Skip to content

Release v3.8.12 - #3264

Merged
diegosouzapw merged 31 commits into
mainfrom
release/v3.8.12
Jun 6, 2026
Merged

diegosouzapw merged 31 commits into
mainfrom
release/v3.8.12

Conversation

@diegosouzapw

@diegosouzapw diegosouzapw commented Jun 5, 2026 •

Copy link
Copy Markdown
Owner

[3.8.12] — 2026-06-06

✨ New Features

🔧 Bug Fixes

📝 Maintenance

  • ci: deploy-vps recreates the PM2 process via the omniroute bin (instead of a bare pm2 restart pinned to the removed app/server-ws.mjs path) and gates the deploy on /api/monitoring/health reporting "status":"healthy", failing the job (with recent PM2 logs) when the box never becomes healthy — supersedes fix(ci): deploy-vps via omniroute bin + fail on unhealthy boot #3262 (#3270 — thanks @diegosouzapw)
  • security: harden the Chipotle executor against CodeQL findings — Math.random() → crypto.randomInt()/crypto.randomUUID() (imported from node:crypto) for session/server IDs, and a strict new URL().hostname check (replacing a substring match) in its test (#3285 — thanks @oyi77)
  • governance: raise the coverage gate from 40% to 60% (statements/lines/functions/branches) now that real coverage sits at ~80% — brings the threshold in line with Hard Rule feat(proxy): enable SOCKS5 proxy support by default #9 (thanks @diegosouzapw)
  • docs: consolidate the community links (Discord + Telegram + WhatsApp) at the top of the README and promote the Free-Token Budget section (#3289 — thanks @diegosouzapw)
  • docs: richer free-tier budget-card image (28 models + first-month strip) and softer ToS framing (caution rather than warning) (#3284 — thanks @diegosouzapw)

🙌 Contributors

Thanks to everyone whose work landed in v3.8.12:

Contributor PRs / Issues
@oyi77 #3250, #3259, #3280, #3285, #3286
@wilsonicdev #3249, #3268, #3282 / #3283 (co-author, #3247 diagnosis), #3287
@strangersp #3261
@MikeTuev #3248
@leninejunior #3271
@zhiru #3274
@diegosouzapw maintainer — #3256, #3263, #3270, #3275, #3277, #3278, #3279, #3281, #3284, #3289


Quality Gate (2026-06-06)

  • lint: 0 errors in the release tree (the only 4 ESLint errors are inside the gitignored nested .claude/worktrees/review-prs checkout — CI runs on a clean checkout and is unaffected)
  • typecheck:core: pass
  • check:cycles: pass (no cycles across 243 files)
  • env-doc-sync / check:docs-all: pass (added the two grok-web TLS vars OMNIROUTE_GROK_TLS_TIMEOUT_MS / OMNIROUTE_GROK_TLS_GRACE_MS to .env.example + ENVIRONMENT.md)
  • test:vitest: 146/146 pass
  • test:unit: 11272+/11286 pass — the 2 deterministic drifts (sidebar-costs-section, t12 minimax) were aligned to the new free-tiers nav (feat(free-tiers): per-model free-token budget + Monthly Budget dashboard card #3263) and MiniMax-M3 (feat(models): add MiniMax M3 across all provider tiers (#3110) #3287) and verified 10/10; the only remaining intermittent failures are the documented concurrency flakes (chatcore-translation-paths, observability-fase04 circuit-breaker reset window), each of which passes 100% in isolation (65/65, 16/16)

Coverage of commits since v3.8.11

  • Range: v3.8.11..release/v3.8.12
  • Commits inspected: 30

⚠️ Flow reminder

After merge → deploy main to the Local VPS (192.168.0.15) for homologation → wait for operator OK → only then tag + GitHub release + npm/Docker/Electron.

Bump 3.8.11 → 3.8.12 across package.json, lockfile, electron/, open-sse/, and
docs/reference/openapi.yaml; add the [3.8.12] cycle placeholder to the root
CHANGELOG and the 41 i18n mirrors. Integration branch for the v3.8.12 cycle —
fixes/features land here via per-issue PRs and it merges to main at release time.
@gemini-code-assist

Copy link
Copy Markdown
Contributor

Warning

You have reached your daily quota limit. Please wait up to 24 hours and I will start processing your requests again!

@kilo-code-bot

kilo-code-bot Bot commented Jun 5, 2026 •

Copy link
Copy Markdown

Code Review Summary

Status: 1 Issue (carried forward) + 1 New Warning | Recommendation: Address before merge

Overview

Severity Count
CRITICAL 1
WARNING 1
SUGGESTION 0
Issue Details (click to expand)

CRITICAL

File Line Issue
tests/unit/chipotle-executor.test.ts N/A Incomplete URL substring check in test assertion

WARNING

File Line Issue
src/lib/quota/sqliteQuotaStore.ts 133 Stale method doc comment — poolUsage() no longer aggregates per-key consumption across dimensions; the implementation was reduced to a stub returning dimensions: [], but the JSDoc still describes the old behavior
Resolved Issues (fixed in incremental diff)
File Previous Issue Resolution
open-sse/executors/chipotle.ts Insecure randomness (Math.random()) Replaced with crypto.randomUUID() in prior commit; current diff adds explicit null check at line 65
open-sse/executors/chipotle.ts Falsy check on connectPromise Changed to explicit !== null at line 65
Files Reviewed (4 files in incremental diff)
  • open-sse/executors/chipotle.ts: Logic fix (explicit null check); previous randomness issue already resolved upstream
  • open-sse/services/grokTlsClient.ts: Cosmetic null-check consistency (lines 44, 127)
  • src/app/(dashboard)/dashboard/usage/components/BudgetTab.tsx: Accessibility fix — added role="presentation" and onKeyDown stop-propagation to checkbox wrapper (line 726)
  • src/lib/quota/sqliteQuotaStore.ts: Removed dead dimension-enumeration code from poolUsage(); method now intentionally returns empty dimensions — doc comment at line 133 still describes old behavior and should be updated

Fix these issues in Kilo Cloud


Reviewed by step-3.7-flash-20260528 · 530,503 tokens

@github-actions

github-actions Bot commented Jun 5, 2026 •

Copy link
Copy Markdown
Contributor

CI Coverage Report

  • Coverage job: success
  • PR test policy: success

Coverage artifact was not available for this run.

diegosouzapw and others added 6 commits June 5, 2026 21:20
Strip ALL <omniModel> tags before forwarding to provider (global regex variant).

Integrated into release/v3.8.12. Thanks @MikeTuev.
… anti-bot (#3180) (#3249)

grok-web: TLS fingerprint impersonation to bypass Cloudflare anti-bot (#3180); sanitize executor error bodies (#12).

Integrated into release/v3.8.12. Thanks @wilsonicdev.
… webTools helpers (#3259)

Add tool-call translation to 8 web-cookie executors via shared webTools helpers.

Integrated into release/v3.8.12. Thanks @oyi77.
Provider refresh/validation, OpenRouter catalog and proxy UI fixes — incl. NVIDIA NIM /models-suffix path fix (real-VPS validated).

Integrated into release/v3.8.12. Thanks @strangersp.
…gineered Amelia protocol (#3250)

Add Chipotle Pepper AI free provider (Amelia protocol); sanitize executor error body (#12).

Integrated into release/v3.8.12. Thanks @oyi77.
Comment thread open-sse/executors/chipotle.ts Fixed
Comment thread tests/unit/chipotle-executor.test.ts Fixed
…3268)

Regression test for the /v1/responses combo-name codex-rewrite guard (#3233, #3227).

Integrated into release/v3.8.12. Thanks @wilsonicdev.
Comment thread open-sse/executors/chipotle.ts Outdated
}

function randomSessionId(): string {
return Array.from({ length: 8 }, () =>

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

WARNING: Insecure randomness - Math.random() is not cryptographically secure. This generates session IDs and server IDs for WebSocket connections. Use crypto.randomUUID() or randomInt from node:crypto instead.

Comment thread tests/unit/chipotle-executor.test.ts Outdated

it("buildUrl returns Amelia endpoint", () => {
const url = executor.buildUrl("pepper-1", false);
assert.ok(url.includes("amelia.chipotle.com"));

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

CRITICAL: Incomplete URL substring check. The test only verifies url.includes("amelia.chipotle.com") which would pass for malicious URLs like https://evil.com#amelia.chipotle.com. Use a proper URL parser or check that the result starts with the expected base URL.

diegosouzapw and others added 14 commits June 6, 2026 02:07
…3256)

Block cross-dimension failover in embedding combos.

Integrated into release/v3.8.12.
Synchronized deploy-vps hardening (PM2 recreate via bin + /api/monitoring/health gate + fail-on-unhealthy). Supersedes #3262.

Integrated into release/v3.8.12.
… rename (#3274)

Detect SQLite driver-unavailable errors to avoid destructive DB rename + optional FTS5 migration guard (split from #3073).

Integrated into release/v3.8.12. Thanks @zhiru.
…r connections (#3271)

Bulk activate/deactivate/retest for selected provider connections.

Integrated into release/v3.8.12. Thanks @leninejunior.
…ard card (#3263)

Free-token budget catalog + per-model budget + Monthly Budget dashboard card (joins #3257 + #3263 into one).

Integrated into release/v3.8.12.
#3260) (#3275)

ds-web/deepseek-v4-pro emits tool calls wrapped as
<tool_call name="skill">{"name":"customize-opencode"}</tool_call> instead of the
canonical <tool>{json}</tool>. webTools.ts only matched <tool>...</tool>, so the block
was silently dropped (and when arguments were present, the surrounding tag leaked into
content). Add TOOL_CALL_TAG_RE to capture the JSON body — the real tool name comes from
the body, never the tag's name= attribute — and extend the early-exit + range stripping.

Regression test: tests/unit/web-tools-translation-3260.test.ts (RED before, GREEN after).
Existing web-tools suites stay green (26/26).
#3277)

Regression of #764. Claude Code → Groq (llama-3.3-70b-versatile) returned HTTP 400
because the model was treated as reasoning-capable: supportsReasoning() defaulted to true,
so applyThinkingBudget did not strip reasoning params, and the claude→openai translator
forwarded reasoning_effort (and re-injected it from output_config.effort) — which Groq
rejects on non-reasoning models.

- providerRegistry: mark llama-3.3-70b-versatile + llama-4-scout supportsReasoning:false
  (gpt-oss / qwen3-32b keep reasoning — they accept reasoning_effort).
- stripThinkingConfig: also strip output_config.effort so the translator can't re-inject
  reasoning_effort downstream.

Regression test: tests/unit/thinking-budget-groq-3258.test.ts (RED before, GREEN after);
existing thinking-budget suites stay green (45/45).
…Data (#3273) (#3278)

A custom OpenAI-compatible image-edit provider received an empty `model`. In production
`globalThis.fetch` is patched with node_modules/undici's fetch, whose `FormData` class
differs from `globalThis.FormData`; passing a native FormData made undici serialize it as
the string "[object FormData]" (text/plain), dropping every field including `model`.

handleOpenAIImageEdit now assembles the multipart body as a Buffer with an explicit
boundary + Content-Type, which every fetch impl accepts verbatim.

Regression test: tests/unit/image-edits-multipart-3273.test.ts reproduces the exact prod
condition (routes through undici's fetch) — RED before (upstream got text/plain
[object FormData]), GREEN after. Existing image suites stay green (50/50).
…utors hall

Audited every commit since v3.8.11 one-by-one. Added the missing v3.8.12
entries (features #3250/#3259/#3263/#3271, fixes #3248/#3249/#3261/#3256/#3274,
maintenance #3270), repointed the combo-rewrite and web-tools entries to their
actually-merged PRs (#3268, #3275) instead of the closed #3242/issue links, and
added the v3.8.12 Contributors hall. Also co-credited @ibanunmangun on the
v3.8.11 #3203 OAuth fix (independent first diagnosis via #3193).
#3279)

Webhooks hardcoded parseAndValidatePublicUrl, which blocks any RFC1918/loopback host —
breaking self-hosted setups that legitimately point webhooks at internal services
(n8n, Home Assistant, a LAN box). Provider URLs already had an opt-in
(OMNIROUTE_ALLOW_PRIVATE_PROVIDER_URLS); webhooks now reuse it.

- outboundUrlGuard: add parseAndValidateWebhookUrl — gates the private-host check on
  arePrivateProviderUrlsAllowed() (default OFF); protocol + embedded-credential checks
  stay unconditional.
- swap all webhook call sites (create/update/test/validate-url + dispatcher x2) to it.

Regression test: tests/unit/webhook-private-optin-3269.test.ts (RED before, GREEN after);
existing webhook SSRF/dispatcher suites stay green (33/33).
…3269) (#3281)

Follow-up to the #3269 private-webhook opt-in. With the opt-in on, the private-host
check was bypassed entirely, leaving cloud-metadata endpoints (169.254.169.254,
metadata.google.internal, 100.100.100.200, link-local 169.254.0.0/16) reachable — the
classic SSRF -> IAM-credential pivot — and the webhook test endpoint returned the
upstream body, making it a content-exfiltration primitive against internal services.

- outboundUrlGuard: add isCloudMetadataHost(); parseAndValidateWebhookUrl blocks those
  hosts UNCONDITIONALLY, even when private targets are opted in.
- webhooks/[id]/test: redact responseBody for private targets (status + latency only).

Regression test: tests/unit/webhook-metadata-guard-3269.test.ts (RED before, GREEN after);
existing webhook SSRF/opt-in suites stay green (34/34).
…3247) (#3283)

A working Qoder PAT was reported as "expired". The validator probes the Cosy endpoint
(api1.qoder.sh) — which IS the correct PAT path (the executor falls back to it after the
expected 401 from api.qoder.com). The bug was the verdict: isCosyAppError (added by #2860)
marked ANY Cosy 500 with "success":false as an auth failure, including a generic
{..."msgCode":500,"message":"Internal Server Error"} server fault — contradicting the
older #1391 "5xx = valid bypass" rule.

Narrow it: a Cosy 500 only marks the PAT invalid when the body carries an EXPLICIT auth
signal (unauthorized/forbidden/expired/token invalid/...); a generic Internal Server Error
falls back to valid-bypass. #2860's protection for genuine auth rejections is preserved.

Regression test: tests/unit/qoder-cli.test.ts — the two pre-existing generic-500 cases now
assert valid:true (they encoded the #3247 bug) + a new explicit-auth-signal case asserts
valid:false. 13/13 green.
…trip) + soften ToS framing to caution (#3284)

- Regenerate the README/dashboard mockup from the catalog: 28 pools in the grid
  (was 9), a balance-floored stacked bar (Mistral now ~40% of the bar, was ~90%),
  and a first-month signup-credit strip (~586M). Add the data-driven generator.
- FREE_TIERS.md: drop the alarming '🚫 Avoid / terms prohibit' framing — relabel
  those 19 providers as 'caution — worth checking', note their access is real and
  the OAuth/keyless ones aren't token-quantifiable (so out of the headline, not
  excluded as unusable).
…s, webhooks, and embeddings enforcement (#3280)

Integrated into release/v3.8.12. Quota Sharing Engine fixes: poolUsageWithDimensions promoted to the QuotaStore interface, single-snapshot burn rate, zero-weight normalization, Anthropic saturation signals, quota.exceeded webhook on block, and embeddings enforcement. Validated: 10/10 PR tests + 34 quota/embedding regression files green, typecheck + lint clean. Dropped the committed .omo/ agent-tooling artifacts.
diegosouzapw and others added 2 commits June 6, 2026 03:43
…is (#3282/#3247)

The #3247 fix shipped via #3283 (parallel session) 46s after @wilsonicdev
filed the same fix in #3282, leaving his PR stranded with no credit — the
#3242 credit-theft pattern. Repoint the entry to the merged #3283, credit
@wilsonicdev as co-author for the independent diagnosis, and note #3283
refined it to keep rejecting on an explicit-auth-signal 500.
…er in test (#3285)

Integrated into release/v3.8.12. CodeQL hardening on the Chipotle executor: Math.random → crypto.randomInt/randomUUID, and a strict URL hostname check in the test. Fixed the node:crypto import (crypto.randomInt is not on the Web Crypto global → would crash at WS-connect) and added a regression guard exercising both helpers.
wilsonicdev and others added 7 commits June 6, 2026 04:18
Integrated into release/v3.8.12. Registers MiniMax-M3 (1M context, Anthropic-compatible) across 8 provider tiers (minimax, minimax-cn, opencode, opencode-go, opencode-zen, trae, ollama-cloud, nvidia). Validated: 8/8 new registry tests + 25 registry/model-catalog regression files green, typecheck + lint clean. Complements the #3141 max_tokens spec already on release.
…sApp) + promote Free-Token Budget section (#3289)

- Add the official Telegram group (t.me/omnirouteOficial) and gather Discord,
  Telegram and both WhatsApp groups into one community card block at the top;
  remove the scattered WhatsApp links from the nav line and the Support section
  (now a pointer to the top).
- Move the Free-Token Budget section from the bottom (before License) up to a
  hero section near the top, retitled '💰 ~1.9B Free Tokens / Month'.
…#3286)

Integrated into release/v3.8.12. Salvaged the emitHookBlocking payload-chaining fix from the now-closed plugins-v4 branch (#3221) and adapted it to the shipped release hooks.ts: each blocking handler now sees the body/metadata as mutated by previous handlers. TDD regression test included (RED before, GREEN after); existing plugins-hooks suites green (19+5), typecheck + lint clean.
Quota Sharing Engine repair (#3280), MiniMax-M3 across 8 tiers (#3287),
emitHookBlocking payload chaining (#3286), Chipotle CodeQL hardening (#3285);
updated the contributors hall.
test:coverage now enforces 60/60/60/60 (statements/lines/functions/branches);
real coverage is ~75-82% so this tightens the floor without new test work.
Updates the c8 --check-coverage thresholds in package.json and the matching
references in CLAUDE.md (Quick Start, testing table, Copilot policy, Hard
Rule #9). Salvaged from the never-pushed chore/skills-governance-tdd-vps
branch; the i18n CLAUDE.md mirrors carry a separate pre-existing drift and
are not gated by check-docs-sync.
….12 diff

- chipotle/grokTls: explicit null checks instead of a Promise in a boolean
  conditional (behavior-preserving; clears the 2 MAJOR reliability bugs)
- sqliteQuotaStore.poolUsage: drop the unreachable dimMap scan loops (dimMap
  was never populated) — the lightweight snapshot already returns no
  dimensions; poolUsageWithDimensions() is the plan-aware path
- BudgetTab: presentation role + keyboard handler on the checkbox wrapper
@sonarqubecloud

sonarqubecloud Bot commented Jun 6, 2026

Copy link
Copy Markdown

Quality Gate Failed Quality Gate failed

Failed conditions
6 Security Hotspots

See analysis details on SonarQube Cloud

@diegosouzapw
diegosouzapw merged commit 78454ee into main Jun 6, 2026
171 of 173 checks passed
HouMinXi pushed a commit to HouMinXi/OmniRoute that referenced this pull request Aug 2, 2026
Poid-ZA pushed a commit to Poid-ZA/OmniRoute that referenced this pull request Aug 5, 2026
muhamadgalihsaputra pushed a commit to niyatna/NiyatnaRoute that referenced this pull request Sep 27, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment