Repository navigation
feat: refresh ClawRouter models through shared Model Core - #413
KillerQueen-Z wants to merge 4 commits into
Conversation
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
⛔ Files ignored due to path filters (6)
📒 Files selected for processing (1)
Included review availability: This review used your included allowance. Your plan provides up to 8 included reviews per hour; 7 remain after this review. 📝 WalkthroughWalkthroughClawRouter now refreshes a shared model catalog from the active gateway and projects eligible model metadata into proxy listings, routing and cost calculations, and OpenClaw model configuration and caches. ChangesShared model catalog
Priority: ➖ Normal Estimated code review effort: 3 (Moderate) | ~25 minutes Change: Feature Suggested reviewers: Sequence Diagram(s)sequenceDiagram
participant startProxy
participant createClawCatalog
participant Gateway
participant PolicyURL
participant ProxyRouter
participant OpenClawConfig
startProxy->>createClawCatalog: Configure for active gateway and network
startProxy->>createClawCatalog: Refresh catalog
createClawCatalog->>Gateway: Fetch gateway model data
createClawCatalog->>PolicyURL: Fetch policy data
createClawCatalog-->>startProxy: Return projected model view
startProxy->>ProxyRouter: Update pricing and capabilities
startProxy->>OpenClawConfig: Send visible models through callback
Merge Risk: ⚪ Minimal · up to The reported request-time catalog mismatch does not occur; no actionable merge-blocking issue remains after normal checks. Security Architecture ReviewSecurity architecture risk: 🔵 Low · up to Remote metadata now influences available choices and cost estimates. Credentials remain restricted to the configured destination, and existing payment checks remain in place. Partial updates can leave different views out of sync; their downstream effects are not fully verified. Retained concerns Security review detailsSecurity Blast Radius
Security Findings and Attack Paths
Trust Boundaries and Controls
Resilience and Maintainability Implications
Hardening Proposals
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✨ Finishing Touches 💡 1📝 Generate docstrings 💡
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
ClawRouter currently requires a catalog release to expose each upstream chat model. This change bundles the shared
@blockrun/model-catalogruntime and refreshes metadata from the active gateway at startup and every five minutes. New chat models appear in/v1/models, the OpenClaw provider/allowlist, and per-agent model caches; updated prices feed routing estimates and spend-cap checks.The runtime is pinned to immutable commit
465c45941fb8ea9d6858fe8402abc8ba8934be90(BlockRunAI/model-catalog#2). That Core fix is now merged, so this dependency is satisfied. The package version remains unchanged; this PR does not publish a release.Behavior and boundaries
Validation
0c1d1ba027fe9fd85ae10fe7ca525c3422012e70: Build & Test, Lint & Typecheck, Desktop, and scanner all passed. The initial run exposed a random-port collision in the existing proxy-reuse fixture; it now reserves its listener through the OS and avoids public gateway requests, and the rerun passed.0c1d1ba027fe9fd85ae10fe7ca525c3422012e70: 6/6 paid requests passed. On both Base and Solana, a live-discovered model absent from the static registry (poolside/laguna-s-2.1) returned the exact test marker; GPT-6 Luna completed a two-request streaming tool-call/result round trip. Every request returned a successful payment receipt and had a successful transaction independently checked via chain RPC. Wallet deltas matched signed quotes exactly: Base $0.006, Solana $0.003; total $0.009. Per-payment cap $0.05; total test cap $0.50. No credentials, wallets, signatures or transaction identifiers are published.Review status and known limits
Independent preliminary source review covered the initial source diff and supporting credential/payment boundaries; its cache-sync and reasoning-metadata observations were fixed and retested. The managed security scan could not generate its inventory (
could not read committed diff blob ...:package.json, despite the blob resolving locally). It remains incomplete: this PR does not claim a completed security scan or zero vulnerabilities.The 2026-10-02 npm audit snapshot reported 26 affected-package entries (4 high, 5 moderate, 17 low, 0 critical). Every advisory-affected lockfile entry is identical to the base revision. The only new package is the shared catalog, which has no runtime dependencies. Existing dependency remediation remains separate from this catalog integration.
Summary by CodeRabbit
2026-10-03 main sync
Merged current main
14d20acinto this branch as3944cfa2f58326103c99506359d317580df1acfc, resolving the new proxy/bundle conflicts while preserving upstream outcome-memory behavior and the catalog-based free-model fallback check. Full local regression (1,139 tests plus 5 lifecycle tests), typecheck, lint, formatting, build and distribution smoke checks passed. GitHub now reports the PR mergeable; CI is rerunning on this commit. The real paid evidence above remains explicitly tied to the previously tested0c1d1barevision.