Skip to content

fix(stream): hold a bare </>/< followed only by whitespace - #26

Merged
senamakel merged 1 commit into
mainfrom
fix/dsml-stream-whitespace-hold
Sep 25, 2026
Merged

senamakel merged 1 commit into
mainfrom
fix/dsml-stream-whitespace-hold

Conversation

@graycyrus

Copy link
Copy Markdown
Contributor

Summary

Follow-up to #25, which already merged before this finding was addressed. TinySweeper correctly flagged a real streaming regression in that PR: the complete-tag regex now accepts a space before the DSML/namespace marker (< | DSML | invoke), but the streaming scrubber's hold-back list (hold_from in stream/mod.rs) only matched fixed literal opener prefixes ("<invoke ", "<|DSML", ...). None of those start with a space, so a fragment boundary landing on "< " (bracket plus whitespace, marker not arrived yet) was released as plain text — and once split from its bracket, the marker that followed could never complete an opener, silently dropping the call.

Fix

Added trailing_bare_angle_bracket: holds a < or </ at the very end of the buffered tail when it is followed only by whitespace so far. Self-correcting once more text arrives — it only re-fires while the tail's end still looks like a bare bracket with nothing conclusive after it, mirroring how a lone < was already held before this gap.

Test plan

  • New test a_whitespace_prefixed_dsml_opener_split_before_the_marker_is_held reproduces TinySweeper's exact scenario (feed "< ", then the rest) — fails without the fix, passes with it.
  • cargo test -p tinytools-agent: 323 passed, including plural_tool_calls_prose_is_not_held (confirms ordinary < in prose is unaffected).
  • cargo fmt --all -- --check: clean.
  • cargo clippy --all-targets --all-features -- -D warnings: clean.

Ref: #25 (discussion: #25 (comment))

TinySweeper flagged a real streaming regression in the prior commit:
the complete-tag regex now accepts a space before the DSML/namespace
marker (`< | DSML | invoke`), but the streaming scrubber's hold-back
list only matched fixed literal opener prefixes ("<invoke ", "<|DSML",
...). None of those start with a space, so a fragment boundary landing
on "< " (bracket plus whitespace, marker not arrived yet) released it
as plain text — and once split from its bracket, the marker that
followed could never complete an opener, silently dropping the call.

Add `trailing_bare_angle_bracket`: hold a `<` or `</` at the very end
of the buffered tail when it is followed only by whitespace so far.
Self-correcting once more text arrives — it only re-fires while the
tail's end still looks like a bare bracket with nothing conclusive
after it, exactly mirroring how a lone `<` was already held before
this gap.

Test plan:
- New test `a_whitespace_prefixed_dsml_opener_split_before_the_marker_is_held`
  reproduces TinySweeper's exact scenario (feed "< ", then the rest) —
  fails without the fix, passes with it.
- `cargo test -p tinytools-agent`: 323 passed, including
  `plural_tool_calls_prose_is_not_held` (confirms ordinary `<` in
  prose is unaffected).
- `cargo fmt --all -- --check`: clean.
- `cargo clippy --all-targets --all-features -- -D warnings`: clean.
@coderabbitai

coderabbitai Bot commented Sep 25, 2026

Copy link
Copy Markdown

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: 7e7d776d-08f2-4d35-9ec1-bb6fab9f1274


Comment @coderabbitai help to get the list of available commands.

@tinysweeper

tinysweeper Bot commented Sep 25, 2026 •

Copy link
Copy Markdown

Tiny Sweeper review

Tiny Sweeper reviewed this change across 6 lane(s) and found 1 active actionable finding(s). Detailed lane evidence and any incomplete work are listed below.

State: Changes requested
Priority: high
Reviewed head: 8128019680df
Updated: 1790333236 (Unix time)

Review snapshot

Change surface Files Review signal Count
Production 1 Active findings 1
Tests 1 Noted findings 0
Documentation 0 Resolved findings 0
Configuration 0 Pending checks/questions 0

Completeness: Complete
Test assessment: No supported feature-to-test mapping was available; this does not mean tests are absent or passed.

What changed

The review could not produce a supported behavioral summary; inspect the cited changed surface and lane details below.

Features

None identified with supported citations.

Tests

No supported feature-to-test mapping was produced. Test execution is not inferred.

Findings

  • high · critique · Hold partially received XML prefixes after the bracket — This only detects a trailing `<` or `</`, so it stops protecting the opener as soon as any prefix character arrives. For example, feeding `"< | DSML | D"` or `"< atem:"` releases t (crates/tinytools\-agent/src/stream/mod\.rs:170)

Before merge

  • Address Hold partially received XML prefixes after the bracket (crates/tinytools\-agent/src/stream/mod\.rs).

How this fits together

flowchart LR
  n0["hold_from<br/>changed<br/>1 finding"]:::blocking
  n1["dsml_split_across_fragments_is_scrubbed<br/>changed"]:::changed
  n2["len"]:::impacted
  n3["feed"]:::impacted
  n4["scrub_all"]:::impacted
  n5["flush"]:::impacted
  n6["...d_string_is_released_once_and_never_shown"]:::impacted
  n7["options"]:::impacted
  n0 -->|calls| n2
  n1 -->|calls| n4
  n1 -->|tests| n4
  n3 -->|calls| n0
  n3 -->|calls| n2
  n3 -->|calls| n7
  n4 -->|calls| n2
  n4 -->|calls| n3
  n4 -->|calls| n5
  n5 -->|calls| n7
  n6 -->|calls| n3
  n6 -->|tests| n3
  n6 -->|calls| n5
  n6 -->|tests| n5
  classDef changed fill:#0d4429,stroke:#238636,color:#e6edf3
  classDef impacted fill:#161b22,stroke:#6e7681,color:#c9d1d9
  classDef flagged fill:#5a1e02,stroke:#d93f0b,color:#ffffff
  classDef blocking fill:#67060c,stroke:#f85149,color:#ffffff
Loading
Agent review details

critique

  • Conclusion: Failure
  • Scope reviewed: all assigned evidence
  • Lane summary: The change correctly holds a fragment ending immediately after `<` or `</`, but it still loses valid whitespace-prefixed DSML and namespaced openers when the boundary occurs after part of the prefix. It is not safe to merge without covering those partial prefixes. _The code index is behind this pull request (indexed at `81def795a27d`), so retrieved context may be out of date._ _Memory was unavailable (model: cortex: v1/recall: timed out after 10s), so this review ran without it._
  • Evidence: crates/tinytools\-agent/src/stream/mod\.rs — Hold partially received XML prefixes after the bracket

security

  • Conclusion: Success
  • Scope reviewed: all assigned evidence
  • Lane summary: The streaming scrubber now retains incomplete angle-bracket openers that may begin whitespace-tolerant invoke-XML blocks. The change is narrowly scoped, covered by a regression test, and safe to merge. _The code index is behind this pull request (indexed at `81def795a27d`), so retrieved context may be out of date._ _Memory was unavailable (model: cortex: v1/recall: timed out after 10s), so this review ran without it._

tests

  • Conclusion: Success
  • Scope reviewed: all assigned evidence
  • Lane summary: Adds a function to detect trailing `<` or `</` followed only by whitespace, so the stream scrubber holds back fragments that might be the start of a whitespace-prefixed DSML/namespace opener. The change is correct and the test exercises the new behaviour. _The code index is behind this pull request (indexed at `81def795a27d`), so retrieved context may be out of date._ _Memory was unavailable (model: cortex: v1/recall: timed out after 10s), so this review ran without it._

commits

  • Conclusion: Neutral
  • Scope reviewed: all assigned evidence
  • Lane summary: Nothing sensitive found in what this pull request commits.

description

  • Conclusion: Success
  • Scope reviewed: all assigned evidence
  • Lane summary: Adds a trailing-bare-angle-bracket check to the stream scrubber's hold-back logic so that a `<` or `</` followed only by whitespace is held across fragment boundaries, preventing silent loss of DSML openers when the marker is delayed. The code is correct, well-tested, and follows the repository's style rules. _The code index is behind this pull request (indexed at `81def795a27d`), so retrieved context may be out of date._ _Memory was unavailable (model: cortex: v1/recall: timed out after 10s), so this review ran without it._

e2e

  • Conclusion: Neutral
  • Scope reviewed: all assigned evidence
  • Lane summary: No end-to-end harness in this repository: no e2e test files and no e2e workflow.
Evidence and run details
  • Models: ladder/vectors, gpt-5.6-luna, deepseek/deepseek-v4-flash
  • Spend: $0.004552
  • Tokens: 82754 input · 13732 output · 20366 cached · 276 embedding
Head State Pass summary
8128019680df changes requested 1 active finding(s), 0 resolved finding(s) (at 1790333236)

tinysweeper 0.1.0

@tinysweeper tinysweeper Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Requesting changes: 1 lane(s) blocking, worst finding is high.

Fix or reply to the findings below and push. The next review clears this automatically once they are gone — you should not need to dismiss anything by hand.

             $0.0046 · 82,754 in / 13,732 out · 20,366 cached (25%) · ladder/vectors, gpt-5.6-luna, deepseek/deepseek-v4-flash · 276 embedded
critique:    $0.0014 · 33,637 in / 3,429 out  · 2,881 cached (9%)   · gpt-5.6-luna, deepseek/deepseek-v4-flash
security:    $0.0007 · 29,208 in / 686 out    · 1,869 cached (6%)   · gpt-5.6-luna
tests:       $0.0011 · 13,117 in / 4,821 out  · 12,800 cached (98%) · deepseek/deepseek-v4-flash
description: $0.0005 · 4,466 in  / 1,548 out  · 2,304 cached (52%)  · deepseek/deepseek-v4-flash

/// landing on the bracket and its whitespace (`"< "`) is released as plain
/// text before the marker arrives, and the opener is unrecoverable once
/// split from its `<`.
fn trailing_bare_angle_bracket(tail: &str) -> Option<usize> {

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

priority high critique confident

Hold partially received XML prefixes after the bracket

This only detects a trailing < or </, so it stops protecting the opener as soon as any prefix character arrives. For example, feeding "< | DSML | D" or "< atem:" releases the text because the tail no longer ends in a bare angle bracket, even though both are valid prefixes of < | DSML | invoke ... and < atem:invoke ... respectively. The next fragment ("SML | invoke ..." or "invoke ...") then lacks the original <... prefix and the call is permanently lost. Hold these whitespace-prefixed DSML and namespace prefixes until they are either recognized as a complete opener or disambiguated as ordinary text.

[RULE] partial-input-loss ·

@senamakel
senamakel merged commit aa44e48 into main Sep 25, 2026
15 of 16 checks passed
@senamakel
senamakel deleted the fix/dsml-stream-whitespace-hold branch September 30, 2026 06:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants