Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion contracts/inline-image-inputs.md
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@ URL accepts only data:image/png|jpeg|webp|gif;base64,<nonempty canonical standar

Public normalization captures fixed array positions and type/URL/detail primitives once; snapshots freeze complete parts, image objects, arrays and messages before async routing/credentials. Invalid first values never retry/coerce into valid later ones. Direct OpenAI and delegated OpenRouter retain the captured wire arrays on nonstream and existing text/refusal/function streams. Preserve exact approved model/provider.only/final-provider scope and fixed provider hosts. No gateway image retrieval, arbitrary-host proxy, local file read, resizing, model capability inference or output-image support is introduced.

Any image history combined with request cache_control, prompt_cache_options, text block directives/breakpoints or marked tools rejects as an explicit local restriction. Existing text/cache/refusal/function history behavior stays unchanged. Direct Anthropic/Gemini images reject before secret resolution and upstream calls; exported native history converters also reject rather than sending OpenAI blocks or dropping image semantics. Native image mappings, remote references, richer/mixed content and image cache controls require follow-up work.
Any image history combined with request cache_control, prompt_cache_options, text block directives/breakpoints or marked tools rejects as an explicit local restriction. Existing text/cache/refusal/function history behavior stays unchanged. Issue #468 adds the omitted-detail native subset in [native inline images](native-inline-images.md); unsupported native detail/MIME/count/role/cache combinations still reject before secret resolution and upstream calls. Remote references, broader native mappings, richer/mixed content and image cache controls require follow-up work.

A managed Jev configuration with sendPrompt:true rejects an image history with a safe route-unavailable response before selector credentials/calls. The existing text-only selector projection cannot silently omit image data or invent a multimodal disclosure policy. sendPrompt:false continues metadata-only eligible-candidate selection; neither path grants an unevaluated destination. Jev policy #7 remains unresolved.

Expand Down
17 changes: 17 additions & 0 deletions contracts/native-inline-images.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,17 @@
# Bounded native inline image inputs

Both chat bases support the selected user image_url subset on direct Anthropic and Gemini routes across nonstream completions, text streams and custom-function streams. Detail must be omitted; every supplied auto/low/high detail rejects before secret resolution and upstream contact. No native resolution control is invented, defaulted or silently substituted for a caller's detail request.

Anthropic maps each captured part to `{type:"image",source:{type:"base64",media_type:<exact MIME>,data:<exact payload>}}`, selecting image/png, image/jpeg, image/webp and image/gif. Gemini maps to `{inlineData:{mimeType:<exact MIME>,data:<exact payload>}}`, selecting PNG/JPEG/WebP. GIF is outside this conservative Gemini subset; its generic Blob reference lists more formats than its image guide, so this is not a universal claim that Gemini rejects GIF. Public HEIC/HEIF/AVIF inputs remain unimplemented.

Remove only the data URL wrapper; preserve exact standard canonical base64 without transcoding, decoding pixels, checking MIME authenticity, resizing, fetching remote hosts or reading files. Preserve input part order, empty text, multiple/image-only arrays and image turns in function-result history. Native converters retain function IDs/names/results and existing adjacent-result grouping. Google still rejects non-image plain/marked arrays at its native boundary; public text-only arrays continue their existing normalization to strings.

At most 20 image occurrences across the complete native history are accepted, including repeated references to the same part; 21 rejects before credentials. This is a local limit, not a provider maximum. Existing full-URL/history/part/HTTP-body limits apply independently. Unsupported role, remote/file URL, malformed encoding/fields and any request/block/tool cache mixture retain existing public early rejection. Direct converters also reject unsupported image/detail/MIME, non-user images and marked history rather than sending OpenAI blocks or dropping them.

The adapter snapshots request history and constructs/serializes the native body before asynchronous secret resolution. Later mutation cannot change the wire payload, and an invalid first image field never retries a later value. Upstream/native model, pixel, animation and image-byte validity limits remain authoritative; encoding-valid data can still fail safely upstream. Provider model capabilities are not inferred from catalog metadata.

Preserve authentication, complete model/final-provider IAM with explicit Deny, limits and registered fixed upstream hosts. No caller image URL becomes a proxy destination. Required usage/audit persistence, missing usage, streamed interruption, cancellation/backpressure, failed possibly-billed attempts and duplicate-accounting signals retain the shared behavior. Image data/MIME/detail/text and provider credentials stay outside operational events, ledger data and errors. Image inputs create no inferred token usage or cost. Secret failures before contact produce no billed usage record; post-contact failures/cancellation preserve possible billing.

Actual installed OpenAI7.23.0/OpenRouter1.4.18 clients on local sockets cover both bases, native text/function nonstream/streams and correlated follow-ups with fresh provider Deny overriding Allow. OpenAI stream abort tests cancel both native bodies and preserve failed possibly-billed accounting. Tests use mock fixed providers and a tiny inline fixture; they do not certify live native models. All three structural pins remain byte-identical.

OpenAI/delegated wire behavior, image source guard and Jev restrictions remain as documented in [inline images](inline-image-inputs.md) and [image schema](image-content-schema.md). Jev sendPrompt:true rejects images before selector credentials; metadata-only eligible selection remains unchanged. Remote inputs, supplied native detail/resolution equivalence, native image caching/outputs, richer parts and live per-model certification remain open under #116; #7 stays unresolved. See [plan](../docs/plans/468-native-inline-images.md), [Anthropic vision](https://platform.claude.com/docs/en/build-with-claude/vision), [Gemini image guide](https://ai.google.dev/gemini-api/docs/generate-content/image-understanding) and [Gemini Part/Blob reference](https://ai.google.dev/api/generate-content#Part).
14 changes: 12 additions & 2 deletions docs/PRD.md
Original file line number Diff line number Diff line change
Expand Up @@ -946,7 +946,7 @@ Offline checks validate all three pins without network; explicit live checks val

Both chat bases accept bounded user image_url arrays with plain text, preserving exact order/empty text and omission of optional auto/low/high detail. Accept only canonical nonempty base64 data:image/png/jpeg/webp/gif URLs: at most524288 UTF-16 units per full URL and786432 across history, at most128 parts per image-bearing message; existing1MiB HTTP body cap remains. Validate encoding without certifying image pixels/MIME or live model capability. Reject other roles, remote/file URLs, original/unknown detail, unknown fields and any request/block/tool caching mixture before routes. Freeze captured primitives/parts/history before async work.

Managed OpenAI/delegated OpenRouter forward images on nonstream/text/refusal/function streams through shared approved model/final-provider IAM/Deny, limits, fixed hosts, required audit/usage and safe missing/possibly-billed failure/cancellation handling. Native Anthropic/Gemini reject before secrets. Jev text disclosure rejects image histories before selector credentials rather than dropping or disclosing images; metadata-only selection remains available. Images never enter operational records/errors or generate inferred tokens/cost; no gateway image fetch or output-image support is added.
Managed OpenAI/delegated OpenRouter forward images on nonstream/text/refusal/function streams through shared approved model/final-provider IAM/Deny, limits, fixed hosts, required audit/usage and safe missing/possibly-billed failure/cancellation handling. Native Anthropic/Gemini initially rejected images before secrets; #468 adds the omitted-detail native subset documented below. Jev text disclosure rejects image histories before selector credentials rather than dropping or disclosing images; metadata-only selection remains available. Images never enter operational records/errors or generate inferred tokens/cost; no gateway image fetch or output-image support is added.

Actual installed OpenAI7.23.0/OpenRouter1.4.18 sockets exercise wire shapes, streamed/nonstream completions and image/function continuation with fresh Deny. Existing structural pins stay byte-identical; transitive image definitions, native/cache/remote/richer mappings, live model certification, full #116 and unresolved #7 remain open. See [plan](plans/464-inline-image-inputs.md) and [contract](../contracts/inline-image-inputs.md).

Expand All @@ -956,4 +956,14 @@ Version 31 adds complete ChatContentItems and ChatContentImage source definition

Independent fixtures cover nested image and union drift, missing/non-object targets, stale version-30 and rehashed invalid exact maps. Controlled live CLI cases verify chat-only drift, one fixed-host credential-free retrieval, unchanged pins, no fetch for stale pins and no success output for malformed selected image sources. Full checks and a fresh official three-pin comparison apply.

This extends source coverage following #464; the bounded inline-image runtime contract, authorization, secrets, audit, usage and provider restrictions stay unchanged. Remote URLs, original/unknown detail, richer content, native image mappings, live model certification, full #116 and unresolved #7 remain open. See [plan](plans/466-image-content-schema.md) and [contract](../contracts/image-content-schema.md).
This extends source coverage following #464; the bounded inline-image runtime contract, authorization, secrets, audit, usage and provider restrictions stay unchanged. Remote URLs, original/unknown detail, richer content, broader native image mappings, live model certification, full #116 and unresolved #7 remain open. See [plan](plans/466-image-content-schema.md) and [contract](../contracts/image-content-schema.md).

## Bounded native inline images (#468)

Direct Anthropic and Gemini map omitted-detail user images on both chat bases and nonstream/text/function streams. Anthropic selects PNG/JPEG/WebP/GIF base64 image sources; Gemini selects PNG/JPEG/WebP inlineData as a conservative subset. Generic Gemini Blob documentation also lists GIF, so its exclusion is a local restriction. Preserve exact MIME/base64, part order, empty text, image-only/multiple arrays and correlated function-result histories. All supplied detail values reject before credentials without invented resolution equivalence.

Native histories accept at most20 image occurrences across all turns, including repeated parts; existing URL/history/part/body budgets also apply. Snapshot and serialize before secret resolution. No remote/file fetch, pixel validation, resizing, output images or marked-image caching is added. Google native plain/marked arrays without images remain rejected; public text-only normalization and Anthropic cache/function behavior stay intact.

Authentication, complete model/final-provider IAM/Deny, limits, fixed registered hosts, private operational audit/usage/errors, required persistence and missing/possibly-billed failed attempts remain shared. Actual installed OpenAI7.23.0/OpenRouter1.4.18 sockets cover both bases, streams/nonstream function follow-ups and fresh provider Deny; SDK image stream cancellation cancels native bodies and retains failed possible-billing records. Raw cases cover selected MIME, count boundaries, detail/GIF/cache/role denial, mutation, secret failure and usage/persistence errors.

All three source pins remain byte-identical. Jev text disclosure still rejects image histories before selector credentials and metadata-only selection remains available. Native resolution/detail equivalence, broader MIME/caching/output/richer inputs, remote references, live per-model certification, full #116 and unresolved #7 remain open. See [plan](plans/468-native-inline-images.md) and [contract](../contracts/native-inline-images.md).
14 changes: 12 additions & 2 deletions docs/acceptance.md
Original file line number Diff line number Diff line change
Expand Up @@ -1345,7 +1345,7 @@ Offline checks validate all three pins without network; explicit live checks val

Both chat bases accept bounded user image_url arrays with plain text, preserving exact order/empty text and omission of optional auto/low/high detail. Accept only canonical nonempty base64 data:image/png/jpeg/webp/gif URLs: at most524288 UTF-16 units per full URL and786432 across history, at most128 parts per image-bearing message; existing1MiB HTTP body cap remains. Validate encoding without certifying image pixels/MIME or live model capability. Reject other roles, remote/file URLs, original/unknown detail, unknown fields and any request/block/tool caching mixture before routes. Freeze captured primitives/parts/history before async work.

Managed OpenAI/delegated OpenRouter forward images on nonstream/text/refusal/function streams through shared approved model/final-provider IAM/Deny, limits, fixed hosts, required audit/usage and safe missing/possibly-billed failure/cancellation handling. Native Anthropic/Gemini reject before secrets. Jev text disclosure rejects image histories before selector credentials rather than dropping or disclosing images; metadata-only selection remains available. Images never enter operational records/errors or generate inferred tokens/cost; no gateway image fetch or output-image support is added.
Managed OpenAI/delegated OpenRouter forward images on nonstream/text/refusal/function streams through shared approved model/final-provider IAM/Deny, limits, fixed hosts, required audit/usage and safe missing/possibly-billed failure/cancellation handling. Native Anthropic/Gemini initially rejected images before secrets; #468 adds the omitted-detail native subset documented below. Jev text disclosure rejects image histories before selector credentials rather than dropping or disclosing images; metadata-only selection remains available. Images never enter operational records/errors or generate inferred tokens/cost; no gateway image fetch or output-image support is added.

Actual installed OpenAI7.23.0/OpenRouter1.4.18 sockets exercise wire shapes, streamed/nonstream completions and image/function continuation with fresh Deny. Existing structural pins stay byte-identical; transitive image definitions, native/cache/remote/richer mappings, live model certification, full #116 and unresolved #7 remain open. See [plan](plans/464-inline-image-inputs.md) and [contract](../contracts/inline-image-inputs.md).

Expand All @@ -1355,4 +1355,14 @@ Version 31 adds complete ChatContentItems and ChatContentImage source definition

Independent fixtures cover nested image and union drift, missing/non-object targets, stale version-30 and rehashed invalid exact maps. Controlled live CLI cases verify chat-only drift, one fixed-host credential-free retrieval, unchanged pins, no fetch for stale pins and no success output for malformed selected image sources. Full checks and a fresh official three-pin comparison apply.

This extends source coverage following #464; the bounded inline-image runtime contract, authorization, secrets, audit, usage and provider restrictions stay unchanged. Remote URLs, original/unknown detail, richer content, native image mappings, live model certification, full #116 and unresolved #7 remain open. See [plan](plans/466-image-content-schema.md) and [contract](../contracts/image-content-schema.md).
This extends source coverage following #464; the bounded inline-image runtime contract, authorization, secrets, audit, usage and provider restrictions stay unchanged. Remote URLs, original/unknown detail, richer content, broader native image mappings, live model certification, full #116 and unresolved #7 remain open. See [plan](plans/466-image-content-schema.md) and [contract](../contracts/image-content-schema.md).

## Bounded native inline images (#468)

Direct Anthropic and Gemini map omitted-detail user images on both chat bases and nonstream/text/function streams. Anthropic selects PNG/JPEG/WebP/GIF base64 image sources; Gemini selects PNG/JPEG/WebP inlineData as a conservative subset. Generic Gemini Blob documentation also lists GIF, so its exclusion is a local restriction. Preserve exact MIME/base64, part order, empty text, image-only/multiple arrays and correlated function-result histories. All supplied detail values reject before credentials without invented resolution equivalence.

Native histories accept at most20 image occurrences across all turns, including repeated parts; existing URL/history/part/body budgets also apply. Snapshot and serialize before secret resolution. No remote/file fetch, pixel validation, resizing, output images or marked-image caching is added. Google native plain/marked arrays without images remain rejected; public text-only normalization and Anthropic cache/function behavior stay intact.

Authentication, complete model/final-provider IAM/Deny, limits, fixed registered hosts, private operational audit/usage/errors, required persistence and missing/possibly-billed failed attempts remain shared. Actual installed OpenAI7.23.0/OpenRouter1.4.18 sockets cover both bases, streams/nonstream function follow-ups and fresh provider Deny; SDK image stream cancellation cancels native bodies and retains failed possible-billing records. Raw cases cover selected MIME, count boundaries, detail/GIF/cache/role denial, mutation, secret failure and usage/persistence errors.

All three source pins remain byte-identical. Jev text disclosure still rejects image histories before selector credentials and metadata-only selection remains available. Native resolution/detail equivalence, broader MIME/caching/output/richer inputs, remote references, live per-model certification, full #116 and unresolved #7 remain open. See [plan](plans/468-native-inline-images.md) and [contract](../contracts/native-inline-images.md).
Loading
Loading