Files
OmniRoute/tests/unit/combo-model-name-collision-8530.test.ts
Diego Rodrigues de Sa e Souza a784c52d34 fix(api): warn (never reject) when a combo name shadows a real model id (#8530) (#8563)
POST /api/combos and PUT /api/combos/[id] had zero validation or
observability when a combo name collided with a real model id, and
sseModelService.getComboForModel() always resolves the combo first. That
combo-first precedence is not a bug: #6940 documents a combo named after a
bare model id (e.g. `gpt-5.5`) as the supported mechanism for per-model
provider fallback, reusing the #3227/#3233 machinery and covered by
tests/unit/responses-combo-resolution-3227.test.ts and
tests/unit/combo-name-codex-responses-rewrite.test.ts. Hard-rejecting a
colliding name (as #8530's literal acceptance criteria requested) would
regress that documented workflow.

Instead, both routes now attach a non-blocking `warning` field
(`COMBO_NAME_SHADOWS_MODEL`) to the create/rename response when the name
collides with a real model id, and a new boot-time scan
(scanComboModelNameCollisionsAtBoot in src/instrumentation-node.ts) logs a
startup warning enumerating existing collisions — so an operator who hits
this by accident has a signal, while the #6940-sanctioned pattern keeps
working exactly as before.

New tests/unit/combo-model-name-collision-8530.test.ts proves both: the
sanctioned shapes (create/rename to a colliding name) still return
201/200 with the warning attached, and non-colliding names get no warning
field at all.

Co-authored-by: ikelvingo <im.kelvinwong@gmail.com>
2026-07-26 03:52:58 -03:00

191 lines
6.8 KiB
TypeScript

// #8530 — combo name / model id collision guard.
//
// #6940 (closed by the maintainer) documents a combo named identically to a
// bare model id (e.g. combo `gpt-5.5`) as THE supported mechanism for
// per-model provider fallback — see `tests/unit/responses-combo-resolution-3227.test.ts`
// and `tests/unit/combo-name-codex-responses-rewrite.test.ts` for the
// combo-before-rewrite precedence this relies on. So creation/rename must
// NEVER hard-reject a colliding name (that would regress #6940); it must
// only make the collision observable via a non-blocking `warning` field.
import test from "node:test";
import assert from "node:assert/strict";
import fs from "node:fs";
import os from "node:os";
import path from "node:path";
const TEST_DATA_DIR = fs.mkdtempSync(path.join(os.tmpdir(), "omniroute-combo-collision-"));
process.env.DATA_DIR = TEST_DATA_DIR;
const core = await import("../../src/lib/db/core.ts");
const combosDb = await import("../../src/lib/db/combos.ts");
const createRoute = await import("../../src/app/api/combos/route.ts");
const comboRoute = await import("../../src/app/api/combos/[id]/route.ts");
const collision = await import("../../src/lib/combos/modelNameCollision.ts");
// A model id that really is registered by multiple providers (verified via
// PROVIDER_MODELS at write time — see open-sse/config/providers/*).
const REAL_MODEL_ID = "gpt-5.5";
// Not a registered bare model id anywhere in the provider registry.
const NON_COLLIDING_NAME = "not-a-real-model-8530-guard-probe";
interface ComboResponseBody {
name?: string;
warning?: { code: string; modelId: string; providerId: string };
}
async function resetStorage() {
core.resetDbInstance();
fs.rmSync(TEST_DATA_DIR, { recursive: true, force: true });
fs.mkdirSync(TEST_DATA_DIR, { recursive: true });
}
function makeCreateRequest(body: unknown) {
return new Request("http://localhost/api/combos", {
method: "POST",
headers: { "content-type": "application/json" },
body: JSON.stringify(body),
});
}
function makeUpdateRequest(body: unknown) {
return new Request("http://localhost/api/combos/combo-1", {
method: "PUT",
headers: { "content-type": "application/json" },
body: JSON.stringify(body),
});
}
test.beforeEach(async () => {
await resetStorage();
});
test.after(() => {
core.resetDbInstance();
fs.rmSync(TEST_DATA_DIR, { recursive: true, force: true });
});
test("POST /api/combos: name colliding with a real model id is created (#6940 pattern), with a warning", async () => {
const response = await createRoute.POST(
makeCreateRequest({
name: REAL_MODEL_ID,
strategy: "priority",
models: [
{ providerId: "codex", model: REAL_MODEL_ID },
{ providerId: "openai", model: REAL_MODEL_ID },
],
})
);
const body = (await response.json()) as ComboResponseBody;
// Legitimate/sanctioned shape MUST still pass — never a 4xx (would regress #6940).
assert.equal(response.status, 201);
assert.equal(body.name, REAL_MODEL_ID);
const stored = await combosDb.getComboByName(REAL_MODEL_ID);
assert.equal(stored?.name, REAL_MODEL_ID);
// But it is now observable via a non-blocking warning.
assert.equal(body.warning?.code, "COMBO_NAME_SHADOWS_MODEL");
assert.equal(body.warning?.modelId, REAL_MODEL_ID);
assert.equal(typeof body.warning?.providerId, "string");
});
test("POST /api/combos: non-colliding name is created with no warning field at all", async () => {
const response = await createRoute.POST(
makeCreateRequest({
name: NON_COLLIDING_NAME,
strategy: "priority",
models: [{ providerId: "claude", model: "claude-sonnet-4-6" }],
})
);
const body = (await response.json()) as ComboResponseBody;
assert.equal(response.status, 201);
assert.equal(body.name, NON_COLLIDING_NAME);
assert.equal("warning" in body, false);
});
test("PUT /api/combos/[id]: renaming to a real model id is applied (#6940 pattern), with a warning", async () => {
const combo = await combosDb.createCombo({
name: "claude-plain",
models: [{ provider: "claude", model: "claude-sonnet-4-6" }],
});
const response = await comboRoute.PUT(makeUpdateRequest({ name: REAL_MODEL_ID }), {
params: Promise.resolve({ id: combo.id }),
});
const body = (await response.json()) as ComboResponseBody;
// Legitimate/sanctioned rename MUST still pass — never a 4xx.
assert.equal(response.status, 200);
assert.equal(body.name, REAL_MODEL_ID);
const stored = await combosDb.getComboByName(REAL_MODEL_ID);
assert.equal(stored?.id, combo.id);
assert.equal(body.warning?.code, "COMBO_NAME_SHADOWS_MODEL");
assert.equal(body.warning?.modelId, REAL_MODEL_ID);
});
test("PUT /api/combos/[id]: renaming to a non-colliding name has no warning field", async () => {
const combo = await combosDb.createCombo({
name: "claude-plain",
models: [{ provider: "claude", model: "claude-sonnet-4-6" }],
});
const response = await comboRoute.PUT(makeUpdateRequest({ name: NON_COLLIDING_NAME }), {
params: Promise.resolve({ id: combo.id }),
});
const body = (await response.json()) as ComboResponseBody;
assert.equal(response.status, 200);
assert.equal(body.name, NON_COLLIDING_NAME);
assert.equal("warning" in body, false);
});
test("scanCombosForModelCollisions: reports existing combos that shadow a real model id", () => {
const results = collision.scanCombosForModelCollisions([
{ name: REAL_MODEL_ID },
{ name: NON_COLLIDING_NAME },
{ name: "" },
]);
assert.equal(results.length, 1);
assert.equal(results[0].comboName, REAL_MODEL_ID);
assert.equal(results[0].modelId, REAL_MODEL_ID);
});
test("findCollidingModel: returns null for a name with no real-model-id collision", () => {
assert.equal(collision.findCollidingModel(NON_COLLIDING_NAME), null);
});
test("scanComboModelNameCollisionsAtBoot: logs a startup warning enumerating existing collisions", async () => {
await combosDb.createCombo({
name: REAL_MODEL_ID,
models: [{ provider: "codex", model: REAL_MODEL_ID }],
});
await combosDb.createCombo({
name: NON_COLLIDING_NAME,
models: [{ provider: "claude", model: "claude-sonnet-4-6" }],
});
const { scanComboModelNameCollisionsAtBoot } = await import("../../src/instrumentation-node.ts");
const originalWarn = console.warn;
const warnings: unknown[][] = [];
console.warn = (...args: unknown[]) => {
warnings.push(args);
};
try {
await scanComboModelNameCollisionsAtBoot();
} finally {
console.warn = originalWarn;
}
const collisionWarning = warnings.find((args) =>
String(args[0]).includes("share a name with a real model id (#8530)")
);
assert.ok(collisionWarning, "expected a startup warning about the model-name collision");
assert.ok(String(collisionWarning![0]).includes(REAL_MODEL_ID));
assert.ok(
!String(collisionWarning![0]).includes(NON_COLLIDING_NAME),
"non-colliding combo must not be reported"
);
});