Skip to content
13 changes: 13 additions & 0 deletions .env.example
Original file line number Diff line number Diff line change
Expand Up @@ -2395,3 +2395,16 @@ QUOTA_STORE_DRIVER=sqlite # sqlite | redis
# OMNIROUTE_DATA_DIR are both unset. Locates the Notion web-thread session cache.
# ─────────────────────────────────────────────────────────────────────────────
# VIBEPROXY_DATA_DIR=

# ── Internal service auth (management-plane service-to-service calls) ─────────
# Inline token for internal service authentication; prefer the _FILE variant in
# containerized deployments so the secret never lands in the environment table.
# OMNIROUTE_INTERNAL_SERVICE_TOKEN=
# Path to a file containing the internal service token (overrides the inline var).
# OMNIROUTE_INTERNAL_SERVICE_TOKEN_FILE=

# ── OpenRouter provider stats (catalog enrichment) ────────────────────────────
# On by default; set to "false" to skip fetching OpenRouter per-provider stats.
# OPENROUTER_PROVIDER_STATS_ENABLED=true
# Cache TTL for the fetched stats, in milliseconds.
# OPENROUTER_PROVIDER_STATS_TTL_MS=3600000
1 change: 1 addition & 0 deletions changelog.d/fixes/prepublish-native-esbuild.md
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
- fix(build): exec native esbuild binary directly in prepublish — esbuild ≥0.25 ships an ELF at bin/esbuild and running it through node crashed every build:cli (dast-smoke red on all PRs)
6 changes: 6 additions & 0 deletions docs/INCIDENT_RESPONSE.md
Original file line number Diff line number Diff line change
@@ -1,3 +1,9 @@
---
title: "Incident Response Runbook — OmniRoute (2026-06-18)"
version: 3.8.50
lastUpdated: 2026-08-06
---

# Incident Response Runbook — OmniRoute (2026-06-18)

**Status**: Authoritative. The 71-pillar audit (L61) references this doc
Expand Down
6 changes: 6 additions & 0 deletions docs/PERF_BUDGETS.md
Original file line number Diff line number Diff line change
@@ -1,3 +1,9 @@
---
title: "Performance Budgets — OmniRoute (2026-06-18)"
version: 3.8.50
lastUpdated: 2026-08-06
---

# Performance Budgets — OmniRoute (2026-06-18)

**Status**: Authoritative. SLO targets that the 71-pillar audit (L13)
Expand Down
6 changes: 6 additions & 0 deletions docs/ROADMAP.md
Original file line number Diff line number Diff line change
@@ -1,3 +1,9 @@
---
title: "OmniRoute Roadmap"
version: 3.8.50
lastUpdated: 2026-08-06
---

# OmniRoute Roadmap

> Version-gated, not date-gated: each milestone ships when its quality gates pass.
Expand Down
6 changes: 6 additions & 0 deletions docs/assets/flags/README.md
Original file line number Diff line number Diff line change
@@ -1,3 +1,9 @@
---
title: "Flag icons"
version: 3.8.50
lastUpdated: 2026-08-06
---

# Flag icons

SVG country flags used by the language selector in the root `README.md`.
Expand Down
6 changes: 6 additions & 0 deletions docs/combo-context-requirements.md
Original file line number Diff line number Diff line change
@@ -1,3 +1,9 @@
---
title: "Combo Context Requirements Feature"
version: 3.8.50
lastUpdated: 2026-08-06
---

# Combo Context Requirements Feature

## Overview
Expand Down
6 changes: 6 additions & 0 deletions docs/getting-started/AUTO-COMBO-GUIDE.md
Original file line number Diff line number Diff line change
@@ -1,3 +1,9 @@
---
title: "Auto-Combo: Let OmniRoute Pick the Best AI for You"
version: 3.8.50
lastUpdated: 2026-08-06
---

# Auto-Combo: Let OmniRoute Pick the Best AI for You

> **TL;DR**: Set your model to `auto` and OmniRoute automatically picks the best AI provider for each request. No configuration needed.
Expand Down
6 changes: 6 additions & 0 deletions docs/getting-started/FREE-TIERS-GUIDE.md
Original file line number Diff line number Diff line change
@@ -1,3 +1,9 @@
---
title: "Free Tiers Guide: Get Free AI Without a Credit Card"
version: 3.8.50
lastUpdated: 2026-08-06
---

# Free Tiers Guide: Get Free AI Without a Credit Card

> **TL;DR**: OmniRoute aggregates free tiers from 50+ providers. Connect multiple free providers for unlimited free AI with automatic fallback.
Expand Down
6 changes: 6 additions & 0 deletions docs/getting-started/PROVIDERS-GUIDE.md
Original file line number Diff line number Diff line change
@@ -1,3 +1,9 @@
---
title: "Providers Guide: Connect AI Models to OmniRoute"
version: 3.8.50
lastUpdated: 2026-08-06
---

# Providers Guide: Connect AI Models to OmniRoute

> **TL;DR**: A provider is a connection to an AI service (like OpenAI, Anthropic, Google). You need at least one provider to use OmniRoute.
Expand Down
6 changes: 6 additions & 0 deletions docs/getting-started/QUICK-START.md
Original file line number Diff line number Diff line change
@@ -1,3 +1,9 @@
---
title: "Quick Start: Get OmniRoute Running in 3 Minutes"
version: 3.8.50
lastUpdated: 2026-08-06
---

# Quick Start: Get OmniRoute Running in 3 Minutes

> **TL;DR**: Install → Connect a free provider → Point your IDE to OmniRoute. Done.
Expand Down
6 changes: 6 additions & 0 deletions docs/guides/DOCKER_RELEASE_CHANNELS.md
Original file line number Diff line number Diff line change
@@ -1,3 +1,9 @@
---
title: "Docker Release Channels"
version: 3.8.50
lastUpdated: 2026-08-06
---

# Docker Release Channels

OmniRoute publishes separate Docker channels for stable releases, active release-branch testing, and development builds.
Expand Down
6 changes: 6 additions & 0 deletions docs/proxy-port-clash-report.md
Original file line number Diff line number Diff line change
@@ -1,3 +1,9 @@
---
title: "Proxy Port Clash Investigation"
version: 3.8.50
lastUpdated: 2026-08-06
---

# Proxy Port Clash Investigation

## Summary
Expand Down
6 changes: 6 additions & 0 deletions docs/proxy-subscriptions.md
Original file line number Diff line number Diff line change
@@ -1,3 +1,9 @@
---
title: "Operator Proxy Subscriptions (Karing-style)"
version: 3.8.50
lastUpdated: 2026-08-06
---

# Operator Proxy Subscriptions (Karing-style)

> Feature design + implementation notes for OmniRoute's operator-level proxy
Expand Down
6 changes: 6 additions & 0 deletions docs/redis-production-config.md
Original file line number Diff line number Diff line change
@@ -1,3 +1,9 @@
---
title: "Redis Production Configuration Guide"
version: 3.8.50
lastUpdated: 2026-08-06
---

# Redis Production Configuration Guide

## Overview
Expand Down
22 changes: 22 additions & 0 deletions docs/reference/ENVIRONMENT.md
Original file line number Diff line number Diff line change
Expand Up @@ -1312,3 +1312,25 @@ Used by `src/lib/vncSession/manifest.ts` to configure Docker-based headless Chro
| `OMNIROUTE_VNC_READY_MS` | `45000` | `src/lib/vncSession/manifest.ts` | Browser readiness timeout (ms). |
| `OMNIROUTE_VNC_HARVEST_MS` | `20000` | `src/lib/vncSession/manifest.ts` | Harvest/cleanup timeout (ms). |
| `VIBEPROXY_DATA_DIR` | _(unset)_ | `open-sse/services/notionThreadSessions.ts` | Directory for Notion thread session persistence. |

### Internal service auth

| Variable | Default | Description |
| --- | --- | --- |
| `OMNIROUTE_INTERNAL_SERVICE_TOKEN` | – | Inline token for management-plane service-to-service authentication. |
| `OMNIROUTE_INTERNAL_SERVICE_TOKEN_FILE` | – | Path to a file containing the internal service token (preferred in containers; overrides the inline variable). |

### OpenRouter provider stats

| Variable | Default | Description |
| --- | --- | --- |
| `OPENROUTER_PROVIDER_STATS_ENABLED` | `true` | Set to `false` to skip fetching OpenRouter per-provider stats for catalog enrichment. |
| `OPENROUTER_PROVIDER_STATS_TTL_MS` | `3600000` | Cache TTL (ms) for the fetched OpenRouter provider stats. |

### Embedded Redis binding

| Variable | Default | Description |
| --- | --- | --- |
| `REDIS_BIND_HOST` | `127.0.0.1` | Bind address for the embedded Redis service. |
| `REDIS_PORT` | `6379` | Port for the embedded Redis service. |
| `OMNIROUTE_REDIS_BIND_HOST` | – | OmniRoute-scoped override for the embedded Redis bind address. |
Original file line number Diff line number Diff line change
@@ -1,3 +1,9 @@
---
title: "Issue-Agent Executable Triage: Session Overview"
version: 3.8.50
lastUpdated: 2026-08-06
---

# Issue-Agent Executable Triage: Session Overview

Machine status: `in_progress`
Expand Down
Original file line number Diff line number Diff line change
@@ -1,3 +1,9 @@
---
title: "Issue-Agent Executable Triage: Research"
version: 3.8.50
lastUpdated: 2026-08-06
---

# Issue-Agent Executable Triage: Research

Machine status: `complete_for_current_phase`
Expand Down
Original file line number Diff line number Diff line change
@@ -1,3 +1,9 @@
---
title: "Issue-Agent Executable Triage: Specifications"
version: 3.8.50
lastUpdated: 2026-08-06
---

# Issue-Agent Executable Triage: Specifications

Machine status: `in_progress`
Expand Down
Original file line number Diff line number Diff line change
@@ -1,3 +1,9 @@
---
title: "Issue-Agent Executable Triage: DAG and WBS"
version: 3.8.50
lastUpdated: 2026-08-06
---

# Issue-Agent Executable Triage: DAG and WBS

Machine status: `in_progress`
Expand Down
Original file line number Diff line number Diff line change
@@ -1,3 +1,9 @@
---
title: "Issue-Agent Executable Triage: Implementation Strategy"
version: 3.8.50
lastUpdated: 2026-08-06
---

# Issue-Agent Executable Triage: Implementation Strategy

Machine status: `in_progress`
Expand Down
Original file line number Diff line number Diff line change
@@ -1,3 +1,9 @@
---
title: "Issue-Agent Executable Triage: Known Issues"
version: 3.8.50
lastUpdated: 2026-08-06
---

# Issue-Agent Executable Triage: Known Issues

Machine status: `open`
Expand Down
Original file line number Diff line number Diff line change
@@ -1,3 +1,9 @@
---
title: "Issue-Agent Executable Triage: Testing Strategy"
version: 3.8.50
lastUpdated: 2026-08-06
---

# Issue-Agent Executable Triage: Testing Strategy

Machine status: `in_progress`
Expand Down
49 changes: 44 additions & 5 deletions scripts/build/prepublish.ts
Original file line number Diff line number Diff line change
Expand Up @@ -22,6 +22,9 @@ import {
readdirSync,
statSync,
chmodSync,
openSync,
readSync,
closeSync,
} from "node:fs";
import { join, dirname } from "node:path";
import { fileURLToPath } from "node:url";
Expand Down Expand Up @@ -70,6 +73,30 @@ function resolveLocalBinEntry(packageName: string, binName: string): string | nu
* tool lives in the local dependency tree; when it is not installed there the call
* falls back to the Node-resolved `npx` entry point, and only then to the shim.
*/
/**
* esbuild ≥0.25 ships its `bin/esbuild` as the NATIVE platform executable on
* Linux/macOS (ELF / Mach-O) instead of a JS shim — running it through
* `process.execPath` makes Node parse machine code as JavaScript and crash with
* "SyntaxError: Invalid or unexpected token". Sniff the magic bytes and exec
* native entries directly; JS entries keep going through this Node binary.
*/
function isNativeExecutable(entryPath: string): boolean {
try {
const fd = openSync(entryPath, "r");
const head = Buffer.alloc(4);
readSync(fd, head, 0, 4, 0);
closeSync(fd);
return (
(head[0] === 0x7f && head[1] === 0x45 && head[2] === 0x4c && head[3] === 0x46) || // ELF
head.readUInt32BE(0) === 0xfeedfacf || // Mach-O 64
head.readUInt32BE(0) === 0xcffaedfe || // Mach-O 64 (LE on disk)
(head[0] === 0x4d && head[1] === 0x5a) // PE (Windows MZ)
);
} catch {
return false;
}
}

function runBuildTool(
packageName: string,
binName: string,
Expand All @@ -78,6 +105,10 @@ function runBuildTool(
): void {
const localEntry = resolveLocalBinEntry(packageName, binName);
if (localEntry) {
if (isNativeExecutable(localEntry)) {
execFileSync(localEntry, [...args], options);
return;
}
execFileSync(process.execPath, [localEntry, ...args], options);
return;
}
Expand Down Expand Up @@ -405,15 +436,23 @@ if (existsSync(opencodePluginSrc) && existsSync(join(opencodePluginSrc, "package
// types). Without this install a fresh CI publish fails at this step.
if (!existsSync(join(opencodePluginSrc, "node_modules"))) {
const npmEntry = resolveBundledNpmEntry("npm-cli.js");
if (!npmEntry) {
if (npmEntry) {
execFileSync(process.execPath, [npmEntry, "install", "--no-audit", "--no-fund"], {
cwd: opencodePluginSrc,
stdio: "inherit",
});
} else if (process.platform !== "win32") {
// No bundled npm entry found (non-standard Node layout). Plain `npm` is
// safe here — the .cmd-shim hazard #8858 guards against is Windows-only.
execFileSync("npm", ["install", "--no-audit", "--no-fund"], {
cwd: opencodePluginSrc,
stdio: "inherit",
});
} else {
throw new Error(
"npm-cli.js not found next to the running Node binary; cannot install the plugin dependencies without falling back to a .cmd shim."
);
}
execFileSync(process.execPath, [npmEntry, "install", "--no-audit", "--no-fund"], {
cwd: opencodePluginSrc,
stdio: "inherit",
});
}
runBuildTool("tsup", "tsup", [], {
cwd: opencodePluginSrc,
Expand Down
15 changes: 11 additions & 4 deletions stryker.conf.json
Original file line number Diff line number Diff line change
Expand Up @@ -39,7 +39,9 @@
"incremental": true,
"incrementalFile": "reports/mutation/stryker-incremental.json",
"testRunner": "tap",
"plugins": ["@stryker-mutator/tap-runner"],
"plugins": [
"@stryker-mutator/tap-runner"
],
"tap": {
"testFiles": [
"tests/unit/7993-noauth-proxy-routing.test.ts",
Expand Down Expand Up @@ -84,9 +86,9 @@
"tests/unit/bug-7940-gemini-retrydelay.test.ts",
"tests/unit/build/check-circular-deps.test.ts",
"tests/unit/cache-sweeps.test.ts",
"tests/unit/chat-adaptive-admission-binding.test.ts",
"tests/unit/cc-bridge-openai-image-7777.test.ts",
"tests/unit/cc-compatible-provider.test.ts",
"tests/unit/chat-adaptive-admission-binding.test.ts",
"tests/unit/chat-combo-live-test.test.ts",
"tests/unit/chat-context-relay.test.ts",
"tests/unit/chat-cooldown-aware-retry.test.ts",
Expand Down Expand Up @@ -312,7 +314,8 @@
"tests/unit/upstream-retry-hints-toggle.test.ts",
"tests/unit/upstream-timeout-model-override.test.ts",
"tests/unit/usage-service-hardening.test.ts",
"tests/unit/validate-response-quality.test.ts"
"tests/unit/validate-response-quality.test.ts",
"tests/unit/xai-agent-tools-passthrough.test.ts"
],
"nodeArgs": [
"--import",
Expand Down Expand Up @@ -421,7 +424,11 @@
".worktrees",
".stryker-tmp"
],
"reporters": ["progress", "html", "json"],
"reporters": [
"progress",
"html",
"json"
],
"htmlReporter": {
"fileName": "reports/mutation/mutation.html"
},
Expand Down
Loading