Skip to content

fix: sete correções simples de issues abertas (base 3.8.52) - #16016

Closed
afonsoft wants to merge 7 commits into
diegosouzapw:release/v3.8.52from
afonsoft:devin/issues-simple-fixes-3.8.52
Closed

afonsoft wants to merge 7 commits into
diegosouzapw:release/v3.8.52from
afonsoft:devin/issues-simple-fixes-3.8.52

Conversation

@afonsoft

@afonsoft afonsoft commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

Summary

⚠️ base-red inherited: #15306

Correções simples de issues abertas, rebaseado em release/v3.8.52 (977d006). Um commit por issue:

Related Issues

Validation

  • Change type: DB / security / CLI / docs / CI
  • Focused tests: tests/unit/usage-history-reset.test.ts (3/3, incl. novo caso token_ledger survives 'all'), tests/unit/providers-enc-v1-guard.test.ts (3/3, novo)
  • npm run lint (eslint nos arquivos alterados — limpo)
  • Reconciliado com release/v3.8.52 (977d006)
  • check-docs-counts-sync.mjs: 0 STRICT drift; mirrors cobertos
  • check-api-typecheck.mjs: 272 erros, todos dentro do baseline (rebaixado em 9 mortos)
  • Production-code changes incluem testes novos/atualizados neste PR.

Tests Added Or Updated

  • tests/unit/usage-history-reset.test.ts — novo caso: token_ledger sobrevive ao reset 'all'.
  • tests/unit/providers-enc-v1-guard.test.ts — novo arquivo: guard enc:v1: no POST/PATCH + invariante do encrypt().

Coverage Notes

  • src/app/api/providers*/route.ts: guard coberto por teste de fonte + invariante no providers-enc-v1-guard.test.ts.
  • tests/ e scripts/check/: nova cobertura de regressão.
  • Resto é docs/código gerado — sem mudança de coverage.

Reviewer Notes

@afonsoft
afonsoft requested a review from diegosouzapw as a code owner October 9, 2026 01:28
@afonsoft

afonsoft commented Oct 9, 2026

Copy link
Copy Markdown
Contributor Author

Corrigidas: #16004 (token_ledger no reset), #15930 (enc:v1: estrangeiro), #15928 ({id} literal no CLI), #15665 (links 404 de skills), #14574 (mirrors i18n + gate), #13697 (doc Qoder PAT), #15988 (DATA_DIR por run no nightly).

devin-ai-integration Bot and others added 7 commits October 9, 2026 17:47
…ouzapw#16004)

Upstream already removed token_ledger from RESET_TARGETS; this adds the
missing regression coverage: a ledger row must survive
resetUsageHistory('all') and deletedTokenLedger must stay 0.
…iegosouzapw#15930)

encrypt() stores enc:v1:-prefixed values verbatim, so a ciphertext blob
produced by another tool or under a different STORAGE_ENCRYPTION_KEY
persisted undecryptable and failed on first use. POST /api/providers and
PATCH /api/providers/[id] now 400 any enc:v1: apiKey this deployment
cannot decrypt; envelopes still decryptable stay allowed.

Co-Authored-By: Afonso Dutra Nogueira Filho <afonsoft@gmail.com>
…gosouzapw#15928)

Generated omniroute api commands sent the literal '{id}' placeholder and
accepted no argument for it. The generator was already fixed to emit
--id + url.replace(); this regenerates bin/cli/api-commands/*.mjs.

Co-Authored-By: Afonso Dutra Nogueira Filho <afonsoft@gmail.com>
…iegosouzapw#15665)

The omniroute-* capability/CLI skills were aggregated into the omni-*
and cli-* sets; omni-auth, cli-serve, cli-providers and cli-eval still
linked to the old 404 paths.

Co-Authored-By: Afonso Dutra Nogueira Filho <afonsoft@gmail.com>
…souzapw#14574)

The root docs and mirrors are now in sync, but the gate still only
checked README.md/AGENTS.md/llm.txt — mirrors drifted undetected before.
check-docs-counts-sync now validates every docs/i18n/*/README.md that
carries a claim, with a localisation-tolerant extractor (numeral
adjacent to the 'migrat' stem).
A pt- PAT (or QODER_PERSONAL_ACCESS_TOKEN) spawns the local qodercli per
request: no tool calling, no streaming, 45s cap — useless for agent
clients. Point users at OAuth or an API key for those paths.

Co-Authored-By: Afonso Dutra Nogueira Filho <afonsoft@gmail.com>
Co-Authored-By: Afonso Dutra Nogueira Filho <afonsoft@gmail.com>
@afonsoft
afonsoft force-pushed the devin/issues-simple-fixes-3.8.52 branch from 6612c13 to 27468d7 Compare October 9, 2026 17:48
@afonsoft

afonsoft commented Oct 9, 2026

Copy link
Copy Markdown
Contributor Author

@diegosouzapw PR rebaseado em release/v3.8.52 (977d006) e mergeable de novo — poderia dar uma review?

Notas rápidas do rebase: a base já trouxe as correções de #16004 (token_ledger fora de RESET_TARGETS), #14574 (mirrors 202) e #15988 (step Prepare isolated runtime state no nightly), então esses três commits viraram só cobertura de regressão/gate. O escopo vivo é: guard enc:v1: em providers (#15930), regen dos api-commands com {id} substituído (#15928), repoint dos links skills/omniroute-* (#15665) e a nota do Qoder PAT (#13697).

Ficamos à disposição se precisar de ajuste em qualquer commit.

@diegosouzapw

Copy link
Copy Markdown
Owner

Thanks @afonsoft for putting this together. I'm closing it because nearly all of it has already landed on release/v3.8.52 through other PRs. A 137-file PR bundling seven unrelated changes can't be merged safely, and merging it as is would only add duplicate code. Item by item:

  1. fix(backend): preserve token balances when resetting usage data #16004, token_ledger survives a usage reset: already covered by tests/unit/usage-history-reset-token-ledger.test.ts (fix(db): keep token_ledger when resetting usage data #16005). The issue is closed.
  2. fix(security): credentials that already carry the enc:v1: prefix are stored verbatim — foreign ciphertext fails later as a confusing "Missing API key" #15930, enc:v1: guard on /api/providers: fix(security): reject encrypted-envelope credentials at provider create/update validation #15932 already rejects enc:v1: in the Zod schema for both create and update, so this route guard would be dead code. It is also looser than the tip: it accepts envelopes the deployment can decrypt, while the schema rejects all of them.
  3. fix(cli): generated omniroute api commands never substitute {id} path params — every get/patch/delete/test-by-id command is broken #15928, CLI {id} path params: the generator fix is fix(cli): resolve required URL path parameters in generated commands #15955, already merged. The regenerated bin/cli/api-commands/* here matches the tip generator byte for byte, and prepublishOnly regenerates these files at publish time anyway.
  4. [bug] skills/omni-auth and cli-providers link to skills/omniroute-*/SKILL.md that no longer exist (404) #15665, skill links: this is the part we're keeping. fix(skills): repoint deleted omniroute-* skill links (Fixes #15665) #15676 just landed the capability-table half. The CLI-table remaps from this PR go in a follow-up PR that credits you with Co-authored-by, with one fix: "Cloud agents (Codex / Devin / Jules)" pointed at cli-backup-sync, which is the backup skill.
  5. docs: 65 README mirrors still say 178 migrations, and the docs-counts gate does not cover them #14574, README migration-count gate: fix(docs): validate migration counts across localized READMEs #15982 already wired buildReadmeMigrationChecks(). A second validator would report the same drift twice.
  6. docs(providers): Qoder PAT path has no tool calling, no streaming and a 45s cap — undocumented, breaks agent combos (499) #13697, Qoder PAT docs: fix(qoder): keep PAT-only transport out of agent tool requests #15919 added a full "Qoder: choose the credential transport" section. Since then, PAT accounts are excluded or fail explicitly when a request carries tools, so the "answered in plain text" note here would now be wrong.
  7. api-typecheck baseline (−9 entries): baseline edits only go in through the ratchet update on the current tip, so we can't take a hand-edited copy.

One more note: every commit here is authored by the Devin AI bot account, and this repo doesn't accept AI/bot authorship metadata in commits (Hard Rule #16 in AGENTS.md). For future PRs, please commit under your own identity. Thanks again, and the link fix will carry your credit.

diegosouzapw added a commit that referenced this pull request Oct 10, 2026
…6109)

Follow-up to #15676 (thanks @Poid-ZA) carrying the CLI-table remaps from #16016 (credited to @afonsoft via Co-authored-by). Every `skills/<dir>/SKILL.md` reference inside the skills now resolves, enforced by a new check in skillManifestsLint.test.ts (4/4; fails with the fix reverted). Cloud-agent rows stay on cli-backup-sync, because the skill generator assigns the `omniroute cloud` command group there (cliRegistryParser.ts:78). Protected surface (skills/**/SKILL.md) approved by the owner. check:docs-all's only red is the inherited provider-count drift, fixed by #15799.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

fix(security): credentials that already carry the enc:v1: prefix are stored verbatim — foreign ciphertext fails later as a confusing "Missing API key"

2 participants