Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .github/ISSUE_TEMPLATE/config.yml
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
blank_issues_enabled: true
contact_links:
- name: Security reports
url: https://github.com/tinyhumansai/rust-template/security/policy
url: https://github.com/tinyhumansai/tinytools/security/policy
about: Please do not report vulnerabilities through public issues.
81 changes: 58 additions & 23 deletions .github/workflows/ci.yml
Original file line numberDiff line numberDiff line change
Expand Up@@ -26,7 +26,6 @@ jobs:
# This job executes repository code (cargo build/test); don't persist
# the token in git config.
persist-credentials: false
Comment thread
senamakel marked this conversation as resolved.
submodules: recursive

- uses: dtolnay/rust-toolchain@stable
with:
Expand All@@ -53,32 +52,71 @@ jobs:
- name: Test default features
run: cargo test

# `cargo build --all-targets` only *compiles* an example. `AGENTS.md`
# promises `cargo run -p template --example basic` works, and a compiled
# example can still fail on its first line.
- name: Run the bundled example
run: cargo run -p template --example basic

# `crates/template-bus` exists so a host can name the payload types
# without compiling the module. That promise is invisible in a diff,
# because a forbidden dependency arrives transitively through a feature
# someone enabled one crate away — so it is asserted rather than
# documented.
# This crate is the vocabulary both an agent harness and a host
# application link against, so its dependency list is a promise to both.
# That promise is invisible in a diff, because a forbidden dependency
# arrives transitively through a feature someone enabled one crate away —
# so it is asserted rather than documented.
#
# The FORWARD form is required. `cargo tree -i <crate> -p template-bus`
# `tinyagents` is on the list for a structural reason, not a size one: it
# depends on *this* crate. An edge back would be a cycle, and the
# `context` module's erasure trait exists precisely to make one
# unnecessary. Everything else on the list is weight a tool author should
# not have to compile to write a tool.
#
# The FORWARD form is required. `cargo tree -i <crate> -p tinytools`
# discards the `-p` scope, prints the whole-workspace inverse tree, and
# exits 0 looking clean even when this crate is the one at fault.
- name: Assert the contract crate stays transport-free
- name: Assert the vocabulary crate stays dependency-light
run: |
set -euo pipefail
forbidden="$(cargo tree -p template-bus -e normal,build --prefix none \
| grep -Ei 'tinybus|tokio|reqwest|ureq|hyper|rusqlite|git2' || true)"
# Compare crate NAMES only. `cargo tree` prints each package as
# `name vX.Y.Z (/path/to/checkout)`, and a consumer may vendor this
# repository *underneath* one of the forbidden crates — tinyagents
# does exactly that — so grepping the raw line matches the path and
# reports a dependency that is not there. Cut the version and path off
# first.
package_names="$(cargo tree -p tinytools --all-features -e normal,build --prefix none \
| awk '{print $1}' | sort -u)"

# An ALLOWLIST, not a blocklist: naming eight forbidden crates only
# catches those eight. Adding `surf`, `async-std`, an arbitrary
# `*-sys` native binding, or any other transport/runtime would pass
# silently under a blocklist. Every package this crate's forward tree
# is reviewed to actually contain is named here instead, so *any*
# newly introduced package — forbidden or merely unreviewed — fails
# the gate until this list is updated in the same commit.
allowed='
tinytools
anyhow
async-trait
serde
serde_core
serde_derive
serde_json
proc-macro2
quote
syn
unicode-ident
itoa
memchr
zmij
'

# Anything in package_names that is not a line of $allowed.
forbidden="$(comm -23 \
<(printf '%s\n' "$package_names") \
<(printf '%s\n' "$allowed" | sort -u))"

if [ -n "$forbidden" ]; then
echo "template-bus pulled in a dependency its manifest forbids:" >&2
echo "tinytools pulled in a dependency its manifest doesn't review for:" >&2
echo "$forbidden" >&2
echo >&2
echo "The contract is what a host compiles against. It must stay free" >&2
echo "of transports, async runtimes, HTTP clients and native libraries." >&2
echo "This crate is what a harness and a host both compile against." >&2
echo "It must stay free of agent harnesses, transports, async" >&2
echo "runtimes, HTTP clients and native libraries. If this package" >&2
echo "is a genuinely reviewed addition, add it to the allowlist in" >&2
echo "this step in the same commit that adds the dependency." >&2
exit 1
fi

Expand All@@ -100,7 +138,6 @@ jobs:
- uses: actions/checkout@v7
with:
persist-credentials: false
submodules: recursive

- uses: dtolnay/rust-toolchain@stable

Expand All@@ -118,7 +155,6 @@ jobs:
- uses: actions/checkout@v7
with:
persist-credentials: false
submodules: recursive

# `rust-version` is inherited from `[workspace.package]`, so every member
# reports the same value. Read it off the package the module ships as
Expand All@@ -128,7 +164,7 @@ jobs:
run: |
set -euo pipefail
msrv="$(cargo metadata --format-version 1 --no-deps \
| jq -r '.packages[] | select(.name == "template") | .rust_version')"
| jq -r '.packages[] | select(.name == "tinytools") | .rust_version')"
if [[ -z "$msrv" || "$msrv" == "null" ]]; then
echo "workspace.package.rust-version is not set in Cargo.toml" >&2
exit 1
Expand All@@ -151,7 +187,6 @@ jobs:
- uses: actions/checkout@v7
with:
persist-credentials: false
submodules: recursive

- name: Check advisories, licenses, bans, and sources
uses: EmbarkStudios/cargo-deny-action@v2
Expand Down
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
feat: the agent tool vocabulary by senamakel · Pull Request #1 · tinyhumansai/tinytools · GitHub
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .github/ISSUE_TEMPLATE/config.yml
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
blank_issues_enabled: true
contact_links:
- name: Security reports
url: https://github.com/tinyhumansai/rust-template/security/policy
url: https://github.com/tinyhumansai/tinytools/security/policy
about: Please do not report vulnerabilities through public issues.
81 changes: 58 additions & 23 deletions .github/workflows/ci.yml
Original file line numberDiff line numberDiff line change
Expand Up@@ -26,7 +26,6 @@ jobs:
# This job executes repository code (cargo build/test); don't persist
# the token in git config.
persist-credentials: false
Comment thread
senamakel marked this conversation as resolved.
submodules: recursive

- uses: dtolnay/rust-toolchain@stable
with:
Expand All@@ -53,32 +52,71 @@ jobs:
- name: Test default features
run: cargo test

# `cargo build --all-targets` only *compiles* an example. `AGENTS.md`
# promises `cargo run -p template --example basic` works, and a compiled
# example can still fail on its first line.
- name: Run the bundled example
run: cargo run -p template --example basic

# `crates/template-bus` exists so a host can name the payload types
# without compiling the module. That promise is invisible in a diff,
# because a forbidden dependency arrives transitively through a feature
# someone enabled one crate away — so it is asserted rather than
# documented.
# This crate is the vocabulary both an agent harness and a host
# application link against, so its dependency list is a promise to both.
# That promise is invisible in a diff, because a forbidden dependency
# arrives transitively through a feature someone enabled one crate away —
# so it is asserted rather than documented.
#
# The FORWARD form is required. `cargo tree -i <crate> -p template-bus`
# `tinyagents` is on the list for a structural reason, not a size one: it
# depends on *this* crate. An edge back would be a cycle, and the
# `context` module's erasure trait exists precisely to make one
# unnecessary. Everything else on the list is weight a tool author should
# not have to compile to write a tool.
#
# The FORWARD form is required. `cargo tree -i <crate> -p tinytools`
# discards the `-p` scope, prints the whole-workspace inverse tree, and
# exits 0 looking clean even when this crate is the one at fault.
- name: Assert the contract crate stays transport-free
- name: Assert the vocabulary crate stays dependency-light
run: |
set -euo pipefail
forbidden="$(cargo tree -p template-bus -e normal,build --prefix none \
| grep -Ei 'tinybus|tokio|reqwest|ureq|hyper|rusqlite|git2' || true)"
# Compare crate NAMES only. `cargo tree` prints each package as
# `name vX.Y.Z (/path/to/checkout)`, and a consumer may vendor this
# repository *underneath* one of the forbidden crates — tinyagents
# does exactly that — so grepping the raw line matches the path and
# reports a dependency that is not there. Cut the version and path off
# first.
package_names="$(cargo tree -p tinytools --all-features -e normal,build --prefix none \
| awk '{print $1}' | sort -u)"

# An ALLOWLIST, not a blocklist: naming eight forbidden crates only
# catches those eight. Adding `surf`, `async-std`, an arbitrary
# `*-sys` native binding, or any other transport/runtime would pass
# silently under a blocklist. Every package this crate's forward tree
# is reviewed to actually contain is named here instead, so *any*
# newly introduced package — forbidden or merely unreviewed — fails
# the gate until this list is updated in the same commit.
allowed='
tinytools
anyhow
async-trait
serde
serde_core
serde_derive
serde_json
proc-macro2
quote
syn
unicode-ident
itoa
memchr
zmij
'

# Anything in package_names that is not a line of $allowed.
forbidden="$(comm -23 \
<(printf '%s\n' "$package_names") \
<(printf '%s\n' "$allowed" | sort -u))"

if [ -n "$forbidden" ]; then
echo "template-bus pulled in a dependency its manifest forbids:" >&2
echo "tinytools pulled in a dependency its manifest doesn't review for:" >&2
echo "$forbidden" >&2
echo >&2
echo "The contract is what a host compiles against. It must stay free" >&2
echo "of transports, async runtimes, HTTP clients and native libraries." >&2
echo "This crate is what a harness and a host both compile against." >&2
echo "It must stay free of agent harnesses, transports, async" >&2
echo "runtimes, HTTP clients and native libraries. If this package" >&2
echo "is a genuinely reviewed addition, add it to the allowlist in" >&2
echo "this step in the same commit that adds the dependency." >&2
exit 1
fi

Expand All@@ -100,7 +138,6 @@ jobs:
- uses: actions/checkout@v7
with:
persist-credentials: false
submodules: recursive

- uses: dtolnay/rust-toolchain@stable

Expand All@@ -118,7 +155,6 @@ jobs:
- uses: actions/checkout@v7
with:
persist-credentials: false
submodules: recursive

# `rust-version` is inherited from `[workspace.package]`, so every member
# reports the same value. Read it off the package the module ships as
Expand All@@ -128,7 +164,7 @@ jobs:
run: |
set -euo pipefail
msrv="$(cargo metadata --format-version 1 --no-deps \
| jq -r '.packages[] | select(.name == "template") | .rust_version')"
| jq -r '.packages[] | select(.name == "tinytools") | .rust_version')"
if [[ -z "$msrv" || "$msrv" == "null" ]]; then
echo "workspace.package.rust-version is not set in Cargo.toml" >&2
exit 1
Expand All@@ -151,7 +187,6 @@ jobs:
- uses: actions/checkout@v7
with:
persist-credentials: false
submodules: recursive

- name: Check advisories, licenses, bans, and sources
uses: EmbarkStudios/cargo-deny-action@v2
Expand Down
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' feat: the agent tool vocabulary by senamakel · Pull Request #1 · tinyhumansai/tinytools · GitHub
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .github/ISSUE_TEMPLATE/config.yml
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
blank_issues_enabled: true
contact_links:
- name: Security reports
url: https://github.com/tinyhumansai/rust-template/security/policy
url: https://github.com/tinyhumansai/tinytools/security/policy
about: Please do not report vulnerabilities through public issues.
81 changes: 58 additions & 23 deletions .github/workflows/ci.yml
Original file line numberDiff line numberDiff line change
Expand Up@@ -26,7 +26,6 @@ jobs:
# This job executes repository code (cargo build/test); don't persist
# the token in git config.
persist-credentials: false
Comment thread
senamakel marked this conversation as resolved.
submodules: recursive

- uses: dtolnay/rust-toolchain@stable
with:
Expand All@@ -53,32 +52,71 @@ jobs:
- name: Test default features
run: cargo test

# `cargo build --all-targets` only *compiles* an example. `AGENTS.md`
# promises `cargo run -p template --example basic` works, and a compiled
# example can still fail on its first line.
- name: Run the bundled example
run: cargo run -p template --example basic

# `crates/template-bus` exists so a host can name the payload types
# without compiling the module. That promise is invisible in a diff,
# because a forbidden dependency arrives transitively through a feature
# someone enabled one crate away — so it is asserted rather than
# documented.
# This crate is the vocabulary both an agent harness and a host
# application link against, so its dependency list is a promise to both.
# That promise is invisible in a diff, because a forbidden dependency
# arrives transitively through a feature someone enabled one crate away —
# so it is asserted rather than documented.
#
# The FORWARD form is required. `cargo tree -i <crate> -p template-bus`
# `tinyagents` is on the list for a structural reason, not a size one: it
# depends on *this* crate. An edge back would be a cycle, and the
# `context` module's erasure trait exists precisely to make one
# unnecessary. Everything else on the list is weight a tool author should
# not have to compile to write a tool.
#
# The FORWARD form is required. `cargo tree -i <crate> -p tinytools`
# discards the `-p` scope, prints the whole-workspace inverse tree, and
# exits 0 looking clean even when this crate is the one at fault.
- name: Assert the contract crate stays transport-free
- name: Assert the vocabulary crate stays dependency-light
run: |
set -euo pipefail
forbidden="$(cargo tree -p template-bus -e normal,build --prefix none \
| grep -Ei 'tinybus|tokio|reqwest|ureq|hyper|rusqlite|git2' || true)"
# Compare crate NAMES only. `cargo tree` prints each package as
# `name vX.Y.Z (/path/to/checkout)`, and a consumer may vendor this
# repository *underneath* one of the forbidden crates — tinyagents
# does exactly that — so grepping the raw line matches the path and
# reports a dependency that is not there. Cut the version and path off
# first.
package_names="$(cargo tree -p tinytools --all-features -e normal,build --prefix none \
| awk '{print $1}' | sort -u)"

# An ALLOWLIST, not a blocklist: naming eight forbidden crates only
# catches those eight. Adding `surf`, `async-std`, an arbitrary
# `*-sys` native binding, or any other transport/runtime would pass
# silently under a blocklist. Every package this crate's forward tree
# is reviewed to actually contain is named here instead, so *any*
# newly introduced package — forbidden or merely unreviewed — fails
# the gate until this list is updated in the same commit.
allowed='
tinytools
anyhow
async-trait
serde
serde_core
serde_derive
serde_json
proc-macro2
quote
syn
unicode-ident
itoa
memchr
zmij
'

# Anything in package_names that is not a line of $allowed.
forbidden="$(comm -23 \
<(printf '%s\n' "$package_names") \
<(printf '%s\n' "$allowed" | sort -u))"

if [ -n "$forbidden" ]; then
echo "template-bus pulled in a dependency its manifest forbids:" >&2
echo "tinytools pulled in a dependency its manifest doesn't review for:" >&2
echo "$forbidden" >&2
echo >&2
echo "The contract is what a host compiles against. It must stay free" >&2
echo "of transports, async runtimes, HTTP clients and native libraries." >&2
echo "This crate is what a harness and a host both compile against." >&2
echo "It must stay free of agent harnesses, transports, async" >&2
echo "runtimes, HTTP clients and native libraries. If this package" >&2
echo "is a genuinely reviewed addition, add it to the allowlist in" >&2
echo "this step in the same commit that adds the dependency." >&2
exit 1
fi

Expand All@@ -100,7 +138,6 @@ jobs:
- uses: actions/checkout@v7
with:
persist-credentials: false
submodules: recursive

- uses: dtolnay/rust-toolchain@stable

Expand All@@ -118,7 +155,6 @@ jobs:
- uses: actions/checkout@v7
with:
persist-credentials: false
submodules: recursive

# `rust-version` is inherited from `[workspace.package]`, so every member
# reports the same value. Read it off the package the module ships as
Expand All@@ -128,7 +164,7 @@ jobs:
run: |
set -euo pipefail
msrv="$(cargo metadata --format-version 1 --no-deps \
| jq -r '.packages[] | select(.name == "template") | .rust_version')"
| jq -r '.packages[] | select(.name == "tinytools") | .rust_version')"
if [[ -z "$msrv" || "$msrv" == "null" ]]; then
echo "workspace.package.rust-version is not set in Cargo.toml" >&2
exit 1
Expand All@@ -151,7 +187,6 @@ jobs:
- uses: actions/checkout@v7
with:
persist-credentials: false
submodules: recursive

- name: Check advisories, licenses, bans, and sources
uses: EmbarkStudios/cargo-deny-action@v2
Expand Down
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' feat: the agent tool vocabulary by senamakel · Pull Request #1 · tinyhumansai/tinytools · GitHub
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .github/ISSUE_TEMPLATE/config.yml
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
blank_issues_enabled: true
contact_links:
- name: Security reports
url: https://github.com/tinyhumansai/rust-template/security/policy
url: https://github.com/tinyhumansai/tinytools/security/policy
about: Please do not report vulnerabilities through public issues.
81 changes: 58 additions & 23 deletions .github/workflows/ci.yml
Original file line numberDiff line numberDiff line change
Expand Up@@ -26,7 +26,6 @@ jobs:
# This job executes repository code (cargo build/test); don't persist
# the token in git config.
persist-credentials: false
Comment thread
senamakel marked this conversation as resolved.
submodules: recursive

- uses: dtolnay/rust-toolchain@stable
with:
Expand All@@ -53,32 +52,71 @@ jobs:
- name: Test default features
run: cargo test

# `cargo build --all-targets` only *compiles* an example. `AGENTS.md`
# promises `cargo run -p template --example basic` works, and a compiled
# example can still fail on its first line.
- name: Run the bundled example
run: cargo run -p template --example basic

# `crates/template-bus` exists so a host can name the payload types
# without compiling the module. That promise is invisible in a diff,
# because a forbidden dependency arrives transitively through a feature
# someone enabled one crate away — so it is asserted rather than
# documented.
# This crate is the vocabulary both an agent harness and a host
# application link against, so its dependency list is a promise to both.
# That promise is invisible in a diff, because a forbidden dependency
# arrives transitively through a feature someone enabled one crate away —
# so it is asserted rather than documented.
#
# The FORWARD form is required. `cargo tree -i <crate> -p template-bus`
# `tinyagents` is on the list for a structural reason, not a size one: it
# depends on *this* crate. An edge back would be a cycle, and the
# `context` module's erasure trait exists precisely to make one
# unnecessary. Everything else on the list is weight a tool author should
# not have to compile to write a tool.
#
# The FORWARD form is required. `cargo tree -i <crate> -p tinytools`
# discards the `-p` scope, prints the whole-workspace inverse tree, and
# exits 0 looking clean even when this crate is the one at fault.
- name: Assert the contract crate stays transport-free
- name: Assert the vocabulary crate stays dependency-light
run: |
set -euo pipefail
forbidden="$(cargo tree -p template-bus -e normal,build --prefix none \
| grep -Ei 'tinybus|tokio|reqwest|ureq|hyper|rusqlite|git2' || true)"
# Compare crate NAMES only. `cargo tree` prints each package as
# `name vX.Y.Z (/path/to/checkout)`, and a consumer may vendor this
# repository *underneath* one of the forbidden crates — tinyagents
# does exactly that — so grepping the raw line matches the path and
# reports a dependency that is not there. Cut the version and path off
# first.
package_names="$(cargo tree -p tinytools --all-features -e normal,build --prefix none \
| awk '{print $1}' | sort -u)"

# An ALLOWLIST, not a blocklist: naming eight forbidden crates only
# catches those eight. Adding `surf`, `async-std`, an arbitrary
# `*-sys` native binding, or any other transport/runtime would pass
# silently under a blocklist. Every package this crate's forward tree
# is reviewed to actually contain is named here instead, so *any*
# newly introduced package — forbidden or merely unreviewed — fails
# the gate until this list is updated in the same commit.
allowed='
tinytools
anyhow
async-trait
serde
serde_core
serde_derive
serde_json
proc-macro2
quote
syn
unicode-ident
itoa
memchr
zmij
'

# Anything in package_names that is not a line of $allowed.
forbidden="$(comm -23 \
<(printf '%s\n' "$package_names") \
<(printf '%s\n' "$allowed" | sort -u))"

if [ -n "$forbidden" ]; then
echo "template-bus pulled in a dependency its manifest forbids:" >&2
echo "tinytools pulled in a dependency its manifest doesn't review for:" >&2
echo "$forbidden" >&2
echo >&2
echo "The contract is what a host compiles against. It must stay free" >&2
echo "of transports, async runtimes, HTTP clients and native libraries." >&2
echo "This crate is what a harness and a host both compile against." >&2
echo "It must stay free of agent harnesses, transports, async" >&2
echo "runtimes, HTTP clients and native libraries. If this package" >&2
echo "is a genuinely reviewed addition, add it to the allowlist in" >&2
echo "this step in the same commit that adds the dependency." >&2
exit 1
fi

Expand All@@ -100,7 +138,6 @@ jobs:
- uses: actions/checkout@v7
with:
persist-credentials: false
submodules: recursive

- uses: dtolnay/rust-toolchain@stable

Expand All@@ -118,7 +155,6 @@ jobs:
- uses: actions/checkout@v7
with:
persist-credentials: false
submodules: recursive

# `rust-version` is inherited from `[workspace.package]`, so every member
# reports the same value. Read it off the package the module ships as
Expand All@@ -128,7 +164,7 @@ jobs:
run: |
set -euo pipefail
msrv="$(cargo metadata --format-version 1 --no-deps \
| jq -r '.packages[] | select(.name == "template") | .rust_version')"
| jq -r '.packages[] | select(.name == "tinytools") | .rust_version')"
if [[ -z "$msrv" || "$msrv" == "null" ]]; then
echo "workspace.package.rust-version is not set in Cargo.toml" >&2
exit 1
Expand All@@ -151,7 +187,6 @@ jobs:
- uses: actions/checkout@v7
with:
persist-credentials: false
submodules: recursive

- name: Check advisories, licenses, bans, and sources
uses: EmbarkStudios/cargo-deny-action@v2
Expand Down
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' feat: the agent tool vocabulary by senamakel · Pull Request #1 · tinyhumansai/tinytools · GitHub
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .github/ISSUE_TEMPLATE/config.yml
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
blank_issues_enabled: true
contact_links:
- name: Security reports
url: https://github.com/tinyhumansai/rust-template/security/policy
url: https://github.com/tinyhumansai/tinytools/security/policy
about: Please do not report vulnerabilities through public issues.
81 changes: 58 additions & 23 deletions .github/workflows/ci.yml
Original file line numberDiff line numberDiff line change
Expand Up@@ -26,7 +26,6 @@ jobs:
# This job executes repository code (cargo build/test); don't persist
# the token in git config.
persist-credentials: false
Comment thread
senamakel marked this conversation as resolved.
submodules: recursive

- uses: dtolnay/rust-toolchain@stable
with:
Expand All@@ -53,32 +52,71 @@ jobs:
- name: Test default features
run: cargo test

# `cargo build --all-targets` only *compiles* an example. `AGENTS.md`
# promises `cargo run -p template --example basic` works, and a compiled
# example can still fail on its first line.
- name: Run the bundled example
run: cargo run -p template --example basic

# `crates/template-bus` exists so a host can name the payload types
# without compiling the module. That promise is invisible in a diff,
# because a forbidden dependency arrives transitively through a feature
# someone enabled one crate away — so it is asserted rather than
# documented.
# This crate is the vocabulary both an agent harness and a host
# application link against, so its dependency list is a promise to both.
# That promise is invisible in a diff, because a forbidden dependency
# arrives transitively through a feature someone enabled one crate away —
# so it is asserted rather than documented.
#
# The FORWARD form is required. `cargo tree -i <crate> -p template-bus`
# `tinyagents` is on the list for a structural reason, not a size one: it
# depends on *this* crate. An edge back would be a cycle, and the
# `context` module's erasure trait exists precisely to make one
# unnecessary. Everything else on the list is weight a tool author should
# not have to compile to write a tool.
#
# The FORWARD form is required. `cargo tree -i <crate> -p tinytools`
# discards the `-p` scope, prints the whole-workspace inverse tree, and
# exits 0 looking clean even when this crate is the one at fault.
- name: Assert the contract crate stays transport-free
- name: Assert the vocabulary crate stays dependency-light
run: |
set -euo pipefail
forbidden="$(cargo tree -p template-bus -e normal,build --prefix none \
| grep -Ei 'tinybus|tokio|reqwest|ureq|hyper|rusqlite|git2' || true)"
# Compare crate NAMES only. `cargo tree` prints each package as
# `name vX.Y.Z (/path/to/checkout)`, and a consumer may vendor this
# repository *underneath* one of the forbidden crates — tinyagents
# does exactly that — so grepping the raw line matches the path and
# reports a dependency that is not there. Cut the version and path off
# first.
package_names="$(cargo tree -p tinytools --all-features -e normal,build --prefix none \
| awk '{print $1}' | sort -u)"

# An ALLOWLIST, not a blocklist: naming eight forbidden crates only
# catches those eight. Adding `surf`, `async-std`, an arbitrary
# `*-sys` native binding, or any other transport/runtime would pass
# silently under a blocklist. Every package this crate's forward tree
# is reviewed to actually contain is named here instead, so *any*
# newly introduced package — forbidden or merely unreviewed — fails
# the gate until this list is updated in the same commit.
allowed='
tinytools
anyhow
async-trait
serde
serde_core
serde_derive
serde_json
proc-macro2
quote
syn
unicode-ident
itoa
memchr
zmij
'

# Anything in package_names that is not a line of $allowed.
forbidden="$(comm -23 \
<(printf '%s\n' "$package_names") \
<(printf '%s\n' "$allowed" | sort -u))"

if [ -n "$forbidden" ]; then
echo "template-bus pulled in a dependency its manifest forbids:" >&2
echo "tinytools pulled in a dependency its manifest doesn't review for:" >&2
echo "$forbidden" >&2
echo >&2
echo "The contract is what a host compiles against. It must stay free" >&2
echo "of transports, async runtimes, HTTP clients and native libraries." >&2
echo "This crate is what a harness and a host both compile against." >&2
echo "It must stay free of agent harnesses, transports, async" >&2
echo "runtimes, HTTP clients and native libraries. If this package" >&2
echo "is a genuinely reviewed addition, add it to the allowlist in" >&2
echo "this step in the same commit that adds the dependency." >&2
exit 1
fi

Expand All@@ -100,7 +138,6 @@ jobs:
- uses: actions/checkout@v7
with:
persist-credentials: false
submodules: recursive

- uses: dtolnay/rust-toolchain@stable

Expand All@@ -118,7 +155,6 @@ jobs:
- uses: actions/checkout@v7
with:
persist-credentials: false
submodules: recursive

# `rust-version` is inherited from `[workspace.package]`, so every member
# reports the same value. Read it off the package the module ships as
Expand All@@ -128,7 +164,7 @@ jobs:
run: |
set -euo pipefail
msrv="$(cargo metadata --format-version 1 --no-deps \
| jq -r '.packages[] | select(.name == "template") | .rust_version')"
| jq -r '.packages[] | select(.name == "tinytools") | .rust_version')"
if [[ -z "$msrv" || "$msrv" == "null" ]]; then
echo "workspace.package.rust-version is not set in Cargo.toml" >&2
exit 1
Expand All@@ -151,7 +187,6 @@ jobs:
- uses: actions/checkout@v7
with:
persist-credentials: false
submodules: recursive

