Skip to content

docs(research): plan first-class attachments - #4223

Closed
AndrewBarba wants to merge 4 commits into
mainfrom
research/first-class-attachments
Closed

AndrewBarba wants to merge 4 commits into
mainfrom
research/first-class-attachments

Conversation

@AndrewBarba

@AndrewBarba AndrewBarba commented Oct 2, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

#4224 keeps attachment bytes out of session history, but the session sandbox is still the only store. Files can vanish when a snapshot changes, and every attachment boots a sandbox. The model also can't reopen a visible image by path, and one oversized image breaks every later call. This research plan proposes a pluggable attachment store with the sandbox as the default, so behavior without configuration does not change. Vercel Blob is opt-in. Two model-facing fixes ship first: path labels on every attachment and a pixel gate.

Related to #3833, #276, and #4194.

Scope decisions:

The plan also compares the attachment handling in opencode v2, Codex, and pi. This PR adds only the plan. It changes no code.

Validation

  • oxfmt --check research/first-class-attachments.md and git diff --check pass.
  • I checked the plan's claims about current code against the source. A fresh-context review checked the plan end to end against eight scenarios, and this revision addresses its findings.
  • Not applicable: tests and changeset, because this is a research document only.

Checklist

  • This change was requested or approved by a maintainer
  • I ran the relevant checks from CONTRIBUTING.md
  • I added tests and documentation where relevant
  • I added a changeset if this touches the published eve package
  • DCO sign-off passes for every commit (git commit --signoff)

Signed-off-by: Andrew Barba <barba@hey.com>
@vercel

vercel Bot commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
eve-docs Ready Ready Preview, v0 Oct 7, 2026 6:13pm UTC
eve-pkg Ready Ready Preview, v0 Oct 7, 2026 6:13pm UTC

Comment thread research/first-class-attachments.md Outdated
Comment thread research/first-class-attachments.md Outdated
Comment thread research/first-class-attachments.md Outdated
Comment thread research/first-class-attachments.md Outdated
Comment thread research/first-class-attachments.md Outdated
Comment thread research/first-class-attachments.md Outdated
Comment thread research/first-class-attachments.md Outdated
Comment thread research/first-class-attachments.md Outdated
Comment thread research/first-class-attachments.md Outdated
Comment thread research/first-class-attachments.md Outdated
@cmpadden
cmpadden marked this pull request as ready for review October 2, 2026 19:16
@cmpadden
cmpadden marked this pull request as draft October 2, 2026 19:17
Comment thread research/first-class-attachments.md Outdated
| ------------------------------------ | --------------------------------------------------- |
| `undefined` | The original, under the native policy |
| `{ type: "text", text }` | The text, in place of the file |
| `{ type: "file", bytes, mediaType }` | The replacement file (for example, a smaller image) |

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Is there anyway to pass by reference with some url? Just thinking through the implications of this for tracing.

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Good question. d34ff90 adds a Tracing section with two answers:

  • Traces: yes. With refs, model-call spans record the attachment descriptor instead of base64. A trace viewer opens the file through the session-authorized route GET /eve/v1/sessions/:id/attachments/:sha, so traces do not store a copy.
  • Providers: no, for now. A signed store URL changes each time eve mints it. The same message then renders differently on each call, which breaks the prompt cache (see research/tool-result-media.md). Private URLs also fail when the provider fetches them (Slack channel: a Google Drive/Dropbox file linked in a thread crashes every later mention (AI_DownloadError: 401) #855). If payload size becomes a problem, provider Files API file_ids are the better option.

Signed-off-by: Andrew Barba <barba@hey.com>
…g fixes

Signed-off-by: Andrew Barba <barba@hey.com>
@AndrewBarba

Copy link
Copy Markdown
Collaborator Author

Superseded by #4625. That plan keeps today's sandbox storage and fixes the attachment pipeline without a new store primitive. The path labels, the inline gate, and PDFs in read_file from this plan carry over into that stack.

This branch was successfully deployed

2 active deployments
Preview – eve-docs — 70e0f3a4 Deployed Oct 7, 2026 by vercel[bot]
Preview – eve-pkg — 70e0f3a4 Deployed Oct 7, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants