9ea41eed78
FOUND BY E2E, NOT BY REASONING. The previous commit's design note asserted the provenance
receipt "never reaches the user: it is appended to the history copy, not the reply." That
was FALSE, and only running the thing showed it. On the first live run against the built
DMG brain, two agentic turns out of two came back with
"Your favourite colour is chartreuse and your project is called Perihelion.
[[RECEIPT - recorded by the soul, not written by the model: no tools ran on this turn.]]"
— the receipt in the user-visible reply.
MECHANISM: the receipt is stored inside the assistant turn, and the agentic path replays
history VERBATIM as Anthropic message objects. So the model sees its own previous answers
ending in [[RECEIPT ...]] and does the obvious thing — it imitates the format and signs the
next answer the same way. The plain path did NOT leak, which is the tell: there, history is
rendered into the SYSTEM prompt as labelled lines rather than replayed as assistant turns,
and a model imitates its own turns far more readily than a transcript.
FIX, two layers, because one of them is not a guarantee:
- receipt_rule() names the marker in both system prompts (plain and agentic): these lines
are written by the system, read them as evidence, never write one. Reduces occurrence.
- receipt_strip() truncates any [[RECEIPT ...]] out of model output before it becomes the
reply — plain path in layered_generate, agentic path on final_text in agentic_loop.
Deterministic. A guard that depends on the model choosing to obey is exactly the class of
thing round 8 exists to stop shipping, so the instruction is the optimisation and the
strip is the guarantee.
Placed ABOVE agentic_loop's empty-check on purpose: a turn whose entire output was an
imitated receipt has produced no answer, and must be reported as no answer.
The receipt stays in HISTORY, which is the whole point and is proven to work: asked "What
source did you use for that?" one turn after a live web_search, this brain answered
"I used Weather Underground (https://www.wunderground.com/weather/is/reykjav%C3%ADk) for the
current temperature in Reykjavik" — a real source, no apology. That is the false confession
dead, and it is dead BECAUSE the model can read the receipt.
BUILT: 887,112 bytes, sha256 54a2eff84d4fa44f8d2db6781dcf225df4b5075a8ec5f1058018bd40cc1af10b
BUG-PLAINCHAT-1 miscompile guard: zero sites.
Refs neuron#109
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
89 lines
5.4 KiB
Plaintext
89 lines
5.4 KiB
Plaintext
// auto-generated by elc --emit-header - do not edit
|
|
extern fn chat_default_model() -> String
|
|
extern fn engram_numeric_valid(s: String) -> Bool
|
|
extern fn parse_float_x100(s: String) -> Int
|
|
extern fn engram_score_node(node_json: String) -> Int
|
|
extern fn engram_render_node(node_json: String) -> String
|
|
extern fn engram_render_nodes(nodes_json: String) -> String
|
|
extern fn engram_dedup_nodes(nodes_json: String) -> String
|
|
extern fn engram_compile_ranked(nodes_json: String, max_nodes: Int) -> String
|
|
extern fn engram_split_topics(message: String) -> String
|
|
extern fn engram_extract_entities(message: String) -> String
|
|
extern fn engram_detect_recall_intent(message: String) -> Bool
|
|
extern fn engram_is_continuation(message: String, hist_len: Int) -> Bool
|
|
extern fn engram_compile_multi(topic: String) -> String
|
|
extern fn engram_nodes_merge(a: String, b: String) -> String
|
|
extern fn id_in_seen(node_id: String, seen: String) -> Bool
|
|
extern fn add_to_seen(seen: String, node_id: String) -> String
|
|
extern fn engram_extract_ids(nodes_json: String) -> String
|
|
extern fn affective_node_ts(node_json: String) -> Int
|
|
extern fn engram_compile(intent: String) -> String
|
|
extern fn distill_transcript(transcript: String) -> String
|
|
extern fn json_safe(s: String) -> String
|
|
extern fn current_engine_note(model: String) -> String
|
|
extern fn bounded_persona_floor() -> String
|
|
extern fn operator_identity_block() -> String
|
|
extern fn build_system_prompt(ctx: String, chat_mode: Bool) -> String
|
|
extern fn hist_append(hist: String, role: String, content: String) -> String
|
|
extern fn conv_hist_key(session_id: String) -> String
|
|
extern fn conv_hist_label(session_id: String) -> String
|
|
extern fn is_utility_request(body: String, session_id: String) -> Bool
|
|
extern fn provenance_scan_urls(arr: String, acc: String) -> String
|
|
extern fn provenance_add_sources(block: String, btype: String, has_cit: Bool, cit_raw: String, acc: String) -> String
|
|
extern fn provenance_names(tools_used: String) -> String
|
|
extern fn text_join_sep(accumulated: String, incoming: String, after_interruption: Bool) -> String
|
|
extern fn receipt_rule() -> String
|
|
extern fn receipt_strip(s: String) -> String
|
|
extern fn tool_receipt(tools_used: String, sources: String) -> String
|
|
extern fn hist_trim(hist: String) -> String
|
|
extern fn hist_trim_with_bell_guard(hist: String) -> String
|
|
extern fn clean_llm_response(s: String) -> String
|
|
extern fn conv_history_persist(session_id: String, hist: String) -> Void
|
|
extern fn conv_history_load(session_id: String) -> String
|
|
extern fn conv_history_record(session_id: String, user_msg: String, assistant_msg: String, receipt: String) -> Void
|
|
extern fn conv_history_block(session_id: String) -> String
|
|
extern fn layered_generate(prompt: String, imprint_id: String, session_id: String) -> String
|
|
extern fn session_preload_bullets(nodes: String, max_bullets: Int, snip_len: Int) -> String
|
|
extern fn affective_context_prefix() -> String
|
|
extern fn handle_chat(body: String) -> String
|
|
extern fn handle_see(body: String) -> String
|
|
extern fn studio_tools_json() -> String
|
|
extern fn agentic_api_key() -> String
|
|
extern fn llm_base_url() -> String
|
|
extern fn llm_wire_format() -> String
|
|
extern fn json_escape(s: String) -> String
|
|
extern fn openai_chat_complete(model: String, base_url: String, api_key: String, safe_sys: String, messages_json: String) -> String
|
|
extern fn agentic_tools_literal() -> String
|
|
extern fn web_search_tool_json() -> String
|
|
extern fn strip_client_web_search(tools_inner: String) -> String
|
|
extern fn agentic_tools_with_web() -> String
|
|
extern fn connector_tools_json() -> String
|
|
extern fn agentic_tools_all() -> String
|
|
extern fn call_mcp_bridge(tool_name: String, tool_input: String) -> String
|
|
extern fn tool_auto_approved(tool_name: String) -> Bool
|
|
extern fn call_neuron_mcp(tool_name: String, args: String) -> String
|
|
extern fn agent_workspace_root() -> String
|
|
extern fn path_within_root(path: String, root: String) -> Bool
|
|
extern fn resolve_in_root(path: String, root: String) -> String
|
|
extern fn run_command_is_readonly(cmd: String) -> Bool
|
|
extern fn cmd_abs_escape_at(cmd: String, root: String, needle: String) -> Bool
|
|
extern fn run_command_guard(cmd: String, root: String) -> String
|
|
extern fn classify_tool_risk(tool_name: String, tool_input: String) -> String
|
|
extern fn dispatch_tool(tool_name: String, tool_input: String) -> String
|
|
extern fn is_builtin_tool(tool_name: String) -> Bool
|
|
extern fn next_bridge_id() -> String
|
|
extern fn handle_chat_plan(body: String) -> String
|
|
extern fn handle_chat_agentic(body: String) -> String
|
|
extern fn agentic_loop(session_id: String, model: String, safe_sys: String, tools_json: String, messages_in: String, h: Map, tools_log_in: String) -> String
|
|
extern fn bridge_save(session_id: String, model: String, safe_sys: String, tools_json: String, messages: String, tools_log: String, tool_use_id: String) -> Bool
|
|
extern fn agentic_resume(session_id: String, tool_use_id: String, content: String) -> String
|
|
extern fn handle_tool_result(session_id: String, body: String) -> String
|
|
extern fn handle_chat_as_soul(body: String) -> String
|
|
extern fn handle_dharma_room_turn(body: String) -> String
|
|
extern fn handle_dharma_room_turn_agentic(body: String) -> String
|
|
extern fn session_summary_write(summary_text: String) -> String
|
|
extern fn session_summary_write_dated(summary_text: String, label: String) -> String
|
|
extern fn session_summary_autogenerate(hist: String) -> String
|
|
extern fn auto_persist(req: String, resp: String) -> Void
|
|
extern fn strengthen_chat_nodes(activation_nodes: String) -> Void
|