Skip to content

fix(responses): strip unsupported hosted web_search on Xiaomi MiMo destinations - #5944

Closed
codingbooo wants to merge 1 commit into
lidge-jun:devfrom
codingbooo:fix/issue-5501-mimo-web-search
Closed

codingbooo wants to merge 1 commit into
lidge-jun:devfrom
codingbooo:fix/issue-5501-mimo-web-search

Conversation

@codingbooo

@codingbooo codingbooo commented Sep 26, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Fixes #5501 by stripping unsupported hosted web_search and web_search_preview tool declarations when routing OpenAI-compatible Responses requests to Xiaomi MiMo destinations (xiaomimimo.com and its subdomains, e.g. api.xiaomimimo.com and token-plan-cn.xiaomimimo.com).

Changes

  • Hosted tool destination policy: Added a destination entry to UNSUPPORTED_HOSTED_TOOLS in src/responses/hosted-tool-policy.ts that matches xiaomimimo.com hosts (parsed via new URL(baseUrl).hostname), denying web_search and web_search_preview.
  • Preserves function tools & standard destinations: Custom function tools are preserved; standard OpenAI and other destinations retain hosted web_search untouched.
  • Unit tests: Added 23 regression test assertions in tests/responses/responses-hosted-tool-declaration.test.ts covering stripping, selector reconciliation, negative controls, and hostname parsing edge cases.
  • Documentation: Updated providers.md and chat-compat.md explaining automatic hosted tool stripping for MiMo hosts.

Verification

  • bun run typecheck: clean 0 errors.
  • bun test tests/responses/responses-hosted-tool-declaration.test.ts: 34 pass, 0 fail.

Checklist

  • I have tested my changes locally.
  • I have updated relevant documentation / tests.
  • I have followed the project's code style and contributing guidelines.

Review readiness checklist

This PR stays in draft until every box below is ticked. Tick all four boxes once the requirements are met:

  • Required local validation passed; commands, results, and any full-suite exception are documented.

  • I pushed my PR to a recent dev commit (at most 10 behind; a maintainer may still ask for the exact tip before merge).

  • I resolved all correct Codex and CodeRabbit findings.

  • My PR is ready for review.

Summary by CodeRabbit

  • Behavior Changes
    • Requests sent to Xiaomi MiMo destinations no longer include hosted web_search or web_search_preview tools. Function tools remain available, and matching works across the provider’s domain and subdomains.
    • OpenCode Go is no longer treated as blocking hosted web search.

@github-actions

Copy link
Copy Markdown
Contributor

✅ Deterministic PR hygiene checks passed.

@github-actions github-actions Bot added the bug Something isn't working label Sep 26, 2026
@github-actions

github-actions Bot commented Sep 26, 2026 •

Copy link
Copy Markdown
Contributor

✅ READY

  • all PR quality gates passed; the review readiness checklist is complete.

Review readiness checklist

  • ✅ Required local validation passed; commands, results, and any full-suite exception are documented.
  • ✅ I pushed my PR to a recent dev commit (at most 10 behind; a maintainer may still ask for the exact tip before merge).
  • ✅ I resolved all correct Codex and CodeRabbit findings.
  • ✅ My PR is ready for review.

✅ 4/4 boxes ticked.

This pull request is already Ready for Review.
The review-ready label marks this PR as ready; review automation runs independently.
Maintainers: @lidge-jun @Ingwannu

@coderabbitai

coderabbitai Bot commented Sep 26, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository: lidge-jun/opencodex/.coderabbit.yaml

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 464e0534-c26f-4dd3-a559-102d2037196f

📥 Commits

Reviewing files that changed from the base of the PR and between bb3f3c2 and 558375c.

📒 Files selected for processing (4)
  • docs-site/src/content/docs/reference/configuration/providers.md
  • src/responses/hosted-tool-policy.ts
  • structure/providers/chat-compat.md
  • tests/responses/responses-hosted-tool-declaration.test.ts

Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 7 remain after this review.


📝 Walkthrough

Walkthrough

The hosted-tool policy now removes web_search and web_search_preview for valid MiMo destination hostnames. Tests cover tool filtering and URL matching. Provider documentation describes the behavior.

Changes

MiMo hosted search compatibility

Layer / File(s) Summary
MiMo destination policy and validation
src/responses/hosted-tool-policy.ts, tests/responses/responses-hosted-tool-declaration.test.ts, structure/providers/chat-compat.md, docs-site/src/content/docs/reference/configuration/providers.md
A valid base URL whose hostname ends in xiaomimimo.com marks both hosted search tool spellings unsupported. Tests check filtering of tools and selectors, preservation of function tools, and matching and non-matching URLs. The compatibility table and provider documentation describe the rule. The OpenCode Go test comment and compatibility text now state that it keeps hosted search.

Priority: ➖ Normal

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Bug fix · Severity of issue fixed: Medium

Merge Risk: ⚪ Minimal · up to 55837

The MiMo destination rule strips unsupported hosted search declarations while preserving function tools. No merge-blocking issue is identified.

Security Architecture Review

Security architecture risk: 🔵 Low · up to 55837

The change removes unsupported hosted search tools for Xiaomi destinations without adding a tool capability or expanding privileges. Risk remains low, with some uncertainty around custom destination routing.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The changed decision affects hosted search declarations on Responses requests classified as Xiaomi-bound; nonmatching destinations retain the prior pass-through behavior.

Trust Boundaries and Controls

  • inferred — Hostname classification follows the configured URL, not the eventual backend behind a proxy or alias. An alias that does not match Xiaomi's hostname will not trigger this compatibility filter; the examined change does not show request-body control of the configured URL or a new authorization bypass.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Linked Issues check ✅ Passed Issue #5501 requires MiMo Responses requests to complete without the rejected web_search declaration. src/responses/hosted-tool-policy.ts:12-22 matches xiaomimimo.com and subdomains by parsed ho…
Out of Scope Changes check ✅ Passed The changed files stay within Issue #5501. The policy change implements MiMo routing behavior. The test additions verify removal, selector reconciliation, function-tool retention, and unchanged behavi…
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 2…
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely describes the main change: removing unsupported hosted web search tools from Responses requests sent to Xiaomi MiMo destinations.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions
github-actions Bot marked this pull request as draft September 26, 2026 13:25
@codingbooo
codingbooo marked this pull request as ready for review September 26, 2026 13:26
@github-actions
github-actions Bot marked this pull request as draft September 26, 2026 13:26
@codingbooo
codingbooo marked this pull request as ready for review September 26, 2026 13:28
@lidge-jun

Copy link
Copy Markdown
Owner

리뷰 · 우선순위 74 / 80

Codex가 Xiaomi MiMo로 글을 보내면, 검색을 안 하는 문장에도 web_search가 같이 붙습니다. MiMo는 그 도구를 이 단계에서 받지 않는다고 거절합니다. 답변이 오기 전에 요청이 끝납니다. 이슈 #5501의 에러 문장입니다.

이 PR은 요청 주소의 호스트가 xiaomimimo.com이거나 그 아래 이름이면, Responses로 나가는 본문에서 web_search와 web_search_preview만 지웁니다. 사람이 만든 function 도구는 남깁니다. 도구 선택이 그 검색뿐이면 선택을 none으로 바꿉니다. 공개 API api.xiaomimimo.com과 토큰 플랜 token-plan-cn.xiaomimimo.com이 둘 다 들어갑니다. 다른 회사 주소의 경로나 쿼리에 그 글자가 있어도 검색은 그대로 둡니다. 주소가 비었거나 깨져 있으면 MiMo로 보지 않습니다.

바탕은 dev입니다. types.ts와 config.ts를 나누는 변경은 아닙니다. 이 이슈를 고치는 다른 열린 PR은 없습니다. #5754는 이미 머지되었고, runTurn 어댑터의 검색이라 이 호스트 규칙과 다릅니다.

라인 - docs-site/src/content/docs/reference/configuration/providers.md의 unsupportedHostedTools. MiMo에서 검색을 빼는 코드는 이 설정 칸을 읽지 않습니다. 호스트 표가 합니다. 설명은 그 칸 문장 한가운데에 있습니다. 칸을 비우거나 null로 지워도 삭제는 남습니다. 문장만 보면 칸을 지우면 검색이 다시 나가는 것처럼 읽힙니다.

라인 - src/responses/hosted-tool-policy.ts의 UNSUPPORTED_HOSTED_TOOLS. 이 표는 Responses를 직렬화할 때만 적용됩니다. 레지스트리의 xiaomi-mimo와 mimo는 Chat 어댑터입니다. 그 프리셋만 쓰면 이 함수가 요청을 보지 않습니다. 이슈의 에러는 Responses 본문이 게이트웨이에 닿았을 때의 문장이라, 주소를 Responses로 둔 설정에는 맞습니다.

메인테이너의 판단이 필요한 지점

이슈를 연 사람은 웹 검색이 동작하기를 원했습니다. 이 PR은 검색을 실행하지 않습니다. 거절나던 선언을 지워서 글 답이 나오게 합니다. 선택이 그 검색뿐이면 none이 되고, 클라이언트에는 검색을 뺐다는 오류가 가지 않습니다. 9월 23일 메인테이너 댓글은, 위쪽이 그 도구를 안 받으면 없는 능력으로 바꾸지 말라고 했습니다. 이 PR은 그 댓글과 같습니다. 검색을 대신 구현할지, 선언만 지울지 정해 주세요.

호스트를 어디까지 볼지도 정해 주세요. 이슈에 적힌 주소는 api.xiaomimimo.com입니다. 코드는 xiaomimimo.com으로 끝나는 호스트를 전부 봅니다.

너의 추천

선언을 지우는 쪽으로 두세요. 닫을 중복 PR은 없습니다. 문서의 MiMo 문장은 unsupportedHostedTools 칸 밖으로 빼세요. 그 칸을 지워도 호스트 표가 검색을 뺀다고 적으면 됩니다. Chat 프리셋은 이 이슈의 재현이 아니면 건드리지 마세요. 준비 체크는 4/4입니다.

이 댓글은 grok-bot이 작성했습니다

lidge-jun added a commit that referenced this pull request Sep 26, 2026
)

Six focused fixes from the assigned bug batch remain as separate attributed commits.

| PR | Change | Author |
| --- | --- | --- |
| #5969 | Preserve Meta Muse tool-choice semantics and reject unsupported selectors before dispatch. | shawnkim |
| #5944 | Remove unsupported hosted web-search declarations for Xiaomi MiMo destinations. | codingbo |
| #5938 | Restart the Windows service child after unexpected exits, including exit 0, while reserving the intentional stay-out code. | codingbo |
| #5935 | Reject Claude message-thread state on translated routes so the client resends full history. | kaladinhonor |
| #5939 | Rewrite standalone `\\0` escapes in Meta tool-schema patterns to equivalent `\\x00`. | boblob6969 |
| #5951 | Preserve Kiro-reported credits across stream attempts and in the usage ledger. | codingbo |

A separate integration commit keeps upstream-controlled Kiro event-type text out of opt-in debug logs. The Kiro stream retains the previously landed bounded HTTP-error text when combined with credit metering.

Left out: #5977. Independent security review found that its local read capability authenticates the request but not the HTTP response. A substituted listener could return a shape-valid forged `protected` verdict. A correct server proof bound to the nonce, endpoint, and body is outside this batch. Both its source commit and status-validation follow-up were reverted in new commits; its test and layout entries are gone. The source PR remains open.

Co-authored-by: shawnkim <shawnkim@markncompany.co.kr>
Co-authored-by: codingbo <cnsdbo@163.com>
Co-authored-by: kaladinhonor <266145786+kaladinhonor@users.noreply.github.com>
Co-authored-by: boblob6969 <boblob6969@icloud.com>
@lidge-jun

Copy link
Copy Markdown
Owner

Thanks! This landed on dev through bug-PR merge train batch 9B, #5985 (merge bf04176). Your change is one commit on dev with you as the author and a Co-authored-by trailer. Closing since the content is now on dev.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working review-ready

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants