A menu for what a chat may use, and three keys
Six smaller things, all of them about the interface not saying what is true.
The @ button only ever inserted the character, which the @ key already does
without a button. It becomes the scope menu: what this chat may use, switched
off per chat. Chat.scope_json is filtered inside resolve_tools AFTER the
capability, permission and instance gates -- exactly as chat.knowledge_bases
narrows knowledge_search -- so a crafted POST turning something on reaches a
tool the gates already removed, and there is a test that writes the column
directly to prove it. Absent means on, for every key, so "why is this off?" has
one answer. It is keyed on the gate rather than the tool name, so notes is one
switch rather than five. The switches carry no role="menuitem", deliberately:
ui.js closes a picker when a menuitem is clicked, which is right for an action
menu and wrong for a list you want to set several of -- which is why the menu
needs no JavaScript at all. Typing @ is untouched.
With no skills, nothing should mention them. tool.skills was gated on the family
alone, so somebody with an empty library was told "the list below gives each
one's name" above no list, handed skill_get, and watched the model spend a round
finding out. It requires skills now; the writing half moved to
tool.skills_write, which is deliberately not gated, because saving the first one
is what somebody with none most needs. And core.tool_list finally reads
tool_names, which had been resolved and documented with no fragment using it.
The composer's toolbar is one row again. .composer__actions is last in the DOM
with margin-left:auto, so the moment an agent chat added a connection, a
directory and a mode, Send and the microphone dropped to a second line.
chat.css has no media queries by design and the fix is not to add one:
.composer__context is the single child allowed to shrink and scroll sideways.
There is a test asserting the file still contains no @media.
The effort picker shows the level in force. "Effort: default" named no level and
was true of nothing in particular; chat.resolved_effort is the chat's own value
and build_request reads the same field, so what is shown is what is sent. The
model's default is a seed, copied onto the row at creation and on a model
change, and never consulted at request time -- a fallback would resurrect it
underneath a cleared effort and make "off" silently do nothing. "off" is a
sentinel and not an empty value, because start_chat declares Form("") and cannot
tell absent from empty: with value="" the reader picks off and gets high.
Alt+M dictates, Alt+R reads the last reply aloud, Ctrl+Enter sends from
anywhere. All three click the button that already does the job, so audio.js
keeps its one delegated listener. Alt+M and not Alt+D, which is the address bar
in Chrome and Firefox. Ctrl+Enter never means Stop -- Send and Stop are the same
element, and Esc already stops. Driven under a DOM stub before committing, per
the rule in CLAUDE.md, and tests/test_commands_js.py pins that every key has a
row in SHORTCUTS, since /help reads that list.
And the memory tooling, which had seven defects. The worst: memory_forget was a
case-insensitive substring first-match delete with nothing warning about it, so
forgetting "coffee" against "Drinks coffee black" and "Allergic to coffee"
silently removed whichever was older -- a wrong deletion nobody would ever find
out about, from a tool whose description invited exactly the short fragment that
misfires. It matches exactly first, then by substring, and refuses an ambiguous
one while naming what it matched. add() refuses an exact duplicate. The
at-the-limit refusal no longer tells the model to delete one to make room: past
the block's budget it is not shown all of them and would be guessing, which
feeds straight back into the first defect. And context.memories no longer claims
the memories "still apply", which nothing checks and which taught a model to
trust a stale one over what the person had just said.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 5
parent
39ff34ffac
commit
0452e742e8
+104
-10
@@ -160,6 +160,11 @@ class ToolContext:
|
||||
# the decrypted credential. None everywhere else, which is what every agent
|
||||
# runner checks first. `generation` clears it when the reply ends.
|
||||
agent: Any = None
|
||||
# Skills this chat has switched off, by name. Enforced in `_run_skill_get`
|
||||
# and not only in the listing: without that the narrowing is advisory, since
|
||||
# a model can name a skill it was never shown and the runner would fetch it
|
||||
# anyway. Same rule as "what may be run is what was offered".
|
||||
skills_off: frozenset[str] = field(default_factory=frozenset)
|
||||
|
||||
|
||||
@dataclass
|
||||
@@ -530,18 +535,46 @@ async def _run_memory_add(context: ToolContext, args: dict[str, Any]) -> ToolOut
|
||||
|
||||
|
||||
async def _run_memory_forget(context: ToolContext, args: dict[str, Any]) -> ToolOutcome:
|
||||
"""Remove one memory, or refuse and say why.
|
||||
|
||||
Exact match first, then substring, and an ambiguous substring removes
|
||||
nothing. This used to be a case-insensitive substring FIRST-match delete
|
||||
with nothing warning about it, so `memory_forget("coffee")` against "Drinks
|
||||
coffee black" and "Allergic to coffee" silently deleted whichever was older
|
||||
-- a wrong deletion nobody would ever find out about, from a tool whose
|
||||
description invited exactly the short fragment that misfires.
|
||||
|
||||
Exact-first is not a nicety: without it, quoting a memory in full still
|
||||
fails whenever that text happens to be a substring of another one.
|
||||
"""
|
||||
wanted = str(args.get("content") or "").strip().lower()
|
||||
with session_scope() as db:
|
||||
user = db.get(User, context.owner_id)
|
||||
records = memories_service.all_for(db, user)
|
||||
match = next((m for m in records if wanted and wanted in m.content.lower()), None)
|
||||
if match is None:
|
||||
if not wanted:
|
||||
return ToolOutcome(
|
||||
"Say which memory to remove, quoting its text.",
|
||||
{"name": "memory_forget", "status": "error", "error": "Nothing given."},
|
||||
)
|
||||
|
||||
exact = [m for m in records if m.content.strip().lower() == wanted]
|
||||
matches = exact or [m for m in records if wanted in m.content.lower()]
|
||||
|
||||
if not matches:
|
||||
return ToolOutcome(
|
||||
"No memory matches that. The full list is in the prompt already.",
|
||||
{"name": "memory_forget", "status": "error", "error": "No match."},
|
||||
)
|
||||
content = match.content
|
||||
memories_service.delete(db, match)
|
||||
if len(matches) > 1:
|
||||
listed = "\n".join(f"- {m.content}" for m in matches[:10])
|
||||
return ToolOutcome(
|
||||
f"That matches {len(matches)} memories, so nothing was removed. "
|
||||
f"Quote the whole text of the one you mean:\n{listed}",
|
||||
{"name": "memory_forget", "status": "error", "error": "Ambiguous."},
|
||||
)
|
||||
|
||||
content = matches[0].content
|
||||
memories_service.delete(db, matches[0])
|
||||
return ToolOutcome(
|
||||
f"Forgotten: {content}",
|
||||
{"name": "memory_forget", "query": content, "status": "ok", "results": []},
|
||||
@@ -554,6 +587,13 @@ async def _run_skill_get(context: ToolContext, args: dict[str, Any]) -> ToolOutc
|
||||
with session_scope() as db:
|
||||
user = db.get(User, context.owner_id)
|
||||
skill = skills_service.by_name(db, name, user)
|
||||
# Enforced here and not only in the listing. Without this the per-chat
|
||||
# narrowing is advisory: a model can name a skill it was never shown --
|
||||
# from an earlier turn, from a note -- and the runner would fetch it.
|
||||
if skill is not None and skill.name in {
|
||||
skills_service.slugify(off) for off in context.skills_off
|
||||
}:
|
||||
skill = None
|
||||
if skill is None:
|
||||
return ToolOutcome(
|
||||
f"There is no skill called {name!r}.",
|
||||
@@ -778,9 +818,13 @@ REGISTRY: dict[str, ToolDef] = {
|
||||
family=FAMILY_MEMORY,
|
||||
description=(
|
||||
"Remember one short, durable fact about the user — a preference, a "
|
||||
"constraint, how they like to be addressed. You are shown every "
|
||||
"memory on every turn, so keep them few and short, and never store "
|
||||
"passwords, keys or anything else secret."
|
||||
"constraint, a name, how they like to be addressed. Every memory is "
|
||||
"put in front of you on every turn, up to a budget, so keep them few "
|
||||
"and keep them short; text over the limit is shortened rather than "
|
||||
"refused, and you are told. Check what is already remembered before "
|
||||
"adding: a fact you have stored already in slightly different words "
|
||||
"costs the same again and makes both of them harder to remove. Never "
|
||||
"store a password, a key or anything else secret."
|
||||
),
|
||||
parameters=_object(
|
||||
{"content": {**_STRING, "description": "One fact, in one sentence."}},
|
||||
@@ -793,10 +837,16 @@ REGISTRY: dict[str, ToolDef] = {
|
||||
name="memory_forget",
|
||||
family=FAMILY_MEMORY,
|
||||
description=(
|
||||
"Remove a memory that has become wrong. Give enough of its text to "
|
||||
"identify it."
|
||||
"Remove a memory that is no longer true. Quote it in full — the "
|
||||
"whole sentence as it appears in your prompt. A fragment that "
|
||||
"matches more than one removes nothing and tells you which ones it "
|
||||
"matched, because deleting the wrong memory is not something anyone "
|
||||
"would find out about."
|
||||
),
|
||||
parameters=_object(
|
||||
{"content": {**_STRING, "description": "The memory's whole text."}},
|
||||
["content"],
|
||||
),
|
||||
parameters=_object({"content": _STRING}, ["content"]),
|
||||
run=_run_memory_forget,
|
||||
risk=RISK_WRITE,
|
||||
),
|
||||
@@ -1035,6 +1085,17 @@ def resolve_tools(db: DBSession, chat: Chat, user: User | None) -> ToolSet:
|
||||
# Resolved against what this reader may see, not against everything that
|
||||
# exists: a tool restricted to a group is not offered outside it.
|
||||
book = _book([*_row_defs(db, user), *_agent_defs(db, chat, user)])
|
||||
|
||||
# What this chat has switched off, applied AFTER the gates and never
|
||||
# instead of them. A chat can only ever *narrow* what the model's
|
||||
# capabilities, the reader's permissions and the instance configuration
|
||||
# already allow -- exactly as `chat.knowledge_bases` narrows
|
||||
# `knowledge_search` and can never widen it. A crafted request that turned
|
||||
# something on here would still be reaching for a tool the gates had
|
||||
# already removed.
|
||||
off = scoped_off(chat)
|
||||
empty_library = not skills_service.count_enabled(db, user, exclude=scoped_skills_off(chat))
|
||||
|
||||
return ToolSet(
|
||||
tuple(
|
||||
tool
|
||||
@@ -1042,10 +1103,42 @@ def resolve_tools(db: DBSession, chat: Chat, user: User | None) -> ToolSet:
|
||||
if _family_allowed(
|
||||
tool.family, config=config, capabilities=capabilities, allowed=allowed
|
||||
)
|
||||
and gate_of(tool.family) not in off
|
||||
# Nothing to read and nothing to improve. Offering `skill_get` with
|
||||
# no skills is what makes a model spend a round looking one up and
|
||||
# being told it does not exist -- and `context.skills` already
|
||||
# vanishes, so the prompt says "read one with skill_get" above a
|
||||
# list that is not there. `skill_create` stays: writing the first
|
||||
# one is exactly what somebody with none needs.
|
||||
and not (empty_library and tool.name in _NEEDS_A_SKILL)
|
||||
)
|
||||
)
|
||||
|
||||
|
||||
# Skills tools that are meaningless with an empty library.
|
||||
_NEEDS_A_SKILL = frozenset({"skill_get", "skill_edit"})
|
||||
|
||||
|
||||
def scoped_off(chat: Chat | None) -> frozenset[str]:
|
||||
"""Gates this chat has switched off. **Absent means on**, always.
|
||||
|
||||
One representation of "on" -- the key not being there -- so that "why is
|
||||
this off?" has one answer rather than two.
|
||||
"""
|
||||
if chat is None:
|
||||
return frozenset()
|
||||
wanted = (getattr(chat, "scope_json", None) or {}).get("families") or {}
|
||||
return frozenset(str(name) for name, on in wanted.items() if on is False)
|
||||
|
||||
|
||||
def scoped_skills_off(chat: Chat | None) -> frozenset[str]:
|
||||
"""Individual skills this chat has switched off, by name."""
|
||||
if chat is None:
|
||||
return frozenset()
|
||||
wanted = (getattr(chat, "scope_json", None) or {}).get("skills") or {}
|
||||
return frozenset(str(name) for name, on in wanted.items() if on is False)
|
||||
|
||||
|
||||
def enabled_tools(db: DBSession, chat: Chat, user: User | None) -> list[dict[str, Any]]:
|
||||
"""The tool schemas to offer for this chat.
|
||||
|
||||
@@ -1070,6 +1163,7 @@ def context_for(
|
||||
owner_id=user.id if user else "",
|
||||
search_config=settings_store.search(db),
|
||||
base_ids=[base.id for base in chat.knowledge_bases] if chat is not None else [],
|
||||
skills_off=scoped_skills_off(chat),
|
||||
tools=tools.by_name if tools is not None else None,
|
||||
interaction_timeout=float(settings_store.agents(db)["approval_timeout"]),
|
||||
)
|
||||
|
||||
Reference in New Issue
Block a user