- spill-policy reserves the spill notice's byte cost inside maxInlineBytes, so the replacement (preview + notice) never exceeds the documented model-facing cap. When the notice alone fills the budget the preview is empty; when even a notice-only replacement is not smaller than the original, the inline result is kept (spilling would only add bytes). - retention TextRetainer trims an oversized single suffix chunk to the last suffixCap bytes on push, so tail/headTail retention stays bounded by suffixCap instead of retaining and re-copying the whole chunk in finish() — this is the spill preview path, which pushes the whole result as one chunk.
web/ - web capability family
The web access capability seam: an abstract web interface, search/fetch provider implementations, and the model-facing web tools. All product packages.
| Package | Role | ctx key |
|---|---|---|
web/ |
Abstract web seam (search/fetch provider registries + selection + vocabulary + WebError) |
ctx.web |
web-search-exa/ |
Exa-backed WebSearchProvider |
(registers on ctx.web) |
web-search-perplexity/ |
Perplexity-backed WebSearchProvider |
(registers on ctx.web) |
web-search-deepseek/ |
DeepSeek-backed WebSearchProvider using native web_search through the Anthropic-compatible API |
(registers on ctx.web) |
web-fetch-local/ |
Anonymous public HTTP(S) WebFetchProvider |
(registers on ctx.web) |
tool-web/ |
Model-facing web_search/web_fetch tool schemas |
(registers on ctx.tools) |
The interface lives at web/web/. Unlike bash/fs, the seam spans two capabilities (search and fetch) with potentially multiple providers each: ctx.web is one web-access middle layer with one provider-selection policy, one abort/error vocabulary, and one product-facing "how this harness reaches the web" config surface. Providers register capabilities, not tools; tool-web is the only owner of model-facing names, schemas, prompt guidance, and presentation. A search provider swap does not change how the model asks for a query, and a fetch implementation swap does not change how the model asks for a URL.
See the web capability seam RFC for the design rationale, including why search and fetch are deliberately one seam and why web_fetch's SSRF protection is deferred.