1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
//! The **history closure** (ARCH §3.3 *the request's referential
//! integrity*): a declaration for every tool the assembled history names
//! that the role's own toolset does not carry.
//!
//! A branch inherits its dispatcher's transcript by fork (§2.3), so the
//! tools that dispatcher used are named in the history whether or not
//! this role was granted them; a provider refuses a history it was not
//! told about, so the array is widened to fit the history rather than the
//! history rewritten to fit the array — transcript entries are immutable
//! and the wire framing is transcript-backed (§2.3, §3.3).
//!
//! **Declaring is not permitting, and the definition now says so**
//! (bl-9c1d). An entry this module adds is one the grant gate will refuse
//! ([`crate::prompt::dispatch::tool_step::permit::refusal`], §3.3): it
//! exists to make the history legible, not to offer the tool. Sent with
//! its committed description and schema it read as an offer, and models
//! took it — across 33 reviewer branches of one lane, `bash` was called
//! **360 times** and refused 360 times, each refusal a full model round
//! trip whose prompt was the entire inherited transcript, and every
//! compactor did the same at its first step. The refusal message was
//! correct and even explained itself; the model tried anyway, because the
//! list it could see said the tool was there.
//!
//! So a non-callable entry carries **the refusal itself as its
//! description** — the same sentence, from the same function, that the
//! door would answer with — and a bare `{"type": "object"}` schema. One
//! home for the sentence, read now before the call instead of after it,
//! and the schema goes too because legibility needs the name, not the
//! shape. A **granted** tool that only reaches the array through the
//! history — granted but undescribed in this tree (§3.3) — is callable,
//! so `refusal` answers `None` for it and it keeps its committed
//! definition; the predicate decides, not this module.
use Grant;
use refusal;
use ;
use crateError;
use crateInjectedTool;
use ;
use ;
/// Append a declaration for every tool `history` names that `tools` does
/// not already carry (module docs). A name the grant gate would refuse
/// is declared **not callable**: the refusal sentence as its description
/// and an opaque schema.
///
/// The other arm is narrower than it looks. A name that reaches here and
/// IS callable is granted, and a granted name with a committed schema was
/// already elected by [`super::compose`] — so the only callable name left
/// is one the tree describes no schema for, and the stand-in is the whole
/// answer. Its skill description, if the tree carries one, still rides
/// through [`entry`]. That is also the shape of a name the model invented
/// under an empty grant, where `refusal` speaks first.
pub
/// The stand-in schema: a shape that says nothing, for an entry whose
/// job is to make a name resolvable rather than to describe a call.
/// Tool names the `tool_use` blocks of `history` reference, in
/// first-appearance order and deduplicated.