Repository navigation
fix(egress): strip _omniroute* markers at shared pre-executor boundary - #14252
Merged
diegosouzapw merged 1 commit intoSep 22, 2026
Conversation
Ensure internal control markers (e.g. _omnirouteSkipContextRelay, _omnirouteInternalRequest) injected during universal/context handoff are stripped at normalizeAttemptBody before reaching any executor. Prevents leaks on custom executors that serialize request bodies independently. Includes cross-layer regression test asserting that universal handoff dispatches contain no _omniroute* keys.
Owner
|
Thanks @alfred-rootson — merging via the release merge-train. Validated in local merge-train (mt-train10c) on the devbox @ train tip 4d841aa1c740bbaa03868dc0a403c62099a99a42 with the 72 sibling PRs of this batch: typecheck:core, file-size, complexity, cognitive-complexity, changelog-integrity green; changed-area node:test 831/831 (0 failing) and vitest 480/482 — the two reds are |
diegosouzapw
added a commit
that referenced
this pull request
Sep 22, 2026
…strip #14252 added stripInternalBodyFields() at the shared pre-executor boundary so _omniroute* routing markers cannot leak upstream. The same helper also removes the four _native*Passthrough markers — but those are read INSIDE the executor (codex.ts:1259, xai.ts:130), which deletes them itself. Stripping them a layer early turned every Responses-native request into a translated one, which then lost client fields to the #2608 allowlist; 'metadata' is how it surfaced. Executor-consumed markers are now a named list the boundary keeps and the serialization strip (applyFingerprint) still removes, so the leak fix stands. Bisected to 1fb7c9d on a clean checkout. Also aligns opencode-executor's auth expectation with #14230, which routed Zen GPT-5.6 through /v1/responses where #12633's x-api-key rule applies. Refs #14496.
diegosouzapw
added a commit
that referenced
this pull request
Sep 22, 2026
#14252 ("strip _omniroute* markers at shared pre-executor boundary") wired stripInternalBodyFields() into normalizeAttemptBody(). That helper removes two classes of marker: the `_omniroute*` prefix class (consumed by routing before dispatch — the ones #14252 was actually about) AND the four keys in INTERNAL_BODY_FIELDS, which are consumed by the EXECUTORS inside transformRequest(): _nativeCodexPassthrough CodexExecutor.transformRequest _nativeXaiResponsesPassthrough XaiExecutor.transformRequest _nativeOpenAICompatibleResponsesPassthrough passthrough dispatch _claudeCodeRequiresLowercaseToolNames BaseExecutor normalizeAttemptBody() runs BEFORE transformRequest(), so every native Responses passthrough was silently demoted to the translated path: CodexExecutor no longer saw its marker, fell through to the RESPONSES_API_ALLOWLIST, and dropped the client's top-level `metadata` (plus the passthrough instructions handling). No error — just a quietly different upstream payload. Red on the release tip: "chatCore keeps Responses-native Codex payloads in native passthrough mode". Fix: split out stripInternalOmnirouteMarkers() (prefix-only) and call that at the pre-executor boundary, preserving #14252's intent. The executor-consumed markers keep being removed at the executor-egress boundary (base.ts, dario.ts, ninerouter.ts, applyFingerprint), which runs after transformRequest has read them. stripInternalBodyFields() itself is unchanged in behavior. Tests: two regressions in strip-internal-omniroute-markers.test.ts — the helper level (prefix strip keeps the executor markers) and the real boundary (prepareUpstreamBody preserves _nativeCodexPassthrough and the client metadata while still dropping _omnirouteSkipContextRelay).
This was referenced Sep 24, 2026
diegosouzapw
added a commit
that referenced
this pull request
Sep 24, 2026
Drains the base-red accumulated on release/v3.8.51 (#14496, #14547). Production fixes: auggie spawn typing, projectCombo type imports, Responses passthrough markers surviving the egress strip (#14252 regression), compression effective-pipeline preview following the runtime lossy policy (#14529 regression, #12063), CLIProxyAPI account-health host default (#14544 regression), DEEP_HEALTH_CHECK_ENABLED env contract. The remaining test guards were realigned to merged design changes, each traced to its commit; the subtitle-runtime fixtures moved to a per-run temp dir; documented file-size/stryker rebaselines absorb the 2026-09-23/24 merge-wave drift.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
Internal routing control markers (e.g.
_omnirouteSkipContextRelay,_omnirouteInternalRequest) are stamped onto internal summarizer request bodies during universal/context handoff.While
applyFingerprint()incliFingerprints.tsalready strips internal fields, executors that serialize their request bodies independently bypass that boundary, causing_omniroute*keys to reach strict-schema upstreams (e.g. Bedrock/Anthropic and OpenAI-compatible gateways) and fail with[400] Extra inputs are not permitted/Unknown parameter.This change adds
stripInternalBodyFields(bodyToSend)insidenormalizeAttemptBody()inopen-sse/handlers/chatCore/upstreamBody.ts— the shared egress boundary that all request bodies pass through before executor dispatch.Validation
tests/unit/strip-internal-omniroute-markers.test.tsextended with an end-to-end regression test drivingmaybeGenerateUniversalHandoffwith a custom-serializing executor.