E2E #6: the flow ordered SIE-first correctly, but the agent never
discovered gnubok_create_sie_upload, ran a local preflight, and sent the
user to the web wizard again; it also rendered a duplicate generic bank
card before the Swedbank-specific one.
1. New sie-drop widget (ui://sie-drop/app.html), rendered
definition-level by gnubok_create_sie_upload: the user drags the
.se/.sie file onto the card, the widget reads the EXACT bytes
(FileReader), computes sha256 (WebCrypto), calls
gnubok_sie_preflight via tools/call with file_content_base64 +
sha256, shows the verdict, and on Importera stages
gnubok_import_sie with the preflight's mappings. No network from
the iframe, no model reproduction: byte path goes through the host
bridge only, narrated into chat via ui/updateContext.
2. The inline size cap now applies only WITHOUT sha256: a hash-verified
payload is byte-exact by proof, so the widget's 100 KB+ base64
passes while unhashed model-retyped content stays refused.
3. Discovery + ordering fixes: create_sie_upload/preflight/import
descriptions name the card path explicitly; create_company's
history_note points at the card; connect_bank description says pass
bank on the FIRST call when the user has named it (the duplicate
generic card came from a bare call followed by the nudged retry).
Co-authored-by: Jakob Wennberg <311770904+jakobwennberg-oss@users.noreply.github.com>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
From the fourth E2E run: the agent correctly refused to reproduce a
104 KB SIE file token by token (silent mid-verifikat truncation) and
dead-ended to the web wizard, and its replies were walls of compliance
prose.
1. gnubok_create_sie_upload: signed same-origin upload URL (reuses the
pending-document infra; .se/.sie/.si only, 50 MB HTTP cap).
gnubok_sie_preflight and gnubok_import_sie accept upload_id as the
byte-exact source, plus optional sha256 (hex of the raw bytes)
verified on the upload_id/base64 paths so truncation is DETECTED,
never silent. Inline content above 120k chars is refused with a
pointer to the upload flow. Scope bookkeeping:write (same intent as
import_sie).
2. Skill: brevity rule (max ~8 short lines per reply, one warning per
step, no legal essays), memory-first rule (check what is already
known before asking the opening questions), the upload-first SIE
step, and gnubok_explain_voucher_gap after import for skipped
voucher numbers.
3. CONNECTORS.md starter prompt rewritten memory-first so it stays
copy-paste ready without the user's own data in it. Plugin v1.2.2.
tools/list ceiling 62K to 62.4K documented in the bench.
Co-authored-by: Jakob Wennberg <311770904+jakobwennberg-oss@users.noreply.github.com>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Three changes from the first real E2E run (Arcim, 2026-08-26):
1. gnubok_sie_preflight: read-only scan of a SIE file shared in chat
BEFORE anything is staged: parse, validate (per-verifikat balance, IB,
closed-year P&L residual), CP1252-mojibake tripwire, duplicate
file/period check, org-number match against the company (the
wrong-company import is the worst silent failure this flow can have),
and suggested account mappings shaped for direct passthrough to
gnubok_import_sie. Both tools now also accept file_content_base64,
decoded with the same encoding detection as the HTTP upload route so
CP437 exports keep their åäö.
2. Onboarding skill v2: opens with TWO questions (orgnr + 'vilket system
hade du innan?'), imports history before the bank (PSD2 rarely reaches
far enough back), and a momentum rule: the create preview is the ONLY
stop; connect tools are called without asking, and categorization
starts as soon as the bank is active. connect_bank instructions now
describe the account-selection dialog that actually gates the first
sync, and the bank history cap.
3. deriveFirstYearDefaults: no closed fiscal period in the registry now
extends the first-year window from 12 to 18 months (BFL 3 kap 3 §):
a 13-month-old company with no annual report is still in its first,
extended räkenskapsår (the Arcim case the 12-month rule missed).
Applied in the web journey and the lookup tool.
tools/list ceiling 61.5K to 62K, documented in the bench.
Co-authored-by: Jakob Wennberg <311770904+jakobwennberg-oss@users.noreply.github.com>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>