Skip to content

fix(provider): harden runtime catalog boundaries - #3243

Merged
kwakayama merged 8 commits into
codex/provider-anthropic-google-hardening-20260802from
codex/provider-runtime-catalog-hardening-20260802
Aug 2, 2026
Merged

kwakayama merged 8 commits into
codex/provider-anthropic-google-hardening-20260802from
codex/provider-runtime-catalog-hardening-20260802

Conversation

@kojiwakayama

Copy link
Copy Markdown
Contributor

Summary

  • make model registry composition project-scoped, generation-safe, and explicitly disposable
  • classify local execution from declared runtime placement instead of provider/model-name heuristics
  • validate runtime tool-calling capabilities at the inspection boundary
  • derive Veryfront Cloud default IDs from one immutable catalog entry
  • reject unsafe provider aliases, gateway URLs, credentials, and invalid thinking budgets

This is stacked on #3242 and contains only the remaining independent provider catalog/registry slice. Local Transformers extraction remains deferred to its extension/package track.

Validation

  • deno check src/provider/index.ts src/agent/index.ts
  • 4 focused suites / 42 steps
  • deno task typecheck
  • scoped provider fmt/lint
  • test typecheck baseline, core dependency, and dependency-boundary audits
  • git diff --check

All passed locally.

@kojiwakayama
kojiwakayama requested a review from kwakayama as a code owner August 2, 2026 12:17

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 963bee1ba0

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

Comment thread src/provider/runtime-inspection.ts
Comment thread src/provider/model-registry.ts
@kojiwakayama
kojiwakayama force-pushed the codex/agent-hosted-runtime-hardening-20260802 branch from 18820d2 to 9027136 Compare August 2, 2026 12:51
@kojiwakayama
kojiwakayama force-pushed the codex/provider-runtime-catalog-hardening-20260802 branch from 193a2b6 to 588e9dd Compare August 2, 2026 12:52
The runtime catalog rewrite dropped the `local` shared registration while
converting the guarded `if (!manager.has(...))` blocks into unconditional
ones, so every `local/...` model string failed to resolve. Nothing replaced
it: `resolveRuntimeModel()` still passes `local/` through untouched, and
`createLocalModel()` already exposes the generic `prepare()` hook that
`ensureModelReady()` was refactored to call.

Re-register `local` alongside the other shared providers and cover
credential-free resolution so the regression cannot return.
`stringifyJsonValue()` lost its string pass-through, so plain-string tool
results were JSON.stringify'd into quote-wrapped text before reaching
OpenAI-compatible messages, Anthropic tool_result blocks, and OpenAI
Responses output.

Restore the pass-through ahead of the undefined-serialization guard the
rewrite added, keeping both behaviours.
Enabling the OpenAI provider-native web_search left three tests asserting
the previous behaviour, where `openai` exposed no provider-native tools at
all. They failed because `web_search` now correctly reaches the runtime
inventory and the fork availability list.

The unit tests next to the change were updated with it, and its own new
"returns no provider-native tool names for unsupported providers" case
moved the unsupported example to google. These three were missed.

Keep each assertion's original intent by pointing it at a combination that
is still genuinely unsupported: OpenAI exposes a native web_search but no
native web_fetch, so the inventory tests now require the supported half to
be advertised and the unsupported half to be dropped. That is a stronger
check than the previous one, which only proved a provider with zero native
tools contributes nothing.
…hardening-20260802' into codex/agent-hosted-runtime-rebased-20260802
…ning-20260802' into codex/provider-runtime-catalog-rebased-20260802
…ardening-20260802' into codex/provider-runtime-catalog-rebased-20260802
Base automatically changed from codex/agent-hosted-runtime-hardening-20260802 to codex/provider-anthropic-google-hardening-20260802 August 2, 2026 14:08
@kwakayama
kwakayama merged commit 303fcfa into codex/provider-anthropic-google-hardening-20260802 Aug 2, 2026
1 check passed
@kwakayama
kwakayama deleted the codex/provider-runtime-catalog-hardening-20260802 branch August 2, 2026 14:09
kojiwakayama added a commit that referenced this pull request Aug 2, 2026
* fix(agent): harden hosted runtime contracts

* fix(provider): harden runtime catalog contracts

* fix(provider): restore the built-in local model provider

The runtime catalog rewrite dropped the `local` shared registration while
converting the guarded `if (!manager.has(...))` blocks into unconditional
ones, so every `local/...` model string failed to resolve. Nothing replaced
it: `resolveRuntimeModel()` still passes `local/` through untouched, and
`createLocalModel()` already exposes the generic `prepare()` hook that
`ensureModelReady()` was refactored to call.

Re-register `local` alongside the other shared providers and cover
credential-free resolution so the regression cannot return.

* fix(provider): stop double-encoding string tool values

`stringifyJsonValue()` lost its string pass-through, so plain-string tool
results were JSON.stringify'd into quote-wrapped text before reaching
OpenAI-compatible messages, Anthropic tool_result blocks, and OpenAI
Responses output.

Restore the pass-through ahead of the undefined-serialization guard the
rewrite added, keeping both behaviours.

* test(agent): align inventory expectations with OpenAI native search

Enabling the OpenAI provider-native web_search left three tests asserting
the previous behaviour, where `openai` exposed no provider-native tools at
all. They failed because `web_search` now correctly reaches the runtime
inventory and the fork availability list.

The unit tests next to the change were updated with it, and its own new
"returns no provider-native tool names for unsupported providers" case
moved the unsupported example to google. These three were missed.

Keep each assertion's original intent by pointing it at a combination that
is still genuinely unsupported: OpenAI exposes a native web_search but no
native web_fetch, so the inventory tests now require the supported half to
be advertised and the unsupported half to be dropped. That is a stronger
check than the previous one, which only proved a provider with zero native
tools contributes nothing.
kojiwakayama added a commit that referenced this pull request Aug 2, 2026
* fix(agent): harden hosted runtime contracts

* fix(provider): harden runtime catalog contracts

* fix(provider): restore the built-in local model provider

The runtime catalog rewrite dropped the `local` shared registration while
converting the guarded `if (!manager.has(...))` blocks into unconditional
ones, so every `local/...` model string failed to resolve. Nothing replaced
it: `resolveRuntimeModel()` still passes `local/` through untouched, and
`createLocalModel()` already exposes the generic `prepare()` hook that
`ensureModelReady()` was refactored to call.

Re-register `local` alongside the other shared providers and cover
credential-free resolution so the regression cannot return.

* fix(provider): stop double-encoding string tool values

`stringifyJsonValue()` lost its string pass-through, so plain-string tool
results were JSON.stringify'd into quote-wrapped text before reaching
OpenAI-compatible messages, Anthropic tool_result blocks, and OpenAI
Responses output.

Restore the pass-through ahead of the undefined-serialization guard the
rewrite added, keeping both behaviours.

* test(agent): align inventory expectations with OpenAI native search

Enabling the OpenAI provider-native web_search left three tests asserting
the previous behaviour, where `openai` exposed no provider-native tools at
all. They failed because `web_search` now correctly reaches the runtime
inventory and the fork availability list.

The unit tests next to the change were updated with it, and its own new
"returns no provider-native tool names for unsupported providers" case
moved the unsupported example to google. These three were missed.

Keep each assertion's original intent by pointing it at a combination that
is still genuinely unsupported: OpenAI exposes a native web_search but no
native web_fetch, so the inventory tests now require the supported half to
be advertised and the unsupported half to be dropped. That is a stronger
check than the previous one, which only proved a provider with zero native
tools contributes nothing.
kojiwakayama added a commit that referenced this pull request Aug 2, 2026
* fix(agent): harden hosted runtime contracts

* fix(provider): harden runtime catalog contracts

* fix(provider): restore the built-in local model provider

The runtime catalog rewrite dropped the `local` shared registration while
converting the guarded `if (!manager.has(...))` blocks into unconditional
ones, so every `local/...` model string failed to resolve. Nothing replaced
it: `resolveRuntimeModel()` still passes `local/` through untouched, and
`createLocalModel()` already exposes the generic `prepare()` hook that
`ensureModelReady()` was refactored to call.

Re-register `local` alongside the other shared providers and cover
credential-free resolution so the regression cannot return.

* fix(provider): stop double-encoding string tool values

`stringifyJsonValue()` lost its string pass-through, so plain-string tool
results were JSON.stringify'd into quote-wrapped text before reaching
OpenAI-compatible messages, Anthropic tool_result blocks, and OpenAI
Responses output.

Restore the pass-through ahead of the undefined-serialization guard the
rewrite added, keeping both behaviours.

* test(agent): align inventory expectations with OpenAI native search

Enabling the OpenAI provider-native web_search left three tests asserting
the previous behaviour, where `openai` exposed no provider-native tools at
all. They failed because `web_search` now correctly reaches the runtime
inventory and the fork availability list.

The unit tests next to the change were updated with it, and its own new
"returns no provider-native tool names for unsupported providers" case
moved the unsupported example to google. These three were missed.

Keep each assertion's original intent by pointing it at a combination that
is still genuinely unsupported: OpenAI exposes a native web_search but no
native web_fetch, so the inventory tests now require the supported half to
be advertised and the unsupported half to be dropped. That is a stronger
check than the previous one, which only proved a provider with zero native
tools contributes nothing.
kojiwakayama added a commit that referenced this pull request Aug 2, 2026
* fix(agent): harden hosted runtime contracts

* fix(provider): harden runtime catalog contracts

* fix(provider): restore the built-in local model provider

The runtime catalog rewrite dropped the `local` shared registration while
converting the guarded `if (!manager.has(...))` blocks into unconditional
ones, so every `local/...` model string failed to resolve. Nothing replaced
it: `resolveRuntimeModel()` still passes `local/` through untouched, and
`createLocalModel()` already exposes the generic `prepare()` hook that
`ensureModelReady()` was refactored to call.

