Files
OmniRoute/open-sse/mcp-server/tools/compressionTools.ts
Diego Rodrigues de Sa e Souza dc40911583 Release v3.8.39 (#5164)
* chore(release): open v3.8.39 development cycle

* docs(changelog): backfill 5 v3.8.38 bullets merged after release finalize

These PRs squash-merged into release/v3.8.38 between the CHANGELOG finalize
(ff57be32f) and the merge-to-main (ae6e2342d), so they shipped in the v3.8.38
tag but had no bullet:

- feat(compression): Ionizer engine (lossy JSON-array sampling + CCR) (#5148)
- fix(sse): preserve non-stream reasoning fields (#5155, @rdself)
- fix(i18n): add missing English UI labels (#5153, @rdself)
- test(combo): gated live smoke (#5151) + release-expectations refresh (#5150, @KooshaPari)

(#5129 exact-host Anthropic baseUrl is already covered by the #5130 bullet — same CodeQL #674.)
Synced 41 i18n CHANGELOG mirrors.

* feat(compression): TOON best-of-N candidate encoder + encoder A/B table (#5163)

Integrated into release/v3.8.39. TOON best-of-N candidate encoder (GCF default, fail-open). 17/17 unit tests pass on merge result; CI reds were base-stale + Quality Ratchet DRIFT.

* fix(zenmux): normalize vendor-prefixed GLM system roles (#5158)

Integrated into release/v3.8.39. ZenMux vendor-prefixed GLM system-role normalization; 12/12 role-normalizer tests pass on merge result. CI reds base-stale.

* [codex] fix xAI OAuth test and reasoning effort (#5157)

Integrated into release/v3.8.39. xAI reasoning-effort normalization (max/xhigh→high) + OAuth test config; 46/46 xai-translator tests pass on merge result. CI reds base-stale.

* docs(i18n): add Traditional Chinese (zh-TW) README and update zh-CN to latest (#5162)

Integrated into release/v3.8.39. Traditional Chinese (zh-TW) README + zh-CN refresh; docs-only.

* test(security): guard PII redaction stays opt-in (default off) + Hard Rule #20 (#5159)

Integrated into release/v3.8.39. PII opt-in regression guard + Hard Rule #20; rebased to strip base-drift (+81/-1). 5/5 guard tests pass; flip-proof verified.

* test(combo): deterministic context-relay universal-handoff coverage (closes phase-2 TODO) (#5168)

Integrated into release/v3.8.39. Deterministic context-relay universal-handoff coverage (3 tests); 3/3 pass on merge result.

* docs(i18n): full sync zh-TW and zh-CN README with canonical English v3.8.39 (#5171)

Integrated into release/v3.8.39. Full zh-TW docs tree + zh-CN sync with canonical English v3.8.39; docs-only.

* fix(serve): honour HOSTNAME from .env instead of hardcoding 0.0.0.0 (#5134) (#5170)

Integrated into release/v3.8.39. HOSTNAME env override in serve (#5134) + regression test (4/4, TDD flip-proof verified).

* fix(sse): resolve nameless deepseek-web tool blocks via parameter-schema match (#5154) (#5173)

Integrated into release/v3.8.39. Schema-based nameless deepseek-web tool-block resolution (#5154); 6/6 tests pass on merge result (incl. ambiguous/no-match negatives + named-tag no-regression).

* fix(sse): normalize array user content for Command Code to avoid upstream 400 (#5166) (#5174)

Integrated into release/v3.8.39. Normalize array user content for Command Code (#5166, user-array/400 symptom); 4/4 tests pass on merge result.

* fix(sse): defer </think> close so it never leaks before tool_calls (#5123) (#5175)

Integrated into release/v3.8.39. Defer </think> close so it never leaks before tool_calls (#5123); 4/4 tests pass (incl. #4633 no-regression). CHANGELOG synced to keep all 3 v3.8.39 fixes.

* fix(dashboard): use amber for home update-step warning icon (#5176)

Integrated into release/v3.8.39. Amber for home update-step warning icon; 1/1 UI test.

