Skip to content

fix(providers): resolve keyring:// keys for custom providers (v3.3.0) - #5

Merged
dirtysouthalpha merged 1 commit into
mainfrom
fix/keyring-env-fallback
Aug 5, 2026
Merged

dirtysouthalpha merged 1 commit into
mainfrom
fix/keyring-env-fallback

Conversation

@dirtysouthalpha

Copy link
Copy Markdown
Owner

Retires the daily cron that has been patching the installed npm dist since 2026-07-03.

The bug. initializeFromConfig() blanked any apiKey stored as the keyring://<provider> marker and left resolution to "the provider's env-var fallback". That works for the built-in providers — anthropic, openai, zai, ollama each register their own well-known variable. A custom provider (longcat, and anything added to config by hand) has none, so it got an empty bearer token and every request 401'd.

Where the fix has been living. NUKE runs scripts/sentinel-cli-repatch.sh from cron every day to re-apply this to dist/, because npm update -g reinstalls dist and wipes it. That script's header documents the bug exactly. A daily cron re-patching a published artifact is a symptom — the patch belongs in source.

Verified: npm run lint (tsc --noEmit) clean; full suite 106 files / 844 passed, 11 skipped.

After publish + install on NUKE, sentinel-cli-repatch.sh and its crontab entry can be deleted.

Scope: this checkout has unrelated uncommitted work on the secrets backends; deliberately not included.

…t built-ins

v3.3.0. Retires a daily cron that has been patching the installed npm dist since
2026-07-03.

initializeFromConfig() blanked any apiKey stored as the `keyring://<provider>`
marker and left resolution to "the provider's env-var fallback". That works for
the BUILT-IN providers in the switch below - anthropic, openai, zai and ollama
each register their own well-known variable. A CUSTOM provider (longcat, and
anything else added to config by hand) has no such fallback, so it was handed an
empty bearer token and every request 401'd.

The fix has existed for a month, in the wrong place: NUKE runs
scripts/sentinel-cli-repatch.sh from cron EVERY DAY to re-apply it to
node_modules/@dirtysouthalpha/sentinel-cli/dist, because `npm update -g`
silently reinstalls dist and wipes it. That script's own header documents the
bug precisely. A daily cron re-patching a published artifact is a symptom; the
patch belongs in source.

Resolves the environment variable directly at the point of blanking rather than
assuming a downstream fallback exists.

Verified: `npm run lint` (tsc --noEmit) clean; full suite 106 files /
844 passed, 11 skipped.

Once 3.3.0 is published and installed on NUKE, sentinel-cli-repatch.sh and its
crontab entry can be deleted - that is the point of the change.

Scope note: this checkout carries unrelated uncommitted work on the secrets
backends (file-backend, windows-backend and their tests). That is someone
else's in-progress change and is deliberately NOT included here.
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.

@dirtysouthalpha
dirtysouthalpha merged commit 2937ffc into main Aug 5, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant