Commit Graph

4561 Commits

Author SHA1 Message Date
Ronald Estacion
eb47b92f22 fix(compression): allow enginesExplicit through PUT validation schema (#4532)
Adds enginesExplicit to the strict compression PUT schema so the panel can save without a 400. Kept only this commit; the Hub-render commit was superseded by Phase 2 (#4521) which rewrote CompressionHub.tsx. Does not reopen the Phase 1 gate (enginesExplicit is recomputed from stored engines, the persisted row is ignored). Tested.

Integrated into release/v3.8.33.
2026-06-21 15:44:22 -03:00
Diego Rodrigues de Sa e Souza
4d3a9fd3df fix(mcp): webFetchInput emits 'URL is required' for a missing url (#4510) (#4541)
The omniroute_web_fetch input schema (#4510) used z.string().min(1, "URL is
required") for the url field, but .min() only fires for an empty string. A
MISSING url (webFetchInput.parse({})) fails the z.string() type check first and
emitted the default Zod v4 message ("expected string, received undefined"), so
the existing test 'webFetchInput rejects missing URL' (expecting /URL is
required/) failed on the full unit suite — a latent base red on release/v3.8.33.

Add the custom message to the type check: z.string({ error: "URL is required" }).
Now both the missing-field and empty-string cases emit 'URL is required'; a valid
url still passes. No other web_fetch behavior changes.

Co-authored-by: Diego Rodrigues de Sa e Souza <diego.souza@cdwasolutions.com.br>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-21 15:43:55 -03:00
Marcos
2b21bb60d9 feat(webhooks): enrich telegram request notifications (#4524)
Adds account/combo/latency/fallbackCount to telegram request.completed notifications; account UUID rendered via truncated display name (no sensitive data leak). Tested. Rebuilt onto release/v3.8.33.

Integrated into release/v3.8.33.
2026-06-21 15:43:21 -03:00
Abhishek Divekar
f91cf72c16 feat(bazaarlink): add authHint to existing APIKEY_PROVIDERS entry (#4522)
Adds authHint + enriched freeNote/apiHint on the existing bazaarlink entry (distinct from the closed-redundant #4497). Integrity test included.

Integrated into release/v3.8.33.
2026-06-21 15:42:45 -03:00
Rahul sharma
9ade3e5f52 fix(no-think): normalize provider prefix to canonical in no-think variants (#4531)
Adds pure normalizeProviderPrefix helper + opt-in aliasToCanonical map so no-think variant ids use canonical provider prefixes in canonical catalog mode. Tested. Rebuilt onto release/v3.8.33.

Integrated into release/v3.8.33.
2026-06-21 15:41:59 -03:00
Chewji
9cf96d0e9f fix(combo): pass maxCooldownMs from settings to recordModelLockoutFailure call sites (#4530)
The combo.ts lockout call sites never forwarded mlSettings.maxCooldownMs to recordModelLockoutFailure, so the admin-configured cap fell back to BACKOFF_CONFIG.max. Passes it at all 3 sites. TDD included.

