M11: what the server will actually read

The release-validation milestone, and the thing it had to settle first was
whether any of the earlier evidence meant what it said. M8 measured a deployment
enforcing a 4,096-token input window while the application budgeted 16,384.
Every request returned 200. What Ollama does with the excess is drop the oldest
tokens, and the oldest tokens here are the system block — the narrator's rules
and the campaign canon. A hundred-turn certification against that server would
have looked perfect and proved nothing, which is why this milestone could not
begin with a hundred turns.

So the application asks now. Ollama's window is a property of how a model was
loaded rather than of the request — sending num_ctx is accepted, ignored, and
worse, reloads the model at the server's own default — so the only honest move
is to find out and then tell the truth about it. /api/ps reports what a resident
model is being served with, /api/show what an unloaded one will load with, both
on the same host inference already uses, through the same endpoint policy and
the same TLS trust store. A verified window is a ceiling on the budget; an
unverified one leaves the budget alone and is recorded as unverified in the
turn's own provenance, so an old turn can be asked afterwards whether it was
built against a checked window. There is no third behaviour, and in particular
no hard-coded 4,096: a number the server did not say would be right on one
machine and wrong on the next.

The proof that this is doing something is a campaign whose canon sits at the
front of the prompt, 120 turns of history, and a 4,096-token window. The canon
is still there afterwards and the oldest history is gone. The same campaign
built the old way produces a prompt more than twice the window — the defect,
reproduced, so the fix is measured against it rather than asserted.

Two defects the validation found on its own, and they are the same defect twice:
something was true and nobody was told. A manual state correction of four
changes with one bad reference applied three, returned 201, and said nothing —
while recording the refusal on the audit row nobody reads. It came to light
because the identity diagnostic's own fixture was refused that way and the whole
run proceeded on a campaign with no scene, which would have read as a model
failure. And the narration-length setting moved no number: brief, medium and
long each became one English sentence, while the numeric hint the model actually
reads was derived from the global reply cap and said the same thing for all
three. Both now say what they did.

The other two post-M8 findings are closed as well. The tab said AI D&D, which no
document had ever claimed it did not; it says Interactive Story now, with the
open campaign first, and the name is the owner's decision rather than a
find-and-replace to something narrower than the engine. After an Undo the reader
could not tell where they had landed; the control row now ends with
"Moment 11 · later story ahead", from the server's own answer, in the word the
transcript already uses, with none of head, branch or depth anywhere near it.

The identity diagnostic exists and the root cause does not. That campaign was
destroyed, so no cause can be established — what M11 owes the finding is
something that can classify the next occurrence, and a diagnostic that makes only
the judgements a program can honestly make: duplicate keys, shared names,
protagonist drift, state and context disagreeing. Whether prose misattributed a
line is left to a person reading it beside its prompt, because a regex cannot
read dialogue and one that pretended to would produce exactly the confident wrong
answer this finding is about. Its detectors are proved to fire against a planted
second Alice.

Two entities may still share a display name. That was checked first, as the
finding asked, and left permitted: a mother and a daughter, or a stranger giving
a false name, are ordinary fiction, and refusing them to guard against a model
mistake would refuse the wrong thing. What was missing was that it happened
silently. It is reported now.

Evidence, not inference: a hundred accepted turns against a real narrator with
genuine process restarts; a real browser against the built SPA; a container with
no network at all; a campaign moved into a data directory that never existed.
Each was discarded and re-run whenever the product changed under it, and the runs
that were thrown away are listed in the report with the reason, along with ten
defects in the harnesses themselves — because a harness that has only ever
agreed with itself is not evidence, and two of M8's five harness defects were
masking real ones.

No dependency was added, removed or upgraded. No acceptance test was retired,
relaxed or reclassified. M11 is implemented and verified; it is not accepted, and
there is no release tag.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Qyn3oRd4D6pi72nKBG725B
This commit is contained in:
JesseMarkowitz
2026-09-07 14:01:20 -04:00
co-authored by Claude Opus 5
parent 1013c94eb1
commit 144406cd48
57 changed files with 7374 additions and 97 deletions
+15
View File
@@ -247,6 +247,10 @@ def export(db: Session, adventure: models.Adventure) -> dict:
"memory": adventure.memory,
"authorsNote": adventure.authors_note,
"aiInstructions": adventure.ai_instructions,
# M11: the campaign's narration-length choice. Chosen data, so it
# travels — a campaign that arrives on another machine should go on
# writing the length of turn its reader asked for.
"narrationLength": adventure.narration_length or "",
"storySummary": adventure.story_summary,
# Phase 18. A bundle written before personas existed has no key here,
# and the import below reads it with `.get`, so it lands with an empty
@@ -396,6 +400,16 @@ def _exported_source(source: models.KnowledgeSource) -> dict:
}
def _narration_length(value) -> str:
"""One of the three lengths, or empty. An unknown value is not carried.
A file could name a length this build does not serve — a later version's, or
a hand-edited one. Storing it would leave the campaign with a preference the
prompt builder ignores, which is indistinguishable from the defect M11 fixed.
"""
return value if value in ("brief", "medium", "long") else ""
def _exported_visual_profile(profile: models.VisualProfile) -> dict:
"""One visual profile, as it goes into the file.
@@ -2011,6 +2025,7 @@ def materialize(
memory=str(payload.get("memory") or ""),
authors_note=str(payload.get("authorsNote") or ""),
ai_instructions=str(payload.get("aiInstructions") or ""),
narration_length=_narration_length(payload.get("narrationLength")),
story_summary=str(payload.get("storySummary") or ""),
world_state=payload.get("worldState") or {},
# M5. Normalised on the way in, so a hand-edited or truncated state
+107 -10
View File
@@ -23,7 +23,7 @@ from dataclasses import dataclass
import tiktoken
from sqlalchemy.orm import object_session
from .. import derived, models, narrative, summaries, worldstate
from .. import contextwindow, derived, models, narrative, summaries, worldstate
from ..knowledge import inject as knowledge_inject
from ..knowledge import records as knowledge_records
from . import encoding, history
@@ -64,6 +64,29 @@ MIN_LENGTH_FLOOR_WORDS = 60
# reader who wants longer turns can ask for them in the author's note.
MAX_LENGTH_FLOOR_WORDS = 300
#: M11, post-M8 finding C: what the campaign's own narration-length choice means
#: in words. Until M11 the choice became one English sentence in the campaign's
#: instructions and moved no number at all, while the numeric hint below was
#: derived from the *global* `max_output_tokens` and therefore read identically
#: for brief, medium and long — at the default cap, "must not exceed 506 words,
#: and it should not stop short of about 177" whichever the reader picked. A
#: setting with a visible control and no measurable effect is worse than no
#: setting, because the reader spends trust on it.
#:
#: These bands are (floor, ceiling) in words. They are a design decision made
#: here rather than a ratified requirement — `BUILD-MILESTONES.md` records
#: "Brief ~100-200 words" as a candidate — and they are deliberately wide enough
#: that a scene can breathe inside one.
LENGTH_BANDS = {
"brief": (70, 180),
"medium": (150, 380),
"long": (320, 700),
}
#: Where the floor lands when a band's ceiling has to be cut down to fit the
#: token cap: keep it proportional rather than letting it collide with the
#: ceiling.
BAND_FLOOR_SHARE = 0.5
# Built from the table vendored in `encoding.py`, not fetched: the upstream
# `tiktoken.get_encoding("cl100k_base")` downloads it on first use, and this
@@ -111,16 +134,49 @@ class Section:
return count_tokens(self.text)
def length_hint(max_output_tokens: int) -> str:
def length_hint(max_output_tokens: int, narration_length: str = "") -> str:
"""Ask for a turn that fits inside the output cap, stated as a word budget.
Returns an empty string when the cap is too small to state usefully. The
model can exceed the hint, so the hint earns its tokens only when there is
enough room for that overshoot to stay inside the cap.
M11: `narration_length` is the campaign's own choice — `brief`, `medium` or
`long`, or empty for a campaign that never made one. It narrows the range
*within* what the token cap allows; it can never widen it, because the cap
is what the endpoint will actually emit and a hint that asked for more than
that would be asking for a truncated turn.
**The generation budget is deliberately not touched.** Capping
`max_output_tokens` per length would make a brief turn likelier to hit the
endpoint's limit mid-sentence, and the state block is emitted *last* — so
the first thing a truncated reply loses is the turn's state. That is the
trade `BUILD-MILESTONES.md` names when it says "do not hard-truncate prose".
"""
words = int((max_output_tokens - LENGTH_HEADROOM) * WORDS_PER_TOKEN * LENGTH_BUFFER)
if words < MIN_LENGTH_HINT_WORDS:
return ""
band = LENGTH_BANDS.get((narration_length or "").strip().lower())
if band is not None:
band_floor, band_ceiling = band
# The cap still wins. A `long` campaign on a 300-token reply cap gets
# the cap's number, not 700, and the floor moves down with it.
words = min(words, band_ceiling)
floor = min(band_floor, int(words * BAND_FLOOR_SHARE))
tail = (
" Finish the narration and append the state block well inside the limit."
)
if floor < MIN_LENGTH_FLOOR_WORDS:
return (
f"[Hard limit: this turn must not exceed {words} words. Write only as "
f"much as the moment needs — a typical turn is much shorter.{tail}]"
)
return (
f"[Hard limit: this turn must not exceed {words} words, and it should not "
f"stop short of about {floor}. Prefer the lower end of that range unless "
f"the scene genuinely needs more.{tail}]"
)
tail = " Finish the narration and append the state block well inside the limit."
# State the number as a ceiling, never as a budget. In measurements, the
@@ -291,6 +347,7 @@ def build_context(
memory_bank: dict | None = None,
exclude_action_id: int | None = None,
knowledge: knowledge_records.Result | None = None,
window: contextwindow.Window | None = None,
) -> tuple[str, str, dict]:
"""Returns (system_text, story_text, context_report). `memory_bank` is the
result of memorybank.retrieve_memories (None when the bank is off);
@@ -302,7 +359,22 @@ def build_context(
embedding call, this function is synchronous, and a prompt builder that can
make network requests is a prompt builder that can fail halfway through a
prompt. None means the campaign has no library, or the caller did not ask.
M11: `window` is what the inference server was found to actually accept
(`contextwindow.probe`), and it arrives the same way and for the same
reason — asking the server is a network call and this function does not make
those. A **verified** window is a ceiling on the configured budget, which is
the whole of M11's no-silent-overflow invariant: the prompt this returns
cannot be longer than what the runtime will read, so `llama.cpp` never gets
the chance to drop the system block off the front. `None` means nobody
checked, and then the configured budget stands and the report says it was
not verified.
"""
# M11: the budget every section below is priced against. Capped by what the
# server was verified to accept; the configured value when nothing was
# verified, or when the reader has asked for something smaller.
budget = contextwindow.effective_budget(settings.context_token_budget, window)
script_mem = _script_memory(adventure)
# M7: priced before anything else, because the answer changes what is left.
# `plan` prices only the protected half — the untrusted-data rule and any
@@ -310,7 +382,7 @@ def build_context(
knowledge_plan = knowledge_inject.plan(
knowledge if knowledge is not None else knowledge_records.Result(),
count_tokens,
settings.context_token_budget,
budget,
)
# ----- The static block, which is identical on every turn -----
@@ -431,7 +503,7 @@ def build_context(
if isinstance(script_mem.get("frontMemory"), str):
front_memory = script_mem["frontMemory"].strip()
length_note = length_hint(settings.max_output_tokens)
length_note = length_hint(settings.max_output_tokens, adventure.narration_length)
# The live sections sit below the history, but they are still part of the
# prompt, so they still count against the budget. `world_lore` is the
@@ -465,7 +537,7 @@ def build_context(
# what it absorbs does not scale with the budget.
output_reserve = max(0, settings.max_output_tokens) + OUTPUT_SAFETY_MARGIN
protected = reserved + output_reserve
if protected >= settings.context_token_budget:
if protected >= budget:
# Failing here is the point. The alternative — carrying on with a token
# or two of history — builds a prompt that is known to overflow, and
# the reader gets a truncated reply with no explanation. §32: "fail
@@ -473,11 +545,18 @@ def build_context(
raise ContextOverflow(
f"The protected context needs {protected} tokens "
f"({reserved} of prompt plus {output_reserve} reserved for the "
f"reply) but the context budget is {settings.context_token_budget}. "
"Raise the context budget, lower the maximum reply length, or "
"shorten the campaign's canon, instructions and persona."
f"reply) but the context budget is {budget}. "
+ (
"That budget is what this server was found to accept, so raising "
"the setting alone will not help — load the model with a larger "
"window. Or lower the maximum reply length, or shorten the "
"campaign's canon, instructions and persona."
if budget < settings.context_token_budget else
"Raise the context budget, lower the maximum reply length, or "
"shorten the campaign's canon, instructions and persona."
)
)
available = settings.context_token_budget - protected
available = budget - protected
# ----- M7: retrieved imported knowledge, out of a share of `available` -----
#
@@ -644,12 +723,30 @@ def build_context(
# protected was subtracted.
"tokens": {
"total": count_tokens(system_text) + count_tokens(story_text),
"budget": settings.context_token_budget,
"budget": budget,
"configured_budget": settings.context_token_budget,
"output_reserve": output_reserve,
"protected": reserved,
"available_for_history": available,
"history_spent": spent,
},
# M11: what the server was found to accept, and how. `verified` false
# means nobody could check — the prompt was built to the configured
# budget and may be larger than the runtime will read. This travels in
# the stored snapshot, so a turn taken against an unverified window is
# identifiable afterwards rather than indistinguishable from a safe one.
"window": {
"verified": (window.verified if window is not None else False),
"tokens": (window.tokens if window is not None else None),
"source": (window.source if window is not None else contextwindow.UNKNOWN),
"model_max": (window.model_max if window is not None else None),
"detail": (window.detail if window is not None else "not checked"),
"capped": (
window is not None
and window.verified
and window.tokens < settings.context_token_budget
),
},
"cards": card_records,
"memories": memory_bank,
# M6: which summary was used, and which stretch of story it covers, so
+248
View File
@@ -0,0 +1,248 @@
"""M11: what the inference server will *actually* accept, as opposed to what we budgeted.
M8 found the failure this module exists to prevent. The application budgets a
prompt up to `Settings.context_token_budget` — 16,384 by default — while Ollama
enforces a window of its own, and on a machine with no VRAM that window defaults
to **4,096**. The request still returns HTTP 200. Nothing warns anybody. What
actually happens is worse than an error: `llama.cpp` drops the **oldest** tokens,
and the oldest tokens in this application are the system block — the narrator
rules and the campaign canon. The symptom is a narrator that forgets canon deep
into a long session, with nothing on screen explaining why, and every acceptance
test that reads a returned 200 as success passing throughout.
The invariant M11 requires:
The application must not silently budget more narrator input
than the configured Ollama runtime will actually accept.
Note the word *silently*. There are two honest outcomes and this module produces
both: either the window is **verified**, in which case the budget is capped to it
so the prompt physically cannot overflow; or it is **unverified**, in which case
the assembly says so, in the context report, on the connection test, and in the
turn's stored provenance. What must not happen is the third thing — assembling
16,384 tokens against a 4,096-token server and calling the result a turn.
## Why this is not solved by sending `num_ctx`
It was tried, and it is documented in `DEVELOPMENT.md`. Ollama's
OpenAI-compatible endpoint accepts `num_ctx` — nested in `options` or at the top
level — returns 200, and ignores it. Worse, it reloads the model at its own
default, so priming the server through the native API first does not help
either: the next request resets the window. The window is a property of how the
model is loaded, not of the request, so the only things that change it are a
model with `num_ctx` baked in (`/api/create`) or `OLLAMA_CONTEXT_LENGTH` on the
server. Both are operator actions. This module's job is not to change the
window; it is to find out what it is and refuse to lie about it.
## How the window is found
Ollama's native API sits beside the OpenAI-compatible one on the same host, so
this asks the server the application is already talking to, and nothing else. No
new destination, the same endpoint policy, the same TLS trust store.
/api/ps a loaded model reports `context_length`: the window the runtime
is enforcing *right now*. This is the truth when it is available.
/api/show an unloaded model may carry `num_ctx` in its baked parameters,
which is the window it will load with; `model_info` carries the
architecture's own ceiling, which caps everything else.
`/api/ps` is asked first because a model that is loaded has already settled the
question. `/api/show` answers it for a model that is not loaded yet, which is the
ordinary case at the start of a session.
## What it deliberately does not do
It does not hard-code 4,096, which would cripple a correctly configured
deployment; it does not raise the budget, which is the operator's decision; it
does not fall back to a cloud probe, a bundled table of model sizes, or a guess
from the model's name. An unknown window is reported as unknown.
"""
from __future__ import annotations
import logging
import re
import time
from dataclasses import dataclass
import httpx
from . import endpoints, tlstrust
log = logging.getLogger(__name__)
#: Short, because this sits in the turn path. A server that does not answer in
#: two seconds has told us what we need to know: we cannot verify the window
#: right now, and the turn should proceed unverified rather than stall.
PROBE_TIMEOUT = 2.0
CONNECT_TIMEOUT = 1.5
#: A verified window is stable — it changes when an operator reloads a model —
#: so it is worth keeping. A failure is cached too, and for much less time,
#: because the commonest cause is a server that is starting up.
POSITIVE_TTL = 600.0
NEGATIVE_TTL = 60.0
#: Sources, in the order of how much they prove.
LOADED = "loaded" # /api/ps: what the runtime is enforcing now
PARAMETERS = "parameters" # /api/show: what the model will load with
UNKNOWN = "unknown"
@dataclass(frozen=True)
class Window:
"""What was learned about the server's input window, and how."""
#: The total context in tokens — input *and* output share it — or None when
#: it could not be determined.
tokens: int | None
#: One of LOADED, PARAMETERS, UNKNOWN.
source: str
#: The architecture's own ceiling, when the server reported one. Useful to a
#: reader deciding whether raising the window is even possible.
model_max: int | None = None
#: Why the window is unknown, or how it was found. Shown to the user.
detail: str = ""
@property
def verified(self) -> bool:
return self.tokens is not None
UNVERIFIED = Window(tokens=None, source=UNKNOWN, detail="not checked")
_cache: dict[tuple[str, str], tuple[float, Window]] = {}
def native_base(endpoint_url: str) -> str:
"""The Ollama-native base beside an OpenAI-compatible endpoint.
`https://host:1234/v1` -> `https://host:1234`. Anything else is used as
given, because an endpoint that is not shaped like Ollama's is one this
cannot interrogate and should not guess about.
"""
trimmed = (endpoint_url or "").rstrip("/")
return re.sub(r"/v1$", "", trimmed)
def effective_budget(configured: int, window: Window | int | None) -> int:
"""The budget the prompt may actually use.
The whole enforcement, in one line: a verified window is a ceiling. The
configured budget still wins when it is *smaller*, because a reader who has
deliberately asked for a shorter prompt should get one.
"""
tokens = window.tokens if isinstance(window, Window) else window
if tokens is None or tokens <= 0:
return configured
return min(configured, tokens)
def cache_clear() -> None:
"""Forgets what was learned. Called when the endpoint or model changes."""
_cache.clear()
async def probe(endpoint_url: str, model: str, *, use_cache: bool = True) -> Window:
"""Asks the server what window `model` gets. Never raises.
Returns `UNVERIFIED` for every failure — refused endpoint, unreachable
server, TLS failure, a non-Ollama endpoint, an unparseable answer. The caller
cannot act differently on those and the reader is told the same thing either
way: the window could not be checked.
"""
if not endpoint_url or not model:
return Window(None, UNKNOWN, detail="no endpoint or model configured")
key = (endpoint_url, model)
now = time.monotonic()
if use_cache:
hit = _cache.get(key)
if hit is not None and hit[0] > now:
return hit[1]
window = await _ask(endpoint_url, model)
ttl = POSITIVE_TTL if window.verified else NEGATIVE_TTL
_cache[key] = (now + ttl, window)
return window
async def _ask(endpoint_url: str, model: str) -> Window:
# The same policy the turn itself is held to. A window probe must not be a
# way to reach an address inference may not (ADR 011, H12).
reason = endpoints.rejection_reason(endpoint_url)
if reason is not None:
return Window(None, UNKNOWN, detail=f"endpoint not allowed — {reason}")
base = native_base(endpoint_url)
try:
async with httpx.AsyncClient(
timeout=httpx.Timeout(PROBE_TIMEOUT, connect=CONNECT_TIMEOUT),
verify=tlstrust.ssl_context(),
) as client:
loaded = await _loaded_window(client, base, model)
if loaded is not None:
tokens, ceiling = loaded
return Window(
tokens, LOADED, ceiling,
f"{tokens:,} tokens, reported by the running model",
)
return await _declared_window(client, base, model)
except (httpx.HTTPError, ValueError, TypeError, KeyError) as exc:
log.debug("context window probe failed for %s: %s", base, exc)
return Window(None, UNKNOWN, detail=f"could not ask the server ({type(exc).__name__})")
async def _loaded_window(client, base: str, model: str):
"""`/api/ps`: the window a resident model is actually being served with."""
resp = await client.get(f"{base}/api/ps")
if resp.status_code != 200:
return None
for entry in (resp.json() or {}).get("models") or []:
if entry.get("name") == model or entry.get("model") == model:
tokens = entry.get("context_length")
if isinstance(tokens, int) and tokens > 0:
return tokens, None
return None
async def _declared_window(client, base: str, model: str) -> Window:
"""`/api/show`: what the model will load with, and its architectural cap."""
resp = await client.post(f"{base}/api/show", json={"model": model})
if resp.status_code != 200:
return Window(
None, UNKNOWN,
detail=f"the server did not describe the model (HTTP {resp.status_code})",
)
body = resp.json() or {}
ceiling = _architecture_ceiling(body.get("model_info") or {})
declared = _num_ctx(body.get("parameters"))
if declared is None:
return Window(
None, UNKNOWN, ceiling,
detail=(
"the model sets no num_ctx, so the server will load it at its own "
"default — which is 4,096 where there is no VRAM"
),
)
tokens = min(declared, ceiling) if ceiling else declared
return Window(
tokens, PARAMETERS, ceiling,
f"{tokens:,} tokens, from the model's own num_ctx",
)
def _num_ctx(parameters) -> int | None:
"""Reads `num_ctx` out of the plain-text parameter block Ollama returns."""
if not isinstance(parameters, str):
return None
match = re.search(r"^\s*num_ctx\s+(\d+)\s*$", parameters, re.MULTILINE)
return int(match.group(1)) if match else None
def _architecture_ceiling(model_info: dict) -> int | None:
"""`<arch>.context_length` — the largest window this model can have."""
for key, value in model_info.items():
if key.endswith(".context_length") and isinstance(value, int) and value > 0:
return value
return None
+14
View File
@@ -461,6 +461,20 @@ MIGRATIONS: list[tuple[int, str | dict[str, str]]] = [
# `MEDIA-EXTENSION-CONTRACT.md` §37 says must never appear without the
# reader asking for it. An M9 campaign therefore opens with no profiles,
# which is what such a campaign had, and plays unchanged without any.
# M11: the campaign's narration-length choice (post-M8 finding C). A new
# column on an existing table, which `create_all` cannot add, so unlike M10
# this one does need a migration.
#
# **No backfill, and the empty default is the correct value.** A campaign
# created before M11 never made this choice — its length preference lives,
# if anywhere, as an English sentence somebody may have edited inside
# `ai_instructions`. Reading a length back out of that free text would be
# inventing a decision the reader did not record. An empty value means "no
# choice", and `length_hint` then behaves exactly as it did before M11, so
# an existing campaign's prompts do not change under it.
(93, "ALTER TABLE adventures ADD COLUMN narration_length VARCHAR(20) "
"NOT NULL DEFAULT ''"),
]
LATEST_VERSION = max((v for v, _ in MIGRATIONS), default=1)
+9
View File
@@ -99,6 +99,15 @@ class Adventure(Base):
memory: Mapped[str] = mapped_column(Text, default="")
authors_note: Mapped[str] = mapped_column(Text, default="")
ai_instructions: Mapped[str] = mapped_column(Text, default="")
#: M11, post-M8 finding C: how long the reader asked turns to be — "brief",
#: "medium", "long", or empty for a campaign that never chose. Stored as its
#: own field rather than left inside `ai_instructions`, because the prompt
#: builder has to *derive a number* from it (`context.builder.LENGTH_BANDS`)
#: and reading an English sentence back out of a free-text field to do that
#: would be a parser nobody wants. The sentence still goes into the
#: instructions, where the reader can edit or remove it; this is the part the
#: application acts on.
narration_length: Mapped[str] = mapped_column(String(20), default="")
# A convenience mirror of whichever summary is eligible at the current
# position, and **never** an input to anything authoritative (M6 corrective,
# review finding M6-F1).
+37
View File
@@ -202,6 +202,43 @@ def entities_of_type(state: dict, wanted: str) -> dict:
}
def duplicate_names(state) -> dict[str, list[str]]:
"""Entities that share a display name, keyed by the name they share.
M11, post-M8 finding D. Two people in one scene were narrated as though
"Alice" were two different Alices, and the root cause could not be
established because the campaign was gone. One structural fact was
establishable by reading the code, and this is it: entities are keyed by the
id the model supplies, `DUPLICATE_ENTITY` rejects only a repeated *key*, and
nothing anywhere looks at `name`. Two entities called Alice are therefore
legal, silent, and exactly what the reader described seeing.
**This reports; it does not refuse.** Two people called Alice is an ordinary
thing for a story to contain — a mother and a daughter, a stranger who gives
a false name — and refusing it would refuse legitimate fiction in order to
guard against a model mistake. What was missing was not a rule but a signal:
nobody could see that it had happened. The identity diagnostic reads this,
the state panel can show it, and the decision stays the reader's.
Names are compared case-insensitively and stripped, because "Alice" and
"alice " are the same person to a reader and to a narrator, which is the
level the confusion happens at. Entities with no name are ignored: an
unnamed entity is not competing for a name with anything.
"""
entities = (state or {}).get("entities")
if not isinstance(entities, dict):
return {}
seen: dict[str, list[str]] = {}
for key, value in entities.items():
if not isinstance(value, dict):
continue
name = str(value.get("name") or "").strip().lower()
if not name:
continue
seen.setdefault(name, []).append(key)
return {name: keys for name, keys in seen.items() if len(keys) > 1}
# --------------------------------------------------------------- possessions
def owner_of(state: dict, item_key: str) -> str | None:
+3
View File
@@ -189,6 +189,9 @@ def create_adventure(
persona_name=payload.persona_name.strip(),
persona_pronouns=payload.persona_pronouns.strip(),
persona_desc=payload.persona_desc.strip(),
# M11: the reader's narration-length choice, kept as data so the prompt
# builder can turn it into a word range (post-M8 finding C).
narration_length=payload.narration_length,
)
db.add(adventure)
db.flush()
+6 -1
View File
@@ -8,6 +8,7 @@ from fastapi import Depends, HTTPException
from sqlalchemy.orm import Session
from ... import derived, memorybank, models, summaries
from ... import contextwindow
from ...context import ContextOverflow, build_context
from ...database import get_db
from ...knowledge import retrieval as knowledge_retrieval
@@ -29,9 +30,13 @@ async def dry_run_context(
# that skipped the library would show a prompt the next turn will not send,
# which is the one thing this panel must never do.
knowledge = await knowledge_retrieval.retrieve(adventure, settings)
# M11: and by the same probe the turn makes, for the same reason — a panel
# that showed a 16,384-token budget while the next turn will be capped to
# 4,096 would be showing a prompt that is not the one about to be sent.
window = await contextwindow.probe(settings.endpoint_url, settings.model)
try:
_, _, report = build_context(
adventure, settings, memories, knowledge=knowledge
adventure, settings, memories, knowledge=knowledge, window=window
)
except ContextOverflow as exc:
# M6: a dry run of a prompt that cannot be built is still an answer, and
+16 -2
View File
@@ -48,6 +48,7 @@ def read_state(
# The raw document, for the correction form to name a key with and for a
# test to assert on without parsing prose.
document=state,
duplicate_names=narrative.model.duplicate_names(state),
)
@@ -95,6 +96,16 @@ def correct_state(
)
if not review.accepted:
raise HTTPException(400, _refusal_message(review))
# M11: a correction can be partly refused — one bad reference among four
# good changes — and until M11 that came back as an unqualified success.
# Partial application is the deliberate behaviour (`validate.py`: losing
# three good changes to one typo is worse), so what M11 adds is the
# telling, not a change of behaviour.
refused = [
{"event": rejection.event, "reason": rejection.reason,
"detail": rejection.detail}
for rejection in review.rejected
]
node = head.node_at(db, adventure, adventure.head_depth)
new_state, _proposal = narrative.store.record(
@@ -120,11 +131,14 @@ def correct_state(
finally:
turns._active_turns.discard(adventure_id)
view = narrative.render.for_inspector(narrative.store.current(adventure))
state_now = narrative.store.current(adventure)
view = narrative.render.for_inspector(state_now)
return schemas.NarrativeStateOut(
groups=[schemas.StateGroup(**group) for group in view["groups"]],
empty=view["empty"],
document=narrative.store.current(adventure),
document=state_now,
duplicate_names=narrative.model.duplicate_names(state_now),
refused=refused,
)
+8
View File
@@ -16,6 +16,7 @@ from ... import (
attempts, head, limits, memorybank, models, narrative, schemas, tree,
worldstate,
)
from ... import contextwindow
from ...context import ContextOverflow, build_context, cursors
from ...knowledge import retrieval as knowledge_retrieval
from ...database import get_db
@@ -202,6 +203,12 @@ async def _generate_turn(
knowledge = await knowledge_retrieval.retrieve(
adventure, settings, exclude_action_id=replacing_id
)
# M11: what this server will actually accept. Asked here rather than inside
# the builder for the same reason retrieval is — the builder makes no
# network calls — and cached per endpoint and model, so it costs one short
# request per session rather than one per turn. An unverified window does
# not block the turn; it is recorded as unverified in the snapshot below.
window = await contextwindow.probe(settings.endpoint_url, settings.model)
try:
system_text, story_text, snapshot = build_context(
adventure,
@@ -209,6 +216,7 @@ async def _generate_turn(
memories,
exclude_action_id=replacing_id,
knowledge=knowledge,
window=window,
)
except ContextOverflow as exc:
# M6: the protected context does not fit in the configured budget, so
+64 -1
View File
@@ -15,7 +15,7 @@ from fastapi import APIRouter, Depends, HTTPException
from sqlalchemy.orm import Session
from starlette.concurrency import run_in_threadpool
from .. import auth, endpoints, models, schemas, tlstrust
from .. import auth, contextwindow, endpoints, models, schemas, tlstrust
from ..database import get_db
from ..providers.openai_compatible import CONNECT_TIMEOUT
@@ -65,6 +65,15 @@ async def update_settings(
if reason is not None:
raise HTTPException(400, f"That endpoint can't be used — {reason}.")
if any(
field in fields and fields[field] != getattr(settings, field)
for field in ("endpoint_url", "model")
):
# M11: a different server or a different model is a different window.
# What was verified about the old pair says nothing about the new one,
# and a stale ceiling is the one thing this must never apply.
contextwindow.cache_clear()
embedding_model_changed = (
"embedding_model" in fields
and fields["embedding_model"] != settings.embedding_model
@@ -165,6 +174,38 @@ async def list_endpoint_models(endpoint_url: str) -> dict:
return {"ok": True, "models": models_available}
def _window_warning(window: contextwindow.Window, settings: models.Settings) -> str | None:
"""What to tell the reader about the window, or None when nothing is wrong.
Three cases, and they need three different things done about them, so they
say three different things (the same reasoning as the connection test's own
four failure kinds).
"""
budget = settings.context_token_budget
if not window.verified:
return (
f"The context window this server will give '{settings.model}' could not "
f"be checked — {window.detail}. The story budget is {budget:,} tokens; "
"if the server's window is smaller than that it silently drops the "
"oldest part of the prompt, which here is the narrator's rules and the "
"campaign canon. See DEVELOPMENT.md, 'The context window your Ollama "
"actually enforces'."
)
if window.tokens < budget:
ceiling = (
f" The model itself can go up to {window.model_max:,}."
if window.model_max and window.model_max > window.tokens else ""
)
return (
f"This server gives '{settings.model}' {window.tokens:,} tokens, which is "
f"less than the {budget:,}-token story budget. Prompts are being built to "
f"{window.tokens:,} so nothing is silently truncated — the campaign simply "
f"gets less history than the setting asks for.{ceiling} To use the whole "
"budget, load the model with a larger window (DEVELOPMENT.md)."
)
return None
@router.post("/test")
async def test_connection(
db: Session = Depends(get_db),
@@ -173,6 +214,28 @@ async def test_connection(
"""Checks the endpoint the turn engine would use, and lists its models."""
settings = get_settings(db, user)
result = await list_endpoint_models(settings.endpoint_url)
if result.get("ok") and settings.model:
# M11: while we have the server's attention, ask what window it will
# give this model. This is where a reader can act on the answer — the
# model picker is on the same screen as the budget — and it is the
# difference between "your prompts are being truncated" being visible
# here and being invisible until the narrator forgets the canon.
# Cached, deliberately. The model-status badge calls this endpoint on
# every page load, so an uncached probe would be two extra requests to
# the inference host per page view for an answer that changes only when
# an operator reloads a model. Changing the endpoint or the model clears
# the cache (`update_settings`), which covers the case a reader can
# actually cause; the detail line always says where the number came from.
window = await contextwindow.probe(settings.endpoint_url, settings.model)
result = result | {"window": {
"verified": window.verified,
"tokens": window.tokens,
"source": window.source,
"model_max": window.model_max,
"detail": window.detail,
"budget": settings.context_token_budget,
"warning": _window_warning(window, settings),
}}
if result.get("ok") and settings.model and settings.model not in result["models"]:
# Reachable, but pointed at a model that is not installed there — the
# commonest way for a correct endpoint to still fail every turn.
+21
View File
@@ -170,6 +170,10 @@ class AdventureCreate(BaseModel):
persona_name: PersonaName = ""
persona_pronouns: PersonaPronouns = ""
persona_desc: Prose = ""
# M11: how long the reader wants turns to be. The setup screen also puts a
# sentence about it into `ai_instructions`; this is the half the prompt
# builder can do arithmetic with.
narration_length: Literal["", "brief", "medium", "long"] = ""
class AdventureUpdate(BaseModel):
@@ -177,6 +181,7 @@ class AdventureUpdate(BaseModel):
memory: Prose | None = None
authors_note: Prose | None = None
ai_instructions: Prose | None = None
narration_length: Literal["", "brief", "medium", "long"] | None = None
story_summary: Prose | None = None
auto_summarize: bool | None = None
memory_bank_enabled: bool | None = None
@@ -328,6 +333,21 @@ class NarrativeStateOut(BaseModel):
groups: list[StateGroup] = []
empty: bool = True
document: dict = {}
#: M11 (post-M8 finding D): entities that share a display name, keyed by the
#: name. Reported rather than refused — two people called Alice is ordinary
#: fiction — but reported, because until M11 it happened silently and one of
#: the finding's candidate failure modes is exactly this.
duplicate_names: dict[str, list[str]] = {}
#: M11: the changes in *this* correction that were refused, and why.
#:
#: `narrative/validate.py` states the rule — "what is never allowed is a
#: rejected event mutating anything, or a rejection being silent" — and until
#: M11 the human-facing half of it was missing. A correction where one event
#: of four was refused returned 201 with the other three applied and said
#: nothing, so the reader believed they had made a change they had not. The
#: refusals were recorded on the proposal for the audit trail; they were
#: simply never shown to the person who wrote them.
refused: list[dict] = []
class StateEventIn(BaseModel):
@@ -472,6 +492,7 @@ class AdventureOut(ORMModel):
memory: str
authors_note: str
ai_instructions: str
narration_length: str
story_summary: str
auto_summarize: bool
memory_bank_enabled: bool