Skip to content

🐛 fix: drop manifests missing api before feeding ToolsEngine#13856

Merged
arvinxx merged 1 commit into
canaryfrom
fix/tools-engine-manifest-guard
Apr 15, 2026
Merged

🐛 fix: drop manifests missing api before feeding ToolsEngine#13856
arvinxx merged 1 commit into
canaryfrom
fix/tools-engine-manifest-guard

Conversation

@arvinxx

@arvinxx arvinxx commented Apr 15, 2026

Copy link
Copy Markdown
Member

💻 Change Type

  • 🐛 fix

🔗 Related Issue

N/A (crash report from desktop renderer)

🔀 Description of Change

Users see this crash on the chat page:

```
TypeError: Cannot read properties of undefined (reading 'map')
at ToolsEngine.convertManifestsToTools (index-...js)
at ToolsEngine.generateToolsDetailed
at TokenTag-...js
```

Root cause

`ToolsEngine.convertManifestsToTools` (`packages/context-engine/src/engine/tools/ToolsEngine.ts:265-266`) does:

```ts
const tools = manifests.flatMap((manifest) => manifest.api.map((api) => ({ ... })));
```

`manifest` itself is defined (otherwise it would fail on `.api` rather than `.map`), but `manifest.api` is `undefined` for at least one entry — so `undefined.map(...)` throws. One bad manifest takes down the whole tools build, and everything that calls `generateTools*` (TokenTag, streaming executor, agent runtime) breaks with it.

Why it gets through

`createToolsEngine` merges manifests from five sources. Only some filter falsy entries, and none validate `api`:

Source Existing guard
`installedPluginManifestList` `.filter(!!i)` — catches falsy only
`builtinTools.map(...)` none
`klavisManifests` `.filter(Boolean)` — catches falsy only
`lobehubSkillManifests` `.filter(Boolean)` — catches falsy only
`additionalManifests` none

A truthy-but-malformed manifest (missing `api`, or `api` not an array) slips through any of them.

Fix

Guard defensively at the merge point with `isValidToolManifest` / `dropInvalidManifests`. Each source is filtered separately and a `console.warn` logs the source + identifier of every dropped entry, so we can trace the bad data back to where it was populated.

🧪 How to Test

  • Tested locally (`bun run type-check` + existing `src/helpers/toolEngineering/index.test.ts` — 14/14 passing)
  • Added/updated tests
  • No new tests needed immediately — change is additive; existing tests still cover the happy path. Follow-up can add an invalid-manifest regression test.

📝 Additional Information

This is a stop the bleed fix. Once the warning surfaces the bad source in real user sessions / CI, the proper follow-up is to fix whichever populator is writing a manifest without `api` (probable suspects: marketplace / custom plugin manifest fetcher returning partial JSON; Klavis or LobeHub-Skill tool sync on schema drift). The warning payload includes `identifier` when available to make that tractable.

…oolsEngine

`ToolsEngine.convertManifestsToTools` calls `manifest.api.map(...)`
without a null check, so any manifest that is truthy but lacks a valid
`api` array crashes the entire tools build with "Cannot read properties
of undefined (reading 'map')". This takes down anything that touches
the tools pipeline on that agent — including TokenTag in ChatInput,
which is why users see the crash on the chat page load path.

Manifests are merged from 5 sources (installed plugins, builtin tools,
Klavis, LobeHub skills, caller-supplied extras), only some of which
filter falsy entries, and none validate `api`. Guard defensively at
the merge point and log the offending source + identifier so the
underlying bad data can be traced.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@vercel

vercel Bot commented Apr 15, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
lobehub Ready Ready Preview, Comment Apr 15, 2026 4:33pm

Request Review

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We've reviewed this pull request using the Sourcery rules engine

@codecov

codecov Bot commented Apr 15, 2026

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 60.00000% with 12 lines in your changes missing coverage. Please review.
✅ Project coverage is 66.76%. Comparing base (8475bc1) to head (46f4312).
⚠️ Report is 2 commits behind head on canary.

Additional details and impacted files
@@            Coverage Diff             @@
##           canary   #13856      +/-   ##
==========================================
- Coverage   66.77%   66.76%   -0.01%     
==========================================
  Files        2046     2046              
  Lines      174449   174474      +25     
  Branches    20490    17166    -3324     
==========================================
+ Hits       116482   116493      +11     
- Misses      57843    57857      +14     
  Partials      124      124              
Flag Coverage Δ
app 59.09% <60.00%> (-0.01%) ⬇️
database 92.42% <ø> (ø)
packages/agent-runtime 79.72% <ø> (ø)
packages/context-engine 83.22% <ø> (ø)
packages/conversation-flow 92.36% <ø> (ø)
packages/file-loaders 87.02% <ø> (ø)
packages/memory-user-memory 74.74% <ø> (ø)
packages/model-bank 99.86% <ø> (ø)
packages/model-runtime 84.20% <ø> (ø)
packages/prompts 69.24% <ø> (ø)
packages/python-interpreter 92.90% <ø> (ø)
packages/ssrf-safe-fetch 0.00% <ø> (ø)
packages/utils 90.34% <ø> (ø)
packages/web-crawler 88.66% <ø> (ø)

Flags with carried forward coverage won't be shown. Click here to find out more.

Components Coverage Δ
Store 66.07% <ø> (ø)
Services 52.13% <ø> (ø)
Server 66.75% <ø> (-0.01%) ⬇️
Libs 52.89% <ø> (ø)
Utils 91.12% <ø> (ø)
🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@arvinxx arvinxx merged commit 6636b35 into canary Apr 15, 2026
31 checks passed
@arvinxx arvinxx deleted the fix/tools-engine-manifest-guard branch April 15, 2026 17:04
canisminor1990 added a commit that referenced this pull request Apr 16, 2026
# 🚀 LobeHub v2.1.50 (20260416)

**Release Date:** April 16, 2026\
**Since v2.1.49:** 107 commits · 101 merged PRs · 13 contributors

> This weekly release focuses on improving runtime stability and gateway
execution consistency, while making Home/Recents workflows faster to
navigate and easier to manage in daily use.

---

## ✨ Highlights

- **Server-side Human Approval Flow** — Agent runtime now supports more
reliable approve/reject/reject-continue handling in gateway mode,
reducing stalled execution paths in long-running tasks. (#13829, #13863,
#13873)

- **Message Gateway End-to-End Hardening** — Gateway message flow, queue
handling, tool callback routing, and stop interruption behavior were
strengthened for better execution continuity. (#13761, #13816, #13820,
#13815)

- **Client Tool Execution in Gateway Mode** — Client-executor tools now
run more predictably across gateway and desktop callers, with improved
executor dispatch behavior. (#13792, #13790)

- **Home / Recents / Sidebar Upgrade** — Sidebar layout, custom sort,
recents operations, and profile actions were improved to reduce
navigation friction in active sessions. (#13719, #13812, #13723, #13739,
#13878, #13734)

- **Agent Workspace and Documents Expansion** — Working panel and agent
document workflows were expanded and polished for better day-to-day
agent operations. (#13766, #13857)

- **Provider and Model Compatibility Improvements** — Added GLM-5.1
support and refined model/provider edge-case handling, including schema
and error-path fixes. (#13757, #13806, #13736, #13740)

---

## 🏗️ Core Agent & Architecture

### Agent runtime and intervention lifecycle

- Added server-side human approval and improved runtime coordination
across approve/reject decision paths. (#13829, #13863)
- Improved interrupted-task handling and operation lifecycle consistency
to reduce half-finished runtime states. (#13714)
- Refined error classification and payload propagation so downstream
surfaces receive clearer actionable errors. (#13736, #13740)

### Execution model and dispatch behavior

- Introduced executor-aware runtime behavior to better separate
client/server tool execution semantics. (#13758)
- Improved tool/plugin resolution and manifest handling to avoid runtime
failures on malformed inputs. (#13856, #13840, #13807)

---

## 📱 Gateway & Platform Integrations

- Added message gateway support and strengthened queue/error behavior
for more stable cross-channel execution. (#13761, #13816, #13820)
- Improved gateway callback pipeline with protocol and API additions for
`tool_execute` / `tool_result`. (#13762, #13764, #13765)
- Improved bot/channel reliability and DM/slash handling in
Discord-related paths. (#13805, #13724)

---

## 🖥️ CLI & User Experience

- Improved CLI reliability across message/topic operations and
build/minify-related paths. (#13731, #13888)
- Added image-to-video options and improved command behavior for
generation workflows. (#13788)
- Improved desktop runtime behavior for remote fetch and Linux
notification urgency handling. (#13789, #13782)

---

## 🔧 Tooling

- Extracted gateway stream client into `@lobechat/agent-gateway-client`
to centralize protocol usage and reduce duplication. (#13866)
- Improved built-in tool coverage and runtime support, including GTD
server runtime and missing lobe-kb tools. (#13854, #13876)
- Updated skill and frontmatter consistency in workflow tooling.
(#13730)

---

## 🔒 Security & Reliability

- **Security:** Strengthened API key WS auth behavior and safer
serverUrl forwarding in gateway-related auth paths. (#13824)
- **Reliability:** Reduced runtime stalls by improving gateway
stop/interrupt and approval-state routing behavior. (#13815, #13863,
#13873)
- **Reliability:** Added defensive guards for malformed tool manifests
and non-string content edge cases. (#13856, #13753)

---

## 👥 Contributors

**101 merged PRs** from **13 contributors** across **107 commits**.

### Community Contributors

- @arvinxx - Runtime, gateway, and execution reliability improvements
- @Innei - Navigation, workflow UX, and desktop/CLI refinements
- @rdmclin2 - Sidebar, recents, and channel behavior updates
- @ONLY-yours - Tooling/runtime fixes and model execution compatibility
- @tjx666 - Model support and release/tooling maintenance
- @nekomeowww - Memory and search-path stability fixes
- @cy948 - CLI indexing and command flow fixes
- @octo-patch - Local system runtime edge-case fixes
- @djthread - Desktop runtime request reliability improvements
- @rivertwilight - Documentation and changelog updates
- @sudongyuer - Subscription/mobile support improvements
- @Zhouguanyang - Provider/model configuration correctness fixes
- @lobehubbot - Translation and maintenance automation support

---

**Full Changelog**: v2.1.49...v2.1.50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant