fix(kiro): canonicalize tool history and route API keys correctly

Route API-key inference through Amazon Q first, enforce adjacent
one-to-one tool use/result pairs after session replay, and treat
payload-invalid HTTP 400 as terminal.
This commit is contained in:
nguyenha935
2026-07-29 19:25:45 +07:00
parent 44c7b34837
commit 16cb40fda1
14 changed files with 1050 additions and 465 deletions

View File

@@ -6,17 +6,10 @@
* direct `claude:kiro` route in ../index.js uses; it is NOT reached through the
* claude→openai→kiro pivot.
*
* It reproduces the two 400-guards that live in openai-to-kiro.js so that a
* Claude client which omits the `tools` array on a follow-up turn (typical
* after client-side compaction) does not trip Kiro's schema validator and get
* "Improperly formed request" (HTTP 400):
*
* 1. flattenClaudeToolInteractions — when the client sent NO tools, collapse
* every tool_use / tool_result block to plain text so no structured tool
* reference survives to trigger the "tools required" rule.
* 2. reconcileOrphanedToolResults — when tools ARE present, fold any
* tool_result whose tool_use_id has no matching tool_use back into the
* user text instead of leaving a dangling structured reference.
* After session replay it delegates to the shared Kiro conversation
* canonicalizer. That layer enforces adjacent one-to-one tool use/results,
* repairs partial parallel calls, and flattens compacted structured references
* that can no longer be represented safely.
*
* It also handles the 9router-synthetic `-agentic` / `-thinking` suffixes and
* the `<thinking_mode>enabled</thinking_mode>` reasoning trigger, matching
@@ -38,82 +31,17 @@ import {
} from "../../config/kiroConstants.js";
import { DEFAULT_IMAGE_MIME } from "../schema/index.js";
import { ROLE, CLAUDE_BLOCK } from "../schema/index.js";
/** Stringify a tool_use input as a readable line. */
function toolUseToText(name, input) {
let argStr;
try {
argStr = typeof input === "string" ? input : JSON.stringify(input ?? {});
} catch {
argStr = "{}";
}
return `[Tool call: ${name || "unknown"}(${argStr})]`;
}
/** Render a Claude tool_result block's content as a readable line. */
function toolResultBlockToText(content) {
let text = "";
if (typeof content === "string") {
text = content;
} else if (Array.isArray(content)) {
text = content
.map((c) => (typeof c === "string" ? c : c?.text || ""))
.filter(Boolean)
.join("\n");
} else if (content) {
try {
text = JSON.stringify(content);
} catch {
text = "";
}
}
return `[Tool result: ${text}]`;
}
/**
* When the client sent no tools, rewrite every tool_use (assistant) and
* tool_result (user) content block into plain text. Keeps text + images.
* Returns a new messages array; never mutates the input.
*/
function flattenClaudeToolInteractions(messages) {
const out = [];
for (const msg of messages) {
if (!msg) continue;
if (msg.role === ROLE.ASSISTANT && Array.isArray(msg.content)) {
const parts = [];
for (const block of msg.content) {
if (block.type === CLAUDE_BLOCK.TEXT && block.text) {
parts.push(block.text);
} else if (block.type === CLAUDE_BLOCK.TOOL_USE) {
parts.push(toolUseToText(block.name, block.input));
}
}
out.push({ ...msg, content: parts.join("\n") });
continue;
}
if (msg.role === ROLE.USER && Array.isArray(msg.content)) {
const newContent = msg.content.map((block) =>
block.type === CLAUDE_BLOCK.TOOL_RESULT
? { type: CLAUDE_BLOCK.TEXT, text: toolResultBlockToText(block.content) }
: block
);
out.push({ ...msg, content: newContent });
continue;
}
out.push(msg);
}
return out;
}
import {
canonicalizeKiroConversation,
normalizeKiroToolSpecs,
} from "../concerns/kiroConversation.js";
/**
* Convert Claude messages to Kiro history + currentMessage.
* Kiro requires alternating user/assistant turns; consecutive same-role
* messages are merged.
*/
function convertClaudeMessagesToKiro(messages, tools, model) {
function convertClaudeMessagesToKiro(messages, model) {
const history = [];
let currentMessage = null;
@@ -122,27 +50,6 @@ function convertClaudeMessagesToKiro(messages, tools, model) {
let pendingToolResults = [];
let pendingImages = [];
let currentRole = null;
let toolsInjected = false;
const clientProvidedTools = Array.isArray(tools) && tools.length > 0;
const buildToolSpecs = () =>
tools.map((t) => {
const name = t.name;
const description = t.description || `Tool: ${name}`;
const schema = t.input_schema || {};
const normalizedSchema =
Object.keys(schema).length === 0
? { type: "object", properties: {}, required: [] }
: { ...schema, required: schema.required ?? [] };
return {
toolSpecification: {
name,
description,
inputSchema: { json: normalizedSchema },
},
};
});
const flushPending = () => {
if (currentRole === ROLE.USER) {
@@ -157,15 +64,6 @@ function convertClaudeMessagesToKiro(messages, tools, model) {
toolResults: pendingToolResults,
};
}
// Attach tools to the first user turn only.
if (clientProvidedTools && !toolsInjected) {
if (!userMsg.userInputMessage.userInputMessageContext) {
userMsg.userInputMessage.userInputMessageContext = {};
}
userMsg.userInputMessage.userInputMessageContext.tools = buildToolSpecs();
toolsInjected = true;
}
history.push(userMsg);
currentMessage = userMsg;
pendingUserContent = [];
@@ -209,7 +107,7 @@ function convertClaudeMessagesToKiro(messages, tools, model) {
}
pendingToolResults.push({
toolUseId: block.tool_use_id,
status: "success",
status: block.is_error ? "error" : "success",
content: [{ text: resultContent }],
});
}
@@ -256,14 +154,7 @@ function convertClaudeMessagesToKiro(messages, tools, model) {
}
}
// Grab tools from the first history user turn before cleanup strips them.
const firstHistoryTools =
history[0]?.userInputMessage?.userInputMessageContext?.tools;
history.forEach((item) => {
if (item.userInputMessage?.userInputMessageContext?.tools) {
delete item.userInputMessage.userInputMessageContext.tools;
}
if (
item.userInputMessage?.userInputMessageContext &&
Object.keys(item.userInputMessage.userInputMessageContext).length === 0
@@ -307,66 +198,9 @@ function convertClaudeMessagesToKiro(messages, tools, model) {
currentMessage = { userInputMessage: { content: "", modelId: model } };
}
// Inject tools into currentMessage after cleanup if not already present.
if (
firstHistoryTools?.length > 0 &&
!currentMessage.userInputMessage.userInputMessageContext?.tools
) {
if (!currentMessage.userInputMessage.userInputMessageContext) {
currentMessage.userInputMessage.userInputMessageContext = {};
}
currentMessage.userInputMessage.userInputMessageContext.tools =
firstHistoryTools;
}
return { history: mergedHistory, currentMessage };
}
/**
* Fold orphaned toolResults (those whose toolUseId has no matching toolUse in
* any assistant turn) back into the user text, removing the dangling
* structured reference that makes Kiro 400.
*/
function reconcileOrphanedToolResults(history, currentMessage) {
const validIds = new Set();
for (const h of history) {
const arm = h.assistantResponseMessage;
if (!arm) continue;
for (const tu of arm.toolUses || []) {
if (tu.toolUseId) validIds.add(tu.toolUseId);
}
}
const carriers = currentMessage ? [...history, currentMessage] : history;
for (const item of carriers) {
const uim = item.userInputMessage;
const ctx = uim?.userInputMessageContext;
if (!ctx?.toolResults?.length) continue;
const kept = [];
const salvaged = [];
for (const tr of ctx.toolResults) {
if (validIds.has(tr.toolUseId)) {
kept.push(tr);
} else {
const text = Array.isArray(tr.content)
? tr.content.map((c) => c?.text || "").join("\n")
: "";
salvaged.push(`[Tool result: ${text}]`);
}
}
if (salvaged.length === 0) continue;
const extra = salvaged.join("\n");
uim.content = uim.content ? `${uim.content}\n\n${extra}` : extra;
ctx.toolResults = kept;
if (kept.length === 0 && !ctx.tools?.length) {
delete uim.userInputMessageContext;
}
}
}
function extractClaudeSystemText(system) {
if (!system) return "";
if (typeof system === "string") return system;
@@ -383,9 +217,8 @@ function extractClaudeSystemText(system) {
* Build a Kiro payload directly from a Claude Messages API request body.
*/
export function claudeToKiroRequest(model, body, stream, credentials) {
let messages = Array.isArray(body.messages) ? body.messages : [];
const messages = Array.isArray(body.messages) ? body.messages : [];
const tools = Array.isArray(body.tools) ? body.tools : [];
const clientProvidedTools = tools.length > 0;
const maxTokens = body.max_tokens || 32000;
const temperature = body.temperature;
const topP = body.top_p;
@@ -397,21 +230,8 @@ export function claudeToKiroRequest(model, body, stream, credentials) {
const additionalModelRequestFields = buildKiroAdditionalModelRequestFieldsForModel(thinkingBody, upstreamModel);
const usesNativeGptEffort = usesKiroNativeGptEffort(thinkingBody, upstreamModel);
// Guard 1: no client tools → flatten all tool interactions to text.
if (!clientProvidedTools) {
messages = flattenClaudeToolInteractions(messages);
}
const { history, currentMessage } = convertClaudeMessagesToKiro(
messages,
tools,
upstreamModel
);
// Guard 2: tools present → reconcile dangling tool_results.
if (clientProvidedTools) {
reconcileOrphanedToolResults(history, currentMessage);
}
const { specs: toolSpecs, nameMap } = normalizeKiroToolSpecs(tools);
const { history, currentMessage } = convertClaudeMessagesToKiro(messages, upstreamModel);
// api_key / idc / external_idp must never use the shared default ARN (belongs
// to another account → 403 "bearer token invalid"); OAuth/social fall back to it.
@@ -460,7 +280,14 @@ export function claudeToKiroRequest(model, body, stream, credentials) {
history,
currentMessage,
});
const replayCurrent = replay.currentMessage?.userInputMessage || {};
const canonical = canonicalizeKiroConversation({
history: replay.history,
currentMessage: replay.currentMessage,
modelId: upstreamModel,
toolSpecs,
nameMap,
});
const replayCurrent = canonical.currentMessage.userInputMessage;
const userInputMessage = {
content: replayCurrent.content || "",
modelId: upstreamModel,
@@ -482,7 +309,7 @@ export function claudeToKiroRequest(model, body, stream, credentials) {
currentMessage: {
userInputMessage,
},
history: replay.history,
history: canonical.history,
},
agentMode: "vibe",
};

View File

@@ -20,148 +20,10 @@ import {
import { parseDataUri } from "../concerns/image.js";
import { DEFAULT_IMAGE_MIME } from "../schema/index.js";
import { ROLE, OPENAI_BLOCK, CLAUDE_BLOCK } from "../schema/index.js";
/** Render a single tool call as a readable text line. */
function toolCallToText(name, input) {
let argStr;
try {
argStr = typeof input === "string" ? input : JSON.stringify(input ?? {});
} catch {
argStr = "{}";
}
return `[Tool call: ${name || "unknown"}(${argStr})]`;
}
/** Render a tool result (string or content-block array) as a text line. */
function toolResultToText(content) {
const text = Array.isArray(content)
? content.map(c => (typeof c === "string" ? c : c.text || "")).join("\n")
: (typeof content === "string" ? content : "");
return `[Tool result: ${text}]`;
}
/**
* Flatten all tool calls/results in a conversation into plain text.
*
* Kiro's schema validator requires a non-empty
* currentMessage.userInputMessageContext.tools array whenever the history
* references any tool use; otherwise it returns "Improperly formed request"
* (HTTP 400). A client can hit this by omitting the `tools` array on a
* follow-up request — typically after client-side compaction (e.g. OpenCode).
*
* Rather than fabricate stub tool specs — which would advertise tool-calling
* capability the client never requested and may not handle, risking a phantom
* tool call on an otherwise plain turn — we collapse the tool interaction into
* text. The request stays honest, and since no structured tool content
* remains, the validator's "tools required" rule never fires.
*
* Only invoked when the client did NOT send tools; when tools are present the
* structured form is preserved.
*/
function flattenToolInteractions(messages) {
const out = [];
for (const msg of messages) {
// OpenAI tool-result message → user text line
if (msg.role === ROLE.TOOL) {
out.push({ role: ROLE.USER, content: toolResultToText(msg.content) });
continue;
}
if (msg.role === ROLE.ASSISTANT) {
const parts = [];
if (Array.isArray(msg.content)) {
for (const c of msg.content) {
if (c.type === CLAUDE_BLOCK.TOOL_USE) {
parts.push(toolCallToText(c.name, c.input));
} else if (c.type === OPENAI_BLOCK.TEXT || c.text) {
parts.push(c.text || "");
}
}
} else if (typeof msg.content === "string") {
parts.push(msg.content);
}
for (const tc of msg.tool_calls || []) {
parts.push(toolCallToText(tc.function?.name, tc.function?.arguments));
}
out.push({ role: ROLE.ASSISTANT, content: parts.filter(Boolean).join("\n") });
continue;
}
// User messages: replace tool_result blocks with text, keep text + images.
if (msg.role === ROLE.USER && Array.isArray(msg.content)) {
const newContent = msg.content.map(c =>
c.type === CLAUDE_BLOCK.TOOL_RESULT
? { type: OPENAI_BLOCK.TEXT, text: toolResultToText(c.content) }
: c
);
out.push({ ...msg, content: newContent });
continue;
}
out.push(msg);
}
return out;
}
/**
* Reconcile orphaned toolResults — those whose toolUseId has no matching
* toolUse in any assistant message. This happens when client-side compaction
* truncates the conversation and removes the assistant message containing the
* tool_use, but keeps the user message with the corresponding tool_result.
*
* A dangling structured reference makes Kiro return 400, so it must be removed.
* But the client deliberately kept the result content through compaction, so
* rather than discard it we fold it back into the user message as text — the
* same shape flattenToolInteractions() produces. The 400 trigger (the
* structured reference) is gone; the content survives.
*
* `messages` is every carrier that can hold toolResults — both history items
* and the popped-out currentMessage (orphans can land on either).
*/
function reconcileOrphanedToolResults(history, currentMessage) {
// Phase 1: collect all valid toolUseIds from assistant messages in history.
// (currentMessage is always a user turn, so it carries no toolUses.)
const validIds = new Set();
for (const h of history) {
const arm = h.assistantResponseMessage;
if (!arm) continue;
for (const tu of arm.toolUses || []) {
if (tu.toolUseId) validIds.add(tu.toolUseId);
}
}
// Phase 2: across history + currentMessage, keep results with a matching
// toolUse and salvage the rest as text.
const carriers = currentMessage ? [...history, currentMessage] : history;
for (const item of carriers) {
const uim = item.userInputMessage;
const ctx = uim?.userInputMessageContext;
if (!ctx?.toolResults?.length) continue;
const kept = [];
const salvaged = [];
for (const tr of ctx.toolResults) {
if (validIds.has(tr.toolUseId)) {
kept.push(tr);
} else {
salvaged.push(toolResultToText(tr.content));
}
}
if (salvaged.length === 0) continue; // no orphans — leave untouched
// Fold orphaned result content into the user text so it is not lost
const extra = salvaged.join("\n");
uim.content = uim.content ? `${uim.content}\n\n${extra}` : extra;
ctx.toolResults = kept;
if (kept.length === 0 && !ctx.tools?.length) {
delete uim.userInputMessageContext;
}
}
}
import {
canonicalizeKiroConversation,
normalizeKiroToolSpecs,
} from "../concerns/kiroConversation.js";
/**
* Safely parse JSON string, returning fallback on failure.
@@ -177,26 +39,15 @@ function safeJSONParse(str, fallback) {
*
* Returns { history, currentMessage }.
*/
function convertMessages(messages, tools, model) {
function convertMessages(messages, model) {
let history = [];
let currentMessage = null;
const clientProvidedTools = tools && tools.length > 0;
// When the client did not send tools, flatten any tool calls/results in the
// history into plain text (see flattenToolInteractions). This keeps the
// request honest and sidesteps Kiro's "tools required" 400, since no
// structured tool content survives to trigger it.
if (!clientProvidedTools) {
messages = flattenToolInteractions(messages);
}
let pendingUserContent = [];
let pendingAssistantContent = [];
let pendingToolResults = [];
let pendingImages = [];
let currentRole = null;
let toolsInjectedToFirstUserMsg = false;
const flushPending = () => {
if (currentRole === "user") {
@@ -219,39 +70,6 @@ function convertMessages(messages, tools, model) {
};
}
// Add tools to the user message that has no preceding assistant messages,
// OR the first user message (whichever comes first after any opening
// assistant messages). We track whether any user message has already
// received tools via a flag on the history array.
if (clientProvidedTools && !toolsInjectedToFirstUserMsg) {
if (!userMsg.userInputMessage.userInputMessageContext) {
userMsg.userInputMessage.userInputMessageContext = {};
}
userMsg.userInputMessage.userInputMessageContext.tools = tools.map(t => {
const name = t.function?.name || t.name;
let description = t.function?.description || t.description || "";
if (!description.trim()) {
description = `Tool: ${name}`;
}
const schema = t.function?.parameters || t.parameters || t.input_schema || {};
// Normalize schema: Kiro requires required[] and proper type/properties
const normalizedSchema = Object.keys(schema).length === 0
? { type: "object", properties: {}, required: [] }
: { ...schema, required: schema.required ?? [] };
return {
toolSpecification: {
name,
description,
inputSchema: { json: normalizedSchema }
}
};
});
toolsInjectedToFirstUserMsg = true;
}
history.push(userMsg);
currentMessage = userMsg;
pendingUserContent = [];
@@ -327,7 +145,7 @@ function convertMessages(messages, tools, model) {
pendingToolResults.push({
toolUseId: block.tool_use_id,
status: "success",
status: block.is_error ? "error" : "success",
content: [{ text: text }]
});
});
@@ -339,7 +157,7 @@ function convertMessages(messages, tools, model) {
const toolContent = typeof msg.content === "string" ? msg.content : "";
pendingToolResults.push({
toolUseId: msg.tool_call_id,
status: "success",
status: msg.is_error || msg.status === "error" ? "error" : "success",
content: [{ text: toolContent }]
});
} else if (content) {
@@ -413,14 +231,8 @@ function convertMessages(messages, tools, model) {
}
}
// Grab tools from first history item BEFORE cleanup removes them
const firstHistoryTools = history[0]?.userInputMessage?.userInputMessageContext?.tools;
// Clean up history for Kiro API compatibility
history.forEach(item => {
if (item.userInputMessage?.userInputMessageContext?.tools) {
delete item.userInputMessage.userInputMessageContext.tools;
}
if (item.userInputMessage?.userInputMessageContext &&
Object.keys(item.userInputMessage.userInputMessageContext).length === 0) {
delete item.userInputMessage.userInputMessageContext;
@@ -473,33 +285,6 @@ function convertMessages(messages, tools, model) {
};
}
// Reconcile orphaned toolResults across history AND currentMessage — when
// client-side compaction removes assistant messages containing tool_use but
// keeps the tool_result, the dangling reference triggers a Kiro 400. Fold the
// content back into the user text instead of discarding it. Run after
// currentMessage is finalized (an orphan can be merged into it) and before
// tool injection (which may re-add userInputMessageContext).
//
// Only needed on the tools-present path: when the client sent no tools,
// flattenToolInteractions already collapsed every toolResult to text, so
// there is nothing structured left to orphan.
if (clientProvidedTools) {
reconcileOrphanedToolResults(mergedHistory, currentMessage);
}
// Inject tools into currentMessage AFTER cleanup. Tools only exist here when
// the client explicitly sent them (otherwise flattenToolInteractions already
// collapsed all tool content to text upstream, so there is nothing to carry).
const resolvedTools = firstHistoryTools;
if (resolvedTools?.length > 0 &&
!currentMessage.userInputMessage.userInputMessageContext?.tools) {
if (!currentMessage.userInputMessage.userInputMessageContext) {
currentMessage.userInputMessage.userInputMessageContext = {};
}
currentMessage.userInputMessage.userInputMessageContext.tools = resolvedTools;
}
return { history: mergedHistory, currentMessage };
}
@@ -532,7 +317,8 @@ export function openaiToKiroRequest(model, body, stream, credentials) {
const additionalModelRequestFields = buildKiroAdditionalModelRequestFieldsForModel(thinkingBody, upstreamModel);
const usesNativeGptEffort = usesKiroNativeGptEffort(thinkingBody, upstreamModel);
const { history, currentMessage } = convertMessages(messages, tools, upstreamModel);
const { specs: toolSpecs, nameMap } = normalizeKiroToolSpecs(tools);
const { history, currentMessage } = convertMessages(messages, upstreamModel);
// API-key (headless) auth uses a raw CodeWhisperer credential whose profile is
// account-specific. Injecting the shared builder-id/social *default* placeholder
@@ -586,7 +372,14 @@ export function openaiToKiroRequest(model, body, stream, credentials) {
history,
currentMessage,
});
const replayCurrent = replay.currentMessage?.userInputMessage || {};
const canonical = canonicalizeKiroConversation({
history: replay.history,
currentMessage: replay.currentMessage,
modelId: upstreamModel,
toolSpecs,
nameMap,
});
const replayCurrent = canonical.currentMessage.userInputMessage;
const payload = {
conversationState: {
@@ -607,7 +400,7 @@ export function openaiToKiroRequest(model, body, stream, credentials) {
})
}
},
history: replay.history
history: canonical.history
},
agentMode: "vibe",
};