fix: address ds-review-bot v6/v7 findings on the image-input assembly

- resolveLlmRoute: reuse the yml pi-ai row for providers it already routes
  (DUPLICATE_ADAPTER boot failure) and detect an unset model by origin, not
  by comparison against one deployment default; covered by a new spec.
- LlmService.resolveModelInfoFor preserves (and validates) modality
  metadata, arming the host image preflight for exact-route resolution.
- session.selectModel refuses a text-only target once the session log
  carries an image on any replayed route; an accepted switch would strand
  every later turn with no in-product recovery.
- The composer no longer gates image intake on the handshake activeModel
  snapshot (wrong authority for a per-session decision); the host preflight
  plus the error strip own capability, deployment limits stay client-side.
- InputHub shell teardown releases the scope's draft images (File objects
  and object URLs leaked for the page lifetime).
- session.prompt image parts carry optional alt into the durable block;
  ImageBlock documents assistant-side rendering as forward compatibility.
- Assembled built-client lane apps/web/tests/image-display.snapshot.ts pins
  the history galleries over the authorized attachment route, the lightbox,
  and the composer paste rail; the attachment rail is an accessible group.
- Docs: validateImage on the seam page, fixture byte metadata matches its
  PNG, and the Agent Note claims now match the shipped coverage.
This commit is contained in:
creatixchu
2026-07-29 18:56:40 +08:00
parent 22e48c1953
commit adce3b833d
21 changed files with 526 additions and 36 deletions

View File

@@ -61,6 +61,61 @@ export function resolveLanTrust(
return { lanAddresses, trustedHosts: [...lanAddresses, ...extra] }
}
/** One provider/model source layer for {@link resolveLlmRoute}, in override order. */
export interface LlmRouteInput {
/** CLI flag values (highest precedence). */
cli: { provider?: string | undefined; model?: string | undefined }
/** Profile-json values (parsed JSON — validated here, the config boundary). */
profile: { provider?: unknown; model?: unknown }
/** The api-gateway yml row's config values (deployment defaults). */
gateway: { provider?: unknown; model?: unknown }
/** Providers the shipped yml already routes through its static pi-ai row. */
ymlPiAiProviders: readonly string[]
}
/** The boot's resolved LLM routing decision. */
export interface LlmRoute {
/** Effective api-gateway provider. */
provider: string
/** Pi-ai provider to mount dynamically; undefined when DeepSeek or a yml-routed provider serves the request. */
dynamicPiAiProvider: string | undefined
}
/**
* Resolve the boot's LLM route from the layered provider/model sources.
* A non-DeepSeek provider requires a model set at least as explicitly as the
* provider itself (flag/profile) — origin decides, never a comparison against
* any deployment's default model value, so editing the yml default cannot
* silently disarm the guard. Providers the shipped yml pi-ai row already
* routes are NOT mounted again: `LlmService.registerAdapter` rejects
* duplicate routes, so the gateway provider/model patch alone selects them.
* @param input - the layered provider/model sources and the yml pi-ai roster.
* @returns the effective provider and the dynamic pi-ai mount decision.
*/
export function resolveLlmRoute(input: LlmRouteInput): LlmRoute {
const provider = input.cli.provider ?? input.profile.provider ?? input.gateway.provider
if (typeof provider !== 'string' || provider === '') {
throw new Error('dsh: api-gateway provider must be a non-empty string')
}
if (provider !== 'deepseek') {
const providerFromYml = input.cli.provider === undefined && input.profile.provider === undefined
// A yml-set provider trusts its own row pairing; an override must bring
// its model along instead of inheriting the yml default's.
const model = providerFromYml
? input.gateway.model
: input.cli.model ?? input.profile.model
if (typeof model !== 'string' || model === '') {
throw new Error(`dsh: provider ${provider} requires an explicit model`)
}
}
return {
provider,
dynamicPiAiProvider: provider === 'deepseek' || input.ymlPiAiProviders.includes(provider)
? undefined
: provider,
}
}
/** One profile-json key mapped onto a yml row's config field. */
interface ProfileMapping {
jsonPath: string
@@ -207,15 +262,16 @@ export class AppCLIEntry {
if (this.options.model !== undefined) put('api-gateway', 'model', this.options.model)
const gatewayConfig = rows.get('api-gateway')?.config as Record<string, unknown> | undefined
const provider = this.options.provider ?? profile.provider ?? gatewayConfig?.provider
const model = this.options.model ?? profile.model ?? gatewayConfig?.model
if (typeof provider !== 'string' || provider === '') {
throw new Error('dsh: api-gateway provider must be a non-empty string')
}
if (provider !== 'deepseek' && (typeof model !== 'string' || model === '' || model === 'deepseek-v4-flash')) {
throw new Error(`dsh: provider ${provider} requires an explicit model`)
}
this.piAiProvider = provider === 'deepseek' ? undefined : provider
const piAiRow = rows.get('llm-pi-ai')?.config as { providers?: { provider?: unknown }[] } | undefined
const route = resolveLlmRoute({
cli: { provider: this.options.provider, model: this.options.model },
profile: { provider: profile.provider, model: profile.model },
gateway: { provider: gatewayConfig?.provider, model: gatewayConfig?.model },
ymlPiAiProviders: (piAiRow?.providers ?? [])
.map(p => p.provider)
.filter((value): value is string => typeof value === 'string'),
})
this.piAiProvider = route.dynamicPiAiProvider
// Source 2b: authorities for the /api browser-trust fence (rationale on
// resolveLanTrust).

View File

@@ -0,0 +1,61 @@
/** resolveLlmRoute: layered provider/model resolution and the dynamic pi-ai mount decision. */
import { describe, expect, it } from 'vitest'
import { resolveLlmRoute } from '../src/app-cli-entry.ts'
/** The shipped yml shape: DeepSeek gateway default plus a pi-ai row routing openai/anthropic. */
const SHIPPED = {
gateway: { provider: 'deepseek', model: 'deepseek-v4-flash' },
ymlPiAiProviders: ['openai', 'anthropic'],
}
describe('resolveLlmRoute', () => {
it('keeps the DeepSeek default without any dynamic mount', () => {
expect(resolveLlmRoute({ cli: {}, profile: {}, ...SHIPPED }))
.toEqual({ provider: 'deepseek', dynamicPiAiProvider: undefined })
})
it('reuses the yml pi-ai row for providers it already routes (no duplicate adapter)', () => {
expect(resolveLlmRoute({
cli: { provider: 'anthropic', model: 'claude-opus-4-8' }, profile: {}, ...SHIPPED,
})).toEqual({ provider: 'anthropic', dynamicPiAiProvider: undefined })
})
it('mounts pi-ai dynamically only for providers absent from the yml row', () => {
expect(resolveLlmRoute({
cli: { provider: 'google', model: 'gemini-3-pro' }, profile: {}, ...SHIPPED,
})).toEqual({ provider: 'google', dynamicPiAiProvider: 'google' })
})
it('requires an explicit model wherever the provider override came from, by origin', () => {
// CLI provider with no CLI/profile model: the yml DeepSeek default must not leak in.
expect(() => resolveLlmRoute({ cli: { provider: 'anthropic' }, profile: {}, ...SHIPPED }))
.toThrow(/provider anthropic requires an explicit model/)
// Profile provider paired with a profile model is explicit enough.
expect(resolveLlmRoute({
cli: {}, profile: { provider: 'openai', model: 'gpt-5' }, ...SHIPPED,
})).toEqual({ provider: 'openai', dynamicPiAiProvider: undefined })
// Profile provider with only the yml default model: same gap, same refusal.
expect(() => resolveLlmRoute({ cli: {}, profile: { provider: 'openai' }, ...SHIPPED }))
.toThrow(/provider openai requires an explicit model/)
})
it('trusts a yml-set non-DeepSeek provider only when its own row carries the model', () => {
expect(resolveLlmRoute({
cli: {}, profile: {},
gateway: { provider: 'anthropic', model: 'claude-opus-4-8' },
ymlPiAiProviders: ['openai', 'anthropic'],
})).toEqual({ provider: 'anthropic', dynamicPiAiProvider: undefined })
expect(() => resolveLlmRoute({
cli: {}, profile: {},
gateway: { provider: 'anthropic' },
ymlPiAiProviders: ['openai', 'anthropic'],
})).toThrow(/provider anthropic requires an explicit model/)
})
it('fails loud on a missing or empty provider', () => {
expect(() => resolveLlmRoute({ cli: {}, profile: {}, gateway: {}, ymlPiAiProviders: [] }))
.toThrow(/provider must be a non-empty string/)
expect(() => resolveLlmRoute({ cli: { provider: '' }, profile: {}, ...SHIPPED }))
.toThrow(/provider must be a non-empty string/)
})
})