- Restricted the reasoning-wrapper removal to leading <think> blocks so a
literal think tag after real content is preserved instead of deleted.
- Added coverage asserting mid-content think tags survive cleanOutput.
Fixes#7231
- Removed MiniMax-style think wrappers in cleanOutput so reasoning-model
responses no longer leak into consolidation summaries or corrupt fact
extraction (the wrapper previously survived parsing and every stored fact
became reasoning prose).
- Added remote consolidation and remote extraction regression coverage.
Fixes#7231
Six suites build a real DB under a temp dir and then `rmSync` it in
`afterEach`. Each leaked its own one-shot statement the same way the source
did, so the teardown hit EBUSY on Windows and failed tests whose assertions
had already passed.
Only the suites that touch a file-backed DB are changed. The remaining
`prepare()` calls in the package tests run against `:memory:`, where there
is nothing to unlink and no cleanup to fail.
Every `db.prepare(...)` in the package was a one-shot: prepared, stepped
once via run/get/all, then dropped without `finalize()`. There were 65 such
sites and no `finalize()` call anywhere. An unfinalized statement keeps the
SQLite connection alive, so `BeamMemory.close()` -> `closeQuietly(db)` ->
`db.close()` never released the file. `closeQuietly` swallows the error;
calling `db.close(true)` instead surfaces "database is locked".
One-shot writes now go through `db.run(sql, params)`, which prepares and
finalizes internally. Statements that are read from, or reused across a
loop, are bound with `using` so they are finalized when they leave scope.
On Windows the effect is user-visible beyond tests: the memory DB and its
`-wal`/`-shm` sidecars stay locked after mnemopi closes them, so the file
cannot be deleted, moved, or rotated. On POSIX the leak is silent because
open files can be unlinked.
The new suite pins both halves: that `db.close(true)` does not throw after
the store paths run, and that a closed bank leaves no `-wal`/`-shm` behind
and can be deleted. All three cases fail on the unfixed sources.
Same class as 14252e71c and #6762, neither of which covered this package.
- An eval-worktree cherry-pick swept 16 packages/*/node_modules symlinks into the index; 'node_modules/' with a trailing slash only matches directories, so symlinked installs bypassed the ignore. Dropped the slash and removed the tracked links.
Aligns the shim's runtime safeParse/__validator with the wire/tool-call
path, so legacy draft-07 documents (tuple items) accept the same values
validateToolArguments does. Adds a regression test.
Swap the batch-shaped scoring loops to the pi-natives kernels behind the
existing TS function signatures, so every caller keeps its guards and
observable behavior: mmrRerank (default Jaccard path), searchExactVectorIndex,
clusterBySimilarity, BinaryVectorStore.search, and FastBinarySearch.search.
cosine_similarity_pairs now takes Float64Array so f64 vectors round-trip
without f32 narrowing. Scalar one-off call sites stay in TS (query-cache
cosine probe, shmr centroid/confidence loops, recall per-row cosine map,
custom-similarity mmrRerank). Adds a seeded parity suite: 1e-9 relative
tolerance for floats, exact equality for Hamming distances and pair lists,
identical MMR index sequences across lambda/topK grids.
Review follow-ups:
- The corruption retry now goes THROUGH the sidecar heal, so a cache
broken in both ways (truncated model blob AND stale/missing
config/tokenizer sidecars) recovers in one pass instead of the retry
escaping with a sidecar error.
- defaultLocalModelInitializer is exported from core as the shared
initializer and the coding-agent embed worker now uses it instead of
calling FlagEmbedding.init directly, so omp's subprocess embeddings
inherit both heals; fastembed/onnxruntime still load only in the
child address space.
defaultLocalModelInitializer (exported @internal for tests; production
seam stays setLocalModelInitializer) now provably retries
FlagEmbedding.init EXACTLY once after a Protobuf-corruption failure,
quarantining the cached file in between, and surfaces the error without
looping when the retry fails too. The heal callsite now passes
options.cacheDir so containment checks the caller's cache root, not
only the global default.
A truncated model_optimized.onnx (observed live: 5.7MB file from June,
'Protobuf parsing failed' on every load) blocks local embeddings
forever: the downloader treats the existing file as complete, so every
init re-parses the same broken bytes and local recall/retain loses its
embedder. defaultLocalModelInitializer now quarantines the exact file
named by the loader (atomic rename to *.corrupt-<ts>) and retries init
ONCE so the model re-downloads.
The extracted path is error-message content: it is honored only when
it resolves inside the fastembed cache directory, so a dependency
emitting an unexpected message can never rename an arbitrary file.
Contract tests: protobuf failure quarantines exactly the named cache
file and reports retry-safe; unrelated errors touch nothing; a missing
file (concurrent heal) stays retry-safe; a path outside the cache root
is refused untouched.