feat(attachments): index common image metadata - #1419
Conversation
|
Note Reviews pausedIt looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the Use the following commands to manage reviews:
Use the checkboxes below for quick actions:
📝 WalkthroughWalkthroughThe attachment parser now supports bounded metadata and text parsing for images, Office packages, ZIP archives, nested email, MP3, legacy Office, and generic binary attachments. Import handling uses a 64 MiB transport limit and excludes unparsed attachments from embedding input. ChangesAttachment parsing
Estimated code review effort: 4 (Complex) | ~60 minutes Merge Risk: 🟠 High · up to The PR broadens attachment parsing and metadata indexing, but the current head still allows malformed JPEGs, nested messages, and Office XML to be processed without sufficient parser-specific resource ceilings, creating a potential availability risk from adversarial attachments. These bounds should be fixed or explicitly accepted before merge. Sequence Diagram(s)sequenceDiagram
participant EmailImportAPI
participant EmailImportService
participant AttachmentParser
participant ContentIndexer
EmailImportAPI->>EmailImportService: upload .eml up to 64 MiB
EmailImportService->>AttachmentParser: attachment MIME and payload
AttachmentParser-->>EmailImportService: metadata, text, manifest, or deferred status
EmailImportService->>ContentIndexer: parsed attachment content segment
🚥 Pre-merge checks | ✅ 4✅ Passed checks (4 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Attachment/parser evidence — current PR head:
Please perform a fresh independent review and hosted-check evaluation for this exact head. No bypass or stale approval is being used. |
|
PR governance metadata gate update for PR governance metadata gate is ready; all current-head requirements passed. |
|
@opencode-agent @cwl-noema-review please independently review exact current head |
|
@opencode-agent @cwl-noema-review please independently re-review exact current head |
|
@opencode-agent @cwl-noema-review please independently re-review exact current head |
|
@opencode-agent @cwl-noema-review please independently re-review exact current head |
|
Please run an independent review for the exact current PR head The attachment feature now accepts valid source files over 20 MiB within the signed 64 MiB import transport ceiling; the image parser's 1 MiB bound is only an animation-marker prefix scan. Local confidential-fixture audit is local-only and now reports |
|
Current-head review requested for f6b3a4c. The attachment parser changes, local fixture evidence, ADR, and focused/full tests are all bound to this exact head. The only current failed check is metadata-only review-gate state from a stale CodeRabbit CHANGES_REQUESTED review on f34d470; do not dismiss or reuse it—refresh independent review for the current SHA. |
|
@opencode-agent @cwl-noema-review Please independently review the exact current head f6b3a4c. Verify the >20MiB attachment behavior, 1MiB prefix-only image scan, 64MiB signed transport guard, generic MIME signature fallback, ADR evidence, and current Checks. Do not use mailbox fixture bytes or stale review evidence; approve only with exact-head structured adversarial validation. |
|
Current PR head is 6842a87. The 1 MiB image bound is now named IMAGE_METADATA_SCAN_PREFIX_BYTES to make the prefix-only contract explicit; parser behavior is unchanged. Focused verification on this head: 159 passed, 1 skipped; Ruff, format check, and git diff --check passed. No customer mailbox bytes were uploaded. |
|
@opencode-agent @cwl-noema-review Please independently review exact current head 6842a87. Verify >20MiB source retention, the explicitly named prefix-only image scan, 64MiB transport guard, generic signature fallback, ADR/changelog alignment, and current Checks. Do not use mailbox fixture bytes or stale review evidence. |
|
Full verification for exact current head 6842a87: 1807 passed, 32 skipped under PYTHONWARNINGS=error; focused attachment/import verification 159 passed, 1 skipped; Ruff, format, and diff checks passed. Local real-dataset audit remains local-only; no mailbox content or bytes were transmitted. |
|
Current-head review requested for 6842a87. All review, check, and local verification evidence must bind to this exact SHA; stale-head evidence must not be reused. |
|
@opencode-agent @cwl-noema-review Please review this exact current PR head only: 653acd8. Re-read the live head and current checks; validate the bounded JPEG/nested-email fixes, tests, ADRs, and no-confidential-upload boundary. Review-only: do not merge, dismiss, bypass, or auto-merge. |
|
Exact-head verification for
|
|
@opencode-agent @cwl-noema-review Please review this exact current PR head only: beb9882. Re-read the live head and validate the final attachment parser, tests, ADRs, and local-only evidence. Review-only: do not merge, dismiss, bypass, or auto-merge. |
| Fresh current-head review request. Exact head: f2e030f. Base: develop@81c105645ca6e680f5f8c15ba9c33b67eb63c48b. Scope: attachment parser registry, generic/unrecognized binary metadata, bounded Office/archive/nested-email parsing, inline-image source evidence, and related ADR/doctoring/tests. CodeGraph indexed the 478-file worktree; focused attachment parser, inline-image, import, and email parser tests pass: 176 passed in 1.21s. Boundary fixtures cover nested-email byte/depth, aggregate Office XML budget, encrypted archive members, generic MIME fallback, and PDF deferred payloads. Stale predecessor findings were rechecked against this head; no stale approval or predecessor check is being reused. Please run independent OpenCode/Noema/Strix and required checks against this exact head only, report remaining source findings with path:line, and keep the PR on the protected normal merge path. |
|
Current-head gate triage: the attachment source/security checks are passing (backend, frontend, CodeQL, Semgrep, OSV, Trivy, Bandit, image validation, and Noema). The only completed failure is the metadata-only gate run 96812447882, which reported that a CodeRabbit warning/failure comment on this SHA was blocking. The current source review evidence is predecessor-bound; this is the known stale CodeRabbit notice classification fixed by Naruon PR #1443. Strix and coverage remain pending. No source finding or force-merge condition is established; keep #1419 on normal revalidation after #1443. |
|
@coderabbitai review\n\nPlease review only exact current head f2e030f; do not reuse predecessor-head evidence. The current metadata gate is stale until this exact head receives a fresh review. |
|
|
Exact-head maintainer review disposition
|
Current-head review disposition
The predecessor reviews are being dismissed as stale after current-head verification. This is normal review-state maintenance, not an approval or branch-protection bypass. Decision remains WAIT_AND_REMEDIATE until current required Checks and independent approval are present. |
Predecessor-head findings were addressed and dispositioned on exact current head f2e030f.
|
@opencode-agent @cwl-noema-review review only exact current head f2e030f of PR #1419 against base develop@81c105645ca6e680f5f8c15ba9c33b67eb63c48b. Walk the complete attachment/image metadata diff, parser limits, inline-image provenance, migration/auth boundaries, ADR/doctoring evidence, and current hosted Checks. Publish structured exact-head verdicts with path:line evidence; approve only if source and security findings are clear. Do not merge, update branch, dismiss reviews, bypass protection, or reuse predecessor evidence. |
|
@opencode-agent @cwl-noema-review review only exact current head |
Current-head remediation
The required checks are pending for this exact head and the PR still needs a current qualifying review. No merge or bypass is requested while those normal gates are incomplete. |
Current-head review disposition
The informational threads are being resolved after this disposition; no approval or check is being fabricated. |
Exact-head check disposition —
|
Exact-head maintenance audit
Normal OpenCode review and scheduler dispatches are requested for this head. Protected auto-merge will be used after the hosted gates pass. |
Summary
image_metadataattachment parser for PNG, JPEG, GIF, and BMP.Real local evidence
A private local
tests/real_datasetsaudit was run without uploading or sharing message, attachment, filename, or content:parsedfalseThis is aggregate and bounded sample evidence; it does not claim that every private attachment was parsed.
Verification
PYTHONWARNINGS=error python3 -m pytest -qfrombackend:1829 passed, 32 skippedpython3 -m pytest -q tests/test_attachment_parser.py:69 passedgit diff --check: passedattachment_parser.pybranch coverage:100%No real mailbox content or attachment bytes were sent to an external provider. OCR, captioning, and object detection remain deferred to a configured local vision sidecar per ADR-0012.
Summary by CodeRabbit
New Features
Bug Fixes
Documentation
Attachment size contract
The 1 MiB image prefix is only an animation-marker scan window, not an attachment-size limit. Image metadata parsing does not reject a payload solely because it is larger than 20 MiB; JPEG header inspection has its own bounded 4 MiB scan. Office packages with embedded media larger than 20 MiB remain admissible when the selected XML safety budgets are satisfied. The signed import transport keeps a separate 64 MiB request-resource guard, and tests cover source uploads over 20 MiB.