Skip to content

feat(dialect): own the native replay envelopes and image marker codec - #40

Merged
senamakel merged 3 commits into
mainfrom
fu-typed-transcript
Oct 1, 2026
Merged

senamakel merged 3 commits into
mainfrom
fu-typed-transcript

Conversation

@senamakel

@senamakel senamakel commented Oct 1, 2026 •

Copy link
Copy Markdown
Member

Design note

Current state. The native replay envelopes ({"content","tool_calls"} for an assistant turn that made calls, {"tool_call_id","content"} for a tool result) were encoded in NativeDialect::to_provider_messages and parsed/re-encoded separately by OpenHuman's message_convert.rs and by tinyagents-session's view/writer code. The [OH_IMAGE:<url>] inline-image marker was split/joined only in the host.

Target. One owner for these encodings: tinytools_agent::dialect::{encode_assistant_envelope, encode_tool_envelope, parse_assistant_envelope, parse_tool_envelope, split_image_parts, join_image_parts, IMAGE_MARKER_PREFIX} plus parse_canonical_* variants that accept a string only when re-encoding it reproduces it byte for byte. That is what lets a durable transcript lift an envelope into typed fields and rebuild the identical string on read (tinyagents-session PR, stacked on this one), falling back to opaque text for anything non-canonical.

Compatibility. NativeDialect now encodes through the shared functions; its output is unchanged (existing dialect tests pass). Additive API only.

Proof. 10 new envelope tests (round trip, non-canonical rejection, split/join identity incl. unterminated markers); all 383 crate tests pass; clippy -D warnings and fmt clean.

Part of the OpenHuman typed-transcript follow-up to #6872.

Summary by CodeRabbit

  • New Features
    • Added support for encoding and parsing assistant tool calls and tool results, including strict validation of canonical envelopes.
    • Added handling for image markers within message content.
    • Assistant reasoning content continues to be preserved when available.

senamakel and others added 3 commits October 1, 2026 11:53
When the native dialect receives an envelope with an empty body, the parser now returns an empty string instead of failing. This allows the system to gracefully process messages that contain only metadata without a payload, matching the behavior of other dialects.

Auto-committed-on: dragonfly
Co-authored-by: Medulla <medulla@tinyhumans.ai>
Move the {content,tool_calls} / {tool_call_id,content} envelope encode and parse
and the [OH_IMAGE:] marker split/join into tinytools-agent so hosts and durable
transcript writers share one definition. Canonical parsers only accept values
that re-encode byte-identically. NativeDialect now encodes through them (output
unchanged).

Co-authored-by: Medulla <medulla@tinyhumans.ai>
Co-authored-by: Medulla <medulla@tinyhumans.ai>
@tinysweeper

tinysweeper Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

Tiny Sweeper review

Tiny Sweeper reviewed this change across 6 lane(s) and found 0 active actionable finding(s). Detailed lane evidence and any incomplete work are listed below.

State: Incomplete
Priority: low
Reviewed head: e4eda5cfd0b2
Updated: 1790845316 (Unix time)

Review snapshot

Change surface Files Review signal Count
Production 3 Active findings 0
Tests 0 Noted findings 0
Documentation 0 Resolved findings 0
Configuration 0 Pending checks/questions 6

Completeness: Incomplete
Test assessment: No supported feature-to-test mapping was available; this does not mean tests are absent or passed.

What changed

The review could not produce a supported behavioral summary; inspect the cited changed surface and lane details below.

Features

None identified with supported citations.

Tests

No supported feature-to-test mapping was produced. Test execution is not inferred.

Findings

No active actionable findings.

Could not review: crates/tinytools-agent/src/dialect/envelope.rs, crates/tinytools-agent/src/dialect/mod.rs, crates/tinytools-agent/src/dialect/native.rs

Before merge

  • Complete the critique review for crates/tinytools-agent/src/dialect/envelope.rs, crates/tinytools-agent/src/dialect/mod.rs, crates/tinytools-agent/src/dialect/native.rs.
  • Complete the security review for crates/tinytools-agent/src/dialect/envelope.rs, crates/tinytools-agent/src/dialect/mod.rs, crates/tinytools-agent/src/dialect/native.rs.

How this fits together

flowchart LR
  n0["NativeDialect<br/>changed"]:::changed
  n1["ToolDialect"]:::impacted
  n2["assistant_envelope_round_trips_byte_exact"]:::impacted
  n3["encode_assistant_envelope"]:::impacted
  n4["call"]:::impacted
  n5["parse_assistant_envelope"]:::impacted
  n6["parse_canonical_assistant_envelope"]:::impacted
  n0 -->|implements| n1
  n2 -->|calls| n3
  n2 -->|tests| n3
  n2 -->|calls| n4
  n2 -->|tests| n4
  n2 -->|calls| n6
  n2 -->|tests| n6
  n6 -->|calls| n3
  n6 -->|calls| n5
  classDef changed fill:#0d4429,stroke:#238636,color:#e6edf3
  classDef impacted fill:#161b22,stroke:#6e7681,color:#c9d1d9
  classDef flagged fill:#5a1e02,stroke:#d93f0b,color:#ffffff
  classDef blocking fill:#67060c,stroke:#f85149,color:#ffffff
Loading
Agent review details

critique

  • Conclusion: Neutral
  • Scope reviewed: incomplete; unanswered: crates/tinytools-agent/src/dialect/envelope.rs, crates/tinytools-agent/src/dialect/mod.rs, crates/tinytools-agent/src/dialect/native.rs
  • Lane summary: Reviewed 0 files; 0 findings. 3 files could not be reviewed: crates/tinytools-agent/src/dialect/envelope.rs, crates/tinytools-agent/src/dialect/mod.rs, crates/tinytools-agent/src/dialect/native.rs.

security

  • Conclusion: Neutral
  • Scope reviewed: incomplete; unanswered: crates/tinytools-agent/src/dialect/envelope.rs, crates/tinytools-agent/src/dialect/mod.rs, crates/tinytools-agent/src/dialect/native.rs
  • Lane summary: Reviewed 0 files; 0 findings. 3 files could not be reviewed: crates/tinytools-agent/src/dialect/envelope.rs, crates/tinytools-agent/src/dialect/mod.rs, crates/tinytools-agent/src/dialect/native.rs.

tests

  • Conclusion: Success
  • Scope reviewed: all assigned evidence
  • Lane summary: _2 memory call(s) failed (model: cortex: v1/answer: timed out after 20s), so this review saw part of what the engine holds._

commits

  • Conclusion: Neutral
  • Scope reviewed: all assigned evidence
  • Lane summary: Nothing sensitive found in what this pull request commits.

description

  • Conclusion: Success
  • Scope reviewed: all assigned evidence
  • Lane summary: This change moves the native replay envelope encoding and image marker logic into a new `envelope.rs` module and refactors `NativeDialect::to_provider_messages` to use the shared functions. The output is unchanged for the existing dialect, and new canonical parsers provide strict round-trip verification. The only rule violation is that the module-local tests are written inline rather than in the required `test.rs` file; this is a low‑severity formatting issue and does not affect correctness. The change is safe to merge once the test location is addressed. _2 memory call(s) failed (model: cortex: v1/answer: timed out after 20s), so this review saw part of what the engine holds._

e2e

  • Conclusion: Neutral
  • Scope reviewed: all assigned evidence
  • Lane summary: No end-to-end harness in this repository: no e2e test files and no e2e workflow.
Evidence and run details
  • Models: ladder/vectors, deepseek/deepseek-v4-flash
  • Spend: $0.004170
  • Tokens: 36112 input · 11662 output · 0 cached · 664 embedding
Head State Pass summary
e4eda5cfd0b2 incomplete 0 active finding(s), 0 resolved finding(s) (at 1790845316)

tinysweeper 0.1.0

@coderabbitai

coderabbitai Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

🧰 Additional context used
📚 Code guidelines (1)
AGENTS.md — auto-discovered

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: c042277e-69c5-4fcc-8876-129196a4bb99

📥 Commits

Reviewing files that changed from the base of the PR and between 8feb557 and e4eda5c.

📒 Files selected for processing (3)
  • crates/tinytools-agent/src/dialect/envelope.rs
  • crates/tinytools-agent/src/dialect/mod.rs
  • crates/tinytools-agent/src/dialect/native.rs

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

The dialect adds assistant and tool JSON envelope encoders and parsers, canonical parsing, and image-marker splitting and joining. The native dialect uses the new encoders when building provider messages.

Changes

Dialect envelope support

Layer / File(s) Summary
Envelope formats and content parts
crates/tinytools-agent/src/dialect/envelope.rs
Adds assistant and tool envelope encoders and lenient parsers. Canonical parsers accept only inputs that re-encode identically. Image-part utilities split and join [OH_IMAGE:<payload>] markers, and tests cover envelope and image-part behavior.
Dialect exports and native encoding
crates/tinytools-agent/src/dialect/mod.rs, crates/tinytools-agent/src/dialect/native.rs
Re-exports the envelope APIs and uses the assistant and tool encoders when building native provider messages. Assistant reasoning content remains optional, and extra metadata remains attached to the assistant message.

Priority: ⬇️ Low

Estimated code review effort: 3 (Moderate) | ~20 minutes

Change: Feature

Merge Risk: ⚪ Minimal · up to e4eda

The shared codecs retain the described native message behavior, with no concrete merge-blocking issue identified. The change is mergeable subject to normal checks.

Security Architecture Review

Security architecture risk: 🔵 Low · up to e4eda

The examined implementation centralizes message encoding without adding tool execution or image retrieval. No introduced security flaw was established, but the exported parsers create a contract that future transcript consumers must use without treating decoded content as authorization. Those downstream consumers were not available for verification.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The demonstrated change affects the public dialect API and native provider-message serialization. The examined codec contains no execution, persistence, or retrieval sink. Additional authority or tenant exposure through future host consumers cannot be established from this PR.

Trust Boundaries and Controls

  • observed — Attacker-supplied JSON or marker text can become typed tool-call data or image references, but parsing itself performs no privileged action. The package documents execution policy, permissions, sandboxing, and approvals as host-owned. Canonical byte equality is a preservation control, not an identity or authorization check.

Hardening Proposals

  • proposed — When integrating the stacked transcript consumer, preserve message roles and call ownership, retain non-canonical text unchanged, and keep host authorization and image-retrieval policy checks separate from successful decoding.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely describes the main changes: moving native replay-envelope handling and image-marker encoding into the dialect module.
Docstring Coverage ✅ Passed Docstring coverage is 86.67% which is sufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 15 functions across 3 files.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


A rabbit packed tool calls with care,
And marked each image in the air.
It joined the text, then checked each seam,
Canonical envelopes gleamed.
“Hop along,” it said, “all clear!”

Comment @coderabbitai help to get the list of available commands.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: e4eda5cfd0

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".


#[cfg(test)]
#[allow(clippy::unwrap_used)]
mod tests {

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Move envelope tests into a dedicated test file

Keeping this new test module inline in envelope.rs violates the repository’s required module layout and causes implementation files to accumulate test code. Move these tests to the dialect’s dedicated test.rs structure and wire them from the module root.

AGENTS.md reference: AGENTS.md:L76-L88

Useful? React with 👍 / 👎.

}

#[cfg(test)]
#[allow(clippy::unwrap_used)]

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Remove the module-wide lint suppression

This module-level allow disables unwrap_used for every test in the module, including future additions, rather than addressing the individual assertions. Rewrite the affected assertions without unwrap() instead of weakening the configured guardrail for the entire test module.

AGENTS.md reference: AGENTS.md:L283-L285

Useful? React with 👍 / 👎.

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-01T08:59:27.751711Z e4eda5c PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@tinysweeper tinysweeper Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

tinysweeper found nothing blocking, but could not review everything, so this is not an approval: crates/tinytools-agent/src/dialect/envelope.rs, crates/tinytools-agent/src/dialect/mod.rs, crates/tinytools-agent/src/dialect/native.rs.

             $0.0042 · 36,112 in / 11,662 out · 0 cached (0%) · ladder/vectors, deepseek/deepseek-v4-flash · 664 embedded
tests:       $0.0022 · 19,452 in / 2,640 out  · 0 cached (0%) · deepseek/deepseek-v4-flash
description: $0.0010 · 10,655 in / 6,989 out  · 0 cached (0%) · deepseek/deepseek-v4-flash

@senamakel
senamakel merged commit 48c1d5e into main Oct 1, 2026
16 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant