Offer coordination tools only to a run that may call them - #731
Open
Chebaleomkar wants to merge 1 commit into
Open
Chebaleomkar wants to merge 1 commit into
Chebaleomkar wants to merge 1 commit into
Conversation
A group peer turn runs at depth 1 with no handoff claim, so authoriseCoordinationRun refuses every ask_person and message_bot call from it, yet toolsForRun still offered both. toolsForRun now asks the same authoriseRun first and offers nothing when a call would be refused. call() keeps its own check for stale schemas. Fixes CopilotKit#716
Chebaleomkar
requested review from
MikeRyanDev,
davidmckayv,
guidovizoso,
mxmzb and
tylerslaton
as code owners
October 3, 2026 18:24
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What this changes
Fixes #716. A group peer turn runs at depth 1 with no
handoffclaim, soauthoriseCoordinationRunrefuses everyask_personandmessage_botcall from it.toolsForRunstill offered both, so the Bot was shown tools that always failed and each attempt wrote anmcp.callback_refusedrow.toolsForRunnow asks the sameauthoriseRunthatcalluses and offers nothing when a call would be refused. This is option 2 from the issue, as @kvnloo recommended there.callkeeps its own check, so a stale schema is still refused and audited. Because the tool list and the refusal use one function, they can't drift apart.Where it runs
toolsForRunnow does the same Postgres readscallalready did (person, Bot profile, source thread, handoff lease), once when the run's tools are chosen.Boundary and audit
callis unchanged.Changelog
CHANGELOG.mdunderUnreleased.Proof
server/tests/remote-coordination.test.tsadds:authoriseCoordinationRunfor a leased delivery, a direct run, and a group peer turn (depth 1, no claim). The peer-turn case failed before the change (offeredmessage_botandask_person, both refused) and passes after it.Run locally on Windows with Bun 1.4.2 (CI pins 1.3.14), against
pgvector/pgvector:pg17with migrations applied:bun run format:check,bun run lint,bun run typecheck: pass.bun test --timeout 60000 server/tests: 4096 pass, 5 skip, 7 fail. All 7 are inlearning-langgraph,learning-mastra,provider-oauth,tenant-packageandproduction-loader-boundary. The first six fail identically onmain(they need the per-Bot installs CI does, or POSIX symlink/inode behaviour).production-loader-boundaryhit the 5 s limit once and passed when rerun on bothmainand this branch.--timeout 60000on this machine: with the 5 s default, 9 of 15 time out onmainand on this branch alike. With it, all 15 pass.