Integrated into release/v3.8.33.
2026-06-21 15:37:23 -03:00
Diego Rodrigues de Sa e Souza
948213899f chore(quality): reconcile file-size baseline (owner final) (#4535)
Rule #9.
2026-06-21 14:26:25 -03:00
Diego Rodrigues de Sa e Souza
2601a557b8 refactor(chatCore): extract Background Task Redirect decision (T41) (#4526, #3501)
Rebuilt onto release/v3.8.33 (base was the now-merged #4511 branch). Integrated into release/v3.8.33.
2026-06-21 14:23:36 -03:00
Diego Rodrigues de Sa e Souza
b28f6e9346 refactor(chatCore): extract pure persistCodexQuotaState core (#4492, #3501)
Rebuilt onto release/v3.8.33. Extracts persistCodexQuotaState into a pure leaf (chatCore/codexQuota.ts). Integrated into release/v3.8.33.
2026-06-21 14:19:34 -03:00
Diego Rodrigues de Sa e Souza
aa019bbb95 fix(mitm): gate sudo prompts on server platform, not browser UA (#4514)
Rebuilt onto release/v3.8.33; reconciled with #4503 (kept fetchModelAliases) — sudo gating now uses server-reported isWin/needsSudoPassword instead of browser UA. Integrated into release/v3.8.33.
2026-06-21 14:16:40 -03:00
Diego Rodrigues de Sa e Souza
96d7f2ac62 fix(mitm): graceful sudo degradation in slim Docker / non-root containers (#4513)
Rebuilt onto release/v3.8.33 (squash-base-stale). Integrated into release/v3.8.33.
2026-06-21 14:15:06 -03:00
Diego Rodrigues de Sa e Souza
34d9335c5f fix(pricing): default cost rows for Antigravity Gemini 3.5 Flash tiers + gemini-pro-agent (#4508)
Rebuilt onto release/v3.8.33 (squash-base-stale). Integrated into release/v3.8.33.
2026-06-21 14:14:53 -03:00
Diego Rodrigues de Sa e Souza
840413faa2 feat(dashboard): inline show/hide toggle for API keys on API Manager page (#4505)
Rebuilt onto release/v3.8.33 (squash-base-stale). Integrated into release/v3.8.33.
2026-06-21 14:14:41 -03:00
Diego Rodrigues de Sa e Souza
bb16f88524 fix(dashboard): enable Codex Apply/Reset buttons when the CLI is installed (#4504)
Rebuilt onto release/v3.8.33 (squash-base-stale). Integrated into release/v3.8.33.
2026-06-21 14:14:28 -03:00
Diego Rodrigues de Sa e Souza
d83e0a4fab fix(dashboard): show API-Key-compatible providers in Antigravity CLI Tools model picker (#4503)
Rebuilt onto release/v3.8.33 (squash-base-stale). Integrated into release/v3.8.33.
2026-06-21 14:14:16 -03:00
Diego Rodrigues de Sa e Souza
4cf73428f8 fix(dashboard): migrate ManualConfigModal copy to shared useCopyToClipboard hook (#4502)
Rebuilt onto release/v3.8.33 (squash-base-stale). Integrated into release/v3.8.33.
2026-06-21 14:14:02 -03:00
Diego Rodrigues de Sa e Souza
89606a2bfe feat(dashboard): toggle-style model deselection in combo builder modal (#4498)
Rebuilt onto release/v3.8.33; reconciled with the already-merged keepOpenOnSelect (#4496) — deselection now rides the existing keepOpenOnSelect + onDeselect wiring instead of a redundant closeOnSelect prop. Integrated into release/v3.8.33.
2026-06-21 14:13:38 -03:00
Diego Rodrigues de Sa e Souza
247e578778 feat(dashboard): Done button in model picker for combo creation (#4496)
Rebuilt onto release/v3.8.33 (squash-base-stale). Integrated into release/v3.8.33.
2026-06-21 14:09:55 -03:00
Diego Rodrigues de Sa e Souza
dac9f7de16 feat(dashboard): per-provider dropdown filter on the quota dashboard (#4495)
Rebuilt onto release/v3.8.33 (squash-base-stale). Integrated into release/v3.8.33.
2026-06-21 14:09:43 -03:00
Diego Rodrigues de Sa e Souza
bb8104f454 chore(quality): reconcile file-size baseline (owner batch1 #4488/#4500) (#4534)
Rule #9.
2026-06-21 14:09:16 -03:00
Diego Rodrigues de Sa e Souza
3a0c40bb5e fix(usage): clear auth-expired message for Kiro social-auth accounts (#4512)
Rebuilt onto release/v3.8.33; usage.ts baseline reconciled for the #4493/#4494/#4512 quota trio. Integrated into release/v3.8.33.
2026-06-21 14:08:01 -03:00
Diego Rodrigues de Sa e Souza
a37ee2fac5 feat(usage): surface Codex code-review weekly window + additional_rate_limits fallback (#4494)
Rebuilt onto release/v3.8.33 (squash-base-stale). Integrated into release/v3.8.33.
2026-06-21 14:06:18 -03:00
Diego Rodrigues de Sa e Souza
cd45943015 fix(usage): parse numeric-string quota reset timestamps as Unix sec/ms (#4493)
Rebuilt onto release/v3.8.33 (squash-base-stale). Integrated into release/v3.8.33.
2026-06-21 14:06:05 -03:00
Diego Rodrigues de Sa e Souza
4279751abd fix(sse): skip disabled providers in combo fallback (#4500)
Rebuilt onto release/v3.8.33 (squash-base-stale). Integrated into release/v3.8.33.
2026-06-21 14:05:53 -03:00
Diego Rodrigues de Sa e Souza
e1546c0118 fix(api): dedupe exact-duplicate ids in /v1/models (#4506, #4424)
Rebuilt onto release/v3.8.33 (squash-base-stale). Integrated into release/v3.8.33.
2026-06-21 14:05:41 -03:00
Diego Rodrigues de Sa e Souza
482433e44f feat(translator): accept OpenAI audio input parts in Gemini translation (#4434)
Rebuilt onto release/v3.8.33 (squash-base-stale). Integrated into release/v3.8.33.
2026-06-21 14:05:29 -03:00
Diego Rodrigues de Sa e Souza
81016bdaeb feat(pricing): add default pricing for Qwen coder-model on qw provider (#4488)
Rebuilt onto release/v3.8.33 (squash-base-stale). Integrated into release/v3.8.33.
2026-06-21 14:05:16 -03:00
Diego Rodrigues de Sa e Souza
aee1f7445d feat(providers): expose gpt-4o on built-in GitHub Copilot (gh) provider (#4487)
Rebuilt onto release/v3.8.33 (squash-base-stale). Integrated into release/v3.8.33.
2026-06-21 14:04:40 -03:00
Diego Rodrigues de Sa e Souza
58d1cc8f03 feat(compression): Phase 2 — named profiles + active selector (#4521)
Compression config Phase 2: named profiles + single active-combo selector wired into the runtime.

Integrated into release/v3.8.33.
2026-06-21 14:02:56 -03:00
Diego Rodrigues de Sa e Souza
185c474ee0 feat(sse): route web_search requests to a configured model (#4509, #4481)
Routes requests carrying a web_search tool to a configured webSearchRouteModel (#4481 layer-2).

Integrated into release/v3.8.33.
2026-06-21 14:02:29 -03:00
Diego Rodrigues de Sa e Souza
f3253ee706 fix(sse): crypto-secure RNG for combo/deck load-balancing selection (#4455)
Replaces Math.random with crypto-secure RNG in combo/deck load-balancing selection (CodeQL #665).

Integrated into release/v3.8.33.
2026-06-21 14:02:01 -03:00
Diego Rodrigues de Sa e Souza
bb4aa0d793 chore(quality): rebaseline cognitiveComplexity 783->792 (#4529)
Cycle drift + #4398 +2. Documented breakdown. Rule #9.
2026-06-21 12:41:55 -03:00
Diego Rodrigues de Sa e Souza
5b15e0192e chore(quality): reconcile file-size baseline for #4519 (#4528)
combo.ts/accountFallback.ts/openai-responses.ts from #4519. Rule #9.
2026-06-21 12:38:34 -03:00
Abhishek Divekar
cda583114f fix(command-code): cap max_tokens per model using registry maxOutputTokens (#4518)
clampMaxTokens now uses the per-model maxOutputTokens from REGISTRY['command-code'] as the upper bound (falls back to MAX_COMMAND_CODE_TOKENS), so GLM-5.x stops being rejected for max_tokens > 131072. Rebuilt onto release/v3.8.33 (passthrough block from the PR base is already present via #2986); 3 tests added.

Integrated into release/v3.8.33.
2026-06-21 12:33:25 -03:00
KooshaPari
c5f3d5fb56 fix(db): scheduled VACUUM + persist lastVacuumAt (#4480, #4437)
Adds a scheduled SQLite VACUUM job that persists last-run state to key_value and fixes the hardcoded lastVacuumAt:null in getDatabaseSettings. Review fixes: corrected the key_value write (no updated_at column), dropped a dead/colliding migration, rewrote the test from Vitest to node:test against the real interface.

Integrated into release/v3.8.33.
2026-06-21 12:29:23 -03:00
Abhishek Divekar
694adf7e13 fix(combo): allow fallback on context-overflow & param-validation 400s; preserve upstream codes (#4519)
Context-overflow and param-validation 400s now fall through to the next combo target (different targets have different context windows / output limits); normalizeUpstreamFailure keeps context_length_exceeded=400 and rate-limit=429. Pure predicates extracted + tested (Rule #18). The codex.ts compression seen in the raw diff was base-divergence noise, not in the feature commit.

Integrated into release/v3.8.33.
2026-06-21 12:29:20 -03:00
Witroch4
d3f1b23a93 feat(usage): API-key USD quota percent + reset hints, weekly window cutoff (#4398)
Adds USD usage percentages and reset hints to @@om-usage and 400 quota rejections, and cuts the weekly USD window at the real observed reset via quota_snapshots instead of resetAt-7d. Rebuilt onto release/v3.8.33 (squash-base-stale; delta = 5 files/+353).

Integrated into release/v3.8.33.
2026-06-21 12:02:34 -03:00
Diego Rodrigues de Sa e Souza
69f63898de chore(quality): reconcile file-size baseline for #4510 web_fetch tool (#4523)
tools.ts 1437->1497, server.ts 1509->1555 from #4510. Justification per Rule #9.
2026-06-21 12:01:57 -03:00
KooshaPari
39592420e4 chore(i18n): remove unused config helpers (#4482)
Removes dead exports DOCS_TARGET_LOCALES and getLanguage (zero callers, Knip-reported) and adds config-adapter coverage test.

Integrated into release/v3.8.33.
2026-06-21 11:58:33 -03:00
Rahul sharma
296b72d070 feat(models): qualify duplicate model names with provider prefix (#4516)
Disambiguates display names when the same model name appears across distinct provider prefixes. Pure, non-mutating; complementary to id-dedupe.

Integrated into release/v3.8.33.
2026-06-21 11:55:11 -03:00
Oonishi
75a84b055f feat(mcp): add omniroute_web_fetch tool for URL content extraction (#4510)
Adds an MCP tool to extract URL content via the existing /v1/web/fetch endpoint (Firecrawl/Jina/Tavily). Mirrors omniroute_web_search; scope execute:search; mcp_audit logged.

Integrated into release/v3.8.33.
2026-06-21 11:55:08 -03:00
Diego Rodrigues de Sa e Souza
335df93d85 chore(release): open v3.8.33 development cycle 2026-06-21 10:41:12 -03:00
Demiurge The Single
0299907a87 fix(auto): enforce quota cutoff before scoring (#4483)
Thanks @megamen32! Rebased onto release/v3.8.32. On review (owner decision) the auto-routing quota cutoff was made OPT-IN behind QuotaPreflightSettings.enabled (default OFF, so current behavior is unchanged) and the ...eligibleTargets last-resort fallback was restored so a quota-blocked target survives as final fallback rather than vanishing. The 429-when-all-blocked guard stays for the enabled path. typecheck clean, 13/13 tests.

(cherry picked from commit 1831c6eca8)
2026-06-21 09:32:15 -03:00
Diego Rodrigues de Sa e Souza
ac65652ed9 fix(antigravity): strip Claude/OpenAI thinking fields from Cloud Code envelope (port from 9router#1926) (#4485)
The unified thinking adapter can set Claude/OpenAI-native thinking fields
(thinking, reasoning_effort, reasoning, enable_thinking, thinking_budget) at
the request body root. The Antigravity envelope spreads ...passthroughFields,
so these leaked into the Google Cloud Code envelope and Google rejected the
request with `400 Bad input: oneOf at '/' not met` (or `Unknown name
"thinking"`), breaking every reasoning/thinking model served via Antigravity
(e.g. claude-opus-4-x-thinking).

Extends the existing #1944 envelope strip (output_config/output_format) to
also drop the whole thinking family. Gemini's own generationConfig.thinkingConfig
travels inside the inner request and is unaffected, so thinking still works.

Reported-by: theseven99 (https://github.com/decolua/9router/issues/1926)

Co-authored-by: Arcfoz <62255009+Arcfoz@users.noreply.github.com>
(cherry picked from commit 5a7c1e1731)
2026-06-21 09:32:12 -03:00
KooshaPari
84626f6b04 perf(dashboard): shrink provider assets and fix usage rollup cutoff (#4464)
Thanks @KooshaPari! Merged the core of this PR (provider-asset shrink + budget gate + usage-rollup same-day cutoff fix + test), rebuilt scoped on release/v3.8.32. On review we dropped the codeqlAlerts 0->1 baseline loosening and the off-topic changes (the codex/memory contract fixes already landed via #4474; getProviderNames removal + cognitive baseline left out). Asset gate passes, rollup 22/22.

(cherry picked from commit 911e1fb3cc)
2026-06-21 09:32:11 -03:00
KooshaPari
d2088ba97c fix(integration): restore codex and memory pipeline contracts (#4474)
Thanks @KooshaPari! Rebased onto release/v3.8.32 (clean cherry-pick — coexists with #4467's specialty changes, 118/118 unit + 12/12 memory-pipeline integration). Codex fingerprint ordering + memory-search contract fixes land.

(cherry picked from commit 21d61c69d7)
2026-06-21 09:32:11 -03:00
Diego Rodrigues de Sa e Souza
bfaf459f3c Release v3.8.32 (#4418)
Release v3.8.32 — see CHANGELOG.md [3.8.32] for the full list. Merged via --admin over documented non-blocking checks: CodeQL alerts ratchet (#665 fixed by #4457/#4462, auto-closes on main rescan), Integration Tests (env-flaky batch-upstream), SonarCloud/SonarQube (advisory new-code).
v3.8.32
2026-06-21 08:56:51 -03:00
Diego Rodrigues de Sa e Souza
d0396c200d Release v3.8.31 (#4377)
Release v3.8.31 — see CHANGELOG.md [3.8.31] for full notes and contributors.

Merged over known non-blocking reds (all correctness gates green): Integration Tests (2/2) is env/flaky (polls a real upstream batch that did not complete in the poll window); SonarQube/SonarCloud is the advisory server-side new-code quality gate. Unit (8 shards), Coverage, Node 22/24/26, Lint, PR Test Policy, Quality Ratchet, Docs-Strict, Quality-Extended and all 4 CodeQL analyses are green.
v3.8.31
2026-06-20 14:55:24 -03:00
Diego Rodrigues de Sa e Souza
3b2a2f02a9 test: exact host membership in MITM hosts test — CodeQL FP (#660)
Use exact array-element membership (.some((h) => h === host)) instead of Array.prototype.includes() in the MITM hosts unit test, so CodeQL's js/incomplete-url-substring-sanitization heuristic does not misread an Array.includes membership check as a String.includes URL-substring test. Functionally identical. Mirrors #4386 (already merged into release/v3.8.31). Closes the only open code-scanning alert (#660).
2026-06-20 11:23:07 -03:00
Diego Rodrigues de Sa e Souza
db362b0126 Release v3.8.30 (#4267)
Release v3.8.30 — see CHANGELOG.md [3.8.30] for the full release notes.
v3.8.30
2026-06-20 07:09:43 -03:00