Skip to content

🎒 fix: Bound Agent Attachment Context - #15694

Merged
danny-avila merged 1 commit into
devfrom
danny-avila/attachment-context-guardrails
Sep 7, 2026
Merged

danny-avila merged 1 commit into
devfrom
danny-avila/attachment-context-guardrails

Conversation

@danny-avila

@danny-avila danny-avila commented Sep 7, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

I add attachment-aware process-memory snapshots around document encoding, attachment processing, context assembly, model execution, terminal persistence, and final publication.

I also add conservative per-turn agent limits for attachment count, aggregate bytes, and extracted-text characters. The aggregate checks cover current, historical, nested, and lazily resolved agent context before model invocation. Missing S3 or local attachment objects now produce an explicit, actionable user-facing error instead of being silently skipped during encoding.

This belongs in the LibreChat host rather than @librechat/agents: the SDK already exposes the model lifecycle callback surface, while LibreChat owns file configuration, storage retrieval, context assembly, persistence, and response publication.

Change Type

  • Bug fix (non-breaking change which fixes an issue)

Testing

  • npm run static-checks -- --against origin/dev
  • cd packages/api && npx tsc --noEmit
  • cd packages/data-provider && npx tsc --noEmit
  • cd packages/api && npx jest src/agents/attachments.test.ts src/files/encode/utils.spec.ts src/files/encode/document.spec.ts --runInBand --coverage=false
  • cd packages/data-provider && npx jest src/file-config.spec.ts --runInBand --coverage=false
  • cd api && npx jest server/controllers/agents/client.test.js --runInBand --coverage=false
  • cd api && npx jest server/controllers/agents/__tests__/request.resumeMetadata.spec.js --runInBand --coverage=false

Test Configuration:

  • Node.js 22
  • Latest origin/dev (1aa86a9cef)

Checklist

  • My code adheres to this project's style guidelines
  • I have performed a self-review of my own code
  • I have commented in complex areas where needed
  • I have made pertinent configuration documentation changes
  • My changes do not introduce new warnings
  • I have written tests demonstrating that my changes are effective
  • Local unit tests pass with my changes

@danny-avila

Copy link
Copy Markdown
Collaborator Author

@codex review

Please review the current PR head 276d5b2. Confirm that this exact commit is the reviewed commit and ignore findings that apply only to earlier heads.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 7, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-07T11:49:13.349075Z 01d8cb1 Manual request
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@danny-avila danny-avila changed the title 🧯 fix: Bound Agent Attachment Context Memory 🧳 fix: Bound Agent Attachment Context Sep 7, 2026

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 276d5b2b95

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread api/server/controllers/agents/client.js Outdated
Comment thread api/server/controllers/agents/client.js Outdated
Comment thread packages/api/src/agents/attachments.ts
Comment thread packages/api/src/agents/initialize.ts Outdated
@danny-avila
danny-avila force-pushed the danny-avila/attachment-context-guardrails branch from 276d5b2 to 1bd8d21 Compare September 7, 2026 04:34
@danny-avila

Copy link
Copy Markdown
Collaborator Author

@codex review

Please review the current PR head 1bd8d21. Confirm that this exact commit is the reviewed commit and ignore findings that apply only to earlier heads.

@danny-avila
danny-avila force-pushed the danny-avila/attachment-context-guardrails branch from 1bd8d21 to 9691be4 Compare September 7, 2026 04:39
@danny-avila

Copy link
Copy Markdown
Collaborator Author

@codex review

Please review the current PR head 9691be4. Confirm that this exact commit is the reviewed commit and ignore findings that apply only to earlier heads.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 9691be4291

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread api/server/controllers/agents/client.js Outdated
Comment thread api/server/controllers/agents/client.js Outdated
Comment thread packages/api/src/files/encode/utils.ts
Comment thread api/app/clients/BaseClient.js
Comment thread api/server/controllers/agents/client.js Outdated
@danny-avila
danny-avila force-pushed the danny-avila/attachment-context-guardrails branch from 9691be4 to d80778b Compare September 7, 2026 04:56
@danny-avila

Copy link
Copy Markdown
Collaborator Author

@codex review

Please review the current PR head d80778b. Confirm that this exact commit is the reviewed commit and ignore findings that apply only to earlier heads.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: d80778b53b

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread packages/api/src/agents/initialize.ts Outdated
@danny-avila
danny-avila force-pushed the danny-avila/attachment-context-guardrails branch from d80778b to a7936a4 Compare September 7, 2026 05:03
@danny-avila

Copy link
Copy Markdown
Collaborator Author

@codex review

Please review the current PR head a7936a4. Confirm that this exact commit is the reviewed commit and ignore findings that apply only to earlier heads.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: a7936a415e

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread api/app/clients/BaseClient.js Outdated
Comment thread api/app/clients/BaseClient.js Outdated
Comment thread api/server/controllers/agents/request.js Outdated
Comment thread packages/api/src/agents/initialize.ts
@danny-avila
danny-avila force-pushed the danny-avila/attachment-context-guardrails branch from a7936a4 to e9fcffc Compare September 7, 2026 05:17
@danny-avila

Copy link
Copy Markdown
Collaborator Author

@codex review commit e9fcffc

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: e9fcffc81c

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread api/app/clients/BaseClient.js Outdated
Comment thread api/server/controllers/agents/client.js
Comment thread api/server/controllers/agents/client.js Outdated
@danny-avila
danny-avila force-pushed the danny-avila/attachment-context-guardrails branch from e9fcffc to efc088a Compare September 7, 2026 05:40
@danny-avila

Copy link
Copy Markdown
Collaborator Author

@codex review commit efc088a

@danny-avila
danny-avila force-pushed the danny-avila/attachment-context-guardrails branch from efc088a to 245089a Compare September 7, 2026 05:43
@danny-avila

Copy link
Copy Markdown
Collaborator Author

@codex review commit 245089a

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 245089ac70

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread api/server/controllers/agents/client.js Outdated
Comment thread packages/api/src/agents/attachments.ts Outdated
Comment thread api/server/controllers/agents/client.js Outdated
Comment thread api/server/controllers/agents/client.js
@danny-avila
danny-avila force-pushed the danny-avila/attachment-context-guardrails branch from 245089a to 6fecda1 Compare September 7, 2026 06:03
@danny-avila

Copy link
Copy Markdown
Collaborator Author

@codex review commit 6fecda1

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 6fecda1dd5

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread api/server/controllers/agents/client.js Outdated
Comment thread api/server/controllers/agents/client.js Outdated
Comment thread packages/api/src/agents/hitl/protection.ts
@danny-avila
danny-avila force-pushed the danny-avila/attachment-context-guardrails branch from 6fecda1 to fb0fbbb Compare September 7, 2026 06:19
@danny-avila

Copy link
Copy Markdown
Collaborator Author

@codex review

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: fb0fbbbc98

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread api/server/controllers/agents/client.js
Comment thread api/server/controllers/agents/client.js
Comment thread packages/data-provider/src/file-config.ts Outdated
Comment thread api/app/clients/BaseClient.js Outdated
Comment thread api/server/controllers/agents/client.js Outdated
@danny-avila
danny-avila force-pushed the danny-avila/attachment-context-guardrails branch from fb0fbbb to 52a7acc Compare September 7, 2026 06:41

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: c3bc2ccb6e

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread packages/api/src/agents/attachments.ts Outdated
Comment thread api/server/controllers/agents/client.js
@danny-avila
danny-avila force-pushed the danny-avila/attachment-context-guardrails branch from c3bc2cc to a99a88f Compare September 7, 2026 09:46
@danny-avila

Copy link
Copy Markdown
Collaborator Author

@codex review

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: a99a88ffd0

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread packages/api/src/agents/attachments.ts Outdated
Comment thread packages/api/src/agents/attachments.ts Outdated
Comment thread api/server/controllers/agents/client.js
@danny-avila
danny-avila force-pushed the danny-avila/attachment-context-guardrails branch from a99a88f to b112f39 Compare September 7, 2026 10:06
@danny-avila

Copy link
Copy Markdown
Collaborator Author

@codex review

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: b112f39854

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread packages/api/src/agents/attachments.ts
Comment thread packages/api/src/agents/attachments.ts Outdated
Comment thread api/server/controllers/agents/client.js Outdated
@danny-avila
danny-avila force-pushed the danny-avila/attachment-context-guardrails branch from b112f39 to 9772191 Compare September 7, 2026 10:25
@danny-avila

Copy link
Copy Markdown
Collaborator Author

@codex review

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 9772191733

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread api/server/controllers/agents/client.js Outdated
Comment thread packages/api/src/agents/attachments.ts Outdated
Comment thread packages/api/src/agents/attachments.ts Outdated
Comment thread packages/api/src/agents/attachments.ts Outdated
@danny-avila
danny-avila force-pushed the danny-avila/attachment-context-guardrails branch from 9772191 to cefb74e Compare September 7, 2026 10:43
@danny-avila

Copy link
Copy Markdown
Collaborator Author

@codex review

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: cefb74ef55

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread api/server/controllers/agents/client.js
Comment thread api/server/controllers/agents/client.js Outdated
Comment thread api/server/controllers/agents/client.js
@danny-avila
danny-avila force-pushed the danny-avila/attachment-context-guardrails branch from cefb74e to e0d0b26 Compare September 7, 2026 11:13
@danny-avila

Copy link
Copy Markdown
Collaborator Author

@codex review

Please review the current PR head e0d0b26. Confirm that this exact commit is the reviewed commit and ignore findings that apply only to earlier heads.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: e0d0b263ce

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread api/server/controllers/agents/client.js
@danny-avila
danny-avila force-pushed the danny-avila/attachment-context-guardrails branch from e0d0b26 to 2061f1b Compare September 7, 2026 11:26
@danny-avila

Copy link
Copy Markdown
Collaborator Author

@codex review

Please review the current PR head 2061f1b. Confirm that this exact commit is the reviewed commit and ignore findings that apply only to earlier heads.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 2061f1b622

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread api/server/controllers/agents/client.js Outdated
@danny-avila
danny-avila force-pushed the danny-avila/attachment-context-guardrails branch from 2061f1b to 01d8cb1 Compare September 7, 2026 11:42
@danny-avila

Copy link
Copy Markdown
Collaborator Author

@codex review

Please review the current PR head 01d8cb1. Confirm that this exact commit is the reviewed commit and ignore findings that apply only to earlier heads.

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. Swish!

Reviewed commit: 01d8cb1c84

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@danny-avila danny-avila changed the title 🧳 fix: Bound Agent Attachment Context 🎒 fix: Bound Agent Attachment Context Sep 7, 2026
@danny-avila
danny-avila merged commit e370ce4 into dev Sep 7, 2026
40 checks passed
@danny-avila
danny-avila deleted the danny-avila/attachment-context-guardrails branch September 7, 2026 12:16
danny-avila added a commit that referenced this pull request Sep 18, 2026
…reads (#16058)

Since #15694 bounded each turn's attachments across history, a thread whose
history counts more than `fileLimit` model-bound files is refused on every turn,
including turns that attach nothing. Two kinds of file reached that count that
never belonged in the prompt.

Code outputs: priming clears an expired sandbox reference on the turn's copy of
the record so the file is re-provisioned, and a route-less record without a
reference was classified as prompt content, so it counted toward the limit and
could be encoded as media. Code outputs now stay tool-owned regardless of
reference liveness, through one predicate shared by admission, BaseClient
delivery and the child run-file encoder.

Tool-routed spreadsheets: with `textFallbackWithoutTools`, #16027 delivered the
fallback text until a tool held a copy. Run Code receives its copy only on its
first call, which a refused turn never makes, so the text counted on every later
turn. An enabled Run Code is a reader again for the types it can read; File
Search still reads only what its store holds.
danny-avila added a commit that referenced this pull request Sep 19, 2026
* 🗂️ fix: Keep a Running Attachment Chat in the Sidebar

Since #15694, a turn with model-bound attachments defers its user-message
write until the model admits the payload. That write was also what created
a new conversation's row, so for the whole first model call, which with a
long generated script or extended thinking can run for minutes, the
conversation did not exist. Any conversation-list refetch in that window
(starting another chat, deleting one, reloading) dropped the running chat
from the sidebar until its run finished, and GET /api/convos/:id answered
404 for it.

When attachments are the only reason to defer, the new conversation's row
is now written as the run starts, carrying the same fields the message
write would set but no message. The message itself stays deferred until
admission, and its write waits for a seed still in flight so the two
upserts never race. A content policy still holds back every write, the
row included, as #14425 intended.

The conversation half of saveMessageToDatabase moves into
saveConversationToDatabase so the seed and the message write share one
path.

* 🧱 refactor: Own Turn Conversation Writes in packages/api

The conversation half of a turn's writes (the row a message save
upserts, the retention context it stamps, and the new seed ahead of a
deferred first message) moves into `conversations/save.ts`, which takes
`getConvo`/`saveConvo` from the caller. BaseClient keeps only the
wiring: the retention lookup that must stay synchronous for Stop, the
message save, and the calls into the module.

The seed passes an empty `appendMessageIds`, which tells `saveConvo`
the row holds no messages yet, so it no longer reads the message list
before the upsert. It also resolves the conversation once and leaves it
on the request, so the deferred message save reuses it instead of
looking the conversation up again.

save.spec.ts drives the real data-schemas methods against an in-memory
MongoDB: the seed creates an empty row without reading messages, the
message save appends to it without a second lookup, an existing chat and
a subagent thread are left alone, a temporary chat keeps its retention,
and a failed lookup settles instead of rejecting.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant