fix(qwen): bump majordomo, and stop handing keys to the wrong vendor
Round 6, and one finding exposed something no reviewer mentioned: the majordomo bump this whole PR depends on was never made. Every test here builds the openai client directly, so all of them passed against a majordomo release that had never heard of qwen — a plain "qwen/<model>" in GADFLY_MODELS, the primary way anyone will use this, would not have resolved at all. A compile error caught it, which is luck. TestBuiltinCompatProvidersResolveViaRegistry now exercises that path; the build is what guards the dep itself, since the old release cannot compile the code below. On the endpoint-override path, kimi and qwen fell through to openai.New's OPENAI_API_KEY default whenever GADFLY_API_KEY was unset — sending an OpenAI key to Moonshot or Alibaba. That is a credential handed to the wrong vendor, and it is the exact failure majordomo's built-ins are written to prevent; I reintroduced it one layer up. Both now pass the key unconditionally, so an absent key is a 401 naming GADFLY_API_KEY rather than a foreign credential on the wire. The test job scrubbed the registry credential and left the checkout token in .git/config, readable by the `go test` it then runs — fixing one credential while its neighbour sat in the open. persist-credentials: false; nothing in that job talks to git after checkout. The cross-language wiring test now QUERIES preflight.sh via a new gadfly_preflight_providers function instead of regexing its case statement. Parsing made that file's formatting a contract no linter enforces, where a harmless reformat breaks a test in another language. Two models flagged it. Also: grep for the scrub check takes -e, so a password starting with a hyphen is not read as options; and key_hint stopped repeating key_env in four of five arms. Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
This commit is contained in:
@@ -55,6 +55,12 @@ jobs:
|
||||
timeout-minutes: 15
|
||||
steps:
|
||||
- uses: actions/checkout@v4
|
||||
with:
|
||||
# Scrubbing the registry credential while leaving the checkout token
|
||||
# in .git/config would just move the prize: `go test` below runs
|
||||
# repository code with the workspace readable. Nothing in this job
|
||||
# talks to git after checkout, so the token has no reason to persist.
|
||||
persist-credentials: false
|
||||
- uses: actions/setup-go@v5
|
||||
with:
|
||||
go-version-file: go.mod
|
||||
|
||||
Reference in New Issue
Block a user