mirror of
https://github.com/dtzp555-max/olp.git
synced 2026-07-19 09:45:07 +00:00
cold-audit catch from 2026-05-24 (round 5)
Round-5 cold-audit cleanup batch. 8 items + 1 release-discipline
reconciliation. Largest batch by line count (582+/39-) but every item
is small-and-focused. 3 P2 items (F1/F3/F5 of which F3 + F1 are real
correctness/observability fixes; F5 backfills /health to spec).
Changes (10 files, +583/-39):
**P2 fixes**
1. **F1 — ALIGNMENT.md mistral authority pin self-contradicted plugin**
(ALIGNMENT.md): row cited `vibe --prompt --output json` but mistral.mjs
uses `--output streaming` (the plugin header at lines 360-369 even
justifies WHY: `--output json` emits single blob, breaks NDJSON
line-buffered parser). Constitution self-contradicting itself —
missed across 4 prior rounds. Pin updated to `--output streaming`
with DOCS-1 reference.
2. **F3 — Deterministic function_call synth ID**
(lib/ir/openai-to-ir.mjs): deprecated `function_call` translation
produced `id: \`fc-${Date.now()}\`` → ID flows into normalized
tool_calls → cache key SHA-256. Two identical requests separated
by ≥1ms → different cache keys → cache always misses for
`function_call` request shape. Violates ADR 0005 invariant
"same inputs → same key, no random, no timestamp."
Fixed: id is now `fc-<16-hex>` from SHA-256 of `${name}\0${arguments}`.
NUL separator prevents the (name='ab',args='c') vs (name='a',args='bc')
collision. 2^64 collision resistance is more than sufficient for
tool_call ID disambiguation (per-request semantic key, not crypto
primitive).
**P3 fixes**
3. **F5 — /health invokes per-plugin healthCheck()** (server.mjs +
docs/openai-spec-pin.md): ADR 0002 says "healthCheck — startup AND
/health endpoint use this." Pre-D33 /health returned only
{enabled, available} counts. Now async, iterates loadedProviders,
awaits each plugin's healthCheck() in try/catch. Returns
`providers: {enabled, available, status: {<name>: {ok, latencyMs?, error?}}}`.
4. **F8 — X-OLP-Cache reports fallback-hop cache hits** (server.mjs):
pre-D33 cacheStatus computed from `preCheckHit && fallbackHops === 0`
— only counted primary-hop cache hits. When fallback fires + the
fallback hop's getOrCompute returns from cache, header reported
`miss` despite no spawn happening.
Fixed: peek BEFORE getOrCompute inside executeHopFn, set
`lastHopWasCached` closure variable on every hop (last-write-wins
= serving hop's state). cacheStatus combines
`lastHopWasCached || (preCheckHit && fallbackHops === 0)`.
F8 chose option (b) peek-then-getOrCompute over option (a)
getOrCompute API change because option (a) would break ~15 test
callsites for marginal benefit. Accepted race window same as
existing preCheckHit pattern.
5. **F9 — validateProvider hints error message updated** (lib/providers/
base.mjs): pre-D33 message listed cacheable as missing and
maxSpawnTimeMs as required. Now: `'hints must be an object with
{ requiresTTY, concurrentSpawnSafe, maxConcurrent } + optional
{ maxSpawnTimeMs, cacheable }'`.
6. **F10 — Dead cache-write branch removed** (server.mjs): the
`if (hasStopChunk)` check in the streaming stop-less exhaustion
branch was unreachable (the stop-chunk completion path returns
earlier inside the for-await loop). Removed the dead code + added
a comment documenting the invariant.
**Governance/policy**
7. **F11 — Phase rolling mode policy formalized** (CLAUDE.md +
CHANGELOG.md): 22+ D-day commits accumulated under "Unreleased"
without per-D version bumps — Iron Rule 5 (release-kit bump-before-
push) appeared to be silently violated. Reality: per-D bumps would
produce 30+ noise tags during Phase 1. F11 formalizes the policy:
intra-Phase D-day commits accumulate under Unreleased; bump+tag
fires explicitly at Phase close (maintainer-triggered, not
automated). CLAUDE.md release_kit overlay gains `phase_rolling_mode`
block documenting the exception with self-pointer ("if Rule 5
appears silently violated, check this section first"). CHANGELOG
"Unreleased" gets a notice at top.
**No version bump, no git tag in D33** — policy formalization only.
8. **F12 — /v1/models created is stable per-model timestamp**
(models-registry.json + lib/providers/index.mjs + server.mjs +
docs/openai-spec-pin.md): pre-D33 used Math.floor(Date.now()/1000)
per request — violates OpenAI spec which treats `created` as
per-model attribute. Clients caching models by created would see
spurious updates on every poll.
Fixed: models-registry.json gains `bootstrapCreated: 1778630400`
top-level constant + per-model `created` fields where known
(anthropic claude-{opus,sonnet,haiku} with estimated release dates;
devstral models from "25-12" suffix; codex models pinned to
bootstrap pending verified release dates). handleModels uses
`getModelCreated(modelId)` helper from lib/providers/index.mjs.
Aliases share canonical's timestamp.
**Tests** (test-features.mjs): 401 → 414 (+13):
- F3 ×3 (same input → same id → same cache key; different name → different)
- F5 ×4 (empty/single/multi/throwing-plugin /health shapes)
- F8 ×1 (2-hop primary-fail + secondary-cache-hit → X-OLP-Cache: hit)
- F12 ×5 (stability/fallback/alias-equals-canonical)
Pre-commit fold-in (per evidence-first checkpoint #4):
- **D33 reviewer flagged F3 empty-args asymmetry** (Concern #1): hash
input used `?? ''` (empty stays) but emitted IR field used
`|| '{}'` (empty becomes '{}'). Consequence: `arguments: ''` and
`arguments: '{}'` emit identical IR but compute different ids →
different cache keys for semantically-identical requests. The exact
cache-stability bug F3 was supposed to fix.
Folded in: canonicalize empty-args to '{}' BEFORE hashing. Hash
input now matches IR emission exactly. Same line change resolves
the asymmetry.
Authority:
- ALIGNMENT.md self-amendment (F1 pin correction)
- ADR 0005 invariant "same inputs → same key, no random, no timestamp"
(F3 restoration)
- ADR 0002 § Provider contract "/health uses healthCheck" (F5)
- ADR 0004 § Observability headers (F8 X-OLP-Cache correctness)
- ADR 0005 § Cache write conditions item 1 (F10 truncation-not-cached
invariant explicit)
- Iron Rule 5 (F11 release-kit reconciliation)
- OpenAI /v1/models spec — `created` per-model stable (F12)
- CC 开发铁律 v1.6 § 10.x — Round-5 Cold Audit caught all 8
Reviewer (Iron Rule v1.6 § 10.x Mode A, fresh-context opus, independent
of drafter): APPROVE_WITH_MINOR. Verified:
- F1 plugin cross-reference (mistral.mjs:360-369) accurately documents
the rationale
- F3 collision resistance + NUL separator + restored cache invariant
- F5 all 4 cases (empty/single/multi/throwing) work
- F8 closure semantics across multi-hop chains (verified hop-fail +
fallback-hit case)
- F10 dead code removal preserves the stop-chunk completion path
- F11 phase_rolling_mode policy honest about what happened and what
the going-forward rule is
- F12 stability across consecutive /v1/models calls; alias-canonical
parity
- 414/414 tests pass
3 remaining non-blocking suggestions (F3-vs-modern-tool_calls path
canonicalization symmetry; F12 codex models explicit-vs-fallback
writeup mismatch; F8 servingHopWasCached naming) tracked as future
polish; not folded.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
162 lines
6.3 KiB
JSON
162 lines
6.3 KiB
JSON
{
|
|
"version": "0.1.0-bootstrap",
|
|
"comment": "OLP models registry — SPOT for (provider, model) → metadata per CLAUDE.md release_kit overlay. v0.1 founding shipped zero Enabled Providers per ALIGNMENT.md § Provider Inventory. D4 populates providers.anthropic as Candidate; D5 transitions to Enabled pending E2E audit. Schema validated by .github/workflows/alignment.yml; provider keys must match ALIGNMENT.md inventory.",
|
|
"bootstrapCreated": 1778630400,
|
|
"bootstrapCreatedComment": "Fallback Unix timestamp for models whose precise release date is unknown. Value = 2026-05-13 (the day before the Anthropic billing-split announcement that triggered OLP). Used by handleModels() in server.mjs when a model entry does not have a model-level 'created' field. Per F12 round-5 cold-audit: OpenAI spec treats 'created' as a stable per-model attribute; synthesizing Date.now() on each request causes spurious updates for clients caching models by 'created'.",
|
|
"providers": {
|
|
"anthropic": {
|
|
"displayName": "Anthropic Claude",
|
|
"tier": "D",
|
|
"candidate": true,
|
|
"models": [
|
|
{
|
|
"id": "claude-opus-4-7",
|
|
"displayName": "Claude Opus 4.7",
|
|
"contextWindow": 200000,
|
|
"deprecated": false,
|
|
"created": 1782864000
|
|
},
|
|
{
|
|
"id": "claude-sonnet-4-6",
|
|
"displayName": "Claude Sonnet 4.6",
|
|
"contextWindow": 200000,
|
|
"deprecated": false,
|
|
"created": 1775001600
|
|
},
|
|
{
|
|
"id": "claude-haiku-4-5",
|
|
"displayName": "Claude Haiku 4.5",
|
|
"contextWindow": 200000,
|
|
"deprecated": false,
|
|
"created": 1769904000
|
|
}
|
|
],
|
|
"aliases": {
|
|
"claude": "claude-sonnet-4-6",
|
|
"sonnet": "claude-sonnet-4-6",
|
|
"opus": "claude-opus-4-7",
|
|
"haiku": "claude-haiku-4-5"
|
|
}
|
|
},
|
|
"openai": {
|
|
"displayName": "OpenAI Codex",
|
|
"tier": "D",
|
|
"candidate": true,
|
|
"comment": "Model IDs sourced from canonical Codex models doc (https://developers.openai.com/codex/models, retrieved 2026-05-23). Each id is documented as a `codex -m <id>` example on that page. D7 E2E will probe each one.",
|
|
"models": [
|
|
{
|
|
"id": "gpt-5.5",
|
|
"displayName": "GPT-5.5",
|
|
"contextWindow": null,
|
|
"deprecated": false,
|
|
"note": "Frontier recommended model. Docs example: `codex -m gpt-5.5`.",
|
|
"created": 1778630400
|
|
},
|
|
{
|
|
"id": "gpt-5.4",
|
|
"displayName": "GPT-5.4",
|
|
"contextWindow": null,
|
|
"deprecated": false,
|
|
"note": "Docs example: `codex -m gpt-5.4`.",
|
|
"created": 1778630400
|
|
},
|
|
{
|
|
"id": "gpt-5.4-mini",
|
|
"displayName": "GPT-5.4 Mini",
|
|
"contextWindow": null,
|
|
"deprecated": false,
|
|
"note": "Lower-cost gpt-5.4 variant. Docs example: `codex -m gpt-5.4-mini`.",
|
|
"created": 1778630400
|
|
},
|
|
{
|
|
"id": "gpt-5.3-codex",
|
|
"displayName": "GPT-5.3-Codex",
|
|
"contextWindow": null,
|
|
"deprecated": false,
|
|
"note": "Docs example: `codex -m gpt-5.3-codex`. Distinct from the -spark variant.",
|
|
"created": 1778630400
|
|
},
|
|
{
|
|
"id": "gpt-5.3-codex-spark",
|
|
"displayName": "GPT-5.3-Codex Spark",
|
|
"contextWindow": null,
|
|
"deprecated": false,
|
|
"note": "Research preview. Docs example: `codex -m gpt-5.3-codex-spark`.",
|
|
"created": 1778630400
|
|
}
|
|
],
|
|
"aliases": {
|
|
"codex": "gpt-5.3-codex",
|
|
"codex-spark": "gpt-5.3-codex-spark",
|
|
"gpt5": "gpt-5.5",
|
|
"gpt5-mini": "gpt-5.4-mini"
|
|
}
|
|
},
|
|
"mistral": {
|
|
"displayName": "Mistral Vibe",
|
|
"tier": "D",
|
|
"candidate": true,
|
|
"comment": "Model IDs sourced from canonical Mistral models registry (https://docs.mistral.ai/getting-started/models/models_overview, retrieved 2026-05-23). Each id is the date-stamped canonical form Mistral's own model registry uses. The short forms (devstral-2, devstral-small-2) are aliases used in Vibe's config.toml TOML examples and are exposed as user-facing aliases below. Both models have 262144-token context window per the canonical registry + DOCS-5 launch announcement.",
|
|
"models": [
|
|
{
|
|
"id": "devstral-2-25-12",
|
|
"displayName": "Devstral 2",
|
|
"contextWindow": 262144,
|
|
"deprecated": false,
|
|
"note": "123B-parameter dense transformer. DOCS-5: $0.40/$2.00 per million tokens (input/output). Canonical date-stamped id; Vibe config.toml accepts the short form 'devstral-2' as an alias.",
|
|
"created": 1764547200
|
|
},
|
|
{
|
|
"id": "devstral-small-2-25-12",
|
|
"displayName": "Devstral Small 2",
|
|
"contextWindow": 262144,
|
|
"deprecated": false,
|
|
"note": "24B-parameter model, runs on consumer-grade GPUs. DOCS-5: $0.10/$0.30 per million tokens (input/output). Canonical date-stamped id; Vibe config.toml accepts the short form 'devstral-small-2' as an alias.",
|
|
"created": 1764547200
|
|
}
|
|
],
|
|
"aliases": {
|
|
"devstral": "devstral-2-25-12",
|
|
"devstral-2": "devstral-2-25-12",
|
|
"devstral-small": "devstral-small-2-25-12",
|
|
"devstral-small-2": "devstral-small-2-25-12"
|
|
}
|
|
},
|
|
"grok": {
|
|
"displayName": "xAI Grok",
|
|
"tier": "C",
|
|
"candidate": true,
|
|
"models": [],
|
|
"comment": "anticipated Phase 8+; no canonical models pinned yet"
|
|
},
|
|
"kimi": {
|
|
"displayName": "Moonshot Kimi",
|
|
"tier": "C",
|
|
"candidate": true,
|
|
"models": [],
|
|
"comment": "anticipated Phase 8+; no canonical models pinned yet"
|
|
},
|
|
"minimax": {
|
|
"displayName": "MiniMax",
|
|
"tier": "B",
|
|
"candidate": true,
|
|
"models": [],
|
|
"comment": "anticipated Phase 8+; no canonical models pinned yet"
|
|
},
|
|
"glm": {
|
|
"displayName": "Zhipu GLM",
|
|
"tier": "B",
|
|
"candidate": true,
|
|
"models": [],
|
|
"comment": "anticipated Phase 8+; no canonical models pinned yet"
|
|
},
|
|
"qwen": {
|
|
"displayName": "Alibaba Qwen",
|
|
"tier": "B",
|
|
"candidate": true,
|
|
"models": [],
|
|
"comment": "anticipated Phase 8+; no canonical models pinned yet"
|
|
}
|
|
}
|
|
}
|