headroom/tests/test_cache/test_prefix_tracker.py

Ignoring revisions in .git-blame-ignore-revs. Click here to bypass and see the normal blame view.

980 lines
39 KiB
Python
Raw Normal View History

"""Tests for PrefixCacheTracker — cache-aware compression."""
import time
import pytest
from headroom.cache.prefix_tracker import (
feat(cache): attribute prompt-cache misses to TTL lapse vs prefix change (#1313) (#1343) ## Description A low prompt-cache hit rate is hard to act on without knowing *why* turns miss. Two very different causes need very different responses: - **TTL lapse** — the session went idle longer than the provider's cache lifetime, so the entry expired. The fix is a longer TTL (e.g. Anthropic's 1h breakpoint instead of the 5m default). - **Prefix change** — the cacheable message prefix shifted, so the new request couldn't match the cached key. A longer TTL won't help here at all. Right now those look identical from the dashboard (just "cache_read was 0"). This adds the attribution so a user can actually decide 5m vs 1h. Closes #1313 ## Type of Change - [ ] Bug fix (non-breaking change that fixes an issue) - [x] New feature (non-breaking change that adds functionality) - [ ] Breaking change (fix or feature that would cause existing functionality to change) - [ ] Documentation update - [ ] Performance improvement - [ ] Code refactoring (no functional changes) ## Changes Made `PrefixCacheTracker` already kept the previous turn's forwarded messages and a per-turn activity timestamp, so the signal was already there — it just wasn't being read. - **`prefix_tracker.py`** — `classify_cache_miss()`: when a turn expected a cached prefix (non-zero cached tokens last turn) but read 0 this turn, returns `ttl_expiry` if the idle gap exceeded the provider cache TTL, else `prefix_change` if the forwarded prefix differs from last turn's, else `unknown`. **TTL wins ties** — once the entry lapsed, a coincident content change is moot, and the 5m-vs-1h decision is exactly what the TTL signal answers. A 1h-breakpoint session can widen the window via `PrefixFreezeConfig.cache_ttl_seconds`. Cold starts and hits return `is_miss=False`. - **Anthropic handlers (streaming + non-streaming)** — classify BEFORE `update_from_response` overwrites the last-turn state the classifier reads, then record the reason. - **`prometheus_metrics.py`** — a per-provider/per-reason counter, `record_cache_miss_attribution()`, reset handling, and a `headroom_cache_miss_attribution_total{provider,reason}` export series. - **`cost.py`** — `build_prefix_cache_stats()` aggregates a `miss_attribution` block (per-provider + totals, with the ttl/prefix split as a % of *attributed* misses, so `unknown` doesn't dilute the headline). - **dashboard** — a "Cache Miss Attribution" panel (TTL expiry / prefix change / unknown / total) with a "mostly TTL lapse" vs "mostly prefix change" headline. Scoped to Anthropic for this first cut (where the tracker is fully wired); OpenAI/Gemini can follow once the shape is proven. ## Testing - [x] Unit tests pass (`pytest`) - [ ] Linting passes (`ruff check .`) - [ ] Type checking passes (`mypy headroom`) - [x] New tests added for new functionality - [ ] Manual testing performed ### Test Output ```text $ python -m pytest tests/test_cache/test_prefix_tracker.py -q 38 passed # 29 existing + 9 new classifier tests (TestClassifyCacheMiss). $ python -m pytest tests/test_proxy_cache_ttl_metrics.py -k "miss_attribution or reset_runtime_clears" -q 5 passed, 8 deselected # new: counter bucketing, stats aggregation, empty case, /metrics export, reset. ``` The full `test_proxy_cache_ttl_metrics.py` / `test_proxy_dashboard_stats_cache.py` files have some failures in this sandbox (`test_stats_endpoint_*`, streaming-parser, reset-counters) — those spin up the proxy server / Rust `_core` extension, which isn't built here. I confirmed via `git stash` that they fail identically on `main` without my changes, so they're pre-existing and unrelated. My additions to the stats dict are purely additive and don't break any passing assertion. ## Real Behavior Proof - Environment: Windows 11, Python 3.10. The Rust `_core` extension and a live proxy aren't available in this checkout. - Exact command / steps: drove `classify_cache_miss()` through every branch with a faithful warm-then-miss sequence; drove `record_cache_miss_attribution()` → `build_prefix_cache_stats()` → `export()` end to end. - Observed result: classifier returns `cold_start`/`hit`/`ttl_expiry`/`prefix_change`/`unknown` correctly, TTL wins the tie when both signals fire, a growing (append-only) prefix is treated as stable, and the 1h override widens the window. The stats builder produces `miss_attribution.totals` (`ttl_expiry`/`prefix_change`/`unknown`/`total` + `ttl_expiry_pct`/`prefix_change_pct` over attributed misses) and `by_provider`; `/metrics` emits `headroom_cache_miss_attribution_total{provider="anthropic",reason="ttl_expiry"}`. - Not tested: a live Anthropic session through the running proxy with a real idle-then-resume to confirm the handler wiring fires end-to-end. I verified the handler integration by reading scope/order (classify before `update_from_response`, `provider_name`/`self.metrics` in scope) and unit-tested every layer it calls, but didn't exercise the actual server loop. ## Review Readiness - [x] I have performed a self-review - [x] This PR is ready for human review ## Checklist - [x] My code follows the project's style guidelines - [x] I have performed a self-review of my code - [x] I have commented my code, particularly in hard-to-understand areas - [ ] I have made corresponding changes to the documentation - [x] My changes generate no new warnings - [x] I have added tests that prove my fix is effective or that my feature works - [x] New and existing unit tests pass locally with my changes - [ ] I have updated the CHANGELOG.md if applicable ## Additional Notes - The classifier is intentionally pure (takes the cache-read result + current forwarded messages + an optional idle override) so it's order-independent and unit-testable without a live tracker clock. - No README/docs change yet — this surfaces in the dashboard and `/metrics`, which are self-describing; happy to add a docs page if you'd like one. - CHANGELOG.md isn't touched — release-please generates it from the `feat(cache):` commit subject. - Follow-ups if useful: extend to OpenAI/Gemini handlers, and add a per-provider breakdown row in the dashboard panel (the stats already carry `by_provider`).
2026-06-24 20:20:34 +05:30
MISS_COLD_START,
MISS_PREFIX_CHANGE,
MISS_TTL_EXPIRY,
MISS_UNKNOWN,
FreezeStats,
PrefixCacheTracker,
PrefixFreezeConfig,
SessionTrackerStore,
)
class TestPrefixCacheTracker:
"""Test PrefixCacheTracker core functionality."""
@pytest.fixture
def tracker(self):
return PrefixCacheTracker("anthropic")
@pytest.fixture
def openai_tracker(self):
return PrefixCacheTracker("openai")
def test_turn_0_no_freeze(self, tracker):
"""First turn should never freeze — no cache state yet."""
assert tracker.get_frozen_message_count() == 0
def test_turn_1_with_cache_hit_freezes(self, tracker):
"""After turn 1 with cache hits, turn 2 should freeze."""
messages = [
{"role": "system", "content": "You are a helpful assistant." * 100},
{"role": "user", "content": "Hello"},
{"role": "assistant", "content": "Hi there!"},
]
# Simulate: provider cached 2000 tokens (system + user)
token_counts = [1500, 50, 500]
tracker.update_from_response(
cache_read_tokens=0,
cache_write_tokens=2050,
messages=messages,
message_token_counts=token_counts,
)
# On turn 2, the first 2 messages (1500 + 50 = 1550 <= 2050) are frozen
assert tracker.get_frozen_message_count() == 3 # All 3 fit within 2050
def test_partial_freeze(self, tracker):
"""Only messages that fit within cached tokens are frozen."""
messages = [
{"role": "system", "content": "System prompt" * 50},
{"role": "user", "content": "First question" * 50},
{"role": "assistant", "content": "First answer" * 50},
{"role": "user", "content": "Second question"},
]
token_counts = [2000, 500, 500, 50]
tracker.update_from_response(
cache_read_tokens=2500,
cache_write_tokens=0,
messages=messages,
message_token_counts=token_counts,
)
# 2000 + 500 = 2500 <= 2500, but 2000 + 500 + 500 = 3000 > 2500
assert tracker.get_frozen_message_count() == 2
def test_cold_start_no_freeze(self, tracker):
"""If cache_read=0 and cache_write=0, don't freeze."""
messages = [{"role": "user", "content": "Hello"}]
tracker.update_from_response(
cache_read_tokens=0,
cache_write_tokens=0,
messages=messages,
)
assert tracker.get_frozen_message_count() == 0
def test_cache_write_freezes_next_turn(self, tracker):
"""Cache writes (new cache entries) should be frozen on the next turn."""
messages = [
{"role": "system", "content": "System" * 200},
{"role": "user", "content": "Hello"},
]
token_counts = [1500, 50]
# Turn 1: provider writes to cache (above min threshold)
tracker.update_from_response(
cache_read_tokens=0,
cache_write_tokens=1550,
messages=messages,
message_token_counts=token_counts,
)
# Turn 2: should freeze what was written
assert tracker.get_frozen_message_count() == 2
def test_min_cached_tokens_threshold(self):
"""Below min_cached_tokens, no freeze."""
config = PrefixFreezeConfig(min_cached_tokens=2000)
tracker = PrefixCacheTracker("anthropic", config)
messages = [{"role": "user", "content": "Hello"}]
# Turn 1: only 500 tokens cached — below threshold
tracker.update_from_response(
cache_read_tokens=0,
cache_write_tokens=500,
messages=messages,
message_token_counts=[500],
)
assert tracker.get_frozen_message_count() == 0
def test_disabled_config(self):
"""Disabled config always returns 0."""
config = PrefixFreezeConfig(enabled=False)
tracker = PrefixCacheTracker("anthropic", config)
messages = [{"role": "system", "content": "System" * 500}]
tracker.update_from_response(
cache_read_tokens=5000,
cache_write_tokens=0,
messages=messages,
message_token_counts=[5000],
)
assert tracker.get_frozen_message_count() == 0
def test_turn_number_increments(self, tracker):
"""Turn number should increment on each update."""
messages = [{"role": "user", "content": "Hello"}]
assert tracker._turn_number == 0
tracker.update_from_response(0, 0, messages)
assert tracker._turn_number == 1
tracker.update_from_response(0, 0, messages)
assert tracker._turn_number == 2
def test_stats_tracking(self, tracker):
"""Stats should reflect tracker state."""
stats = tracker.stats
assert isinstance(stats, FreezeStats)
assert stats.busts_avoided == 0
assert stats.tokens_preserved == 0
assert stats.turn_number == 0
def test_record_bust_avoided(self, tracker):
"""Recording bust avoided should update stats."""
tracker.record_bust_avoided(tokens_preserved=5000, compression_foregone=500)
tracker.record_bust_avoided(tokens_preserved=3000, compression_foregone=200)
stats = tracker.stats
assert stats.busts_avoided == 2
assert stats.tokens_preserved == 8000
assert stats.compression_foregone_tokens == 700
assert stats.net_benefit_tokens == 7300
def test_should_force_compress_outside_frozen(self, tracker):
"""Messages outside frozen prefix should always be compressed."""
tracker._cached_message_count = 3
assert tracker.should_force_compress(5, 1000, 200) is True
def test_should_force_compress_when_savings_exceed_discount(self, tracker):
"""For Anthropic (90% discount), compression must save >90% to be worth it."""
tracker._cached_message_count = 5
# 95% savings > 90% discount — should force compress
assert tracker.should_force_compress(2, 1000, 50) is True
# 50% savings < 90% discount — should NOT force compress
assert tracker.should_force_compress(2, 1000, 500) is False
def test_should_force_compress_openai(self, openai_tracker):
"""For OpenAI (50% discount), compression must save >50% to be worth it."""
openai_tracker._cached_message_count = 5
# 60% savings > 50% discount — should force compress
assert openai_tracker.should_force_compress(2, 1000, 400) is True
# 40% savings < 50% discount — should NOT force compress
assert openai_tracker.should_force_compress(2, 1000, 600) is False
def test_estimate_message_tokens(self):
"""Token estimation should roughly match character / 3.5."""
messages = [
{"role": "system", "content": "A" * 350}, # ~100 tokens
{"role": "user", "content": "B" * 70}, # ~20 tokens
]
counts = PrefixCacheTracker._estimate_message_tokens(messages)
assert len(counts) == 2
assert counts[0] > counts[1] # System should have more tokens
def test_estimate_content_blocks(self):
"""Token estimation should handle Anthropic content blocks."""
messages = [
{
"role": "user",
"content": [
{"type": "text", "text": "A" * 350},
{"type": "text", "text": "B" * 350},
],
},
]
counts = PrefixCacheTracker._estimate_message_tokens(messages)
assert len(counts) == 1
assert counts[0] > 100
def test_estimate_tool_result_content(self):
"""Token estimation should count tool_result content field."""
tool_content = "x" * 3500 # ~1000 tokens
messages = [
{
"role": "user",
"content": [
{
"type": "tool_result",
"tool_use_id": "t1",
"content": tool_content,
}
],
},
]
counts = PrefixCacheTracker._estimate_message_tokens(messages)
assert len(counts) == 1
# Should be ~1000 tokens, definitely > 100
assert counts[0] > 100
def test_estimate_tool_use_input(self):
"""Token estimation should count tool_use input field."""
messages = [
{
"role": "assistant",
"content": [
{
"type": "tool_use",
"id": "t1",
"name": "Read",
"input": {"file_path": "/very/long/path/" + "x" * 700},
}
],
},
]
counts = PrefixCacheTracker._estimate_message_tokens(messages)
assert len(counts) == 1
# Should count the serialized input dict
assert counts[0] > 50
def test_estimate_tool_result_nested_blocks(self):
"""Token estimation should handle nested content blocks in tool_result."""
messages = [
{
"role": "user",
"content": [
{
"type": "tool_result",
"tool_use_id": "t1",
"content": [
{"type": "text", "text": "A" * 3500},
],
}
],
},
]
counts = PrefixCacheTracker._estimate_message_tokens(messages)
assert len(counts) == 1
assert counts[0] > 100
def test_session_ttl_expiry(self):
"""Tracker should report as expired after TTL."""
config = PrefixFreezeConfig(session_ttl_seconds=1)
tracker = PrefixCacheTracker("anthropic", config)
assert tracker.is_expired is False
# Simulate time passing
tracker._last_activity = time.time() - 2
assert tracker.is_expired is True
class TestSessionTrackerStore:
"""Test SessionTrackerStore management."""
@pytest.fixture
def store(self):
return SessionTrackerStore()
def test_get_or_create_new(self, store):
"""Should create a new tracker for unknown session."""
tracker = store.get_or_create("session-1", "anthropic")
assert isinstance(tracker, PrefixCacheTracker)
assert tracker.provider == "anthropic"
def test_get_or_create_existing(self, store):
"""Should return the same tracker for the same session."""
tracker1 = store.get_or_create("session-1", "anthropic")
tracker2 = store.get_or_create("session-1", "anthropic")
assert tracker1 is tracker2
def test_different_sessions(self, store):
"""Different sessions should get different trackers."""
tracker1 = store.get_or_create("session-1", "anthropic")
tracker2 = store.get_or_create("session-2", "openai")
assert tracker1 is not tracker2
assert tracker1.provider == "anthropic"
assert tracker2.provider == "openai"
def test_active_sessions_count(self, store):
"""Should track the number of active sessions."""
assert store.active_sessions == 0
store.get_or_create("s1", "anthropic")
assert store.active_sessions == 1
store.get_or_create("s2", "openai")
assert store.active_sessions == 2
def test_cleanup_expired(self, store):
"""Should remove expired sessions on cleanup."""
config = PrefixFreezeConfig(session_ttl_seconds=1)
store = SessionTrackerStore(default_config=config)
tracker = store.get_or_create("expired-session", "anthropic")
tracker._last_activity = time.time() - 2
# Force cleanup
store._last_cleanup = 0
store._maybe_cleanup()
assert store.active_sessions == 0
def test_compute_session_id_from_header(self, store):
"""Should use x-headroom-session-id header if present."""
class MockRequest:
headers = {"x-headroom-session-id": "explicit-id-123"}
session_id = store.compute_session_id(
MockRequest(), "claude-3", [{"role": "user", "content": "Hi"}]
)
assert session_id == "explicit-id-123"
def test_compute_session_id_from_hash(self, store):
"""Should hash model + system prompt as fallback."""
class MockRequest:
headers = {}
messages = [
{"role": "system", "content": "You are helpful."},
{"role": "user", "content": "Hi"},
]
id1 = store.compute_session_id(MockRequest(), "claude-3", messages)
id2 = store.compute_session_id(MockRequest(), "claude-3", messages)
assert id1 == id2 # Stable hash
assert len(id1) == 16
# Different model = different session
id3 = store.compute_session_id(MockRequest(), "gpt-4", messages)
assert id3 != id1
fix(cache): stable session identity and per-conversation prefix trackers under agentic clients (#2193) ## Description Running headroom as the proxy for Claude Code destroys Anthropic prompt-cache reuse (#2085: ~4.4x cache-creation inflation, 2.5–3x net cost). Tracing live Claude Code traffic through the proxy shows **two independent session-identity defects**, both of which orphan or thrash the frozen-prefix state; this PR fixes both. ### Defect 1: `<system-reminder>` turns rotate the fallback session id mid-conversation Claude Code interleaves reminder turns into the history as actual `role:"system"` messages (hook output, skills lists, file-truncation notices). `compute_session_id` hashed **every** system message, so the id rotated each time a reminder landed. Live trace (subagent reading two 80KB files; sid changes exactly when the truncation reminder appears, and the tracker restarts at turn 0): ``` REQ#2 sid=68d4ee666990 nmsg=3 [0]SYSTEM<<top-level system>> [1]user [2]SYSTEM<<skills reminder>> REQ#3 sid=6944948c9fb2 nmsg=6 ... [5]SYSTEM<<Truncated: PARTIAL view ...>> <- id rotated ``` Everything keyed on the session id is orphaned at that moment: the prefix tracker (freeze never survives past a reminder-bearing turn), beta-header stickiness, the CCR and memory-tool registries, and the compression cache. **Fix:** hash only the **leading run** of system messages (everything before the first non-system turn) — the top-level system prompt on the Anthropic path (folded in as the synthetic first message), the conventional leading system message(s) on the OpenAI path. Stable for the life of a conversation; mid-history system turns are content, not identity. ### Defect 2: conversations sharing a (now stable) id thrash one tracker With ids stable, the fallback tuple `model + system prompt` is identical across every same-type parallel subagent (and any sessions reusing one system prompt) — all of them collapse onto one `PrefixCacheTracker`, and their interleaved histories cross-contaminate the freeze state: the forwarded prefix is byte-unstable on nearly every turn and the provider cache is re-written instead of read. Reproduced against the real code paths (script below): ``` 1) fallback session ids: A=3dc639aaf4f48fa1 B=3dc639aaf4f48fa1 -> COLLIDE=True 2) single conversation, legacy : stable prefix on 4/4 later turns, trackers=1 2) interleaved (subagents), legacy : stable prefix on 0/9 later turns, trackers=1 2) interleaved, lineage resolution : stable prefix on 8/8 later turns, trackers=2 ``` **Fix:** `SessionTrackerStore.resolve_tracker` — within a session id, reuse the tracker whose previous request messages are a prefix of the incoming history (client histories are append-only, so a conversation's next request always extends its previous one); a diverging or rewritten history (client-side compaction) starts a fresh lineage. Matching uses the repo's existing canonical cross-turn equivalence (`_canonicalize_for_prefix_compare`, the same one the cache-stable delta path uses) on the **original client bytes**, so moved cache breakpoints, string<->block sugar, transport annotations, or a tail-mutating `pre_compress` hook never read as a rewrite. Byte-identical histories (templated fan-outs before they diverge) intentionally share a tracker — their provider cache line is identical too. ### Both fixes together, on live Claude Code traffic (sonnet, 2 parallel Explore agents) ``` main conversation: sid=5b7e245a... one tracker, turns 0->4, id stable across reminders agents (collide): sid=2bdffc9e... -> lineage bare (alpha) turns 0->1->2 -> lineage "~1" (beta) turns 0->1->2 ``` Before: the agents' ids rotated per reminder (every tracker stuck at turn 0), and whenever they did share an id they thrashed one tracker (`0/9` stable prefixes in the repro). ### Why not key the session id on conversation content? Draft #1912 folds the first user turn into the fallback id; this change composes with it, but identity-level keying alone can't close #2085: identical first turns (templated fan-outs) still collide, and everything keyed on the session id rotates with it when the client rewrites history. The "session" (client/workspace grouping) and the "conversation" (positional cache lineage) are different identities; only the tracker holds positional per-turn state that thrashes under collision — beta stickiness is a monotone union and the compression cache is content-addressed — so lineage resolution lives one level below the session id and leaves the id semantics (and every other consumer) untouched. ## Changes Made - `headroom/cache/prefix_tracker.py`: - `compute_session_id`: harvest only the leading system run (defect 1). - `SessionTrackerStore.resolve_tracker`: conversation-lineage resolution (defect 2). First lineage lives under the bare session id — single-conversation sessions behave byte-identically to before; degrades to `get_or_create` when messages are absent or prefix freeze is disabled. - Lineages are capped per session id (`PrefixFreezeConfig.max_lineages_per_session`, default 32). **Over-cap conversations share one overflow tracker instead of evicting an established lineage** — any eviction policy degrades every conversation once the working set exceeds the cap (under round-robin the victim is always the conversation about to arrive), while overflow sharing degrades only the over-cap tail, to exactly the pre-lineage shared behavior; `0` disables lineage splitting. Chains are stored as structural snapshots that normalize `NaN` (`json.loads` accepts bare NaN, and `NaN != NaN` would read a byte-identical resend as a rewrite). Synthetic lineage keys use a `\x00` separator, which cannot appear in an HTTP header value, so they can never collide with a client-supplied `x-headroom-session-id`. - `headroom/proxy/handlers/anthropic.py`, `openai.py`: the session id and the lineage both derive from the **same original client bytes** (a turn-dependent hook rewrite can no longer rotate one without the other); anthropic folds in its synthetic system message so explicit-header clients with different system prompts stay separate. Plus a docstring correction in `streaming.py` that falsely claimed its coarse mid-turn key "mirrors" `compute_session_id`. - `tests/test_cache/test_prefix_tracker.py`: 24 new test cases — reminder-rotation regression; interleaved isolation + per-conversation turn state; identical-first-turn share-then-split; cache_control movement (3 cases); representation churn (string<->block sugar / streaming `index` / Bedrock cachePoint); rewritten history → fresh lineage (compacted / middle-edited / truncated); legacy no-messages / freeze-disabled / empty-canonical fallbacks; NaN-in-tool-payload stability; overflow sharing, established-lineages-survive-cap, and a cap+1 round-robin no-cliff guard; TTL cleanup; session-id-not-rotated-by-lineage guard. One existing test renamed (`uses_all_system_messages` → `distinguishes_leading_system_run`) to match the new contract. - Three SimpleNamespace stub stores in existing tests gained a `resolve_tracker` field (handlers call it unconditionally — a silent `hasattr` fallback would degrade to the pre-fix behavior with no signal). One of them is the cold-start fast-pass suite (#2073), which landed while this branch was in review. - `CHANGELOG.md` entry. ## Type of Change - [x] Bug fix (non-breaking change that fixes an issue) ## Testing - [x] Unit tests pass (`pytest`) — 11 failed, 8652 passed, 528 skipped in 4:37 (the 11 are pre-existing on unmodified `main` — verified by rerunning the same node ids on a clean checkout: gh-CLI/onnx/PID-reuse/deadline flakes and order-dependent cases, none touching session/cache/proxy paths) - [x] Linting passes (`ruff check .`) — All checks passed (ruff 0.15.17, CI-pinned; `ruff format --check .` clean) - [x] Type checking passes (`mypy headroom`) — Success: no issues found in 471 source files - [x] New tests added for new functionality — 24 test cases; the rotation/isolation/no-cliff ones fail on `main` - [x] Manual testing performed — live Claude Code end-to-end, below ### Test Output ```text $ python -m pytest tests/ -q 11 failed, 8652 passed, 528 skipped, 5857 warnings in 276.68s (0:04:36) # same 11 fail on unmodified main (env/order-dependent: test_wrap_claude_base_url pid-reuse, # copilot_auth gh-cli fallback, image_compression onnx, content_router deadline, rtk/output-shaper/dedup order flakes) $ python -m pytest tests/test_cache/test_prefix_tracker.py -q 63 passed $ uvx ruff@0.15.17 check . && uvx ruff@0.15.17 format --check . All checks passed! / 1208 files already formatted $ mypy headroom Success: no issues found in 471 source files $ python repro_2085.py 1) fallback session ids: A=3dc639aaf4f48fa1 B=3dc639aaf4f48fa1 -> COLLIDE=True 2) single conversation, legacy : stable prefix on 4/4 later turns, trackers=1 2) interleaved (subagents), legacy : stable prefix on 0/9 later turns, trackers=1 2) interleaved, lineage resolution : stable prefix on 8/8 later turns, trackers=2 ``` ## Real Behavior Proof - Environment: macOS arm64, Python 3.13, `uv sync --extra dev --extra proxy`; real Claude Code CLI pointed at the proxy via `ANTHROPIC_BASE_URL=http://127.0.0.1:8790`, real Anthropic backend. - Exact command / steps: ran Claude Code sessions that launch 2–3 parallel Explore subagents (each reading multi-KB JSON files, several tool-loop turns each), with an observability wrapper printing each request's resolved session id, tracker identity, and turn counter inside the proxy. - Observed result: on `main`, subagent session ids rotate on reminder-bearing turns (trackers permanently stuck at turn 0); when conversations do share an id they share one tracker whose turn counter interleaves all of them. On this branch: ids stable for the life of each conversation; colliding subagents resolve to separate lineages (`bare`, `~1`) with clean per-conversation turn progressions (trace above). Unit-level repro shows forwarded-prefix stability going 0/9 → 8/8 for the interleaved shape. - Not tested: reporter-scale cache-economics (his 4.4x needs his long-session workload against a paid backend); happy to coordinate with @RomanAlexanderW on a before/after — the number to watch is the cache-read ratio in Claude Code transcripts recovering toward ~96%. <details> <summary>repro_2085.py</summary> ```python """Repro for #2085: concurrent conversations sharing a fallback session id (same model + system prompt — e.g. a Claude Code session and its parallel subagents) collapse onto one PrefixCacheTracker and thrash its frozen-prefix state -> byte-unstable forwarded prefixes -> the provider prompt cache is re-written on nearly every call. Uses headroom's real code paths. Run from the repo root: python ../repro_2085.py """ from headroom.cache.prefix_tracker import PrefixFreezeConfig, SessionTrackerStore MODEL = "claude-sonnet-5" # Claude Code system prompt: long, static, identical across the main session # and every parallel subagent of the same type. SYSTEM = ("You are Claude Code, Anthropic's official CLI for Claude. " * 40)[:2000] def convo(name: str, turns: int) -> list[dict]: msgs = [{"role": "system", "content": SYSTEM}] for t in range(turns): msgs.append({"role": "user", "content": f"[{name}] user turn {t}: " + ("x" * 800)}) msgs.append( {"role": "assistant", "content": f"[{name}] tool_result {t}: " + ('{"data": 1}' * 200)} ) return msgs class _Req: # request stub: no x-headroom-session-id header headers: dict = {} # --- Part 1: identity collision (real derivation) ---------------------------- store = SessionTrackerStore(PrefixFreezeConfig()) id_a = store.compute_session_id(_Req(), MODEL, convo("A", 3)) id_b = store.compute_session_id(_Req(), MODEL, convo("B", 5)) print(f"1) fallback session ids: A={id_a} B={id_b} -> COLLIDE={id_a == id_b}") # --- Part 2: interleaved conversations thrash the freeze state --------------- def run(interleave: bool, lineage_resolution: bool) -> tuple[int, int, int]: store = SessionTrackerStore(PrefixFreezeConfig()) stable_turns = 0 later_turns = 0 seq = [] for t in range(1, 6): seq.append(("A", convo("A", t))) if interleave: seq.append(("B", convo("B", t))) for _name, msgs in seq: sid = store.compute_session_id(_Req(), MODEL, msgs) if lineage_resolution: tracker = store.resolve_tracker(sid, "anthropic", messages=msgs) else: tracker = store.get_or_create(sid, "anthropic") if tracker._turn_number > 0: later_turns += 1 if tracker._forwarded_prefix_stable(msgs): stable_turns += 1 tracker.update_from_response( cache_read_tokens=5000 * len(msgs), cache_write_tokens=2000, messages=msgs, ) return stable_turns, later_turns, store.active_sessions for label, interleave, fixed in ( ("single conversation, legacy ", False, False), ("interleaved (subagents), legacy ", True, False), ("interleaved, lineage resolution ", True, True), ): stable, later, sessions = run(interleave, fixed) print(f"2) {label}: stable prefix on {stable}/{later} later turns, trackers={sessions}") ``` </details> ## Review Readiness - [x] I have performed a self-review - [x] This PR is ready for human review ## Checklist - [x] My code follows the project's style guidelines - [x] I have performed a self-review of my code - [x] I have commented my code, particularly in hard-to-understand areas - [ ] I have made corresponding changes to the documentation (CHANGELOG only — no docs describe the tracker store) - [x] My changes generate no new warnings - [x] I have added tests that prove my fix is effective or that my feature works - [x] New and existing unit tests pass locally with my changes - [x] I have updated the CHANGELOG.md if applicable ## Additional Notes - Addresses the session-identity mechanisms of #2085; intentionally does not `Closes` it — the reporter should confirm the cache-read ratio recovers on live traffic first. - Composes with draft #1912 (first-user-turn fallback id). - Known bounded tradeoffs (all strictly milder than the per-turn thrash this fixes): a fork-style branch that resends a parent's full history adopts the parent's lineage, costing the parent one cold restart at its next turn; a request that aborts before the response and is retried with different bytes starts a fresh lineage; history truncation/tail-edit starts a fresh lineage even though the shorter provider prefix may still be warm. - Hot-path cost, measured on a 199-message/2.1MB agentic history: canonical projection 0.21ms + structural snapshot 0.92ms + match loop 0.06ms with 32 candidate lineages (2.27ms absolute worst case) ≈ **1.3ms per request** — same order as the handler's existing request deepcopy (0.80ms) and below one `json.dumps` of the body (2.9ms). Chain memory is structure-only (~180-330KB per lineage; message strings are shared with state the tracker already retains). - Known semantic shift to flag: hashing only the leading system run means conversations distinguished ONLY by mid-list system messages (e.g. clients injecting a per-conversation system context late in the list) now share a fallback id. The tracker is protected by lineage resolution; the residual sharing concentrates in the CCR sticky-tool registry and the monotone beta union — the same pre-existing class as same-system-prompt conversations today. Happy to file the CCR-stickiness scoping as a follow-up. - Out of scope, observed while tracing: `SessionCcrTracker.has_done_ccr` mildly cross-contaminates conversations sharing an id (monotone, no thrash) — can file separately if useful. --------- Co-authored-by: JerrettDavis <mxjerrett@gmail.com>
2026-07-15 23:42:20 +05:00
def test_compute_session_id_distinguishes_leading_system_run(self, store):
"""Different dynamic LEADING system messages should not collide."""
fix(cache): avoid fallback session collisions (#1827) ## Description Cache-mode session tracking currently collapses unrelated conversations when they share a large static first system prompt. The fallback session-id hash ignores later system messages entirely, so dynamic per-conversation context can get cut out of the key and two different sessions reuse the same `PrefixCacheTracker`. This hashes the full ordered system-text payload instead, while leaving explicit `x-headroom-session-id` overrides untouched. Refs #1808. ## Type of Change - [x] Bug fix (non-breaking change that fixes an issue) - [ ] New feature (non-breaking change that adds functionality) - [ ] Breaking change (fix or feature that would cause existing functionality to change) - [ ] Documentation update - [ ] Performance improvement - [ ] Code refactoring (no functional changes) ## Changes Made - Collected all system-text content when building the fallback cache session id. - Stopped truncating fallback session-id input to the first 500 characters of the first system message. - Added a regression that proves two conversations with different later system context no longer collide. - Added a preservation test that appending only non-system turns keeps the same fallback session id. - Applied the pinned Ruff formatter to three pre-existing files on the current base so the repo-wide lint job passes unchanged semantics. ## Testing - [x] Unit tests pass (`uv run pytest tests/test_cache/test_prefix_tracker.py -q`) - [x] Linting passes (`uv run ruff check headroom/cache/prefix_tracker.py tests/test_cache/test_prefix_tracker.py`) - [ ] Type checking passes (`uv run mypy headroom`) - [x] New tests added for new functionality when applicable - [ ] Manual testing performed ### Test Output ```text uv run pytest tests/test_cache/test_prefix_tracker.py -q 40 passed, 1 warning in 0.15s uv run ruff check headroom/cache/prefix_tracker.py tests/test_cache/test_prefix_tracker.py All checks passed! uv run ruff check . All checks passed! uv run ruff format --check . 1046 files already formatted ``` ## Real Behavior Proof - Environment: Windows, project `uv` environment, focused cache-tracker regression. - Exact command / steps: run `tests/test_cache/test_prefix_tracker.py` on `origin/main` with the new collision regression present, then rerun the same file on this branch. - Observed result: base returns the same session id for two conversations that differ only in a later system message and fails `assert id_a != id_b`; head passes the focused file and keeps the fallback session id stable when only non-system turns are appended. - Not tested: live proxy traffic through a real agentic client. ## Review Readiness - [x] I have performed a self-review - [x] This PR is ready for human review ## Checklist - [x] My code follows the project's style guidelines - [x] I have performed a self-review of my code - [x] I have commented my code, particularly in hard-to-understand areas - [x] I have made corresponding changes to the documentation - [x] My changes generate no new warnings - [x] I have added tests that prove my fix is effective or that my feature works - [x] New and existing unit tests pass locally with my changes - [x] I have updated the CHANGELOG.md if applicable ## Additional Notes This is only the session-collision half of #1808. The duplicate-response-header fix stays separate so this PR can reference the issue without claiming the whole bug report is resolved. The extra formatting-only diff comes from the current base failing the pinned full-repo Ruff format check.
2026-07-08 00:26:36 -04:00
class MockRequest:
headers = {}
static_prompt = "framework prompt " * 80
conv_a = [
{"role": "system", "content": [{"type": "text", "text": static_prompt}]},
{"role": "system", "content": [{"type": "text", "text": "context: session A"}]},
{"role": "user", "content": "hello"},
]
conv_b = [
{"role": "system", "content": [{"type": "text", "text": static_prompt}]},
{"role": "system", "content": [{"type": "text", "text": "context: session B"}]},
{"role": "user", "content": "hello"},
]
id_a = store.compute_session_id(MockRequest(), "claude-3", conv_a)
id_b = store.compute_session_id(MockRequest(), "claude-3", conv_b)
assert id_a != id_b
fix(proxy/anthropic): scope session id by top-level system prompt (#2070) ## Description `SessionTrackerStore.compute_session_id` (`headroom/cache/prefix_tracker.py`) computes a fallback session id (when no `x-headroom-session-id` header is present) from `model` + system-prompt text. But it harvests system text **only** from `messages` entries with `role == "system"`: ```python for msg in messages: if msg.get("role") == "system": ... # collect system text system_content = json.dumps(system_parts, ...) key = f"{model}:{system_content}" ``` Anthropic's `/v1/messages` carries the system prompt as a **top-level** `body["system"]` field — it never sends `role:"system"` entries inside `messages`. And `x-headroom-session-id` is a Headroom-internal header no client sends. So for every genuine Anthropic request `system_parts` is empty and the id collapses to `md5(f"{model}:[]")` — **every conversation on the same model shares one session id**, and therefore one `PrefixCacheTracker` and all session-sticky state. The colliding state cross-contaminates across conversations (`anthropic.py:1052`): - sticky `headroom_retrieve` / memory tools keyed purely on `session_id` (no content guard) get injected into another conversation's tool list — busting its tools cache and adding tools its client never requested; - sticky `anthropic-beta` header tokens leak across conversations; - `frozen_message_count` and the per-session compression cache cross-contaminate. (The sibling `StreamingMixin._get_session_key` already reads `body.get("system")` and its docstring claims to mirror `compute_session_id` — which it did not.) Closes: no issue filed — found while auditing the session/prefix tracker. ## Fix Add an optional `system` parameter to `compute_session_id` and fold its text (a plain string or a list of `{"type":"text"}` blocks) into the hash. The Anthropic handler passes `body.get("system")`. OpenAI callers don't pass it (defaults to `None`), so their behavior is unchanged. ## Type of Change - [x] Bug fix (non-breaking change that fixes an issue) ## Changes Made - `headroom/cache/prefix_tracker.py`: `compute_session_id` accepts an optional `system` and folds it into the id. - `headroom/proxy/handlers/anthropic.py`: pass `system=body.get("system")` when computing the session id. - `tests/test_cache/test_prefix_tracker.py`: add `test_compute_session_id_distinguishes_top_level_system` (distinct systems → distinct ids; list-form == string-form; `system=None` unchanged). ## Testing - [x] New regression test added (`tests/test_cache/test_prefix_tracker.py`) - [x] Linting/formatting clean — run with the CI-pinned `ruff==0.15.17` - [ ] Full `pytest` deferred to CI (local-OOM reason below). ```text $ uvx ruff@0.15.17 check headroom/cache/prefix_tracker.py headroom/proxy/handlers/anthropic.py tests/test_cache/test_prefix_tracker.py All checks passed! ``` ## Real Behavior Proof - Environment: Windows 11, Python 3.10, headroom from this branch. Importing `headroom` pulls in the torch/transformers stack and a full `pytest` gets OOM-killed on this box, so I verified the hash logic with a dependency-free script and left the full pytest to CI. - Exact command / steps: computed ids for two conversations with the same model and messages but different top-level `system` prompts, through the old (never-folds-system) and new logic. - Observed result: the old logic collapses both to one id (the leak); the new logic separates them, folds list-form system the same as string-form, and leaves the `system=None` (OpenAI) path unchanged: ```text OLD: A=97d8857ba27010bb B=97d8857ba27010bb same=True NEW: A=1e838c0f6e3980a6 B=18ec49bfa8240852 same=False SESSION-ID SYSTEM FIX VERIFIED (old collapses Anthropic convos; new separates them) ``` - Not tested: a full two-conversation proxy run asserting no sticky-tool leakage (needs the heavy stack). The fix is confined to `compute_session_id` + the one handler call site, and the new test drives the method directly. Full local `pytest` deferred to CI (OOM, per above). ## Review Readiness - [x] I have performed a self-review - [x] This PR is ready for human review ## Checklist - [x] My code follows the project's style guidelines - [x] I have performed a self-review of my code - [x] I have commented my code, particularly in hard-to-understand areas - [ ] I have made corresponding changes to the documentation - [x] My changes generate no new warnings - [x] I have added tests that prove my fix is effective or that my feature works - [ ] New and existing unit tests pass locally with my changes — ran lint + a standalone logic check; full pytest deferred to CI (local OOM, disclosed above) - [x] I have updated the CHANGELOG.md if applicable ## Additional Notes - Backward-compatible: the new `system` parameter defaults to `None`, so the OpenAI call sites (`openai.py`) need no change and their session ids are identical. - @JerrettDavis tagging you — this one lets one Anthropic conversation's sticky tools/headers leak into another on the same model, so it seemed worth surfacing. Thanks!
2026-07-13 05:10:58 +05:30
def test_compute_session_id_distinguishes_top_level_system(self, store):
"""Anthropic carries the system prompt as a top-level field (not a
role:'system' message). The handler folds it in as a synthetic system
message so two conversations with the same model and turns but different
system prompts get distinct ids otherwise they share one tracker and
their sticky state cross-contaminates. This exercises that mechanism."""
class MockRequest:
headers = {}
turns = [{"role": "user", "content": "hello"}]
def with_system(system):
# Mirror what handlers/anthropic.py does for the top-level system.
return [{"role": "system", "content": system}, *turns]
id_a = store.compute_session_id(
MockRequest(), "claude-3", with_system("You are a Python expert.")
)
id_b = store.compute_session_id(
MockRequest(), "claude-3", with_system("You are a Rust expert.")
)
assert id_a != id_b
# A list-of-text-blocks system folds the same text as the string form.
id_a_list = store.compute_session_id(
MockRequest(),
"claude-3",
with_system([{"type": "text", "text": "You are a Python expert."}]),
)
assert id_a_list == id_a
fix(cache): avoid fallback session collisions (#1827) ## Description Cache-mode session tracking currently collapses unrelated conversations when they share a large static first system prompt. The fallback session-id hash ignores later system messages entirely, so dynamic per-conversation context can get cut out of the key and two different sessions reuse the same `PrefixCacheTracker`. This hashes the full ordered system-text payload instead, while leaving explicit `x-headroom-session-id` overrides untouched. Refs #1808. ## Type of Change - [x] Bug fix (non-breaking change that fixes an issue) - [ ] New feature (non-breaking change that adds functionality) - [ ] Breaking change (fix or feature that would cause existing functionality to change) - [ ] Documentation update - [ ] Performance improvement - [ ] Code refactoring (no functional changes) ## Changes Made - Collected all system-text content when building the fallback cache session id. - Stopped truncating fallback session-id input to the first 500 characters of the first system message. - Added a regression that proves two conversations with different later system context no longer collide. - Added a preservation test that appending only non-system turns keeps the same fallback session id. - Applied the pinned Ruff formatter to three pre-existing files on the current base so the repo-wide lint job passes unchanged semantics. ## Testing - [x] Unit tests pass (`uv run pytest tests/test_cache/test_prefix_tracker.py -q`) - [x] Linting passes (`uv run ruff check headroom/cache/prefix_tracker.py tests/test_cache/test_prefix_tracker.py`) - [ ] Type checking passes (`uv run mypy headroom`) - [x] New tests added for new functionality when applicable - [ ] Manual testing performed ### Test Output ```text uv run pytest tests/test_cache/test_prefix_tracker.py -q 40 passed, 1 warning in 0.15s uv run ruff check headroom/cache/prefix_tracker.py tests/test_cache/test_prefix_tracker.py All checks passed! uv run ruff check . All checks passed! uv run ruff format --check . 1046 files already formatted ``` ## Real Behavior Proof - Environment: Windows, project `uv` environment, focused cache-tracker regression. - Exact command / steps: run `tests/test_cache/test_prefix_tracker.py` on `origin/main` with the new collision regression present, then rerun the same file on this branch. - Observed result: base returns the same session id for two conversations that differ only in a later system message and fails `assert id_a != id_b`; head passes the focused file and keeps the fallback session id stable when only non-system turns are appended. - Not tested: live proxy traffic through a real agentic client. ## Review Readiness - [x] I have performed a self-review - [x] This PR is ready for human review ## Checklist - [x] My code follows the project's style guidelines - [x] I have performed a self-review of my code - [x] I have commented my code, particularly in hard-to-understand areas - [x] I have made corresponding changes to the documentation - [x] My changes generate no new warnings - [x] I have added tests that prove my fix is effective or that my feature works - [x] New and existing unit tests pass locally with my changes - [x] I have updated the CHANGELOG.md if applicable ## Additional Notes This is only the session-collision half of #1808. The duplicate-response-header fix stays separate so this PR can reference the issue without claiming the whole bug report is resolved. The extra formatting-only diff comes from the current base failing the pinned full-repo Ruff format check.
2026-07-08 00:26:36 -04:00
def test_compute_session_id_is_stable_when_only_non_system_turns_change(self, store):
"""Appending non-system turns should keep the same fallback session id."""
class MockRequest:
headers = {}
base_messages = [
{"role": "system", "content": [{"type": "text", "text": "framework prompt"}]},
{"role": "system", "content": [{"type": "text", "text": "context: session A"}]},
{"role": "user", "content": "hello"},
]
extended_messages = base_messages + [{"role": "assistant", "content": "hi there"}]
id1 = store.compute_session_id(MockRequest(), "claude-3", base_messages)
id2 = store.compute_session_id(MockRequest(), "claude-3", extended_messages)
assert id1 == id2
def test_compute_session_id_no_system(self, store):
"""Should work without system messages."""
class MockRequest:
headers = {}
messages = [{"role": "user", "content": "Hi"}]
session_id = store.compute_session_id(MockRequest(), "claude-3", messages)
assert isinstance(session_id, str)
assert len(session_id) == 16
fix(cache): stable session identity and per-conversation prefix trackers under agentic clients (#2193) ## Description Running headroom as the proxy for Claude Code destroys Anthropic prompt-cache reuse (#2085: ~4.4x cache-creation inflation, 2.5–3x net cost). Tracing live Claude Code traffic through the proxy shows **two independent session-identity defects**, both of which orphan or thrash the frozen-prefix state; this PR fixes both. ### Defect 1: `<system-reminder>` turns rotate the fallback session id mid-conversation Claude Code interleaves reminder turns into the history as actual `role:"system"` messages (hook output, skills lists, file-truncation notices). `compute_session_id` hashed **every** system message, so the id rotated each time a reminder landed. Live trace (subagent reading two 80KB files; sid changes exactly when the truncation reminder appears, and the tracker restarts at turn 0): ``` REQ#2 sid=68d4ee666990 nmsg=3 [0]SYSTEM<<top-level system>> [1]user [2]SYSTEM<<skills reminder>> REQ#3 sid=6944948c9fb2 nmsg=6 ... [5]SYSTEM<<Truncated: PARTIAL view ...>> <- id rotated ``` Everything keyed on the session id is orphaned at that moment: the prefix tracker (freeze never survives past a reminder-bearing turn), beta-header stickiness, the CCR and memory-tool registries, and the compression cache. **Fix:** hash only the **leading run** of system messages (everything before the first non-system turn) — the top-level system prompt on the Anthropic path (folded in as the synthetic first message), the conventional leading system message(s) on the OpenAI path. Stable for the life of a conversation; mid-history system turns are content, not identity. ### Defect 2: conversations sharing a (now stable) id thrash one tracker With ids stable, the fallback tuple `model + system prompt` is identical across every same-type parallel subagent (and any sessions reusing one system prompt) — all of them collapse onto one `PrefixCacheTracker`, and their interleaved histories cross-contaminate the freeze state: the forwarded prefix is byte-unstable on nearly every turn and the provider cache is re-written instead of read. Reproduced against the real code paths (script below): ``` 1) fallback session ids: A=3dc639aaf4f48fa1 B=3dc639aaf4f48fa1 -> COLLIDE=True 2) single conversation, legacy : stable prefix on 4/4 later turns, trackers=1 2) interleaved (subagents), legacy : stable prefix on 0/9 later turns, trackers=1 2) interleaved, lineage resolution : stable prefix on 8/8 later turns, trackers=2 ``` **Fix:** `SessionTrackerStore.resolve_tracker` — within a session id, reuse the tracker whose previous request messages are a prefix of the incoming history (client histories are append-only, so a conversation's next request always extends its previous one); a diverging or rewritten history (client-side compaction) starts a fresh lineage. Matching uses the repo's existing canonical cross-turn equivalence (`_canonicalize_for_prefix_compare`, the same one the cache-stable delta path uses) on the **original client bytes**, so moved cache breakpoints, string<->block sugar, transport annotations, or a tail-mutating `pre_compress` hook never read as a rewrite. Byte-identical histories (templated fan-outs before they diverge) intentionally share a tracker — their provider cache line is identical too. ### Both fixes together, on live Claude Code traffic (sonnet, 2 parallel Explore agents) ``` main conversation: sid=5b7e245a... one tracker, turns 0->4, id stable across reminders agents (collide): sid=2bdffc9e... -> lineage bare (alpha) turns 0->1->2 -> lineage "~1" (beta) turns 0->1->2 ``` Before: the agents' ids rotated per reminder (every tracker stuck at turn 0), and whenever they did share an id they thrashed one tracker (`0/9` stable prefixes in the repro). ### Why not key the session id on conversation content? Draft #1912 folds the first user turn into the fallback id; this change composes with it, but identity-level keying alone can't close #2085: identical first turns (templated fan-outs) still collide, and everything keyed on the session id rotates with it when the client rewrites history. The "session" (client/workspace grouping) and the "conversation" (positional cache lineage) are different identities; only the tracker holds positional per-turn state that thrashes under collision — beta stickiness is a monotone union and the compression cache is content-addressed — so lineage resolution lives one level below the session id and leaves the id semantics (and every other consumer) untouched. ## Changes Made - `headroom/cache/prefix_tracker.py`: - `compute_session_id`: harvest only the leading system run (defect 1). - `SessionTrackerStore.resolve_tracker`: conversation-lineage resolution (defect 2). First lineage lives under the bare session id — single-conversation sessions behave byte-identically to before; degrades to `get_or_create` when messages are absent or prefix freeze is disabled. - Lineages are capped per session id (`PrefixFreezeConfig.max_lineages_per_session`, default 32). **Over-cap conversations share one overflow tracker instead of evicting an established lineage** — any eviction policy degrades every conversation once the working set exceeds the cap (under round-robin the victim is always the conversation about to arrive), while overflow sharing degrades only the over-cap tail, to exactly the pre-lineage shared behavior; `0` disables lineage splitting. Chains are stored as structural snapshots that normalize `NaN` (`json.loads` accepts bare NaN, and `NaN != NaN` would read a byte-identical resend as a rewrite). Synthetic lineage keys use a `\x00` separator, which cannot appear in an HTTP header value, so they can never collide with a client-supplied `x-headroom-session-id`. - `headroom/proxy/handlers/anthropic.py`, `openai.py`: the session id and the lineage both derive from the **same original client bytes** (a turn-dependent hook rewrite can no longer rotate one without the other); anthropic folds in its synthetic system message so explicit-header clients with different system prompts stay separate. Plus a docstring correction in `streaming.py` that falsely claimed its coarse mid-turn key "mirrors" `compute_session_id`. - `tests/test_cache/test_prefix_tracker.py`: 24 new test cases — reminder-rotation regression; interleaved isolation + per-conversation turn state; identical-first-turn share-then-split; cache_control movement (3 cases); representation churn (string<->block sugar / streaming `index` / Bedrock cachePoint); rewritten history → fresh lineage (compacted / middle-edited / truncated); legacy no-messages / freeze-disabled / empty-canonical fallbacks; NaN-in-tool-payload stability; overflow sharing, established-lineages-survive-cap, and a cap+1 round-robin no-cliff guard; TTL cleanup; session-id-not-rotated-by-lineage guard. One existing test renamed (`uses_all_system_messages` → `distinguishes_leading_system_run`) to match the new contract. - Three SimpleNamespace stub stores in existing tests gained a `resolve_tracker` field (handlers call it unconditionally — a silent `hasattr` fallback would degrade to the pre-fix behavior with no signal). One of them is the cold-start fast-pass suite (#2073), which landed while this branch was in review. - `CHANGELOG.md` entry. ## Type of Change - [x] Bug fix (non-breaking change that fixes an issue) ## Testing - [x] Unit tests pass (`pytest`) — 11 failed, 8652 passed, 528 skipped in 4:37 (the 11 are pre-existing on unmodified `main` — verified by rerunning the same node ids on a clean checkout: gh-CLI/onnx/PID-reuse/deadline flakes and order-dependent cases, none touching session/cache/proxy paths) - [x] Linting passes (`ruff check .`) — All checks passed (ruff 0.15.17, CI-pinned; `ruff format --check .` clean) - [x] Type checking passes (`mypy headroom`) — Success: no issues found in 471 source files - [x] New tests added for new functionality — 24 test cases; the rotation/isolation/no-cliff ones fail on `main` - [x] Manual testing performed — live Claude Code end-to-end, below ### Test Output ```text $ python -m pytest tests/ -q 11 failed, 8652 passed, 528 skipped, 5857 warnings in 276.68s (0:04:36) # same 11 fail on unmodified main (env/order-dependent: test_wrap_claude_base_url pid-reuse, # copilot_auth gh-cli fallback, image_compression onnx, content_router deadline, rtk/output-shaper/dedup order flakes) $ python -m pytest tests/test_cache/test_prefix_tracker.py -q 63 passed $ uvx ruff@0.15.17 check . && uvx ruff@0.15.17 format --check . All checks passed! / 1208 files already formatted $ mypy headroom Success: no issues found in 471 source files $ python repro_2085.py 1) fallback session ids: A=3dc639aaf4f48fa1 B=3dc639aaf4f48fa1 -> COLLIDE=True 2) single conversation, legacy : stable prefix on 4/4 later turns, trackers=1 2) interleaved (subagents), legacy : stable prefix on 0/9 later turns, trackers=1 2) interleaved, lineage resolution : stable prefix on 8/8 later turns, trackers=2 ``` ## Real Behavior Proof - Environment: macOS arm64, Python 3.13, `uv sync --extra dev --extra proxy`; real Claude Code CLI pointed at the proxy via `ANTHROPIC_BASE_URL=http://127.0.0.1:8790`, real Anthropic backend. - Exact command / steps: ran Claude Code sessions that launch 2–3 parallel Explore subagents (each reading multi-KB JSON files, several tool-loop turns each), with an observability wrapper printing each request's resolved session id, tracker identity, and turn counter inside the proxy. - Observed result: on `main`, subagent session ids rotate on reminder-bearing turns (trackers permanently stuck at turn 0); when conversations do share an id they share one tracker whose turn counter interleaves all of them. On this branch: ids stable for the life of each conversation; colliding subagents resolve to separate lineages (`bare`, `~1`) with clean per-conversation turn progressions (trace above). Unit-level repro shows forwarded-prefix stability going 0/9 → 8/8 for the interleaved shape. - Not tested: reporter-scale cache-economics (his 4.4x needs his long-session workload against a paid backend); happy to coordinate with @RomanAlexanderW on a before/after — the number to watch is the cache-read ratio in Claude Code transcripts recovering toward ~96%. <details> <summary>repro_2085.py</summary> ```python """Repro for #2085: concurrent conversations sharing a fallback session id (same model + system prompt — e.g. a Claude Code session and its parallel subagents) collapse onto one PrefixCacheTracker and thrash its frozen-prefix state -> byte-unstable forwarded prefixes -> the provider prompt cache is re-written on nearly every call. Uses headroom's real code paths. Run from the repo root: python ../repro_2085.py """ from headroom.cache.prefix_tracker import PrefixFreezeConfig, SessionTrackerStore MODEL = "claude-sonnet-5" # Claude Code system prompt: long, static, identical across the main session # and every parallel subagent of the same type. SYSTEM = ("You are Claude Code, Anthropic's official CLI for Claude. " * 40)[:2000] def convo(name: str, turns: int) -> list[dict]: msgs = [{"role": "system", "content": SYSTEM}] for t in range(turns): msgs.append({"role": "user", "content": f"[{name}] user turn {t}: " + ("x" * 800)}) msgs.append( {"role": "assistant", "content": f"[{name}] tool_result {t}: " + ('{"data": 1}' * 200)} ) return msgs class _Req: # request stub: no x-headroom-session-id header headers: dict = {} # --- Part 1: identity collision (real derivation) ---------------------------- store = SessionTrackerStore(PrefixFreezeConfig()) id_a = store.compute_session_id(_Req(), MODEL, convo("A", 3)) id_b = store.compute_session_id(_Req(), MODEL, convo("B", 5)) print(f"1) fallback session ids: A={id_a} B={id_b} -> COLLIDE={id_a == id_b}") # --- Part 2: interleaved conversations thrash the freeze state --------------- def run(interleave: bool, lineage_resolution: bool) -> tuple[int, int, int]: store = SessionTrackerStore(PrefixFreezeConfig()) stable_turns = 0 later_turns = 0 seq = [] for t in range(1, 6): seq.append(("A", convo("A", t))) if interleave: seq.append(("B", convo("B", t))) for _name, msgs in seq: sid = store.compute_session_id(_Req(), MODEL, msgs) if lineage_resolution: tracker = store.resolve_tracker(sid, "anthropic", messages=msgs) else: tracker = store.get_or_create(sid, "anthropic") if tracker._turn_number > 0: later_turns += 1 if tracker._forwarded_prefix_stable(msgs): stable_turns += 1 tracker.update_from_response( cache_read_tokens=5000 * len(msgs), cache_write_tokens=2000, messages=msgs, ) return stable_turns, later_turns, store.active_sessions for label, interleave, fixed in ( ("single conversation, legacy ", False, False), ("interleaved (subagents), legacy ", True, False), ("interleaved, lineage resolution ", True, True), ): stable, later, sessions = run(interleave, fixed) print(f"2) {label}: stable prefix on {stable}/{later} later turns, trackers={sessions}") ``` </details> ## Review Readiness - [x] I have performed a self-review - [x] This PR is ready for human review ## Checklist - [x] My code follows the project's style guidelines - [x] I have performed a self-review of my code - [x] I have commented my code, particularly in hard-to-understand areas - [ ] I have made corresponding changes to the documentation (CHANGELOG only — no docs describe the tracker store) - [x] My changes generate no new warnings - [x] I have added tests that prove my fix is effective or that my feature works - [x] New and existing unit tests pass locally with my changes - [x] I have updated the CHANGELOG.md if applicable ## Additional Notes - Addresses the session-identity mechanisms of #2085; intentionally does not `Closes` it — the reporter should confirm the cache-read ratio recovers on live traffic first. - Composes with draft #1912 (first-user-turn fallback id). - Known bounded tradeoffs (all strictly milder than the per-turn thrash this fixes): a fork-style branch that resends a parent's full history adopts the parent's lineage, costing the parent one cold restart at its next turn; a request that aborts before the response and is retried with different bytes starts a fresh lineage; history truncation/tail-edit starts a fresh lineage even though the shorter provider prefix may still be warm. - Hot-path cost, measured on a 199-message/2.1MB agentic history: canonical projection 0.21ms + structural snapshot 0.92ms + match loop 0.06ms with 32 candidate lineages (2.27ms absolute worst case) ≈ **1.3ms per request** — same order as the handler's existing request deepcopy (0.80ms) and below one `json.dumps` of the body (2.9ms). Chain memory is structure-only (~180-330KB per lineage; message strings are shared with state the tracker already retains). - Known semantic shift to flag: hashing only the leading system run means conversations distinguished ONLY by mid-list system messages (e.g. clients injecting a per-conversation system context late in the list) now share a fallback id. The tracker is protected by lineage resolution; the residual sharing concentrates in the CCR sticky-tool registry and the monotone beta union — the same pre-existing class as same-system-prompt conversations today. Happy to file the CCR-stickiness scoping as a follow-up. - Out of scope, observed while tracing: `SessionCcrTracker.has_done_ccr` mildly cross-contaminates conversations sharing an id (monotone, no thrash) — can file separately if useful. --------- Co-authored-by: JerrettDavis <mxjerrett@gmail.com>
2026-07-15 23:42:20 +05:00
def test_mid_conversation_system_turns_do_not_rotate_session_id(self, store):
"""Claude Code sends <system-reminder> turns as role:"system" MESSAGES
interleaved into the history (hook outputs, skills lists, truncation
notices). Hashing those into the fallback id rotates the session id
mid-conversation orphaning the prefix tracker and every other
session-sticky subsystem (beta headers, CCR/memory registries, the
compression cache) each time a reminder lands. Only the LEADING run of
system messages is session identity; later system turns are content.
"""
class MockRequest:
headers = {}
leading = {"role": "system", "content": "You are an agent. " * 40}
turn1 = [leading, {"role": "user", "content": "read file A"}]
turn2 = turn1 + [
{"role": "assistant", "content": "read it"},
{"role": "user", "content": "tool result ..."},
{
"role": "system",
"content": "<system-reminder>Truncated: PARTIAL view</system-reminder>",
},
{"role": "user", "content": "continue"},
]
id1 = store.compute_session_id(MockRequest(), "claude-sonnet-5", turn1)
id2 = store.compute_session_id(MockRequest(), "claude-sonnet-5", turn2)
assert id1 == id2
class TestConversationLineageResolution:
"""resolve_tracker: one PrefixCacheTracker per conversation lineage (#2085).
Concurrent conversations that share a fallback session id (same model +
same system prompt e.g. a Claude Code session and its parallel subagents)
must not thrash one tracker's frozen-prefix state: interleaved turns would
each see the *other* conversation's prefix, freeze never stabilizes, and
the provider prompt cache is re-written on every call.
resolve_tracker keys trackers by message lineage instead: an incoming
history that extends a known lineage reuses its tracker; a diverging or
rewritten history gets a fresh one. The session id itself is never changed,
so session-sticky state keyed on it elsewhere (beta headers, CCR/memory
registries, the compression cache) is unaffected.
"""
@pytest.fixture
def store(self):
return SessionTrackerStore()
@staticmethod
def _history(name: str, turn: int) -> list[dict]:
"""Client-shaped request messages for `turn` (1-based): u0,a0,...,u_{turn-1}."""
messages: list[dict] = []
for t in range(turn):
messages.append({"role": "user", "content": f"[{name}] user {t} " + "x" * 200})
if t < turn - 1:
messages.append(
{"role": "assistant", "content": f"[{name}] assistant {t} " + "y" * 200}
)
return messages
@staticmethod
def _block_history(turn: int, cc_on: int | None) -> list[dict]:
"""Block-content history; cache_control breakpoint on message `cc_on` (or none)."""
messages: list[dict] = []
for t in range(turn):
messages.append(
{"role": "user", "content": [{"type": "text", "text": f"user {t} " + "x" * 200}]}
)
if t < turn - 1:
messages.append(
{
"role": "assistant",
"content": [{"type": "text", "text": f"assistant {t} " + "y" * 200}],
}
)
if cc_on is not None:
msg = messages[cc_on]
blocks = [dict(b) for b in msg["content"]]
blocks[-1] = {**blocks[-1], "cache_control": {"type": "ephemeral"}}
messages[cc_on] = {**msg, "content": blocks}
return messages
def test_interleaved_conversations_resolve_to_independent_trackers(self, store):
"""The #2085 production shape: two conversations, one session id,
alternating requests. Each must keep its own tracker and per-turn state
(on a shared tracker, _turn_number would count both conversations)."""
sid = "shared-fallback-id"
trackers: dict[str, PrefixCacheTracker] = {}
for turn in range(1, 5):
for name in ("A", "B"):
history = self._history(name, turn)
tracker = store.resolve_tracker(sid, "anthropic", messages=history)
trackers.setdefault(name, tracker)
assert tracker is trackers[name], f"[{name}] turn {turn} switched trackers"
tracker.update_from_response(
cache_read_tokens=1000 * turn,
cache_write_tokens=500,
messages=history,
)
assert trackers["A"] is not trackers["B"]
assert trackers["A"]._turn_number == 4
assert trackers["B"]._turn_number == 4
def test_identical_first_turns_share_until_divergence_then_split(self, store):
"""Templated fan-outs send byte-identical first turns. While histories
are identical, sharing a tracker is harmless (the provider cache line
is identical too); they must split as soon as the histories diverge."""
sid = "shared"
first = [{"role": "user", "content": "verify the fix " + "p" * 300}]
t_a1 = store.resolve_tracker(sid, "anthropic", messages=first)
t_b1 = store.resolve_tracker(sid, "anthropic", messages=first)
assert t_b1 is t_a1
a2 = first + [
{"role": "assistant", "content": "answer A"},
{"role": "user", "content": "next A"},
]
b2 = first + [
{"role": "assistant", "content": "answer B"},
{"role": "user", "content": "next B"},
]
t_a2 = store.resolve_tracker(sid, "anthropic", messages=a2)
t_b2 = store.resolve_tracker(sid, "anthropic", messages=b2)
assert t_a2 is not t_b2
a3 = a2 + [
{"role": "assistant", "content": "answer A2"},
{"role": "user", "content": "next A2"},
]
assert store.resolve_tracker(sid, "anthropic", messages=a3) is t_a2
@pytest.mark.parametrize(
"cc_turn2",
[0, -1, None],
ids=["breakpoint-stays", "breakpoint-moved-to-last", "breakpoint-removed"],
)
def test_cache_control_movement_does_not_split_lineage(self, store, cc_turn2):
"""Clients move the cache_control breakpoint every turn; that must not
read as a rewritten history."""
sid = "shared"
t1 = store.resolve_tracker(sid, "anthropic", messages=self._block_history(1, cc_on=0))
t2 = store.resolve_tracker(
sid, "anthropic", messages=self._block_history(2, cc_on=cc_turn2)
)
assert t2 is t1
@pytest.mark.parametrize(
"requote",
[
lambda m: {**m, "content": [{"type": "text", "text": m["content"]}]},
lambda m: {
**m,
"content": [{"type": "text", "text": m["content"], "index": 0}],
},
lambda m: {
**m,
"content": [
{"type": "text", "text": m["content"]},
{"cachePoint": {"type": "default"}},
],
},
],
ids=["string-to-block-sugar", "streaming-index-annotation", "bedrock-cachepoint-block"],
)
def test_representation_churn_does_not_split_lineage(self, store, requote):
"""Clients re-encode history turn-to-turn without changing content
(litellm flips string<->block sugar, streaming assembly adds `index`,
Bedrock moves its cachePoint block). Lineage matching must use the
same canonical equivalence as the cache-stable delta path."""
sid = "shared"
first = {"role": "user", "content": "hello " + "x" * 200}
t1 = store.resolve_tracker(sid, "anthropic", messages=[first])
grown = [
requote(first),
{"role": "assistant", "content": "hi"},
{"role": "user", "content": "next"},
]
assert store.resolve_tracker(sid, "anthropic", messages=grown) is t1
@pytest.mark.parametrize(
"rewrite",
[
lambda h: [{"role": "user", "content": "[summary of the conversation so far]"}],
lambda h: [h[0], {"role": "assistant", "content": "EDITED"}, *h[2:]],
lambda h: h[:-2],
],
ids=["compacted", "middle-edited", "truncated"],
)
def test_rewritten_history_gets_fresh_tracker(self, store, rewrite):
"""A rewritten history (client-side /compact, edits, truncation) means
the provider cache line is gone anyway: start a fresh lineage, keep the
old tracker until TTL, and never touch the session id."""
sid = "shared"
history = self._history("A", 3)
tracker = store.resolve_tracker(sid, "anthropic", messages=history)
fresh = store.resolve_tracker(sid, "anthropic", messages=rewrite(history))
assert fresh is not tracker
assert store.active_sessions == 2
@pytest.mark.parametrize("messages", [None, []], ids=["none", "empty"])
def test_resolve_without_messages_matches_legacy_get_or_create(self, store, messages):
tracker = store.resolve_tracker("sid", "anthropic", messages=messages)
assert tracker is store.get_or_create("sid", "anthropic")
def test_resolve_with_freeze_disabled_matches_legacy_get_or_create(self):
"""With prefix freeze off there is no frozen state to protect — skip
lineage bookkeeping entirely."""
store = SessionTrackerStore(PrefixFreezeConfig(enabled=False))
t_a = store.resolve_tracker("sid", "anthropic", messages=self._history("A", 1))
t_b = store.resolve_tracker("sid", "anthropic", messages=self._history("B", 1))
assert t_a is t_b
assert t_a is store.get_or_create("sid", "anthropic")
def test_over_cap_conversations_share_one_overflow_tracker(self):
"""A fan-out storm on one session id must not grow trackers unbounded:
past the cap, new conversations share one overflow tracker instead of
evicting an established lineage."""
store = SessionTrackerStore(PrefixFreezeConfig(max_lineages_per_session=4))
sid = "storm"
overflow = set()
for i in range(9):
tracker = store.resolve_tracker(
sid, "anthropic", messages=[{"role": "user", "content": f"task {i} " + "z" * 100}]
)
if i >= 4:
overflow.add(id(tracker))
assert store.active_sessions == 5 # 4 lineages + 1 shared overflow
assert len(overflow) == 1
def test_established_lineages_survive_cap_overflow(self):
"""Filling the family must never evict an established conversation —
under round-robin any eviction victim is the next requester, which
would degrade EVERY conversation to a cold tracker per turn."""
store = SessionTrackerStore(PrefixFreezeConfig(max_lineages_per_session=2))
sid = "shared"
parent_history = self._history("parent", 4)
parent = store.resolve_tracker(sid, "anthropic", messages=parent_history)
shorty = store.resolve_tracker(sid, "anthropic", messages=self._history("shorty", 1))
# Third divergent conversation lands on the overflow tracker; both
# established lineages keep their trackers.
newcomer = store.resolve_tracker(sid, "anthropic", messages=self._history("new", 1))
assert newcomer is not parent
assert newcomer is not shorty
grown = parent_history + [
{"role": "assistant", "content": "[parent] assistant 3 " + "y" * 200},
{"role": "user", "content": "[parent] user 4 " + "x" * 200},
]
assert store.resolve_tracker(sid, "anthropic", messages=grown) is parent
assert (
store.resolve_tracker(sid, "anthropic", messages=self._history("shorty", 2)) is shorty
)
def test_no_cliff_at_cap_plus_one_round_robin(self):
"""cap+1 conversations round-robining turns: the in-cap conversations
keep their trackers on every round (no eviction churn); only the
over-cap tail shares the overflow tracker."""
store = SessionTrackerStore(PrefixFreezeConfig(max_lineages_per_session=3))
sid = "shared"
trackers: dict[str, PrefixCacheTracker] = {}
for turn in range(1, 4):
for name in ("A", "B", "C", "D"):
tracker = store.resolve_tracker(
sid, "anthropic", messages=self._history(name, turn)
)
if turn == 1:
trackers[name] = tracker
elif name != "D":
assert tracker is trackers[name], f"[{name}] turn {turn} lost its tracker"
else:
assert tracker is trackers["D"] # stable overflow tracker
def test_empty_canonical_history_falls_back_to_legacy(self):
"""A history whose every message projects away (pure directive
content) carries no lineage signal behave like get_or_create."""
store = SessionTrackerStore()
tracker = store.resolve_tracker("sid", "anthropic", messages=[{}])
assert tracker is store.get_or_create("sid", "anthropic")
def test_nan_in_tool_payload_does_not_split_lineage(self):
"""json.loads accepts bare NaN, and NaN != NaN — a resent history
containing one must still read as the same conversation."""
store = SessionTrackerStore()
sid = "shared"
turn1 = [
{"role": "user", "content": "run the tool " + "x" * 200},
{
"role": "assistant",
"content": [
{"type": "tool_use", "id": "t1", "name": "score", "input": {"v": float("nan")}}
],
},
{
"role": "user",
"content": [{"type": "tool_result", "tool_use_id": "t1", "content": "ok"}],
},
]
t1 = store.resolve_tracker(sid, "anthropic", messages=turn1)
turn2 = turn1 + [
{"role": "assistant", "content": "done"},
{"role": "user", "content": "next"},
]
assert store.resolve_tracker(sid, "anthropic", messages=turn2) is t1
def test_expired_lineages_are_cleaned_up(self):
config = PrefixFreezeConfig(session_ttl_seconds=1)
store = SessionTrackerStore(default_config=config)
for name in ("A", "B"):
tracker = store.resolve_tracker("sid", "anthropic", messages=self._history(name, 1))
tracker._last_activity = time.time() - 2
store._last_cleanup = 0
store._maybe_cleanup()
assert store.active_sessions == 0
# The lineage index must not resurrect evicted trackers: extending an
# evicted conversation starts cold.
fresh = store.resolve_tracker("sid", "anthropic", messages=self._history("A", 2))
assert fresh._turn_number == 0
def test_shared_session_id_is_not_rotated(self, store):
"""Composition guard: lineage resolution must not leak into session-id
derivation beta stickiness and the compression cache key on it."""
class MockRequest:
headers = {}
msgs_a = [{"role": "system", "content": "S"}, *self._history("A", 1)]
msgs_b = [{"role": "system", "content": "S"}, *self._history("B", 1)]
id_a = store.compute_session_id(MockRequest(), "claude-3", msgs_a)
id_b = store.compute_session_id(MockRequest(), "claude-3", msgs_b)
assert id_a == id_b
class TestMultiTurnScenario:
"""Integration-style tests simulating multi-turn conversations."""
def test_five_turn_conversation(self):
"""Simulate a 5-turn conversation with growing prefix."""
tracker = PrefixCacheTracker("anthropic")
# Turn 1: System + User (cold start, no cache)
messages_t1 = [
{"role": "system", "content": "System prompt" * 200},
{"role": "user", "content": "Question 1"},
]
token_counts_t1 = [2000, 50]
assert tracker.get_frozen_message_count() == 0 # No freeze on turn 1
tracker.update_from_response(
cache_read_tokens=0,
cache_write_tokens=2050,
messages=messages_t1,
message_token_counts=token_counts_t1,
)
# Turn 2: Previous messages cached, new user message added
messages_t2 = messages_t1 + [
{"role": "assistant", "content": "Answer 1"},
{"role": "user", "content": "Question 2"},
]
token_counts_t2 = [2000, 50, 200, 50]
frozen = tracker.get_frozen_message_count()
assert frozen == 2 # System + User1 frozen
tracker.update_from_response(
cache_read_tokens=2050,
cache_write_tokens=250,
messages=messages_t2,
message_token_counts=token_counts_t2,
)
# Turn 3: Even more cached
messages_t3 = messages_t2 + [
{"role": "assistant", "content": "Answer 2"},
{"role": "user", "content": "Question 3"},
]
token_counts_t3 = [2000, 50, 200, 50, 200, 50]
frozen = tracker.get_frozen_message_count()
assert frozen == 4 # System + User1 + Asst1 + User2 frozen
tracker.update_from_response(
cache_read_tokens=2300,
cache_write_tokens=250,
messages=messages_t3,
message_token_counts=token_counts_t3,
)
# Verify turn count
assert tracker._turn_number == 3
def test_cache_bust_resets_freeze(self):
"""If cache is busted (0 read, 0 write), freeze should reset."""
tracker = PrefixCacheTracker("anthropic")
messages = [
{"role": "system", "content": "System" * 200},
{"role": "user", "content": "Hello"},
]
# Turn 1: Cache established
tracker.update_from_response(
cache_read_tokens=0,
cache_write_tokens=2000,
messages=messages,
message_token_counts=[1500, 500],
)
assert tracker.get_frozen_message_count() == 2 # Both fit within 2000
# Turn 2: Cache bust (0 reads, system prompt changed)
tracker.update_from_response(
cache_read_tokens=0,
cache_write_tokens=0,
messages=messages,
message_token_counts=[1500, 500],
)
# After a bust with 0 total, freeze should reset
assert tracker.get_frozen_message_count() == 0
feat(cache): attribute prompt-cache misses to TTL lapse vs prefix change (#1313) (#1343) ## Description A low prompt-cache hit rate is hard to act on without knowing *why* turns miss. Two very different causes need very different responses: - **TTL lapse** — the session went idle longer than the provider's cache lifetime, so the entry expired. The fix is a longer TTL (e.g. Anthropic's 1h breakpoint instead of the 5m default). - **Prefix change** — the cacheable message prefix shifted, so the new request couldn't match the cached key. A longer TTL won't help here at all. Right now those look identical from the dashboard (just "cache_read was 0"). This adds the attribution so a user can actually decide 5m vs 1h. Closes #1313 ## Type of Change - [ ] Bug fix (non-breaking change that fixes an issue) - [x] New feature (non-breaking change that adds functionality) - [ ] Breaking change (fix or feature that would cause existing functionality to change) - [ ] Documentation update - [ ] Performance improvement - [ ] Code refactoring (no functional changes) ## Changes Made `PrefixCacheTracker` already kept the previous turn's forwarded messages and a per-turn activity timestamp, so the signal was already there — it just wasn't being read. - **`prefix_tracker.py`** — `classify_cache_miss()`: when a turn expected a cached prefix (non-zero cached tokens last turn) but read 0 this turn, returns `ttl_expiry` if the idle gap exceeded the provider cache TTL, else `prefix_change` if the forwarded prefix differs from last turn's, else `unknown`. **TTL wins ties** — once the entry lapsed, a coincident content change is moot, and the 5m-vs-1h decision is exactly what the TTL signal answers. A 1h-breakpoint session can widen the window via `PrefixFreezeConfig.cache_ttl_seconds`. Cold starts and hits return `is_miss=False`. - **Anthropic handlers (streaming + non-streaming)** — classify BEFORE `update_from_response` overwrites the last-turn state the classifier reads, then record the reason. - **`prometheus_metrics.py`** — a per-provider/per-reason counter, `record_cache_miss_attribution()`, reset handling, and a `headroom_cache_miss_attribution_total{provider,reason}` export series. - **`cost.py`** — `build_prefix_cache_stats()` aggregates a `miss_attribution` block (per-provider + totals, with the ttl/prefix split as a % of *attributed* misses, so `unknown` doesn't dilute the headline). - **dashboard** — a "Cache Miss Attribution" panel (TTL expiry / prefix change / unknown / total) with a "mostly TTL lapse" vs "mostly prefix change" headline. Scoped to Anthropic for this first cut (where the tracker is fully wired); OpenAI/Gemini can follow once the shape is proven. ## Testing - [x] Unit tests pass (`pytest`) - [ ] Linting passes (`ruff check .`) - [ ] Type checking passes (`mypy headroom`) - [x] New tests added for new functionality - [ ] Manual testing performed ### Test Output ```text $ python -m pytest tests/test_cache/test_prefix_tracker.py -q 38 passed # 29 existing + 9 new classifier tests (TestClassifyCacheMiss). $ python -m pytest tests/test_proxy_cache_ttl_metrics.py -k "miss_attribution or reset_runtime_clears" -q 5 passed, 8 deselected # new: counter bucketing, stats aggregation, empty case, /metrics export, reset. ``` The full `test_proxy_cache_ttl_metrics.py` / `test_proxy_dashboard_stats_cache.py` files have some failures in this sandbox (`test_stats_endpoint_*`, streaming-parser, reset-counters) — those spin up the proxy server / Rust `_core` extension, which isn't built here. I confirmed via `git stash` that they fail identically on `main` without my changes, so they're pre-existing and unrelated. My additions to the stats dict are purely additive and don't break any passing assertion. ## Real Behavior Proof - Environment: Windows 11, Python 3.10. The Rust `_core` extension and a live proxy aren't available in this checkout. - Exact command / steps: drove `classify_cache_miss()` through every branch with a faithful warm-then-miss sequence; drove `record_cache_miss_attribution()` → `build_prefix_cache_stats()` → `export()` end to end. - Observed result: classifier returns `cold_start`/`hit`/`ttl_expiry`/`prefix_change`/`unknown` correctly, TTL wins the tie when both signals fire, a growing (append-only) prefix is treated as stable, and the 1h override widens the window. The stats builder produces `miss_attribution.totals` (`ttl_expiry`/`prefix_change`/`unknown`/`total` + `ttl_expiry_pct`/`prefix_change_pct` over attributed misses) and `by_provider`; `/metrics` emits `headroom_cache_miss_attribution_total{provider="anthropic",reason="ttl_expiry"}`. - Not tested: a live Anthropic session through the running proxy with a real idle-then-resume to confirm the handler wiring fires end-to-end. I verified the handler integration by reading scope/order (classify before `update_from_response`, `provider_name`/`self.metrics` in scope) and unit-tested every layer it calls, but didn't exercise the actual server loop. ## Review Readiness - [x] I have performed a self-review - [x] This PR is ready for human review ## Checklist - [x] My code follows the project's style guidelines - [x] I have performed a self-review of my code - [x] I have commented my code, particularly in hard-to-understand areas - [ ] I have made corresponding changes to the documentation - [x] My changes generate no new warnings - [x] I have added tests that prove my fix is effective or that my feature works - [x] New and existing unit tests pass locally with my changes - [ ] I have updated the CHANGELOG.md if applicable ## Additional Notes - The classifier is intentionally pure (takes the cache-read result + current forwarded messages + an optional idle override) so it's order-independent and unit-testable without a live tracker clock. - No README/docs change yet — this surfaces in the dashboard and `/metrics`, which are self-describing; happy to add a docs page if you'd like one. - CHANGELOG.md isn't touched — release-please generates it from the `feat(cache):` commit subject. - Follow-ups if useful: extend to OpenAI/Gemini handlers, and add a per-provider breakdown row in the dashboard panel (the stats already carry `by_provider`).
2026-06-24 20:20:34 +05:30
class TestClassifyCacheMiss:
"""Cache-miss attribution (#1313): TTL lapse vs prefix change vs unknown."""
BASE = [
{"role": "system", "content": "x" * 4000},
{"role": "user", "content": "hello"},
]
CHANGED = [
{"role": "system", "content": "DIFFERENT" * 400},
{"role": "user", "content": "hello"},
]
def _warm(self, tracker, messages, read=500, write=500):
"""Simulate a turn that left `messages` cached."""
tracker.update_from_response(
cache_read_tokens=read, cache_write_tokens=write, messages=messages
)
def test_cold_start_is_not_a_miss(self):
"""No prior cached prefix → cold start, is_miss False."""
tracker = PrefixCacheTracker("anthropic")
result = tracker.classify_cache_miss(0, self.BASE)
assert result.is_miss is False
assert result.reason == MISS_COLD_START
def test_cache_read_is_a_hit(self):
"""A non-zero read on an expected-cached prefix is a hit, not a miss."""
tracker = PrefixCacheTracker("anthropic")
self._warm(tracker, self.BASE)
result = tracker.classify_cache_miss(800, self.BASE)
assert result.is_miss is False
assert result.reason == "hit"
def test_ttl_expiry_when_idle_exceeds_ttl(self):
"""Idle longer than the cache TTL → ttl_expiry."""
tracker = PrefixCacheTracker("anthropic")
self._warm(tracker, self.BASE)
result = tracker.classify_cache_miss(0, self.BASE, idle_seconds=400)
assert result.is_miss is True
assert result.reason == MISS_TTL_EXPIRY
assert result.ttl_exceeded is True
assert result.cache_ttl_seconds == 300
def test_ttl_wins_tie_when_prefix_also_changed(self):
"""When idle past TTL AND prefix changed, TTL expiry wins (docstring)."""
tracker = PrefixCacheTracker("anthropic")
self._warm(tracker, self.BASE)
result = tracker.classify_cache_miss(0, self.CHANGED, idle_seconds=400)
assert result.reason == MISS_TTL_EXPIRY
assert result.ttl_exceeded is True
assert result.prefix_changed is True
def test_prefix_change_within_ttl(self):
"""Within TTL but the forwarded prefix differs → prefix_change."""
tracker = PrefixCacheTracker("anthropic")
self._warm(tracker, self.BASE)
result = tracker.classify_cache_miss(0, self.CHANGED, idle_seconds=10)
assert result.is_miss is True
assert result.reason == MISS_PREFIX_CHANGE
assert result.prefix_changed is True
assert result.ttl_exceeded is False
def test_unknown_when_stable_prefix_within_ttl(self):
"""Within TTL, prefix unchanged, but still no read → unknown."""
tracker = PrefixCacheTracker("anthropic")
self._warm(tracker, self.BASE)
result = tracker.classify_cache_miss(0, self.BASE, idle_seconds=10)
assert result.is_miss is True
assert result.reason == MISS_UNKNOWN
def test_growing_prefix_is_stable(self):
"""A turn that appends to last turn's forwarded prefix is not a change."""
tracker = PrefixCacheTracker("anthropic")
self._warm(tracker, self.BASE)
grown = self.BASE + [{"role": "assistant", "content": "hi back"}]
result = tracker.classify_cache_miss(0, grown, idle_seconds=10)
# Prefix preserved (only appended) → not a prefix_change.
assert result.prefix_changed is False
assert result.reason == MISS_UNKNOWN
def test_one_hour_ttl_override(self):
"""cache_ttl_seconds override widens the TTL window (1h breakpoint)."""
tracker = PrefixCacheTracker("anthropic", PrefixFreezeConfig(cache_ttl_seconds=3600))
self._warm(tracker, self.BASE)
# 400s idle is past the 300s default but within 3600s → not TTL expiry.
result = tracker.classify_cache_miss(0, self.BASE, idle_seconds=400)
assert result.cache_ttl_seconds == 3600
assert result.ttl_exceeded is False
assert result.reason == MISS_UNKNOWN
def test_resolved_ttl_falls_back_to_provider_default(self):
assert PrefixCacheTracker("anthropic").resolved_cache_ttl_seconds() == 300
assert (
PrefixCacheTracker(
"anthropic", PrefixFreezeConfig(cache_ttl_seconds=3600)
).resolved_cache_ttl_seconds()
== 3600
)