Repository navigation
Conversation
|
Follow-up
Tests: |
|
Follow-up
Remaining failures are inherited from the base ( |
|
Good, minimal-footprint approach — reusing the existing |
7ba2294 to
657c49a
Compare
|
Re-homed to |
7427104 to
f307c1d
Compare
System One models (TypeSafe Jev) answer typed noul/choice/score questions about a state with calibrated probabilities instead of generating text. OpenRouter serves them at /api/v1/systemone with the TypeSafe request and response shape, so POST /v1/systemone forwards the body unchanged using the existing dashboard openrouter credentials: no new provider or key, and the TypeSafe SDKs work by pointing their base URL at OmniRoute. The call log records input/output tokens and the exact USD cost OpenRouter returns in usage.cost; upstream status and retry-after are kept on errors.
Review of the System One proxy found that API-key restrictions did not apply to it: credential selection ignored the key's allowed connections, /v1/systemone had no endpoint category (so a key limited to "models" could still call it), and bare model ids such as jev-latest bypassed deny rules written for the typesafe/ namespace OpenRouter routes them to. - register a "systemone" endpoint category and pass allowedConnections plus the canonical typesafe/<id> model to credential selection and policy - record successful calls in usage_history and charge the exact usage.cost to the API-key budget ledger - put the connection into cooldown on upstream 401/403/429/5xx, not on 422 - scan state and question instructions in the prompt-injection guard - reject an empty or non-JSON 200 body as a sanitized 502 - document the request body and bearer security in the OpenAPI spec
- type the credential union and the question map so the strict api and open-sse typechecks no longer report new errors in the systemone route and the injection-guard extractor - split the System One handler into small helpers (parse, usage, failure, success) so it adds no new cyclomatic or cognitive complexity - raise the frozen size of the generated openapi.generated.ts by the one endpoint entry the spec now emits (1347 -> 1357) - regenerate skills/omni-inference/SKILL.md, which the generator derives from docs/openapi.yaml and now lists POST /api/v1/systemone
f307c1d to
c489758
Compare
… the dashboard GET /v1/systemone/models returns the live OpenRouter decisions catalog (output_modalities=decisions) with upstream ids, names and pricing, since those models are absent from the default OpenRouter list and only work through /v1/systemone. The Endpoints page gets a System One section for the POST and GET routes, with the 13 new strings translated in all 66 locales.
Route native TypeSafe, OpenRouter and local Ollama decision models through the configured provider connection. Keep gateway-prefixed IDs unambiguous, preserve bare Jev compatibility, and never fall back from a missing direct provider to a gateway. Share typed validation while respecting backend limits, native pricing overrides, read-only catalog eligibility and model-scoped failures. Co-authored-by: Sean P. Ford <sean@seanford.com> Co-authored-by: Praveen K Palaniswamy <Praveen.Palaniswamy@gmail.com>
Combining the TypeSafe, OpenRouter and Ollama work@diegosouzapw — this PR now addresses the overlap you pointed out between the different System One PRs. Instead of choosing between TypeSafe and OpenRouter, it lets the same endpoint use either one, or a configured local Ollama server. The model name tells OmniRoute which connection to use:
If the requested connection is missing, the request fails rather than being sent somewhere else. Existing calls using Credit for the work reused:
I adapted parts of their code; I did not copy their complete commits or merge their PRs. Both authors are credited in commit The proposal is to support decision models like we support embeddings or image models: providers can offer them alongside chat, or offer only decisions. The model list shows which connection serves each model. Existing key restrictions, cost tracking and error handling still apply. The optional work that uses Jev to choose a chat model is left for separate PRs. The targeted tests pass, and the OpenRouter path has been tested on a running instance. TypeSafe and Ollama were tested with simulated responses only; I do not have the setup to claim real requests to those two passed. The full test runs still have failures, described in the PR, and translated docs are being finished. Could this be the shared starting point for the TypeSafe and Ollama PRs? I'd like to agree on the remaining work with their authors and keep everyone credited. |
Synchronize README, API and provider references in all 66 translated locales, plus the provider-count mirrors. Preserve source receipts and update hashes after formatting. No production code changes.
|
Thanks @PixmaNts, and thanks for the credit. I'm happy for #14667 to be the shared base. The Ollama pieces from #15410 are all here. I ran your branch at Worked as expected (live)
Small points
Unit tests only (not live): model discovery, @diegosouzapw — if you agree with this direction, I'll close #15410 once #14667 lands. |
Summary
Make System One a provider/model capability rather than an OpenRouter-only proxy.
Typed
noul,choiceandscorequestions use the same publicPOST /v1/systemoneoperation with native TypeSafe, OpenRouter or local Ollama.The model identity follows the ordinary gateway convention:
typesafe/jev-latestjev-latestopenrouter/typesafe/jev-1.13typesafe/jev-1.13openrouter/inception/mercury-decide:freeinception/mercury-decide:freeollama-local/clef-flashclef-flashAn unqualified SDK id such as
jev-latestretains its OpenRouter default.An unavailable explicit direct provider does not silently fall back to a gateway.
The legacy alias spelling
~typesafe/jev-latestalso retains its OpenRouter route.Scope
policy and resilience mechanisms, attributed to the selected connection provider.
decisionprovider capability andsystemonemodel endpoint. Decision-only modelscannot execute through chat; mixed chat/decision models keep their chat capability.
GET /v1/systemone/modelsaggregates eligible configured backends. Returned idsround-trip into the POST route; prices retain provenance, and a partial backend
outage does not hide the healthy backends.
No provider/status badges, model lists, explanations or request-example panels.
Migration
The original OpenRouter-only version accepted
typesafe/jev-1.13as a vendor id.That qualified id now selects TypeSafe directly. Use
openrouter/typesafe/jev-1.13to retain the OpenRouter connection and billing.The dedicated catalog advertises the new qualified identities.
Related work
Refs #13987. Native TypeSafe work in #14498 and #14031, and the local Ollama adapter
and decision-discovery work in #15410, informed this integration. #15278/#15279's
internal routing clients and Jev-driven combo strategy remain separate concerns;
this PR does not add an internal classifier or a new combo strategy.
Verification
Review corrections are complete. Final regression set: 60 passes; dashboard card/decision-label tests: four passes. Typecheck, changed-file ESLint, provider consistency, complexity, file-size, OpenAPI routes and generated skills checks pass. Translated documentation is complete in follow-up commit
89dc1f45d8: README, API reference and provider reference in all 66 translated locales (198 files), plus 66 provider-count mirrors. Source/target receipts match after formatting and commit hooks; an incremental dry-run reports no outstanding translations for these sources.Production verification (2026-10-05)
Built the local combined image with this PR and the existing local-only features,
took a data-volume backup (gzip integrity verified), and deployed it with the
previous image retained for rollback. Container healthy,
/api/health200, zero restarts.GET /v1/systemone/models: 200, 13 decision rows, ids prefixedopenrouter/,owned_by: openrouter,supported_endpoints: [systemone], catalog status complete.POST /v1/systemone,model: openrouter/inception/mercury-decide:free: 200,typed Noul answer and exact cost zero (
X-OmniRoute-Cost-Status: known).model: typesafe/jev-latest, with no native key configured: rejected instead ofsilently using the available OpenRouter key.
~typesafe/jev-latest: 200, upstream versioned Jev response and cost returned./v1/models: no decision-only rows; GPT-6.1 Sol, Claude Opus 5.5 and ClinePassquota still work. Combined branch typecheck, 60 focused tests and 493 full MCP/cache
Vitest tests pass.
Previously completed checks: focused decision/provider tests (103 passes), adjacent
module tests (495 passes), full MCP/autoCombo/cache Vitest suite (493 passes),
typecheck, changed-file lint, provider consistency, OpenAPI routes, size, complexity,
canonical documentation gates, generated skills, assets and changelog integrity.
The full Node unit run is not green: 45,232 passes, 11 failures, 53 cancellations
and 27 skips. The added TypeSafe provider's missing golden snapshot was corrected
and its three tests now pass. Four locale-sensitive failures pass in an English
test environment (15 focused tests); four file failures are missing installed
@agentclientprotocol/sdk/istanbul-lib-instrumentdependencies. Two assertionsexpect the spec reporter but receive TAP. Pending-promise cancellations occur in
untouched timeout/semaphore/auth tests. These files are unchanged from the base;
none of this is being hidden by relaxing assertions or running with no tests.
The full UI configuration is also not entirely green locally (400 files / 2,593 tests
passed; 32 files failed, 17 test failures and two unhandled errors). Backend suites
under jsdom cannot bundle
node:sqlite; locale-sensitive formatting assertions passwhen rerun in English (five focused files / 28 tests). FlowCanvas still reports two
existing delayed-fitView teardown errors. The System One compact-card tests pass.
Native TypeSafe and Ollama adapters are contract-tested with mocks. This deployment
has no native TypeSafe credentials and its local Ollama is below the minimum System
One version, so no real native-inference verification is claimed. No credentials,
provider onboarding or Ollama upgrade are part of this change.
Review corrections include native TypeSafe model-only 404 lockout (without claiming
chat/passthrough support), operator pricing overrides, known Ollama image-capability
checks, missing upstream model fallback for accounting, and rejecting empty/array
answer payloads. Image modalities for OpenRouter remain enforced by the upstream
model contract; no public-catalog fetch is added to every inference request. Catalog
enumeration must not mutate account-selection/affinity state per model, and local
credential error markers must be rejected before choosing any upstream host.
Human source contributions acknowledged: native TypeSafe provider/credential-check
material from Sean P. Ford (#14498), and decision-only guarding/Ollama capability
mapping from Praveen K Palaniswamy (#15410). Their PRs remain open; no foreign branch
or worktree is modified by this integration.
Do not confuse those with this PR's own actionable gate failures; all remaining
limitations will be named in the final verification record.
Remaining global documentation-translation drift is
docs/architecture/QUALITY_GATES.mdonly. Its content and stale translation receipt also exist on the untouched base. This follow-up does not adopt its hash or claim that unrelated drift is resolved.