mirror of
https://github.com/diegosouzapw/OmniRoute.git
synced 2026-08-16 04:03:02 +03:00
* fix(quality): resolve net-new lint errors and allowlist #9343 assert rewrite Two `no-explicit-any` errors landed with #9407 and #9320 after the suppressions inventory was generated. Project policy is to fix new violations rather than freeze them, so both are typed instead: - #9407: `executor as unknown as Record<string, unknown>` - #9320: `(k: { name?: string })` Also allowlists the net-assert reduction in web-tools-translation-2820 (39->35). #9343 inverted the contract — bare JSON must no longer be promoted to tool_calls without an explicit <tool> envelope — so the tests were rewritten to assert non-promotion, which costs fewer asserts than validating a promoted object. More restrictive, not weaker. * fix(quality): raise integration ceiling to 40min and unpin codex-cli version in test The integration gate's 20min ceiling killed a healthy run: measured 22m08s hermetic on an idle 16-core box (935 tests across 112 files, strictly serial at --test-concurrency=1 because ~16 of them bind a port or share a DB). The "~3-10min" estimate in the code was stale by ~3x. 40min keeps the ceiling's real purpose — turning a genuine hang into a visible failure — without failing a long-but-healthy suite. Also fixes a base-red in chat-pipeline:564c204efebumped DEFAULT_CODEX_CLIENT_VERSION to 0.146.0 but the User-Agent assertion still pinned 0.144.1. The line two above already read the constant via getCodexClientVersion(); this one duplicated the literal. Deriving it from the same source stops the next bump from breaking the test again. * fix(ratelimit): re-arm Bottleneck reservoir heartbeat after updateSettings Bottleneck 2.19.5 (frozen upstream dependency, no release since 2019) has a bug in LocalDatastore#_startHeartbeat() (node_modules/bottleneck/lib/ LocalDatastore.js:29,56): the guard `if (this.heartbeat == null && ...)` only (re)creates the periodic reservoir-refresh interval the first time it runs. Every later call -- including the one updateSettings() itself triggers internally -- falls into the else branch and does clearInterval(this.heartbeat) WITHOUT resetting the reference back to null. Because the stale reference sticks around, every future _startHeartbeat() call keeps taking the same dead else branch: the periodic reservoir refresh is gone forever after the first manual updateSettings() call on a limiter. Every limiter created by this file starts with a live heartbeat (buildLimiterDefaults() always sets reservoirRefreshInterval/ reservoirRefreshAmount), so the very first updateFromHeaders() / updateFromResponseBody() / applyRequestQueueSettings() call against a limiter permanently kills its refresh. In production this wedges the request queue once the reservoir hits 0: an auto-enrolled apikey connection accumulates its default 60 requests, the reservoir zeroes, the queue freezes for ~120s, the watchdog fires a synthetic 502 (RATE_LIMIT_QUEUE_WEDGED), the connection cools down and gets excluded from weighted combo pools -- turning a configured 70/30 split into ~50/50. Add applyLimiterSettings(), a module-local wrapper around limiter.updateSettings() that nulls the stale heartbeat reference and re-invokes _startHeartbeat() afterward so it takes the "start a fresh interval" branch again. Route all 5 updateSettings() call sites through it (updateAllLimiterSettings, both updateFromHeaders() branches, loadPersistedLimits(), and updateFromResponseBody()). updateAllLimiterSettings is now async and awaited by its two callers (initializeRateLimits, applyRequestQueueSettings); the sync call sites use the existing trackAsyncOperation() fire-and-forget tracking pattern. tests/integration/combo-matrix/weighted.test.ts is the E2E proof: the "weighted: 70/30" case now passes with zero WEDGED/RATE_LIMIT_QUEUE/502 log lines across 200 sequential requests (previously the wedge/recovery cycle inflated its runtime and skewed the distribution toward ~50/50). Refs #8213 * fix(tests): remove stray TDD probes committed by accident inf4e93f339dThree TDD repro/probe test files landed on the release tip viaf4e93f339d(docs: add management authentication terminology guide, files from a worktree. Each file is a pre-fix TDD probe that belongs to a *different*, still-in-flight fix branch/PR and duplicates a file path that PR already owns and will properly update on merge: - tests/unit/authz/probe-9033-repro.test.ts: probe for #9033 (IP blacklist direct-connection bypass). 3/4 asserts fail against this tree (D1, D2, Bonus — all assert the not-yet-implemented target behavior); D3 passes (pre-existing behavior). Owned by PR #9385 (open, unmerged), which modifies this exact path. - tests/unit/repro-8522.test.ts: probe for #8522 (absolute file-size baseline reds innocent PRs on inherited drift). First test fails against this tree's evaluateFileSizes (still absolute-only); second (sanity: real growth still flags) passes. #8522 is actually CLOSED upstream — PR #9355 merged the real fix into release/v3.8.50 today (2026-08-05T15:53Z) modifying this exact path — but this branch's merge-base with release/v3.8.50 (6b0e11e378) predates that merge, so the fix has not synced into this tree yet. - tests/unit/repro-8956.test.ts: probe for #8956 (resolveProjectRoot stops at synthetic Next.js standalone package.json). First test fails against this tree; second (sanity: named package.json still resolves) passes. Owned by PR #9354 (open, unmerged), which modifies this exact path. Each deleted file's real implementation + passing version already exists in its owning PR and will land normally through that PR's own merge — deleting the premature copy here does not lose any coverage. No config/quality/test-masking-allowlist.json entry was added: the _deletedWithReplacement schema only supports `replacement` (a test file that must already exist in this tree's HEAD — none does, the real versions live in the unmerged sibling PRs above) or `sourceRemoved` (production files that must be absent from HEAD — they are not, none of the three issues are implemented in this tree). Neither shape fits an "owned by an in-flight sibling PR" deletion, so the CI test-masking gate will flag these 3 deletions for mandatory human review on this branch's next PR diff against release/v3.8.50 — flagged for the owner rather than inventing a new allowlist shape. Refs #9033, #8522, #8956, #7786 * fix(tests): align 8189-classifier-compat with #9276 always-mode semantics tests/unit/8189-classifier-compat-auto-narrow.test.ts was a test-sibling forgotten when #9276 (commit6b531fbacd) removed the unconditional `if (mode === "always") return true` branch from shouldDefaultAllowClassifier(). tests/unit/claude-classifier-compat.test.ts was updated in that same commit; this file was not. Old contract: 'always' mode short-circuited every Claude-format request unconditionally (operator opt-in was treated as sufficient on its own). New contract: 'always' now requires the same SECURITY_MONITOR_MARKER system-prompt text as 'auto' — the marker-optional behavior let a normal chat request through /v1/messages be silently swallowed by an operator's 'always' opt-in. The single 'always' test (1 assert, no-marker body expecting true) is replaced by two tests mirroring the depth already used for 'auto' mode in the same file: no-marker/false and marker-present/true. Net effect is +1 assert, not a reduction — the new pair verifies both directions of the narrowed contract instead of only the now-incorrect unconditional case. Before: 3/4 pass (the 'always' test failed: expected true, got false). After: 5/5 pass. Refs #9276 * fix(tests): align deepseek-web-tools-execute with #9343 tool envelope contract tests/unit/deepseek-web-tools-execute-2820.test.ts (executor level) was a test-sibling forgotten when #9343 (commitd969555417) hardened tool-call parsing: bare JSON with no explicit <tool>/<tool_call> envelope is never promoted to tool_calls anymore (previously it was, whenever a tools[] set was requested — a security gap allowing prose/code-fenced JSON echoed back by the model, or a copy-attack, to trigger real tool execution). Three siblings were updated in the same commit: web-tools-translation.test.ts and web-tools-translation-2820.test.ts (parseToolCallsFromText, the shared translator), and deepseek-web-tools-variants.test.ts (parseDeepSeekToolCalls, deepseek-specific parser) — all inverted their bare-JSON assertions to `toolCalls === null` + `content === text` (preserved verbatim, not stripped). This file calls the executor's execute() (full HTTP round trip through buildToolAwareResult), so it was not touched by that diff and kept asserting the old contract (finish_reason: "tool_calls", content: null). Verified against source (open-sse/executors/deepseek-web.ts buildToolAwareResult): when parseDeepSeekToolCalls returns toolCalls=null, hasCalls is false, so finish_reason is "stop", message.tool_calls is never set, and message.content is the parser's returned content — which for text with no <tool>/<tool_call> tag at all is the original string, unchanged (parseToolCallsFromText's early-return branch). The test now asserts exactly that shape, at the same executor level as the rest of the file's tool_calls that make sense at that level as the rest of the file's tool_calls Refs #9343 * fix(tests): align visionBridge tests with #8430 contract (partial — see note) Two test-siblings were forgotten when #8430 (commit7e55abbc41) hardened Vision Bridge's vision-model selection: getBestVisionModel() now validates that a candidate has a usable active connection (hasUsableCredentialsForModel, DB-backed) before returning it, instead of unconditionally returning the fixedModel or a hardcoded "openai/gpt-4o-mini" default. Three siblings were updated in the same commit (visionBridgeRouter.test.ts, the new repro-8430.test.ts, vision-bridge-preserve-on-failure-4012.test.ts); these two were not. tests/unit/guardrails/visionBridgeHelpers.callVisionModel.test.ts (8 failures, all "No vision-capable provider connected"): callVisionModel()'s `routerConfig` param only merges into getBestVisionModel's CONFIG argument, never its `deps` argument, so there is no way to inject a credentials stub through this function's public signature (unlike the guardrail class and getBestVisionModel itself, which do accept an injectable `hasUsableCredentials`). These tests exercise callVisionModel's own request/response handling, not credential routing (already covered elsewhere), so the fix seeds one real usable `provider_connections` row per provider the file exercises (openai, anthropic) via createProviderConnection in a test.before() hook, with resetDbInstance() in test.after() per the DB-handle-cleanup convention. All 8 now pass. tests/unit/guardrails/visionBridge.test.ts (7 failures): 1 of the 7 (VB-S03) is a genuine forgotten-contract case, fixed here — same semantic flip already applied to vision-bridge-preserve-on-failure-4012.test.ts: in the combo describe path, when EVERY describe call fails, the raw image is now replaced with an "(unavailable)" stub instead of preserved, because that path is only reached for confirmed non-vision targets. Assertions inverted to match (imagePart undefined, unavailable-stub present), same assert count, no weakening. *** THE OTHER 6 (VB-S12, VB-S12b, VB-S01, VB-S13, VB-S07, VB-S10) ARE DELIBERATELY LEFT FAILING. *** These are NOT a #8430 contract change — root- caused to what looks like a separate, unintentional regression: the ONE call to getBestVisionModel() in visionBridge.ts's whole-request-reroute path (line 244, `getBestVisionModel({ fixedModel: configuredModel })`) does not pass a `deps` second argument, so it always uses the real DB-backed hasUsableCredentialsForModel instead of this.deps.hasUsableCredentials — even though the two adjacent checks in the very same function (`checkCreds(model)` at line 226, `checkCreds(bestModel)` at line 246) DO honor the injectable override. In this suite's empty-but-readable isolated test DB, that real check deterministically returns `false` (not the indeterminate `null` the file's own createGuardrail() comment says these tests rely on: "Fail-open (null) so classic VB-S01/S07/S10 reroute tests keep working without a live credential DB"), so getBestVisionModel silently returns null, the reroute branch's `if (bestModel && ...)` guard never fires, and every test that expects a reroute observes a silent no-op instead. Evidence this is a source gap, not a test that needs updating: - The file's own pre-existing comment names VB-S01/S07/S10 as tests the `null` fail-open default is SUPPOSED to keep green. - VB-CRED-01/02 (the file's only two tests that actually inject a non-default hasUsableCredentials mock) both pass today, but neither one's assertions distinguish "mock honored" from "mock ignored, real check also says no" — they don't prove the threading works, they just don't happen to notice it's missing. - visionBridgeRouter.test.ts, repro-8430.test.ts, and vision-bridge-preserve-on-failure-4012.test.ts (22 tests, all green) all either call getBestVisionModel directly with explicit deps, or mock callVisionModel wholesale (bypassing getBestVisionModel entirely) — none of them exercises this exact call site through the guardrail's own deps. Per instructions, this was intentionally NOT "fixed" by weakening these 6 tests' assertions (that would mask the gap) or by seeding fake DB credentials to route around it (that would hide a real production DI inconsistency behind a test-only workaround) or by touching src/lib/guardrails/visionBridge.ts (a production behavior change outside a test-alignment task's scope, and Hard Rule #18 requires its own TDD/validation cycle). Flagging for the owner: the likely one-line fix is threading `{ hasUsableCredentials: this.deps.hasUsableCredentials }` as getBestVisionModel's second argument at visionBridge.ts:244, mirroring the two adjacent call sites in the same function. Before: 15 failures (7 + 8). After: 9 pass added (1 + 8), 6 still fail (unchanged, by design). Refs #8430 * feat(quality): add strayFromCommit deletion allowlist form to test-masking gate The deletion allowlist supported two shapes: replacement (test rewritten elsewhere) and sourceRemoved (feature deleted). Neither fits a third legitimate case surfaced today: test files that entered the repo BY ACCIDENT — commitf4e93f339d(#7786 docs) swept another session's worktree artifacts into the release, including TDD probes owned by open fix PRs (probe-9033-repro -> PR #9385, repro-8956 -> PR #9354, repro-8522 -> PR #9355). Those probes fail by design until their owning PR merges, so every unit run on the release tip broke on them. The new strayFromCommit form is verified, not trusted: the gate asks git which commit actually ADDED the file (git log --diff-filter=A) and only exempts the deletion