* fix(api): LAN/Tailscale dashboard — host-aware CSP + GET-exempt version route + combo field errors (#5083) (#5177)

Integrated into release/v3.8.39. Host-aware CSP (ReDoS/injection-safe host validation) + GET-exempt /api/system/version (POST/spawn stays LOCAL_ONLY, exact-match safe-methods-only) + COMBO_002 firstField. 44/44 tests + route-guard membership gate green. CHANGELOG synced to keep all 4 v3.8.39 fixes.

* fix(api): replace #5083 global middleware CSP with declarative ws: scheme (#5083)

Follow-up to PR #5177 (merged): that version implemented the LAN-CSP fix (Bug 1)
with a new global `src/middleware.ts` + `src/server/csp.ts`, which contradicts the
project's documented architecture — 'No global Next.js middleware — interception is
route-specific' (CLAUDE.md / AGENTS.md) — and was merged unverified (middleware vs
next.config header precedence was never confirmed in a real build).

This replaces that approach with the minimal, declarative equivalent:
  • next.config.mjs: connect-src now permits the bare `ws:` scheme (symmetric with the
    bare `wss:` already allowed) so the dashboard can reach its own Live WS server from
    a LAN/Tailscale host. No middleware.
  • Removes src/middleware.ts, src/server/csp.ts, and tests/unit/csp-host-aware.test.ts.
  • Adds tests/unit/csp-lan-ws-5083.test.ts (incl. a guard asserting src/middleware.ts
    does NOT exist, so the global-middleware approach cannot silently return).

Bugs 2 (GET-exempt /api/system/version) and 3 (COMBO_002 field surfacing) from #5177
are unaffected and remain in place.

Co-authored-by: KooshaPari <KooshaPari@users.noreply.github.com>

* test(combo): end-to-end quota-share DRR routing-decision coverage (matrix parity) (#5179)

Integrated into release/v3.8.39. Quota-share DRR routing-decision coverage (matrix parity); 2/2 pass on merge result.

* feat(agent-bridge): graceful cert-install fallback with manual guide for containers (#4546) (#5178)

Integrated into release/v3.8.39. Agent-bridge graceful cert-install fallback + manual guide (#4546); 6/6 tests pass on merge result.

* fix(antigravity): family-scoped quota lockout (gemini/claude buckets) (#5180)

Integrated into release/v3.8.39 — family-scoped antigravity quota lockout. Rebased from v3.8.37 + validated (vitest 5/5, typecheck clean, full combo-matrix green, model-lockout 99/0). Same-model cross-account retry (chat.ts) deferred pending live antigravity VPS validation.

* fix(cli): force NODE_ENV to match dev/start run mode in custom Next server (#5189)

Integrated into release/v3.8.39. Force NODE_ENV to match dev/start run mode in custom Next server; 2/2 source-scan+ordering tests pass on merge result.

* feat(compression): CCR ranged/grep/stats retrieval (ReDoS-safe, backward-compat) (#5187)

Integrated into release/v3.8.39. CCR ranged/grep/stats retrieval (safe-regex ReDoS guard + length/match caps); 17/17 tests pass on merge result.

* docs(combo): sync all combo/routing-strategy docs to current state + document test coverage (#5185)

Integrated into release/v3.8.39. Combo/routing-strategy docs sync; docs-only.

* fix(mcp): return 404 (not 400) for unknown Streamable HTTP session id (#5169) (#5191)

* fix(api): respect blocked Auto (Zero-Config) provider in /v1/models catalog (#5192) (#5194)

* test(combo): deterministic context-relay codex quota-handoff coverage (closes last gap) (#5195)

* test(ci): wire antigravity-quota-family under test:vitest (fix test-discovery orphan) (#5196)

* fix(oauth): antigravity login no longer hangs — fire-and-forget onboarding + bounded post-exchange (#5193)

Antigravity OAuth hang fix (no-PKCE/no-openid + bounded post-exchange + exchange-500 fix). Includes #5200 (Koosha) revert + owner rebaseline to keep documented comments. Integrated into release/v3.8.39.

* feat(oauth): remote Antigravity login via local helper + paste-credentials (#5203)

Remote Antigravity login: local helper (omniroute login antigravity) + paste-credentials. Integrated into release/v3.8.39.

