Repository navigation
Conversation
…etwork call A Goal verifier child that called `web_fetch` or `web_search` once had its whole run stopped. `beforeTool` latched a `capability_violation` on the first refused call and the next `beforeLlm` turned that latch into an abort, so the Goal surfaced as `paused(verifier_capability)` even though the child still held `read`, `grep`, `glob` and `bash` to reach the same evidence locally. The child is an ordinary `verifier` delegation, and that role grants `web_fetch` and `features.webSearch`; the canonical read-only ceiling does not remove either. The model was therefore offered tools that the guard would then treat as a violation. - Withhold `web_fetch` and `web_search` from the tool catalog of a Turn whose intent is the readonly Goal verifier profile, so the child is no longer offered them. - Keep the runtime guard as a fallback, but only for network tools: a refused call returns an offline instruction (use local evidence, judge PARTIAL when it is missing) and the run continues. It stops as a capability violation only when network tools are called in two consecutive child turns, or in three turns overall. Parallel calls from one model response count once. - Treat any other tool outside the read-only ceiling (write, edit, todowrite, delegation, memory, computer use) as a violation on its first call. - State in the verifier reminder that the run is offline. `route_unavailable` and `child_budget_exhausted` are unchanged. Fixes #419 Co-authored-by: Hylouis233 <Hylouis233@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Change
Fixes #419.
A
/goalrun whose verifier child calledweb_fetchorweb_searchonce was stopped and surfaced aspaused(verifier_capability), even though the child still heldread,grep,globandbashand could verify from local evidence.Root cause:
verifierdelegation. Theverifierrole asset grantsweb_fetchandfeatures.webSearch, and the canonical read-only ceiling removes neither, so the model was offered both tools (nativeweb_fetch, andweb_searchfrom the builtin Matrix MCP server).GoalVerifierChildCoordinator.beforeToollatched acapability_violationon the first refused network call, and the nextbeforeLlmturned the latch into an abort. The "blocked result goes back to the model" recovery path was unreachable.Fix:
web_fetchandweb_searchfrom the tool catalog of any Turn whose intent is thegoal-verifier-readonlyprofile. This applies to native tools and to MCP tools, both inline and deferred (tool_search/mcp_invoke), and to plugin capability bindings.capability_violationonly when network tools are called in 2 consecutive child turns, or in 3 child turns overall.capability_violationon its first call.route_unavailableandchild_budget_exhaustedbehavior is unchanged.Credit: builds on the reporter's patch (Hylouis233/minimax-code@69810ab), credited with a
Co-authored-bytrailer. Its unrelatedgoalVerifierRunIdformatting change was dropped.bug,cliValidation
pnpm verify(full profile) oncfff8f9with a clean tracked tree, darwin, Node 24.16.0: PASS (15 gates). capability suite 218 files, 5447 passed / 17 skipped; status-contract 9; policy 142; sandbox 48.test:windowsskipped (platform),test:release-packageskipped (requires an npm release archive).packages/local-runtime-v2/test/unit/agent/goal-verifier-readonly-guard.test.ts(registered intest/vitest-suites.json), 21 tests. It covers the turn-based fallback, non-network violations, unchanged route/budget aborts, the reminder, catalog withholding for native and builtin Matrix MCPweb_search(inline and deferred), and that the verifier task-child prompt has no web-search guidance under thetuianddesktopprofiles. With the source changes reverted, the first 17 tests of this file ran againstmain: 13 failed; the 4 passing ones are intended no-regression checks.eslint(repository config) on all changed.tsfiles: 0 errors. The remaining prettier warnings are on lines this change does not touch and are also reported for the pre-change versions of those lines./goalrun against a real model; offline unit tests only. Windows and Linux CI not run locally. Network access throughbash(for examplecurl) is out of scope and remains governed by the permission policy. The legacy prompt path without a prompt profile still renders thefeatures.webSearch"Factual Freshness And Search" section for the verifier; the product always renders task children with thetuiordesktopV2 profile, where that section is absent. A per-turn feature toggle would require threading the Goal verifier origin into task binding capture and is out of scope.Publication and contribution checks
release/public-source.json; new tests are declared intest/vitest-suites.jsonwhere applicable.Maintainer handoff
Publication scope or license changes (if any): none.
Shared-source port: pending.
Need help on this PR? Tag
@codesmith-botwith what you need. Autofix is disabled.