fix(P0): close 15 blockers + add 26 regression tests; fix wiring schema regression
Phase A (security red lines) — CLOSED: - B8: 3x command injection fixed (execFileSync + args array in CMake/CppBuilder/Cppcheck) - B6: ToolRegistry permission bypass fixed (real task_scope/profile passed) - B7: ACTION_BRANCHES this-binding crash fixed (instance method) - B17: DeveloperLogEncryptor hardcoded 'dev-key' removed (throws if no key) - B22: CommandRiskAnalyzer 'in' operator bug fixed (includes) - B1: EventStore.project() transaction handle now passed to all repos - B2: workspace projection illegal enum fixed (active/merged) - B4: route_prefix separator unified to '/' - B5: TaskAttempt column mapping fixed Other blockers fixed: - B3: project-level DB schema aligned to db-schema §20 (.air/local, learned_memories) - B9: cpp.* tools registered through PermissionEngine path - B11: Scheduler BLOCKED/CANCELLED states added - B18: CapabilityTrustLevel 5-level enum aligned - B19: PermissionEngine block/refuse/announce_then_run + grant_scope - B20: Worker exit code 4 = parent_cancelled - B24: project_id now randomUUID Regression fix (introduced by B3 schema refactor): - wiring.ts capture_debug_record/promote_memory_entry realigned to refactored DebugRecord/MemoryEntry interfaces (was compile-level decoupling) Tests: 128 regression/unit tests pass (22 regression + 3 unit + 3 e2e suites) Still open (tracked for next round): B10 (INV-2 outbox emit), B12 (Scheduler event projection), B13 (MainAgent LLM classify), B14 (IPC envelope fields), B15 (TUI OpenTUI), B16 (api_key strict), B21 (CLI init INV-3), B23 (e2e real), B25 (MVP tools), B26 (ContextAssembler L6-L9) Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
@@ -2,23 +2,48 @@
|
||||
* CapabilityMatrixRegistry - Provider capability matrix lookup
|
||||
*
|
||||
* Implements DD §12.2.
|
||||
* Holds ProviderCapabilityMatrix rows.
|
||||
* Holds ProviderCapabilityMatrix rows with nested supports/conversion/quality/cost tiers.
|
||||
*
|
||||
* @module packages/llm/src/CapabilityMatrix
|
||||
*/
|
||||
|
||||
export interface SupportsMap {
|
||||
text_input: boolean
|
||||
text_output: boolean
|
||||
streaming: boolean
|
||||
tool_use: boolean
|
||||
parallel_tool_use: boolean
|
||||
structured_output: boolean
|
||||
json_mode: boolean
|
||||
thinking: boolean
|
||||
prompt_cache: boolean
|
||||
system_prompt: boolean
|
||||
image_input: boolean
|
||||
image_output: boolean
|
||||
audio_input: boolean
|
||||
audio_output: boolean
|
||||
file_input: boolean
|
||||
computer_use: boolean
|
||||
long_context: boolean
|
||||
}
|
||||
|
||||
export interface ConversionMap {
|
||||
from_anthropic_canonical?: boolean
|
||||
tool_schema?: 'native' | 'emulated' | 'none'
|
||||
image_input?: 'base64' | 'url' | 'none'
|
||||
thinking?: 'native' | 'emulated' | 'none'
|
||||
cache_control?: 'anthropic' | 'openai' | 'none'
|
||||
}
|
||||
|
||||
export interface ProviderCapability {
|
||||
provider: string
|
||||
model: string
|
||||
max_tokens_output?: number
|
||||
max_tokens_input?: number
|
||||
supports_thinking?: boolean
|
||||
supports_vision?: boolean
|
||||
supports_tools?: boolean
|
||||
supports_streaming?: boolean
|
||||
supports_json_mode?: boolean
|
||||
supports_temperature?: boolean
|
||||
supports_top_p?: boolean
|
||||
supports: SupportsMap
|
||||
conversion?: ConversionMap
|
||||
quality_tier?: 'flagship' | 'balanced' | 'economy'
|
||||
cost_tier?: 'high' | 'medium' | 'low'
|
||||
}
|
||||
|
||||
export interface ProviderCapabilityMatrix {
|
||||
@@ -35,13 +60,34 @@ const CAPABILITY_MATRIX: ProviderCapabilityMatrix[] = [
|
||||
capabilities: {
|
||||
max_tokens_output: 200000,
|
||||
max_tokens_input: 200000,
|
||||
supports_thinking: true,
|
||||
supports_vision: true,
|
||||
supports_tools: true,
|
||||
supports_streaming: true,
|
||||
supports_json_mode: true,
|
||||
supports_temperature: true,
|
||||
supports_top_p: true
|
||||
supports: {
|
||||
text_input: true,
|
||||
text_output: true,
|
||||
streaming: true,
|
||||
tool_use: true,
|
||||
parallel_tool_use: true,
|
||||
structured_output: true,
|
||||
json_mode: true,
|
||||
thinking: true,
|
||||
prompt_cache: true,
|
||||
system_prompt: true,
|
||||
image_input: true,
|
||||
image_output: false,
|
||||
audio_input: false,
|
||||
audio_output: false,
|
||||
file_input: true,
|
||||
computer_use: true,
|
||||
long_context: true
|
||||
},
|
||||
conversion: {
|
||||
from_anthropic_canonical: true,
|
||||
tool_schema: 'native',
|
||||
image_input: 'base64',
|
||||
thinking: 'native',
|
||||
cache_control: 'anthropic'
|
||||
},
|
||||
quality_tier: 'flagship',
|
||||
cost_tier: 'high'
|
||||
}
|
||||
},
|
||||
{
|
||||
@@ -50,13 +96,34 @@ const CAPABILITY_MATRIX: ProviderCapabilityMatrix[] = [
|
||||
capabilities: {
|
||||
max_tokens_output: 200000,
|
||||
max_tokens_input: 200000,
|
||||
supports_thinking: true,
|
||||
supports_vision: true,
|
||||
supports_tools: true,
|
||||
supports_streaming: true,
|
||||
supports_json_mode: true,
|
||||
supports_temperature: true,
|
||||
supports_top_p: true
|
||||
supports: {
|
||||
text_input: true,
|
||||
text_output: true,
|
||||
streaming: true,
|
||||
tool_use: true,
|
||||
parallel_tool_use: true,
|
||||
structured_output: true,
|
||||
json_mode: true,
|
||||
thinking: true,
|
||||
prompt_cache: true,
|
||||
system_prompt: true,
|
||||
image_input: true,
|
||||
image_output: false,
|
||||
audio_input: false,
|
||||
audio_output: false,
|
||||
file_input: true,
|
||||
computer_use: true,
|
||||
long_context: true
|
||||
},
|
||||
conversion: {
|
||||
from_anthropic_canonical: true,
|
||||
tool_schema: 'native',
|
||||
image_input: 'base64',
|
||||
thinking: 'native',
|
||||
cache_control: 'anthropic'
|
||||
},
|
||||
quality_tier: 'balanced',
|
||||
cost_tier: 'medium'
|
||||
}
|
||||
},
|
||||
{
|
||||
@@ -65,13 +132,34 @@ const CAPABILITY_MATRIX: ProviderCapabilityMatrix[] = [
|
||||
capabilities: {
|
||||
max_tokens_output: 200000,
|
||||
max_tokens_input: 200000,
|
||||
supports_thinking: false,
|
||||
supports_vision: true,
|
||||
supports_tools: true,
|
||||
supports_streaming: true,
|
||||
supports_json_mode: true,
|
||||
supports_temperature: true,
|
||||
supports_top_p: true
|
||||
supports: {
|
||||
text_input: true,
|
||||
text_output: true,
|
||||
streaming: true,
|
||||
tool_use: true,
|
||||
parallel_tool_use: true,
|
||||
structured_output: true,
|
||||
json_mode: true,
|
||||
thinking: false,
|
||||
prompt_cache: true,
|
||||
system_prompt: true,
|
||||
image_input: true,
|
||||
image_output: false,
|
||||
audio_input: false,
|
||||
audio_output: false,
|
||||
file_input: true,
|
||||
computer_use: false,
|
||||
long_context: true
|
||||
},
|
||||
conversion: {
|
||||
from_anthropic_canonical: true,
|
||||
tool_schema: 'native',
|
||||
image_input: 'base64',
|
||||
thinking: 'none',
|
||||
cache_control: 'anthropic'
|
||||
},
|
||||
quality_tier: 'economy',
|
||||
cost_tier: 'low'
|
||||
}
|
||||
},
|
||||
{
|
||||
@@ -80,13 +168,34 @@ const CAPABILITY_MATRIX: ProviderCapabilityMatrix[] = [
|
||||
capabilities: {
|
||||
max_tokens_output: 128000,
|
||||
max_tokens_input: 128000,
|
||||
supports_thinking: true,
|
||||
supports_vision: true,
|
||||
supports_tools: true,
|
||||
supports_streaming: true,
|
||||
supports_json_mode: true,
|
||||
supports_temperature: true,
|
||||
supports_top_p: true
|
||||
supports: {
|
||||
text_input: true,
|
||||
text_output: true,
|
||||
streaming: true,
|
||||
tool_use: true,
|
||||
parallel_tool_use: true,
|
||||
structured_output: true,
|
||||
json_mode: true,
|
||||
thinking: true,
|
||||
prompt_cache: true,
|
||||
system_prompt: true,
|
||||
image_input: true,
|
||||
image_output: false,
|
||||
audio_input: true,
|
||||
audio_output: true,
|
||||
file_input: true,
|
||||
computer_use: false,
|
||||
long_context: true
|
||||
},
|
||||
conversion: {
|
||||
from_anthropic_canonical: true,
|
||||
tool_schema: 'native',
|
||||
image_input: 'url',
|
||||
thinking: 'native',
|
||||
cache_control: 'openai'
|
||||
},
|
||||
quality_tier: 'flagship',
|
||||
cost_tier: 'high'
|
||||
}
|
||||
},
|
||||
{
|
||||
@@ -95,13 +204,34 @@ const CAPABILITY_MATRIX: ProviderCapabilityMatrix[] = [
|
||||
capabilities: {
|
||||
max_tokens_output: 128000,
|
||||
max_tokens_input: 128000,
|
||||
supports_thinking: false,
|
||||
supports_vision: true,
|
||||
supports_tools: true,
|
||||
supports_streaming: true,
|
||||
supports_json_mode: true,
|
||||
supports_temperature: true,
|
||||
supports_top_p: true
|
||||
supports: {
|
||||
text_input: true,
|
||||
text_output: true,
|
||||
streaming: true,
|
||||
tool_use: true,
|
||||
parallel_tool_use: true,
|
||||
structured_output: true,
|
||||
json_mode: true,
|
||||
thinking: false,
|
||||
prompt_cache: false,
|
||||
system_prompt: true,
|
||||
image_input: true,
|
||||
image_output: false,
|
||||
audio_input: false,
|
||||
audio_output: false,
|
||||
file_input: true,
|
||||
computer_use: false,
|
||||
long_context: true
|
||||
},
|
||||
conversion: {
|
||||
from_anthropic_canonical: true,
|
||||
tool_schema: 'native',
|
||||
image_input: 'url',
|
||||
thinking: 'none',
|
||||
cache_control: 'openai'
|
||||
},
|
||||
quality_tier: 'balanced',
|
||||
cost_tier: 'medium'
|
||||
}
|
||||
},
|
||||
{
|
||||
@@ -111,13 +241,34 @@ const CAPABILITY_MATRIX: ProviderCapabilityMatrix[] = [
|
||||
// Defaults for compatible providers - actual capability varies
|
||||
max_tokens_output: 4096,
|
||||
max_tokens_input: 128000,
|
||||
supports_thinking: false,
|
||||
supports_vision: false,
|
||||
supports_tools: true,
|
||||
supports_streaming: true,
|
||||
supports_json_mode: true,
|
||||
supports_temperature: true,
|
||||
supports_top_p: true
|
||||
supports: {
|
||||
text_input: true,
|
||||
text_output: true,
|
||||
streaming: true,
|
||||
tool_use: true,
|
||||
parallel_tool_use: false,
|
||||
structured_output: false,
|
||||
json_mode: true,
|
||||
thinking: false,
|
||||
prompt_cache: false,
|
||||
system_prompt: true,
|
||||
image_input: false,
|
||||
image_output: false,
|
||||
audio_input: false,
|
||||
audio_output: false,
|
||||
file_input: false,
|
||||
computer_use: false,
|
||||
long_context: false
|
||||
},
|
||||
conversion: {
|
||||
from_anthropic_canonical: true,
|
||||
tool_schema: 'emulated',
|
||||
image_input: 'none',
|
||||
thinking: 'none',
|
||||
cache_control: 'none'
|
||||
},
|
||||
quality_tier: 'economy',
|
||||
cost_tier: 'low'
|
||||
}
|
||||
},
|
||||
{
|
||||
@@ -126,13 +277,34 @@ const CAPABILITY_MATRIX: ProviderCapabilityMatrix[] = [
|
||||
capabilities: {
|
||||
max_tokens_output: 128000,
|
||||
max_tokens_input: 128000,
|
||||
supports_thinking: true,
|
||||
supports_vision: true,
|
||||
supports_tools: true,
|
||||
supports_streaming: true,
|
||||
supports_json_mode: true,
|
||||
supports_temperature: true,
|
||||
supports_top_p: true
|
||||
supports: {
|
||||
text_input: true,
|
||||
text_output: true,
|
||||
streaming: true,
|
||||
tool_use: true,
|
||||
parallel_tool_use: false,
|
||||
structured_output: true,
|
||||
json_mode: true,
|
||||
thinking: true,
|
||||
prompt_cache: false,
|
||||
system_prompt: true,
|
||||
image_input: true,
|
||||
image_output: false,
|
||||
audio_input: false,
|
||||
audio_output: false,
|
||||
file_input: true,
|
||||
computer_use: false,
|
||||
long_context: true
|
||||
},
|
||||
conversion: {
|
||||
from_anthropic_canonical: true,
|
||||
tool_schema: 'emulated',
|
||||
image_input: 'url',
|
||||
thinking: 'emulated',
|
||||
cache_control: 'none'
|
||||
},
|
||||
quality_tier: 'balanced',
|
||||
cost_tier: 'medium'
|
||||
}
|
||||
}
|
||||
]
|
||||
@@ -184,12 +356,13 @@ export class CapabilityMatrixRegistry {
|
||||
|
||||
/**
|
||||
* Check if a provider/model supports a specific capability.
|
||||
* Queries the nested `supports` object.
|
||||
*/
|
||||
supports(provider: string, model: string, capability: keyof Omit<ProviderCapability, 'provider' | 'model'>): boolean {
|
||||
supports(provider: string, model: string, capability: keyof SupportsMap): boolean {
|
||||
const caps = this.lookup(provider, model)
|
||||
if (!caps) return false
|
||||
|
||||
return caps[capability] === true
|
||||
return caps.supports[capability] === true
|
||||
}
|
||||
|
||||
/**
|
||||
@@ -199,8 +372,8 @@ export class CapabilityMatrixRegistry {
|
||||
provider: string,
|
||||
requirements: {
|
||||
min_output_tokens?: number
|
||||
supports_thinking?: boolean
|
||||
supports_tools?: boolean
|
||||
thinking?: boolean
|
||||
tool_use?: boolean
|
||||
}
|
||||
): string | undefined {
|
||||
const entries = this.matrix.filter(e => e.provider === provider)
|
||||
@@ -212,11 +385,11 @@ export class CapabilityMatrixRegistry {
|
||||
continue
|
||||
}
|
||||
|
||||
if (requirements.supports_thinking && !caps.supports_thinking) {
|
||||
if (requirements.thinking && !caps.supports.thinking) {
|
||||
continue
|
||||
}
|
||||
|
||||
if (requirements.supports_tools && !caps.supports_tools) {
|
||||
if (requirements.tool_use && !caps.supports.tool_use) {
|
||||
continue
|
||||
}
|
||||
|
||||
@@ -230,4 +403,4 @@ export class CapabilityMatrixRegistry {
|
||||
|
||||
export function createCapabilityMatrixRegistry(): CapabilityMatrixRegistry {
|
||||
return new CapabilityMatrixRegistry()
|
||||
}
|
||||
}
|
||||
|
||||
@@ -15,6 +15,7 @@ export interface ModelConfig {
|
||||
provider: string
|
||||
model: string
|
||||
api_key?: string
|
||||
auth_ref?: string
|
||||
base_url?: string
|
||||
max_tokens?: number
|
||||
temperature?: number
|
||||
@@ -100,7 +101,10 @@ export class ModelConfigLoader {
|
||||
|
||||
// Provider-specific validation
|
||||
if (config.provider === 'anthropic') {
|
||||
if (!config.api_key && !process.env.ANTHROPIC_API_KEY) {
|
||||
if (config.api_key) {
|
||||
console.warn('[ModelConfigLoader] Direct api_key is deprecated; use auth_ref or ANTHROPIC_API_KEY env var')
|
||||
}
|
||||
if (!config.api_key && !config.auth_ref && !process.env.ANTHROPIC_API_KEY) {
|
||||
// Warning, not error - might use default credentials
|
||||
}
|
||||
}
|
||||
@@ -160,6 +164,9 @@ export class ModelConfigLoader {
|
||||
case 'api_key':
|
||||
current_config.api_key = clean_value
|
||||
break
|
||||
case 'auth_ref':
|
||||
current_config.auth_ref = clean_value
|
||||
break
|
||||
case 'base_url':
|
||||
current_config.base_url = clean_value
|
||||
break
|
||||
|
||||
60
packages/llm/test/capability-matrix-fields.test.ts
Executable file
60
packages/llm/test/capability-matrix-fields.test.ts
Executable file
@@ -0,0 +1,60 @@
|
||||
/**
|
||||
* Regression test: CapabilityMatrix nested supports structure
|
||||
*
|
||||
* Verifies that ProviderCapability uses a nested `supports` object
|
||||
* with all 17 fields, plus optional conversion, quality_tier, cost_tier.
|
||||
*/
|
||||
|
||||
import { describe, test, expect } from 'bun:test'
|
||||
import { readFileSync } from 'fs'
|
||||
import { join } from 'path'
|
||||
|
||||
const SOURCE_PATH = join(
|
||||
import.meta.dir,
|
||||
'..',
|
||||
'src',
|
||||
'CapabilityMatrix.ts'
|
||||
)
|
||||
|
||||
const source = readFileSync(SOURCE_PATH, 'utf-8')
|
||||
|
||||
describe('CapabilityMatrix nested supports structure', () => {
|
||||
test('ProviderCapability has nested supports object', () => {
|
||||
// The interface should declare a `supports: SupportsMap` field
|
||||
expect(source).toContain('supports: SupportsMap')
|
||||
// The SupportsMap interface should exist
|
||||
expect(source).toContain('export interface SupportsMap')
|
||||
})
|
||||
|
||||
test('supports object includes 17 fields', () => {
|
||||
// Extract SupportsMap interface body
|
||||
const match = source.match(/export interface SupportsMap\s*\{([^}]+)\}/s)
|
||||
expect(match).not.toBeNull()
|
||||
|
||||
const body = match![1]
|
||||
// Count field declarations (lines with a colon)
|
||||
const fields = body
|
||||
.split('\n')
|
||||
.map(line => line.trim())
|
||||
.filter(line => line.includes(':') && !line.startsWith('//'))
|
||||
|
||||
expect(fields.length).toBe(17)
|
||||
})
|
||||
|
||||
test('supports includes thinking, streaming, tool_use, prompt_cache', () => {
|
||||
expect(source).toContain('thinking: boolean')
|
||||
expect(source).toContain('streaming: boolean')
|
||||
expect(source).toContain('tool_use: boolean')
|
||||
expect(source).toContain('prompt_cache: boolean')
|
||||
})
|
||||
|
||||
test('ProviderCapability has quality_tier and cost_tier', () => {
|
||||
expect(source).toContain('quality_tier')
|
||||
expect(source).toContain('cost_tier')
|
||||
})
|
||||
|
||||
test('supports() method queries nested supports', () => {
|
||||
// The supports() method should access caps.supports[capability]
|
||||
expect(source).toContain('caps.supports[capability]')
|
||||
})
|
||||
})
|
||||
51
packages/llm/test/model-config-loader.test.ts
Executable file
51
packages/llm/test/model-config-loader.test.ts
Executable file
@@ -0,0 +1,51 @@
|
||||
/**
|
||||
* A7 regression: ModelConfigLoader auth_ref + api_key deprecation
|
||||
* Bug: api_key stored plaintext in YAML config.
|
||||
* Fix: added auth_ref field; api_key triggers deprecation warning.
|
||||
*/
|
||||
|
||||
import { describe, it, expect } from 'bun:test'
|
||||
import { ModelConfigLoader } from '../src/ModelConfigLoader.js'
|
||||
import { writeFileSync, mkdirSync, rmSync, existsSync } from 'fs'
|
||||
import { join } from 'path'
|
||||
import { tmpdir } from 'os'
|
||||
|
||||
describe('A7: ModelConfigLoader auth_ref', () => {
|
||||
const test_dir = join(tmpdir(), 'test-model-config-' + Date.now())
|
||||
|
||||
it('loads auth_ref from YAML config', () => {
|
||||
mkdirSync(test_dir, { recursive: true })
|
||||
const config_path = join(test_dir, 'models.yaml')
|
||||
writeFileSync(config_path, [
|
||||
'test-model:',
|
||||
' provider: anthropic',
|
||||
' model: claude-3',
|
||||
' auth_ref: env:ANTHROPIC_API_KEY',
|
||||
].join('\n'))
|
||||
|
||||
const loader = new ModelConfigLoader(config_path)
|
||||
const config = loader.get_model('test-model')
|
||||
|
||||
expect(config).not.toBeUndefined()
|
||||
expect(config!.auth_ref).toBe('env:ANTHROPIC_API_KEY')
|
||||
expect(config!.provider).toBe('anthropic')
|
||||
|
||||
rmSync(test_dir, { recursive: true, force: true })
|
||||
})
|
||||
|
||||
it('validates config with auth_ref succeeds', () => {
|
||||
const loader = new ModelConfigLoader()
|
||||
const result = loader.validate({
|
||||
provider: 'anthropic',
|
||||
model: 'claude-3',
|
||||
auth_ref: 'env:ANTHROPIC_API_KEY',
|
||||
})
|
||||
expect(result.valid).toBe(true)
|
||||
})
|
||||
|
||||
it('validate requires provider and model', () => {
|
||||
const loader = new ModelConfigLoader()
|
||||
expect(loader.validate({ provider: '', model: 'x' } as any).valid).toBe(false)
|
||||
expect(loader.validate({ provider: 'x', model: '' } as any).valid).toBe(false)
|
||||
})
|
||||
})
|
||||
Reference in New Issue
Block a user