* fix(translator): accept Claude Messages shape in non-stream malformed-200 guard (#5156)

Integrated into release/v3.8.39

* fix(cli): default dev bundler to Turbopack (16.2.x panic no longer reproduces) (#5206)

Integrated into release/v3.8.39

* fix(cli): auto-calibrate server V8 heap from physical RAM (#5172) (#5213)

The server was spawned with a fixed --max-old-space-size=512 (omniroute serve)
or no heap flag at all (Electron), so RAM-rich boxes still OOM-crashed under
load (Ineffective mark-compacts near heap limit ~500MB) with many providers/
accounts and large model catalogs. New calibrateHeapFallbackMb(os.totalmem())
defaults the heap to ~35% of RAM clamped [512,4096], wired into serve.mjs and
electron/main.js. Explicit OMNIROUTE_MEMORY_MB still wins (#2939 unchanged).

Also addresses #5160 (same OOM root); #5152 (docker) benefits via the same knob.

Closes #5172

* fix(proxy): coalesce fast-fail health probes (#5208)

Integrated into release/v3.8.39

* fix(proxy): close dispatchers when clearing cache (#5202)

Integrated into release/v3.8.39

* fix(cli): raise dev server Node heap limit to 8GB to prevent OOM (#5198)

Integrated into release/v3.8.39

* fix(auth): allow synthetic no-auth fallback for mimocode (#5205)

Integrated into release/v3.8.39

* fix(oauth): preserve Antigravity refresh_token on empty/omitted upstream response (#3850) (#5214)

Google's OAuth refresh tokens are non-rotating: the refresh response usually
omits refresh_token and occasionally returns it as an empty string. The
Antigravity executor used `typeof tokens.refresh_token === "string" ? ... `
which accepts "" (typeof "" === "string") and overwrote the stored token with
empty, nulling it on first refresh. Now treats non-string OR empty as absent and
preserves credentials.refreshToken, matching refreshGoogleToken semantics.

Closes #3850

* fix(responses): normalize non-array input (#5204)

Integrated into release/v3.8.39

* fix(stream): normalize safety finish reasons via shared helper (#5197)

Integrated into release/v3.8.39

* fix(request-logger): never render negative '(-100%)' compression badge (#5201)

Integrated into release/v3.8.39

* fix(combo): reject empty responses api output (#5207)

Integrated into release/v3.8.39 — combo failover now rejects empty Responses API output (validateQuality). Baseline rebaseline dropped (main-measured drift; maintainer rebaselines at release).

* fix(pwa): prefer cached navigation before offline page (#5209)

Integrated into release/v3.8.39 — PWA service worker prefers cached navigation before offline page (#5165).

* chore(release): v3.8.39 — 2026-06-28

* chore(release): rebaseline openapi+i18n coverage ratchet drift for v3.8.39

---------

Co-authored-by: Arthur Bodera <abodera@gmail.com>
Co-authored-by: Nguyen Minh <lop123thcs@gmail.com>
Co-authored-by: lunkerchen <labanchen@gmail.com>
Co-authored-by: Ankit <177378174+anki1kr@users.noreply.github.com>
Co-authored-by: KooshaPari <KooshaPari@users.noreply.github.com>
Co-authored-by: Ardem2025 <ardemb22@gmail.com>
Co-authored-by: backryun <bakryun0718@proton.me>
Co-authored-by: Anton <39598727+NomenAK@users.noreply.github.com>
Co-authored-by: KooshaPari <42529354+KooshaPari@users.noreply.github.com>
Co-authored-by: Wilson <pedbookmed@gmail.com>
Co-authored-by: Randi <55005611+rdself@users.noreply.github.com>
2026-06-28 06:58:29 -03:00

373 lines
14 KiB
TypeScript

/**
* OmniRoute MCP Compression Tools — Manage and monitor prompt compression.
*
* Tools:
* 1. omniroute_compression_status — Get compression config, analytics, and cache stats
* 2. omniroute_compression_configure — Update compression settings
*/
import { logToolCall } from "../audit.ts";
import {
getCompressionSettings,
updateCompressionSettings,
} from "../../../src/lib/db/compression.ts";
import { getCompressionAnalyticsSummary } from "../../../src/lib/db/compressionAnalytics.ts";
import { getCacheStatsSummary } from "../../../src/lib/db/compressionCacheStats.ts";
import { listCompressionCombos } from "../../../src/lib/db/compressionCombos.ts";
import type { McpToolExtraLike } from "../scopeEnforcement.ts";
import {
getMcpDescriptionCompressionStats,
snapshotMcpDescriptionCompressionStats,
} from "../descriptionCompressor.ts";
/**
* Handle compression_status tool: return current compression config, analytics, and cache stats
*/
export async function handleCompressionStatus(
args: Record<string, never>,
extra?: McpToolExtraLike
): Promise<{
enabled: boolean;
strategy: string;
settings: {
maxTokens: number;
autoTriggerMode: string;
targetRatio: number;
preserveSystemPrompt: boolean;
mcpDescriptionCompressionEnabled: boolean;
};
analytics: {
totalRequests: number;
compressedRequests: number;
tokensSaved: number;
avgCompressionRatio: number;
byMode: Record<string, { count: number; tokensSaved: number; avgSavingsPct: number }>;
byEngine: Record<string, { count: number; tokensSaved: number; avgSavingsPct: number }>;
byCompressionCombo: Record<string, { count: number; tokensSaved: number }>;
validationFallbacks: number;
requestsWithReceipts: number;
realUsage: {
requestsWithReceipts: number;
promptTokens: number;
completionTokens: number;
totalTokens: number;
cacheReadTokens: number;
cacheWriteTokens: number;
estimatedUsdSaved: number;
bySource: Record<string, number>;
};
mcpDescriptionCompression: {
descriptionsCompressed: number;
charsBefore: number;
charsAfter: number;
charsSaved: number;
estimatedTokensSaved: number;
persistedEstimatedTokensSaved: number;
persistedSnapshots: number;
source: "mcp_metadata_estimate";
notProviderUsage: true;
};
};
cacheStats: {
hits: number;
misses: number;
hitRate: string;
tokensSaved: number;
} | null;
}> {
const start = Date.now();
try {
const settings = await getCompressionSettings();
await snapshotMcpDescriptionCompressionStats();
const analyticsSummary = getCompressionAnalyticsSummary();
const mcpDescriptionStats = getMcpDescriptionCompressionStats();
const cacheStats = getCacheStatsSummary();
const result = {
enabled: settings.enabled,
strategy: settings.defaultMode || "standard",
settings: {
maxTokens: settings.autoTriggerTokens,
autoTriggerMode: settings.autoTriggerMode ?? "lite",
targetRatio: 0.7, // Default target ratio
preserveSystemPrompt: settings.preserveSystemPrompt,
mcpDescriptionCompressionEnabled: settings.mcpDescriptionCompressionEnabled !== false,
},
analytics: {
totalRequests: analyticsSummary.totalRequests,
compressedRequests: Object.values(analyticsSummary.byMode ?? {}).reduce(
(sum, mode) => sum + mode.count,
0
),
tokensSaved: analyticsSummary.totalTokensSaved,
avgCompressionRatio: analyticsSummary.avgSavingsPct,
byMode: analyticsSummary.byMode ?? {},
byEngine: analyticsSummary.byEngine ?? {},
byCompressionCombo: analyticsSummary.byCompressionCombo ?? {},
validationFallbacks: analyticsSummary.validationFallbacks,
requestsWithReceipts: analyticsSummary.realUsage.requestsWithReceipts,
realUsage: analyticsSummary.realUsage,
mcpDescriptionCompression: {
descriptionsCompressed: mcpDescriptionStats.descriptionsCompressed,
charsBefore: mcpDescriptionStats.charsBefore,
charsAfter: mcpDescriptionStats.charsAfter,
charsSaved: mcpDescriptionStats.charsSaved,
estimatedTokensSaved: mcpDescriptionStats.estimatedTokensSaved,
persistedEstimatedTokensSaved:
analyticsSummary.mcpDescriptionCompression.estimatedTokensSaved,
persistedSnapshots: analyticsSummary.mcpDescriptionCompression.snapshots,
source: "mcp_metadata_estimate" as const,
notProviderUsage: true as const,
},
},
cacheStats: cacheStats
? {
hits: Math.round(cacheStats.cacheHitRate * (cacheStats.totalRequests || 1)),
misses: Math.round((1 - cacheStats.cacheHitRate) * (cacheStats.totalRequests || 1)),
hitRate: `${(cacheStats.cacheHitRate * 100).toFixed(2)}%`,
tokensSaved: Math.round(cacheStats.avgNetSavings),
}
: null,
};
const duration = Date.now() - start;
await logToolCall("omniroute_compression_status", args, result, duration, true);
return result;
} catch (error) {
const duration = Date.now() - start;
const errorMessage = error instanceof Error ? error.message : String(error);
await logToolCall(
"omniroute_compression_status",
args,
{ error: errorMessage },
duration,
false,
"ERROR"
);
throw error;
}
}
/**
* Handle compression_configure tool: update compression settings
*/
export async function handleCompressionConfigure(
args: {
enabled?: boolean;
strategy?: string;
autoTriggerMode?: string;
maxTokens?: number;
targetRatio?: number;
preserveSystemPrompt?: boolean;
mcpDescriptionCompressionEnabled?: boolean;
},
extra?: McpToolExtraLike
): Promise<{
success: boolean;
updated: Record<string, unknown>;
settings: {
enabled: boolean;
strategy: string;
autoTriggerMode: string;
maxTokens: number;
targetRatio: number;
preserveSystemPrompt: boolean;
mcpDescriptionCompressionEnabled: boolean;
};
}> {
const start = Date.now();
try {
const updates: Record<string, unknown> = {};
if (args.enabled !== undefined) {
updates.enabled = args.enabled;
}
if (args.strategy !== undefined) {
updates.defaultMode = args.strategy;
}
if (args.autoTriggerMode !== undefined) {
updates.autoTriggerMode = args.autoTriggerMode;
}
if (args.maxTokens !== undefined) {
updates.autoTriggerTokens = args.maxTokens;
}
if (args.preserveSystemPrompt !== undefined) {
updates.preserveSystemPrompt = args.preserveSystemPrompt;
}
if (args.mcpDescriptionCompressionEnabled !== undefined) {
updates.mcpDescriptionCompressionEnabled = args.mcpDescriptionCompressionEnabled;
}
const settings = await updateCompressionSettings(updates);
const result = {
success: true,
updated: updates,
settings: {
enabled: settings.enabled,
strategy: settings.defaultMode || "standard",
autoTriggerMode: settings.autoTriggerMode ?? "lite",
maxTokens: settings.autoTriggerTokens,
targetRatio: 0.7, // Default target ratio
preserveSystemPrompt: settings.preserveSystemPrompt,
mcpDescriptionCompressionEnabled: settings.mcpDescriptionCompressionEnabled !== false,
},
};
const duration = Date.now() - start;
await logToolCall("omniroute_compression_configure", args, result, duration, true);
return result;
} catch (error) {
const duration = Date.now() - start;
const errorMessage = error instanceof Error ? error.message : String(error);
await logToolCall(
"omniroute_compression_configure",
args,
{ error: errorMessage },
duration,
false,
"ERROR"
);
throw error;
}
}
import { z } from "zod";
import {
compressionStatusInput,
compressionConfigureInput,
setCompressionEngineInput,
listCompressionCombosInput,
compressionComboStatsInput,
} from "../schemas/tools.ts";
import { handleCcrRetrieve } from "../../services/compression/engines/ccr/index.ts";
import { resolveCallerScopeContext } from "../scopeEnforcement.ts";
const ccrRetrieveInput = z.object({
hash: z
.string()
.min(6)
.max(64)
.describe("24-hex content hash from a [CCR retrieve hash=<hash>] marker"),
mode: z
.enum(["full", "head", "tail", "lines", "grep", "stats"])
.optional()
.describe("Retrieval mode: full (default) | head | tail | lines | grep | stats"),
n: z.number().int().positive().max(10000).optional().describe("head/tail: number of lines"),
start: z.number().int().positive().optional().describe("lines: 1-indexed inclusive start"),
end: z.number().int().positive().optional().describe("lines: 1-indexed inclusive end"),
pattern: z.string().max(512).optional().describe("grep: regex (validated safe; ReDoS-rejected)"),
unique: z.boolean().optional().describe("grep: dedupe matching lines"),
});
export async function handleSetCompressionEngine(
args: z.infer<typeof setCompressionEngineInput>
): Promise<{ success: boolean; settings: Record<string, unknown> }> {
const updates: Record<string, unknown> = { enabled: true };
if (args.engine) {
updates.defaultMode = args.engine === "caveman" ? "standard" : args.engine;
if (args.engine === "off") updates.enabled = false;
}
if (args.cavemanIntensity) {
const current = await getCompressionSettings();
updates.cavemanConfig = {
...(current.cavemanConfig ?? {}),
intensity: args.cavemanIntensity,
};
}
if (args.rtkIntensity) {
const current = await getCompressionSettings();
updates.rtkConfig = {
...(current.rtkConfig ?? {}),
intensity: args.rtkIntensity,
};
}
if (args.outputMode !== undefined) {
const current = await getCompressionSettings();
updates.cavemanOutputMode = {
...(current.cavemanOutputMode ?? {}),
enabled: args.outputMode,
};
}
const settings = await updateCompressionSettings(updates);
return { success: true, settings: settings as unknown as Record<string, unknown> };
}
export async function handleListCompressionCombos(): Promise<{
combos: ReturnType<typeof listCompressionCombos>;
}> {
return { combos: listCompressionCombos() };
}
export async function handleCompressionComboStats(
args: z.infer<typeof compressionComboStatsInput>
): Promise<Record<string, unknown>> {
const summary = getCompressionAnalyticsSummary(args.since === "all" ? undefined : args.since);
if (!args.comboId) return summary as unknown as Record<string, unknown>;
return {
comboId: args.comboId,
summary,
combo: summary.byCompressionCombo[args.comboId] ?? { count: 0, tokensSaved: 0 },
};
}
export const compressionTools = {
omniroute_compression_status: {
name: "omniroute_compression_status",
description:
"Returns current compression configuration, strategy, analytics summary (requests compressed, tokens saved, avg ratio), and provider-aware cache statistics.",
scopes: ["read:compression"],
inputSchema: compressionStatusInput,
handler: (args: z.infer<typeof compressionStatusInput>) => handleCompressionStatus(args),
},
omniroute_compression_configure: {
name: "omniroute_compression_configure",
description:
"Configure compression settings at runtime. Supports enabling/disabling compression, changing strategy (off/lite/standard/aggressive/ultra/rtk/stacked), adjusting maxTokens threshold, targetRatio, auto-trigger mode, system prompt preservation, and MCP description compression.",
scopes: ["write:compression"],
inputSchema: compressionConfigureInput,
handler: (args: z.infer<typeof compressionConfigureInput>) => handleCompressionConfigure(args),
},
omniroute_set_compression_engine: {
name: "omniroute_set_compression_engine",
description: "Set the active compression engine and Caveman/RTK runtime options.",
scopes: ["write:compression"],
inputSchema: setCompressionEngineInput,
handler: (args: z.infer<typeof setCompressionEngineInput>) => handleSetCompressionEngine(args),
},
omniroute_list_compression_combos: {
name: "omniroute_list_compression_combos",
description: "List compression combos and their engine pipelines.",
scopes: ["read:compression"],
inputSchema: listCompressionCombosInput,
handler: (_args: z.infer<typeof listCompressionCombosInput>) => handleListCompressionCombos(),
},
omniroute_compression_combo_stats: {
name: "omniroute_compression_combo_stats",
description: "Get compression analytics grouped by engine and compression combo.",
scopes: ["read:compression"],
inputSchema: compressionComboStatsInput,
handler: (args: z.infer<typeof compressionComboStatsInput>) =>
handleCompressionComboStats(args),
},
omniroute_ccr_retrieve: {
name: "omniroute_ccr_retrieve",
description:
"Retrieve the verbatim content block stored by the CCR compression engine. " +
"When a large block is compressed, a marker `[CCR retrieve hash=<24hex> chars=N]` " +
"is inserted. Pass the hash from the marker to this tool to get the original text back. " +
"Optional `mode` (head/tail/lines/grep/stats) retrieves a slice or summary instead of the whole block; omit for the full block. " +
"Scope: read:compression. Always available (sticky-on).",
scopes: ["read:compression"],
inputSchema: ccrRetrieveInput,
handler: (args: z.infer<typeof ccrRetrieveInput>, extra?: McpToolExtraLike) => {
// Derive caller identity from MCP auth context so the retrieve is scoped to the
// same principal that stored the block. This closes the cross-tenant IDOR (HIGH).
const { callerId } = resolveCallerScopeContext(extra, ["read:compression"]);
return handleCcrRetrieve(args, callerId === "anonymous" ? undefined : callerId);
},
},
};