fix(tool-search): validate deferred tool_call arguments against the concrete schema before dispatch

The generic tool_call(name, arguments: object) bridge hides a deferred tool's
real parameter schema from provider-native validation. Before this, only
top-level required-key absence was checked, so invalid enums, wrong types,
nested required fields and forbidden extra properties reached the handler
or MCP server. Now the call is coerced (same coerce_tool_args path normal
dispatch uses) and validated with the schema's declared JSON Schema draft;
failures return the path, constraint and parameters schema so the model
repairs the call in one round-trip. Fails open on missing/malformed schemas,
external $ref, or missing jsonschema.

Fixes #73175

Salvaged from #73179 onto current main (post core-tool deferral #97979).
Co-authored-by: teknium1 <teknium@nousresearch.com>
This commit is contained in:
DragonnZhang
2026-09-01 22:33:05 -07:00
committed by Teknium
parent 94db305b1a
commit 9514d354ca
5 changed files with 345 additions and 28 deletions
+3 -3
View File
@@ -1386,9 +1386,9 @@ def handle_function_call(
"Use tool_search to find tools you can call."
)
)
# Probe-validate against the deferred tool's schema (ironclaw#5149):
# a blind call missing required arguments returns the parameter
# schema instead of dispatching into an opaque downstream failure.
# Validate against the deferred tool's concrete schema before
# dispatch. This covers constraints the provider cannot enforce
# through the generic tool_call ``arguments: object`` bridge.
_probe_err = _ts_mod.validate_deferred_call_args(underlying_name, underlying_args)
if _probe_err is not None:
return _return_bridge_result(_probe_err)