Skip to content

fix(restore): restore 77 deleted files from git history - #5910

Closed
KooshaPari wants to merge 203 commits into
diegosouzapw:mainfrom
KooshaPari:fix/restore-missing-files
Closed

KooshaPari wants to merge 203 commits into
diegosouzapw:mainfrom
KooshaPari:fix/restore-missing-files

Conversation

@KooshaPari

Copy link
Copy Markdown
Contributor

Restores source files dropped by botched upstream merge cb43b60. All files recovered from git history.

Wave 1 (9 files, already merged #189): wildcardRouter, cors, errorResponse, compressionCacheStats, reasoningCache, logPayloads, batchEndpoints, modelCompat, apiKey

Wave 2 (19 files): claudeCode{CCH,Obfuscation,Fingerprint,ExtraRemap}, runtimeHeartbeat, memoryTools, mcp-server/schemas/audit, translator/formats, utils/urlSanitize, config/defaultThinkingSignature, compression/ultraHeuristic, db/{quotaSnapshots,syncTokens,upstreamProxy}, combos/steps, spend/batchWriter, lib/ipUtils, shared/utils/requestId, lib/cacheControlSettings, server/cors/origins, lib/pricingSync, shared/contracts/quota, shared/utils/resolveOmniRouteBaseUrl, lib/skills/executor, lib/oauth/gitlab

Wave 3 (44 files): open-sse services (antigravity, autoCombo, backgroundTaskDetector, bailian, comboAgentMiddleware, compression/cachingAware, errorClassifier, modelCapabilities, modelDeprecation, payloadRules, quotaMonitor, sessionManager), open-sse utils (cacheControlPolicy, streamPayloadCollector), domain modules (connectionModelRules, omnirouteResponseMeta, quotaCache, tagRouter), DB (creditBalance, providerLimits), display/names, memory/{retrieval,types}, piiSanitizer, plugins/index, skills/{schemas,types}, usage/tokenAccounting, usageDb, shared/constants/{comboConfigMode,upstreamHeaders}, shared/utils/{logger,maskEmail,shuffleDeck}, sse/services/cooldownAwareRetry, sse/utils/logger, types/{apiKey,provider,usage}

Fixes: typecheck:core 88 errors → ~20, unblocks revive-140 and revive-143

KooshaPari and others added 30 commits May 2, 2026 05:32
…el family (#1)

- Add 'invalid argument' to MODEL_UNAVAILABLE_FRAGMENTS so Antigravity 400
  errors on claude-opus-4-6-thinking trigger automatic fallback to
  claude-opus-4-6 or claude-opus-4-5-20251101
- Add NVIDIA Minimax model family for cross-model fallback when minimax-m2.7
  or minimax-m2.5 returns model-unavailable errors (404 Function not found)
* chore: add trufflehog ignore file [skip ci]

* chore: add trufflehog secrets scanning config [skip ci]
* chore(OmniRoute): add packageManager field

* chore(OmniRoute): add packageManager field

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* fix(tsconfig): enable strict mode in OmniRoute

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* fix(tsconfig): enable strict mode in OmniRoute

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* fix(tsconfig): enable strict mode in OmniRoute

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* fix(tsconfig): enable strict mode and related flags in OmniRoute

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* fix(tsconfig): enable strict mode and related flags in OmniRoute

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* fix(tsconfig): enable strict mode in OmniRoute

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* fix(tsconfig): enable strict mode in OmniRoute

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* chore(OmniRoute): add benchmarks and test scaffolding

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* docs(omniroute): add sladge badge evidence

Co-authored-by: Codex <noreply@openai.com>

* fix(omniroute): align benchmark tests with correct test runner

Convert benchmarks.test.ts from Vitest globals to node:test/assert API so
it runs correctly under node --test (used by both test:unit and test:benchmarks).

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* chore: add missing governance files

* chore: pin trufflehog action to SHA

---------

Co-authored-by: Claude Opus 4.7 <noreply@anthropic.com>
Co-authored-by: Codex <noreply@openai.com>
Conflict resolution: accepted upstream version for all conflicting files.
Local agent-specific customizations in .agents/workflows/ and i18n docs
were removed in favor of upstream's evolved versions.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
Resolved conflicts by accepting origin/main version for:
- README.md, package.json (fork-specific content)
- src/lib/benchmarks.ts, tsconfig.json (deleted per upstream)

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
Adds cancel-in-progress concurrency groups to:
- build-fork.yml
- claude.yml
- docker-publish.yml
- electron-release.yml
- lock-released-branch.yml
- npm-publish.yml

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
- Replace ubuntu-latest with ubuntu-24.04 across all jobs
- Upgrade actions/checkout@v4 → v6 in opencode-plugin-ci.yml and opencode-provider-ci.yml
- Upgrade actions/setup-node@v4 → v6 in opencode-plugin-ci.yml
- Replace ubuntu-latest with ubuntu-24.04 across all jobs
- Upgrade actions/checkout@v4 → v6 in opencode-plugin-ci.yml and opencode-provider-ci.yml
- Upgrade actions/setup-node@v4 → v6 in opencode-plugin-ci.yml
- Replace ubuntu-latest with ubuntu-24.04 across all jobs
- Upgrade actions/checkout@v4 → v6 in opencode-plugin-ci.yml and opencode-provider-ci.yml
- Upgrade actions/setup-node@v4 → v6 in opencode-plugin-ci.yml
- Replace ubuntu-latest with ubuntu-24.04 across all jobs
- Upgrade actions/checkout@v4 → v6 in opencode-plugin-ci.yml and opencode-provider-ci.yml
- Upgrade actions/setup-node@v4 → v6 in opencode-plugin-ci.yml
- Replace ubuntu-latest with ubuntu-24.04 across all jobs
- Upgrade actions/checkout@v4 → v6 in opencode-plugin-ci.yml and opencode-provider-ci.yml
- Upgrade actions/setup-node@v4 → v6 in opencode-plugin-ci.yml
- Replace ubuntu-latest with ubuntu-24.04 across all jobs
- Upgrade actions/checkout@v4 → v6 in opencode-plugin-ci.yml and opencode-provider-ci.yml
- Upgrade actions/setup-node@v4 → v6 in opencode-plugin-ci.yml
- Replace ubuntu-latest with ubuntu-24.04 across all jobs
- Upgrade actions/checkout@v4 → v6 in opencode-plugin-ci.yml and opencode-provider-ci.yml
- Upgrade actions/setup-node@v4 → v6 in opencode-plugin-ci.yml
- Replace ubuntu-latest with ubuntu-24.04 across all jobs
- Upgrade actions/checkout@v4 → v6 in opencode-plugin-ci.yml and opencode-provider-ci.yml
- Upgrade actions/setup-node@v4 → v6 in opencode-plugin-ci.yml
- Replace ubuntu-latest with ubuntu-24.04 across all jobs
- Upgrade actions/checkout@v4 → v6 in opencode-plugin-ci.yml and opencode-provider-ci.yml
- Upgrade actions/setup-node@v4 → v6 in opencode-plugin-ci.yml
ubuntu-latest is ambiguous and may advance to ubuntu-26.04 in future
runners, causing unexpected breakage. Pin explicitly to ubuntu-24.04.
The Claude Code workflow had no top-level permissions: block. Add
minimal scoped permissions (read on contents/pull-requests/issues,
write on id-token/actions) matching what the job actually needs.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
- Add upstream remote: diegosouzapw/OmniRoute (latest: v3.8.8)
- Create UPSTREAM_SYNC.md: protocol for tracking + cherry-picking upstream fixes
- Create docs/ADR-001-canonical-routing.md: decision to make OmniRoute the canonical
  routing project, rebuilt around bifrost + cliproxy

Cluster convergence plan: phenoAI/phenoRouterMonitor/Tokn/helios-router are archive
candidates pending migration into OmniRoute workspace. Source repos remain intact.

