Files
OmniRoute/tests/unit/cli-runtime-extended.test.ts
Diego Rodrigues de Sa e Souza 7db430a352 Release v3.8.14 (#3340)
* chore(release): open v3.8.14 development cycle

Version bump 3.8.13 -> 3.8.14 (root + electron + open-sse + openapi + lockfiles).
Seed the v3.8.14 changelog with the four post-tag hotfixes that shipped to
Docker/Electron in v3.8.13 but missed the immutable npm 3.8.13 (#3336 SSRF /
CodeQL #323, #3334/#3335/#3339 Electron packaging). i18n CHANGELOG mirrors get
the in-progress placeholder section.

* feat: add per-provider custom headers support for OpenAI/Anthropic-compatible nodes (#3338)

Integrated into release/v3.8.14

* fix: Kiro Builder ID token import fails with Bad credentials (#3333)

Integrated into release/v3.8.14 — adds Builder ID cached-creds + OIDC refresh path for Kiro token import, with regression tests (#3333).

* Improve code quality: auto-pr/docstrings-1780792063 (#3337)

Integrated into release/v3.8.14 — docstring for context analytics route re-export.

* fix(catalog): remove minimaxai/minimax-m3 from NVIDIA NIM tier (404 upstream) (#3329) (#3341)

NVIDIA NIM does not host minimaxai/minimax-m3 — every request returns
404 page not found, while sibling minimaxai/minimax-m2.7 on the same provider
works. Advertising a model that 404s is a catalog bug; remove it from the nvidia
tier (it remains on the tiers that actually serve MiniMax M3). Re-add only once
NVIDIA serves it.

Co-authored-by: mikmaneggahommie <mikmaneggahommie@users.noreply.github.com>

* fix(cli): write OpenCode config to ~/.config on all platforms incl. Windows (#3330) (#3343)

resolveOpencodeConfigDir used %APPDATA% on Windows, but OpenCode reads its
config from XDG ~/.config/opencode/ on every platform (on Windows:
%USERPROFILE%\.config\opencode\, NOT %APPDATA%). So a Windows user who
configured OpenCode via the dashboard had the file written where OpenCode never
looks — it silently had no effect.

Use the XDG path (XDG_CONFIG_HOME || ~/.config) unconditionally. Update the UI
note + route JSDoc, and flip the three tests that encoded the old %APPDATA%
behavior (t40 per-platform + card-note, cli-runtime-extended getCliConfigPaths).

Co-authored-by: abdulkadirozyurt <abdulkadirozyurt@users.noreply.github.com>

* fix(proxy): make auto-selection fallback opt-in (#3332) (#3344)

selectWorkingProxyFallback (Step 11 of resolveProxyForConnection) listed ALL
registry proxies, ignoring assignments and per-connection proxy_enabled, and
returned the first working one with level:'autoSelect'. So a single proxy added
to the registry silently became a global fallback for every connection's traffic.

Gate it behind a new PROXY_AUTO_SELECT_ENABLED feature flag (default off): the
fallback now no-ops unless the operator opts in. No registry proxy becomes a
silent global default anymore.

Co-authored-by: hertznsk <hertznsk@users.noreply.github.com>

* fix(sse): treat MiniMax M3 as multimodal so vision isn't stripped (#3328) (#3342)

MiniMax M3 via the opencode provider (oc/minimax-m3-free) appeared blind:
image inputs didn't reach the model, while the same model in Cline could
see them. Verified empirically that MiniMax M3 on the opencode upstream IS
multimodal -- a base64 image is described correctly (it returns 403 only
for remote image URLs, which it doesn't accept).

Root cause: OmniRoute treated MiniMax M3 as a non-vision model in two
places, so when compression was active the image was replaced with a text
placeholder before dispatch:
- compression's modelSupportsVision() heuristic (lite.ts) only matched
  gpt-4/4o/claude-3/gemini/vision -- minimax was absent -> replaceImageUrls
  stripped the image.
- the opencode minimax-m3-free catalog entry lacked supportsVision, so the
  combo vision-capability gate could also exclude/mishandle it.

Add 'minimax-m3' to the vision heuristic and supportsVision: true to the
opencode minimax-m3-free entry. TDD: a failing-then-passing test in
compression/lite.test.ts proves replaceImageUrls now keeps images for
minimax-m3 ids, plus a registry assertion mirroring the #2822 qwen test.

Reported-by: @mikmaneggahommie

* docs(i18n): translate 25 core documentation files to Indonesian (#3348)

Integrated into release/v3.8.14 — Indonesian i18n docs.

* fix(review): resolve /review-reviews battery findings (LEDGER-1..11) on v3.8.14 (#3350)

Integrated into release/v3.8.14 — /review-reviews battery hardening (LEDGER-1..11) for #3338 custom-headers + #3333 kiro, plus cycle-test drift fixes (#3329/#3330/#3332).

* fix(provider-proxy): honor per-account proxy toggles (#3349)

Integrated into release/v3.8.14 — honor per-account proxy toggles + auto-fallback opt-in via PROXY_AUTO_SELECT_ENABLED.

* fix(dashboard): remove duplicate Distribute Proxies button on provider page (#3352)

* fix(providers): reduce proxy label noise (#3346)

Integrated into release/v3.8.14 — reduce proxy label noise + a11y (aria-label/sr-only).

* fix(duckduckgo): restore bare Response contract and rebase onto release/v3.8.14 (#3323)

Integrated into release/v3.8.14 — browser-backed cookie providers (duckduckgo/claude-web) with restored executor contract + unit tests.

* fix(noauth): expose only usable model aliases (#3345)

Integrated into release/v3.8.14 — noauth usable-alias filtering + registry alias plumbing (veo-free).

* fix(dashboard): stop infinite config-load loop on Hermes Agent detail page (#3353)

* fix(electron): tree-kill the server on exit/update to release the omniroute.exe lock (#3347) (#3354)

* chore(release): finalize v3.8.14 changelog + clear release-gate drift

- CHANGELOG: finalize the v3.8.14 section (date, full New Features/Bug Fixes/
  Maintenance coverage of all 16 cycle commits, Contributors hall of 12).
- docs: document OMNIROUTE_BROWSER_POOL + WEB_COOKIE_USE_BROWSER (#3323) in
  .env.example + ENVIRONMENT.md; regenerate the id/llm.txt strict mirror (#3348
  had translated it; llm.txt mirrors must match root).
- test(proxy-fetch): #3323 made tlsClient.available a computed getter — stub it
  via Object.defineProperty instead of assignment (5 tests were red on the base).

* fix(translator): coerce Gemini functionDeclaration parameters to an OBJECT schema (#3357) (#3360)

* fix(gemini): resolve truncation/suppression of false positive textual tool call markers in backticks (#3358)

Integrated into release/v3.8.14 — Gemini/Antigravity textual tool-call marker normalization (no false-positive suppression + split-chunk buffering).

* docs(changelog): add #3358 Gemini textual tool-call normalization to v3.8.14

* fix(dashboard): surface real analytics error instead of generic placeholder (#3356) (#3361)

The Analytics page discarded the server's error body on a non-OK response and
rendered a generic "An error occurred", so users (and maintainers) could not see
why /api/usage/analytics 500'd after an upgrade. Now the route returns the real
reason via buildErrorBody (sanitized, Hard Rule #12) and the page surfaces it via
a new readFetchErrorMessage helper that handles both the OpenAI-style and legacy
error shapes.

Reported-by: @superti4r

---------

Co-authored-by: PizzaV <103120356+pizzav-xyz@users.noreply.github.com>
Co-authored-by: Someres <168349709+quanturbo@users.noreply.github.com>
Co-authored-by: Dong Mengzhe <154944819+Lang-Qiu@users.noreply.github.com>
Co-authored-by: mikmaneggahommie <mikmaneggahommie@users.noreply.github.com>
Co-authored-by: abdulkadirozyurt <abdulkadirozyurt@users.noreply.github.com>
Co-authored-by: hertznsk <hertznsk@users.noreply.github.com>
Co-authored-by: Krisna Santosa <54174372+KrisnaSantosa15@users.noreply.github.com>
Co-authored-by: Randi <55005611+rdself@users.noreply.github.com>
Co-authored-by: Wilson <pedbookmed@gmail.com>
Co-authored-by: Paijo <14921983+oyi77@users.noreply.github.com>
Co-authored-by: Ardem2025 <ardemb22@gmail.com>
2026-06-07 07:20:02 -03:00

370 lines
14 KiB
TypeScript

import test from "node:test";
import assert from "node:assert/strict";
import fs from "node:fs";
import os from "node:os";
import path from "node:path";
import { createRequire, syncBuiltinESMExports } from "node:module";
import { pathToFileURL } from "node:url";
const require = createRequire(import.meta.url);
const childProcess = require("node:child_process");
const modulePath = path.join(process.cwd(), "src/shared/services/cliRuntime.ts");
const originalSpawn = childProcess.spawn;
const originalExecFileSync = childProcess.execFileSync;
const originalEnv = { ...process.env };
const tempDirs = new Set();
async function importFresh(label) {
return import(`${pathToFileURL(modulePath).href}?case=${label}-${Date.now()}-${Math.random()}`);
}
function restoreEnv() {
for (const key of Object.keys(process.env)) {
if (!(key in originalEnv)) delete process.env[key];
}
Object.assign(process.env, originalEnv);
}
function createTempDir(prefix) {
const dir = fs.mkdtempSync(path.join(os.tmpdir(), prefix));
tempDirs.add(dir);
return dir;
}
function writeScript(dir, name, content, executable = true) {
const filePath = path.join(dir, name);
fs.mkdirSync(path.dirname(filePath), { recursive: true });
fs.writeFileSync(filePath, content);
if (process.platform !== "win32") {
fs.chmodSync(filePath, executable ? 0o755 : 0o644);
}
return filePath;
}
test.afterEach(() => {
childProcess.spawn = originalSpawn;
childProcess.execFileSync = originalExecFileSync;
syncBuiltinESMExports();
restoreEnv();
for (const dir of tempDirs) {
fs.rmSync(dir as any, { recursive: true, force: true });
}
tempDirs.clear();
});
test("CLI config helpers enforce safe config homes and expose per-tool config paths", async () => {
const cliRuntime = await importFresh("config-helpers");
const homeDir = os.homedir();
const safeOverride = path.join(homeDir, "tmp-cli-config-home");
process.env.CLI_ALLOW_CONFIG_WRITES = "off";
assert.equal(cliRuntime.isCliConfigWriteAllowed(), false);
assert.match(cliRuntime.ensureCliConfigWriteAllowed(), /CLI_ALLOW_CONFIG_WRITES=false/);
process.env.CLI_CONFIG_HOME = safeOverride;
assert.equal(cliRuntime.getCliConfigHome(), safeOverride);
process.env.CLI_CONFIG_HOME = "relative/path";
assert.equal(cliRuntime.getCliConfigHome(), homeDir);
process.env.CLI_CONFIG_HOME = "/tmp/outside-home";
assert.equal(cliRuntime.getCliConfigHome(), homeDir);
process.env.CLI_CONFIG_HOME = safeOverride;
assert.deepEqual(cliRuntime.getCliConfigPaths("codex"), {
config: path.join(safeOverride, ".codex", "config.toml"),
auth: path.join(safeOverride, ".codex", "auth.json"),
});
assert.equal(
cliRuntime.getCliPrimaryConfigPath("codex"),
path.join(safeOverride, ".codex", "config.toml")
);
assert.equal(cliRuntime.getCliConfigPaths("unknown"), null);
process.env.XDG_CONFIG_HOME = path.join(homeDir, ".config-test");
// #3330: OpenCode uses XDG (`~/.config` / $XDG_CONFIG_HOME) on every platform,
// including Windows — no %APPDATA% special-case.
const expectedOpencodeRoot = process.env.XDG_CONFIG_HOME;
assert.deepEqual(cliRuntime.getCliConfigPaths("opencode"), {
config: path.join(expectedOpencodeRoot, "opencode", "opencode.json"),
});
});
test("getCliRuntimeStatus rejects unsafe env overrides and reports validated runtime mode", async () => {
process.env.CLI_MODE = "container";
process.env.CLI_CLAUDE_BIN = "relative/claude";
const cliRuntime = await importFresh("unsafe-env-command");
const status = await cliRuntime.getCliRuntimeStatus("claude");
assert.equal(status.installed, false);
assert.equal(status.runnable, false);
assert.equal(status.reason, "unsafe_path");
assert.equal(status.runtimeMode, "container");
assert.equal(status.requiresBinary, true);
});
test("getCliRuntimeStatus reports not_executable for absolute env override files without execute permission", async () => {
const tempDir = createTempDir("omniroute-cli-notexec-");
const scriptName = process.platform === "win32" ? "codex.cmd" : "codex";
const scriptPath = writeScript(
tempDir,
scriptName,
process.platform === "win32"
? "@echo off\r\necho codex 1.0.0\r\nREM padding padding padding\r\n"
: "#!/bin/sh\necho codex 1.0.0\n# padding padding padding\n",
false
);
process.env.CLI_CODEX_BIN = scriptPath;
const cliRuntime = await importFresh("not-executable");
const status = await cliRuntime.getCliRuntimeStatus("codex");
assert.equal(status.installed, true);
if (process.platform === "win32") {
assert.equal(status.runnable, true);
assert.equal(status.reason, null);
} else {
assert.equal(status.runnable, false);
assert.equal(status.reason, "not_executable");
}
assert.equal(status.commandPath, scriptPath);
});
test("getCliRuntimeStatus reports healthcheck_failed when a binary exists but does not answer version probes", async () => {
const tempDir = createTempDir("omniroute-cli-healthcheck-");
const scriptName = process.platform === "win32" ? "qodercli.cmd" : "qodercli";
const scriptPath = writeScript(
tempDir,
scriptName,
process.platform === "win32"
? "@echo off\r\nexit /b 1\r\nREM padding padding padding\r\n"
: "#!/bin/sh\nexit 1\n# padding padding padding\n"
);
process.env.CLI_QODER_BIN = scriptPath;
process.env.CLI_MODE = "invalid-mode";
const cliRuntime = await importFresh("healthcheck-failed");
const status = await cliRuntime.getCliRuntimeStatus("qoder");
assert.equal(status.installed, true);
assert.equal(status.runnable, false);
assert.equal(status.reason, "healthcheck_failed");
assert.equal(status.runtimeMode, "auto");
});
test("getCliRuntimeStatus healthchecks Windows .exe paths with spaces without shell", async () => {
if (process.platform !== "win32") return;
const tempDir = path.join(createTempDir("omniroute-cli-space-"), "dir with space");
const scriptPath = writeScript(
tempDir,
"claude.exe",
"fake executable content padding padding padding"
);
const spawnCalls = [];
process.env.CLI_CLAUDE_BIN = scriptPath;
childProcess.spawn = (command, args, options) => {
spawnCalls.push({ command, args, options });
const child = new (require("node:events").EventEmitter)();
child.stdout = new (require("node:events").EventEmitter)();
child.stderr = new (require("node:events").EventEmitter)();
child.kill = () => true;
setImmediate(() => {
child.stdout.emit("data", "2.1.157 (Claude Code)\n");
child.emit("close", 0);
});
return child;
};
syncBuiltinESMExports();
const cliRuntime = await importFresh("windows-exe-space-no-shell");
const status = await cliRuntime.getCliRuntimeStatus("claude");
assert.equal(status.installed, true);
assert.equal(status.runnable, true);
assert.equal(status.reason, null);
assert.equal(status.commandPath, scriptPath);
assert.equal(spawnCalls[0].command, scriptPath);
assert.deepEqual(spawnCalls[0].args, ["--version"]);
assert.equal(spawnCalls[0].options.shell, undefined);
});
test("getCliRuntimeStatus still healthchecks Windows .cmd wrappers through shell", async () => {
if (process.platform !== "win32") return;
const tempDir = createTempDir("omniroute-cli-cmd-shell-");
const scriptPath = writeScript(
tempDir,
"codex.cmd",
"@echo off\r\necho codex 1.2.3\r\nREM padding padding padding\r\n"
);
const spawnCalls = [];
process.env.CLI_CODEX_BIN = scriptPath;
childProcess.spawn = (command, args, options) => {
spawnCalls.push({ command, args, options });
const child = new (require("node:events").EventEmitter)();
child.stdout = new (require("node:events").EventEmitter)();
child.stderr = new (require("node:events").EventEmitter)();
child.kill = () => true;
setImmediate(() => {
child.stdout.emit("data", "codex 1.2.3\n");
child.emit("close", 0);
});
return child;
};
syncBuiltinESMExports();
const cliRuntime = await importFresh("windows-cmd-shell");
const status = await cliRuntime.getCliRuntimeStatus("codex");
assert.equal(status.installed, true);
assert.equal(status.runnable, true);
assert.equal(status.reason, null);
// The command is passed to spawn unquoted — Node quotes it for cmd.exe when
// shell:true. We must NOT manually interpolate quotes (hard rule #13).
assert.equal(spawnCalls[0].command, scriptPath);
assert.deepEqual(spawnCalls[0].args, ["--version"]);
assert.equal(spawnCalls[0].options.shell, true);
});
test("shouldUseShellForCommand never uses the shell on non-Windows platforms", async () => {
if (process.platform === "win32") return;
const cliRuntime = await importFresh("should-use-shell-posix");
for (const cmd of ["/usr/bin/claude", "/opt/My App/claude.exe", "tool.cmd", "x.bat"]) {
assert.equal(
cliRuntime.shouldUseShellForCommand(cmd),
false,
`expected no shell on POSIX for: ${cmd}`
);
}
});
test("getCliRuntimeStatus discovers binaries from CLI_EXTRA_PATHS during PATH lookup", async () => {
const tempDir = createTempDir("omniroute-cli-extra-path-");
const scriptName = process.platform === "win32" ? "qodercli.cmd" : "qodercli";
writeScript(
tempDir,
scriptName,
process.platform === "win32"
? "@echo off\r\necho qodercli 1.2.3\r\nREM padding padding padding\r\n"
: "#!/bin/sh\necho qodercli 1.2.3\n# padding padding padding\n"
);
process.env.CLI_EXTRA_PATHS = tempDir;
process.env.PATH = process.platform === "win32" ? process.env.PATH || "" : "/bin:/usr/bin";
const cliRuntime = await importFresh("extra-paths");
const status = await cliRuntime.getCliRuntimeStatus("qoder");
assert.equal(status.installed, true);
assert.equal(status.runnable, true);
assert.equal(status.reason, null);
assert.equal(
path.basename(String(status.commandPath)).toLowerCase(),
process.platform === "win32" ? "qodercli.cmd" : "qodercli"
);
});
test("getCliRuntimeStatus resolves known binaries from npm global prefix discovered via npm config", async () => {
const prefixDir = createTempDir("omniroute-cli-prefix-");
const scriptName = process.platform === "win32" ? "qodercli.cmd" : "qodercli";
const scriptPath = writeScript(
path.join(prefixDir, process.platform === "win32" ? "" : "bin"),
scriptName,
process.platform === "win32"
? "@echo off\r\necho qodercli 1.2.3\r\nREM padding padding padding\r\n"
: "#!/bin/sh\necho qodercli 1.2.3\n# padding padding padding\n"
);
delete process.env.npm_config_prefix;
process.env.PATH = process.platform === "win32" ? process.env.PATH || "" : "/bin:/usr/bin";
childProcess.execFileSync = (command, args) => {
assert.equal(command, "npm");
assert.deepEqual(args, ["config", "get", "prefix"]);
return `${prefixDir}\n`;
};
syncBuiltinESMExports();
const cliRuntime = await importFresh("npm-prefix-known-path");
const status = await cliRuntime.getCliRuntimeStatus("qoder");
assert.equal(status.installed, true);
assert.equal(status.runnable, true);
assert.equal(status.reason, null);
assert.equal(status.commandPath, scriptPath);
});
test("getCliRuntimeStatus ignores suspicious known-path binaries and symlink escapes", async () => {
const prefixDir = createTempDir("omniroute-cli-suspicious-");
const binDir = path.join(prefixDir, process.platform === "win32" ? "" : "bin");
const scriptName = process.platform === "win32" ? "qodercli.exe" : "qodercli";
fs.mkdirSync(binDir, { recursive: true });
fs.writeFileSync(path.join(binDir, scriptName), "");
process.env.npm_config_prefix = prefixDir;
process.env.PATH = process.platform === "win32" ? process.env.PATH || "" : "/bin:/usr/bin";
const cliRuntime = await importFresh("suspicious-size");
const suspiciousStatus = await cliRuntime.getCliRuntimeStatus("qoder");
assert.equal(suspiciousStatus.installed, false);
assert.equal(suspiciousStatus.reason, "suspicious_size");
if (process.platform !== "win32") {
const escapePrefix = createTempDir("omniroute-cli-escape-");
const escapeBinDir = path.join(escapePrefix, "bin");
const outsideDir = createTempDir("omniroute-cli-outside-");
const outsideTarget = writeScript(
outsideDir,
"qodercli",
"#!/bin/sh\necho qodercli 9.9.9\n# padding padding padding\n"
);
fs.mkdirSync(escapeBinDir, { recursive: true });
fs.symlinkSync(outsideTarget, path.join(escapeBinDir, "qodercli"));
process.env.npm_config_prefix = escapePrefix;
const escapedRuntime = await importFresh("symlink-escape");
const escapedStatus = await escapedRuntime.getCliRuntimeStatus("qoder");
assert.equal(escapedStatus.installed, false);
assert.equal(escapedStatus.reason, "symlink_escape");
}
});
test("getCliRuntimeStatus tolerates spawn errors during healthcheck and marks the tool as not runnable", async () => {
const tempDir = createTempDir("omniroute-cli-spawn-error-");
const scriptName = process.platform === "win32" ? "cline.cmd" : "cline";
const scriptPath = writeScript(
tempDir,
scriptName,
process.platform === "win32"
? "@echo off\r\necho cline\r\nREM padding padding padding\r\n"
: "#!/bin/sh\necho cline\n# padding padding padding\n"
);
process.env.CLI_CLINE_BIN = scriptPath;
childProcess.spawn = () => {
const child = new (require("node:events").EventEmitter)();
child.stdout = new (require("node:events").EventEmitter)();
child.stderr = new (require("node:events").EventEmitter)();
child.kill = () => true;
setImmediate(() => child.emit("error", new Error("spawn blocked")));
return child;
};
syncBuiltinESMExports();
const cliRuntime = await importFresh("spawn-error");
const status = await cliRuntime.getCliRuntimeStatus("cline");
assert.equal(status.installed, true);
assert.equal(status.runnable, false);
assert.equal(status.reason, "healthcheck_failed");
});