Re-register `local` alongside the other shared providers and cover
credential-free resolution so the regression cannot return.

* fix(provider): stop double-encoding string tool values

`stringifyJsonValue()` lost its string pass-through, so plain-string tool
results were JSON.stringify'd into quote-wrapped text before reaching
OpenAI-compatible messages, Anthropic tool_result blocks, and OpenAI
Responses output.

Restore the pass-through ahead of the undefined-serialization guard the
rewrite added, keeping both behaviours.

* test(agent): align inventory expectations with OpenAI native search

Enabling the OpenAI provider-native web_search left three tests asserting
the previous behaviour, where `openai` exposed no provider-native tools at
all. They failed because `web_search` now correctly reaches the runtime
inventory and the fork availability list.

The unit tests next to the change were updated with it, and its own new
"returns no provider-native tool names for unsupported providers" case
moved the unsupported example to google. These three were missed.

Keep each assertion's original intent by pointing it at a combination that
is still genuinely unsupported: OpenAI exposes a native web_search but no
native web_fetch, so the inventory tests now require the supported half to
be advertised and the unsupported half to be dropped. That is a stronger
check than the previous one, which only proved a provider with zero native
tools contributes nothing.
kojiwakayama added a commit that referenced this pull request Aug 2, 2026
* fix(agent): harden hosted runtime contracts

* fix(provider): harden runtime catalog contracts

* fix(provider): restore the built-in local model provider

The runtime catalog rewrite dropped the `local` shared registration while
converting the guarded `if (!manager.has(...))` blocks into unconditional
ones, so every `local/...` model string failed to resolve. Nothing replaced
it: `resolveRuntimeModel()` still passes `local/` through untouched, and
`createLocalModel()` already exposes the generic `prepare()` hook that
`ensureModelReady()` was refactored to call.

Re-register `local` alongside the other shared providers and cover
credential-free resolution so the regression cannot return.

* fix(provider): stop double-encoding string tool values

`stringifyJsonValue()` lost its string pass-through, so plain-string tool
results were JSON.stringify'd into quote-wrapped text before reaching
OpenAI-compatible messages, Anthropic tool_result blocks, and OpenAI
Responses output.

Restore the pass-through ahead of the undefined-serialization guard the
rewrite added, keeping both behaviours.

* test(agent): align inventory expectations with OpenAI native search

Enabling the OpenAI provider-native web_search left three tests asserting
the previous behaviour, where `openai` exposed no provider-native tools at
all. They failed because `web_search` now correctly reaches the runtime
inventory and the fork availability list.

The unit tests next to the change were updated with it, and its own new
"returns no provider-native tool names for unsupported providers" case
moved the unsupported example to google. These three were missed.

Keep each assertion's original intent by pointing it at a combination that
is still genuinely unsupported: OpenAI exposes a native web_search but no
native web_fetch, so the inventory tests now require the supported half to
be advertised and the unsupported half to be dropped. That is a stronger
check than the previous one, which only proved a provider with zero native
tools contributes nothing.
kojiwakayama added a commit that referenced this pull request Aug 2, 2026
* fix(agent): harden hosted runtime contracts

* fix(provider): harden runtime catalog contracts

* fix(provider): restore the built-in local model provider

The runtime catalog rewrite dropped the `local` shared registration while
converting the guarded `if (!manager.has(...))` blocks into unconditional
ones, so every `local/...` model string failed to resolve. Nothing replaced
it: `resolveRuntimeModel()` still passes `local/` through untouched, and
`createLocalModel()` already exposes the generic `prepare()` hook that
`ensureModelReady()` was refactored to call.

Re-register `local` alongside the other shared providers and cover
credential-free resolution so the regression cannot return.

* fix(provider): stop double-encoding string tool values

`stringifyJsonValue()` lost its string pass-through, so plain-string tool
results were JSON.stringify'd into quote-wrapped text before reaching
OpenAI-compatible messages, Anthropic tool_result blocks, and OpenAI
Responses output.

Restore the pass-through ahead of the undefined-serialization guard the
rewrite added, keeping both behaviours.

* test(agent): align inventory expectations with OpenAI native search

Enabling the OpenAI provider-native web_search left three tests asserting
the previous behaviour, where `openai` exposed no provider-native tools at
all. They failed because `web_search` now correctly reaches the runtime
inventory and the fork availability list.

The unit tests next to the change were updated with it, and its own new
"returns no provider-native tool names for unsupported providers" case
moved the unsupported example to google. These three were missed.

Keep each assertion's original intent by pointing it at a combination that
is still genuinely unsupported: OpenAI exposes a native web_search but no
native web_fetch, so the inventory tests now require the supported half to
be advertised and the unsupported half to be dropped. That is a stronger
check than the previous one, which only proved a provider with zero native
tools contributes nothing.
kojiwakayama added a commit that referenced this pull request Aug 2, 2026
* fix(agent): harden hosted runtime contracts

* fix(provider): harden runtime catalog contracts

* fix(provider): restore the built-in local model provider

The runtime catalog rewrite dropped the `local` shared registration while
converting the guarded `if (!manager.has(...))` blocks into unconditional
ones, so every `local/...` model string failed to resolve. Nothing replaced
it: `resolveRuntimeModel()` still passes `local/` through untouched, and
`createLocalModel()` already exposes the generic `prepare()` hook that
`ensureModelReady()` was refactored to call.

Re-register `local` alongside the other shared providers and cover
credential-free resolution so the regression cannot return.

* fix(provider): stop double-encoding string tool values

`stringifyJsonValue()` lost its string pass-through, so plain-string tool
results were JSON.stringify'd into quote-wrapped text before reaching
OpenAI-compatible messages, Anthropic tool_result blocks, and OpenAI
Responses output.

Restore the pass-through ahead of the undefined-serialization guard the
rewrite added, keeping both behaviours.

* test(agent): align inventory expectations with OpenAI native search

Enabling the OpenAI provider-native web_search left three tests asserting
the previous behaviour, where `openai` exposed no provider-native tools at
all. They failed because `web_search` now correctly reaches the runtime
inventory and the fork availability list.

The unit tests next to the change were updated with it, and its own new
"returns no provider-native tool names for unsupported providers" case
moved the unsupported example to google. These three were missed.

Keep each assertion's original intent by pointing it at a combination that
is still genuinely unsupported: OpenAI exposes a native web_search but no
native web_fetch, so the inventory tests now require the supported half to
be advertised and the unsupported half to be dropped. That is a stronger
check than the previous one, which only proved a provider with zero native
tools contributes nothing.
kojiwakayama added a commit that referenced this pull request Aug 2, 2026
* fix(agent): harden hosted runtime contracts

* fix(provider): harden runtime catalog contracts

* fix(provider): restore the built-in local model provider

The runtime catalog rewrite dropped the `local` shared registration while
converting the guarded `if (!manager.has(...))` blocks into unconditional
ones, so every `local/...` model string failed to resolve. Nothing replaced
it: `resolveRuntimeModel()` still passes `local/` through untouched, and
`createLocalModel()` already exposes the generic `prepare()` hook that
`ensureModelReady()` was refactored to call.

Re-register `local` alongside the other shared providers and cover
credential-free resolution so the regression cannot return.

* fix(provider): stop double-encoding string tool values

`stringifyJsonValue()` lost its string pass-through, so plain-string tool
results were JSON.stringify'd into quote-wrapped text before reaching
OpenAI-compatible messages, Anthropic tool_result blocks, and OpenAI
Responses output.

Restore the pass-through ahead of the undefined-serialization guard the
rewrite added, keeping both behaviours.

* test(agent): align inventory expectations with OpenAI native search

Enabling the OpenAI provider-native web_search left three tests asserting
the previous behaviour, where `openai` exposed no provider-native tools at
all. They failed because `web_search` now correctly reaches the runtime
inventory and the fork availability list.

The unit tests next to the change were updated with it, and its own new
"returns no provider-native tool names for unsupported providers" case
moved the unsupported example to google. These three were missed.

Keep each assertion's original intent by pointing it at a combination that
is still genuinely unsupported: OpenAI exposes a native web_search but no
native web_fetch, so the inventory tests now require the supported half to
be advertised and the unsupported half to be dropped. That is a stronger
check than the previous one, which only proved a provider with zero native
tools contributes nothing.
kojiwakayama added a commit that referenced this pull request Aug 2, 2026
* fix(agent): harden hosted runtime contracts

* fix(provider): harden runtime catalog contracts

* fix(provider): restore the built-in local model provider

The runtime catalog rewrite dropped the `local` shared registration while
converting the guarded `if (!manager.has(...))` blocks into unconditional
ones, so every `local/...` model string failed to resolve. Nothing replaced
it: `resolveRuntimeModel()` still passes `local/` through untouched, and
`createLocalModel()` already exposes the generic `prepare()` hook that
`ensureModelReady()` was refactored to call.

Re-register `local` alongside the other shared providers and cover
credential-free resolution so the regression cannot return.

* fix(provider): stop double-encoding string tool values

`stringifyJsonValue()` lost its string pass-through, so plain-string tool
results were JSON.stringify'd into quote-wrapped text before reaching
OpenAI-compatible messages, Anthropic tool_result blocks, and OpenAI
Responses output.

Restore the pass-through ahead of the undefined-serialization guard the
rewrite added, keeping both behaviours.

* test(agent): align inventory expectations with OpenAI native search

Enabling the OpenAI provider-native web_search left three tests asserting
the previous behaviour, where `openai` exposed no provider-native tools at
all. They failed because `web_search` now correctly reaches the runtime
inventory and the fork availability list.

The unit tests next to the change were updated with it, and its own new
"returns no provider-native tool names for unsupported providers" case
moved the unsupported example to google. These three were missed.

Keep each assertion's original intent by pointing it at a combination that
is still genuinely unsupported: OpenAI exposes a native web_search but no
native web_fetch, so the inventory tests now require the supported half to
be advertised and the unsupported half to be dropped. That is a stronger
check than the previous one, which only proved a provider with zero native
tools contributes nothing.
kojiwakayama added a commit that referenced this pull request Aug 2, 2026
* fix(agent): harden hosted runtime contracts

* fix(provider): harden runtime catalog contracts

* fix(provider): restore the built-in local model provider

The runtime catalog rewrite dropped the `local` shared registration while
converting the guarded `if (!manager.has(...))` blocks into unconditional
ones, so every `local/...` model string failed to resolve. Nothing replaced
it: `resolveRuntimeModel()` still passes `local/` through untouched, and
`createLocalModel()` already exposes the generic `prepare()` hook that
`ensureModelReady()` was refactored to call.

Re-register `local` alongside the other shared providers and cover
credential-free resolution so the regression cannot return.

* fix(provider): stop double-encoding string tool values

`stringifyJsonValue()` lost its string pass-through, so plain-string tool
results were JSON.stringify'd into quote-wrapped text before reaching
OpenAI-compatible messages, Anthropic tool_result blocks, and OpenAI
Responses output.

Restore the pass-through ahead of the undefined-serialization guard the
rewrite added, keeping both behaviours.

* test(agent): align inventory expectations with OpenAI native search

Enabling the OpenAI provider-native web_search left three tests asserting
the previous behaviour, where `openai` exposed no provider-native tools at
all. They failed because `web_search` now correctly reaches the runtime
inventory and the fork availability list.

The unit tests next to the change were updated with it, and its own new
"returns no provider-native tool names for unsupported providers" case
moved the unsupported example to google. These three were missed.

Keep each assertion's original intent by pointing it at a combination that
is still genuinely unsupported: OpenAI exposes a native web_search but no
native web_fetch, so the inventory tests now require the supported half to
be advertised and the unsupported half to be dropped. That is a stronger
check than the previous one, which only proved a provider with zero native
tools contributes nothing.
kojiwakayama added a commit that referenced this pull request Aug 2, 2026
* fix(agent): harden hosted runtime contracts

* fix(provider): harden runtime catalog contracts

* fix(provider): restore the built-in local model provider

The runtime catalog rewrite dropped the `local` shared registration while
converting the guarded `if (!manager.has(...))` blocks into unconditional
ones, so every `local/...` model string failed to resolve. Nothing replaced
it: `resolveRuntimeModel()` still passes `local/` through untouched, and
`createLocalModel()` already exposes the generic `prepare()` hook that
`ensureModelReady()` was refactored to call.

Re-register `local` alongside the other shared providers and cover
credential-free resolution so the regression cannot return.

* fix(provider): stop double-encoding string tool values

`stringifyJsonValue()` lost its string pass-through, so plain-string tool
results were JSON.stringify'd into quote-wrapped text before reaching
OpenAI-compatible messages, Anthropic tool_result blocks, and OpenAI
Responses output.

Restore the pass-through ahead of the undefined-serialization guard the
rewrite added, keeping both behaviours.

* test(agent): align inventory expectations with OpenAI native search

Enabling the OpenAI provider-native web_search left three tests asserting
the previous behaviour, where `openai` exposed no provider-native tools at
all. They failed because `web_search` now correctly reaches the runtime
inventory and the fork availability list.

The unit tests next to the change were updated with it, and its own new
"returns no provider-native tool names for unsupported providers" case
moved the unsupported example to google. These three were missed.

Keep each assertion's original intent by pointing it at a combination that
is still genuinely unsupported: OpenAI exposes a native web_search but no
native web_fetch, so the inventory tests now require the supported half to
be advertised and the unsupported half to be dropped. That is a stronger
check than the previous one, which only proved a provider with zero native
tools contributes nothing.
kojiwakayama added a commit that referenced this pull request Aug 2, 2026
* fix(agent): harden hosted runtime contracts

* fix(provider): harden runtime catalog contracts

* fix(provider): restore the built-in local model provider

The runtime catalog rewrite dropped the `local` shared registration while
converting the guarded `if (!manager.has(...))` blocks into unconditional
ones, so every `local/...` model string failed to resolve. Nothing replaced
it: `resolveRuntimeModel()` still passes `local/` through untouched, and
`createLocalModel()` already exposes the generic `prepare()` hook that
`ensureModelReady()` was refactored to call.

Re-register `local` alongside the other shared providers and cover
credential-free resolution so the regression cannot return.

* fix(provider): stop double-encoding string tool values

`stringifyJsonValue()` lost its string pass-through, so plain-string tool
results were JSON.stringify'd into quote-wrapped text before reaching
OpenAI-compatible messages, Anthropic tool_result blocks, and OpenAI
Responses output.

Restore the pass-through ahead of the undefined-serialization guard the
rewrite added, keeping both behaviours.

* test(agent): align inventory expectations with OpenAI native search

Enabling the OpenAI provider-native web_search left three tests asserting
the previous behaviour, where `openai` exposed no provider-native tools at
all. They failed because `web_search` now correctly reaches the runtime
inventory and the fork availability list.

The unit tests next to the change were updated with it, and its own new
"returns no provider-native tool names for unsupported providers" case
moved the unsupported example to google. These three were missed.

Keep each assertion's original intent by pointing it at a combination that
is still genuinely unsupported: OpenAI exposes a native web_search but no
native web_fetch, so the inventory tests now require the supported half to
be advertised and the unsupported half to be dropped. That is a stronger
check than the previous one, which only proved a provider with zero native
tools contributes nothing.
kojiwakayama added a commit that referenced this pull request Aug 2, 2026
* fix(agent): harden hosted runtime contracts

* fix(provider): harden runtime catalog contracts

* fix(provider): restore the built-in local model provider

The runtime catalog rewrite dropped the `local` shared registration while
converting the guarded `if (!manager.has(...))` blocks into unconditional
ones, so every `local/...` model string failed to resolve. Nothing replaced
it: `resolveRuntimeModel()` still passes `local/` through untouched, and
`createLocalModel()` already exposes the generic `prepare()` hook that
`ensureModelReady()` was refactored to call.

Re-register `local` alongside the other shared providers and cover
credential-free resolution so the regression cannot return.

* fix(provider): stop double-encoding string tool values

`stringifyJsonValue()` lost its string pass-through, so plain-string tool
results were JSON.stringify'd into quote-wrapped text before reaching
OpenAI-compatible messages, Anthropic tool_result blocks, and OpenAI
Responses output.

Restore the pass-through ahead of the undefined-serialization guard the
rewrite added, keeping both behaviours.

* test(agent): align inventory expectations with OpenAI native search

Enabling the OpenAI provider-native web_search left three tests asserting
the previous behaviour, where `openai` exposed no provider-native tools at
all. They failed because `web_search` now correctly reaches the runtime
inventory and the fork availability list.

The unit tests next to the change were updated with it, and its own new
"returns no provider-native tool names for unsupported providers" case
moved the unsupported example to google. These three were missed.

Keep each assertion's original intent by pointing it at a combination that
is still genuinely unsupported: OpenAI exposes a native web_search but no
native web_fetch, so the inventory tests now require the supported half to
be advertised and the unsupported half to be dropped. That is a stronger
check than the previous one, which only proved a provider with zero native
tools contributes nothing.
kojiwakayama added a commit that referenced this pull request Aug 2, 2026
* fix(agent): harden hosted runtime contracts

* fix(provider): harden runtime catalog contracts

* fix(provider): restore the built-in local model provider

The runtime catalog rewrite dropped the `local` shared registration while
converting the guarded `if (!manager.has(...))` blocks into unconditional
ones, so every `local/...` model string failed to resolve. Nothing replaced
it: `resolveRuntimeModel()` still passes `local/` through untouched, and
`createLocalModel()` already exposes the generic `prepare()` hook that
`ensureModelReady()` was refactored to call.

Re-register `local` alongside the other shared providers and cover
credential-free resolution so the regression cannot return.

* fix(provider): stop double-encoding string tool values

`stringifyJsonValue()` lost its string pass-through, so plain-string tool
results were JSON.stringify'd into quote-wrapped text before reaching
OpenAI-compatible messages, Anthropic tool_result blocks, and OpenAI
Responses output.

Restore the pass-through ahead of the undefined-serialization guard the
rewrite added, keeping both behaviours.

* test(agent): align inventory expectations with OpenAI native search

Enabling the OpenAI provider-native web_search left three tests asserting
the previous behaviour, where `openai` exposed no provider-native tools at
all. They failed because `web_search` now correctly reaches the runtime
inventory and the fork availability list.

The unit tests next to the change were updated with it, and its own new
"returns no provider-native tool names for unsupported providers" case
moved the unsupported example to google. These three were missed.

Keep each assertion's original intent by pointing it at a combination that
is still genuinely unsupported: OpenAI exposes a native web_search but no
native web_fetch, so the inventory tests now require the supported half to
be advertised and the unsupported half to be dropped. That is a stronger
check than the previous one, which only proved a provider with zero native
tools contributes nothing.
kojiwakayama added a commit that referenced this pull request Aug 2, 2026
* fix(agent): harden hosted runtime contracts

* fix(provider): harden runtime catalog contracts

* fix(provider): restore the built-in local model provider

The runtime catalog rewrite dropped the `local` shared registration while
converting the guarded `if (!manager.has(...))` blocks into unconditional
ones, so every `local/...` model string failed to resolve. Nothing replaced
it: `resolveRuntimeModel()` still passes `local/` through untouched, and
`createLocalModel()` already exposes the generic `prepare()` hook that
`ensureModelReady()` was refactored to call.

Re-register `local` alongside the other shared providers and cover
credential-free resolution so the regression cannot return.

* fix(provider): stop double-encoding string tool values

`stringifyJsonValue()` lost its string pass-through, so plain-string tool
results were JSON.stringify'd into quote-wrapped text before reaching
OpenAI-compatible messages, Anthropic tool_result blocks, and OpenAI
Responses output.

Restore the pass-through ahead of the undefined-serialization guard the
rewrite added, keeping both behaviours.

* test(agent): align inventory expectations with OpenAI native search

Enabling the OpenAI provider-native web_search left three tests asserting
the previous behaviour, where `openai` exposed no provider-native tools at
all. They failed because `web_search` now correctly reaches the runtime
inventory and the fork availability list.

The unit tests next to the change were updated with it, and its own new
"returns no provider-native tool names for unsupported providers" case
moved the unsupported example to google. These three were missed.

Keep each assertion's original intent by pointing it at a combination that
is still genuinely unsupported: OpenAI exposes a native web_search but no
native web_fetch, so the inventory tests now require the supported half to
be advertised and the unsupported half to be dropped. That is a stronger
check than the previous one, which only proved a provider with zero native
tools contributes nothing.
kojiwakayama added a commit that referenced this pull request Aug 2, 2026
* fix(agent): harden hosted runtime contracts

* fix(provider): harden runtime catalog contracts

* fix(provider): restore the built-in local model provider

The runtime catalog rewrite dropped the `local` shared registration while
converting the guarded `if (!manager.has(...))` blocks into unconditional
ones, so every `local/...` model string failed to resolve. Nothing replaced
it: `resolveRuntimeModel()` still passes `local/` through untouched, and
`createLocalModel()` already exposes the generic `prepare()` hook that
`ensureModelReady()` was refactored to call.

Re-register `local` alongside the other shared providers and cover
credential-free resolution so the regression cannot return.

* fix(provider): stop double-encoding string tool values

`stringifyJsonValue()` lost its string pass-through, so plain-string tool
results were JSON.stringify'd into quote-wrapped text before reaching
OpenAI-compatible messages, Anthropic tool_result blocks, and OpenAI
Responses output.

Restore the pass-through ahead of the undefined-serialization guard the
rewrite added, keeping both behaviours.

* test(agent): align inventory expectations with OpenAI native search

Enabling the OpenAI provider-native web_search left three tests asserting
the previous behaviour, where `openai` exposed no provider-native tools at
all. They failed because `web_search` now correctly reaches the runtime
inventory and the fork availability list.

The unit tests next to the change were updated with it, and its own new
"returns no provider-native tool names for unsupported providers" case
moved the unsupported example to google. These three were missed.

Keep each assertion's original intent by pointing it at a combination that
is still genuinely unsupported: OpenAI exposes a native web_search but no
native web_fetch, so the inventory tests now require the supported half to
be advertised and the unsupported half to be dropped. That is a stronger
check than the previous one, which only proved a provider with zero native
tools contributes nothing.
kojiwakayama added a commit that referenced this pull request Aug 2, 2026
* fix(agent): harden hosted runtime contracts

* fix(provider): harden runtime catalog contracts

* fix(provider): restore the built-in local model provider

The runtime catalog rewrite dropped the `local` shared registration while
converting the guarded `if (!manager.has(...))` blocks into unconditional
ones, so every `local/...` model string failed to resolve. Nothing replaced
it: `resolveRuntimeModel()` still passes `local/` through untouched, and
`createLocalModel()` already exposes the generic `prepare()` hook that
`ensureModelReady()` was refactored to call.

Re-register `local` alongside the other shared providers and cover
credential-free resolution so the regression cannot return.

* fix(provider): stop double-encoding string tool values

`stringifyJsonValue()` lost its string pass-through, so plain-string tool
results were JSON.stringify'd into quote-wrapped text before reaching
OpenAI-compatible messages, Anthropic tool_result blocks, and OpenAI
Responses output.

Restore the pass-through ahead of the undefined-serialization guard the
rewrite added, keeping both behaviours.

* test(agent): align inventory expectations with OpenAI native search

Enabling the OpenAI provider-native web_search left three tests asserting
the previous behaviour, where `openai` exposed no provider-native tools at
all. They failed because `web_search` now correctly reaches the runtime
inventory and the fork availability list.

The unit tests next to the change were updated with it, and its own new
"returns no provider-native tool names for unsupported providers" case
moved the unsupported example to google. These three were missed.

Keep each assertion's original intent by pointing it at a combination that
is still genuinely unsupported: OpenAI exposes a native web_search but no
native web_fetch, so the inventory tests now require the supported half to
be advertised and the unsupported half to be dropped. That is a stronger
check than the previous one, which only proved a provider with zero native
tools contributes nothing.
kojiwakayama added a commit that referenced this pull request Aug 2, 2026
* fix(agent): harden hosted runtime contracts

* fix(provider): harden runtime catalog contracts

* fix(provider): restore the built-in local model provider

The runtime catalog rewrite dropped the `local` shared registration while
converting the guarded `if (!manager.has(...))` blocks into unconditional
ones, so every `local/...` model string failed to resolve. Nothing replaced
it: `resolveRuntimeModel()` still passes `local/` through untouched, and
`createLocalModel()` already exposes the generic `prepare()` hook that
`ensureModelReady()` was refactored to call.

Re-register `local` alongside the other shared providers and cover
credential-free resolution so the regression cannot return.

* fix(provider): stop double-encoding string tool values

`stringifyJsonValue()` lost its string pass-through, so plain-string tool
results were JSON.stringify'd into quote-wrapped text before reaching
OpenAI-compatible messages, Anthropic tool_result blocks, and OpenAI
Responses output.

Restore the pass-through ahead of the undefined-serialization guard the
rewrite added, keeping both behaviours.

* test(agent): align inventory expectations with OpenAI native search

Enabling the OpenAI provider-native web_search left three tests asserting
the previous behaviour, where `openai` exposed no provider-native tools at
all. They failed because `web_search` now correctly reaches the runtime
inventory and the fork availability list.

The unit tests next to the change were updated with it, and its own new
"returns no provider-native tool names for unsupported providers" case
moved the unsupported example to google. These three were missed.

Keep each assertion's original intent by pointing it at a combination that
is still genuinely unsupported: OpenAI exposes a native web_search but no
native web_fetch, so the inventory tests now require the supported half to
be advertised and the unsupported half to be dropped. That is a stronger
check than the previous one, which only proved a provider with zero native
tools contributes nothing.
kojiwakayama added a commit that referenced this pull request Aug 3, 2026
* fix(agent): harden hosted runtime contracts

* fix(provider): harden runtime catalog contracts

* fix(provider): restore the built-in local model provider

The runtime catalog rewrite dropped the `local` shared registration while
converting the guarded `if (!manager.has(...))` blocks into unconditional
ones, so every `local/...` model string failed to resolve. Nothing replaced
it: `resolveRuntimeModel()` still passes `local/` through untouched, and
`createLocalModel()` already exposes the generic `prepare()` hook that
`ensureModelReady()` was refactored to call.

Re-register `local` alongside the other shared providers and cover
credential-free resolution so the regression cannot return.

* fix(provider): stop double-encoding string tool values

`stringifyJsonValue()` lost its string pass-through, so plain-string tool
results were JSON.stringify'd into quote-wrapped text before reaching
OpenAI-compatible messages, Anthropic tool_result blocks, and OpenAI
Responses output.

Restore the pass-through ahead of the undefined-serialization guard the
rewrite added, keeping both behaviours.

* test(agent): align inventory expectations with OpenAI native search

Enabling the OpenAI provider-native web_search left three tests asserting
the previous behaviour, where `openai` exposed no provider-native tools at
all. They failed because `web_search` now correctly reaches the runtime
inventory and the fork availability list.

The unit tests next to the change were updated with it, and its own new
"returns no provider-native tool names for unsupported providers" case
moved the unsupported example to google. These three were missed.

Keep each assertion's original intent by pointing it at a combination that
is still genuinely unsupported: OpenAI exposes a native web_search but no
native web_fetch, so the inventory tests now require the supported half to
be advertised and the unsupported half to be dropped. That is a stronger
check than the previous one, which only proved a provider with zero native
tools contributes nothing.
kojiwakayama added a commit that referenced this pull request Aug 3, 2026
* fix(agent): harden hosted runtime contracts

* fix(provider): harden runtime catalog contracts

* fix(provider): restore the built-in local model provider

The runtime catalog rewrite dropped the `local` shared registration while
converting the guarded `if (!manager.has(...))` blocks into unconditional
ones, so every `local/...` model string failed to resolve. Nothing replaced
it: `resolveRuntimeModel()` still passes `local/` through untouched, and
`createLocalModel()` already exposes the generic `prepare()` hook that
`ensureModelReady()` was refactored to call.

Re-register `local` alongside the other shared providers and cover
credential-free resolution so the regression cannot return.

* fix(provider): stop double-encoding string tool values

`stringifyJsonValue()` lost its string pass-through, so plain-string tool
results were JSON.stringify'd into quote-wrapped text before reaching
OpenAI-compatible messages, Anthropic tool_result blocks, and OpenAI
Responses output.

Restore the pass-through ahead of the undefined-serialization guard the
rewrite added, keeping both behaviours.

* test(agent): align inventory expectations with OpenAI native search

Enabling the OpenAI provider-native web_search left three tests asserting
the previous behaviour, where `openai` exposed no provider-native tools at
all. They failed because `web_search` now correctly reaches the runtime
inventory and the fork availability list.

The unit tests next to the change were updated with it, and its own new
"returns no provider-native tool names for unsupported providers" case
moved the unsupported example to google. These three were missed.

Keep each assertion's original intent by pointing it at a combination that
is still genuinely unsupported: OpenAI exposes a native web_search but no
native web_fetch, so the inventory tests now require the supported half to
be advertised and the unsupported half to be dropped. That is a stronger
check than the previous one, which only proved a provider with zero native
tools contributes nothing.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants