Files
OmniRoute/tests/unit/tool-request-sanitization.test.ts
Diego Rodrigues de Sa e Souza 36abd86929 fix(ci): clear the 08-08 base-red layers — dead-code, prod crash in chat.ts, Responses payload regression, born-red stdio test, gate drifts (#9757)
* fix(ci): drop unused RadarReferrals type export — dead-code ratchet back to 227 baseline

The radar referral-links feature (#9697) exported the inferred type
RadarReferrals from feedSchema.ts but nothing imports it (the singular
RadarReferral is the consumed type). knip counts it as a new dead export,
pushing the dead-code ratchet to 228 > 227 and failing Fast Quality Gates
on every PR born after the merge. RadarReferralsSchema itself stays — it
is used by RadarFeedSchema.

Refs #9737

* fix(ci): clear the 08-08 base-red layer — prod crash in chat.ts, Responses API payload regression, born-red stdio test, gate drifts

Six independent base-reds from the 08-07 evening merge batch, each verified
against the pure release/v3.8.50 tip:

- src/sse/handlers/chat.ts: #9467's squash carried a refactor hunk that
  renamed the all-rate-limited breaker guard to an UNDEFINED variable
  (isAllRateLimited) — a production ReferenceError on the all-accounts-429
  path (chat.ts is outside typecheck:core scope, so only tests caught it).
  Restore credentials?.allRateLimited. Guard: chat-rate-limit-body-lock (2/2),
  also un-breaks batch_api and chat-combo-live-test.
- open-sse/utils/stream.ts: #9315 switched providerPayload summaries to the
  accumulated responseBody, but in passthrough paths that body is synthesized
  in chat-completion shape — Responses API lost its `response` object in the
  dashboard payload. Keep the events-derived summary for OPENAI_RESPONSES
  only. Guard: stream-utils + stream-collector-9315 suites (51/51).
- tests/unit/mcp-stdio-json-purity.test.ts: born red — the full CLI chain
  takes ~10s (2x tsx import + DB init) and the test slept a fixed 4s. Poll
  for the first stdout line with a 60s deadline instead.
- tests/unit/plugins-route-error-sanitization.test.ts: register #9445's new
  marketplace/install route in PLUGIN_ROUTES (route already sanitizes) (33/33).
- tests/unit/provider-models-route-codex.test.ts: realign pinned GPT-5.6
  input limit to #9432's deliberate 272000→922000 bump (7/7).
- lint: fix 11 no-explicit-any errors in repro-9630 + specialty-9293 tests,
  prune 1 orphaned suppression, allowlist the opencode-ai devDependency
  (#8869, publisher-verified), and reword a doc line the fabricated-docs
  gate misread as an env var.

Gates re-verified locally: lint:json --max-warnings 0 exit 0, dead-code 227,
typecheck:core clean, check:deps OK, check:fabricated-docs OK.

Refs #9737

* fix(ci): clear the third 08-08 base-red layer — invalid ru rule pack, stale event pin, orphaned UI repro test, pack/mutation/file-size drifts

Follow-up to the previous layer: the serial fast-gates chain unmasked one
more stratum after file-size/dead-code went green, all verified against the
merged release/v3.8.50 tip:

- compression rules ru/ultra.json (#9581): two rules shipped
  minIntensity "notes", which is not a valid CavemanIntensity
  (lite|full|ultra) — loading ANY language pack list threw and killed the
  rtk-loader suite. Mapped both to "ultra" (they are the most aggressive
  punctuation/case rules, matching the en pack tiers). 2/2.
- plugins-welcome-banner-e2e: #9668 added the onStreamComplete builtin
  event (real emission path via runOnStreamCompleteHooks) and missed this
  pinned-list sibling. 35/35.
- tests/unit/free-pool-frontend-repro (#9046): landed as .tsx with
  node:test semantics — no runner collects tests/unit/*.tsx, so it NEVER
  ran (test-discovery NEW-orphan). It contains zero JSX; renamed to .test.ts
  so the unit runner's existing glob collects it. 5/5 (first real run).
- pack-policy: allow + require bin/mcpStdioConsoleGuard.mjs (#9281) — it is
  preloaded via node --import by bin/mcp-server.mjs, so a published artifact
  without it crashes 'omniroute --mcp' at startup.
- stryker.conf.json: add 5 covering unit tests from the batch (#8779/#9204/
  #9330/#9630/openrouter-passthrough) to tap.testFiles (--strict drift).
- file-size-baseline: consolidate the base-drift rebaseline for the 12
  files grown by the 08-06..08-08 batches (#9616's entries never reached the
  base; measured on this branch's tree — this PR's own source edits add zero
  lines to any frozen file).

Local battery: file-size/deps/test-discovery/mutation/pack-policy/dead-code/
duplication/docs-all/secrets/vuln/workflows ratchets all exit 0; full lint
gate --max-warnings 0 exit 0.

Refs #9737

* fix(types): clear the 3 uncovered open-sse-typecheck regressions + realign combo skip-code siblings

Fourth base-red layer unmasked by the serial gates. The other 4 typecheck
regressions (codex.ts, kiro.ts, tierResolver.test.ts, translator/index.ts)
already have dedicated open [TS7] PRs (#9748/#9753/#9742/#9747) — not
duplicated here. This commit covers only what no open PR owns:

- devin-agentic/serializer.ts TS2367: drop the dead 'role === "system"'
  branch — the guard above already narrows role to user|assistant (system
  throws unsupported_role). Devin suites 104/104.
- raycast.ts TS2416: the buildHeaders 'override' never matched the base
  signature (2nd param is the signed payload string, not the stream
  boolean) — renamed to a private buildRaycastRequestHeaders helper so a
  polymorphic buildHeaders(credentials, true) call can never bind here.
- modelMetadataRegistry.ts TS2352: PricingByProvider → nested-record cast
  now goes through unknown (shape is runtime-guarded by findInsensitive).
- combo-routing-engine.test.ts: realign 2 pre-dispatch-skip expectations to
  #9630's deliberate ALL_TARGETS_SKIPPED contract (87/87).

Refs #9737

* fix(ci): clear the fifth 08-08 base-red layer — reasoning-placeholder contract sweep, GPT-5.6 limits sweep, vi key parity

The 08-08 merges (#9610 reasoning replay, #9432 GPT-5.6 limits, #9630 combo
skip codes, #9336 provider key links) each changed a contract and left
sibling tests pinning the old one. Full grep sweep per contract, not just
the shard that happened to go red:

- reasoning placeholder (#9573/#9610): the fix DELIBERATELY removed
  NON_ANTHROPIC_THINKING_PLACEHOLDER injection on cache miss — the model
  echoed the placeholder as its own reasoning (empty stop) and re-poisoned
  cache + client history; DeepSeek's 400 is specific to an EMPTY STRING, not
  an absent field. Realigned reasoning-cache (2 cases, renamed to describe
  omission) + tool-request-sanitization (1 case + dead import). 60/60.
- GPT-5.6 Codex limits (#9432, 272000 -> 1050000 ctx / 922000 input):
  realigned vscode-token-routes-gpt56 (2) + vscode-token-routes (3). 43/43
  together with t23-t24.
- combo skip codes (#9630): t23-t24-fallback-resilience T24 now expects
  ALL_TARGETS_SKIPPED like the combo-routing-engine siblings.
- vi.json key parity: #9336 added providers.getApiKey/getApiKeyDescription
  to en.json without syncing vi (the only locale with a parity gate).
  Translated both; providers block reordered to match en key order. 5/5.
- pack-artifact-policy.test.ts: sibling of this PR's own required-paths
  change (bin/mcpStdioConsoleGuard.mjs). 10/10.
- combo-routing-engine.test.ts: dropped the 6 comment lines added in the
  previous commit so the frozen test file-size stays at its baseline (the
  rationale lives in that commit message, not the test body).

Gates: file-size, test-discovery, mutation-test-coverage, pack-policy,
open-sse-typecheck, dead-code all exit 0.

Refs #9737

* fix(translator): keep the reasoning_content placeholder for Xiaomi MiMo — #9610 traded one live 400 for another

The xiaomi-mimo replay test (9router#1321) went red on the base after #9610
removed the NON_ANTHROPIC_THINKING_PLACEHOLDER injection globally. That test
is NOT stale — it guards a documented upstream 400 ('Param Incorrect: The
reasoning_content in the thinking mode must be passed back to the API'), so
realigning it would have masked a reintroduced production bug.

Two real bugs conflict here:
- #9573: forwarding the placeholder makes the model continue its chain of
  thought FROM that text (echo -> empty stop) and re-poisons cache/history.
- 9router#1321/#1337: omitting reasoning_content on a plain replay turn makes
  Xiaomi MiMo reject the request outright.

#9610's evidence for omitting is provider-specific — it verified that
deepseek-v4-flash accepts an ABSENT field. It does not extend to MiMo. So the
omission stays for every provider #9610 covered, and the placeholder survives
the cache miss only for xiaomi-mimo (new requiresReasoningContentPresence
predicate next to isReasoningOnlyReplayTarget). The echo that comes back is
still stripped on the way in by isInternalReasoningPlaceholder(), so #9573's
cache/history poisoning stays fixed for MiMo too.

Both contracts now hold simultaneously: xiaomi-mimo replay + reasoning-cache +
tool-request-sanitization 61/61; placeholder-strip/responses/translator/combo
regression sweep 168/168. Gates: file-size, open-sse-typecheck, dead-code,
mutation-test-coverage exit 0; typecheck:core clean.

A live check on the VPS (Hard Rule #18 path 2) is the only way to confirm the
DeepSeek half of #9610's empirical claim; flagging it in the PR rather than
widening this fix on speculation.

Refs #9737

* test(translator): pin the reasoning-placeholder provider scope so neither half of the conflict can silently re-break

#9610 removed the placeholder globally on the strength of ONE provider's
observed behavior (deepseek-v4-flash accepting an absent reasoning_content),
which re-opened the MiMo 400 (9router#1321). The previous commit scoped the
placeholder to xiaomi-mimo; this pins BOTH directions in one test so the next
global edit fails loudly instead of trading the bugs again:

- xiaomi-mimo plain replay turn, cache miss -> reasoning_content present
  (narrowing the scope away from MiMo re-opens 9router#1321)
- deepseek plain replay turn, cache miss -> reasoning_content absent
  (widening it back to DeepSeek re-opens the #9573 echo bug)

Guard verified by mutation: forcing requiresReasoningContentPresence() to
return true makes the DeepSeek half fail (1 pass / 1 fail), and the file was
restored from the pre-probe copy before committing.

Also checked kimi-coding/kimi-coding-apikey, the other strict-contract entries
in REASONING_REPLAY_PROVIDERS: their originating PR (#7673) fixes capture and
replay of REAL reasoning and documents no 400 on an absent field, so they stay
out of the placeholder scope — evidence-scoped, not speculatively widened.

Reasoning suites together: 87/87. Gates: file-size, test-discovery,
mutation-test-coverage, dead-code exit 0; eslint clean.

Refs #9737

---------

Co-authored-by: diegosouzapw <diegosouzapw@users.noreply.github.com>
2026-08-08 09:08:45 -03:00

238 lines
6.7 KiB
TypeScript

import test from "node:test";
import assert from "node:assert/strict";
const {
coerceSchemaNumericFields,
sanitizeToolDescription,
coerceToolSchemas,
sanitizeToolDescriptions,
injectEmptyReasoningContentForToolCalls,
} = await import("../../open-sse/translator/helpers/schemaCoercion.ts");
const { translateRequest } = await import("../../open-sse/translator/index.ts");
const { FORMATS } = await import("../../open-sse/translator/formats.ts");
const { clearModelsDevCapabilities, saveModelsDevCapabilities } =
await import("../../src/lib/modelsDevSync.ts");
function buildCapability(overrides = {}) {
return {
tool_call: null,
reasoning: null,
attachment: null,
structured_output: null,
temperature: null,
modalities_input: "[]",
modalities_output: "[]",
knowledge_cutoff: null,
release_date: null,
last_updated: null,
status: null,
family: null,
open_weights: null,
limit_context: null,
limit_input: null,
limit_output: null,
interleaved_field: null,
...overrides,
};
}
test("tool sanitization: coerces numeric JSON Schema fields recursively", () => {
const schema = {
type: "object",
properties: {
count: { type: "integer", minimum: "1", maximum: "10" },
items: {
type: "array",
minItems: "2",
items: { type: "string", minLength: "3" },
},
},
};
const result = coerceSchemaNumericFields(schema);
assert.equal((result as any).properties.count.minimum, 1);
(assert as any).equal((result as any).properties.count.maximum, 10);
(assert as any).equal((result as any).properties.items.minItems, 2);
assert.equal((result as any).properties.items.items.minLength, 3);
});
test("tool sanitization: preserves non-numeric JSON Schema strings", () => {
const schema = {
type: "object",
properties: {
value: { type: "string", minimum: "abc" },
},
};
const result = coerceSchemaNumericFields(schema);
assert.equal((result as any).properties.value.minimum, "abc");
});
test("tool sanitization: normalizes descriptions across OpenAI, Claude, and Gemini shapes", () => {
const openAITool = sanitizeToolDescription({
type: "function",
function: { name: "sum", description: null, parameters: {} },
});
const claudeTool = sanitizeToolDescription({
name: "sum",
description: 42,
input_schema: { type: "object" },
});
const geminiTool = sanitizeToolDescription({
functionDeclarations: [{ name: "sum", description: false, parameters: {} }],
});
(assert as any).equal(((openAITool as any).function as any).description, "");
assert.equal((claudeTool as any).description, "42");
assert.equal((geminiTool as any).functionDeclarations[0].description, "false");
});
test("tool sanitization: coerces schemas and descriptions in tool arrays", () => {
const tools = sanitizeToolDescriptions(
coerceToolSchemas([
{
type: "function",
function: {
name: "sum",
description: 5,
parameters: {
type: "object",
properties: {
count: { type: "integer", minimum: "1" },
},
},
},
},
])
);
assert.equal(tools[0].function.description, "5");
assert.equal(tools[0].function.parameters.properties.count.minimum, 1);
});
test("translateRequest sanitizes tools before Claude output", () => {
const translated = translateRequest(
FORMATS.OPENAI,
FORMATS.CLAUDE,
"claude-sonnet-4-6",
{
messages: [{ role: "user", content: "hello" }],
tools: [
{
type: "function",
function: {
name: "sum",
description: null,
parameters: {
type: "object",
properties: {
count: { type: "integer", minimum: "1", maximum: "9" },
},
},
},
},
],
},
false,
null,
"claude"
);
assert.equal(translated.tools[0].description, "");
assert.equal(translated.tools[0].input_schema.properties.count.minimum, 1);
assert.equal(translated.tools[0].input_schema.properties.count.maximum, 9);
});
test("translateRequest sanitizes OpenAI tool payloads on passthrough", () => {
const translated = translateRequest(
FORMATS.OPENAI,
FORMATS.OPENAI,
"gpt-5.2",
{
messages: [{ role: "user", content: "hello" }],
tools: [
{
type: "function",
function: {
name: "sum",
description: 7,
parameters: {
type: "object",
properties: {
count: { type: "integer", minimum: "2" },
},
},
},
},
],
},
false,
null,
"openai"
);
assert.equal(translated.tools[0].function.description, "7");
assert.equal(translated.tools[0].function.parameters.properties.count.minimum, 2);
});
test("tool sanitization: injects empty reasoning_content only for DeepSeek tool-call history", () => {
const messages = [
{ role: "user", content: "hello" },
{
role: "assistant",
tool_calls: [{ id: "call_1", type: "function", function: { name: "sum", arguments: "{}" } }],
},
];
const deepseekMessages = injectEmptyReasoningContentForToolCalls(
messages,
"deepseek",
"deepseek-v4-flash"
);
const openaiMessages = injectEmptyReasoningContentForToolCalls(messages, "openai", "gpt-4o");
assert.equal(deepseekMessages[1].reasoning_content, "");
assert.equal(openaiMessages[1].reasoning_content, undefined);
});
test("translateRequest omits reasoning_content for DeepSeek assistant tool calls on cache miss", () => {
clearModelsDevCapabilities();
saveModelsDevCapabilities({
deepseek: {
"deepseek-v4-flash": buildCapability({
interleaved_field: "reasoning_content",
reasoning: true,
tool_call: true,
}),
},
});
const translated = translateRequest(
FORMATS.OPENAI,
FORMATS.OPENAI,
"deepseek-v4-flash",
{
messages: [
{ role: "user", content: "hello" },
{
role: "assistant",
tool_calls: [
{ id: "call_1", type: "function", function: { name: "sum", arguments: "{}" } },
],
},
{ role: "tool", tool_call_id: "call_1", content: "3" },
],
},
false,
null,
"deepseek"
);
// #9573/#9610: the former NON_ANTHROPIC_THINKING_PLACEHOLDER injection was the root
// cause of the echo → empty-stop bug (the model continued its chain of thought from
// the placeholder and re-poisoned cache + history). On a cache miss the field is now
// omitted; DeepSeek's 400 is specific to an empty string, not an absent field.
assert.equal(translated.messages[1].reasoning_content, undefined);
clearModelsDevCapabilities();
});