fix: doctor/exit-code bugs, npx-cache warning, add key wizard (0.1.4) - #10
Merged
Merged
Conversation
…e 0.1.4 - Fix `doctor` reporting configuration/credentials as ready while embedding.base_url/model were still the install template's placeholder values. - Fix the CLI entrypoint always exiting 0: main()'s return value (notably doctor's pass/fail code) was never applied to process.exitCode, so scripted checks against the exit code always saw success. - Warn when `chilon-recall qoder` is run from an npx temporary cache, since the generated .qoder/mcp.json embeds that ephemeral path and breaks silently on the next cache clear or version bump. - Add `chilon-recall key`: a hidden-input prompt for a provider API key that calls the provider's /models endpoint, suggests an embedding and reranker model, and prints ready-to-run env var commands. The key is used for a single request and never written to disk. - Bump package/plugin/Python distribution/server version to 0.1.4 and update the pinned npx examples in both READMEs.
…ZodError output, silent setup - secretPrompt: onData treated a whole pasted chunk as one character, so a paste with any newline (trailing or embedded) fell into the default case and hung forever instead of resolving/rejecting. Iterate per character. - models: a header-unsafe key (e.g. one with an embedded newline) made Headers.append throw with the raw key embedded in its own message, which was then wrapped straight into the thrown error, leaking the plaintext key and mislabeling the failure as a network problem. Validate the key before ever calling fetch, and redact it from any error that still slips through. - models: reranker model names matching /bge/i etc. also landed in the embedding bucket, so recommendModels could suggest a reranker as the embedding model. Exclude rerank matches from the embedding bucket first. - keyWizard: the "persists" commands (setx / >> ~/.bashrc) write the plaintext key to the registry/disk if the user runs them, and land in shell history/scrollback either way; the notes didn't say so. - providers.py / models.mjs: a base_url that already ends with the target suffix (e.g. "/embeddings") no longer gets it appended twice. - config: ZodError#message is a JSON dump of its issues; that was surfacing verbatim in MCP tool errors and doctor's report for something as ordinary as a typo'd config key. Added describeConfigError to turn it into a sentence. - runtime/cli: setupEngine (venv + pip install) ran silently for up to a minute with zero output, looking hung. Stream phase announcements and the underlying process output to stderr, keeping stdout's single-JSON contract intact.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
doctorreportingconfiguration.ready/credentials_ready: truewhileembedding.base_url/modelwere still the install template's placeholder values.0—main()'s return value (notablydoctor's pass/fail code) was never applied toprocess.exitCode.chilon-recall qoderis run from annpxtemporary cache, since the generated.qoder/mcp.jsonembeds that ephemeral path.chilon-recall key: hidden-input provider API key prompt that queries/modelsand suggests embedding/reranker models plus ready-to-run env var commands.Follow-up fixes (this update)
Found by a code review of the
keywizard added above:dataevent, not one event per character.promptSecret'sswitchonly matched single-character strings, so any paste containing a newline (trailing or embedded) fell intodefault, got spliced into the value, and never resolved or rejected. Now iterates per character so paste behaves like typing.Headers.appendthrow with the raw key quoted in its own message, which was wrapped straight into the thrown error — leaking the keymodels.mjspromises is "never ... logged, or echoed back", and mislabeling a bad-credential problem as a network failure. Now validated before the request is made, with a redaction fallback for anything that still slips through.bge-reranker-largematching/bge/i) landed in both buckets;suggestedEmbeddingModelcould then pick a reranker. Rerank matches are now excluded from the embedding bucket.setx/>> ~/.bashrcdo write the plaintext key (registry / disk) if the user runs them, and land in shell history/scrollback regardless. Added an explicit note.base_urlcould double-concatenate its suffix: abase_urlalready ending in/embeddings(Python) or/models(Node) no longer gets the suffix appended twice.ZodError#messageis a JSON dump of.issues; an extra/typo'd config key surfaced that raw dump through MCP tool errors anddoctor's report. AddeddescribeConfigErrorto render it as a sentence.setup/installlooked hung: engine setup (venv +pip install) ran silently for up to a minute. Phase announcements and the underlying process output now stream to stderr live, while stdout keeps its single-JSON-object contract for scripts.Test plan
npm test— 46 Node tests + 9 Python tests pass (13 new: paste/newline handling, key redaction, rerank/embedding overlap, URL double-concat, ZodError formatting, setup progress plumbing)chilon-recall setupend-to-end: confirmed stdout stays a single clean JSON object while stderr streams live phase/pip output