Skip to content

Release v3.8.17 - #3448

Merged
diegosouzapw merged 34 commits into
mainfrom
release/v3.8.17
Jun 9, 2026
Merged

diegosouzapw merged 34 commits into
mainfrom
release/v3.8.17

Conversation

@diegosouzapw

@diegosouzapw diegosouzapw commented Jun 8, 2026 •

Copy link
Copy Markdown
Owner

[3.8.17] — 2026-06-09

✨ New Features

  • feat(providers): LMArena provider — routes requests to the LMArena battle platform via the new lmarena executor; supports streaming chat completions. (#3421 — thanks @oyi77)
  • feat(providers): ZenMux provider — adds the zenmux executor for ZenMux's OpenAI-compatible endpoint with streaming support. (#3429 — thanks @oyi77)
  • feat(providers): Gemini Business provider — adds the gemini-business executor (Phase 2C of the Google provider expansion), enabling Gemini models via Google Workspace accounts. (#3436 — thanks @oyi77)
  • feat(plugin+api): auto-combos API + free model quota display — new GET /api/combos/auto endpoint lists dynamically scored combos; provider pages now surface free-tier quotas inline; MCP-plugin surface extended to match. (#3435 — thanks @mrmm)
  • feat(opencode-plugin): per-prefix API format selection, debug logging, and free-label normaliser — three backports from the mrmm fork: each route prefix can specify its own wire format (OpenAI / Anthropic / Gemini), structured debug output is toggled via env var, and free-tier labels are normalized across providers. (#3420 — thanks @herjarsa)
  • feat(connections): connection pagination, health filter, batch-delete confirmation, and custom banned keywords — the provider connections table is now paginated; a health-state filter lets operators show only healthy/degraded/failed connections; multi-select + confirm dialog for bulk deletes; per-connection keyword denylist for content safety. (#3454 — thanks @sdfsdfw2)
  • feat(settings): Endpoint Token Saver visibility toggle — operators can now show or hide the Token Saver widget on the endpoint page from Settings → Appearance. (#3461 — thanks @rdself)
  • feat(catalog): model catalog name feature flag — a new feature flag controls whether the catalog exposes provider-prefixed model names, letting deployments opt into the legacy bare-name format for downstream tooling compatibility. (#3464 — thanks @rdself)

🔧 Bug Fixes

  • fix(translator): Vertex AI tool calls no longer fail with 400 Unknown name "id" — the OpenAI-style id field is stripped from functionCall/functionResponse parts for vertex/vertex-partner; the public Gemini API still receives id as required. (#3457 — thanks @nullbytef0x / @diegosouzapw)
  • fix(claude): Claude Code claude-opus-4-8 tool calls no longer break with tool call could not be parsed — OmniRoute no longer force-injects interleaved-thinking / advanced-tool-use / effort beta flags the client never negotiated; clients sending their own anthropic-beta header control those betas themselves. (#3458 — thanks @Forcerecon / @diegosouzapw)
  • fix(catalog): imported/custom models on no-auth providers (e.g. [provider removed at its operator's request]) now appear in GET /api/v1/models and the Playground model selector — the eligibility gate required a DB connection row which no-auth providers never have, silently dropping every imported model for them. (#3463 — thanks @tjengbudi / @diegosouzapw)
  • fix(browser): optional cloakbrowser import no longer causes bundle errors when the package is absent — the import is now wrapped in a dynamic require so the build succeeds on environments that don't install the optional dep. (#3460 — thanks @rdself)
  • fix(claude-web): claude-web session handling cleanup — corrects an edge case where session cookies were not properly refreshed after a Turnstile challenge, and removes stale wrapper code left over from the provider split. (#3449 — thanks @androw)
  • fix(analytics): SQL named params are now scoped per query context — a shared params object was being mutated across concurrent analytics queries, causing SQLITE_MISUSE: named parameter not found errors under load. (#3447 — thanks @ReqX)
  • fix(command-code): chat endpoint reverted to /alpha/generate and model-sync discovery fixed — a prior refactor incorrectly targeted the wrong path, causing Command Code completions to silently 404; model listing now also resolves from the correct discovery endpoint. (#3432 — thanks @TapZe)
  • fix(command-code): CLI version header aligned to current Command Code release — the X-Command-Code-Version header value was pinned to a stale version string, causing upstream version-gated features to be rejected. (#3462 — thanks @hevener10)
  • fix(sse): provider IDs are normalized to strings before lookup — numeric provider IDs (e.g. from legacy DB rows) caused undefined lookups in the executor registry; all IDs are now coerced to string at the SSE entry point. (#3427 — thanks @disafronov)
  • fix(stream): textual tool-call slicing index mismatch resolved and containsTextualToolCallMarker deduplicated — two related bugs in the rolling-buffer parser caused partial tool-call chunks to be emitted twice or sliced from the wrong offset, producing garbled JSON in streamed tool responses. (#3413 — thanks @Ardem2025)
  • fix(stream): OpenAI usage-only chunks (empty choices: []) are now passed through instead of being dropped — some providers emit a trailing stats-only chunk after the last content delta; discarding it caused usage counters to be missing in logged responses. (#3422 — thanks @xz-dev)
  • fix(translator): empty-string reasoning_content replaced with placeholder on cache miss — injectEmptyReasoningContentForToolCalls pre-sets reasoning_content="" before the cache lookup; the old guard checked for undefined, never firing on miss and leaving "" in place, which DeepSeek V4+ rejects with a 400. (#3433 — thanks @ViFigueiredo)
  • fix(catalog): combos auto-compute context_length for any provider-ID form — the context-length resolution only matched exact-string provider IDs, missing combos declared with a numeric or aliased ID; the lookup now normalizes before matching. (#3417 — thanks @herjarsa)
  • fix(healthcheck): container bridge network IP probed correctly — the healthcheck script was hard-coded to localhost which resolves to IPv6 ::1 inside some container runtimes; it now queries the bridge gateway IP so the probe succeeds on both bridge and host networking modes. (#3434 — thanks @naimo84)
  • fix(publish): onnxruntime CUDA binary removed from npm tarball — the native .node binary exceeded npm's 413 payload limit and was never needed at runtime (OmniRoute uses the CPU build); the pack policy now excludes the CUDA artifact. (#3437 — thanks @herjarsa)

📝 Maintenance

  • docs: critical documentation gaps closed — new guides for ACP protocol, router strategies, compression, REST API reference, and updated AUTO-COMBO deep-dive; getting-started section added with Quick Start, Providers, Free Tiers, Auto-Combo, and Troubleshooting pages. (#3438 — thanks @oyi77)
  • docs(opencode-plugin): plugin README rewritten to lead with the why — positions the plugin as the recommended integration path over the legacy @omniroute/opencode-provider package, with migration guidance. (#3418 — thanks @herjarsa)
  • docs(env): COMMAND_CODE_VERSION override documented — environment variable added to .env.example and reference docs so operators can pin the CLI version header without a code change. (#3462 — thanks @hevener10)
  • test(auto-combo): same-provider connection identity assertion added — regression test covering the case where two connections for the same provider share an account ID, verifying the combo engine selects the correct one. (#3378 — thanks @oyi77)
  • deps: electron upgraded to 42.3.3; electron-builder to 26.15.2; electron-updater to 6.8.9; 4 development-group and 10 production-group packages bumped via Dependabot. (#3441 / #3442 / #3443 / #3444 / #3445 — thanks @diegosouzapw)
  • chore(release): v3.8.17 development cycle opened from main. (thanks @diegosouzapw)

🙌 Contributors

Thank you to everyone who contributed to this release!

Contributor Contributions
@oyi77 LMArena provider (#3421), ZenMux provider (#3429), Gemini Business provider (#3436), auto-combo test (#3378), critical docs (#3438)
@herjarsa opencode-plugin per-prefix format (#3420), catalog context_length fix (#3417), opencode-plugin README (#3418), tarball publish fix (#3437)
@mrmm auto-combos API + free quota display (#3435)
@sdfsdfw2 connection pagination, health filter, batch-delete, banned keywords (#3454)
@rdself cloakbrowser import fix (#3460), Token Saver toggle (#3461), catalog name feature flag (#3464)
@androw claude-web session handling cleanup (#3449)
@ReqX analytics SQL named params scoping fix (#3447)
@TapZe command-code chat endpoint + model sync fix (#3432)
@hevener10 command-code CLI version header fix + env docs (#3462)
@disafronov SSE provider ID normalization (#3427)
@Ardem2025 stream slicing index mismatch + dedup fix (#3413)
@xz-dev stream empty choices passthrough fix (#3422)
@ViFigueiredo translator reasoning_content placeholder fix (#3433)
@naimo84 healthcheck container bridge IP fix (#3434)
@nullbytef0x reported Vertex AI function_call.id bug (→ #3457)
@Forcerecon reported forced anthropic-beta corruption bug (→ #3458)
@tjengbudi reported no-auth models missing from catalog (→ #3463)
@diegosouzapw Vertex AI fix (#3457), anthropic-beta fix (#3458), catalog no-auth fix (#3463), release management

Quality Gate

Check Status
lint ✅ pass
typecheck:core ✅ pass
check:cycles ✅ pass
check:docs-all ✅ pass
test:unit ✅ pass
test:vitest ✅ 146/146

Commit coverage

  • Range: v3.8.16..HEAD
  • Commits inspected: 32
  • CHANGELOG bullets: 29 (5 dep bumps consolidated into 1 grouped entry)
  • Coverage: 100% — every commit is attributed

Regressions fixed in this release commit

⚠️ After merging: run Phase 2 (Local VPS homologation) before tagging.

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request bumps the project version from 3.8.16 to 3.8.17 across various package configuration files, lockfiles, OpenAPI documentation, and updates the CHANGELOG.md with a new unreleased section. As there are no review comments, I have no further feedback to provide.

Important

The consumer version of Gemini Code Assist on GitHub is being sunset. Starting June 18, 2026, new organization installations will be blocked, and all code review activity will officially cease on July 17, 2026.
For more details on the timeline and next steps, please review the Help Documentation.

@github-actions

github-actions Bot commented Jun 8, 2026 •

Copy link
Copy Markdown
Contributor

CI Coverage Report

  • Coverage job: skipped
  • PR test policy: success

Coverage artifact was not available for this run.

@sonarqubecloud

sonarqubecloud Bot commented Jun 8, 2026

Copy link
Copy Markdown

dependabot Bot and others added 20 commits June 8, 2026 18:39
…del sync discovery (#3432)

Integrated into release/v3.8.17
Integrated into release/v3.8.17
…d path over @omniroute/opencode-provider (#3418)

Integrated into release/v3.8.17
…, compression) (#3438)

Integrated into release/v3.8.17
…deduplicate containsTextualToolCallMarker (#3413)

Integrated into release/v3.8.17
…abel normaliser (3 mrmm-fork backports) (#3420)

Integrated into release/v3.8.17
Comment on lines +361 to +363
const cleaned = name
.replace(/\s*\(free\)\s*$/i, "")
.replace(/[\s-]+free\s*$/i, "")
Comment on lines +361 to +362
const cleaned = name
.replace(/\s*\(free\)\s*$/i, "")
Comment thread open-sse/executors/gemini-business.ts Dismissed
Comment on lines +93 to +96
const response = await fetch(`${baseURL}/models`, {
headers: { Authorization: `Bearer ${apiKey}` },
signal: controller.signal,
});
Comment thread open-sse/executors/lmarena.ts Fixed
ViFigueiredo and others added 3 commits June 8, 2026 19:04
Comment on lines +118 to +120
const cleaned = name
.replace(/\s*\(free\)\s*$/i, "")
.replace(/[\s-]+free\s*$/i, "")
Comment on lines +118 to +119
const cleaned = name
.replace(/\s*\(free\)\s*$/i, "")
…tion, and custom banned keywords (#3454)

Integrated into release/v3.8.17
diegosouzapw and others added 9 commits June 8, 2026 20:54
#3457)

Vertex AI's FunctionCall/FunctionResponse protos have no id field; emitting it made Vertex reject tool calls with 400 'Unknown name id'. The id is now stripped only when the routed provider is vertex/vertex-partner (threaded via credentials._provider), preserving it for the public Gemini API where Gemini 3+ uses it for signature matching.

Co-authored-by: nullbytef0x <nullbytef0x@users.noreply.github.com>
…g/effort betas (#3415) (#3458)

Claude Code -> claude-opus-4-8 turns intermittently died with 'tool call could not be parsed (retry also failed)'. OmniRoute's claude identity cloak rebuilt the anthropic-beta header from scratch and unconditionally forced interleaved-thinking-2025-05-14 (+ advanced-tool-use / effort for heavy agents), even when the client never negotiated them. The forced interleaved-thinking conflicts with tool_choice-forced turns, producing malformed opus tool_use streams (and sibling 400 'Thinking may not be enabled when tool_choice forces tool use').

selectBetaFlags now takes the client's inbound anthropic-beta: when present, thinking/effort betas are only emitted if the client requested them. Opaque clients (no header — the OAuth cloak path) keep the full set unchanged, so existing behavior and the #2454 model-tier gating are preserved.

Co-authored-by: Forcerecon <Forcerecon@users.noreply.github.com>
…/models (#3200) (#3463)

The custom-models loop in getUnifiedModelsResponse gated every model through hasEligibleConnectionForModel(getConnectionsForProvider(...)). no-auth providers (theoldllm, etc.) never create DB connection rows, so that returned [] and the gate dropped every imported/custom model for them — the Playground dropdown showed nothing for imported models while built-in/custom models on auth providers worked. Built-in models survived because they go through providerSupportsModel(), which already has a no-auth bypass (#2798).

The custom-model gate now applies the same no-auth bypass, keeping the eligibility check (with parentProviderType) intact for auth providers.

Co-authored-by: tjengbudi <tjengbudi@users.noreply.github.com>
Co-authored-by: a2belugin <a2belugin@users.noreply.github.com>
#3462 added a process.env.COMMAND_CODE_VERSION read but did not document it,
tripping the env-doc-sync gate on the release branch (PR-merges bypass the
pre-commit check-docs-sync hook). Add the var to .env.example + ENVIRONMENT.md.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Integrated into release/v3.8.17
CHANGELOG: 8 features, 15 bug fixes, 6 maintenance entries (29 bullets / 32 commits since v3.8.16).
i18n: sync [3.8.17] section to all 41 locale CHANGELOG files.

fix(translator): strip empty reasoning_content on non-tool-call kimi-k2 messages (#3433 regression)
fix(translator): update placeholder assertion for non-empty cache-miss behaviour (test alignment)
fix(executor): lmarena.ts return wrapper shape {response,url,headers,transformedBody} (#3421 regression)
test: align lmarena-provider + tool-request-sanitization to corrected executor contract
Comment thread open-sse/executors/lmarena.ts Dismissed
@diegosouzapw
diegosouzapw merged commit 6ebc493 into main Jun 9, 2026
7 of 8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.