when it matches the declared hash; a non-empty reason naming the owning PR/issue is mandatory. Also allowlists the deepseek-web-tools-execute assert reduction (23->21) fromed661f2126— same #9343 contract-inversion class as the existing web-tools-translation entry. Gate unit tests: 55/55 pass. Full gate vs main: OK. * fix(guardrails): pass credential deps to getBestVisionModel at reroute call site The individual-model reroute path in VisionBridgeGuardrail.preCall() calls getBestVisionModel({ fixedModel: configuredModel }) without its second `deps` argument, so the router always falls back to the real DB-backed hasUsableCredentialsForModel instead of an injected `deps.hasUsableCredentials` override. The two adjacent credential checks in the same function (the original-model check and the best-model check, both via the local `checkCreds` binding) already thread deps correctly — only this middle call, added in #8430, was left out. Pass the same resolved `checkCreds` used by those two adjacent checks as `getBestVisionModel`'s deps argument so all three credential checks in this reroute path stay consistent. Fixes 6 tests in tests/unit/guardrails/visionBridge.test.ts that depended on the injected hasUsableCredentials mock being honored on this path: VB-S12, VB-S12b, VB-S01, VB-S13, VB-S07, VB-S10. Refs #8430 * fix(quality): raise unit ceiling to 100min and align 2 more forgotten sibling tests Unit ceiling 45->100min: a hermetic-env measurement on the loaded devbox (load 7-26) was still inside invocation 1 of 3 at 76min when killed; contention factor 2-3x measured, no idle measurement exists. The pre-flight's real condition is exactly that contended one (unit runs in Promise.all with integration+vitest), and there 45min provably killed a healthy suite and fabricated a false base-red. The 45min value came from v3.8.43 as an estimate never validated by measurement. TODO in-code: re-tighten after an idle run on the .113 box. Also aligns the 6th and 7th occurrences of the same systemic pattern (behavior change merged updating only part of the sibling tests): - issue-7859-gemini-web-redirect-valid: #9407 refined ServiceLogin redirects to mean expired session; the #7859 regression coverage is preserved via a non-ServiceLogin public redirect variant. - provider-validation-specialty claude-web 429: #9406 inverted the contract (rate-limited session is unhealthy); the dedicated repro file owns the full contract, this sibling now matches it. Also carries the file-size rebaseline for #9323's base.ts growth (1578->1623, WAF retry + burst guard) and the eslintWarnings baseline tightened 5000->0 (real measured value with the TS7 suppressions in place — 5000 left the ratchet inert). Refs #9407, #9406, #9323 * fix(tests): restore the 3 TDD probes now owned by merged fixes and drop their stray allowlist entries The base advanced while this PR was open: the real fixes for the three issues behind the stray probes all merged into release/v3.8.50 — #9385 (issue 9033), #9355 (issue 8522) and #9354 (issue 8956). - probe-9033-repro / repro-8522: the base rewrote both probes into the regression tests of their merged fixes, so the delete side of the rebase conflict was dropped and the base versions kept. - repro-8956: #9354 only realigned one fixture line in auto-update.test.ts (package.json marker now needs a name field) and added no test for the new skip-synthetic behavior — the probe is the ONLY regression coverage of that merged fix (2/2 green on the base), so deleting it would remove real coverage. Restored. With no test-file deletions left in the PR diff, the three strayFromCommit allowlist entries are stale and removed. The strayFromCommit form support in check-test-masking.mjs stays (covered by its own fixtures). * fix(quality): rebaseline file-size for PR #9529 own growth The base sits exactly at the old frozen values, so the base-relative mode (#8522) does not cover this growth — it is this PR's own: - open-sse/services/rateLimitManager.ts 1060->1105: the applyLimiterSettings() helper that re-arms the reservoir heartbeat after updateSettings (Bottleneck 2.19.5 fix, TDD in ratelimit-reservoir-refresh.test.ts). - tests/integration/chat-pipeline.test.ts 1592->1598: codex User-Agent derived from getCodexClientVersion() instead of a pinned literal. - tests/unit/provider-validation-specialty.test.ts 2980->2985: new claude-web 429 -> valid:false coverage (#9406). * fix(docs): sync provider count to 291 in README and CLAUDE The live catalog counts 291 providers but README.md/CLAUDE.md still said 290, so the STRICT 'Docs Gates (fast-path)' check reds EVERY open PR against release/v3.8.50 (verified on #9537/#9539 as well — inherited base-red, not introduced by this PR). Updated all provider-count mentions including the section anchor. * fix(tests): align launch-codex 6312 guard with the async #9454 spawn contract #9454 made resolveCodexSpawn async (PATH-probes a native codex.exe before the .cmd shim) and updated its own tests, but left this older sibling calling the function synchronously — destructuring the Promise yields undefined and reds Unit fast-path (1/4) for EVERY open PR against the release (verified on #9537/#9539; inherited base-red). Realigned to the async contract with an injected probe; keeps the original #6312 fallback guard plus the only non-Windows codex coverage (now also asserting the probe never runs off Windows). * fix(translator): move state-mutating reasoning summary helper out of the pure leaf #9500 added buildResponsesReasoningSummaryDelta(state, ...) to pureHelpers.ts, but the function reads AND mutates stream state (reasoningSummaryIndex map) — violating the leaf contract declared in the file header ('no host imports, no stream state') and guarded by response-openai-responses-purehelpers-split.test.ts, which reds Unit fast-path (4/4) for every open PR (inherited base-red, verified on #9537/#9539). Moved verbatim to the host next to the other stream-state helpers (markResponsesReasoningDeltaEmitted); the host was its only consumer. Behavior unchanged: repro-9500-reasoning-separator 3/3 green, leaf/host architecture tests green. * fix(quality): rebaseline openai-responses.ts for the leaf-state relocation The #9500 helper moved from pureHelpers.ts into the host (previous commit) grows the host file 1174->1204 while the leaf shrinks by the same amount — net-zero LOC across the pair, but the per-file frozen ratchet only sees the growing side. * fix(tests): let the 9442 cert-mode test see past the harness trust-store guard tests/_setup/isolateDataDir.ts sets OMNIROUTE_SKIP_SYSTEM_TRUST=1 globally, which makes installCert() return before issuing any command — so the #9442 install-gap test captured nothing and could NEVER pass under npm run test:unit (it only passed invoked directly, harness-less; inherited base-red on Unit fast-path 3/4, verified on #9537/#9539). Clear the flag for this file only (restored in test.after): safe because every spawned command is a logging stub on PATH and OMNIROUTE_NO_SUDO=1 strips sudo, so nothing touches the real trust store. 6/6 under the CI harness including system-trust-test-guard. --------- Co-authored-by: diegosouzapw <diegosouzapw@users.noreply.github.com>
116 lines
34 KiB
JSON
116 lines
34 KiB
JSON
{
|
||
"_comment": "Anti test-masking allowlist (check-test-masking.mjs). Files here are EXEMPT ONLY from the net-assert-REDUCTION signal, when the reduction is a verified-legitimate refactor or field removal (NOT weakening to go green). New tautologies (assert.ok(true)), new .skip/.todo/.only, and test-file deletions are STILL flagged for these files. Every entry needs a reason with the PR ref. Prune an entry once the release that introduced the reduction has merged to main (the merge-base then already reflects the reduced state, so the signal no longer fires).",
|
||
"tests/unit/appearance-widget-settings-schema.test.ts": "v3.8.27 #4033: the `showTokenSaverOnEndpoint` schema field was removed (renamed/consolidated into the settings surface); its 2 asserts were removed accordingly — the field no longer exists in source. Verified legitimate, not masking.",
|
||
"tests/unit/dashboard-shell-tabs.test.ts": "v3.8.27 #3973: settings UI refactored from a tabbed client component to redirect-based routing; 5 old-structure asserts (tabpanel/aria/initialTab) were replaced by 4 new-structure asserts (redirect/resolveSettingsRoute), net -1. Asserts replaced, not weakened. Verified legitimate.",
|
||
"tests/integration/combo-routing-e2e.test.ts": "v3.8.29 #4129: integration tests aligned to post-v3.8.28 routing behavior — 3 separate per-call status asserts collapsed into a single loop assertion and seenProviders expectations updated to the new routing order (42→39). Asserts restructured/updated, not weakened. Verified legitimate. Prune after v3.8.29 merges to main.",
|
||
"tests/unit/compression/ccr-marker-retrieve.test.ts": "v3.8.29 #4226: the vestigial reconstructCcr round-trip helper was removed from source; its 3 asserts were removed accordingly (36→33). Helper no longer exists. Verified legitimate, not masking. Prune after v3.8.29 merges to main.",
|
||
"tests/unit/compression/session-dedup.test.ts": "v3.8.29 #4226: the vestigial SessionDedup round-trip helper was removed from source; its 2 asserts were removed accordingly (32→30). Helper no longer exists. Verified legitimate, not masking. Prune after v3.8.29 merges to main.",
|
||
"tests/unit/compression/ultra.test.ts": "v3.8.29 #4253: the vestigial SLM seam + dead deprecated alias were removed from the ultra compression engine; 6 asserts covering the removed seam were removed accordingly (49→43). Verified legitimate, not masking. Prune after v3.8.29 merges to main.",
|
||
"tests/unit/db-backup-extended.test.ts": "v3.8.29 #4132: db-backup de-flake — 1 timing-sensitive assertion on fire-and-forget backup completion was removed in favor of awaiting actual completion (44→43). Verified legitimate, not masking. Prune after v3.8.29 merges to main.",
|
||
"@omniroute/opencode-plugin/tests/combos.test.ts": "v3.8.31 #4384: the plugin now prefixes every catalog key with the `omniroute` provider id and drops the legacy `combo/` namespace; the test asserting raw-deletion + a `combo/<slug>` key (a namespace that no longer exists) was removed and the remaining asserts switched to `omniroute/<slug>` keys (82→81). Asserts updated to the new key contract, not weakened. Verified legitimate. Prune after v3.8.31 merges to main.",
|
||
"tests/unit/chatgpt-web.test.ts": "v3.8.43 #5549: fix(chatgpt-web) restore dot-form Pro model ids — dois assert.equal separados (base Pro slug + pass-through slug) consolidados num único assert.equal(body.model, expectedSlugById[omniId], ...) orientado por tabela de mapeamento (281→280). Asserts consolidados, não enfraquecidos. Verificado legítimo. Prune após v3.8.43 mergear para main.",
|
||
"tests/unit/chatcore-sanitization.test.ts": "v3.8.43 #5805: fix(translator) strip orphaned tool results — orphaned tool_result blocks (no matching tool_use) are now removed by stripOrphanedToolResults BEFORE content normalization, so the 3 positive `[Tool Result: …]`-text asserts were replaced by removal asserts (no tool_result block, no text), net 65→64. Behavior aligned to the merged #5805 contract; the sibling 'preserves Claude passthrough tool_result' assert (matching tool_use) is untouched. Verified legitimate, not masking. Prune after v3.8.43 merges to main.",
|
||
"src/app/(dashboard)/dashboard/providers/[id]/__tests__/useModelVisibilityHandlers.test.tsx": "v3.8.43 #5856: fix(dashboard) unify CSRF origin fallback — the model-visibility handler no longer issues a separate `/api/auth/csrf` fetch, so the two asserts pinning the 2nd fetch + its CSRF header were removed and the fetch-count assert updated 2→1 (7→5). Asserts follow the reduced fetch behavior, not weakened. Verified legitimate. Prune after v3.8.43 merges to main.",
|
||
"tests/unit/provider-validation-specialty.test.ts": "v3.8.43 #5855: fix(qwen-web) unblock validator (retired endpoint) — the old `chat.qwen.ai/api/v2/user` probe asserts (exact URL / Authorization / source / Cookie / WAF-error) no longer apply after the endpoint migration and were replaced by new chathub-path behavior asserts (valid/error/warning), net 406→400. Asserts migrated to the new API surface (#5855/#5432), not weakened. Verified legitimate. Prune after v3.8.43 merges to main.",
|
||
"tests/unit/chatcore-translation-paths.test.ts": "v3.8.44 #5958: fix(cc-compatible) send SSE accept for streamed requests — o assert do header Accept mudou de application/json para text/event-stream e dois asserts (stream + context_management) foram consolidados num único assert.deepEqual de tupla (297→296). Asserts consolidados/atualizados ao novo contrato, não enfraquecidos. Verificado legítimo. Prune após v3.8.44 mergear para main.",
|
||
"tests/unit/combo-context-window-filter.test.ts": "v3.8.44 #6088: fix(combo) prefer known context capacity over unknown — a semântica do filtro mudou (unknown-context só sobrevive como fallback), o arquivo foi reescrito: 18 asserts pequenos (length/didFallback/ok) viraram 4 assert.deepEqual na LISTA ORDENADA completa de sobreviventes por caso (mais forte por caso). Asserts migrados ao novo contrato, não enfraquecidos. Verificado legítimo. Prune após v3.8.44 mergear para main.",
|
||
"tests/unit/qoder-executor.test.ts": "v3.8.44 #5816: feat(qoder) drive PAT auth via qodercli — o executor migrou de chamadas HTTP diretas (api.qoder.com/api1.qoder.sh, headers Cosy-*) para o contrato stdio qodercli://; os asserts que pinavam URLs/headers da superfície aposentada foram substituídos por asserts do novo contrato (73→65). Asserts migrados à nova superfície, não enfraquecidos. Verificado legítimo. Prune após v3.8.44 mergear para main.",
|
||
"tests/unit/qoder-jobtoken-exchange-4683.test.ts": "v3.8.44 #5816: feat(qoder) drive PAT auth via qodercli — o exchange de job token deixou de fazer o POST personal_token direto (agora via qodercli); 2 asserts da superfície HTTP aposentada removidos, demais migrados (27→25). Verificado legítimo, não mascaramento. Prune após v3.8.44 mergear para main.",
|
||
"tests/integration/v1-contracts-behavior.test.ts": "v3.8.46 #6303: fix(api) filter specialty model catalogs — os 10 asserts inline de SHAPE das listas embedding/image (object=='model', type=='embedding'/'image', typeof id/owned_by) foram removidos porque #6303 unificou os catálogos de especialidade e moveu a cobertura de shape para tests/unit/models-catalog-route.test.ts (que asserta embedding.type/gpt-image-2.type=='image'/owned_by de forma mais abrangente, +audio/rerank/video/music) e o comportamento de credential-hiding para tests/unit/specialty-model-catalog-routes.test.ts; net 44→42. Cobertura migrada, não enfraquecida. Verificado legítimo. Prune após v3.8.46 mergear para main.",
|
||
"tests/unit/check-docs-symbols.test.ts": "v3.8.46 release-PR CI: o gate check:docs-symbols (stale-enforcement) flagou as 2 ultimas entradas de KNOWN_STALE_DOC_REFS (/api/chat, /api/settings/tunnels) como CORRIGIDAS e exigiu remove-las, esvaziando o allowlist. Os 2 asserts removidos eram `assert.ok(size > 0)` (guarda non-empty) que ficaram FALSOS — um allowlist vazio e o estado valido/ideal (todo ref stale foi corrigido). A invariante significativa (/api/-shape de cada entrada presente) foi mantida; net 28->26. Nao e enfraquecimento — a assuncao non-empty tornou-se obsoleta. Prune apos v3.8.46 mergear para main.",
|
||
"tests/unit/combo-quota-share-cooldown-wait.test.ts": "v3.8.47 #6897: de-flake redesign dos testes timing-sensitive de cooldown/breaker do combo (#6803) — asserts dependentes de timing real substituídos por asserts determinísticos com clock controlado, net 12→6. Asserts redesenhados, não enfraquecidos (a suíte prova o MESMO contrato sem flake). Verificado legítimo. Prune após v3.8.47 mergear para main.",
|
||
"tests/unit/combo-strategy-fallbacks.test.ts": "v3.8.47 #6897: mesmo de-flake redesign (#6803) — asserts timing-sensitive de fallback de estratégia consolidados em asserts determinísticos, net 58→52. Verificado legítimo, não mascaramento. Prune após v3.8.47 mergear para main.",
|
||
"tests/unit/provider-page-helpers-3501.test.ts": "v3.8.47 #6862: feat GPT-5.6 family — 2 assert.ok(values.includes(...)) substituídos por 1 assert.deepEqual(values, [lista completa ordenada de effort tiers]) — asserção estritamente MAIS FORTE, net 69→68. Verificado legítimo. Prune após v3.8.47 mergear para main.",
|
||
"tests/unit/vscode-token-routes.test.ts": "v3.8.47 #6862: feat GPT-5.6 family — a matriz de modelos do VS Code token route migrou de GPT-5.4/5.5 para a família 5.6 (tiers consolidados, context 200k→500k, novos slugs sol); os asserts da matriz aposentada foram substituídos pelos da nova (net 247→200). Asserts migrados ao novo catálogo, não enfraquecidos. Verificado legítimo. Prune após v3.8.47 mergear para main.",
|
||
"tests/unit/providers-page-utils.test.ts": "v3.8.47 #6675: remoção dos providers obsoletos glhf/kluster/cablyai/inclusionai — os 2 asserts que citavam providers removidos do catálogo foram removidos junto (net 276→274). Superfície aposentada, não mascaramento. Verificado legítimo. Prune após v3.8.47 mergear para main.",
|
||
"_deletedWithReplacement": {
|
||
"_comment": "Deleções de arquivo de teste com SUBSTITUTO verificado (o gate exige que o replacement exista no HEAD e seja arquivo de teste). Uso restrito ao caso 'reescrito em outro path sem rename detectável pelo -M do git'. Cada entrada precisa de reason com PR ref e passa por revisão humana no release PR. Prune após o release mergear para main.",
|
||
"open-sse/services/combo/__tests__/targetExhaustion.test.ts": {
|
||
"replacement": "tests/unit/combo/combo-target-exhaustion.test.ts",
|
||
"reason": "v3.8.44 #5976: os testes de exaustão eram flake-prone (delays Math.random, timeouts 30s, >3min no CI) e foram REESCRITOS como unit determinístico com MAIS cobertura (21 casos/52 asserts vs 13 casos/37 asserts). Documentado no commit 5fe225850. Revisão humana: apresentado ao operador no STOP #1 do release v3.8.44."
|
||
},
|
||
"src/shared/components/AutoRoutingBanner.test.tsx": {
|
||
"replacement": "tests/unit/home-no-autorouting-banner.test.ts",
|
||
"reason": "v3.8.45 #6164: fix(dashboard) remove the always-on Auto-Routing banner — o COMPONENTE foi deletado junto com o teste (feature removida pelo mantenedor, não mascaramento). O replacement guarda o novo contrato: a home NÃO renderiza o banner e o componente permanece deletado."
|
||
},
|
||
"tests/unit/free-provider-rankings-configured-filter.test.ts": {
|
||
"replacement": "tests/unit/freeProviderRankings-filters.test.ts",
|
||
"reason": "v3.8.45 #6251 supersede #6245: a página Free Provider Rankings migrou do toggle client-side 'Configured Only' (#6245, configuredProviderIds no cliente) para filtros server-side configuredOnly/availableOnly (#6251). O teste antigo pinava a implementação removida (7 asserts quebrados contra código que não existe); o replacement cobre o contrato novo com 11 casos (server-side, lib helper). Verificado legítimo — supersessão documentada no CHANGELOG do #6251."
|
||
},
|
||
"tests/unit/video-dashscope.test.ts": {
|
||
"replacement": "tests/unit/alibaba-video-media.test.ts",
|
||
"reason": "v3.8.49 #8266 reorganized the Alibaba video catalog: the flat wan2.7-t2v id moved out of the plain \"alibaba\" provider (which now only exposes the dated wan2.7-t2v-2026-06-12) and lives only under \"qwen-cloud\" today. All 6 tests in the deleted file built requests against alibaba/wan2.7-t2v, which the new allowlist now rejects with HTTP 400 (verified directly against VIDEO_PROVIDERS in open-sse/config/videoRegistry.ts before deletion). Coverage for this exact id already exists and was confirmed green pre-deletion in tests/unit/alibaba-video-media.test.ts (including an explicit \"Alibaba rejects video models outside its own allowlist\" case for alibaba/wan2.7-t2v) and tests/unit/qwen-cloud-video-media.test.ts (covers the same flat id under qwen-cloud/wan2.7-t2v). Verified legitimate, not masking."
|
||
},
|
||
"tests/unit/usage-analytics-route-extra.test.ts": {
|
||
"replacement": "tests/unit/usage-analytics-route.test.ts",
|
||
"reason": "v3.8.49 base-red reconcile: the file was a 100% duplicate — all 10 of its test names exist verbatim (comm -12 verified) among the 22 in tests/unit/usage-analytics-route.test.ts, created by #7700 before #7300 fixed the retention-cutoff fixture only in the main file (reads getUserDatabaseSettings().retention.usageHistory live instead of hardcoding 30d). The stale copy red-failed 'does not double-count raw and aggregated rows' (1 !== 2) against correct production behavior. Zero unique coverage lost; the maintained main file passes 22/22. Verified legitimate, not masking."
|
||
},
|
||
"tests/unit/free-budget-card.test.tsx": {
|
||
"replacement": "tests/unit/ui/free-budget-card.test.tsx",
|
||
"reason": "v3.8.49 #7840: feat(catalog) map unmapped free tiers — o arquivo foi MOVIDO de tests/unit/ para tests/unit/ui/ junto com a expansão do catálogo (o -M do git não detectou o rename porque o conteúdo mudou junto). O componente FreeBudgetCard continua em src/app/(dashboard)/dashboard/usage/components/ e o teste no novo path cobre o mesmo contrato. Relocação, não deleção."
|
||
},
|
||
"tests/unit/guardrails/visionBridgeRouter.test.tsx": {
|
||
"replacement": "tests/unit/guardrails/visionBridgeRouter.test.ts",
|
||
"reason": "v3.8.49 #8433: fix(guardrails) Vision Bridge describe-fallback ignora candidatos inalcançáveis — o teste migrou de .tsx para .ts (não renderiza nada, era TSX por engano) no mesmo diretório, com a cobertura do novo comportamento de fallback. Troca de extensão, não perda de cobertura."
|
||
},
|
||
"tests/unit/qwen-api-key-auto-create.test.ts": {
|
||
"replacement": "tests/unit/qwen-settings-route.test.ts",
|
||
"reason": "v3.8.49 #7866: refactor(qwen) remove o provider OAuth legado — a superfície testada foi DELETADA junto (open-sse/config/providers/registry/qwen/index.ts, open-sse/services/tokenRefresh/providers/qwen.ts, src/lib/oauth/providers/qwen.ts). O fluxo guide-settings que sobrou é coberto pelo replacement (POST escreve o contrato V4 e preserva credenciais alheias; DELETE remove só o que é do OmniRoute)."
|
||
},
|
||
"tests/unit/qwen-strip-stream-options-claude-code-port663.test.ts": {
|
||
"replacement": "tests/unit/qwen-code-config.test.ts",
|
||
"reason": "v3.8.49 #7866: refactor(qwen) remove o provider OAuth legado — o executor cujo stream_options o teste pinava não existe mais. A integração Qwen Code foi RECONSTRUÍDA para o upstream V4 e o replacement guarda o contrato novo, incluindo a migração da forma root-array da integração removida e a limpeza das credenciais legadas de security.auth."
|
||
},
|
||
"tests/unit/ui/provider-plan-config.test.tsx": {
|
||
"replacement": "tests/unit/quota-plans-route-retired.test.ts",
|
||
"reason": "v3.8.49 #7127: fix(tests) suíte vitest UI de volta ao verde — a rota Plans e o ProviderPlanConfigClient foram APOSENTADOS; o replacement inverte a asserção e guarda a aposentadoria (o arquivo da rota e o ProviderPlanConfigClient não existem mais, costs-quota-plans saiu do sidebarVisibility e da navegação)."
|
||
},
|
||
"tests/unit/plugin-sandbox-permissions.test.ts": {
|
||
"sourceRemoved": [
|
||
"src/lib/plugins/pluginWorker.ts",
|
||
"src/lib/plugins/sandbox.ts",
|
||
"src/lib/plugins/signing.ts"
|
||
],
|
||
"reason": "v3.8.50 #9126 (commit 8fac6bcd48): pluginWorker.ts, sandbox.ts e signing.ts foram removidos por completo (\"zero importers confirmed\") — o subsistema de sandbox de plugins com worker-thread nunca foi ligado a nenhum consumidor. O teste era source-scan sobre pluginWorker.ts (ver docstring do arquivo deletado); sem o arquivo-fonte não há mais o que testar. OMNIROUTE_PLUGINS_ALLOW_EXEC também foi removido de .env.example e da doc na mesma release. Sem substituto porque a feature foi extinta, não migrada."
|
||
},
|
||
"tests/unit/plugins-sandbox.test.ts": {
|
||
"sourceRemoved": ["src/lib/plugins/sandbox.ts"],
|
||
"reason": "v3.8.50 #9126 (commit 8fac6bcd48): sandbox.ts foi removido por completo junto com pluginWorker.ts e signing.ts (\"zero importers confirmed\", subsistema de sandbox de plugins nunca ligado a nenhum consumidor). O teste cobria SandboxLevel/getSandboxLabel exportados por sandbox.ts; sem o arquivo-fonte não há mais símbolo a testar. Mesma causa-raiz de tests/unit/plugin-sandbox-permissions.test.ts nesta entrada."
|
||
}
|
||
},
|
||
"tests/unit/catalog-updates-v3x.test.ts": "v3.8.45 #6248: fix(providers) remove deprecated MiMo V2 entries — os 5 asserts removidos pinavam specs de modelos mimo-v2-* que deixaram de existir no catálogo (54→49). Asserts seguem a remoção dos modelos, não enfraquecimento. Verificado legítimo. Prune após v3.8.45 mergear para main.",
|
||
"tests/unit/xiaomi-mimo-provider.test.ts": "v3.8.45 #6248: fix(providers) remove deprecated MiMo V2 entries — 2 asserts sobre mimo-v2-pro/omni/flash removidos junto com os modelos (21→19). Verificado legítimo, não mascaramento. Prune após v3.8.45 mergear para main.",
|
||
"tests/unit/provider-models-route.test.ts": "v3.8.45 #6170: fix(providers) correct Kiro model catalog to real upstream ids — 3 assert.ok positivos de ids fabricados (claude-opus-4.7/sonnet-4.6) substituídos por 1 assert positivo de conjunto + 1 assert NEGATIVO garantindo que os ids fabricados sumiram (310→309). Asserts migrados ao catálogo real, não enfraquecidos. Verificado legítimo. Prune após v3.8.45 mergear para main.",
|
||
"tests/unit/copilot-gemini-claude-route-no-responses.test.ts": "v3.8.45 #6154: fix(providers) refresh GitHub Copilot catalog — 2 asserts combinados (registry-exists + par claude/gemini) reescritos como loop per-model com assert.ok individual por id do catálogo novo (7→6). Asserts reestruturados ao catálogo atualizado, não enfraquecidos. Verificado legítimo. Prune após v3.8.45 mergear para main.",
|
||
"tests/unit/agy-gemini-3696-tier-passthrough.test.ts": "v3.8.49 #8013: refactor(antigravity) align official clients and callable catalog — o id gemini-3.1-pro-high foi aposentado do catálogo público (o upstream rejeita a discovery slot com 400) e a tier High passou a usar o id distinto gemini-pro-agent, então o assert de passthrough do id aposentado foi removido (net 3→2). Superfície verificada inexistente em open-sse/config/antigravityModelAliases.ts; cobertura de gemini-pro-agent mantida em antigravity-retired-public-models.test.ts e agy-provider.test.ts. Verificado legítimo. Prune após v3.8.49 mergear para main.",
|
||
"tests/unit/agy-gemini-400-3229.test.ts": "v3.8.49 #8013: mesma causa do #3696 — gemini-3.1-pro-high aposentado em favor de gemini-pro-agent; o assert de passthrough do id aposentado saiu, restando gemini-3.1-pro-low e o plain id (net 9→8). Verificado contra open-sse/config/antigravityModelAliases.ts. Verificado legítimo. Prune após v3.8.49 mergear para main.",
|
||
"tests/unit/anthropic-cache-fingerprint.test.ts": "v3.8.49 #8464: feat(anthropic) add Claude Opus 5 support — o billing header nativo passou a usar CLAUDE_CODE_CLIENT_BILLING_VERSION, um valor capturado do binário assinado (src/shared/constants/claudeCodeClient.ts), no lugar do cálculo homebrew de fingerprint sha256 por dia/mensagem. O teste antigo REIMPLEMENTAVA o algoritmo inline sem nunca importar o código de produção; virou 1 assert que importa a constante real (net 8→1) — mais forte, não mais fraco. O fingerprint dinâmico por dia sobrevive só no caminho CC-bridge e está coberto em cc-bridge-transforms.test.ts (versionFormat ex-machina/omniroute-daystamp). Verificado legítimo. Prune após v3.8.49 mergear para main.",
|
||
"tests/unit/antigravity-client-profile.test.ts": "v3.8.49 #8013: o modelo de perfil harness/sdk/cli virou ide/cli unificado; getAntigravityBootstrapHeaders, antigravityHarnessUserAgent, deriveAntigravityMachineId e seedAntigravityVersionCache/clearAntigravityVersionCache foram removidos (grep confirma ausência) e substituídos por getAntigravityEnvelopeUserAgent + seedAntigravityIdeVersionCache/seedAntigravityCliVersionCache. O arquivo foi reescrito cobrindo o contrato novo inteiro (normalização de perfis legados, validação Zod, headers de identidade para ide e cli); net 29→26 é a consolidação. Verificado legítimo. Prune após v3.8.49 mergear para main.",
|
||
"tests/unit/antigravity-model-aliases.test.ts": "v3.8.49 #8013: os aliases de remapeamento de gemini-3-pro-preview, gemini-2.5-computer-use-preview-10-2025 e dos tiers de gemini-3.5-flash saíram de ANTIGRAVITY_MODEL_ALIASES (restam 4 entradas), então esses ids passam verbatim; claude-sonnet-5 e gemini-2.5-pro saíram de ANTIGRAVITY_PUBLIC_MODELS e isUserCallableAntigravityModelId retorna false para eles de fato. Dezenas de asserts individuais foram consolidados em loops sobre EXPECTED_FLASH_TIERS/RETIRED_FLASH_IDS, com cobertura NOVA para ids aposentados (net 73→62). Verificado legítimo. Prune após v3.8.49 mergear para main.",
|
||
"tests/unit/antigravity-tool-cloaking.test.ts": "v3.8.49 #8013: fix(antigravity) preserve protocol fidelity and fail closed — o mecanismo de cloaking (AG_DECOY_TOOLS, AG_TOOL_SUFFIX, cloakAntigravityToolPayload: renomeava tools do cliente com sufixo e injetava tools-chamariz) foi removido do código (grep confirma ausência total) e substituído por sanitizeAntigravityToolPayload, que preserva nome/ordem/identidade e só remove enumDescriptions (rejeitado com 400 pelo upstream). Os asserts do cloaking testavam código morto; o arquivo novo cobre a sanitização real com casos a mais (anyOf/allOf/$defs/additionalProperties). Net 23→12. Verificado legítimo. Prune após v3.8.49 mergear para main.",
|
||
"tests/unit/cache-control-claude-providers.test.ts": "v3.8.49 #7866: refactor(qwen) remove o provider OAuth legado — qwen não existe mais em CACHING_PROVIDERS nem em src/shared/constants/providers.ts (grep confirma), então o assert providerSupportsCaching(\"qwen\",\"openai\")===true testava um provider extinto (net 22→21). Verificado legítimo. Prune após v3.8.49 mergear para main.",
|
||
"tests/unit/cache-control-policy.test.ts": "v3.8.49 #8705 + #7866: a estratégia de combo deixou de gatear shouldPreserveCacheControl — a doc-string em open-sse/utils/cacheControlPolicy.ts documenta a mudança de política (reescrever breakpoints por requisição derrubava o prompt cache upstream, ~200k cache_write tokens/turn em produção). Os 8 testes \"rejeita combo com estratégia X\" (false) viraram um loop sobre 8 estratégias incluindo a nova quota-share (true), mais 2 testes negativos NOVOS (provider sem cache, cliente não caching-aware); 1 assert a menos vem do qwen removido pelo #7866. Net 96→91 é consolidação sobre superfície MAIOR. Verificado legítimo. Prune após v3.8.49 mergear para main.",
|
||
"tests/unit/codex-failover.test.ts": "v3.8.49 #7866: o assert getMaxAttempts(\"qwen\")===3 exercitava um ramo do helper LOCAL do teste (a fonte real, chatCore.ts, nunca especializou qwen) para um provider agora extinto; removido junto (net 30→29). Verificado legítimo. Prune após v3.8.49 mergear para main.",
|
||
"tests/unit/executor-claude-identity.test.ts": "v3.8.49 #8464: buildHashFor (hash do billing header) foi removida de claudeIdentity.ts sem call sites remanescentes — a lógica equivalente migrou para ccBridgeTransforms.ts (rota CC-bridge separada) e o path nativo usa placeholder cch=00000. Os 2 testes do describe morto (3 asserts) saem e 1 assert novo cobre selectBetaFlags para Opus 5 (net 47→45). Verificado legítimo. Prune após v3.8.49 mergear para main.",
|
||
"tests/unit/executor-default-base.test.ts": "v3.8.49 #7866 + #8464: o provider \"qwen\" (distinto de qwen-cloud/qwen-web) saiu do DefaultExecutor — não há mais case \"qwen\" em open-sse/executors/default.ts —, então os 3 testes que o exercitavam (9 asserts) foram removidos; o #8464 acrescentou 4 asserts de Opus 5/Stainless/billing no mesmo arquivo. Net 214→209. Verificado legítimo. Prune após v3.8.49 mergear para main.",
|
||
"tests/unit/executor-kimi-web-decoder.test.ts": "v3.8.49 #7531: o protocolo Connect do kimi-web trocou isEndOfStream (que silenciava JSON inválido e mensagens tool/function) por getConnectEndStreamError, e foldMessages agora LANÇA em vez de descartar conteúdo não suportado — endurecimento, não enfraquecimento. Os 4 testes do describe antigo (5 asserts) foram consolidados em 1 teste do decoder (net 40→35). Verificado legítimo. Prune após v3.8.49 mergear para main.",
|
||
"tests/unit/guide-settings-route.test.ts": "v3.8.49 #7866: saveQwenConfig foi removida do route.ts de guide-settings e o switch(toolId) não trata mais \"qwen\" (cai no default \"not supported\"), como parte da remoção da integração Qwen Code legada. Os 2 testes daquele fluxo (12 asserts) saíram porque a feature deixou de existir (net 35→23). Verificado legítimo. Prune após v3.8.49 mergear para main.",
|
||
"tests/unit/kimi-web-models-discovery.test.ts": "v3.8.49 #7531: kimi-web migrou de descoberta remota (HTTP a GetAvailableModels) para catálogo estático curado — KIMI_WEB_STATIC_MODELS=[k3,k2d6] em registry/kimi/web/index.ts. O teste foi reescrito para validar source=\"local_catalog\" e ZERO chamadas de fetch, no lugar de validar payload/headers de uma chamada remota que não existe mais (net 9→4). Verificado legítimo. Prune após v3.8.49 mergear para main.",
|
||
"tests/unit/oauth-providers-config.test.ts": "v3.8.49 #7866: QWEN_CONFIG/QWEN_OAUTH_CLIENT_ID saíram das configs OAuth (zero refs a qwen em src/lib/oauth/). O teste dedicado de hostname (4 asserts) e 3 asserts de qwenMapped no teste combinado foram removidos; +2 asserts novos de outras PRs do ciclo (clientProfile do Antigravity #8013, device-model Windows do Kimi #7531). Net 121→116. Verificado legítimo. Prune após v3.8.49 mergear para main.",
|
||
"tests/unit/oauth-providers-error-handling.test.ts": "v3.8.49 #7866: o teste \"P2: refreshQwenToken handles invalid_grant\" (3 asserts) saiu — refreshQwenToken não existe mais em open-sse/services/tokenRefresh/. Os demais testes só tiveram o path de leitura do source atualizado pela decomposição de tokenRefresh.ts (#8547/#7817) e tokenHealthCheck.ts (#7719), sem perda de asserts. Net 43→40. Verificado legítimo. Prune após v3.8.49 mergear para main.",
|
||
"tests/unit/perplexity-key-validation-models.test.ts": "v3.8.49 #7687: o registry da Perplexity separou modelsUrl (catálogo Agent, agora undefined) de testKeyModelsUrl (validação de chave, mantém /v1/models). O 2º teste antigo (3 asserts de shape estático de string) virou um teste COMPORTAMENTAL que mocka fetch e valida a chamada real de validateProviderApiKey — mais forte (net 7→6). Verificado legítimo. Prune após v3.8.49 mergear para main.",
|
||
"tests/unit/provider-header-profiles.test.ts": "v3.8.49 #7866: getQwenOauthHeaders() foi removida por completo de open-sse/config/providerHeaderProfiles.ts (grep confirma zero ocorrências); os 8 asserts perdidos testavam função extinta e 2 asserts novos cobrem getQoderDashscopeCompatHeaders (que reaproveita getQwenCliUserAgent, ainda existente). Net 29→23. Verificado legítimo. Prune após v3.8.49 mergear para main.",
|
||
"tests/unit/provider-request-capture-toolname-antigravity-4181.test.ts": "v3.8.49 #8013: o cloak _ide/AG_TOOL_SUFFIX foi removido — o Antigravity passou a usar o catálogo oficial de nomes de ferramentas, sem disfarce (grep confirma que cloakAntigravityToolPayload e AG_TOOL_SUFFIX não existem mais). O arquivo virou 1 teste do novo sanitizeAntigravityToolPayload; a cobertura do comportamento novo foi ampliada em antigravity-tool-cloaking.test.ts (3 testes dedicados). Net 13→5. Verificado legítimo. Prune após v3.8.49 mergear para main.",
|
||
"tests/unit/public-client-ids-3493.test.ts": "v3.8.49 #7866: QWEN_CONFIG saiu de src/lib/oauth/constants/oauth.ts (zero ocorrências); o único assert perdido validava QWEN_CONFIG.clientId (net 5→4). Verificado legítimo. Prune após v3.8.49 mergear para main.",
|
||
"tests/unit/search-handler-extended.test.ts": "v3.8.49 #7687: a cobertura de handleSearch/Perplexity migrou para tests/unit/search-handler-perplexity-options.test.ts (arquivo novo: cobre os mesmos campos + filtros de locale e acrescenta um caso de validação que não existia — allowlist/denylist de domínio mistos). Net 150→143. Destino verificado existente. Verificado legítimo. Prune após v3.8.49 mergear para main.",
|
||
"tests/unit/token-refresh-route-service.test.ts": "v3.8.49 #7866: refreshQwenToken e OAUTH_ENDPOINTS.qwen saíram do código (zero ocorrências); o assert perdido (qwen.providerSpecificData.resourceUrl) testava um fluxo de refresh inexistente e o contador de chamadas foi ajustado de >=8 para >=7 (uma chamada HTTP a menos). Net 50→49. Verificado legítimo. Prune após v3.8.49 mergear para main.",
|
||
"tests/unit/translator-openai-to-kiro.test.ts": "v3.8.49 #8565: auto-kiro passou a ser REJEITADO com erro (KIRO_REMOVED_AUTO_ALIAS_MESSAGE, \"not a real Kiro upstream model\") em vez de mapeado silenciosamente para \"auto\"; o teste do comportamento antigo foi removido porque hoje ele asseriria o comportamento errado. A rejeição está coberta em kiro-model-aliases.test.ts (assert.throws /not a real Kiro/) e kiro-available-models.test.ts. Net 119→118. Verificado legítimo. Prune após v3.8.49 mergear para main.",
|
||
"tests/unit/usage-providers.test.ts": "v3.8.49 #7866: o case \"qwen\" saiu de getUsageForProvider (não há mais case \"qwen\" no switch de open-sse/services/usage.ts); o teste cobria esse ramo extinto (net 20→19). Verificado legítimo. Prune após v3.8.49 mergear para main.",
|
||
"tests/unit/usage-service-hardening.test.ts": "v3.8.49 #7866/#8565/#8013: qwen removido (−3 asserts); o Kimi/Kiro builder-id (uso profileless) passou a ter SUCESSO real em vez de erro de ARN — supportsProfilelessKiroUsage(\"builder-id\") retorna true —, trocando 1 assert de regex de erro por 3 asserts de valor; e os ids de bucket de quota do Antigravity foram atualizados para o catálogo atual. Rodado no HEAD: 23/23 passam. Net 210→209. Verificado legítimo. Prune após v3.8.49 mergear para main.",
|
||
"tests/unit/virtual-auto-combo.test.ts": "v3.8.49 #7928/#8183: o pooling de contas passou a agrupar conexões web-session do mesmo provider numa entrada lógica com allowedConnectionIds (campo confirmado em open-sse/services/autoCombo/virtualFactory.ts), e o pool no-auth virou uma allowlist fixa (AUTO_COMBO_NOAUTH_ALLOWLIST = opencode, felo-web) — os testes antigos esperavam duplicatas e a inclusão de duckduckgo-web/theoldllm/chipotle, que hoje são corretamente excluídos. Guard dedicado em noauth-autocombo-allowlist.test.ts. Rodado no HEAD: 10/10 passam. Net 39→31. Verificado legítimo. Prune após v3.8.49 mergear para main.",
|
||
"open-sse/services/__tests__/tierResolver.test.ts": "v3.8.49 #7866: refactor(qwen) remove o provider OAuth legado — o teste \"classifies Qwen as free\" e a entrada de qwen na lista do batch saíram junto com o provider, e os índices do batch desceram de 10 para 9 elementos (net 61→59). Superfície extinta, não enfraquecimento. Verificado legítimo. Prune após v3.8.49 mergear para main.",
|
||
"tests/unit/plugins-welcome-banner-e2e.test.ts": "v3.8.50 #9126 (commit 8fac6bcd48): o teste único 'BUILTIN_EVENTS has all 14 events' (13 asserts .ok/.equal) foi reestruturado em 3 testes mais específicos — 'contains only emitted/public events' (assert.deepEqual da lista completa), 'does not advertise dead events' (7 asserts .equal(false) para eventos sem emissor real: onModelSelect/onComboResolve/onRateLimit/onQuotaExhaust/onProviderError/onStreamStart/onStreamEnd) e 'lifecycle events remain represented' (4 asserts .ok). Contrato mais forte (agora também nega presença dos eventos mortos), não mais fraco — a contagem líquida cai (73→61) porque o assert.deepEqual único substitui múltiplos assert.ok redundantes com a mesma cobertura. Asserts restruturados, não removidos sem substituição. Verificado legítimo.",
|
||
"tests/unit/web-tools-translation-2820.test.ts": "v3.8.50 #9343 (commit d969555417): fix(security) exige envelope <tool> explicito — JSON puro NAO deve mais ser promovido a tool_calls. Os 5 testes foram REESCRITOS para o contrato oposto (antes: 'promove e valida name/arguments'; agora: 'toolCalls === null e content preservado'), o que naturalmente usa menos asserts: verificar a NAO-promocao custa 2 asserts, verificar o objeto promovido custava 4. Contrato mais restritivo, nao mais fraco (39->35). Verificado legitimo — a inversao esta explicita nos proprios nomes dos testes ('does NOT promote ... (#9343)').",
|
||
"tests/unit/deepseek-web-tools-execute-2820.test.ts": "v3.8.50 ed661f2126 (alinhamento ao #9343): o teste 'parses bare JSON reply into OpenAI tool_calls' foi reescrito para o contrato INVERTIDO do fix de seguranca #9343 — JSON puro sem envelope <tool> NAO deve mais ser promovido. Verificar a nao-promocao custa 3 asserts (finish_reason stop, sem tool_calls, content preservado verbatim) onde validar o objeto promovido custava 5 (23->21). Mesma classe da entrada web-tools-translation-2820 acima. Contrato mais restritivo, nao mais fraco."
|
||
}
|