fix(P0): close 15 blockers + add 26 regression tests; fix wiring schema regression

Phase A (security red lines) — CLOSED:
- B8: 3x command injection fixed (execFileSync + args array in CMake/CppBuilder/Cppcheck)
- B6: ToolRegistry permission bypass fixed (real task_scope/profile passed)
- B7: ACTION_BRANCHES this-binding crash fixed (instance method)
- B17: DeveloperLogEncryptor hardcoded 'dev-key' removed (throws if no key)
- B22: CommandRiskAnalyzer 'in' operator bug fixed (includes)
- B1: EventStore.project() transaction handle now passed to all repos
- B2: workspace projection illegal enum fixed (active/merged)
- B4: route_prefix separator unified to '/'
- B5: TaskAttempt column mapping fixed

Other blockers fixed:
- B3: project-level DB schema aligned to db-schema §20 (.air/local, learned_memories)
- B9: cpp.* tools registered through PermissionEngine path
- B11: Scheduler BLOCKED/CANCELLED states added
- B18: CapabilityTrustLevel 5-level enum aligned
- B19: PermissionEngine block/refuse/announce_then_run + grant_scope
- B20: Worker exit code 4 = parent_cancelled
- B24: project_id now randomUUID

Regression fix (introduced by B3 schema refactor):
- wiring.ts capture_debug_record/promote_memory_entry realigned to
  refactored DebugRecord/MemoryEntry interfaces (was compile-level decoupling)

Tests: 128 regression/unit tests pass (22 regression + 3 unit + 3 e2e suites)

Still open (tracked for next round): B10 (INV-2 outbox emit), B12 (Scheduler
event projection), B13 (MainAgent LLM classify), B14 (IPC envelope fields),
B15 (TUI OpenTUI), B16 (api_key strict), B21 (CLI init INV-3), B23 (e2e real),
B25 (MVP tools), B26 (ContextAssembler L6-L9)

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
AirCoding
2026-06-03 13:13:27 +08:00
parent 79d776fdc9
commit 20bad8ca29
67 changed files with 2390 additions and 555 deletions

View File

@@ -2,23 +2,48 @@
* CapabilityMatrixRegistry - Provider capability matrix lookup
*
* Implements DD §12.2.
* Holds ProviderCapabilityMatrix rows.
* Holds ProviderCapabilityMatrix rows with nested supports/conversion/quality/cost tiers.
*
* @module packages/llm/src/CapabilityMatrix
*/
export interface SupportsMap {
text_input: boolean
text_output: boolean
streaming: boolean
tool_use: boolean
parallel_tool_use: boolean
structured_output: boolean
json_mode: boolean
thinking: boolean
prompt_cache: boolean
system_prompt: boolean
image_input: boolean
image_output: boolean
audio_input: boolean
audio_output: boolean
file_input: boolean
computer_use: boolean
long_context: boolean
}
export interface ConversionMap {
from_anthropic_canonical?: boolean
tool_schema?: 'native' | 'emulated' | 'none'
image_input?: 'base64' | 'url' | 'none'
thinking?: 'native' | 'emulated' | 'none'
cache_control?: 'anthropic' | 'openai' | 'none'
}
export interface ProviderCapability {
provider: string
model: string
max_tokens_output?: number
max_tokens_input?: number
supports_thinking?: boolean
supports_vision?: boolean
supports_tools?: boolean
supports_streaming?: boolean
supports_json_mode?: boolean
supports_temperature?: boolean
supports_top_p?: boolean
supports: SupportsMap
conversion?: ConversionMap
quality_tier?: 'flagship' | 'balanced' | 'economy'
cost_tier?: 'high' | 'medium' | 'low'
}
export interface ProviderCapabilityMatrix {
@@ -35,13 +60,34 @@ const CAPABILITY_MATRIX: ProviderCapabilityMatrix[] = [
capabilities: {
max_tokens_output: 200000,
max_tokens_input: 200000,
supports_thinking: true,
supports_vision: true,
supports_tools: true,
supports_streaming: true,
supports_json_mode: true,
supports_temperature: true,
supports_top_p: true
supports: {
text_input: true,
text_output: true,
streaming: true,
tool_use: true,
parallel_tool_use: true,
structured_output: true,
json_mode: true,
thinking: true,
prompt_cache: true,
system_prompt: true,
image_input: true,
image_output: false,
audio_input: false,
audio_output: false,
file_input: true,
computer_use: true,
long_context: true
},
conversion: {
from_anthropic_canonical: true,
tool_schema: 'native',
image_input: 'base64',
thinking: 'native',
cache_control: 'anthropic'
},
quality_tier: 'flagship',
cost_tier: 'high'
}
},
{
@@ -50,13 +96,34 @@ const CAPABILITY_MATRIX: ProviderCapabilityMatrix[] = [
capabilities: {
max_tokens_output: 200000,
max_tokens_input: 200000,
supports_thinking: true,
supports_vision: true,
supports_tools: true,
supports_streaming: true,
supports_json_mode: true,
supports_temperature: true,
supports_top_p: true
supports: {
text_input: true,
text_output: true,
streaming: true,
tool_use: true,
parallel_tool_use: true,
structured_output: true,
json_mode: true,
thinking: true,
prompt_cache: true,
system_prompt: true,
image_input: true,
image_output: false,
audio_input: false,
audio_output: false,
file_input: true,
computer_use: true,
long_context: true
},
conversion: {
from_anthropic_canonical: true,
tool_schema: 'native',
image_input: 'base64',
thinking: 'native',
cache_control: 'anthropic'
},
quality_tier: 'balanced',
cost_tier: 'medium'
}
},
{
@@ -65,13 +132,34 @@ const CAPABILITY_MATRIX: ProviderCapabilityMatrix[] = [
capabilities: {
max_tokens_output: 200000,
max_tokens_input: 200000,
supports_thinking: false,
supports_vision: true,
supports_tools: true,
supports_streaming: true,
supports_json_mode: true,
supports_temperature: true,
supports_top_p: true
supports: {
text_input: true,
text_output: true,
streaming: true,
tool_use: true,
parallel_tool_use: true,
structured_output: true,
json_mode: true,
thinking: false,
prompt_cache: true,
system_prompt: true,
image_input: true,
image_output: false,
audio_input: false,
audio_output: false,
file_input: true,
computer_use: false,
long_context: true
},
conversion: {
from_anthropic_canonical: true,
tool_schema: 'native',
image_input: 'base64',
thinking: 'none',
cache_control: 'anthropic'
},
quality_tier: 'economy',
cost_tier: 'low'
}
},
{
@@ -80,13 +168,34 @@ const CAPABILITY_MATRIX: ProviderCapabilityMatrix[] = [
capabilities: {
max_tokens_output: 128000,
max_tokens_input: 128000,
supports_thinking: true,
supports_vision: true,
supports_tools: true,
supports_streaming: true,
supports_json_mode: true,
supports_temperature: true,
supports_top_p: true
supports: {
text_input: true,
text_output: true,
streaming: true,
tool_use: true,
parallel_tool_use: true,
structured_output: true,
json_mode: true,
thinking: true,
prompt_cache: true,
system_prompt: true,
image_input: true,
image_output: false,
audio_input: true,
audio_output: true,
file_input: true,
computer_use: false,
long_context: true
},
conversion: {
from_anthropic_canonical: true,
tool_schema: 'native',
image_input: 'url',
thinking: 'native',
cache_control: 'openai'
},
quality_tier: 'flagship',
cost_tier: 'high'
}
},
{
@@ -95,13 +204,34 @@ const CAPABILITY_MATRIX: ProviderCapabilityMatrix[] = [
capabilities: {
max_tokens_output: 128000,
max_tokens_input: 128000,
supports_thinking: false,
supports_vision: true,
supports_tools: true,
supports_streaming: true,
supports_json_mode: true,
supports_temperature: true,
supports_top_p: true
supports: {
text_input: true,
text_output: true,
streaming: true,
tool_use: true,
parallel_tool_use: true,
structured_output: true,
json_mode: true,
thinking: false,
prompt_cache: false,
system_prompt: true,
image_input: true,
image_output: false,
audio_input: false,
audio_output: false,
file_input: true,
computer_use: false,
long_context: true
},
conversion: {
from_anthropic_canonical: true,
tool_schema: 'native',
image_input: 'url',
thinking: 'none',
cache_control: 'openai'
},
quality_tier: 'balanced',
cost_tier: 'medium'
}
},
{
@@ -111,13 +241,34 @@ const CAPABILITY_MATRIX: ProviderCapabilityMatrix[] = [
// Defaults for compatible providers - actual capability varies
max_tokens_output: 4096,
max_tokens_input: 128000,
supports_thinking: false,
supports_vision: false,
supports_tools: true,
supports_streaming: true,
supports_json_mode: true,
supports_temperature: true,
supports_top_p: true
supports: {
text_input: true,
text_output: true,
streaming: true,
tool_use: true,
parallel_tool_use: false,
structured_output: false,
json_mode: true,
thinking: false,
prompt_cache: false,
system_prompt: true,
image_input: false,
image_output: false,
audio_input: false,
audio_output: false,
file_input: false,
computer_use: false,
long_context: false
},
conversion: {
from_anthropic_canonical: true,
tool_schema: 'emulated',
image_input: 'none',
thinking: 'none',
cache_control: 'none'
},
quality_tier: 'economy',
cost_tier: 'low'
}
},
{
@@ -126,13 +277,34 @@ const CAPABILITY_MATRIX: ProviderCapabilityMatrix[] = [
capabilities: {
max_tokens_output: 128000,
max_tokens_input: 128000,
supports_thinking: true,
supports_vision: true,
supports_tools: true,
supports_streaming: true,
supports_json_mode: true,
supports_temperature: true,
supports_top_p: true
supports: {
text_input: true,
text_output: true,
streaming: true,
tool_use: true,
parallel_tool_use: false,
structured_output: true,
json_mode: true,
thinking: true,
prompt_cache: false,
system_prompt: true,
image_input: true,
image_output: false,
audio_input: false,
audio_output: false,
file_input: true,
computer_use: false,
long_context: true
},
conversion: {
from_anthropic_canonical: true,
tool_schema: 'emulated',
image_input: 'url',
thinking: 'emulated',
cache_control: 'none'
},
quality_tier: 'balanced',
cost_tier: 'medium'
}
}
]
@@ -184,12 +356,13 @@ export class CapabilityMatrixRegistry {
/**
* Check if a provider/model supports a specific capability.
* Queries the nested `supports` object.
*/
supports(provider: string, model: string, capability: keyof Omit<ProviderCapability, 'provider' | 'model'>): boolean {
supports(provider: string, model: string, capability: keyof SupportsMap): boolean {
const caps = this.lookup(provider, model)
if (!caps) return false
return caps[capability] === true
return caps.supports[capability] === true
}
/**
@@ -199,8 +372,8 @@ export class CapabilityMatrixRegistry {
provider: string,
requirements: {
min_output_tokens?: number
supports_thinking?: boolean
supports_tools?: boolean
thinking?: boolean
tool_use?: boolean
}
): string | undefined {
const entries = this.matrix.filter(e => e.provider === provider)
@@ -212,11 +385,11 @@ export class CapabilityMatrixRegistry {
continue
}
if (requirements.supports_thinking && !caps.supports_thinking) {
if (requirements.thinking && !caps.supports.thinking) {
continue
}
if (requirements.supports_tools && !caps.supports_tools) {
if (requirements.tool_use && !caps.supports.tool_use) {
continue
}
@@ -230,4 +403,4 @@ export class CapabilityMatrixRegistry {
export function createCapabilityMatrixRegistry(): CapabilityMatrixRegistry {
return new CapabilityMatrixRegistry()
}
}

View File

@@ -15,6 +15,7 @@ export interface ModelConfig {
provider: string
model: string
api_key?: string
auth_ref?: string
base_url?: string
max_tokens?: number
temperature?: number
@@ -100,7 +101,10 @@ export class ModelConfigLoader {
// Provider-specific validation
if (config.provider === 'anthropic') {
if (!config.api_key && !process.env.ANTHROPIC_API_KEY) {
if (config.api_key) {
console.warn('[ModelConfigLoader] Direct api_key is deprecated; use auth_ref or ANTHROPIC_API_KEY env var')
}
if (!config.api_key && !config.auth_ref && !process.env.ANTHROPIC_API_KEY) {
// Warning, not error - might use default credentials
}
}
@@ -160,6 +164,9 @@ export class ModelConfigLoader {
case 'api_key':
current_config.api_key = clean_value
break
case 'auth_ref':
current_config.auth_ref = clean_value
break
case 'base_url':
current_config.base_url = clean_value
break