Expand description
turnframe-provider: the provider-neutral model layer of Turnframe (spec §20).
The core runtime never sees OpenAI-, Anthropic-, Gemini- or Bedrock-specific wire types (spec §0 rule 8). It speaks this crate’s normalized vocabulary:
- a
request::ModelRequestdescribes one model call: purpose, messages, expectedrequest::OutputSpec, read-only tools, limits and metadata; - a
response::ModelResponsecarries the normalized answer, aresponse::FinishReasonandresponse::TokenUsage; - a
stream::ModelStreamdelivers the same answer incrementally andstream::reconstructrebuilds the full response deterministically; structured::parse_structuredturns a response into a typed value all-or-nothing (spec I18): schema validation with deny-unknown semantics, then typed deserialization; a single malformed act rejects the whole output;error::ProviderErroris the typed failure family, classified byerror::RetryClassand free of secrets, request bodies and headers;provider::ModelProvideris the trait every adapter implements against a configuredcapabilities::ModelProfile; capabilities are declared per provider-model pair, never inferred from the brand (spec §20.3);router::PolicyRouterselects candidates by capability fit first, then tenant policy, then health and preference — and refuses to downgrade the structured-output requirement of a critical stage (spec §0 rule 9, §20.4);fallback::execute_with_fallbacktries candidates in order, retries by class, records every attempt and never merges partial outputs (spec §20.7).
Concrete adapters live in sibling crates (turnframe-provider-openai, …) and
prove themselves with the reusable [conformance] suite (feature
conformance, spec §20.8).
§Where the safety rules live
| Rule | Where it is enforced |
|---|---|
| Model arrays are all-or-nothing (I18) | structured, stream::StreamAccumulator |
| No silent capability downgrade (§0.9) | purpose::ModelPurpose::requirements, router::PolicyRouter |
| Provider failure cannot repeat effects (I17) | fallback::FallbackStage is a required parameter |
| Secrets never reach prompts or logs (§25.2) | secret::ApiKey, secret::Redactor, error Display |
| Record every provider attempt (§20.7) | fallback::ProviderAttempt |
Modules§
- capabilities
- Capability model (spec §20.3) and per-model configuration profiles.
- dialect
- Rewriting a JSON Schema for a provider’s dialect, without weakening it.
- error
- The typed provider failure family and its retry classification (spec §24, §20.7).
- fallback
- Retry and fallback across candidates (spec §20.7, invariant I17).
- ids
- Identity newtypes of the provider layer.
- prelude
- The most used items, for
use turnframe_provider::prelude::*. - provider
- The trait every adapter implements (spec §20.1).
- purpose
- Normalized request purposes (spec §20.2) and what each one demands.
- request
- The normalized model request (spec §20.1).
- response
- The normalized model response (spec §20.1).
- router
- Provider selection (spec §20.4, §20.6, ADR-008).
- secret
- Credentials and redaction (spec §25.2).
- stream
- Incremental output and its deterministic reassembly (spec §18.5, §20.8).
- structured
- All-or-nothing structured parsing (invariant I18, spec §0 rule 6).
- testing
- Test doubles for the provider layer, always compiled.
- trace
- Every call a provider makes, as it went over the wire, for a person debugging a turn: the request with its prompts and schema, and what came back.