Skip to content

fix(review): resolve findings from /review-reviews battery (v3.8.21 hardening) - #3618

Merged
diegosouzapw merged 3 commits into
release/v3.8.21from
fix/review-reviews-v3821-battery
Jun 11, 2026
Merged

diegosouzapw merged 3 commits into
release/v3.8.21from
fix/review-reviews-v3821-battery

Conversation

@diegosouzapw

Copy link
Copy Markdown
Owner

Pre-release hardening from the /review-reviews multi-reviewer battery (7 Opus reviewers at max effort) over release/v3.8.21 vs main. Zero blocker / zero high — these are the confirmed medium/low/nit findings, each fixed under the Hard Rule #18 validation gate (TDD or live verification).

Resolved (LEDGER ids)

id Sev Fix
L1 med npm tarball no longer ships co-located test files — files[] negations (!**/__tests__/**, !**/*.test.*, !**/*.spec.*; 1615→1573 files, 42 test files dropped) + reconciled .npmignore; the #3578 closure gate now asserts the real npm pack --dry-run output in both directions (closure present + zero test files).
L2 med getSanitizedCachedProviderLimitsMap scopes its connection scan to antigravity/agy (skips it for an empty cache) instead of decrypting every active connection on each dashboard poll. Output proven identical.
L3 med DB-seeded regression pinning the Antigravity usage_history fallback model-id join (quotaSource flips to localUsageHistory).
L4 low gemini→openai: a signed native functionCall arriving while a textual <thinking> wrapper is still buffered now flushes that reasoning to reasoning_content before the tool call instead of dropping it (+ convergence follow-up: clear the partial open-tag fragment too).
L5 low toClientAntigravityQuotaModelId centralized in antigravityModelAliases.ts (was an inline if-ladder in usage.ts), documenting the dual meaning of gemini-3.5-flash-low in the upstream quota namespace.
L6 low checkIdempotencyCache returns { hit, idempotencyKey } so the Phase 9.2 save site reuses a single key derivation; new tests pin sanitizeChatRequestBody + the idempotency check at the chatCore extraction seam.
L7 low test: the unclosed-reasoning-tag heuristic preserves a real visible prefix and does not capture <thoughtful>-style non-tags.
L8 low /v1/completions SSE branch drops a stale upstream content-length after rewrite (the JSON branch already did).
L9 low test: the Antigravity SSE markdown extraction branch (exported processAntigravitySSEPayload @internal).
L10 low dropped 4 vacuous *ConfigId asserts (fields the executor never sets) for a real request.contents assert.
L11 nit upstream-ca/test "no-persist" test now asserts the persisted CA-path file is never written (was tautological).
L12/L13 nit trailing newline in semanticCache.ts; stray blank line in usageHistory.ts.
L15 low test: a partial textual tool call survives a reasoning-only chunk interruption.

Acknowledged / WONTFIX

Validation

  • lint 0 errors · typecheck:core clean · test:vitest 146/146 · build ✓ (525 pages)
  • test:unit: the pre-existing cycle drift (3× chatcore-translation-paths [BUG] Valid max_tokens-truncated response misclassified as "empty content" → fake 502 #3572 + 6 others) is identical at baseline 797de433f — this work adds zero new failures; all new/changed suites green.
  • Convergence re-review (3 Opus reviewers over the fix diff): 0 masking tests, L2/L5/L6 equivalences proven, RISK1 (files[] negation) & RISK2 (idempotency scope) safe, L14 WONTFIX justified; 1 low finding (partial open-tag buffer) fixed in commit 3.

🤖 Generated with Claude Code

…ews battery

Pre-release hardening from the /review-reviews multi-reviewer battery over
release/v3.8.21 vs main (7 Opus reviewers). Zero blocker/high; these are the
confirmed medium/low/nit findings.

- LEDGER-1 (npm publish surface): files[] now negates **/__tests__/ + *.test.*/
  *.spec.* so co-located tests never ship (1615->1573 files, 42 test files
  dropped); .npmignore reconciled with a precedence note; the #3578 closure test
  now asserts the REAL
> omniroute@3.8.21 prepare
> husky

omniroute-3.8.21.tgz output in both directions.
- LEDGER-2 (perf): getSanitizedCachedProviderLimitsMap scopes the connection scan
  to antigravity/agy (and skips it for an empty cache) instead of decrypting every
  active connection on each dashboard poll. Output is identical.
- LEDGER-4 (correctness): a signed native functionCall arriving while a textual
  <thinking> wrapper is still buffered now flushes that reasoning as
  reasoning_content instead of dropping it.
- LEDGER-5 (maintainability): toClientAntigravityQuotaModelId centralized in
  antigravityModelAliases.ts (was an inline if-ladder in usage.ts), documenting the
  dual meaning of gemini-3.5-flash-low in the upstream quota namespace.
- LEDGER-8 (correctness): /v1/completions SSE branch drops stale content-length
  after rewrite, mirroring the JSON branch.
- LEDGER-10/11 (test quality): drop 4 vacuous *ConfigId asserts; upstream-ca/test
  no-persist test now asserts the persisted path file is never written.
- LEDGER-12/13 (style): trailing newline in semanticCache.ts; remove stray blank
  line in usageHistory.ts.
- LEDGER-15 (test): pin recovery of a partial textual tool call interrupted by a
  reasoning-only chunk.

Tests: all affected suites green (TDD RED verified for LEDGER-4).
…eviews battery

Second batch of the /review-reviews hardening (part 2 of 2).

- LEDGER-5 (maintainability): centralize toClientAntigravityQuotaModelId in
  antigravityModelAliases.ts (was an inline if-ladder in usage.ts), documenting
  the dual meaning of gemini-3.5-flash-low in the upstream quota namespace; shared
  with the provider-limits cache sanitizer. (impl was in part 1; this adds the test)
- LEDGER-6 (test-gap + maintainability): checkIdempotencyCache now returns
  { hit, idempotencyKey } so the Phase 9.2 save site reuses a single key derivation
  instead of re-deriving it; new unit tests pin sanitizeChatRequestBody (token-field
  normalization, empty-name stripping, tool filtering) and checkIdempotencyCache
  (miss/hit/null-key) at the chatCore extraction seam.
- LEDGER-3 (test): DB-seeded regression proving the Antigravity local-usage fallback
  flips quotaSource to localUsageHistory when usage_history has a row keyed by the
  client tier id (and stays fetchAvailableModels when it does not) — pins the model-id
  join contract #3604 relies on.
- LEDGER-7 (test): pin that the unclosed-reasoning-tag heuristic preserves a real
  visible prefix and does not capture <thoughtful>-style non-tags.
- LEDGER-9 (test): export processAntigravitySSEPayload (@internal) and pin the
  Antigravity SSE markdown extraction branch.
- LEDGER-14 (DISCUSS → WONTFIX, live-verified): probed retrieveUserQuota with a real
  agy consumer token — the non-daily cloudcode-pa host ACCEPTS it (429 RESOURCE_EXHAUSTED,
  an authenticated response; identical on daily-* host), so #3604 is NOT agy-host-limited.
  No code change.
- LEDGER-16..20: ACK/WONTFIX (justified in the review ledger).

Validation: lint 0 errors; typecheck:core clean; test:vitest 146/146; all new/changed
suites green. Full test:unit pre-existing drift (chatcore-translation-paths #3572 + 6
others) confirmed identical at baseline 797de43 — zero new failures from this work.
…nvergence)

Convergence re-review (round 2) of the LEDGER-4 fix found that
flushOpenTextualReasoning early-returns when ONLY textualReasoningTagBuffer
(a partial open-tag fragment buffered at a chunk boundary) is set — leaving it
stale, whereas the pre-fix branch cleared all three buffers unconditionally.
Explicitly clear it in the functionCall branch so behavior matches the original
(plus the new reasoning flush). Translator suite 31/31 green.
@gemini-code-assist

Copy link
Copy Markdown
Contributor

Warning

You have reached your daily quota limit. Please wait up to 24 hours and I will start processing your requests again!

@diegosouzapw
diegosouzapw merged commit c2d9022 into release/v3.8.21 Jun 11, 2026
2 checks passed
@kilo-code-bot

kilo-code-bot Bot commented Jun 11, 2026 •

Copy link
Copy Markdown

Code Review Summary

Status: No Issues Found | Recommendation: Merge

Files Reviewed (14 files)
  • .npmignore — reconciled with package.json files[] negations
  • CHANGELOG.md — updated release notes
  • open-sse/config/antigravityModelAliases.ts — centralized quota-bucket remap
  • open-sse/executors/antigravity.ts — exported for unit tests
  • open-sse/handlers/chatCore.ts — removed redundant idempotency key derivation
  • open-sse/handlers/chatCore/idempotency.ts — returns idempotencyKey alongside hit
  • open-sse/handlers/chatCore/semanticCache.ts — trailing newline fix
  • open-sse/services/usage.ts — removed duplicated quota remap
  • open-sse/translator/response/gemini-to-openai.ts — flush buffered reasoning before tool calls
  • package.json — added test-file exclusion negations
  • src/app/api/v1/completions/contentCompletionTransform.ts — drops stale content-length
  • src/lib/usage/providerLimits.ts — scope connection scan to antigravity/agy only
  • tests/unit/antigravity-local-usage-fallback-3821.test.ts — new
  • tests/unit/antigravity-model-aliases.test.ts — new test for quota remap
  • tests/unit/chatcore-extracted-modules-3821.test.ts — new
  • tests/unit/completions-text-format-3571.test.ts — new content-length tests
  • tests/unit/executor-agy.test.ts — new markdown-extraction tests
  • tests/unit/mcp-published-files-closure-3578.test.ts — new dual-direction npm pack gate
  • tests/unit/provider-limits-sanitize-scope-3821.test.ts — new
  • tests/unit/response-sanitizer.test.ts — new reasoning-prefix tests
  • tests/unit/translator-resp-gemini-to-openai.test.ts — new flush-before-toolcall tests

Reviewed by step-3.7-flash-20260528 · 1,105,670 tokens

@diegosouzapw
diegosouzapw deleted the fix/review-reviews-v3821-battery branch June 11, 2026 05:50
diegosouzapw added a commit that referenced this pull request Jun 11, 2026
* chore(release): open v3.8.21 development cycle

* fix: pass through valid max_tokens-truncated responses instead of fake 502 (#3572) (#3595)

* fix: /v1/completions returns legacy text-completion format, not chat (#3571) (#3596)

* fix: z.ai/GLM coding plan no longer shows Monthly 0% when no monthly cap (#3580) (#3597)

* docs: mark DISCOVERY_TOOL_DESIGN endpoints as Phase-2 not-yet-implemented (#3498) (#3599)

* fix(agent-bridge): add validate-only upstream-ca/test route (#3488) (#3600)

* fix(gamification): add level/badges/badges-earned profile routes (#3484)

* security(oauth): migrate 5 public client_ids to resolvePublicCred (#3493)

* fix(mcp): ship MCP server source closure in npm files + coverage gate (#3578)

* fix: add reasoning token buffer for combo routing (fixes #3587) (#3588)

Integrated into release/v3.8.21

* Refactor: Extract chatCore phases into modular files (#3598)

Integrated into release/v3.8.21 — chatCore phase modularization. Adjusted: re-derive idempotencyKey for the save path after the check moved into the module (co-authored). Thanks @oyi77!

* docs(changelog): credit #3598 (chatCore modularization) + #3588 (combo reasoning buffer)

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* fix(api): implement GET /api/guardrails + POST /api/guardrails/test, drop shadow/guardrails doc-fiction (#3496) (#3602)

Integrated into release/v3.8.21 — implements GET /api/guardrails + POST /api/guardrails/test, removes shadow/guardrails doc-fiction. TDD-validated (5/5) + check-docs-symbols/typecheck/eslint green.

* fix(gemini): isolate textual reasoning wrappers (#3605)

Split-out PR C from #3584. Isolates textual reasoning wrappers (<think>/<thinking>/<thought>/<internal_thought>, including malformed/open tags) into reasoning_content across both the non-streaming sanitizer and the Gemini streaming translator, with split-chunk buffering. Additive to the existing textual tool-call pipeline; does not touch the #3569 native functionResponse path. Integrated into release/v3.8.21. Thanks @dhaern!

* fix(antigravity): normalize Gemini 3.5 Flash tier IDs (#3603)

Split-out PR A from #3584. Normalizes the Antigravity/agy Gemini 3.5 Flash tier IDs to clean public names (gemini-3.5-flash-low/medium/high), maps them to the live upstream IDs at the executor boundary, and removes Antigravity from the global model resolver so the executor owns wire normalization. Maintainer follow-up: kept gemini-3.5-flash-preview as a hidden backward-compat alias routing to the High tier (so saved combos/configs keep working). Live-validated the tier set via the agy CLI catalog. Integrated into release/v3.8.21. Thanks @dhaern!

* fix(agent-bridge): surface real MITM startup-failure cause, not always port 443 (#3606) (#3608)

Integrated into release/v3.8.21 (#3606)

* fix(oauth): surface real Kiro import-token failure cause, not a bare 500 (#3589) (#3609)

Integrated into release/v3.8.21 (#3589)

* docs(opencode-provider): soft-deprecate in favor of @omniroute/opencode-plugin (#3419) (#3613)

Integrated into release/v3.8.21 (#3419)

* fix(usage): normalize Antigravity and agy provider quotas (#3604)

Split-out PR B from #3584. Normalizes Antigravity/agy provider quotas: prefers retrieveUserQuota for live consumption, falls back to fetchAvailableModels and local usage_history, sanitizes cached Provider Limits so retired upstream IDs are not re-exposed, and schedules a deduplicated post-usage refresh. Maintainer follow-up: decoupled the post-usage refresh via a lightweight usageEvents bus (usageHistory no longer dynamic-imports providerLimits) so it does not pull the executors/translator graph into the typecheck-core surface — typecheck:core stays at 0. Integrated into release/v3.8.21. Thanks @dhaern!

* feat(cli): add autostart on/off/toggle shorthand for headless serve mode (#3331) (#3614)

Integrated into release/v3.8.21 (#3331)

* docs(changelog): credit #3603 (Flash tier IDs) + #3604 (provider quotas) + #3605 (reasoning wrappers)

Co-authored-by: diegosouzapw <diegosouza.pw@gmail.com>

* fix(review): resolve findings from /review-reviews battery (v3.8.21 hardening) (#3618)

Pre-release hardening from the /review-reviews battery — 15 findings resolved (L1-L13,L15) + L14 live-verified WONTFIX, convergence re-review clean. lint/typecheck:core/test:vitest(146)/build green; zero new test:unit failures vs baseline 797de43.

* chore(release): v3.8.21 CHANGELOG + i18n + env-doc sync

---------

Co-authored-by: Hernan Javier Ardila Sanchez <hjasgr@gmail.com>
Co-authored-by: Paijo <14921983+oyi77@users.noreply.github.com>
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
Co-authored-by: Raxxoor <manker_lol@hotmail.com>
HouMinXi pushed a commit to HouMinXi/OmniRoute that referenced this pull request Aug 2, 2026
* chore(release): open v3.8.21 development cycle

* fix: pass through valid max_tokens-truncated responses instead of fake 502 (diegosouzapw#3572) (diegosouzapw#3595)

* fix: /v1/completions returns legacy text-completion format, not chat (diegosouzapw#3571) (diegosouzapw#3596)

* fix: z.ai/GLM coding plan no longer shows Monthly 0% when no monthly cap (diegosouzapw#3580) (diegosouzapw#3597)

* docs: mark DISCOVERY_TOOL_DESIGN endpoints as Phase-2 not-yet-implemented (diegosouzapw#3498) (diegosouzapw#3599)

* fix(agent-bridge): add validate-only upstream-ca/test route (diegosouzapw#3488) (diegosouzapw#3600)

* fix(gamification): add level/badges/badges-earned profile routes (diegosouzapw#3484)

* security(oauth): migrate 5 public client_ids to resolvePublicCred (diegosouzapw#3493)

* fix(mcp): ship MCP server source closure in npm files + coverage gate (diegosouzapw#3578)

* fix: add reasoning token buffer for combo routing (fixes diegosouzapw#3587) (diegosouzapw#3588)

Integrated into release/v3.8.21

* Refactor: Extract chatCore phases into modular files (diegosouzapw#3598)

Integrated into release/v3.8.21 — chatCore phase modularization. Adjusted: re-derive idempotencyKey for the save path after the check moved into the module (co-authored). Thanks @oyi77!

* docs(changelog): credit diegosouzapw#3598 (chatCore modularization) + diegosouzapw#3588 (combo reasoning buffer)

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* fix(api): implement GET /api/guardrails + POST /api/guardrails/test, drop shadow/guardrails doc-fiction (diegosouzapw#3496) (diegosouzapw#3602)

Integrated into release/v3.8.21 — implements GET /api/guardrails + POST /api/guardrails/test, removes shadow/guardrails doc-fiction. TDD-validated (5/5) + check-docs-symbols/typecheck/eslint green.

* fix(gemini): isolate textual reasoning wrappers (diegosouzapw#3605)

Split-out PR C from diegosouzapw#3584. Isolates textual reasoning wrappers (<think>/<thinking>/<thought>/<internal_thought>, including malformed/open tags) into reasoning_content across both the non-streaming sanitizer and the Gemini streaming translator, with split-chunk buffering. Additive to the existing textual tool-call pipeline; does not touch the diegosouzapw#3569 native functionResponse path. Integrated into release/v3.8.21. Thanks @dhaern!

* fix(antigravity): normalize Gemini 3.5 Flash tier IDs (diegosouzapw#3603)

Split-out PR A from diegosouzapw#3584. Normalizes the Antigravity/agy Gemini 3.5 Flash tier IDs to clean public names (gemini-3.5-flash-low/medium/high), maps them to the live upstream IDs at the executor boundary, and removes Antigravity from the global model resolver so the executor owns wire normalization. Maintainer follow-up: kept gemini-3.5-flash-preview as a hidden backward-compat alias routing to the High tier (so saved combos/configs keep working). Live-validated the tier set via the agy CLI catalog. Integrated into release/v3.8.21. Thanks @dhaern!

* fix(agent-bridge): surface real MITM startup-failure cause, not always port 443 (diegosouzapw#3606) (diegosouzapw#3608)

Integrated into release/v3.8.21 (diegosouzapw#3606)

* fix(oauth): surface real Kiro import-token failure cause, not a bare 500 (diegosouzapw#3589) (diegosouzapw#3609)

Integrated into release/v3.8.21 (diegosouzapw#3589)

* docs(opencode-provider): soft-deprecate in favor of @omniroute/opencode-plugin (diegosouzapw#3419) (diegosouzapw#3613)

Integrated into release/v3.8.21 (diegosouzapw#3419)

* fix(usage): normalize Antigravity and agy provider quotas (diegosouzapw#3604)

Split-out PR B from diegosouzapw#3584. Normalizes Antigravity/agy provider quotas: prefers retrieveUserQuota for live consumption, falls back to fetchAvailableModels and local usage_history, sanitizes cached Provider Limits so retired upstream IDs are not re-exposed, and schedules a deduplicated post-usage refresh. Maintainer follow-up: decoupled the post-usage refresh via a lightweight usageEvents bus (usageHistory no longer dynamic-imports providerLimits) so it does not pull the executors/translator graph into the typecheck-core surface — typecheck:core stays at 0. Integrated into release/v3.8.21. Thanks @dhaern!

* feat(cli): add autostart on/off/toggle shorthand for headless serve mode (diegosouzapw#3331) (diegosouzapw#3614)

Integrated into release/v3.8.21 (diegosouzapw#3331)

* docs(changelog): credit diegosouzapw#3603 (Flash tier IDs) + diegosouzapw#3604 (provider quotas) + diegosouzapw#3605 (reasoning wrappers)

Co-authored-by: diegosouzapw <diegosouza.pw@gmail.com>

* fix(review): resolve findings from /review-reviews battery (v3.8.21 hardening) (diegosouzapw#3618)

Pre-release hardening from the /review-reviews battery — 15 findings resolved (L1-L13,L15) + L14 live-verified WONTFIX, convergence re-review clean. lint/typecheck:core/test:vitest(146)/build green; zero new test:unit failures vs baseline 6d24708.

* chore(release): v3.8.21 CHANGELOG + i18n + env-doc sync

---------

Co-authored-by: Hernan Javier Ardila Sanchez <hjasgr@gmail.com>
Co-authored-by: Paijo <14921983+oyi77@users.noreply.github.com>
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
Co-authored-by: Raxxoor <manker_lol@hotmail.com>
Poid-ZA pushed a commit to Poid-ZA/OmniRoute that referenced this pull request Aug 5, 2026
* chore(release): open v3.8.21 development cycle

* fix: pass through valid max_tokens-truncated responses instead of fake 502 (diegosouzapw#3572) (diegosouzapw#3595)

* fix: /v1/completions returns legacy text-completion format, not chat (diegosouzapw#3571) (diegosouzapw#3596)

* fix: z.ai/GLM coding plan no longer shows Monthly 0% when no monthly cap (diegosouzapw#3580) (diegosouzapw#3597)

* docs: mark DISCOVERY_TOOL_DESIGN endpoints as Phase-2 not-yet-implemented (diegosouzapw#3498) (diegosouzapw#3599)

* fix(agent-bridge): add validate-only upstream-ca/test route (diegosouzapw#3488) (diegosouzapw#3600)

* fix(gamification): add level/badges/badges-earned profile routes (diegosouzapw#3484)

* security(oauth): migrate 5 public client_ids to resolvePublicCred (diegosouzapw#3493)

* fix(mcp): ship MCP server source closure in npm files + coverage gate (diegosouzapw#3578)

* fix: add reasoning token buffer for combo routing (fixes diegosouzapw#3587) (diegosouzapw#3588)

Integrated into release/v3.8.21

* Refactor: Extract chatCore phases into modular files (diegosouzapw#3598)

Integrated into release/v3.8.21 — chatCore phase modularization. Adjusted: re-derive idempotencyKey for the save path after the check moved into the module (co-authored). Thanks @oyi77!

* docs(changelog): credit diegosouzapw#3598 (chatCore modularization) + diegosouzapw#3588 (combo reasoning buffer)

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* fix(api): implement GET /api/guardrails + POST /api/guardrails/test, drop shadow/guardrails doc-fiction (diegosouzapw#3496) (diegosouzapw#3602)

Integrated into release/v3.8.21 — implements GET /api/guardrails + POST /api/guardrails/test, removes shadow/guardrails doc-fiction. TDD-validated (5/5) + check-docs-symbols/typecheck/eslint green.

* fix(gemini): isolate textual reasoning wrappers (diegosouzapw#3605)

Split-out PR C from diegosouzapw#3584. Isolates textual reasoning wrappers (<think>/<thinking>/<thought>/<internal_thought>, including malformed/open tags) into reasoning_content across both the non-streaming sanitizer and the Gemini streaming translator, with split-chunk buffering. Additive to the existing textual tool-call pipeline; does not touch the diegosouzapw#3569 native functionResponse path. Integrated into release/v3.8.21. Thanks @dhaern!

* fix(antigravity): normalize Gemini 3.5 Flash tier IDs (diegosouzapw#3603)

Split-out PR A from diegosouzapw#3584. Normalizes the Antigravity/agy Gemini 3.5 Flash tier IDs to clean public names (gemini-3.5-flash-low/medium/high), maps them to the live upstream IDs at the executor boundary, and removes Antigravity from the global model resolver so the executor owns wire normalization. Maintainer follow-up: kept gemini-3.5-flash-preview as a hidden backward-compat alias routing to the High tier (so saved combos/configs keep working). Live-validated the tier set via the agy CLI catalog. Integrated into release/v3.8.21. Thanks @dhaern!

* fix(agent-bridge): surface real MITM startup-failure cause, not always port 443 (diegosouzapw#3606) (diegosouzapw#3608)

Integrated into release/v3.8.21 (diegosouzapw#3606)

* fix(oauth): surface real Kiro import-token failure cause, not a bare 500 (diegosouzapw#3589) (diegosouzapw#3609)

Integrated into release/v3.8.21 (diegosouzapw#3589)

* docs(opencode-provider): soft-deprecate in favor of @omniroute/opencode-plugin (diegosouzapw#3419) (diegosouzapw#3613)

Integrated into release/v3.8.21 (diegosouzapw#3419)

* fix(usage): normalize Antigravity and agy provider quotas (diegosouzapw#3604)

Split-out PR B from diegosouzapw#3584. Normalizes Antigravity/agy provider quotas: prefers retrieveUserQuota for live consumption, falls back to fetchAvailableModels and local usage_history, sanitizes cached Provider Limits so retired upstream IDs are not re-exposed, and schedules a deduplicated post-usage refresh. Maintainer follow-up: decoupled the post-usage refresh via a lightweight usageEvents bus (usageHistory no longer dynamic-imports providerLimits) so it does not pull the executors/translator graph into the typecheck-core surface — typecheck:core stays at 0. Integrated into release/v3.8.21. Thanks @dhaern!

* feat(cli): add autostart on/off/toggle shorthand for headless serve mode (diegosouzapw#3331) (diegosouzapw#3614)

Integrated into release/v3.8.21 (diegosouzapw#3331)

* docs(changelog): credit diegosouzapw#3603 (Flash tier IDs) + diegosouzapw#3604 (provider quotas) + diegosouzapw#3605 (reasoning wrappers)

Co-authored-by: diegosouzapw <diegosouza.pw@gmail.com>

* fix(review): resolve findings from /review-reviews battery (v3.8.21 hardening) (diegosouzapw#3618)

Pre-release hardening from the /review-reviews battery — 15 findings resolved (L1-L13,L15) + L14 live-verified WONTFIX, convergence re-review clean. lint/typecheck:core/test:vitest(146)/build green; zero new test:unit failures vs baseline 797de43.

* chore(release): v3.8.21 CHANGELOG + i18n + env-doc sync

---------

Co-authored-by: Hernan Javier Ardila Sanchez <hjasgr@gmail.com>
Co-authored-by: Paijo <14921983+oyi77@users.noreply.github.com>
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
Co-authored-by: Raxxoor <manker_lol@hotmail.com>
tkgo11 pushed a commit to tkgo11/OmniRoute that referenced this pull request Sep 23, 2026
…ardening) (diegosouzapw#3618)

Pre-release hardening from the /review-reviews battery — 15 findings resolved (L1-L13,L15) + L14 live-verified WONTFIX, convergence re-review clean. lint/typecheck:core/test:vitest(146)/build green; zero new test:unit failures vs baseline 6d24708.
muhamadgalihsaputra pushed a commit to niyatna/NiyatnaRoute that referenced this pull request Sep 27, 2026
* chore(release): open v3.8.21 development cycle

* fix: pass through valid max_tokens-truncated responses instead of fake 502 (diegosouzapw#3572) (diegosouzapw#3595)

* fix: /v1/completions returns legacy text-completion format, not chat (diegosouzapw#3571) (diegosouzapw#3596)

* fix: z.ai/GLM coding plan no longer shows Monthly 0% when no monthly cap (diegosouzapw#3580) (diegosouzapw#3597)

* docs: mark DISCOVERY_TOOL_DESIGN endpoints as Phase-2 not-yet-implemented (diegosouzapw#3498) (diegosouzapw#3599)

* fix(agent-bridge): add validate-only upstream-ca/test route (diegosouzapw#3488) (diegosouzapw#3600)

* fix(gamification): add level/badges/badges-earned profile routes (diegosouzapw#3484)

* security(oauth): migrate 5 public client_ids to resolvePublicCred (diegosouzapw#3493)

* fix(mcp): ship MCP server source closure in npm files + coverage gate (diegosouzapw#3578)

* fix: add reasoning token buffer for combo routing (fixes diegosouzapw#3587) (diegosouzapw#3588)

Integrated into release/v3.8.21

* Refactor: Extract chatCore phases into modular files (diegosouzapw#3598)

Integrated into release/v3.8.21 — chatCore phase modularization. Adjusted: re-derive idempotencyKey for the save path after the check moved into the module (co-authored). Thanks @oyi77!

* docs(changelog): credit diegosouzapw#3598 (chatCore modularization) + diegosouzapw#3588 (combo reasoning buffer)

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* fix(api): implement GET /api/guardrails + POST /api/guardrails/test, drop shadow/guardrails doc-fiction (diegosouzapw#3496) (diegosouzapw#3602)

Integrated into release/v3.8.21 — implements GET /api/guardrails + POST /api/guardrails/test, removes shadow/guardrails doc-fiction. TDD-validated (5/5) + check-docs-symbols/typecheck/eslint green.

* fix(gemini): isolate textual reasoning wrappers (diegosouzapw#3605)

Split-out PR C from diegosouzapw#3584. Isolates textual reasoning wrappers (<think>/<thinking>/<thought>/<internal_thought>, including malformed/open tags) into reasoning_content across both the non-streaming sanitizer and the Gemini streaming translator, with split-chunk buffering. Additive to the existing textual tool-call pipeline; does not touch the diegosouzapw#3569 native functionResponse path. Integrated into release/v3.8.21. Thanks @dhaern!

* fix(antigravity): normalize Gemini 3.5 Flash tier IDs (diegosouzapw#3603)

Split-out PR A from diegosouzapw#3584. Normalizes the Antigravity/agy Gemini 3.5 Flash tier IDs to clean public names (gemini-3.5-flash-low/medium/high), maps them to the live upstream IDs at the executor boundary, and removes Antigravity from the global model resolver so the executor owns wire normalization. Maintainer follow-up: kept gemini-3.5-flash-preview as a hidden backward-compat alias routing to the High tier (so saved combos/configs keep working). Live-validated the tier set via the agy CLI catalog. Integrated into release/v3.8.21. Thanks @dhaern!

* fix(agent-bridge): surface real MITM startup-failure cause, not always port 443 (diegosouzapw#3606) (diegosouzapw#3608)

Integrated into release/v3.8.21 (diegosouzapw#3606)

* fix(oauth): surface real Kiro import-token failure cause, not a bare 500 (diegosouzapw#3589) (diegosouzapw#3609)

Integrated into release/v3.8.21 (diegosouzapw#3589)

* docs(opencode-provider): soft-deprecate in favor of @omniroute/opencode-plugin (diegosouzapw#3419) (diegosouzapw#3613)

Integrated into release/v3.8.21 (diegosouzapw#3419)

* fix(usage): normalize Antigravity and agy provider quotas (diegosouzapw#3604)

Split-out PR B from diegosouzapw#3584. Normalizes Antigravity/agy provider quotas: prefers retrieveUserQuota for live consumption, falls back to fetchAvailableModels and local usage_history, sanitizes cached Provider Limits so retired upstream IDs are not re-exposed, and schedules a deduplicated post-usage refresh. Maintainer follow-up: decoupled the post-usage refresh via a lightweight usageEvents bus (usageHistory no longer dynamic-imports providerLimits) so it does not pull the executors/translator graph into the typecheck-core surface — typecheck:core stays at 0. Integrated into release/v3.8.21. Thanks @dhaern!

* feat(cli): add autostart on/off/toggle shorthand for headless serve mode (diegosouzapw#3331) (diegosouzapw#3614)

Integrated into release/v3.8.21 (diegosouzapw#3331)

* docs(changelog): credit diegosouzapw#3603 (Flash tier IDs) + diegosouzapw#3604 (provider quotas) + diegosouzapw#3605 (reasoning wrappers)

Co-authored-by: diegosouzapw <diegosouza.pw@gmail.com>

* fix(review): resolve findings from /review-reviews battery (v3.8.21 hardening) (diegosouzapw#3618)

Pre-release hardening from the /review-reviews battery — 15 findings resolved (L1-L13,L15) + L14 live-verified WONTFIX, convergence re-review clean. lint/typecheck:core/test:vitest(146)/build green; zero new test:unit failures vs baseline 408d91a2c.

* chore(release): v3.8.21 CHANGELOG + i18n + env-doc sync

---------

Co-authored-by: Hernan Javier Ardila Sanchez <hjasgr@gmail.com>
Co-authored-by: Paijo <14921983+oyi77@users.noreply.github.com>
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
Co-authored-by: Raxxoor <manker_lol@hotmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant