fix(openwebui): guarantee answer after tool budget

This commit is contained in:
Mikei386
2026-08-24 08:06:34 +02:00
parent c402ea79f7
commit 81a563372d
7 changed files with 133 additions and 17 deletions
+7
View File
@@ -0,0 +1,7 @@
FROM ghcr.io/open-webui/open-webui:v0.9.5
COPY platform/openwebui/patch_tool_finalization.py /tmp/patch_tool_finalization.py
RUN python /tmp/patch_tool_finalization.py \
/app/backend/open_webui/utils/middleware.py \
&& rm /tmp/patch_tool_finalization.py
@@ -1,7 +1,7 @@
"""
title: MikeAI Stability Guard
author: MikeAI
version: 2.1.0
version: 2.2.0
description: Bounds tool output and context use and breaks repeated tool-call loops.
"""
@@ -29,9 +29,9 @@ class Filter:
max_total_tool_chars: int = 36000
compacted_tool_chars: int = 2000
duplicate_tool_call_limit: int = 2
# OpenWebUI itself stops after twelve rounds without giving the model
# another completion. Stay below that ceiling so the model still gets
# a final, tool-free turn.
# Secondary protection for histories that re-enter the filter. The
# live internal tool loop is bounded and finalized by the derived
# OpenWebUI image because inlet filters do not run between its rounds.
max_tool_calls_per_turn: int = 10
max_private_table_tool_calls: int = 6
+3 -1
View File
@@ -237,7 +237,9 @@ with con:
"Für Repository-Suche, echte Datei-Inhalte und gezielte "
"Code-Suche auf GitHub. Bei Fragen zu Implementierung, README, API-Routen oder "
"Quellcode dieses Werkzeug statt allgemeiner Websuche verwenden. Keine Issues, "
"Pull Requests, Actions, rekursiven Komplettbäume oder Schreibzugriffe.",
"Pull Requests, Actions, rekursiven Komplettbäume oder Schreibzugriffe. Bei einem "
"konkreten Repository zuerst README beziehungsweise Wurzel einmal lesen, danach "
"höchstens drei gezielte Code-Suchen und nur relevante Trefferdateien öffnen.",
),
"athena-operator-local": (
"Athena Operator",
+7 -1
View File
@@ -213,7 +213,13 @@ params = {
"For GitHub repository implementation details, README files, source trees, "
"API routes, or code search, use the dedicated official GitHub repository "
"tool instead of guessing from ordinary web results. Use general web search "
"for wider public discussion and non-repository sources. "
"for wider public discussion and non-repository sources. For one named repository, "
"do not enumerate files recursively. Read the root README or one root listing once, "
"then use one to three targeted code searches for terms such as route, API, CLI, "
"endpoint, command or the relevant framework, and open only the few matching files "
"needed for evidence. If a live deployment is also mentioned, inspect that service "
"once with its domain tool. Normally finish within six GitHub calls and always "
"synthesize an answer from the evidence already obtained. "
"If a specialist tool returns an authentication, authorization, connection, "
"or configuration error, do not repeat the same call. Report the error. For "
"public information you may make at most one focused fallback attempt with "
@@ -0,0 +1,91 @@
#!/usr/bin/env python3
"""Make Open WebUI finish with an answer when its internal tool budget is used.
Open WebUI 0.9.5 otherwise ends the request with only
``Tool-call limit reached``. The patch is deliberately assertion-based: an
upstream source change makes the image build fail instead of silently applying
the modification at the wrong location.
"""
from pathlib import Path
import sys
if len(sys.argv) != 2:
raise SystemExit("usage: patch_tool_finalization.py MIDDLEWARE_PY")
path = Path(sys.argv[1])
source = path.read_text()
patch_marker = "The tool budget for this turn is exhausted. Do not call"
if patch_marker in source:
raise SystemExit("Open WebUI tool-finalization patch is already present")
needle = """ res = await generate_chat_completion(
request,
new_form_data,
user,
bypass_system_prompt=True,
)
"""
replacement = """ # The upstream loop otherwise stops with only
# `Tool-call limit reached` after executing this batch. Reserve
# the final completion for synthesis: keep every accumulated
# result, but expose no tools to the model and explicitly require
# a useful, evidence-bounded answer.
force_final_response = (
max_tool_call_iterations is not None
and tool_call_iterations >= max_tool_call_iterations
)
if force_final_response:
new_form_data.pop('tools', None)
new_form_data.pop('tool_ids', None)
final_metadata = dict(metadata)
final_metadata['tools'] = {}
final_metadata['tool_ids'] = []
final_metadata['tool_servers'] = []
new_form_data['metadata'] = final_metadata
new_form_data['messages'] = add_or_update_system_message(
'The tool budget for this turn is exhausted. Do not call '
'or imitate any more tools. Give the user a concise final '
'answer now using only the tool results already present. '
'Explicitly distinguish verified findings from inference, '
'and state what could not be verified. Never end without a '
'visible answer.',
new_form_data['messages'],
append=True,
)
res = await generate_chat_completion(
request,
new_form_data,
user,
bypass_system_prompt=True,
)
"""
if source.count(needle) != 1:
raise SystemExit(
f"expected exactly one Open WebUI continuation anchor, found {source.count(needle)}"
)
source = source.replace(needle, replacement)
needle = """ await stream_body_handler(res, new_form_data)
output[:0] = prior_output
"""
replacement = """ await stream_body_handler(res, new_form_data)
if force_final_response:
# A model may still print tool-shaped output after the
# schemas were removed. It must not trigger the upstream
# hard-error path or another execution attempt.
tool_calls.clear()
output[:0] = prior_output
"""
if source.count(needle) != 1:
raise SystemExit(
f"expected exactly one Open WebUI stream anchor, found {source.count(needle)}"
)
source = source.replace(needle, replacement)
path.write_text(source)