Skip to content

fix(guardrails): vision-bridge DI gap + capability-gated stub + stale 7859 mock (#9541) - #9546

Closed
diegosouzapw wants to merge 4 commits into
release/v3.8.50from
fix/9541-visionbridge-di-credentials
Closed

diegosouzapw wants to merge 4 commits into
release/v3.8.50from
fix/9541-visionbridge-di-credentials

Conversation

@diegosouzapw

Copy link
Copy Markdown
Owner

Fixes the three deterministic Unit Tests fast-path shard reds hitting every code PR since 2026-08-04 (Refs #9541 — the load-dependent D1/D2 half was fixed by #9385):

  1. DI gap: visionBridge.ts didn't thread its injected hasUsableCredentials into getBestVisionModel() — fix(providers): Vision Bridge describe-model unreachable when no openai provider connected → raw image forwarded to non-vision model #8430's fixedModel validation ran the real DB check under test DI, so CI's empty credential store silently disabled the reroute path (VB-S12/S01/… red on every PR, docs-only included).
  2. [BUG] Nvidia NIM via Omniroute fails to process image inputs #4012 × fix(providers): Vision Bridge describe-model unreachable when no openai provider connected → raw image forwarded to non-vision model #8430 composition: the all-describes-failed stub now only replaces images when the upstream is confirmed NOT vision-capable — a vision-capable upstream keeps its raw images (VB-S03).
  3. Stale mock: the fix(providers): Gemini Web connection test fails — 'Redirect blocked' 302 despite validator treating 302 as valid #7859 test's public-redirect mock used ServiceLogin, which fix(providers): gemini-web connection test false-positives while 15s queue masks failures #9407 redefined as expired-session — moved to a non-ServiceLogin public target; both contracts keep dedicated coverage.

Validation (CI loader set): visionBridge 25/25 · 4012+8430 5/5 · 7859+9407 12/12 · typecheck clean. This PR's own fast-path shards double as the live proof.

… 7859 mock (#9541)

Three deterministic fast-path shard reds on every code PR since 2026-08-04:

1. visionBridge.ts did not thread its injected hasUsableCredentials into
   getBestVisionModel(), so #8430's fixedModel validation ran the REAL DB
   check even under test DI — an empty credential store (CI) silently
   disabled the whole reroute path (VB-S12/S12b/S01/S13/S07/S10 red on
   every PR, including docs-only).
2. #8430's all-describes-failed stub replaced raw images even for a
   CONFIRMED vision-capable upstream forced through the combo path,
   violating the #4012 preserve contract (VB-S03). The stub is now gated
   on the upstream NOT being vision-capable — exactly the case #8430's
   own rationale covers.
3. The #7859 regression test mocked its public redirect as
   accounts.google.com/ServiceLogin, which #9407 has since redefined as
   an EXPIRED session — the mock now uses a non-ServiceLogin public
   target, keeping both contracts covered by their own tests.

Validated with the CI loader set (isolateDataDir): visionBridge 25/25,
vision-bridge-preserve-4012 + repro-8430 5/5, 7859+9407 12/12,
typecheck:core clean.
@diegosouzapw

Copy link
Copy Markdown
Owner Author

Superseded by #9529 (merged): it shipped the identical vision-bridge DI fix, the test realignments (VB-S03/7859) and the provider-count docs sync — this branch's diff against release/v3.8.50 is now empty. Root-cause analysis lives in #9541.

@diegosouzapw
diegosouzapw deleted the fix/9541-visionbridge-di-credentials branch August 6, 2026 02:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant