feat(tinytools-std): file_state, url_guard, detect_tools from OpenHuman; parser regression tests - #33
Conversation
Introduce the tinytools-std crate with modules for command output handling, tool detection, file state management, and URL guarding. This provides the foundational library components for the tinytools project, including tests for each module to ensure basic functionality. Auto-committed-on: dragonfly Co-authored-by: Medulla <medulla@tinyhumans.ai>
…ut/mod.rs,crates/tinytools-std/ Auto-committed-on: dragonfly Co-authored-by: Medulla <medulla@tinyhumans.ai>
…rates/tinytools-std/src/detect_ Auto-committed-on: dragonfly Co-authored-by: Medulla <medulla@tinyhumans.ai>
…rates/tinytools-std/src/detect_ Auto-committed-on: dragonfly Co-authored-by: Medulla <medulla@tinyhumans.ai>
…tes/tinytools-agent/src/pformat Auto-committed-on: dragonfly Co-authored-by: Medulla <medulla@tinyhumans.ai>
…tput, detect_tools Extracted from OpenHuman (host-independent). file_state::init_global now takes an enabled flag instead of reading OPENHUMAN_FILE_STATE_GUARD. Also adds parser regression cases and pformat registry tests to tinytools-agent that were only covered host-side. Co-authored-by: Medulla <medulla@tinyhumans.ai>
tinytools::command_output has the identical implementation and tests, so the copy in tinytools-std was redundant. Co-authored-by: Medulla <medulla@tinyhumans.ai>
Tiny Sweeper review
|
|
Important Review skippedAuto reviews are disabled on base/target branches other than the default branch. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Comment |
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: f3fd597206
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| } | ||
| } | ||
|
|
||
| Ok(url) |
There was a problem hiding this comment.
Bind requests to the vetted DNS result
When a caller passes the returned URL to a normal HTTP client, the hostname is resolved a second time because this function discards addrs and returns only the original URL. A rebinding domain can therefore return a public address during this check and a private address during the client's lookup, bypassing the advertised SSRF protection. Return the vetted addresses for a pinned connection, or perform the request through a connector that preserves Host/SNI while using those addresses.
AGENTS.md reference: AGENTS.md:L61-L63
Useful? React with 👍 / 👎.
| coord.writes.write().insert( | ||
| resolved_path.clone(), | ||
| WriteStamp { | ||
| writer: agent_id.to_string(), | ||
| timestamp: now, |
There was a problem hiding this comment.
Preserve every writer needed by history queries
When agent A writes a path and agent B later writes the same path, this insertion erases A's stamp. As a result, paths_written_by(&[A]) incorrectly omits the path, and parent_stale_files can miss A's stale-parent notification when B is outside the supplied child set, despite both APIs promising historical “all”/“any” behavior. Retain per-writer write history, or otherwise maintain independent attribution data for these queries.
AGENTS.md reference: AGENTS.md:L61-L63
Useful? React with 👍 / 👎.
Summary
tinytools-std(kept out of the dependency-lighttinytoolsvocabulary crate, so tokio/parking_lot/log do not leak into it) holding host-independent tool building blocks extracted from OpenHuman:file_state: cross-agent read/write stamps, per-path async locks, task-local agent id.init_global(enabled: bool)replaces theOPENHUMAN_FILE_STATE_GUARDenv read; the host decides.url_guard: URL validation with SSRF and DNS-rebinding checks (same behaviour and messages).detect_tools:find_on_pathand the read-onlydetect_toolstool.tinytools-agent: adds parser regression cases the host had pinned on its own (large args, special chars, cross-alias closers, raw JSON not a call, empty tool_result / tool_calls,<invoke>forms, fenced JSON) asparse/test/regressions.rs, and pformat registry tests.command_outputcopy was already identical totinytools::command_output, so it is not duplicated here.Stacking
Base is
move-openhuman-tool-helpers(#32): the OpenHuman pin sits on that branch, which is ahead ofmain.Verification
cargo fmt --check,cargo clippy -p tinytools-std -p tinytools-agent --all-targets -- -D warnings,cargo test -p tinytools-std(73 passed),cargo test -p tinytools-agent(373 passed).Co-authored-by: Medulla medulla@tinyhumans.ai