require artifact-targeted mutation for completion

This commit is contained in:
pewdiepie-archdaemon
2026-09-17 23:25:13 +00:00
parent 0aaefd1451
commit da7e8a9c2f
2 changed files with 33 additions and 3 deletions
+19 -2
View File
@@ -1372,6 +1372,17 @@ def runtime_required_artifacts(user_text, client_runtime_context):
return tuple(paths)
def execution_targets_required_artifact(tool_name, arguments, required_artifacts):
"""Return true only when a successful mutation names a required output."""
if canonical(tool_name) == 'write_file':
return True
serialized = (
arguments if isinstance(arguments, str)
else json.dumps(arguments or {}, ensure_ascii=False)
)
return any(str(path or '').rstrip('/') in serialized for path in required_artifacts)
def protocol_safe_tool_calls(calls):
"""Keep malformed model calls out of the next provider request."""
safe_calls = copy.deepcopy(calls)
@@ -4508,7 +4519,11 @@ async def stream_preview(*, endpoint_url, model, messages, headers, turn_contrac
history[-1] = {'role': 'assistant', 'content': confirmation}
yield event({'type': 'final_response', 'content': confirmation})
break
if native_workspace_enabled and required_artifacts and not successful_write:
if (
native_workspace_enabled
and required_artifacts
and not successful_artifact_write
):
# Runner-owned workspaces (for example Harbor containers)
# are not visible in the harness process. Use declared
# completion requirements plus successful mutation evidence
@@ -5047,7 +5062,9 @@ async def stream_preview(*, endpoint_url, model, messages, headers, turn_contrac
successful_duplicate_counts.pop(prior_signature, None)
if canonical(block.tool_type) in {'edit_document', 'update_document'}:
successful_editor_writer = canonical(block.tool_type)
if canonical(block.tool_type) == 'write_file':
if execution_targets_required_artifact(
block.tool_type, args, required_artifacts,
):
successful_artifact_write = True
except (ValueError, jsonschema.ValidationError) as exc:
if str(exc).startswith('The calendar read has not succeeded yet.'):
+14 -1
View File
@@ -5,7 +5,7 @@ import jsonschema
import pytest
import re
from src.clean_agent_preview import conversation, readonly_call, preview_call_allowed, evaluate_preview_call, authorized_write_families, compact_schemas, normalize_preview_function_args, normalize_preview_call_args, private_browser_dom_batch, private_browser_state_transition, private_browser_success_repeat_limit, stream_preview, denied_response, execution_has_write_effect, requests_mutation, claims_completion, recent_successful_write_families, scope_preview_contract, multimodal_image_count, attachment_reference_count, active_document_context_message, active_email_context_message, targets_active_editor, active_editor_whole_draft_request, active_editor_suggestion_request, scope_active_editor_contract, native_execution_limits, interactive_execution_limit, runtime_required_artifacts, document_suggestions_event, document_suggestion_quality_error, required_read_tool_choice, required_active_editor_tool_choice, sealed_read_arguments, email_identifier_error, requested_item_limit, contract_item_limit, notes_terminal_response, documents_terminal_response, shell_listing_terminal_response, shell_output_terminal_response, ui_panel_terminal_response, ui_toggle_state_result, calendar_terminal_response, memory_terminal_response, tasks_terminal_response, task_list_requires_synthesis, skills_terminal_response, cookbook_servers_terminal_response, prior_short_answer_for_no_tool_summary, prior_collection_repeat_answer, prior_failed_operation_answer, prior_cookbook_server_answer, prior_workspace_path_answer, prior_web_source_answer, bounded_web_evidence_answer, inherit_referential_read_arguments, normalized_search_intent, requested_web_source_links, web_source_links, requested_web_link_limit, preserve_requested_web_recency, ground_referenced_note_content, note_search_result_empty, note_referent_error, research_referent_error, private_browser_open_url, private_browser_effective_url, web_fetch_observation_is_boilerplate, broad_current_web_request, record_tool_execution, align_structured_tool_history, provider_request_messages, offered_tool_alias, dependent_write_prerequisite_error, bounded_research_tool_policy, retrieved_source_urls, serialize_required_email_attachment_chain
from src.clean_agent_preview import conversation, readonly_call, preview_call_allowed, evaluate_preview_call, authorized_write_families, compact_schemas, normalize_preview_function_args, normalize_preview_call_args, private_browser_dom_batch, private_browser_state_transition, private_browser_success_repeat_limit, stream_preview, denied_response, execution_has_write_effect, requests_mutation, claims_completion, recent_successful_write_families, scope_preview_contract, multimodal_image_count, attachment_reference_count, active_document_context_message, active_email_context_message, targets_active_editor, active_editor_whole_draft_request, active_editor_suggestion_request, scope_active_editor_contract, native_execution_limits, interactive_execution_limit, runtime_required_artifacts, execution_targets_required_artifact, document_suggestions_event, document_suggestion_quality_error, required_read_tool_choice, required_active_editor_tool_choice, sealed_read_arguments, email_identifier_error, requested_item_limit, contract_item_limit, notes_terminal_response, documents_terminal_response, shell_listing_terminal_response, shell_output_terminal_response, ui_panel_terminal_response, ui_toggle_state_result, calendar_terminal_response, memory_terminal_response, tasks_terminal_response, task_list_requires_synthesis, skills_terminal_response, cookbook_servers_terminal_response, prior_short_answer_for_no_tool_summary, prior_collection_repeat_answer, prior_failed_operation_answer, prior_cookbook_server_answer, prior_workspace_path_answer, prior_web_source_answer, bounded_web_evidence_answer, inherit_referential_read_arguments, normalized_search_intent, requested_web_source_links, web_source_links, requested_web_link_limit, preserve_requested_web_recency, ground_referenced_note_content, note_search_result_empty, note_referent_error, research_referent_error, private_browser_open_url, private_browser_effective_url, web_fetch_observation_is_boilerplate, broad_current_web_request, record_tool_execution, align_structured_tool_history, provider_request_messages, offered_tool_alias, dependent_write_prerequisite_error, bounded_research_tool_policy, retrieved_source_urls, serialize_required_email_attachment_chain
from src.tool_capabilities import capabilities_for_tool
@@ -455,6 +455,19 @@ def test_compact_writer_advertises_parallel_independent_file_calls():
assert 'multiple write_file calls in the same response' in writer['function']['description']
def test_read_only_python_does_not_satisfy_required_artifact():
required = ('/workspace/output.html',)
assert not execution_targets_required_artifact(
'python', {'code': "Image.open('/workspace/input/reference.png')"}, required,
)
assert execution_targets_required_artifact(
'python', {'code': "open('/workspace/output.html', 'w').write(body)"}, required,
)
assert execution_targets_required_artifact(
'write_file', {'path': '/workspace/output.html', 'content': '<html />'}, required,
)
def test_read_only_gate_blocks_mutation_and_network_shell():
assert readonly_call('manage_notes', {'action': 'list'})
assert readonly_call('manage_notes', {'action': 'view', 'id': 'abc'})