-
Notifications
You must be signed in to change notification settings - Fork 1.3k
feat(transport): carry opt-in Antigravity TLS profile onto provider egress #6359
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from all commits
cb6f5a7
9a6fbae
2f18f8f
2b4ca58
3210394
5b048c3
37d8557
3bcf64d
d8bb74b
22e745c
8bf7e61
a3d8874
c163f14
9a49d97
fd0bb60
5bd4466
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,23 @@ | ||
| import type { OcxProviderConfig } from "../types"; | ||
|
|
||
| export const RUNTIME_PROVIDER_FETCH = Symbol("opencodex.provider.runtime-fetch"); | ||
|
|
||
| export interface RuntimeProviderFetch { | ||
| providerName: string; | ||
| origins: readonly string[]; | ||
| fetch: typeof globalThis.fetch; | ||
| } | ||
|
|
||
| /** Return only an explicitly injected executor matching the provider and exact destination origin. */ | ||
| export function runtimeProviderFetch( | ||
| provider: OcxProviderConfig, | ||
| providerName: string | undefined, | ||
| ): typeof globalThis.fetch | undefined { | ||
| const runtime = (provider as OcxProviderConfig & { [RUNTIME_PROVIDER_FETCH]?: RuntimeProviderFetch })[RUNTIME_PROVIDER_FETCH]; | ||
| if (!runtime || runtime.providerName !== providerName) return undefined; | ||
| try { | ||
| return runtime.origins.includes(new URL(provider.baseUrl).origin) ? runtime.fetch : undefined; | ||
| } catch { | ||
| return undefined; | ||
| } | ||
| } |
| Original file line number | Diff line number | Diff line change | ||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| @@ -0,0 +1,221 @@ | ||||||||||||||||||||||||||||||||||||||||
| import type { OcxProviderConfig } from "../types"; | ||||||||||||||||||||||||||||||||||||||||
| import { redactSecretString } from "./redact"; | ||||||||||||||||||||||||||||||||||||||||
| import { runtimeProviderFetch } from "./provider-runtime-fetch"; | ||||||||||||||||||||||||||||||||||||||||
| import { markEgressTransparentExecutor } from "./provider-egress"; | ||||||||||||||||||||||||||||||||||||||||
| import { | ||||||||||||||||||||||||||||||||||||||||
| outboundProxyConfigured, | ||||||||||||||||||||||||||||||||||||||||
| proxyEnvPresent, | ||||||||||||||||||||||||||||||||||||||||
| resolveProxyRoute, | ||||||||||||||||||||||||||||||||||||||||
| socks5ProxyFromEnv, | ||||||||||||||||||||||||||||||||||||||||
| type ProxyEnvMap, | ||||||||||||||||||||||||||||||||||||||||
| } from "./proxy-env"; | ||||||||||||||||||||||||||||||||||||||||
|
|
||||||||||||||||||||||||||||||||||||||||
| export type ProviderTlsProfile = "antigravity-browser"; | ||||||||||||||||||||||||||||||||||||||||
| /** | ||||||||||||||||||||||||||||||||||||||||
| * `pending` means the profile is configured and valid but no request has used it yet; the | ||||||||||||||||||||||||||||||||||||||||
| * dashboard must not report a configured profile as `disabled` before its first send. | ||||||||||||||||||||||||||||||||||||||||
| */ | ||||||||||||||||||||||||||||||||||||||||
| export type ProviderTlsProfileStatus = "disabled" | "pending" | "active" | "failed"; | ||||||||||||||||||||||||||||||||||||||||
| export const ANTIGRAVITY_TLS_HOSTS = new Set([ | ||||||||||||||||||||||||||||||||||||||||
| "daily-cloudcode-pa.googleapis.com", | ||||||||||||||||||||||||||||||||||||||||
| "cloudcode-pa.googleapis.com", | ||||||||||||||||||||||||||||||||||||||||
| ]); | ||||||||||||||||||||||||||||||||||||||||
| type TlsRuntime = { | ||||||||||||||||||||||||||||||||||||||||
| fetch(input: string | URL | Request, init?: RequestInit): Promise<Response>; | ||||||||||||||||||||||||||||||||||||||||
| resolveProxyRoute?: typeof resolveProxyRoute; | ||||||||||||||||||||||||||||||||||||||||
| env?: ProxyEnvMap; | ||||||||||||||||||||||||||||||||||||||||
| }; | ||||||||||||||||||||||||||||||||||||||||
| let status = new Map<string, ProviderTlsProfileStatus>(); | ||||||||||||||||||||||||||||||||||||||||
| let runtime: TlsRuntime | undefined; | ||||||||||||||||||||||||||||||||||||||||
|
|
||||||||||||||||||||||||||||||||||||||||
| export function isCanonicalAntigravityUrl(input: string | URL): boolean { | ||||||||||||||||||||||||||||||||||||||||
| try { | ||||||||||||||||||||||||||||||||||||||||
| const url = new URL(input); | ||||||||||||||||||||||||||||||||||||||||
| return ( | ||||||||||||||||||||||||||||||||||||||||
| url.protocol === "https:" && | ||||||||||||||||||||||||||||||||||||||||
| (url.port === "" || url.port === "443") && | ||||||||||||||||||||||||||||||||||||||||
| !url.username && | ||||||||||||||||||||||||||||||||||||||||
| !url.password && | ||||||||||||||||||||||||||||||||||||||||
| ANTIGRAVITY_TLS_HOSTS.has(url.hostname.toLowerCase()) | ||||||||||||||||||||||||||||||||||||||||
| ); | ||||||||||||||||||||||||||||||||||||||||
| } catch { | ||||||||||||||||||||||||||||||||||||||||
| return false; | ||||||||||||||||||||||||||||||||||||||||
| } | ||||||||||||||||||||||||||||||||||||||||
| } | ||||||||||||||||||||||||||||||||||||||||
|
|
||||||||||||||||||||||||||||||||||||||||
| export function providerTlsProfileConfigError( | ||||||||||||||||||||||||||||||||||||||||
| providerName: string, | ||||||||||||||||||||||||||||||||||||||||
| provider: Pick< | ||||||||||||||||||||||||||||||||||||||||
| OcxProviderConfig, | ||||||||||||||||||||||||||||||||||||||||
| "adapter" | "authMode" | "googleMode" | "baseUrl" | "tlsProfile" | ||||||||||||||||||||||||||||||||||||||||
| >, | ||||||||||||||||||||||||||||||||||||||||
| ): string | null { | ||||||||||||||||||||||||||||||||||||||||
| if (provider.tlsProfile === undefined) return null; | ||||||||||||||||||||||||||||||||||||||||
| if (provider.tlsProfile !== "antigravity-browser") | ||||||||||||||||||||||||||||||||||||||||
| return "tlsProfile must be antigravity-browser"; | ||||||||||||||||||||||||||||||||||||||||
| if ( | ||||||||||||||||||||||||||||||||||||||||
| providerName !== "google-antigravity" || | ||||||||||||||||||||||||||||||||||||||||
| provider.adapter !== "google" || | ||||||||||||||||||||||||||||||||||||||||
| provider.authMode !== "oauth" || | ||||||||||||||||||||||||||||||||||||||||
| provider.googleMode !== "cloud-code-assist" || | ||||||||||||||||||||||||||||||||||||||||
| !isCanonicalAntigravityUrl(provider.baseUrl) | ||||||||||||||||||||||||||||||||||||||||
| ) { | ||||||||||||||||||||||||||||||||||||||||
| return "tlsProfile antigravity-browser requires the canonical Google Antigravity OAuth destination"; | ||||||||||||||||||||||||||||||||||||||||
| } | ||||||||||||||||||||||||||||||||||||||||
| return null; | ||||||||||||||||||||||||||||||||||||||||
| } | ||||||||||||||||||||||||||||||||||||||||
|
|
||||||||||||||||||||||||||||||||||||||||
| export function getProviderTlsProfileStatus( | ||||||||||||||||||||||||||||||||||||||||
| name: string, | ||||||||||||||||||||||||||||||||||||||||
| configured?: boolean, | ||||||||||||||||||||||||||||||||||||||||
| ): ProviderTlsProfileStatus { | ||||||||||||||||||||||||||||||||||||||||
| const recorded = status.get(name); | ||||||||||||||||||||||||||||||||||||||||
| if (configured === undefined) return recorded ?? "disabled"; | ||||||||||||||||||||||||||||||||||||||||
| if (!configured) return "disabled"; | ||||||||||||||||||||||||||||||||||||||||
| return recorded === undefined || recorded === "disabled" ? "pending" : recorded; | ||||||||||||||||||||||||||||||||||||||||
| } | ||||||||||||||||||||||||||||||||||||||||
|
|
||||||||||||||||||||||||||||||||||||||||
| /** The `/api/providers` fragment for a configured profile; empty when the provider has none. */ | ||||||||||||||||||||||||||||||||||||||||
| export function providerTlsProfileDiagnostic( | ||||||||||||||||||||||||||||||||||||||||
| name: string, | ||||||||||||||||||||||||||||||||||||||||
| provider: Pick<OcxProviderConfig, "tlsProfile">, | ||||||||||||||||||||||||||||||||||||||||
| ): { tlsProfile?: { profile: ProviderTlsProfile; status: ProviderTlsProfileStatus } } { | ||||||||||||||||||||||||||||||||||||||||
| if (provider.tlsProfile === undefined) return {}; | ||||||||||||||||||||||||||||||||||||||||
| return { tlsProfile: { profile: provider.tlsProfile, status: getProviderTlsProfileStatus(name, true) } }; | ||||||||||||||||||||||||||||||||||||||||
| } | ||||||||||||||||||||||||||||||||||||||||
|
|
||||||||||||||||||||||||||||||||||||||||
| export function resetProviderTlsProfileForTests(): void { | ||||||||||||||||||||||||||||||||||||||||
| status = new Map(); | ||||||||||||||||||||||||||||||||||||||||
| runtime = undefined; | ||||||||||||||||||||||||||||||||||||||||
| } | ||||||||||||||||||||||||||||||||||||||||
|
|
||||||||||||||||||||||||||||||||||||||||
| export function setProviderTlsRuntimeForTest( | ||||||||||||||||||||||||||||||||||||||||
| next: TlsRuntime | undefined, | ||||||||||||||||||||||||||||||||||||||||
| ): void { | ||||||||||||||||||||||||||||||||||||||||
| runtime = next; | ||||||||||||||||||||||||||||||||||||||||
| } | ||||||||||||||||||||||||||||||||||||||||
|
|
||||||||||||||||||||||||||||||||||||||||
| function preserveTransportError(error: unknown): Error { | ||||||||||||||||||||||||||||||||||||||||
| // A configured proxy URL can carry user:pass@, and the native transport may echo it. The | ||||||||||||||||||||||||||||||||||||||||
| // shared redactor does not mask URL userinfo, so strip it here before the message travels. | ||||||||||||||||||||||||||||||||||||||||
| const message = redactSecretString( | ||||||||||||||||||||||||||||||||||||||||
| error instanceof Error ? error.message : "provider TLS transport failed", | ||||||||||||||||||||||||||||||||||||||||
| ).replace(/\/\/[^/@\s]+@/g, "//<redacted>@"); | ||||||||||||||||||||||||||||||||||||||||
| const name = error instanceof Error ? error.name : "Error"; | ||||||||||||||||||||||||||||||||||||||||
| if (name === "AbortError" || name === "TimeoutError") | ||||||||||||||||||||||||||||||||||||||||
| return new DOMException(message, name); | ||||||||||||||||||||||||||||||||||||||||
| const wrapped = new Error(message); | ||||||||||||||||||||||||||||||||||||||||
| wrapped.name = name; | ||||||||||||||||||||||||||||||||||||||||
| return wrapped; | ||||||||||||||||||||||||||||||||||||||||
| } | ||||||||||||||||||||||||||||||||||||||||
|
|
||||||||||||||||||||||||||||||||||||||||
| /** Proxy schemes the native TLS transport can carry for a route decided elsewhere. */ | ||||||||||||||||||||||||||||||||||||||||
| const TLS_PROXY_PROTOCOLS = new Set(["http:", "https:", "socks5:", "socks5h:"]); | ||||||||||||||||||||||||||||||||||||||||
|
|
||||||||||||||||||||||||||||||||||||||||
| function requireDirect(env: ProxyEnvMap): Record<string, never> { | ||||||||||||||||||||||||||||||||||||||||
| // The native transport reads HTTP_PROXY/HTTPS_PROXY/ALL_PROXY itself whenever no proxy option | ||||||||||||||||||||||||||||||||||||||||
| // is given, and it has no per-request "direct" switch. A direct route is therefore only | ||||||||||||||||||||||||||||||||||||||||
| // honoured when no proxy variable exists at all; otherwise omitting the option would send the | ||||||||||||||||||||||||||||||||||||||||
| // credential through the environment proxy the operator routed this request away from. | ||||||||||||||||||||||||||||||||||||||||
| if (outboundProxyConfigured(env)) { | ||||||||||||||||||||||||||||||||||||||||
| throw new Error("provider TLS profile cannot force a direct connection while a proxy environment variable is set"); | ||||||||||||||||||||||||||||||||||||||||
| } | ||||||||||||||||||||||||||||||||||||||||
| return {}; | ||||||||||||||||||||||||||||||||||||||||
| } | ||||||||||||||||||||||||||||||||||||||||
|
|
||||||||||||||||||||||||||||||||||||||||
| /** | ||||||||||||||||||||||||||||||||||||||||
| * The proxy option expressing this send's route on the native transport, or a refusal. | ||||||||||||||||||||||||||||||||||||||||
| * | ||||||||||||||||||||||||||||||||||||||||
| * `sendWithConnectionPolicy` resolves the per-provider egress (`providers.<name>.proxy` / | ||||||||||||||||||||||||||||||||||||||||
| * `noProxy`) and passes it as `init.proxy`: a URL, `false` for direct, or absent when the | ||||||||||||||||||||||||||||||||||||||||
| * provider inherits the global environment route. | ||||||||||||||||||||||||||||||||||||||||
| */ | ||||||||||||||||||||||||||||||||||||||||
| function tlsProxyOption(init: RequestInit | undefined, destination: string | URL): { proxy?: string } { | ||||||||||||||||||||||||||||||||||||||||
| const env = runtime?.env ?? process.env; | ||||||||||||||||||||||||||||||||||||||||
| const decided = init !== undefined && Object.hasOwn(init, "proxy") | ||||||||||||||||||||||||||||||||||||||||
| ? (init as RequestInit & { proxy?: unknown }).proxy | ||||||||||||||||||||||||||||||||||||||||
| : undefined; | ||||||||||||||||||||||||||||||||||||||||
| if (typeof decided === "string") { | ||||||||||||||||||||||||||||||||||||||||
| let protocol: string; | ||||||||||||||||||||||||||||||||||||||||
| try { | ||||||||||||||||||||||||||||||||||||||||
| protocol = new URL(decided).protocol; | ||||||||||||||||||||||||||||||||||||||||
| } catch { | ||||||||||||||||||||||||||||||||||||||||
| throw new Error("provider TLS profile cannot preserve configured proxy semantics"); | ||||||||||||||||||||||||||||||||||||||||
| } | ||||||||||||||||||||||||||||||||||||||||
| if (!TLS_PROXY_PROTOCOLS.has(protocol)) { | ||||||||||||||||||||||||||||||||||||||||
| throw new Error("provider TLS profile cannot preserve configured proxy semantics"); | ||||||||||||||||||||||||||||||||||||||||
| } | ||||||||||||||||||||||||||||||||||||||||
| return { proxy: decided }; | ||||||||||||||||||||||||||||||||||||||||
| } | ||||||||||||||||||||||||||||||||||||||||
| if (decided === false) return requireDirect(env); | ||||||||||||||||||||||||||||||||||||||||
| const route = (runtime?.resolveProxyRoute ?? resolveProxyRoute)(new URL(destination), env); | ||||||||||||||||||||||||||||||||||||||||
| if (route.kind === "fallback") { | ||||||||||||||||||||||||||||||||||||||||
| // `resolveProxyRoute` only classifies HTTP(S) proxies; an inherited ALL_PROXY of socks5:// | ||||||||||||||||||||||||||||||||||||||||
| // or socks5h:// is the route the ordinary outbound path takes through socks5ProxyFromEnv(). | ||||||||||||||||||||||||||||||||||||||||
| // Carry that same route when no HTTPS-specific variable outranks it, instead of refusing | ||||||||||||||||||||||||||||||||||||||||
| // every Antigravity send for an operator whose only global proxy is SOCKS. | ||||||||||||||||||||||||||||||||||||||||
| const socks = proxyEnvPresent("HTTPS_PROXY", env) ? undefined : socks5ProxyFromEnv(env); | ||||||||||||||||||||||||||||||||||||||||
| if (socks) return { proxy: socks.trim() }; | ||||||||||||||||||||||||||||||||||||||||
| throw new Error("provider TLS profile cannot preserve configured proxy semantics"); | ||||||||||||||||||||||||||||||||||||||||
|
lidge-jun marked this conversation as resolved.
|
||||||||||||||||||||||||||||||||||||||||
| } | ||||||||||||||||||||||||||||||||||||||||
| if (route.kind === "proxy") return { proxy: route.proxy }; | ||||||||||||||||||||||||||||||||||||||||
| return requireDirect(env); | ||||||||||||||||||||||||||||||||||||||||
| } | ||||||||||||||||||||||||||||||||||||||||
|
|
||||||||||||||||||||||||||||||||||||||||
| export function providerTlsFetch( | ||||||||||||||||||||||||||||||||||||||||
| name: string, | ||||||||||||||||||||||||||||||||||||||||
| provider: Pick< | ||||||||||||||||||||||||||||||||||||||||
| OcxProviderConfig, | ||||||||||||||||||||||||||||||||||||||||
| "adapter" | "authMode" | "googleMode" | "baseUrl" | "tlsProfile" | ||||||||||||||||||||||||||||||||||||||||
| >, | ||||||||||||||||||||||||||||||||||||||||
| fallback: typeof globalThis.fetch, | ||||||||||||||||||||||||||||||||||||||||
| ): typeof globalThis.fetch { | ||||||||||||||||||||||||||||||||||||||||
| if (provider.tlsProfile === undefined) { | ||||||||||||||||||||||||||||||||||||||||
| status.set(name, "disabled"); | ||||||||||||||||||||||||||||||||||||||||
| return fallback; | ||||||||||||||||||||||||||||||||||||||||
| } | ||||||||||||||||||||||||||||||||||||||||
| if (providerTlsProfileConfigError(name, provider)) { | ||||||||||||||||||||||||||||||||||||||||
| status.set(name, "failed"); | ||||||||||||||||||||||||||||||||||||||||
| return (async () => { | ||||||||||||||||||||||||||||||||||||||||
| throw new Error("invalid provider TLS profile"); | ||||||||||||||||||||||||||||||||||||||||
| }) as unknown as typeof globalThis.fetch; | ||||||||||||||||||||||||||||||||||||||||
| } | ||||||||||||||||||||||||||||||||||||||||
| // Transparent to provider egress: the route decided at the physical send arrives as | ||||||||||||||||||||||||||||||||||||||||
| // `init.proxy` and is either carried by the native transport or refused below. | ||||||||||||||||||||||||||||||||||||||||
| return markEgressTransparentExecutor((async (input, init) => { | ||||||||||||||||||||||||||||||||||||||||
| const destination = | ||||||||||||||||||||||||||||||||||||||||
| typeof input === "string" || input instanceof URL ? input : input.url; | ||||||||||||||||||||||||||||||||||||||||
| if (!isCanonicalAntigravityUrl(destination)) { | ||||||||||||||||||||||||||||||||||||||||
| status.set(name, "failed"); | ||||||||||||||||||||||||||||||||||||||||
| throw new Error("provider TLS profile refused noncanonical destination"); | ||||||||||||||||||||||||||||||||||||||||
| } | ||||||||||||||||||||||||||||||||||||||||
| try { | ||||||||||||||||||||||||||||||||||||||||
| const configured = runtimeProviderFetch( | ||||||||||||||||||||||||||||||||||||||||
| provider as OcxProviderConfig, | ||||||||||||||||||||||||||||||||||||||||
| name, | ||||||||||||||||||||||||||||||||||||||||
| ); | ||||||||||||||||||||||||||||||||||||||||
| const proxyOption = tlsProxyOption(init, destination); | ||||||||||||||||||||||||||||||||||||||||
| const mod = | ||||||||||||||||||||||||||||||||||||||||
| configured === undefined | ||||||||||||||||||||||||||||||||||||||||
| ? runtime ?? ((await import("wreq-js")) as unknown as TlsRuntime) | ||||||||||||||||||||||||||||||||||||||||
| : undefined; | ||||||||||||||||||||||||||||||||||||||||
| const { proxy: _decidedRoute, ...rest } = (init ?? {}) as RequestInit & { proxy?: unknown }; | ||||||||||||||||||||||||||||||||||||||||
| const response = await (configured ?? mod!.fetch)(input, { | ||||||||||||||||||||||||||||||||||||||||
| ...rest, | ||||||||||||||||||||||||||||||||||||||||
| redirect: "manual", | ||||||||||||||||||||||||||||||||||||||||
| browser: "chrome_142", | ||||||||||||||||||||||||||||||||||||||||
| os: "windows", | ||||||||||||||||||||||||||||||||||||||||
| ...proxyOption, | ||||||||||||||||||||||||||||||||||||||||
| } as RequestInit & { browser: string; os: string }); | ||||||||||||||||||||||||||||||||||||||||
| status.set(name, "active"); | ||||||||||||||||||||||||||||||||||||||||
| return response; | ||||||||||||||||||||||||||||||||||||||||
| } catch (error) { | ||||||||||||||||||||||||||||||||||||||||
| if (init?.signal?.aborted && error === init.signal.reason) { | ||||||||||||||||||||||||||||||||||||||||
| // A caller cancellation says nothing about the profile's health. | ||||||||||||||||||||||||||||||||||||||||
| throw error; | ||||||||||||||||||||||||||||||||||||||||
| } | ||||||||||||||||||||||||||||||||||||||||
| status.set(name, "failed"); | ||||||||||||||||||||||||||||||||||||||||
| throw preserveTransportError(error); | ||||||||||||||||||||||||||||||||||||||||
|
Comment on lines
+212
to
+218
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🎯 Functional Correctness | 🟡 Minor | ⚡ Quick win 🔎 Supported by static analysis🏁 Script executed: sed -n '1,245p' src/lib/provider-tls-profile.ts
rg -n 'wreq-js|signal.reason|AbortError' src/lib tests/providers/provider-tls-profile.test.ts package.jsonRepository: lidge-jun/opencodex Length of output: 12070 🏁 Script executed: set -eu
printf '%s\n' '--- candidate files ---'
git ls-files | rg '(^|/)(provider-runtime-fetch|provider-tls-profile|package-lock|bun.lock|npm-shrinkwrap|pnpm-lock|wreq-js|native|transport|provider).*'
printf '%s\n' '--- provider runtime adapter ---'
rg -n -C 8 'runtimeProviderFetch|setProviderTlsRuntimeForTest|providerTlsFetch|wreq-js|fetch\(input|signal' src tests package.json bun.lock* package-lock.json 2>/dev/null || true
printf '%s\n' '--- package metadata and lock entry ---'
sed -n '70,105p' package.json
rg -n -C 12 '"wreq-js"|wreq-js@|wreq' bun.lock* package-lock.json pnpm-lock.yaml yarn.lock 2>/dev/null || true
printf '%s\n' '--- test file relevant sections ---'
sed -n '130,225p' tests/providers/provider-tls-profile.test.ts
printf '%s\n' '--- local package/cache candidates ---'
find . -path './node_modules' -prune -o -iname '*wreq*' -print
find /tmp /root/.bun /root/.npm -iname '*wreq*' -print 2>/dev/null | head -80Repository: lidge-jun/opencodex Length of output: 45674 🏁 Script executed: set -eu
printf '%s\n' '--- provider-runtime-fetch.ts ---'
cat -n src/lib/provider-runtime-fetch.ts
printf '%s\n' '--- focused providerTlsFetch callers ---'
rg -n -C 10 'providerTlsFetch|runtimeProviderFetch|setProviderTlsRuntimeForTest' src tests/providers/provider-tls-profile.test.ts --glob '*.ts'
printf '%s\n' '--- wreq lock context ---'
sed -n '1,35p' bun.lock
sed -n '306,320p' bun.lock
printf '%s\n' '--- local package manifests/caches ---'
find . -path './node_modules' -prune -o -type f \\( -name 'package.json' -o -name '*.d.ts' -o -name '*.js' -o -name '*.ts' \\) -print | rg 'wreq|provider-runtime' || true
find /root/.bun /root/.npm /tmp -type f -iname '*wreq*' -print 2>/dev/null | head -100 || trueRepository: lidge-jun/opencodex Length of output: 41749 🌐 Web query:
💡 Result: 🏁 Script executed: set -eu
printf '%s\n' '--- provider-runtime-fetch.ts ---'
cat -n src/lib/provider-runtime-fetch.ts
printf '%s\n' '--- focused providerTlsFetch callers ---'
rg -n -C 10 'providerTlsFetch|runtimeProviderFetch|setProviderTlsRuntimeForTest' src tests/providers/provider-tls-profile.test.ts --glob '*.ts'
printf '%s\n' '--- wreq lock context ---'
sed -n '1,35p' bun.lock
sed -n '306,320p' bun.lock
printf '%s\n' '--- local package manifests/caches ---'
find . -path './node_modules' -prune -o -type f \( -name 'package.json' -o -name '*.d.ts' -o -name '*.js' -o -name '*.ts' \) -print | rg 'wreq|provider-runtime' || true
find /root/.bun /root/.npm /tmp -type f -iname '*wreq*' -print 2>/dev/null | head -100 || trueRepository: lidge-jun/opencodex Length of output: 41764 🏁 Script executed: set -eu
python3 - <<'PY'
import json, urllib.request, tarfile, io, re
def get(url):
req = urllib.request.Request(url, headers={"User-Agent": "repository-inspection"})
with urllib.request.urlopen(req, timeout=20) as r:
return r.read()
repo = "https://api.github.com/repos/sqdshguy/wreq-js"
try:
commit = json.loads(get(repo + "/commits/57db58a"))
print("--- release commit ---")
print(commit.get("sha"), commit.get("commit", {}).get("message", "").splitlines()[0])
tree_sha = commit.get("commit", {}).get("tree", {}).get("sha")
tree = json.loads(get(repo + "/git/trees/" + tree_sha + "?recursive=1"))
paths = [x["path"] for x in tree.get("tree", []) if re.search(r"(abort|fetch|request|signal|transport)", x["path"], re.I)]
print("--- relevant release paths ---")
print("\n".join(paths[:200]))
for path in paths:
if path.endswith((".rs", ".ts", ".js", ".md")):
raw = "https://raw.githubusercontent.com/sqdshguy/wreq-js/57db58a/" + path
try:
text = get(raw).decode("utf-8", "replace")
except Exception:
continue
hits = [(i + 1, line) for i, line in enumerate(text.splitlines())
if re.search(r"(abort|signal|reason|cancel|DOMException|AbortError)", line, re.I)]
if hits:
print(f"--- {path} ---")
for n, line in hits[:120]:
print(f"{n}:{line}")
except Exception as e:
print("github inspection error:", repr(e))
print("--- npm package metadata and files ---")
try:
meta = json.loads(get("https://registry.npmjs.org/wreq-js/2.3.1"))
print("dist.tarball:", meta.get("dist", {}).get("tarball"))
data = get(meta["dist"]["tarball"])
with tarfile.open(fileobj=io.BytesIO(data), mode="r:gz") as tf:
names = [m.name for m in tf.getmembers() if m.isfile()]
print("\n".join(names[:200]))
for m in tf.getmembers():
if not m.isfile() or not m.name.endswith((".js", ".ts", ".d.ts", ".md", ".json")):
continue
raw = tf.extractfile(m).read().decode("utf-8", "replace")
hits = [(i + 1, line) for i, line in enumerate(raw.splitlines())
if re.search(r"(abort|signal|reason|cancel|DOMException|AbortError)", line, re.I)]
if hits:
print(f"--- {m.name} ---")
for n, line in hits[:120]:
print(f"{n}:{line}")
except Exception as e:
print("npm inspection error:", repr(e))
PYRepository: lidge-jun/opencodex Length of output: 563 🏁 Script executed: set -eu
tmp=$(mktemp)
trap 'rm -f "$tmp"' EXIT
printf '%s\n' '--- GitHub release commit tree ---'
curl -kfsSL -A repository-inspection https://api.github.com/repos/sqdshguy/wreq-js/commits/57db58a > "$tmp"
python3 - "$tmp" <<'PY'
import json, sys
d=json.load(open(sys.argv[1]))
print("commit:", d.get("sha"))
print("message:", d.get("commit",{}).get("message","").splitlines()[0])
print("tree:", d.get("commit",{}).get("tree",{}).get("sha"))
PY
tree=$(python3 - "$tmp" <<'PY'
import json, sys
print(json.load(open(sys.argv[1]))["commit"]["tree"]["sha"])
PY
)
curl -kfsSL -A repository-inspection "https://api.github.com/repos/sqdshguy/wreq-js/git/trees/$tree?recursive=1" |
python3 -c 'import json,sys,re; d=json.load(sys.stdin); print("\n".join(x["path"] for x in d.get("tree",[]) if re.search(r"(abort|fetch|request|signal|transport)",x["path"],re.I)))'
printf '%s\n' '--- GitHub source hits ---'
for path in $(curl -kfsSL -A repository-inspection "https://api.github.com/repos/sqdshguy/wreq-js/git/trees/$tree?recursive=1" | python3 -c 'import json,sys,re; d=json.load(sys.stdin); print("\n".join(x["path"] for x in d.get("tree",[]) if x["path"].endswith((".rs",".ts",".js",".md")) and re.search(r"(abort|fetch|request|signal|transport)",x["path"],re.I)))'); do
body=$(curl -kfsSL -A repository-inspection "https://raw.githubusercontent.com/sqdshguy/wreq-js/57db58a/$path" || true)
hits=$(printf '%s\n' "$body" | rg -n -i 'abort|signal|reason|cancel|DOMException|AbortError' || true)
if [ -n "$hits" ]; then
printf '%s\n' "--- $path ---"
printf '%s\n' "$hits" | head -120
fi
done
printf '%s\n' '--- npm package metadata and JS/TS declarations ---'
curl -kfsSL -A repository-inspection https://registry.npmjs.org/wreq-js/2.3.1 |
python3 -c 'import json,sys; print(json.load(sys.stdin)["dist"]["tarball"])'
tarball=$(curl -kfsSL -A repository-inspection https://registry.npmjs.org/wreq-js/2.3.1 | python3 -c 'import json,sys; print(json.load(sys.stdin)["dist"]["tarball"])')
curl -kfsSL "$tarball" | tar -tzf - | head -200Repository: lidge-jun/opencodex Length of output: 1950 🏁 Script executed: set -eu
base=https://raw.githubusercontent.com/sqdshguy/wreq-js/57db58a
printf '%s\n' '--- cancellation test context ---'
curl -kfsSL "$base/src/test/http/requests.spec.ts" | sed -n '280,325p'
printf '%s\n' '--- fetch API documentation cancellation references ---'
curl -kfsSL "$base/docs/api-reference/fetch.mdx" | rg -n -C 8 -i 'signal|abort|reason|cancel|error'
printf '%s\n' '--- source tree paths ---'
curl -kfsSL -A repository-inspection 'https://api.github.com/repos/sqdshguy/wreq-js/git/trees/820d0342afd86dba2448933342071d1b14f6a9cb?recursive=1' |
python3 -c 'import json,sys; d=json.load(sys.stdin); print("\n".join(x["path"] for x in d.get("tree",[]) if x["path"].startswith("src/") or x["path"].startswith("crates/") or x["path"].startswith("native/")))'Repository: lidge-jun/opencodex Length of output: 5094 🏁 Script executed: set -eu
base=https://raw.githubusercontent.com/sqdshguy/wreq-js/57db58a
printf '%s\n' '--- wreq-js wrapper ---'
curl -kfsSL "$base/src/wreq-js.ts" | cat -n | sed -n '1,260p'
printf '%s\n' '--- generated types signal/error declarations ---'
curl -kfsSL "$base/src/generated-types.ts" | rg -n -C 5 -i 'AbortSignal|signal|AbortError|reason|error'
printf '%s\n' '--- native require wrapper references ---'
for f in src/native-require.ts src/native-require-cjs.ts; do
printf '%s\n' "--- $f ---"
curl -kfsSL "$base/$f" | cat -n | sed -n '1,220p'
doneRepository: lidge-jun/opencodex Length of output: 9834 🏁 Script executed: set -eu
curl -kfsSL https://raw.githubusercontent.com/sqdshguy/wreq-js/57db58a/src/wreq-js.ts |
rg -n -C 18 -i 'signal|cancelRequest|enableCancellation|AbortError|reason|catch \(.*error|RequestError'Repository: lidge-jun/opencodex Length of output: 42190 Recognize normalized abort errors without suppressing unrelated failures.
Do not skip the status update for every rejection after signal abortion. A separate transport or routing failure can race with cancellation. Match the normalized Suggested fix } catch (error) {
- if (init?.signal?.aborted && error === init.signal.reason) {
+ if (
+ init?.signal?.aborted &&
+ (error === init.signal.reason ||
+ (error instanceof Error && error.name === "AbortError"))
+ ) {
// A caller cancellation says nothing about the profile's health.
- throw error;
+ if (error === init.signal.reason) throw error;
+ throw preserveTransportError(error);
}
status.set(name, "failed");
throw preserveTransportError(error);Add a regression test for a distinct 📝 Committable suggestion
Suggested change
🤖 Prompt for AI Agents |
||||||||||||||||||||||||||||||||||||||||
| } | ||||||||||||||||||||||||||||||||||||||||
| }) as typeof globalThis.fetch); | ||||||||||||||||||||||||||||||||||||||||
| } | ||||||||||||||||||||||||||||||||||||||||
Uh oh!
There was an error while loading. Please reload this page.