OpenWork (modelstudioai/openwork) has forked the Electron desktop code and is
self-contained now, so retire the Electron package and its release/sync
machinery from this repo:
- Delete packages/desktop (Electron app, live-host app, bun workspace).
- Retire scripts/desktop-openwork-sync.ts and the desktop-openwork-sync root
script; the OpenWork sync is no longer needed.
- Retire .github/workflows/live-host.yml, live-host-release.yml and
sync-live-host-to-oss.yml; live-host releases now live in OpenWork. The
CLI-side packages/cli/src/serve/live code stays for now (separate cleanup).
- Retire scripts/check-voice-guard-sync.js (cli<->desktop parity only) and
its CI step.
- Clean up remaining references: root package.json workspaces negation and
package-lock.json, eslint/prettier/yamllint ignores, architecture docs,
web-shell skill descriptions, and review-lib workspace fixtures/comments
(renamed to point at packages/desktop-shell, the remaining negation).
Deliberately kept: the Electron->Tauri upgrade bridge — desktop-release.yml
(incl. the electron_bridge input), create-electron-bridge-manifest.mjs,
sync-desktop-to-oss.yml (mirrors Tauri desktop-shell artifacts only) and
everything under packages/desktop-shell.
* feat(voice): support trusted private ASR base URLs
* fix(voice): address private endpoint review findings
* test(voice): cover private endpoint edge cases
* test(voice): pin remaining endpoint edge cases
* fix(voice): address private endpoint review feedback
* fix(voice): clarify allowlist URL and normalize IPv6
* fix(voice): harden NAT64 address validation
* fix(voice): address managed endpoint review findings
* refactor(voice): extract shared IPv6 transition unwrap ladder (#8350)
Deduplicate the IPv6-transition unwrapping sequence (mapped, compatible,
NAT64, dotted-quad) that was repeated verbatim between isPrivateNetworkIp
and isAlwaysBlockedVoiceAddress on both CLI and Desktop surfaces. A single
unwrapIpv6TransitionStep helper now yields the next canonical address (or
'blocked' for unrecognized ::ffff: forms), and each predicate recurses
through it, preserving the exact re-check semantics at every unwrap level.
* test(voice): cover allowInsecureBaseUrl wiring through desktop default transports (#8350)
* fix(voice): add allowlist hint to private-network rejection error (#8350)
* fix(voice): reject always-blocked base URLs before offering the allowlist hint (#8350)
* fix(voice): resolve exact desktop voice provider before OAuth (#8350)
* fix(voice): address review feedback for trusted private base URLs (#8350)
* fix(voice): align desktop voice resolution with CLI semantics (#8350)
* fix(voice): scope desktop fail-closed resolution to policy-bearing entries (#8350)
* fix(voice): address round-8 review findings for trusted private base URLs (#8350)
Run the invasive process-global `mock.module('ws')` suite as
voice-ws-handler.isolated.ts so the desktop package's single-process
`bun test` run no longer leaks the fake socket into unrelated ws
consumers; the existing isolated loop runs it in its own process.
Shape-guard the desktop provider scan: non-object modelProviders
elements are skipped (falling through to OAuth instead of throwing a
raw TypeError), and non-string baseUrl/envKey/settings.env values on a
voice-model entry now surface the PROVIDER_ENTRY_REMEDY remediation
error instead of crashing.
Compute the DashScope-compatible /v1 rewrite before any allowlist
match in fromExactModelProvider so the stage-1 check, the remediation
messages, and the top-level recheck all compare the same final URL and
a single allowlist entry converges for split-horizon deployments.
Extend the CLI allowlist remediation messages to state which settings
scopes honor the entry, since serve mode never shows the interactive
workspace-strip warning. Thread providerProtocol through the CLI voice
model seams (createVoiceModelSource and the daemon buildModelsConfig)
so protocol-mapped custom provider groups resolve like the rest of the
CLI model surface, and document the remaining protocol-agnostic desktop
scan in the design doc. Correct the getHomeEnvFallback comment: it
adopts the narrower getHomeEnvFallbackVars candidate set on purpose.
Add multi-record DNS answer tests on both CLI and desktop net guards so
the records.some classification is pinned against the array shape
defaultLookupHost always produces in production.
* fix(voice): address round-9 review findings for trusted private base URLs (#8350)
* fix(voice): address round-10 review findings for trusted private base URLs (#8350)
* fix(voice): classify desktop voice duplicates before ambiguity check (#8350)
* fix(scripts): compare voice guard mirrors as parse trees (#8350)
---------
Co-authored-by: rockybot2026 <265985139+rockybot2026@users.noreply.github.com>
Co-authored-by: qwen-code-dev-bot <qwen-code-dev@service.alibaba.com>
Co-authored-by: qwen-code-ci-bot <qwen-code-ci-bot@users.noreply.github.com>
Co-authored-by: qwen-code-dev-bot <qwen-code-dev-bot@users.noreply.github.com>
Co-authored-by: Shaojin Wen <shaojin.wensj@alibaba-inc.com>