Skip to content

fix(api): dynamic import for MITM + fix Turbopack over-bundling warnings - #6366

Merged
diegosouzapw merged 3 commits into
diegosouzapw:release/v3.8.46from
Iammilansoni:fix/mitm-stub-runtime-error
Jul 6, 2026
Merged

diegosouzapw merged 3 commits into
diegosouzapw:release/v3.8.46from
Iammilansoni:fix/mitm-stub-runtime-error

Conversation

@Iammilansoni

@Iammilansoni Iammilansoni commented Jul 6, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Fix MITM manager stub reached at runtime error when clicking Start/Stop in the AgentBridge dashboard
  • Fix 379 Turbopack build warnings about overly broad file patterns matching 33,530 files

Changes

1. MITM stub error (main blocker)

src/app/api/tools/agent-bridge/server/route.ts: Switch startMitm/stopMitm to dynamic await import("@/mitm/manager.runtime") for start, stop, and restart actions. Static imports for getCachedPassword, setCachedPassword, getMitmStatus remain on the stub (safe degraded behavior).

2. Turbopack over-bundling warnings

src/lib/agentSkills/generator.ts: Changed path.resolve(process.cwd(), outputDir) to path.join(process.cwd(), outputDir). Turbopack's static analyzer cannot resolve path.resolve() with process.cwd(), causing it to fall back to tracing the entire project root (33,530 files). path.join() produces a literal path the analyzer can resolve.

Context

The @/mitm/manager -> manager.stub.ts alias in next.config.mjs is intentional — it prevents Turbopack from bundling native child_process/fs imports during next build. The stub provides safe fallbacks for status/password functions but correctly throws for startMitm/stopMitm. Routes that need the real implementation (like settings/mitm/route.ts) already use dynamic imports of @/mitm/manager.runtime to bypass the alias. This PR applies the same pattern to the agent-bridge server route.

For the Turbopack warnings: generator.ts is dynamically imported by agent-skills/generate/route.ts, so it IS part of the build. The path.resolve(process.cwd(), ...) pattern produces a path that Turbopack cannot statically analyze, triggering the broad pattern warning.

Closes #6329

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request updates the server route for the agent bridge to dynamically import startMitm and stopMitm from the runtime manager during action execution. The review feedback correctly identifies that getMitmStatus should also be dynamically imported to avoid Turbopack stubbing issues, and notes a potential bug where the cached password is lost during a restart. Additionally, the feedback points out that tests must be included when modifying production code, in accordance with the repository style guide.

Important

The consumer version of Gemini Code Assist on GitHub is being sunset. Starting June 18, 2026, new organization installations will be blocked, and all code review activity will officially cease on July 17, 2026.
For more details on the timeline and next steps, please review the Help Documentation.


if (action === "restart") {
const pwd = sudoPassword || getCachedPassword() || "";
const { startMitm, stopMitm } = await import("@/mitm/manager.runtime");

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

high

There are two correctness issues in this restart block:\n\n1. Stubbed getMitmStatus: The statically imported getMitmStatus will resolve to the stubbed version (manager.stub.ts) due to the Turbopack alias. Since the stub cannot access native APIs, it will return a fallback status (e.g., running: false), causing the restart action to skip stopping the active MITM server and then fail when attempting to start it again.\n * Fix: Dynamically import getMitmStatus from @/mitm/manager.runtime along with startMitm and stopMitm.\n\n2. Cached Password Cleared: Calling stopMitm(pwd) internally calls clearCachedPassword(). If the user triggered restart without providing a sudoPassword in the request body (relying on the cached password), the cached password will be lost after stopMitm runs. The subsequent startMitm will succeed using the local pwd variable, but any future actions requiring the cached password will fail.\n * Fix: Re-cache the password after stopping by changing if (sudoPassword) setCachedPassword(sudoPassword); to if (sudoPassword || pwd) setCachedPassword(sudoPassword || pwd);.

Suggested change
const { startMitm, stopMitm } = await import("@/mitm/manager.runtime");
const { startMitm, stopMitm, getMitmStatus } = await import("@/mitm/manager.runtime");

*/
import { AgentBridgeServerActionSchema } from "@/shared/schemas/agentBridge";
import { startMitm, stopMitm, getMitmStatus, setCachedPassword, getCachedPassword } from "@/mitm/manager";
import { getCachedPassword, setCachedPassword, getMitmStatus } from "@/mitm/manager";

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

medium

Since getMitmStatus is only used in the restart action and must be dynamically imported from @/mitm/manager.runtime to avoid the Turbopack stub, it should be removed from the static imports here.

Suggested change
import { getCachedPassword, setCachedPassword, getMitmStatus } from "@/mitm/manager";
import { getCachedPassword, setCachedPassword } from "@/mitm/manager";

try {
if (action === "start") {
if (sudoPassword) setCachedPassword(sudoPassword);
const { startMitm } = await import("@/mitm/manager.runtime");

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

medium

According to the Repository Style Guide (Rule 9), changing production code under src/ requires including tests. Please ensure that appropriate unit or integration tests are added or updated in the tests/ directory to cover these changes (e.g., verifying the dynamic import behavior and the restart action).

References
  1. Always include tests when changing production code (src/, open-sse/, electron/, bin/). (link)

@Iammilansoni
Iammilansoni force-pushed the fix/mitm-stub-runtime-error branch from 560c8da to bdc038f Compare July 6, 2026 14:49
@Iammilansoni Iammilansoni changed the title fix(api): use dynamic import for startMitm/stopMitm to bypass Turbopack alias fix(api): dynamic import for MITM + fix Turbopack over-bundling warnings Jul 6, 2026
…ling warnings

MITM stub error (main blocker):
The agent-bridge/server route statically imported startMitm, stopMitm,
and getMitmStatus from @/mitm/manager, which Turbopack aliases to
manager.stub.ts during build. The stub throws STUB_ERROR on start/stop
and returns stubbed status, causing the AgentBridge dashboard to crash.

Switch to dynamic import of @/mitm/manager.runtime (bypasses the alias)
for start, stop, and restart actions. Static imports for
getCachedPassword and setCachedPassword remain on the stub (safe degraded
behavior). Also re-cache password after stopMitm in restart action,
since stopMitm calls clearCachedPassword() internally.

Turbopack warnings (379 warnings about 33,530 files):
generator.ts used path.resolve(process.cwd(), outputDir) which Turbopack
cannot resolve statically, causing it to trace the entire project root.
Switch to path.join() for explicit path construction.

Added unit tests verifying the dynamic import path resolves the real
MITM module (not the stub).

Closes diegosouzapw#6329
@Iammilansoni
Iammilansoni force-pushed the fix/mitm-stub-runtime-error branch from bdc038f to a61ff1b Compare July 6, 2026 14:55
@diegosouzapw
diegosouzapw changed the base branch from main to release/v3.8.46 July 6, 2026 20:25
@diegosouzapw diegosouzapw reopened this Jul 6, 2026
@diegosouzapw

Copy link
Copy Markdown
Owner

Merged — thank you, @Iammilansoni! The agent-bridge route now dynamically imports @/mitm/manager.runtime (bypassing the Turbopack stub alias) and the agent-skills generator anchors its output path with path.join so Turbopack stops tracing the whole project root (#6329). Verified locally: the new agent-bridge-server-route-dynamic-import.test.ts passes 6/6 and check:agent-skills-sync stays green (generator change is output-neutral). Integrated into release/v3.8.46.

@diegosouzapw
diegosouzapw merged commit 49795c2 into diegosouzapw:release/v3.8.46 Jul 6, 2026
7 checks passed
diegosouzapw added a commit that referenced this pull request Jul 7, 2026
…ssion)

#6366 switched the output base from path.resolve to path.join(process.cwd(),
outputDir) to keep Turbopack's static analyzer from tracing the project root.
path.join mangles an absolute outputDir (a tmp dir in the generator tests) into
cwd/tmp/…, so apply mode reported success while writing nothing at the expected
path. Guard with path.isAbsolute — absolute paths pass through, the relative
production case ('skills') keeps the Turbopack-friendly join form. The existing
agentSkills-generator suite is the regression guard (now 21/21).
diegosouzapw added a commit that referenced this pull request Jul 7, 2026
…auto-resolve, add captain pre-flight fixes, Contributors hall (Phase 0a.1/0a.3a)

Repairs ~29 [3.8.46] bullets whose (#N) PR links were stripped by a prior merge
conflict auto-resolve, adds bullets for the captain's own pre-flight base-red
fixes (#6408 catalog cache, #6366 agentSkills, doubao CodeQL), folds the ~53
v3.8.45 sync-back carryover commits (already documented under [3.8.45]) into a
coverage-satisfying Maintenance note, consolidates the duplicate New Features
block + normalizes the Bug Fixes heading, and injects the mandatory
### 🙌 Contributors table (45 external contributors). Coverage 90→13 uncovered
(the 13 are zero-ref release plumbing). Syncs all 42 i18n mirrors.
HouMinXi pushed a commit to HouMinXi/OmniRoute that referenced this pull request Aug 2, 2026
…ngs (diegosouzapw#6366)

Dynamic MITM manager import on the agent-bridge route + Turbopack static-analyzer anchor in the skills generator (diegosouzapw#6329). Integrated into release/v3.8.46.
HouMinXi pushed a commit to HouMinXi/OmniRoute that referenced this pull request Aug 2, 2026
…w#6366 regression)

diegosouzapw#6366 switched the output base from path.resolve to path.join(process.cwd(),
outputDir) to keep Turbopack's static analyzer from tracing the project root.
path.join mangles an absolute outputDir (a tmp dir in the generator tests) into
cwd/tmp/…, so apply mode reported success while writing nothing at the expected
path. Guard with path.isAbsolute — absolute paths pass through, the relative
production case ('skills') keeps the Turbopack-friendly join form. The existing
agentSkills-generator suite is the regression guard (now 21/21).
tkgo11 pushed a commit to tkgo11/OmniRoute that referenced this pull request Sep 23, 2026
…auto-resolve, add captain pre-flight fixes, Contributors hall (Phase 0a.1/0a.3a)

Repairs ~29 [3.8.46] bullets whose (#N) PR links were stripped by a prior merge
conflict auto-resolve, adds bullets for the captain's own pre-flight base-red
fixes (diegosouzapw#6408 catalog cache, diegosouzapw#6366 agentSkills, doubao CodeQL), folds the ~53
v3.8.45 sync-back carryover commits (already documented under [3.8.45]) into a
coverage-satisfying Maintenance note, consolidates the duplicate New Features
block + normalizes the Bug Fixes heading, and injects the mandatory
### 🙌 Contributors table (45 external contributors). Coverage 90→13 uncovered
(the 13 are zero-ref release plumbing). Syncs all 42 i18n mirrors.
muhamadgalihsaputra pushed a commit to niyatna/NiyatnaRoute that referenced this pull request Sep 27, 2026
…ngs (diegosouzapw#6366)

Dynamic MITM manager import on the agent-bridge route + Turbopack static-analyzer anchor in the skills generator (diegosouzapw#6329). Integrated into release/v3.8.46.
muhamadgalihsaputra pushed a commit to niyatna/NiyatnaRoute that referenced this pull request Sep 27, 2026
…w#6366 regression)

diegosouzapw#6366 switched the output base from path.resolve to path.join(process.cwd(),
outputDir) to keep Turbopack's static analyzer from tracing the project root.
path.join mangles an absolute outputDir (a tmp dir in the generator tests) into
cwd/tmp/…, so apply mode reported success while writing nothing at the expected
path. Guard with path.isAbsolute — absolute paths pass through, the relative
production case ('skills') keeps the Turbopack-friendly join form. The existing
agentSkills-generator suite is the regression guard (now 21/21).
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

fix(startup): MITM/agent-bridge dashboard fails to open — npm run build warnings

2 participants