Skip to content

fix(release): apply v3.8.50 release commits on top of base-reds fix (#9985) - #17

Closed
jonlwheat2-gif wants to merge 23 commits into
release/v3.8.50from
fix/release-v3.8.50-sync-release-commits
Closed

jonlwheat2-gif wants to merge 23 commits into
release/v3.8.50from
fix/release-v3.8.50-sync-release-commits

Conversation

@jonlwheat2-gif

Copy link
Copy Markdown
Owner

Summary

Applies the 19 commits from release/v3.8.50 on top of the base-reds fix (diegosouzapw#9985). These commits include quality gate fixes, provider updates, and new features that landed after the base-reds fix branch was created.

Depends on PR #16 (base-reds fix).

Commits applied (19)

Commit Description
d01a4ae6c fix(release): drain v3.8.50 base-reds — build-breaking import, stale provider docs, orphaned suppressions (diegosouzapw#11038)
ae2de4511 fix(sse): resolve OpencodeExecutor target format through the provider alias (diegosouzapw#11047)
02a6c3d90 fix(sse): split concatenated tool_call arguments from same-name index collisions (diegosouzapw#11043)
1c920eb8b fix(webhooks): remove 3 declared-but-never-emitted ghost events (diegosouzapw#11050)
666e4aaca fix(providers): route Muse Spark to the Responses API on opencode-zen too (diegosouzapw#11049)
c9775366f refactor(providers): dedupe identical opencode-zen/opencode-go model entries (diegosouzapw#11051)
f968496cc fix(gamification): validate leaderboard limit/offset before the SQLite bind (diegosouzapw#11059)
0ff0490ad test(db): assert resetDbInstance swaps the singleton, WAL mode, and schema_version seed (diegosouzapw#10906)
9b801b7e0 fix(dashboard): compute unique connection names from array to avoid overwrite (diegosouzapw#11033) (diegosouzapw#11067)
7e48be806 feat(dashboard): trigger key validation on Enter in AddApiKeyModal (diegosouzapw#10995) (diegosouzapw#11056)
8643e0f57 fix(cli): default limit.context to 128k when unknown in OpenCode configs (diegosouzapw#11035, diegosouzapw#11032) (diegosouzapw#11054)
7c39e9597 fix(providers): update hailuo-web domain to chat.minimax.io (diegosouzapw#11000) (diegosouzapw#11055)
7ffa3efaf fix(quality): move diegosouzapw#11050 changelog fragment + rebaseline AddApiKeyModal (diegosouzapw#11056)
7ddbaf69a feat(cli): add native Bun backend support and Dockerfile.bun (diegosouzapw#11039)
5a60a46e2 fix: deprecate blackbox provider (diegosouzapw#10997) (diegosouzapw#11074)
e06f8b7ec feat(api): flag a pinned account on /v1/combos steps without leaking the id (diegosouzapw#11076)
b6412c6fe fix(command-code): use the documented /provider/v1 chat endpoint (diegosouzapw#10265) (diegosouzapw#11072)
6cd4d38e2 fix(m365): BizChat invocation shape drift + HAR-import UX (diegosouzapw#11069)
742ccb98a fix(ci): register oauth-autoimport-local-only test in stryker (diegosouzapw#11053)

Manual fix included

Synced skills/omni-webhooks/SKILL.md with agentSkills.ts after the ghost-event cleanup (diegosouzapw#11050) changed the webhook event description.

Source

Cherry-picked from diegosouzapw/OmniRoute@release/v3.8.50 (commits d01a4ae6c..742ccb98a).

backryun and others added 23 commits August 21, 2026 14:39
…ale provider docs, orphaned lint suppressions
… alias (diegosouzapw#11047)

⭐5 — OpencodeExecutor buscava targetFormat com o id bruto do provider em vez do alias público ("oc"), caindo em default openai → corpo Responses no URL chat/completions (400). resolveOpencodeTargetFormat resolve via PROVIDER_ID_TO_ALIAS. TDD 4/4 + 32/32 irmãos, lint/tsc limpos. Fecha diegosouzapw#11046. Base-red diegosouzapw#9985 inherited.
… collisions (diegosouzapw#11043)

⭐5 — Providers que não bumpam index/id em tool calls repetidas do mesmo nome colam N arguments JSON num só ({...}{...}{...}); leitores a jusante pegam só o primeiro e dropam o resto em silêncio. Detecta N objetos concatenados e divide de volta em N tool_calls. TDD 20/20 + 86/86 irmãos. Fecha diegosouzapw#11044. Base-red diegosouzapw#9985 inherited.
…osouzapw#11050)

⭐5 — Remove 3 webhook events declarados mas nunca emitidos (provider.error/recovered, combo.switched): union 7→4, z.enum com 400 em ghost values (era z.string pass-through). Breaking intencional + testado. TDD 3/3, i18n B-pattern (42 __MISSING__). Base-red diegosouzapw#9985 inherited.
… too (diegosouzapw#11049)

⭐5 — Muse Spark responde só na Responses API; diegosouzapw#10874 corrigiu só o provider `opencode`, mas `opencode-zen` (faltava targetFormat em 2 entries) e `opencode-go` (6 entries effort-tier) nunca receberam. Espelha a declaração. freebuff NÃO tocado (backend codebuff.com /chat/completions distinto, verificado). TDD 2/2 + 18/18 irmãos. Fecha diegosouzapw#11048. Base-red diegosouzapw#9985 inherited.
…entries (diegosouzapw#11051)

⭐5 — Dedupe dos 3 entries byte-idênticos (kimi-k2.7-code, qwen3.5-plus, qwen3.6-plus) entre opencode-zen e opencode-go via OPENCODE_ZEN_GO_SHARED_MODELS (padrão GLM_SHARED_MODELS), frozen e testado por deep-equal. Pure move, sem mudança de comportamento; check:provider-consistency OK (267 entries, 348 providers). TDD 3/3. Follow-up de diegosouzapw#11049/diegosouzapw#11048. Base-red diegosouzapw#9985 inherited.
…e bind (diegosouzapw#11059)

⭐5 — LIMIT negativo = "sem limite" no SQLite: ?limit=-1 retornava a leaderboard inteira em endpoint management autenticado; ceil por Math.min só no upper. Duas camadas: route rejeita não-inteiro/fora de range com 400 (mesmo contrato de parseListLimit), getTopN clampeia como backstop defense-in-depth + exporta LEADERBOARD_MAX_LIMIT. TDD red→green, 5 casos novos, 84/84 suíte gamification. Fecha diegosouzapw#11058.
…chema_version seed (diegosouzapw#10906)

⭐5 — Preenche os 3 test.skip com asserções reais (resetDbInstance troca o singleton preservando a linha no disco, journal_mode WAL, schema_version=1). Além do valor pretendido, o autor redesenhou o setup()/cleanup() do arquivo corrigindo um bug de isolamento pré-existente que eu apontei em review: DATA_DIR/SQLITE_FILE são const de topo de módulo; o cleanup() usava require() CJS que nunca resetava a instância ESM-importada, então os testes 1-4 passavam "por acidente" contra a conexão nunca fechada. Agora: tempDir compartilhado definido antes do primeiro import, resetDbInstance importado via ESM uma vez, handle fechado antes de cada reopen, e o catch{} silencioso removido. 7/7 verdes no arquivo inteiro.
…verwrite (diegosouzapw#11033) (diegosouzapw#11067)

⭐5 — computeConnectionDefaultName aceita array de nomes existentes e acha o próximo não-conflitante, evitando overwrite de nome de conexão. TDD. Fecha diegosouzapw#11033.
…iegosouzapw#10995) (diegosouzapw#11056)

⭐5 — onKeyDown Enter no input de chave da AddApiKeyModal dispara a validação. TDD. Fecha diegosouzapw#10995.
…igs (diegosouzapw#11035, diegosouzapw#11032) (diegosouzapw#11054)

⭐5 — OpenCode config: limit.context default 128k quando metadata de catálogo desconhecida (diegosouzapw#11035/diegosouzapw#11032); limit emitido por model entry. TDD, suíte aberta limpa.
…zapw#11000) (diegosouzapw#11055)

⭐5 — Atualiza domínio do provider hailuo-web para chat.minimax.io (diegosouzapw#11000). Merge autorizado pelo operador (ordem explícita de prosseguir sem o smoke VPS da Hard Rule #18).
…es/ section + rebaseline AddApiKeyModal (1067->1073, diegosouzapw#11056 growth)
…uzapw#11039)

⭐4 — Suporte de backend nativo Bun + Dockerfile.bun multi-stage + fallback dinâmico de driver SQLite (better-sqlite3 prioritário sob Bun, bun:sqlite fallback; Node preservado) + correção de estabilidade do DAST CI smoke.
Validado a fundo (worktree board sobre tip): bun-support 4/4, typecheck:core limpo, dashboard-typecheck OK (220 dentro do baseline), open-sse-typecheck OK (5 pré-existentes), gate de runtime OK sob Node, changelog-integrity OK, file-size/complexity/cognitive/dead-code OK. Verificado que o driver preserva a cadeia Node/falback conforme AGENTS.md; teste bun-support presente. Baselines de typecheck removidos são ratchet honesto (erros não existem mais).
OBS: destravei 2 base-reds do tip neste turno (push direto 7ffa3ef): movi o changelog fragment da diegosouzapw#11050 da seção inválida breaking/ para fixes/, e rebaselinei AddApiKeyModal 1067->1073 (crescimento da diegosouzapw#11056). Sem isso a diegosouzapw#11039 e o resto da fila ficariam vermelhos.
…iegosouzapw#10997) (diegosouzapw#11074)

⭐5 — api.blackbox.ai retorna 404 (curl-verificado); espelha o precedente galadriel: deprecated:true + riskNoticeVariant + subscriptionRisk + deprecationReason (flag de display apenas, não bloqueia registro/execução). TDD + 171 testes irmãos. Fecha diegosouzapw#10997.
…the id (diegosouzapw#11076)

⭐5 — /v1/combos strip connectionId de propósito; dois passos pinando contas DIFERENTES do mesmo provider viram objetos byte-idênticos e um cliente conclui que não há failover. Adiciona accountPinned (boolean derivado do connectionId, nunca vaza o id) em cada passo model; sempre true/false, nunca em combo-ref. Sem rota/schema/mudança de caller. TDD. Fecha diegosouzapw#10968.
…gosouzapw#10265) (diegosouzapw#11072)

⭐5 — Fecha diegosouzapw#10265: chat do command-code migra do endpoint CLI-only /alpha/generate (version-gated + proxy-blocked para callers externos) para o documentado /provider/v1/chat/completions (OpenAI format). Removido o envelope CLI reverse-engineered (config/memory/taste/skills + headers CLI-impersonation), substituído por passthrough OpenAI plano com normalização de model id vendor-prefixed (diegosouzapw#10809), clamp de max_tokens (diegosouzapw#5166), sanitização de reasoning_effort. commandCode.ts 1037→171 linhas.
Validado no worktree board sobre tip: typecheck:core limpo; 175/175 testes focados (command-code executor/vision/usage/maxtokens/user-array/validation-specialty/responses-handler/provider-models-scoping); changelog-integrity/file-size/complexity/cognitive todos OK. TDD RED→GREEN documentado.
…ty alias note (diegosouzapw#11069)

⭐5 — M365 Copilot (BizChat) individual/consumer path — 3 itens: (1) forma de invocação do diegosouzapw#10718 derivou de novo (2026-08-21 capture): optionsSets 14→34, allowedMessageTypes 6→30, tone "magic"→"Magic", plugins []→[{BingWebSearch}], disconnectBehavior em todos os tiers, +8 keys de clientInfo; verificado contra conta real com round-trip WebSocket (ping-then-close → resposta real). (2) Aviso sobre o alias Antigravity gemini-3.1-pro-high ainda não publicado (3.8.49 pré-data). (3) Botão "Import .har file" no modal de credencial M365.

Conflito resolvido em copilot-m365-frames.ts (board vs release tip): mantive o forwarding de opts.plugins/toolChoice/customInstructions do HEAD com os NOVOS defaults da captura (BingWebSearch builtin, tone "Magic"). Alinhei 3 testes pré-existentes que afirmavam o contrato antigo (m365-bizchat-frames-4042 clientInfo, m365-tone-model-variants tone, copilot-m365-tool-calls plugins) — propagação de contrato, não mascaramento. Rebaselinei AddApiKeyModal 1073→1080 (crescimento próprio da parte 3, ~Har import button) com anotação.

Validação: typecheck limpo, 142/142 testes m365/copilot verdes, changelog-integrit/file-size/eslint OK.
…ost-event cleanup

The webhook ghost-event removal (diegosouzapw#11050) reverted the description from
'provider.error, budget.exceeded' back to 'request.failed, quota.exceeded'
since provider.error is no longer emitted. Regenerate SKILL.md to match.
jonlwheat2-gif pushed a commit that referenced this pull request Aug 23, 2026
…ocess-spawning endpoints (diegosouzapw#11189)

Validated on the combined batch board (gates + typecheck clean) and this branch: security-route-guard-tiers green. Regression coverage for the Hard Rule #15/#17 contract — Tier 1 process-spawning prefixes (/api/services/, /api/mcp/, /api/cli-tools/runtime/) must stay LOCAL_ONLY before any auth check. Conflict with the tip was only stale provider-count docs. Thank you @rqzbeh!
@jonlwheat2-gif
jonlwheat2-gif deleted the fix/release-v3.8.50-sync-release-commits branch August 25, 2026 20:33
jonlwheat2-gif pushed a commit that referenced this pull request Sep 15, 2026
…LOCAL_ONLY (diegosouzapw#13745)

GHSA-35fw-cv32-2373 and GHSA-jx89-f37j-pq89 — the same defect class as
/api/acp/agents (GHSA-hf57): a route whose handler chain spawns a host process
was classified Tier 3 MANAGEMENT only, and requireManagementAuth() waives auth
when requireLogin=false. Hard Rules #15/#17 require the LOCAL_ONLY gate, which
runs on the stamped real peer before any auth check.

cli-tools (GHSA-35fw): 14 routes reach
getCliRuntimeStatus() -> locateCommand() -> runProcess("sh", ["-c",
'command -v -- "$1"']) -> spawn(), exactly like their six gated siblings
(forge/grok-build/jcode/qwen/omp/letta-settings):
all-statuses, status, and the claude/cline/codewhale/codex/crush/deepseek-tui/
droid/kilo/openclaw/pi/smelt-settings routes. The advisory counted 13; it
missed /api/cli-tools/detect, which is heavier — detectAllTools() runs
execFile(binary, ["--version"]) and execFile("which") per tool.

skills (GHSA-jx89): POST /api/skills/install stores the request's handlerCode
verbatim as the skill handler with no allowlist, so a value equal to a built-in
name (execute_command / eval_code) aliases the real sandboxed built-in;
POST /api/skills/executions then runs it. The sandbox is a real container, but
the spawn is transitive, which is why the 6A.8 source scan never flagged it.

Entries are exact paths, not a /api/cli-tools/ blanket prefix: apply, backups,
config, guide-settings, hermes-agent-settings, keys, logs, openclaw/auto-order
and codex-profiles do not spawn and remote dashboards use them. All 16 are
mirrored into SPAWN_CAPABLE_PREFIXES (no manage-scope bypass) and added to the
route-guard-membership roots so the gate enforces them from now on.

Functional trade-off, same one already accepted for grok/forge/jcode/qwen: a
dashboard served through a tunnel no longer shows the CLI Tools status badges.

Tests are red-first. Two existing negative controls pointed at routes that turn
out to spawn (/api/cli-tools/all-statuses, /api/skills/install); they now point
at routes that genuinely do not (/api/cli-tools/config, /api/skills/marketplace,
/api/skills/skillssh/install), so the non-over-gating assertions are kept.
jonlwheat2-gif pushed a commit that referenced this pull request Sep 16, 2026
…apw#13717)

Merged after a maintainer rework that kept every one of @HouMinXi's commits intact.

**What the rework added on top of the contribution:** the new DB health-check behaviour is gated behind a default-off feature flag (`src/shared/constants/featureFlagDefinitions.ts`, `defaultValue: "false"`), documented in `docs/reference/FEATURE_FLAGS.md` with the description key carried into all 66 locales, so the release default is unchanged and the new bounds only apply when an operator opts in. The optional-FTS5 migration set was reconciled by hand with the "180" entry that landed meanwhile (`src/lib/db/migrationRunner/constants.ts`).

**Carried from your rebased head:** the `/api/db/health` local-only classification in `src/server/authz/routeGuard.ts` plus its `routeGuard` assertion — `runManagedDbHealthCheck()` forks native diagnostics into a child process, so Hard Rules #15/#17 apply. Re-verified here: 37 pass / 0 fail.

Validated as a combined board first (this PR merged with the 21 siblings of the same wave on the release tip): eslint with the frozen suppressions, typecheck:core, check:open-sse-typecheck, complexity, cognitive-complexity, changelog-integrity, i18n new-key coverage, docs-counts, docs-sync, migration-numbering, provider-consistency and a duplicate-identifier audit all green, plus 176 passing / 0 failing focused node:test cases across the 25 test files the wave touches and the dashboard test under Vitest (2/0). Then re-validated alone on the fresh tip before this merge: conflicts re-resolved, file sizes rebaselined for this PR's own growth, eslint and this PR's focused tests re-run.

Thank you for the depth of this one — the resource-bounds suite and the sql.js startup/backup coverage are the kind of tests that keep a database layer honest.
jonlwheat2-gif pushed a commit that referenced this pull request Sep 29, 2026
…the loopback-only tier (diegosouzapw#15041)

/api/version-manager/* is now loopback-only (read-only GETs exempted) and the install version is pattern-validated (Hard Rules #15/#17). 12 failures on the tip, green with the change; check-route-guard-membership, openapi security-tier and route-guard suites green. Thank you @HouMinXi!
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

9 participants