mirror of
https://github.com/garrytan/gbrain.git
synced 2026-07-29 19:01:39 +00:00
* fix(subagent): bind Anthropic SDK messages.create() correctly The makeSubagentHandler was casting `new Anthropic()` directly to MessagesClient, but MessagesClient.create() maps to sdk.messages.create(), not sdk.create(). Every subagent job immediately died with: client.create is not a function Fix: wrap the SDK instance so .create() delegates to .messages.create() with proper `this` binding via .bind(sdk.messages). Discovered on first production run of gbrain agent against Supabase. Co-Authored-By: Wintermute <wintermute@openclaw.ai> * chore(ci): add typescript typecheck to test pipeline + clean up baseline errors Root cause infra gap that let the v0.16.0 subagent bug ship: CI ran only `bun test`, which transpiles types without checking them. Type errors only surfaced at runtime, in production. Changes: - Add `typescript` devDep and a `typecheck` npm script (`tsc --noEmit`). - Chain `bun run typecheck` into `bun run test` so developers get the same pipeline locally that CI runs. - Flip `.github/workflows/test.yml` to invoke `bun run test` (the npm script, including typecheck) instead of `bun test` (runner only). - Clean up 100+ pre-existing type errors across 30+ files so the first run of `tsc --noEmit` is green. Root causes were: - `databaseUrl` → `database_url` rename drift in test fixtures (9 files) - `PageType` union missing `'meeting'` / `'note'` entries that are already used in both src and tests (link-extraction.ts comments acknowledged the gap) - `GBrainConfig.storage` field never declared despite being read in files.ts and operations.ts - `ErrorCode` union missing `'permission_denied'` - `OrchestratorOpts` shape changed; test callers not updated - Dead-code comparisons in migration orchestrators against narrowed status types - postgres.js `Row`-callback type drift on several `.map()` calls - Buffer-as-BodyInit assignment in supabase.ts (real but non-fatal runtime bug; Uint8Array slice works and is type-correct) - Various `as X` single-step casts that now need `as unknown as X` per TS's stricter structural-conversion rules - Bump `beforeAll` hook timeout to 30s on four PGLite-heavy tests that were flaky under parallel test execution: wait-for-completion, extract-fs, e2e/search-quality, e2e/graph-quality. All pass in isolation; timeouts only happened when dozens of PGLite instances init'd simultaneously. The new CI pipeline now fails on any type error across src/ or test/, giving us the compile-time regression guard the subagent fix depends on. * fix(subagent): bind Anthropic SDK messages.create() correctly Shipped bug: v0.16.0 cast `new Anthropic()` to `MessagesClient`, but `.create()` lives at `sdk.messages.create`, not on the top-level client. Every subagent job in production died on first LLM call with `client.create is not a function`. Discovered on the first `gbrain agent run` against Supabase. Fix: assign `sdk.messages` directly to the `MessagesClient` slot. `sdk.messages` IS the object with a callable `.create()`; the original bug was picking the wrong entry point on the SDK. No helper, no wrapper, no `.bind()` — JS method-call semantics preserve `this` at the call site because `subagent.ts:336` invokes `client.create(...)` with `client === sdk.messages`. The one-line assignment also typechecks cleanly against the existing `MessagesClient` interface (SDK's first `create` overload: `(MessageCreateParamsNonStreaming, Core.RequestOptions?) => APIPromise<Message>` is assignable structurally). This gives us compile-time regression protection: anyone reverting to `new Anthropic()` would fail tsc because `Anthropic` has no top-level `.create`. (The companion chore commit puts `tsc --noEmit` in CI so this guard is enforced.) Also adds a `makeAnthropic?: () => Anthropic` dep-injection seam so the factory default construction branch is testable without real API calls. Regression test drives one handler turn through a fake SDK, asserting `sdk.messages.create` is actually called. If someone later reverts to `new Anthropic()`, both guards fire: tsc fails AND the test fails. Co-Authored-By: Wintermute <wintermute@garrytan.com> * chore(tests): add bunfig.toml + 60s hook timeouts to stabilize PGLite-heavy suites After turning on tsc in CI (previous commit), running the full `bun run test` suite in one shot triggered flaky `beforeEach/afterEach hook timed out` failures on 8+ test files. Every failure traced to PGLite WASM init contention when many test files spin up fresh PGLite instances in parallel; each one alone passes in isolation. - `bunfig.toml` sets the global test hook timeout to 60s (default is 5s), covering every test file without per-file edits. - Individual `beforeAll(fn, 60_000)` / `beforeEach(fn, 15_000)` calls on the 8 tests that flaked most stay in place as explicit safety nets so a future bunfig config change doesn't silently re-introduce the flake. Result: 1997 pass, 0 fail on `bun run test` (117 tests added since the prior baseline by picking up typecheck-gated passes). No infrastructure flake tolerated in CI. * chore: bump version and changelog (v0.16.3) Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Wintermute <wintermute@garrytan.com> Co-authored-by: Wintermute <wintermute@openclaw.ai> Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
143 lines
5.1 KiB
TypeScript
143 lines
5.1 KiB
TypeScript
import { readFileSync, existsSync } from 'fs';
|
|
import { join, dirname } from 'path';
|
|
import { parse as parseYaml } from './yaml-lite.ts';
|
|
import type { StorageBackend } from './storage.ts';
|
|
|
|
/**
|
|
* Universal file reader with fallback chain:
|
|
* 1. Local file exists → return it
|
|
* 2. .redirect.yaml pointer exists → fetch from storage (v0.9+ format)
|
|
* 3. .redirect breadcrumb exists → fetch from storage (legacy v0.8 format)
|
|
* 4. .supabase marker in parent dir → prefer storage, fall back to local
|
|
* 5. None → throw
|
|
*/
|
|
|
|
export interface ResolvedFile {
|
|
data: Buffer;
|
|
source: 'local' | 'storage' | 'redirect';
|
|
}
|
|
|
|
/** v0.9+ redirect format (.redirect.yaml) — richer metadata */
|
|
export interface RedirectYaml {
|
|
target: string; // supabase://brain-files/{storagePath}
|
|
bucket: string;
|
|
storage_path: string;
|
|
size: number;
|
|
size_human: string;
|
|
hash: string; // sha256:...
|
|
mime: string;
|
|
uploaded: string; // ISO timestamp
|
|
source_url?: string;
|
|
type?: string; // transcript, article, image, etc.
|
|
}
|
|
|
|
/** Legacy v0.8 redirect format (.redirect) */
|
|
export interface RedirectInfo {
|
|
moved_to: string;
|
|
bucket: string;
|
|
path: string;
|
|
moved_at: string;
|
|
original_hash: string;
|
|
}
|
|
|
|
export interface MarkerInfo {
|
|
synced_at: string;
|
|
bucket: string;
|
|
prefix: string;
|
|
file_count: number;
|
|
}
|
|
|
|
export async function resolveFile(
|
|
filePath: string,
|
|
brainRoot: string,
|
|
storage?: StorageBackend,
|
|
): Promise<ResolvedFile> {
|
|
// Validate filePath stays within brainRoot (prevents MCP callers from reading arbitrary files)
|
|
const { resolve: resolvePath } = await import('path');
|
|
const resolvedRoot = resolvePath(brainRoot);
|
|
const resolvedFull = resolvePath(brainRoot, filePath);
|
|
if (!resolvedFull.startsWith(resolvedRoot + '/') && resolvedFull !== resolvedRoot) {
|
|
throw new Error(`Path traversal blocked: ${filePath} resolves outside brain root`);
|
|
}
|
|
|
|
const fullPath = join(brainRoot, filePath);
|
|
|
|
// 1. Local file exists
|
|
if (existsSync(fullPath)) {
|
|
return { data: readFileSync(fullPath), source: 'local' };
|
|
}
|
|
|
|
// 2. .redirect.yaml pointer (v0.9+ format)
|
|
const yamlRedirectPath = fullPath + '.redirect.yaml';
|
|
if (existsSync(yamlRedirectPath)) {
|
|
if (!storage) throw new Error(`File redirected to storage but no storage backend configured: ${filePath}`);
|
|
const info = parseRedirectYaml(yamlRedirectPath);
|
|
const data = await storage.download(info.storage_path);
|
|
return { data, source: 'redirect' };
|
|
}
|
|
|
|
// 3. Legacy .redirect breadcrumb (v0.8 format)
|
|
const legacyRedirectPath = fullPath + '.redirect';
|
|
if (existsSync(legacyRedirectPath)) {
|
|
if (!storage) throw new Error(`File redirected to storage but no storage backend configured: ${filePath}`);
|
|
const info = parseRedirect(legacyRedirectPath);
|
|
const data = await storage.download(info.path);
|
|
return { data, source: 'redirect' };
|
|
}
|
|
|
|
// 4. .supabase marker in parent directory
|
|
const markerPath = join(dirname(fullPath), '.supabase');
|
|
if (existsSync(markerPath)) {
|
|
if (!storage) throw new Error(`Directory mirrored to storage but no storage backend configured: ${filePath}`);
|
|
const marker = parseMarker(markerPath);
|
|
// Validate marker.prefix: reject path traversal, absolute paths, bare '..'
|
|
if (marker.prefix) {
|
|
if (/\.\.[\\/]/.test(marker.prefix) || marker.prefix === '..' || marker.prefix.startsWith('/')) {
|
|
throw new Error(`Blocked: .supabase marker prefix contains path traversal: ${marker.prefix}`);
|
|
}
|
|
}
|
|
const filename = filePath.split('/').pop() || '';
|
|
if (/\.\.[\\/]/.test(filename) || filename === '..' || filename.startsWith('/')) {
|
|
throw new Error(`Blocked: filename contains path traversal: ${filename}`);
|
|
}
|
|
const storagePath = (marker.prefix || '') + filename;
|
|
try {
|
|
const data = await storage.download(storagePath);
|
|
return { data, source: 'storage' };
|
|
} catch {
|
|
// Fall back to local if storage fails and local exists
|
|
if (existsSync(fullPath)) {
|
|
return { data: readFileSync(fullPath), source: 'local' };
|
|
}
|
|
throw new Error(`File not found locally or in storage: ${filePath}`);
|
|
}
|
|
}
|
|
|
|
throw new Error(`File not found: ${filePath}`);
|
|
}
|
|
|
|
/** Parse v0.9+ .redirect.yaml pointer */
|
|
export function parseRedirectYaml(path: string): RedirectYaml {
|
|
const content = readFileSync(path, 'utf-8');
|
|
return parseYaml(content) as unknown as RedirectYaml;
|
|
}
|
|
|
|
/** Parse legacy v0.8 .redirect breadcrumb */
|
|
export function parseRedirect(path: string): RedirectInfo {
|
|
const content = readFileSync(path, 'utf-8');
|
|
return parseYaml(content) as unknown as RedirectInfo;
|
|
}
|
|
|
|
export function parseMarker(path: string): MarkerInfo {
|
|
const content = readFileSync(path, 'utf-8');
|
|
return parseYaml(content) as unknown as MarkerInfo;
|
|
}
|
|
|
|
/** Human-readable file size */
|
|
export function humanSize(bytes: number): string {
|
|
if (bytes < 1024) return `${bytes} B`;
|
|
if (bytes < 1024 * 1024) return `${Math.round(bytes / 1024)} KB`;
|
|
if (bytes < 1024 * 1024 * 1024) return `${Math.round(bytes / (1024 * 1024))} MB`;
|
|
return `${(bytes / (1024 * 1024 * 1024)).toFixed(1)} GB`;
|
|
}
|