fix(openai-chat): strip the Responses-only encrypted tool annotation - #1779
Conversation
Codex multi-agent v2 stamps a Responses-only 'encrypted: true' marker on collaboration tool schemas. Forwarded verbatim to a generic openai-chat upstream, the provider returned spawn_agent calls with the required message argument empty. Strip the marker at the protocol boundary rather than per provider name, and share one implementation with the Anthropic path. Properties and definitions literally named 'encrypted' survive, and literal payloads under const, default, enum, and examples are left untouched. The walk is iterative over an explicit stack. Schemas are caller-supplied, so depth is attacker-influenced and a recursive walk would answer a deep schema with a stack overflow on the request path; a 50k-deep regression covers it. Closes #1774 Co-authored-by: ZHJay <ZHJay@users.noreply.github.com>
|
✅ Deterministic PR hygiene checks passed. |
|
Caution Review failedThe pull request is closed. ℹ️ Recent review info⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: ASSERTIVE Plan: Pro Plus Run ID: 📒 Files selected for processing (4)
📝 WalkthroughWalkthroughThe change adds a shared, iterative sanitizer for Responses-only ChangesEncrypted marker sanitization
Estimated code review effort: 3 (Moderate) | ~25 minutes Sequence Diagram(s)sequenceDiagram
participant OpenAIChatAdapter
participant SchemaSanitizer
participant ChatCompletionsSerializer
OpenAIChatAdapter->>SchemaSanitizer: sanitize tool parameter schema
SchemaSanitizer-->>OpenAIChatAdapter: return schema without Responses-only markers
OpenAIChatAdapter->>ChatCompletionsSerializer: serialize normalized tool schema
Possibly related PRs
Suggested labels: Suggested reviewers: ✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
…idge-jun#1779) Codex multi-agent v2 stamps a Responses-only 'encrypted: true' marker on collaboration tool schemas. Forwarded verbatim to a generic openai-chat upstream, the provider returned spawn_agent calls with the required message argument empty. Strip the marker at the protocol boundary rather than per provider name, and share one implementation with the Anthropic path. Properties and definitions literally named 'encrypted' survive, and literal payloads under const, default, enum, and examples are left untouched. The walk is iterative over an explicit stack. Schemas are caller-supplied, so depth is attacker-influenced and a recursive walk would answer a deep schema with a stack overflow on the request path; a 50k-deep regression covers it. Closes lidge-jun#1774 Co-authored-by: ZHJay <ZHJay@users.noreply.github.com>
Summary
Codex multi-agent v2 stamps a Responses-only
encrypted: truemarker on collaboration tool schemas. Forwarded verbatim to a genericopenai-chatupstream, the provider returnedspawn_agentcalls with the requiredmessageargument empty.This lands @ZHJay's #1776 with one blocking fix. The marker is stripped at the protocol boundary rather than per provider name, sharing one implementation with the Anthropic path. Properties and definitions literally named
encryptedsurvive, and literal payloads underconst,default,enum, andexamplesare untouched.The traversal is now iterative over an explicit stack. Tool schemas are caller-supplied, so nesting depth is attacker-influenced, and the recursive version in #1776 would have answered a deep schema with a stack overflow on the request path.
Closes #1774
Verification
Run on the Linux validation host against this exact head:
bun x tsc --noEmitclean. The expect() count reflects a new 50,000-deep schema regression that walks every level to prove the strip is both correct and bounded.Checklist
bun x tsc --noEmitcleanSummary by CodeRabbit
Bug Fixes
Tests