- name: Check advisories, licenses, bans, and sources
uses: EmbarkStudios/cargo-deny-action@v2
Expand Down
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' feat: the agent tool vocabulary by senamakel · Pull Request #1 · tinyhumansai/tinytools · GitHub
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .github/ISSUE_TEMPLATE/config.yml
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
blank_issues_enabled: true
contact_links:
- name: Security reports
url: https://github.com/tinyhumansai/rust-template/security/policy
url: https://github.com/tinyhumansai/tinytools/security/policy
about: Please do not report vulnerabilities through public issues.
81 changes: 58 additions & 23 deletions .github/workflows/ci.yml
Original file line numberDiff line numberDiff line change
Expand Up@@ -26,7 +26,6 @@ jobs:
# This job executes repository code (cargo build/test); don't persist
# the token in git config.
persist-credentials: false
Comment thread
senamakel marked this conversation as resolved.
submodules: recursive

- uses: dtolnay/rust-toolchain@stable
with:
Expand All@@ -53,32 +52,71 @@ jobs:
- name: Test default features
run: cargo test

# `cargo build --all-targets` only *compiles* an example. `AGENTS.md`
# promises `cargo run -p template --example basic` works, and a compiled
# example can still fail on its first line.
- name: Run the bundled example
run: cargo run -p template --example basic

# `crates/template-bus` exists so a host can name the payload types
# without compiling the module. That promise is invisible in a diff,
# because a forbidden dependency arrives transitively through a feature
# someone enabled one crate away — so it is asserted rather than
# documented.
# This crate is the vocabulary both an agent harness and a host
# application link against, so its dependency list is a promise to both.
# That promise is invisible in a diff, because a forbidden dependency
# arrives transitively through a feature someone enabled one crate away —
# so it is asserted rather than documented.
#
# The FORWARD form is required. `cargo tree -i <crate> -p template-bus`
# `tinyagents` is on the list for a structural reason, not a size one: it
# depends on *this* crate. An edge back would be a cycle, and the
# `context` module's erasure trait exists precisely to make one
# unnecessary. Everything else on the list is weight a tool author should
# not have to compile to write a tool.
#
# The FORWARD form is required. `cargo tree -i <crate> -p tinytools`
# discards the `-p` scope, prints the whole-workspace inverse tree, and
# exits 0 looking clean even when this crate is the one at fault.
- name: Assert the contract crate stays transport-free
- name: Assert the vocabulary crate stays dependency-light
run: |
set -euo pipefail
forbidden="$(cargo tree -p template-bus -e normal,build --prefix none \
| grep -Ei 'tinybus|tokio|reqwest|ureq|hyper|rusqlite|git2' || true)"
# Compare crate NAMES only. `cargo tree` prints each package as
# `name vX.Y.Z (/path/to/checkout)`, and a consumer may vendor this
# repository *underneath* one of the forbidden crates — tinyagents
# does exactly that — so grepping the raw line matches the path and
# reports a dependency that is not there. Cut the version and path off
# first.
package_names="$(cargo tree -p tinytools --all-features -e normal,build --prefix none \
| awk '{print $1}' | sort -u)"

# An ALLOWLIST, not a blocklist: naming eight forbidden crates only
# catches those eight. Adding `surf`, `async-std`, an arbitrary
# `*-sys` native binding, or any other transport/runtime would pass
# silently under a blocklist. Every package this crate's forward tree
# is reviewed to actually contain is named here instead, so *any*
# newly introduced package — forbidden or merely unreviewed — fails
# the gate until this list is updated in the same commit.
allowed='
tinytools
anyhow
async-trait
serde
serde_core
serde_derive
serde_json
proc-macro2
quote
syn
unicode-ident
itoa
memchr
zmij
'

# Anything in package_names that is not a line of $allowed.
forbidden="$(comm -23 \
<(printf '%s\n' "$package_names") \
<(printf '%s\n' "$allowed" | sort -u))"

if [ -n "$forbidden" ]; then
echo "template-bus pulled in a dependency its manifest forbids:" >&2
echo "tinytools pulled in a dependency its manifest doesn't review for:" >&2
echo "$forbidden" >&2
echo >&2
echo "The contract is what a host compiles against. It must stay free" >&2
echo "of transports, async runtimes, HTTP clients and native libraries." >&2
echo "This crate is what a harness and a host both compile against." >&2
echo "It must stay free of agent harnesses, transports, async" >&2
echo "runtimes, HTTP clients and native libraries. If this package" >&2
echo "is a genuinely reviewed addition, add it to the allowlist in" >&2
echo "this step in the same commit that adds the dependency." >&2
exit 1
fi

Expand All@@ -100,7 +138,6 @@ jobs:
- uses: actions/checkout@v7
with:
persist-credentials: false
submodules: recursive

- uses: dtolnay/rust-toolchain@stable

Expand All@@ -118,7 +155,6 @@ jobs:
- uses: actions/checkout@v7
with:
persist-credentials: false
submodules: recursive

# `rust-version` is inherited from `[workspace.package]`, so every member
# reports the same value. Read it off the package the module ships as
Expand All@@ -128,7 +164,7 @@ jobs:
run: |
set -euo pipefail
msrv="$(cargo metadata --format-version 1 --no-deps \
| jq -r '.packages[] | select(.name == "template") | .rust_version')"
| jq -r '.packages[] | select(.name == "tinytools") | .rust_version')"
if [[ -z "$msrv" || "$msrv" == "null" ]]; then
echo "workspace.package.rust-version is not set in Cargo.toml" >&2
exit 1
Expand All@@ -151,7 +187,6 @@ jobs:
- uses: actions/checkout@v7
with:
persist-credentials: false
submodules: recursive

- name: Check advisories, licenses, bans, and sources
uses: EmbarkStudios/cargo-deny-action@v2
Expand Down
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' feat: the agent tool vocabulary by senamakel · Pull Request #1 · tinyhumansai/tinytools · GitHub
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .github/ISSUE_TEMPLATE/config.yml
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
blank_issues_enabled: true
contact_links:
- name: Security reports
url: https://github.com/tinyhumansai/rust-template/security/policy
url: https://github.com/tinyhumansai/tinytools/security/policy
about: Please do not report vulnerabilities through public issues.
81 changes: 58 additions & 23 deletions .github/workflows/ci.yml
Original file line numberDiff line numberDiff line change
Expand Up@@ -26,7 +26,6 @@ jobs:
# This job executes repository code (cargo build/test); don't persist
# the token in git config.
persist-credentials: false
Comment thread
senamakel marked this conversation as resolved.
submodules: recursive

- uses: dtolnay/rust-toolchain@stable
with:
Expand All@@ -53,32 +52,71 @@ jobs:
- name: Test default features
run: cargo test

# `cargo build --all-targets` only *compiles* an example. `AGENTS.md`
# promises `cargo run -p template --example basic` works, and a compiled
# example can still fail on its first line.
- name: Run the bundled example
run: cargo run -p template --example basic

# `crates/template-bus` exists so a host can name the payload types
# without compiling the module. That promise is invisible in a diff,
# because a forbidden dependency arrives transitively through a feature
# someone enabled one crate away — so it is asserted rather than
# documented.
# This crate is the vocabulary both an agent harness and a host
# application link against, so its dependency list is a promise to both.
# That promise is invisible in a diff, because a forbidden dependency
# arrives transitively through a feature someone enabled one crate away —
# so it is asserted rather than documented.
#
# The FORWARD form is required. `cargo tree -i <crate> -p template-bus`
# `tinyagents` is on the list for a structural reason, not a size one: it
# depends on *this* crate. An edge back would be a cycle, and the
# `context` module's erasure trait exists precisely to make one
# unnecessary. Everything else on the list is weight a tool author should
# not have to compile to write a tool.
#
# The FORWARD form is required. `cargo tree -i <crate> -p tinytools`
# discards the `-p` scope, prints the whole-workspace inverse tree, and
# exits 0 looking clean even when this crate is the one at fault.
- name: Assert the contract crate stays transport-free
- name: Assert the vocabulary crate stays dependency-light
run: |
set -euo pipefail
forbidden="$(cargo tree -p template-bus -e normal,build --prefix none \
| grep -Ei 'tinybus|tokio|reqwest|ureq|hyper|rusqlite|git2' || true)"
# Compare crate NAMES only. `cargo tree` prints each package as
# `name vX.Y.Z (/path/to/checkout)`, and a consumer may vendor this
# repository *underneath* one of the forbidden crates — tinyagents
# does exactly that — so grepping the raw line matches the path and
# reports a dependency that is not there. Cut the version and path off
# first.
package_names="$(cargo tree -p tinytools --all-features -e normal,build --prefix none \
| awk '{print $1}' | sort -u)"

# An ALLOWLIST, not a blocklist: naming eight forbidden crates only
# catches those eight. Adding `surf`, `async-std`, an arbitrary
# `*-sys` native binding, or any other transport/runtime would pass
# silently under a blocklist. Every package this crate's forward tree
# is reviewed to actually contain is named here instead, so *any*
# newly introduced package — forbidden or merely unreviewed — fails
# the gate until this list is updated in the same commit.
allowed='
tinytools
anyhow
async-trait
serde
serde_core
serde_derive
serde_json
proc-macro2
quote
syn
unicode-ident
itoa
memchr
zmij
'

# Anything in package_names that is not a line of $allowed.
forbidden="$(comm -23 \
<(printf '%s\n' "$package_names") \
<(printf '%s\n' "$allowed" | sort -u))"

if [ -n "$forbidden" ]; then
echo "template-bus pulled in a dependency its manifest forbids:" >&2
echo "tinytools pulled in a dependency its manifest doesn't review for:" >&2
echo "$forbidden" >&2
echo >&2
echo "The contract is what a host compiles against. It must stay free" >&2
echo "of transports, async runtimes, HTTP clients and native libraries." >&2
echo "This crate is what a harness and a host both compile against." >&2
echo "It must stay free of agent harnesses, transports, async" >&2
echo "runtimes, HTTP clients and native libraries. If this package" >&2
echo "is a genuinely reviewed addition, add it to the allowlist in" >&2
echo "this step in the same commit that adds the dependency." >&2
exit 1
fi

Expand All@@ -100,7 +138,6 @@ jobs:
- uses: actions/checkout@v7
with:
persist-credentials: false
submodules: recursive

- uses: dtolnay/rust-toolchain@stable

Expand All@@ -118,7 +155,6 @@ jobs:
- uses: actions/checkout@v7
with:
persist-credentials: false
submodules: recursive

# `rust-version` is inherited from `[workspace.package]`, so every member
# reports the same value. Read it off the package the module ships as
Expand All@@ -128,7 +164,7 @@ jobs:
run: |
set -euo pipefail
msrv="$(cargo metadata --format-version 1 --no-deps \
| jq -r '.packages[] | select(.name == "template") | .rust_version')"
| jq -r '.packages[] | select(.name == "tinytools") | .rust_version')"
if [[ -z "$msrv" || "$msrv" == "null" ]]; then
echo "workspace.package.rust-version is not set in Cargo.toml" >&2
exit 1
Expand All@@ -151,7 +187,6 @@ jobs:
- uses: actions/checkout@v7
with:
persist-credentials: false
submodules: recursive

- name: Check advisories, licenses, bans, and sources
uses: EmbarkStudios/cargo-deny-action@v2
Expand Down
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })(); feat: the agent tool vocabulary by senamakel · Pull Request #1 · tinyhumansai/tinytools · GitHub
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .github/ISSUE_TEMPLATE/config.yml
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
blank_issues_enabled: true
contact_links:
- name: Security reports
url: https://github.com/tinyhumansai/rust-template/security/policy
url: https://github.com/tinyhumansai/tinytools/security/policy
about: Please do not report vulnerabilities through public issues.
81 changes: 58 additions & 23 deletions .github/workflows/ci.yml
Original file line numberDiff line numberDiff line change
Expand Up@@ -26,7 +26,6 @@ jobs:
# This job executes repository code (cargo build/test); don't persist
# the token in git config.
persist-credentials: false
Comment thread
senamakel marked this conversation as resolved.
submodules: recursive

- uses: dtolnay/rust-toolchain@stable
with:
Expand All@@ -53,32 +52,71 @@ jobs:
- name: Test default features
run: cargo test

# `cargo build --all-targets` only *compiles* an example. `AGENTS.md`
# promises `cargo run -p template --example basic` works, and a compiled
# example can still fail on its first line.
- name: Run the bundled example
run: cargo run -p template --example basic

# `crates/template-bus` exists so a host can name the payload types
# without compiling the module. That promise is invisible in a diff,
# because a forbidden dependency arrives transitively through a feature
# someone enabled one crate away — so it is asserted rather than
# documented.
# This crate is the vocabulary both an agent harness and a host
# application link against, so its dependency list is a promise to both.
# That promise is invisible in a diff, because a forbidden dependency
# arrives transitively through a feature someone enabled one crate away —
# so it is asserted rather than documented.
#
# The FORWARD form is required. `cargo tree -i <crate> -p template-bus`
# `tinyagents` is on the list for a structural reason, not a size one: it
# depends on *this* crate. An edge back would be a cycle, and the
# `context` module's erasure trait exists precisely to make one
# unnecessary. Everything else on the list is weight a tool author should
# not have to compile to write a tool.
#
# The FORWARD form is required. `cargo tree -i <crate> -p tinytools`
# discards the `-p` scope, prints the whole-workspace inverse tree, and
# exits 0 looking clean even when this crate is the one at fault.
- name: Assert the contract crate stays transport-free
- name: Assert the vocabulary crate stays dependency-light
run: |
set -euo pipefail
forbidden="$(cargo tree -p template-bus -e normal,build --prefix none \
| grep -Ei 'tinybus|tokio|reqwest|ureq|hyper|rusqlite|git2' || true)"
# Compare crate NAMES only. `cargo tree` prints each package as
# `name vX.Y.Z (/path/to/checkout)`, and a consumer may vendor this
# repository *underneath* one of the forbidden crates — tinyagents
# does exactly that — so grepping the raw line matches the path and
# reports a dependency that is not there. Cut the version and path off
# first.
package_names="$(cargo tree -p tinytools --all-features -e normal,build --prefix none \
| awk '{print $1}' | sort -u)"

# An ALLOWLIST, not a blocklist: naming eight forbidden crates only
# catches those eight. Adding `surf`, `async-std`, an arbitrary
# `*-sys` native binding, or any other transport/runtime would pass
# silently under a blocklist. Every package this crate's forward tree
# is reviewed to actually contain is named here instead, so *any*
# newly introduced package — forbidden or merely unreviewed — fails
# the gate until this list is updated in the same commit.
allowed='
tinytools
anyhow
async-trait
serde
serde_core
serde_derive
serde_json
proc-macro2
quote
syn
unicode-ident
itoa
memchr
zmij
'

# Anything in package_names that is not a line of $allowed.
forbidden="$(comm -23 \
<(printf '%s\n' "$package_names") \
<(printf '%s\n' "$allowed" | sort -u))"

if [ -n "$forbidden" ]; then
echo "template-bus pulled in a dependency its manifest forbids:" >&2
echo "tinytools pulled in a dependency its manifest doesn't review for:" >&2
echo "$forbidden" >&2
echo >&2
echo "The contract is what a host compiles against. It must stay free" >&2
echo "of transports, async runtimes, HTTP clients and native libraries." >&2
echo "This crate is what a harness and a host both compile against." >&2
echo "It must stay free of agent harnesses, transports, async" >&2
echo "runtimes, HTTP clients and native libraries. If this package" >&2
echo "is a genuinely reviewed addition, add it to the allowlist in" >&2
echo "this step in the same commit that adds the dependency." >&2
exit 1
fi

Expand All@@ -100,7 +138,6 @@ jobs:
- uses: actions/checkout@v7
with:
persist-credentials: false
submodules: recursive

- uses: dtolnay/rust-toolchain@stable

Expand All@@ -118,7 +155,6 @@ jobs:
- uses: actions/checkout@v7
with:
persist-credentials: false
submodules: recursive

# `rust-version` is inherited from `[workspace.package]`, so every member
# reports the same value. Read it off the package the module ships as
Expand All@@ -128,7 +164,7 @@ jobs:
run: |
set -euo pipefail
msrv="$(cargo metadata --format-version 1 --no-deps \
| jq -r '.packages[] | select(.name == "template") | .rust_version')"
| jq -r '.packages[] | select(.name == "tinytools") | .rust_version')"
if [[ -z "$msrv" || "$msrv" == "null" ]]; then
echo "workspace.package.rust-version is not set in Cargo.toml" >&2
exit 1
Expand All@@ -151,7 +187,6 @@ jobs:
- uses: actions/checkout@v7
with:
persist-credentials: false
submodules: recursive

- name: Check advisories, licenses, bans, and sources
uses: EmbarkStudios/cargo-deny-action@v2
Expand Down
Loading