From 172124e875b10305aa576603b4b720b6a9fd9452 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Jakob=20H=C3=B6gerl?= Date: Wed, 7 Oct 2026 16:50:40 +0200 Subject: [PATCH 1/2] Bundle OpenCodeReview v1.12.12 ocr v1.12.12 no longer rejects a --model that is missing from a built-in provider's suggested list; it warns and leaves validation to the provider. With v1.12.10, a review configured with provider: openai-responses, model: gpt-6.1-sol failed with 'model "gpt-6.1-sol" is not available for provider "openai-responses"'. - internal/ocrbin/VERSION: v1.12.10 -> v1.12.12 (Docker image and release binaries). - builtinProviders: the preset registry is unchanged in v1.12.12 (29 providers); only the version in the comment changes. - README / example config: llm.model can be any ID the provider serves. Co-Authored-By: Claude Opus 5.5 (1M context) --- README.md | 2 ++ internal/config/config.go | 2 +- internal/ocrbin/VERSION | 2 +- internal/ocrbin/ocrbin.go | 2 +- pruefbyte.example.yml | 2 +- 5 files changed, 6 insertions(+), 4 deletions(-) diff --git a/README.md b/README.md index ad85527..fec213f 100644 --- a/README.md +++ b/README.md @@ -62,6 +62,8 @@ Settings are layered; later layers win: The repository file may set `llm.provider` (OCR built-in providers only, and only when the global config does not set one: a provider the operator names keeps the shared API key with that vendor), `llm.model`, `ocr.*` (except `binary` and `extra_args`) and `review.*`. Anything that decides where credentials are sent, or what gets executed, is rejected there: custom providers with their own `llm.url` belong in the global file. +`llm.model` can be any model ID the provider serves. OCR's model lists for its built-in providers are only suggestions: a model that is not listed works, and OCR logs `[ocr] WARNING: model "…" is not in the suggested models for provider "…"; the provider will validate it`. A wrong ID therefore fails at the provider's API, not earlier. (OCR v1.12.10 and older, bundled with pruefbyte 0.1.0, rejected unlisted models.) + Secrets are only ever read from the env vars named by `gitlab.token_env` and `llm.api_key_env`. `ocr` runs with a private, temporary `HOME`, so its config file and session logs never touch the runner. Example `.pruefbyte.yml`: diff --git a/internal/config/config.go b/internal/config/config.go index 097475b..99e8653 100644 --- a/internal/config/config.go +++ b/internal/config/config.go @@ -241,7 +241,7 @@ func (c Config) Validate() error { } // builtinProviders mirrors OCR's built-in provider presets (`ocr llm providers`, -// v1.12.10). OCR rejects a custom provider that uses one of these names. +// v1.12.12). OCR rejects a custom provider that uses one of these names. var builtinProviders = map[string]bool{ "anthropic": true, "bedrock": true, "openai": true, "openai-responses": true, "openrouter": true, "gemini": true, "dashscope": true, "dashscope-tokenplan": true, diff --git a/internal/ocrbin/VERSION b/internal/ocrbin/VERSION index 68d89df..dc5ef6d 100644 --- a/internal/ocrbin/VERSION +++ b/internal/ocrbin/VERSION @@ -1 +1 @@ -v1.12.10 +v1.12.12 diff --git a/internal/ocrbin/ocrbin.go b/internal/ocrbin/ocrbin.go index 65e819e..bb11433 100644 --- a/internal/ocrbin/ocrbin.go +++ b/internal/ocrbin/ocrbin.go @@ -31,7 +31,7 @@ var ( sum string // hex sha256 of the uncompressed binary, from OCR's release checksums ) -// Version is the OCR release pruefbyte is built and tested against, e.g. v1.12.10. +// Version is the OCR release pruefbyte is built and tested against, e.g. v1.12.12. func Version() string { return strings.TrimSpace(versionFile) } // Available reports whether this build carries an ocr binary. diff --git a/pruefbyte.example.yml b/pruefbyte.example.yml index 37b24ff..e4894c0 100644 --- a/pruefbyte.example.yml +++ b/pruefbyte.example.yml @@ -12,7 +12,7 @@ llm: # A provider set here is fixed: repositories cannot switch the shared API key to # another vendor. Leave it out to let each repository choose. provider: anthropic # any OCR built-in provider; other names are custom providers - model: claude-sonnet-5 + model: claude-sonnet-5 # any model ID the provider serves; OCR's built-in lists are only suggestions api_key_env: PRUEFBYTE_LLM_API_KEY # env var holding the API key url: "" # base URL override; required for custom providers protocol: "" # custom providers: anthropic | openai | openai-responses | anthropic-bedrock From a14dd550d1f459a2ded28b2d7de0ca04cf0e1f59 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Jakob=20H=C3=B6gerl?= Date: Wed, 7 Oct 2026 17:11:52 +0200 Subject: [PATCH 2/2] Qualify the model note and drop pinned versions from comments - README: unlisted models work with the bundled OCR (v1.12.12+); an older ocr on the PATH or set via ocr.binary may still reject them. - Comments in config.go and ocrbin.go refer to internal/ocrbin/VERSION instead of repeating the version. Co-Authored-By: Claude Opus 5.5 (1M context) --- README.md | 2 +- internal/config/config.go | 5 +++-- internal/ocrbin/ocrbin.go | 2 +- 3 files changed, 5 insertions(+), 4 deletions(-) diff --git a/README.md b/README.md index fec213f..125c857 100644 --- a/README.md +++ b/README.md @@ -62,7 +62,7 @@ Settings are layered; later layers win: The repository file may set `llm.provider` (OCR built-in providers only, and only when the global config does not set one: a provider the operator names keeps the shared API key with that vendor), `llm.model`, `ocr.*` (except `binary` and `extra_args`) and `review.*`. Anything that decides where credentials are sent, or what gets executed, is rejected there: custom providers with their own `llm.url` belong in the global file. -`llm.model` can be any model ID the provider serves. OCR's model lists for its built-in providers are only suggestions: a model that is not listed works, and OCR logs `[ocr] WARNING: model "…" is not in the suggested models for provider "…"; the provider will validate it`. A wrong ID therefore fails at the provider's API, not earlier. (OCR v1.12.10 and older, bundled with pruefbyte 0.1.0, rejected unlisted models.) +`llm.model` can be any model ID the provider serves. With the OCR that pruefbyte bundles (the Docker image and release binaries, OCR v1.12.12 or newer), the model lists of OCR's built-in providers are only suggestions: a model that is not listed works, and OCR logs `[ocr] WARNING: model "…" is not in the suggested models for provider "…"; the provider will validate it`. A wrong ID therefore fails at the provider's API, not earlier. OCR v1.12.10 and older rejects unlisted models; that is what pruefbyte 0.1.0 bundles, and what an older `ocr` on your PATH (with `go install` builds, or set via `ocr.binary`) may still do. `pruefbyte version` shows which OCR is used. Secrets are only ever read from the env vars named by `gitlab.token_env` and `llm.api_key_env`. `ocr` runs with a private, temporary `HOME`, so its config file and session logs never touch the runner. diff --git a/internal/config/config.go b/internal/config/config.go index 99e8653..79d113b 100644 --- a/internal/config/config.go +++ b/internal/config/config.go @@ -240,8 +240,9 @@ func (c Config) Validate() error { return errors.Join(errs...) } -// builtinProviders mirrors OCR's built-in provider presets (`ocr llm providers`, -// v1.12.12). OCR rejects a custom provider that uses one of these names. +// builtinProviders mirrors OCR's built-in provider presets (`ocr llm providers`) +// for the version pinned in internal/ocrbin/VERSION; check it on every OCR bump. +// OCR rejects a custom provider that uses one of these names. var builtinProviders = map[string]bool{ "anthropic": true, "bedrock": true, "openai": true, "openai-responses": true, "openrouter": true, "gemini": true, "dashscope": true, "dashscope-tokenplan": true, diff --git a/internal/ocrbin/ocrbin.go b/internal/ocrbin/ocrbin.go index bb11433..0c6e43c 100644 --- a/internal/ocrbin/ocrbin.go +++ b/internal/ocrbin/ocrbin.go @@ -31,7 +31,7 @@ var ( sum string // hex sha256 of the uncompressed binary, from OCR's release checksums ) -// Version is the OCR release pruefbyte is built and tested against, e.g. v1.12.12. +// Version is the OCR release pruefbyte is built and tested against, as pinned in VERSION (e.g. vX.Y.Z). func Version() string { return strings.TrimSpace(versionFile) } // Available reports whether this build carries an ocr binary.