Completes STEP 10 of phenotype-registry RATIONALIZATION_PLAN.md.
Scaffold the bifrost-consuming routing core per ADR-001:
- src/domain/router/port.ts: RouterPort interface, RouteRequest/Response/Error
  types, RouterConfig with provider priority + tier overrides, DEFAULT_ROUTER_CONFIG
- src/lib/adapters/bifrostAdapter.ts: wraps bifrost OpenAI-compat HTTP gateway;
  x-provider header injection, bearer auth, fallback across priority list,
  fitnessTier overrides, listAvailableProviders + listModels
- src/lib/adapters/fakeRouterAdapter.ts: in-memory RouterPort for unit tests
  with preconfigured queue + introspectable call log
- tests/unit/bifrost-routing-core.test.ts: 20 TDD tests, all green (no live gateway)

Refs: ADR-001, feat/bifrost-routing-core

Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
…MCP walkthrough, fallback demo, architecture) (#11)
KooshaPari and others added 21 commits July 2, 2026 00:01
#150)

What
- Continuous per-provider latency / error-rate sampling with rolling
  window mean/stddev detection
- Typed playbook dispatch (force-proxy-rotation, degrade-provider,
  drop-cooldown, noop) on detected anomalies, with per-provider
  cool-off and dry-run mode
- SQLite ledger of every sample + anomaly + dispatch, with TTL prune
- Resilience tab UI for all 5 tunables (window, zThreshold, cooloff,
  minSamples, dryRun) plus master `enabled`
- Feature flag OMNIROUTE_SELF_HEALING_ENABLED (category: health,
  default: false) - default-off behaviour is unchanged
- Boot-time wiring in server-init.ts (lazy hydration, no startup cost
  when the flag is off)

Why
The auto-combo engine needs to react to transient provider degradation
without operator intervention. Phase 3 v2 replaces the static
`selfHealing.ts` (167-line grep-based exclusion list) with a
statistically-grounded detector and a typed action catalog.

Layout
- src/lib/db/migrations/100_provider_health_history.sql
- src/lib/db/providerHealthHistory.ts            (+ hash-dedup, prune)
- src/lib/db/__tests__/providerHealthHistory.test.ts
- src/lib/resilience/anomalyDetector.ts          (pure-function)
- src/lib/resilience/playbooks.ts                (typed catalog)
- src/lib/resilience/selfHealingSettings.ts      (tunables schema)
- src/lib/resilience/selfHealingManager.ts       (coordinator)
- src/lib/resilience/anomalyHook.ts              (singleton)
- src/lib/resilience/__tests__/                  (4 test files)
- src/learning/types.ts                          (shared types)
- src/app/api/resilience/route.ts                (GET/PATCH selfHealing)
- src/app/(dashboard)/dashboard/settings/components/ResilienceTab.tsx
- src/server-init.ts                             (lazy hydration)
- src/shared/constants/featureFlagDefinitions.ts (new flag)
- tests/e2e/selfHealing.test.ts                  (node:test runner)

Deviations from research dossier
- migration 097_provider_health_history.sql -> 100_ (slot 097 was
  already taken by model_intelligence)
- engine.ts was extended in src/server-init.ts (the actual boot
  entry point in this clone - engine.ts does not exist)
- xxhash hash helper was inlined (no such util module exists yet)

Docs
- docs/architecture/RESILIENCE_GUIDE.md  (new section 4)
- docs/routing/AUTO-COMBO.md             (new Self-Healing section)

Typecheck manifest tsconfig.typecheck-noimplicit-core.json updated to
include the 6 new files.
…tputs/cache_control (#174)

* docs(api): Responses API feature-coverage matrix

Maps the OpenAI Responses API surface (/v1/responses, the protocol used
by Claude Code and the Codex CLI) against OmniRoute's current
implementation. Documents which features are supported, stubbed, or
missing, with cell-by-cell links to the source file that implements
(or neglects to implement) each feature.

This audit precedes the three parity implementations in the next
commits (tool_use blocks, structured_outputs, prompt_cache_control).

* feat(transformer): tool_use blocks + structured_outputs + prompt_cache_control

Three high-leverage Claude Code / Anthropic-shaped-client parity items
implemented on the Responses API SSE transformer:

1. tool_use blocks (Anthropic-style): emits a parallel output item of
   type=tool_use with parsed input object alongside the existing
   function_call item. Auto-enabled when the request's tools[] contains
   an Anthropic-shaped entry (input_schema without Chat-style
   parameters). Opt-in via emitToolUse flag otherwise. Both items share
   the same id so clients can correlate.

2. structured_outputs (response_format): the factory accepts the
   request's response_format / output_format and surfaces it on the
   response (response.created, response.in_progress, response.completed)
   as output_format with the declared json_schema (name, schema, strict).
   This lets clients validate the emitted message content without a
   second round-trip.

3. prompt_cache_control (prompt_cache_key + usage cache tokens): the
   factory reads request.prompt_cache_key (snake_case preferred, with
   camelCase alias) and echoes it on the response. Cache-creation and
   cache-read token counts from the upstream usage envelope are
   forwarded as-is into the Responses API usage object — never
   invented, only surfaced when the upstream reports them.

Wires the new options arg through the responsesHandler so the
request body + tools[] reach the transformer. Legacy two-arg call
path remains unchanged.

* test(transformer): 42 Responses API parity tests

Comprehensive unit tests over the Responses API TransformStream. All
tests are pure — no network, no DB — and stream JSON-shaped SSE chunks
through the transformer via a small sse() helper that JSON.stringifies
a plain object and wraps it in the SSE data: ... envelope.

Coverage:
- 7 tool_use emission tests (auto, opt-in, JSON-input, invalid-JSON,
  Chat-shaped fallback, id correlation, streaming events)
- 6 structured_outputs tests (json_schema, json_object, text, default
  strict=true, strict=false, absent)
- 7 prompt_cache tests (snake_case, camelCase alias, priority,
  absence, cache_creation/cache_read passthrough, no fabrication,
  OpenAI-shaped cached_tokens)
- 22 baseline guards (response.created first, response.completed
  last, dense output, reasoning, <think>, function_call args
  streaming, keepalive, abort safety, sequence_number monotonicity,
  usage-only chunks, tools detection, error suppression, legacy
  two-arg call compatibility)
- audit.ts: full MCP audit logger with SQLite (better-sqlite3/node:sqlite dual driver)
- scopeEnforcement.ts: scope evaluation and caller context resolution
- translator/registry.ts: request translator type registry
- db/cliToolState.ts, db/prompts.ts, db/stateReset.ts: DB domain modules required by typecheck
- tsconfig.json: restore root tsconfig base (lib: dom+esnext, paths) for typecheck-core
Co-authored-by: OmniRoute Decomposition <decompose@phenotype.local>
Co-authored-by: Claude Opus 4.7 <noreply@anthropic.com>
…013) (#145)

* refactor(executors): extract userAgentHeader leaf from base.ts (PR-012)

* refactor(executors): extract mergeAbortSignals leaf from base.ts (PR-013)
Co-authored-by: kooshapari <kooshapari@users.noreply.github.com>
Co-authored-by: kooshapari <kooshapari@users.noreply.github.com>
…cord) (#98)

* fix(combos): restore deleted /api/combos routes + sanitize unknown config keys (L5-121)

The combo save routes at `src/app/api/combos/route.ts` and
`src/app/api/combos/[id]/route.ts` were deleted by `05924441a`
("chore(OmniRoute): add packageManager field") but the GUI's combos
page (`src/app/(dashboard)/dashboard/combos/page.tsx` lines 718, 746,
788, 840, 1578, 292) still issues fetch calls to `/api/combos${id}`
for create + update + delete flows. Until the GUI is migrated to the
new `/v1/combos` + `/api/combos/auto` API surface, these legacy
endpoints must remain in place.

This commit:

1. Restores `src/app/api/combos/route.ts` (GET, POST) and
   `src/app/api/combos/[id]/route.ts` (GET, PUT, DELETE), adapted to
   the current `requireManagementAuth` / `validateBody` / `isValidationFailure`
   surface and the Next.js 15 async-`params` API.

2. Restores the supporting modules the route files import:
   `src/lib/combos/steps.ts`, `src/lib/combos/compositeTiers.ts`,
   `src/shared/utils/machineId.ts`, and the missing
   `src/shared/validation/helpers.ts` (re-exports updated to return
   the error object instead of a NextResponse so route handlers can
   decide their own status + shape).

3. Exports `comboRuntimeConfigSchema` from
   `src/shared/validation/schemas.ts` so the client and server can
   both use its `.shape` to compute the set of allowed config keys.

4. Adds a `sanitizeComboRuntimeConfig` helper in each route that
   strips unknown keys from `body.config` before validation. The
   schema is `.strict()`, so any field not enumerated in the schema
   would otherwise produce a 400. This is the second 400 source
   reproduced in `tests/unit/combos-routes-regression.test.ts`.

5. Updates the client-side `sanitizeComboRuntimeConfig` in
   `src/app/(dashboard)/dashboard/combos/page.tsx` to use the same
   allowlist (so the GUI also stops sending unknown keys, instead of
   relying on the server to silently drop them).

6. Adds 13 regression tests in
   `tests/unit/combos-routes-regression.test.ts` covering the route
   export shape, toggle isActive, unknown-field config sanitization,
   zero-latency opt-in, legacy compressionOverride migration, JSON
   body parsing, missing-combo 404, full CRUD lifecycle.

Browser-side noise (MaxListenersExceededWarning: 11 close/end
listeners, ObjectMultiplex orphaned data for app-init-liveness /
background-liveness, malformed chunks) is a side-effect of the
missing routes: the SSE/control-center streams keep firing while the
PUT request gets a 404. Restoring the routes resolves the noise as
well.

* feat(bifrost): wire kill switch into BifrostBackendExecutor (B9.1)

Closes the wiring step that B9 (PR #95) deferred to post-merge.
The kill-switch state machine in open-sse/services/bifrostKillSwitch.ts
is now actually driving the Bifrost executor at execute() time, so
auto-trip thresholds (p99 latency, error rate, cost ratio) cause a
real fallback to the legacy chatCore path.

Files changed:

| File | Lines | Purpose |
|---|---|---|
| open-sse/executors/bifrost.ts | 134 | Pre-check isActive() + post recordObservation() + healthCheck short-circuit + BIFROST_KILLSWITCH_DISABLED env-bypass |
| open-sse/services/bifrostKillSwitch.ts | 49 | Add BifrostKillSwitchActiveError + BIFROST_KILLSWITCH_ACTIVE constant (stable .name for dispatcher) |
| tests/unit/bifrost-kill-switch-wiring.test.ts | 292 | 12 cases, 4 describe blocks (pre-check, post-record, env-bypass, healthCheck) |
| PLAN.md | 1 | § 2.5.2: B9.1 row added, marked DONE 2026-06-20 |
| AGENTS.md | 24 | Recent Changes (B9.1 wiring) section |

Wiring pattern (BifrostBackendExecutor.execute() public API unchanged):

1. Pre-check — after BIFROST_ENABLED and provider-support checks,
   isActive(this.provider) is consulted. If true, throw
   BifrostKillSwitchActiveError (name=BIFROST_KILLSWITCH_ACTIVE).
   The dispatcher (chatCore.ts / trafficShadow.ts) catches it and
   falls back to legacy chatCore.

2. Post-record — after fetch() returns (or throws), call
   recordObservation({ timestamp, provider, latencyMs, ok }). ok=false
   feeds the error-rate threshold; network errors record ok=false and
   rethrow.

3. healthCheck() propagation — when the per-provider kill switch is
   active, return { ok:false, error: 'kill_switch_active', latencyMs }
   before touching the network, so k8s liveness/load-balancer probes
   can short-circuit.

4. Escape hatch — BIFROST_KILLSWITCH_DISABLED=true skips both the
   pre-check throw and the post-record call. Production should leave
   this unset.

Auto-trip thresholds (per bifrostKillSwitch.ts DEFAULT_THRESHOLDS):
- maxErrorRate: 0.05 (5% error rate over sliding window)
- maxLatencyMs: 5000 (5s p99 latency)
- maxCostRatio: 2.0 (2x legacy cost)
- minSampleSize: 10 (at least 10 samples before evaluating)

Refs:
- ADR-031 (Bifrost Tier-1 router decision),
  docs/adr/0031-bifrost-tier1-router.md
- PLAN.md § 2.5.2 (B9.1 row, v8.1 task track)
- PR #95 (B9 close-out, parent commit c7ba8f4)
- L5-121 (this turn)

L5-121 / 2026-06-20

---------

Co-authored-by: KooshaPari <kooshapari@users.noreply.github.com>
…-05-06) (#99)

Upstream commit 7509a32 fixes a polynomial ReDoS in the regex used
by open-sse/services/comboAgentMiddleware.ts. In KooshaPari/OmniRoute,
that file was deleted on 2026-05-06 (commit 0592444) as part of the
v8.1 Bifrost Tier-1 router refactor (ADR-031) which superseded the
combo agent middleware path entirely.

The vulnerable regex no longer exists in this fork, so the upstream
fix is a no-op. The associated regression test (tests/unit/combo-omnimodel-tag-stripping.test.ts)
is also dropped because it imports from the deleted middleware and
would not compile in this fork.

This commit records the resolution for the security-audit trail
(ADR-042 monthly cadence).

Refs:
  - upstream:    7509a32 (diegosouzapw/OmniRoute, 2026-06)
  - KP deletion: 0592444 (KooshaPari/OmniRoute, 2026-05-06)
  - ADR-031:     docs/adr/0031-bifrost-tier1-router.md
  - ADR-042:     docs/adr/0042-security-audit-cadence.md
  - worklog:     worklogs/2026-06-21-L5-122-upstream-security-sync.md

Co-authored-by: KooshaPari <kooshapari@users.noreply.github.com>
quality-gate.yml: bind workflow_call inputs to env vars before shell
use to prevent script injection via inputs.not-applicable,
inputs.coverage-report, inputs.coverage-format, inputs.threshold.
Pattern: env: VARNAME: ${{ inputs.x }} then $VARNAME in run:.

latency-budget.yml: pin actions/github-script to full commit SHA
(f28e40c7f34bde8b3046d885e986cb6290c5673b, v7) — was unpinned @v7
tag on a workflow with pull-requests:write scope, allowing tag
mutation to execute arbitrary code with write permissions.
Co-authored-by: KooshaPari <kooshapari@users.noreply.github.com>
…r-2) (#102)

* feat(bifrost): B10 OTel bridge — Tier-1/Tier-2 unified traces

Implements B10 of the v8.1 Bifrost Tier-1 router track (PLAN.md § 2.5.2).
Unifies distributed traces between Tier-1 (Bifrost, Go) and Tier-2
(OmniRoute, TS) so a single trace crosses the HTTP boundary via W3C
traceparent.

- open-sse/observability/otelExporter.ts (NEW, 201 lines)
- open-sse/observability/traceparent.ts (NEW, 377 lines, replaces 3 hand-rolled copies)
- open-sse/observability/bifrostSpan.ts (NEW, 254 lines)
- open-sse/observability/comboSpan.ts (NEW, 175 lines)
- src/instrumentation-node.ts (PROMOTED from stub, +120 lines initOtel)
- tests/unit/otel-exporter.test.ts (NEW, 12 tests pass)
- tests/unit/traceparent.test.ts (NEW, 42 tests pass)
- tests/unit/bifrost-span.test.ts (NEW, 13 tests pass)
- tests/unit/combo-span.test.ts (NEW, 11 tests pass)
- tests/unit/instrumentation-node.test.ts (NEW, 8 tests pass)
- PLAN.md § 2.5.2 — B10 row added (DONE 2026-06-21)
- AGENTS.md — 'Recent Changes (B10)' section added

- getTracer(name: string) — returns OTel Tracer proxy (no-op if SDK not init)
- isOtelEnabled() — true iff OTEL_EXPORTER_OTLP_ENDPOINT is set and OTEL_SDK_DISABLED != true
- recordException(span, error) — standard OTel recordException

- Replaces hand-rolled traceparent logic in cursor.ts, grok-web.ts, validation.ts
- All three now import from @/open-sse/observability/traceparent

- All spans are no-ops unless OTEL_EXPORTER_OTLP_ENDPOINT is set
- initOtel() is idempotent (latch on first call); logs once on init; never blocks the request path
- SDK packages (@opentelemetry/sdk-node etc.) are NOT hard deps — dynamically imported only when env opt-in is set

Refs: ADR-031, ADR-018, PLAN.md § 2.5.2 (B10),
docs/adr/0031-bifrost-tier1-router.md, /tmp/b10-plan.md.

Test result: 86/86 pass across 5 test files.

* ci: skip root npm build when package missing

* fix(otel): wire bifrost span context

---------

Co-authored-by: KooshaPari <kooshapari@users.noreply.github.com>
…en, lock hash check, SSOT drift cron (#121)

Track T1 of the v30 71-pillar P2-lift plan. Five deliverables:

- (a) .github/inventory/fleet.json — C4 component+container model for OmniRoute
  (6 containers, 5 relationships, system context)
- (b) .github/workflows/contract_tests.yaml — CI workflow for boundary contract tests
  (triggered on PR paths: src/ open-sse/ tests/contract/)
- (c) .github/workflows/sbom-gen.yaml — CycloneDX SBOM generation CI
  (on push to main touching package.json, weekly Monday @06:00 UTC, manual)
- (d) .github/workflows/cargo-lock-hash.yaml — Weekly lock file determinism check
  (SHA256 hash verification, npm ci --dry-run integrity test)
- (e) .github/workflows/ssot-drift-cron.yaml — Weekly SSOT drift scan
  (docs-sync, route-validation provider-catalog drift checks)

Refs: Pillars L2, L27, L29, L30, L65
…aks.toml (#137)

Adds 47-pillar gitleaks coverage (was last remaining L47.1 gap):
- .github/workflows/gitleaks-fleet.yml: daily 01:00 UTC cron + push + PR scan
- .gitleaks.toml: per-repo allowlist for known false positives
  (test fixtures, .env.example, ADR docs, lockfiles)

Closes v37 systemize T1 (gitleaks-fleet). Fleet is now 86/86 at 3/3.

Co-authored-by: kooshapari <kooshapari@users.noreply.github.com>
The file was deleted during a merge. Restore commits (39a6ba8, 4bcd63d,
2e68c0a) exist in history but did not reach current main tip. Restores the
123-line credential override loader that open-sse/config/constants.ts imports
at module load, unblocking typecheck and vitest suites.
Dropped during upstream merge sync (bdcc23d). package.json was absent from
origin/main, breaking all npm/typecheck/test invocations. Restored from commit
3e88fc0 (the most recent version in git history, v3.8.43).
Restored from previous commits:
- src/lib/logPayloads.ts (from 39a6ba8)
- src/shared/utils/apiKey.ts (from 78f09c8)
- src/shared/constants/batchEndpoints.ts (from 2e68c0a)
- src/shared/constants/modelCompat.ts (from 39a6ba8)
- src/lib/api/errorResponse.ts (from 2e68c0a)
- open-sse/utils/cors.ts (from 39a6ba8)
- open-sse/services/wildcardRouter.ts (from 39a6ba8)
- src/lib/db/reasoningCache.ts (from 39a6ba8)
- src/lib/db/compressionCacheStats.ts (from 507842c)

All files verified in git history and restored to current state.
src/lib/combos/steps.ts already exists on main (not a deletion).
Restores files dropped during upstream/main merge (bdcc23d):
- open-sse/services/claudeCodeCCH.ts
- open-sse/services/claudeCodeObfuscation.ts
- open-sse/services/claudeCodeFingerprint.ts
- open-sse/services/claudeCodeExtraRemap.ts
- open-sse/mcp-server/runtimeHeartbeat.ts
- open-sse/mcp-server/tools/memoryTools.ts
- open-sse/mcp-server/schemas/audit.ts
- open-sse/translator/formats.ts
- open-sse/utils/urlSanitize.ts
- open-sse/config/defaultThinkingSignature.ts
- open-sse/services/compression/ultraHeuristic.ts
- src/lib/db/quotaSnapshots.ts
- src/lib/db/syncTokens.ts
- src/lib/db/upstreamProxy.ts
- src/lib/combos/steps.ts
- src/lib/spend/batchWriter.ts
- src/lib/ipUtils.ts
- src/shared/utils/requestId.ts
- src/lib/cacheControlSettings.ts
- src/server/cors/origins.ts
- src/lib/pricingSync.ts
- src/shared/contracts/quota.ts
- src/shared/utils/resolveOmniRouteBaseUrl.ts
- src/lib/skills/executor.ts
- src/lib/oauth/gitlab.ts
Second wave: open-sse services, autoCombo engine, domain rules,
DB modules, skills types, usage/memory/display modules, logger,
type definitions, and SSE utilities dropped by merge cb43b60.
@KooshaPari
KooshaPari requested a review from diegosouzapw as a code owner July 2, 2026 08:36

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request introduces significant repository hygiene, governance, and architectural updates to OmniRoute, notably integrating maximhq/bifrost as a Tier-1 router layer (ADR-031), adding an Electrobun-based desktop application spike, and standardizing CI/CD, pre-commit/pre-push hooks, and project tracking. Review feedback identifies a critical path resolution bug in the ADR quality lint script (.githooks/adr-quality-lint.py) that causes it to silently skip execution, along with style guide violations regarding the placement of CODEOWNERS and .gitleaks-push.sh in the project root. Additionally, a compatibility improvement is suggested for the pre-commit hook fallback path to handle environments where bun is not installed.

Important

The consumer version of Gemini Code Assist on GitHub is being sunset. Starting June 18, 2026, new organization installations will be blocked, and all code review activity will officially cease on July 17, 2026.
For more details on the timeline and next steps, please review the Help Documentation.

Comment on lines +18 to +19
root = Path(__file__).resolve().parent.parent.parent
adr_dir = root / "docs/adr"

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

critical

There is a path resolution bug here. Since this script is located in .githooks/adr-quality-lint.py, resolving .parent.parent.parent goes three levels up, which points to the directory above the repository root. This causes adr_dir to point to a non-existent path, making the linter silently skip execution by returning 0 on line 21. It should only go two levels up to reach the repository root.

Suggested change
root = Path(__file__).resolve().parent.parent.parent
adr_dir = root / "docs/adr"
root = Path(__file__).resolve().parent.parent
adr_dir = root / "docs/adr"

Comment thread .husky/pre-commit
Comment on lines +29 to +30
bun scripts/check/check-docs-sync.mjs
bun scripts/check/check-t11-any-budget.mjs No newline at end of file

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

medium

The fallback checks use bun directly, which will fail if bun is not installed on the developer's machine. Since this is a fallback path when lefthook is not installed, we should ensure it is compatible with environments that only have node installed, or check for bun's existence first.

if command -v bun >/dev/null 2>&1; then
  bun scripts/check/check-docs-sync.mjs
  bun scripts/check/check-t11-any-budget.mjs
else
  node scripts/check/check-docs-sync.mjs
  node scripts/check/check-t11-any-budget.mjs
fi

Comment thread CODEOWNERS
@@ -0,0 +1,21 @@
# CODEOWNERS — OmniRoute

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

medium

This file is placed in the project root, which violates the Repository Style Guide (Rule 1: File Placement & Organization). The root directory should only contain specific allowed files, and CODEOWNERS is not among them. Please move these rules to .github/CODEOWNERS (which already exists and is being modified in this PR) and remove this root-level file.

References
  1. The Project Root MUST ONLY CONTAIN specific allowed files. CODEOWNERS is not in the allowed list of files in the project root. (link)

Comment thread .gitleaks-push.sh
@@ -0,0 +1,109 @@
#!/usr/bin/env bash

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

medium

This script is placed in the project root, which violates the Repository Style Guide (Rule 1: File Placement & Organization). All maintenance, debugging, generation, or experimental scripts must be placed strictly inside one of the scripts/ subfolders. Please move this script to an appropriate subfolder under scripts/ (such as scripts/ad-hoc/ or a new subfolder) and update any references to it.

References
  1. ALL maintenance, debugging, generation, or experimental scripts MUST be placed strictly inside one of the scripts/ subfolders. NEVER dump loose scripts in the project root. (link)

@KooshaPari

Copy link
Copy Markdown
Contributor Author

Superseded by #190 (waves 2+3 squash-merged). This PR's file set is already on main.

@KooshaPari KooshaPari closed this Jul 2, 2026
@KooshaPari
KooshaPari deleted the fix/restore-missing-files branch July 2, 2026 22:10
@KooshaPari
KooshaPari restored the fix/restore-missing-files branch July 16, 2026 03:32
@KooshaPari
KooshaPari deleted the fix/restore-missing-files branch August 13, 2026 06:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant