresh already rotated —
a state read, inventoried like the family-cooldown lookup (tokenHealthCheck.ts
2 -> 3).

Refs #13866
…ests + pack-policy + dashboard-typecheck)

Three production defects the tests caught:
- rateLimitManager: maxWaitMs=0 (the #12902 disable sentinel) hit #12715's
  queue-budget gate as "0 ms left" and 503'd every protected request.
- emergencyFallback: #14006 silently switched the budget-exhaustion target
  provider nvidia -> groq against ENVIRONMENT.md and the NIM snapshot; restored.
- claudeConnectionFields.ts vs ClaudeConnectionFields.tsx (#13074) differed only
  by casing; helpers renamed to claudeConnectionFieldValues.ts.

Guards realigned to legitimate changes: #13874 rotation map (distinct token in
the error test), #13350 origin-IP denylist, #13318 shared-catalog growth
(counts by invariant), comboTargetKeyPolicy import in the telegram stub, the
22 README mirrors that #13940/#14106 stamped with the retired openference.svg
(translated Cerebras cells recovered from history, hashes re-stamped),
bin/antigravity-bridge.mjs allowed in the pack policy, and the two dashboard
typecheck regressions (typed pinned section, ComponentProps cast).

Refs #13866.
…ntory the semantic-cache embedding picker's connection read

Both arrived with the tip merge: #13848 added 13 explicit any casts to
translator-openai-to-gemini.test.ts (no-explicit-any is an error under
tests/), and 7a92129's embeddingOptions.ts reads provider connections
once without a hard-session-lease inventory entry. Stale suppression
count pruned for the test file only.

Refs #13866.
…-gemini.test.ts

The file sits exactly at its frozen size cap; typing the pairing tests
(no-explicit-any) pushed it 14 lines over. The two cases are a coherent
regression suite of their own, so they move to
translator-openai-to-gemini-turn-pairing-13848.test.ts (registered in
stryker tap.testFiles) instead of widening the baseline.
diegosouzapw added a commit that referenced this pull request Sep 21, 2026
Both branches drained the same wave of base-reds in parallel. Every file
#14164 touches is taken verbatim from its head (c02e379); this branch keeps
only what #14164 does not carry: the Zod schema for /v1/responses/input_tokens
(v1ResponsesInputTokensSchema — #14164 uses a passthrough object, which
satisfies the t06 gate but pins no wire type) with its regression test, and
the auto-update test writing its log under its own temp dir instead of
/tmp (EACCES on the .113 runner).
@diegosouzapw
diegosouzapw merged commit d610c24 into release/v3.8.51 Sep 21, 2026
31 of 32 checks passed
@diegosouzapw
diegosouzapw deleted the fix/release-v3.8.51-basereds-0919 branch September 21, 2026 19:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

fix: the 92-error ESLint base-red on release/v3.8.51 is one file losing its bulk suppression — #13848 pushed it 74→87

1 participant