diff --git a/docs/decisions.md b/docs/decisions.md index d46b869..c91b464 100644 --- a/docs/decisions.md +++ b/docs/decisions.md @@ -27,6 +27,7 @@ Approved by the owner on 2026-09-17. One commit each. |---|---|---| | P1 | Inference contract 6: the `tools` array is fixed per epoch. `find_tool` returns schemas as a tool result and the model calls them through a `call_tool(name, arguments)` meta-tool. Never instruct the model to call an undeclared tool. | M0 (h): adding a tool re-read the whole prompt; undeclared calls were coerced into `write_file`. | | P2 | Inference contract 2: the session log stores assistant messages exactly as returned, including `reasoning_content`, and replays them unchanged. Remove the "known risk" about dropped thinking blocks. | M0 (e): Ornith's template keeps every think block. | +| P3 | Inference contract 7: requests set `return_progress: true`; progress events count as liveness. | M0 (i): otherwise the stream is silent during prefill. | ## Proposed changes to the design brief @@ -34,7 +35,6 @@ From M0 and the kickoff review. None is applied yet. Each lands as its own commi | # | Change | Evidence | |---|---|---| -| P3 | Inference contract 7: requests set `return_progress: true`; progress events count as liveness. | M0 (i): otherwise the stream is silent during prefill. | | P4 | Inference contract 8: the thinking cap uses `reasoning_control` and the control endpoint. | README b10809. Not yet exercised. | | P5 | Settle the open question: chat-completions with server-side tool parsing. | M0 (b), (c). | | P6 | Code constraints: `Decision` lives in `brokerd`, has a private field and does not implement `Deserialize`. `proto` carries a plain `DecisionRecord` for the audit log. | Rust privacy is per crate, and a deserializable type can be built by anyone. | diff --git a/docs/design.md b/docs/design.md index 8a8eebf..0b06c04 100644 --- a/docs/design.md +++ b/docs/design.md @@ -100,8 +100,9 @@ ordinary outbound networking can reach the whole tailnet and the internet as the `brokerd` applies grants to the target tool, not to `call_tool`. Never prompt the model to call a tool that is not in the `tools` array: the server's grammar forces such a call into a declared tool. -7. **Liveness, not deadlines.** Streaming always. The timeout is "no bytes for N seconds", never a - total-request deadline. +7. **Liveness, not deadlines.** Streaming always, with `return_progress: true` so that prompt + processing produces events. The timeout is "no bytes for N seconds", never a total-request + deadline. Progress events count as bytes. 8. **Runaway control.** Per-turn thinking-token cap, per-turn tool-iteration cap, detection of repeated identical tool calls. 9. **Startup self-test.** On boot `loopd` checks: tool-call round trip parses, turn-2 prompt