Repository navigation
fix(skills): stop ambient env leaking into generated SKILL.md output - #15948
BenjaminAronsson wants to merge 3 commits into
Conversation
The curl-example builders called resolveOmniRouteBaseUrl(), which reads process.env. Their only consumer is the SKILL.md generator, whose output is committed and then diff-gated by check:agent-skills-sync — so the committed artifact was a function of whoever last ran the generator. Anyone with PORT, API_PORT, DASHBOARD_PORT, BASE_URL or OMNIROUTE_BASE_URL set wrote their own host into the files, and CI, which sets none of them, reported drift. That is the trap that left all 20 skills drifted and blocked every PR into the branch (the Merge integrity job is .mergify.yml's always-on merge anchor). baseUrl is now an explicit argument defaulting to DEFAULT_OMNIROUTE_BASE_URL, so regeneration is reproducible on any machine. diegosouzapw#15778's capability is preserved, not dropped: a caller that wants the operator's configured host passes resolveOmniRouteBaseUrl() as that argument, and its test now asserts exactly that. What changes is that it must be asked for rather than picked up from the environment. Verified byte-identical to the regenerated output in diegosouzapw#15945, so the two land in either order without conflict. The determinism test was confirmed RED against the previous code ('env {"PORT":"37128"} leaked into the example') before the fix was restored. 5/5 in the contract suite, 30/30 across agentSkills-generator and cli-api-generator-ref-params, typecheck and lint 0.
…ossary, route map, ToS-default test fallout (#16092) Validated on the branch: 94/94 node tests across the touched files + glossary/route-map gates, the 4 vitest files 20/20 run individually, API typecheck and eslint clean. Remaining tip reds owned elsewhere: executor golden (#16058), quality-rail (#15682), chaosVirtualCombo (#16090), skills sync (#15945/#15948).
Refresh against the current release base, preserve canonical generator defaults and explicit host support, and remove an inaccurate reference to a generator CLI flag. Co-authored-by: diegosouzapw <8016841+diegosouzapw@users.noreply.github.com>
|
Hi @BenjaminAronsson — closing this pull request to clear the open queue. The branch |
|
Owner has explicitly requested reopening and merging the campaign PRs. This PR was already reopened when checked. The relay-15948 reconciliation worktree belongs to another session, so this campaign will not overwrite or merge over that session. A fresh read-only VPS probe on generated-output candidate 6718424 confirms the independent determinism defect: PORT=37128 makes sync exit 2 (19 stale / 27 unchanged). This PR remains necessary unless a new current-base execution proves supersession. Fresh required checks are pending; no inherited failure or pending result is being treated as PASS. |
Preserve deterministic examples and contributor history while refreshing the exact release base and correcting the changelog fragment format. Co-authored-by: diegosouzapw <8016841+diegosouzapw@users.noreply.github.com>
|
Reopened at the repository owner's explicit request, retaining the original contribution. Thank you @BenjaminAronsson for fixing environment-dependent generated examples. Normal fast-forward update: head With dependencies matching the current lock: exact-base-helper RED 3 PASS / 2 FAIL; restored fix GREEN 35 PASS across the contract, skill-generator and CLI-reference-parameter suites. Focused lint, final format, test-masking, changelog, typecheck:core and normal hooks exit 0. The physical cache is from a completed clean npm ci; no separate clean install per worktree is claimed. Admission remains HOLD until current-candidate applicable CI succeeds and the separately owned generated-content repair #15945 lands. This PR intentionally does not copy that contribution: its standalone generator still reports 20 pending / 26 unchanged / zero errors. No merge, bypass, force push or baseline increase occurred. |
Summary
SKILL.mdgenerator's output a pure function of its inputs. fix(skills): regenerate the 20 SKILL.md files drifted since #14381 #15945 regenerates the 20 drifted files; this PR stops them drifting again.apiOperationExample.ts/cliConfigurationExample.tscalledresolveOmniRouteBaseUrl(), which readsprocess.env. Their only consumer is the generator, whose output is committed and then diff-gated bycheck:agent-skills-sync— so the committed artifact was a function of whoever last ran the generator. Anyone withPORT,API_PORT,DASHBOARD_PORT,BASE_URLorOMNIROUTE_BASE_URLset baked their own host into the repo; CI, which sets none of them, then reported drift. BecauseMerge integrityis.mergify.yml's always-on merge anchor, that drift blocked every PR into the branch.baseUrlis now an explicit argument defaulting toDEFAULT_OMNIROUTE_BASE_URL, so regeneration is reproducible on any machine.resolveOmniRouteBaseUrl()as that argument. What changes is that it must be asked for rather than picked up from the ambient environment.Related Issues
Validation
src/lib/agentSkills/**), no request-path or DB codenpm run lint— exit 0release/v3.8.52tip (61e07fb7e0); focused checks rerun afterwardtests/unit/cli-configuration-consumer-contract.test.tsagentSkills-generator+cli-api-generator-ref-paramstypecheck:corenpm run lintgit diffempty)TDD record (Hard Rule #18). The new determinism test was confirmed RED against the previous code before the fix was restored:
Tests Added Or Updated
tests/unit/cli-configuration-consumer-contract.test.ts(updated) — three changes:generated examples ignore ambient base-url env so committed output is reproducible— asserts the default output is identical across all five env vars (PORT,API_PORT,DASHBOARD_PORT,BASE_URL,OMNIROUTE_BASE_URL). This is the regression guard, and the one confirmed red above.configuration-API examples are reproducible and still accept an explicit host— pins the/api/cli-tools/*branch, which routes throughcliConfigurationExample.ts, on both paths.configuration examples track the configured loopback port…→…when given one. Same assertion (http://localhost:37128, no20128), now via the explicit argument, so fix(docs): resolve generated skill curl examples to the configured loopback port #15778's behaviour stays covered rather than being silently dropped.withBaseUrlEnv()helper so each test restores all five vars in afinally, replacing the previous three-variable save/restore block.Coverage Notes
src/lib/agentSkills/apiOperationExample.tsandsrc/lib/agentSkills/cliConfigurationExample.ts. Both are fully exercised bycli-configuration-consumer-contract.test.ts, which covers every branch: bearer, dashboard-session (login / mutation / read), and the two/api/cli-tools/*paths — each now on both the default and explicit-baseUrlpaths, so the new parameter adds covered branches rather than uncovered ones.process.envreads.Reviewer Notes
skills/changes — content is fix(skills): regenerate the 20 SKILL.md files drifted since #14381 #15945's, the trap is this one's — so its ownMerge integrityrun still shows the inherited 20-skill drift until fix(skills): regenerate the 20 SKILL.md files drifted since #14381 #15945 lands.resolveOmniRouteBaseUrl()callers (A2A skills, MCPinternalFetch, two API routes). Those are genuine runtime consumers where reading the environment is correct.