headroom/tests/test_netcost_gate.py
Focused Instability fe4f9ee478
feat(policy): decay P_alive from idle time near cache TTL (#856 P3b) (#1028)
## Description

#856 P3b (umbrella #904), the idle-timer-compaction increment after P2
(#905), P2b (#944), and P3a (#1015), all merged.

Anthropic prompt-cache entries live in a ~5-minute TTL tier (the basis
for the 1.25× write multiplier). As a session goes idle the cached
suffix approaches lapse, so **P_alive** — the probability the cache
still survives to the next turn — decays toward 0. When P_alive → 0 the
net-cost penalty term `P_alive·(w−r)·(S+ΔT)` vanishes and a deep edit
near lapse is free to make: the suffix is about to be rebuilt cold
regardless. P2/P3a fed the break-even gate a **static**
`HEADROOM_NET_COST_P_ALIVE` constant; this derives P_alive from an idle
signal when one is available.

Flag-gated under `HEADROOM_NET_COST_POLICY` (the same flag as
P2/P2b/P3a), default **off**.

## Type of Change

- [x] New feature (non-breaking change which adds functionality)
- [ ] Bug fix
- [ ] Breaking change
- [ ] Documentation

## Changes Made

- `ContentRouter.apply`: reads an optional `idle_seconds` kwarg and
derives `P_alive = max(0, 1 − idle_s / ttl)` **once per request** (idle
is a per-request property, like `frozen_message_count`), passing it to
the gate as `p_alive_override`. Absent/malformed `idle_seconds` → `None`
→ the P2 env-constant path is preserved exactly.
- `ContentRouter._net_cost_allows`: new `p_alive_override` param. When
set it replaces the `HEADROOM_NET_COST_P_ALIVE` constant (clamped to
[0,1]); otherwise unchanged. An admit made under a decayed (`< 1.0`)
idle P_alive emits the `router:netcost_idle_compaction` marker and the
`netcost_idle_admitted` counter (independent of the P3a batch marker;
both may apply).
- Cache TTL: module default 300s (Anthropic tier), overridable via
`HEADROOM_NET_COST_CACHE_TTL_SECONDS`, with malformed/non-positive
guards. Explicitly **distinct** from
`PrefixFreezeConfig.session_ttl_seconds` (tracker cleanup, 600s).
- `PrefixCacheTracker.seconds_since_activity()`: exposes the idle signal
for the proxy handlers to plumb (see Additional Notes).

## Testing

- [x] Unit tests pass (`pytest`)
- [x] Linting passes (`ruff check .`)
- [x] New tests added for new functionality

### Test Output

```text
$ pytest tests/test_netcost_gate.py -q
25 passed in 2.03s

$ pytest tests/ -k "content_router or netcost or router or prefix_tracker or prefix" -q
245 passed, 8 skipped, 6252 deselected, 1 warning in 24.47s

$ ruff check headroom/transforms/content_router.py headroom/cache/prefix_tracker.py tests/test_netcost_gate.py
All checks passed!

$ ruff format --check headroom/transforms/content_router.py headroom/cache/prefix_tracker.py tests/test_netcost_gate.py
3 files already formatted

$ mypy headroom/transforms/content_router.py headroom/cache/prefix_tracker.py
Success: no issues found in 2 source files
```

## Real Behavior Proof

- Environment: local macOS, repo .venv, Python 3.11.9, gpt-4o tokenizer
fixture
- Exact command / steps: drive `ContentRouter.apply()` on the P2
"blocked" baseline (a modest tool-dump shave, ΔT≈5K, under a ~120K-token
cached suffix — rejected at the default P_alive=1.0), varying only
`idle_seconds`.
- Observed result: `idle_seconds=295` (TTL 300) → P_alive≈0.017, penalty
collapses, the edit is admitted and `router:netcost_idle_compaction` is
emitted; `idle_seconds=0` → P_alive=1.0, byte-identical to the constant
baseline (still blocked, `netcost:skip:` emitted, no idle marker);
absent/malformed `idle_seconds` → env-constant path (blocked);
`HEADROOM_NET_COST_CACHE_TTL_SECONDS=60` with `idle_seconds=59` → unlock
(custom TTL controls the decay).
- Not tested: live proxy traffic — deferred to the default-on milestone
per #904 (ships default-off to gather telemetry first).

## Review Readiness

- [x] I have performed a self-review
- [x] This PR is ready for human review

## Additional Notes

**Proxy wiring is a deliberate follow-up**, mirroring how P2 shipped
P_alive as an unplumbed constant and gathered telemetry before
default-on. The gate already honors `idle_seconds` via kwarg and
`PrefixCacheTracker.seconds_since_activity()` exposes the value; the
remaining step is for the provider handlers (`handlers/anthropic.py`,
`handlers/openai.py`) to pass it alongside the existing
`frozen_message_count` kwarg (`pipeline.apply` already forwards
`**kwargs` to `transform.apply`, so no pipeline change is needed). One
wiring caveat is documented on `seconds_since_activity()`:
`SessionTrackerStore.get_or_create` refreshes `_last_activity` on
access, so the handler must read idle before fetching the tracker for
the current request. Kept out of this PR for reviewability and because
it touches ~10 call sites across both providers.

---------

Co-authored-by: JD Davis <mxjerrett@gmail.com>
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
2026-06-18 11:15:40 -05:00

413 lines
20 KiB
Python

"""Net-cost mutation gate in ContentRouter (#856 P2, flag-gated).
``HEADROOM_NET_COST_POLICY=1`` routes every router mutation candidate
through ``CompressionPolicy.net_mutation_gain`` with the issue's v1
estimators (exact ΔT, S = token total after the slot, env-tunable R and
P_alive). Flag off (default) preserves exact current behavior.
"""
from __future__ import annotations
import json
import pytest
from headroom import OpenAIProvider, Tokenizer
from headroom.transforms.content_router import ContentRouter, ContentRouterConfig
_provider = OpenAIProvider()
@pytest.fixture
def tokenizer() -> Tokenizer:
return Tokenizer(_provider.get_token_counter("gpt-4o"), "gpt-4o")
@pytest.fixture
def router() -> ContentRouter:
return ContentRouter(ContentRouterConfig())
def _tool_json(rows: int) -> str:
return json.dumps(
[{"id": i, "name": f"item_{i}", "status": "ok", "score": i * 3.14} for i in range(rows)]
)
def _messages(tool_content: str, suffix_filler_words: int) -> list[dict]:
suffix = "analysis context word " * suffix_filler_words
return [
{"role": "user", "content": "fetch the records"},
{"role": "tool", "content": tool_content},
{"role": "user", "content": suffix},
{"role": "user", "content": "summarize"},
]
def _tool_slot_compressed(result, messages) -> bool:
return result.messages[1]["content"] != messages[1]["content"]
class TestNetCostGate:
def test_flag_off_compresses_as_before(self, router, tokenizer, monkeypatch):
monkeypatch.delenv("HEADROOM_NET_COST_POLICY", raising=False)
messages = _messages(_tool_json(300), suffix_filler_words=4000)
result = router.apply([dict(m) for m in messages], tokenizer)
assert _tool_slot_compressed(result, messages)
assert not any(t.startswith("netcost:") for t in result.transforms_applied)
def test_flag_on_blocks_when_suffix_dominates(self, router, tokenizer, monkeypatch):
# Big suffix after a modest shave: corrected formula says the cache
# invalidation outweighs the saving -> slot left untouched.
monkeypatch.setenv("HEADROOM_NET_COST_POLICY", "1")
messages = _messages(_tool_json(300), suffix_filler_words=40000)
result = router.apply([dict(m) for m in messages], tokenizer)
assert not _tool_slot_compressed(result, messages)
assert any(t.startswith("netcost:skip:") for t in result.transforms_applied)
def test_flag_on_allows_when_shave_dominates(self, router, tokenizer, monkeypatch):
# Tiny suffix after a huge shave -> gate allows, compression applies.
monkeypatch.setenv("HEADROOM_NET_COST_POLICY", "1")
messages = _messages(_tool_json(2000), suffix_filler_words=5)
result = router.apply([dict(m) for m in messages], tokenizer)
assert _tool_slot_compressed(result, messages)
assert not any(t.startswith("netcost:skip:") for t in result.transforms_applied)
def test_flag_on_gates_cached_results_too(self, router, tokenizer, monkeypatch):
# First apply warms the result cache with the flag off; second apply
# with the flag on must still gate the cache-hit path.
messages = _messages(_tool_json(300), suffix_filler_words=40000)
monkeypatch.delenv("HEADROOM_NET_COST_POLICY", raising=False)
warm = router.apply([dict(m) for m in messages], tokenizer)
assert _tool_slot_compressed(warm, messages)
monkeypatch.setenv("HEADROOM_NET_COST_POLICY", "1")
gated = router.apply([dict(m) for m in messages], tokenizer)
assert not _tool_slot_compressed(gated, messages)
assert any(t.startswith("netcost:skip:") for t in gated.transforms_applied)
def test_malformed_env_falls_back_to_defaults(self, router, tokenizer, monkeypatch):
monkeypatch.setenv("HEADROOM_NET_COST_POLICY", "1")
monkeypatch.setenv("HEADROOM_NET_COST_EXPECTED_READS", "lots")
monkeypatch.setenv("HEADROOM_NET_COST_P_ALIVE", "warm")
messages = _messages(_tool_json(300), suffix_filler_words=40000)
# Must not raise; defaults (R=10, P=1) still block this scenario.
result = router.apply([dict(m) for m in messages], tokenizer)
assert not _tool_slot_compressed(result, messages)
def test_p_alive_zero_disables_penalty(self, router, tokenizer, monkeypatch):
# Cold cache (P_alive=0): no suffix penalty, mutation always wins.
monkeypatch.setenv("HEADROOM_NET_COST_POLICY", "1")
monkeypatch.setenv("HEADROOM_NET_COST_P_ALIVE", "0")
messages = _messages(_tool_json(300), suffix_filler_words=40000)
result = router.apply([dict(m) for m in messages], tokenizer)
assert _tool_slot_compressed(result, messages)
def test_nonfinite_env_falls_back_to_defaults(self, router, tokenizer, monkeypatch):
# ``float("inf")``/``float("nan")`` parse without ValueError; the gate
# must reject them and fall back to defaults so telemetry isn't
# poisoned. With R=10/P=1 defaults this scenario still skips.
monkeypatch.setenv("HEADROOM_NET_COST_POLICY", "1")
monkeypatch.setenv("HEADROOM_NET_COST_EXPECTED_READS", "inf")
monkeypatch.setenv("HEADROOM_NET_COST_P_ALIVE", "nan")
messages = _messages(_tool_json(300), suffix_filler_words=40000)
result = router.apply([dict(m) for m in messages], tokenizer)
assert not _tool_slot_compressed(result, messages)
# Marker must be a bounded band, never a raw float / "nan".
skip_markers = [t for t in result.transforms_applied if t.startswith("netcost:skip:")]
assert skip_markers
assert all(m.split(":")[-1] in _GAIN_BANDS for m in skip_markers)
_GAIN_BANDS = {
"0",
"lt100",
"lt1k",
"lt10k",
"gte10k",
"neg_lt100",
"neg_lt1k",
"neg_lt10k",
"neg_gte10k",
"nan",
}
class TestNetCostHelpers:
def test_gain_bucket_bands_and_sign(self):
from headroom.transforms.content_router import _gain_bucket
assert _gain_bucket(0) == "0"
assert _gain_bucket(50) == "lt100"
assert _gain_bucket(500) == "lt1k"
assert _gain_bucket(5000) == "lt10k"
assert _gain_bucket(50000) == "gte10k"
assert _gain_bucket(-50) == "neg_lt100"
assert _gain_bucket(-50000) == "neg_gte10k"
assert _gain_bucket(float("nan")) == "nan"
assert _gain_bucket(float("inf")) == "nan"
def test_message_tokens_block_list_beats_repr(self, tokenizer):
# str(content) over a block list counts repr punctuation/type names;
# the block-aware helper counts only the text-bearing payload.
from headroom.transforms.content_router import _netcost_message_tokens
text = "word " * 200
block_msg = {
"role": "user",
"content": [
{"type": "text", "text": text},
{"type": "image", "source": {"data": "x" * 500}},
],
}
helper = _netcost_message_tokens(block_msg, tokenizer)
text_only = tokenizer.count_text(text)
# Helper tracks the text payload closely; the image block adds only a
# small repr proxy, far less than stringifying the whole list.
assert abs(helper - text_only) < text_only * 0.5
assert helper < tokenizer.count_text(str(block_msg["content"]))
def test_message_tokens_tool_result_blocks(self, tokenizer):
from headroom.transforms.content_router import _netcost_message_tokens
payload = "log line " * 100
msg = {
"role": "user",
"content": [
{
"type": "tool_result",
"tool_use_id": "t1",
"content": [{"type": "text", "text": payload}],
}
],
}
assert _netcost_message_tokens(msg, tokenizer) >= tokenizer.count_text(payload) * 0.8
def test_message_tokens_string_content(self, tokenizer):
from headroom.transforms.content_router import _netcost_message_tokens
s = "plain string content " * 50
assert _netcost_message_tokens({"role": "user", "content": s}, tokenizer) == (
tokenizer.count_text(s)
)
def _frozen_messages(tool_content: str, suffix_filler_words: int) -> list[dict]:
"""A short conversation whose compressible tool dump sits *inside* the
frozen prefix (index 1, with frozen_message_count=2)."""
suffix = "analysis context word " * suffix_filler_words
return [
{"role": "user", "content": "fetch the records"},
{"role": "tool", "content": tool_content},
{"role": "user", "content": suffix},
{"role": "user", "content": "summarize"},
]
class TestNetCostFrozenUnlock:
"""#856 P2b: let formula-positive deep edits through the frozen floor."""
def test_flag_off_frozen_stays_frozen(self, router, tokenizer, monkeypatch):
# Default (flag off): a message in the prefix cache is never mutated,
# however compressible it is — the binary floor wins.
monkeypatch.delenv("HEADROOM_NET_COST_POLICY", raising=False)
messages = _frozen_messages(_tool_json(2000), suffix_filler_words=5)
result = router.apply([dict(m) for m in messages], tokenizer, frozen_message_count=2)
assert not _tool_slot_compressed(result, messages)
assert "router:netcost_frozen_unlock" not in result.transforms_applied
def test_flag_on_unlocks_when_shave_dominates(self, router, tokenizer, monkeypatch):
# Huge shave deep in the frozen zone, tiny suffix after -> the
# break-even gate clears the deep edit and it proceeds (the "50K
# stale dump, 10K suffix" user story).
monkeypatch.setenv("HEADROOM_NET_COST_POLICY", "1")
messages = _frozen_messages(_tool_json(2000), suffix_filler_words=5)
result = router.apply([dict(m) for m in messages], tokenizer, frozen_message_count=2)
assert _tool_slot_compressed(result, messages)
assert "router:netcost_frozen_unlock" in result.transforms_applied
def test_flag_on_keeps_frozen_when_suffix_dominates(self, router, tokenizer, monkeypatch):
# Modest shave, big cached suffix -> gate runs on the unlocked slot
# but rejects it. The frozen message is left byte-identical and no
# unlock marker is emitted, proving the floor opened yet the formula
# still protected the cache.
monkeypatch.setenv("HEADROOM_NET_COST_POLICY", "1")
messages = _frozen_messages(_tool_json(300), suffix_filler_words=40000)
result = router.apply([dict(m) for m in messages], tokenizer, frozen_message_count=2)
assert not _tool_slot_compressed(result, messages)
assert "router:netcost_frozen_unlock" not in result.transforms_applied
assert any(t.startswith("netcost:skip:") for t in result.transforms_applied)
def test_flag_on_block_content_frozen_stays_frozen(self, router, tokenizer, monkeypatch):
# The gate is wired into the string and parallel-merge paths only;
# block-list frozen content (whose per-block cache_control contract
# is not net-cost aware) stays frozen even with a tiny suffix.
monkeypatch.setenv("HEADROOM_NET_COST_POLICY", "1")
big = "log line of output " * 400
messages = [
{"role": "user", "content": "fetch"},
{
"role": "user",
"content": [
{
"type": "tool_result",
"tool_use_id": "t1",
"content": [{"type": "text", "text": big}],
}
],
},
{"role": "user", "content": "summarize"},
]
original = [dict(m) for m in messages]
result = router.apply([dict(m) for m in messages], tokenizer, frozen_message_count=2)
assert result.messages[1]["content"] == original[1]["content"]
assert "router:netcost_frozen_unlock" not in result.transforms_applied
class TestNetCostBatchReclaim:
"""#856 P3a: batch deep edits -- once one net-positive edit is admitted at
slot K, deeper candidates ride that cache-bust for free (S charged as 0).
Tests are cache-cold (fresh router per fixture) so every candidate flows
through the parallel-merge pass in ascending slot order, which is where the
shared batch_state floor is set and then reclaimed.
"""
@staticmethod
def _convo(slot1: str, slot2: str, filler_words: int) -> list[dict]:
# Two consecutive tool dumps (slots 1 and 2) followed by a filler
# suffix. Slot 1 is the shallower candidate; slot 2 the deeper one.
suffix = "analysis context word " * filler_words
return [
{"role": "user", "content": "fetch the records"},
{"role": "tool", "content": slot1},
{"role": "tool", "content": slot2},
{"role": "user", "content": suffix},
{"role": "user", "content": "summarize"},
]
@staticmethod
def _compressed(result, original, idx: int) -> bool:
return result.messages[idx]["content"] != original[idx]["content"]
def test_flag_off_no_batch_marker(self, router, tokenizer, monkeypatch):
# Without the flag the batch path is inert -- no marker, no counter.
monkeypatch.delenv("HEADROOM_NET_COST_POLICY", raising=False)
messages = self._convo(_tool_json(2000), _tool_json(800), filler_words=5)
original = [dict(m) for m in messages]
result = router.apply([dict(m) for m in messages], tokenizer)
assert "router:netcost_batch_admit" not in result.transforms_applied
# Both deep edits still compress (no gate at all when flag off).
assert self._compressed(result, original, 1)
assert self._compressed(result, original, 2)
def test_deeper_edit_rides_free(self, router, tokenizer, monkeypatch):
# Slot 1 (huge shave) admits on its own merit and opens the floor;
# slot 2 then admits via the batch reclaim path and emits the marker.
monkeypatch.setenv("HEADROOM_NET_COST_POLICY", "1")
messages = self._convo(_tool_json(2000), _tool_json(800), filler_words=5)
original = [dict(m) for m in messages]
result = router.apply([dict(m) for m in messages], tokenizer)
assert self._compressed(result, original, 1)
assert self._compressed(result, original, 2)
markers = [t for t in result.transforms_applied if t == "router:netcost_batch_admit"]
# Exactly one deeper slot rode the floor for free.
assert len(markers) == 1
def test_batch_admits_otherwise_blocked_edit(self, router, tokenizer, monkeypatch):
# Slot 2 (modest shave, large suffix after it) would be blocked on its
# own S, but slot 1's admit already busted the suffix -- so slot 2 rides
# free. Pairs with test_no_prior_admit_keeps_block, which shows the same
# slot-2 config stays blocked when no shallower edit opens the floor.
monkeypatch.setenv("HEADROOM_NET_COST_POLICY", "1")
messages = self._convo(_tool_json(2000), _tool_json(300), filler_words=4000)
original = [dict(m) for m in messages]
result = router.apply([dict(m) for m in messages], tokenizer)
assert self._compressed(result, original, 1) # floor-setting admit
assert self._compressed(result, original, 2) # rode free
assert "router:netcost_batch_admit" in result.transforms_applied
def test_no_prior_admit_keeps_block(self, router, tokenizer, monkeypatch):
# Neither candidate beats its own S (both modest shaves under a huge
# suffix), so the floor is never opened and no slot rides free. Guards
# against a floor-init / off-by-one bug that would grant a free ride
# with no genuine shallower mutation behind it.
monkeypatch.setenv("HEADROOM_NET_COST_POLICY", "1")
messages = self._convo(_tool_json(300), _tool_json(300), filler_words=40000)
original = [dict(m) for m in messages]
result = router.apply([dict(m) for m in messages], tokenizer)
assert not self._compressed(result, original, 1)
assert not self._compressed(result, original, 2)
assert "router:netcost_batch_admit" not in result.transforms_applied
def test_frozen_unlock_and_batch_combine(self, router, tokenizer, monkeypatch):
# Two frozen string slots inside the prefix (frozen_message_count=3).
# Slot 1 unlocks and sets the floor; slot 2 unlocks AND rides free.
# Slot 2 carries both markers; the batch counter must not double-count.
monkeypatch.setenv("HEADROOM_NET_COST_POLICY", "1")
messages = self._convo(_tool_json(2000), _tool_json(800), filler_words=5)
original = [dict(m) for m in messages]
result = router.apply([dict(m) for m in messages], tokenizer, frozen_message_count=3)
assert self._compressed(result, original, 1)
assert self._compressed(result, original, 2)
unlocks = [t for t in result.transforms_applied if t == "router:netcost_frozen_unlock"]
batch = [t for t in result.transforms_applied if t == "router:netcost_batch_admit"]
assert len(unlocks) == 2 # both frozen slots opened
assert len(batch) == 1 # only the deeper one rode free -- no double-count
class TestNetCostIdleCompaction:
"""#856 P3b: derive P_alive from idle time. As the session goes idle the
cached suffix nears TTL lapse, P_alive -> 0, the net-cost penalty term
vanishes, and edits that lose to a warm suffix become free.
Baseline shape (mirrors TestNetCostGate.test_flag_on_blocks...): a modest
tool-dump shave under a huge cached suffix is BLOCKED at the default
P_alive=1.0. These tests vary only the idle signal.
"""
def test_idle_near_ttl_unlocks_blocked_edit(self, router, tokenizer, monkeypatch):
# idle ~= cache TTL (default 300s) -> P_alive ~= 0 -> penalty ~= 0 ->
# the otherwise-blocked deep edit is admitted and marked.
monkeypatch.setenv("HEADROOM_NET_COST_POLICY", "1")
messages = _messages(_tool_json(300), suffix_filler_words=40000)
result = router.apply([dict(m) for m in messages], tokenizer, idle_seconds=295.0)
assert _tool_slot_compressed(result, messages)
assert "router:netcost_idle_compaction" in result.transforms_applied
assert not any(t.startswith("netcost:skip:") for t in result.transforms_applied)
def test_idle_zero_matches_constant_baseline(self, router, tokenizer, monkeypatch):
# idle=0 -> P_alive=1.0, identical to the env-constant default: the
# edit stays blocked and no idle marker is emitted.
monkeypatch.setenv("HEADROOM_NET_COST_POLICY", "1")
messages = _messages(_tool_json(300), suffix_filler_words=40000)
result = router.apply([dict(m) for m in messages], tokenizer, idle_seconds=0.0)
assert not _tool_slot_compressed(result, messages)
assert "router:netcost_idle_compaction" not in result.transforms_applied
assert any(t.startswith("netcost:skip:") for t in result.transforms_applied)
def test_idle_absent_uses_env_constant(self, router, tokenizer, monkeypatch):
# No idle_seconds kwarg -> override is None -> P2 env-constant path.
monkeypatch.setenv("HEADROOM_NET_COST_POLICY", "1")
messages = _messages(_tool_json(300), suffix_filler_words=40000)
result = router.apply([dict(m) for m in messages], tokenizer)
assert not _tool_slot_compressed(result, messages)
assert "router:netcost_idle_compaction" not in result.transforms_applied
def test_malformed_idle_falls_back_to_constant(self, router, tokenizer, monkeypatch):
# Non-numeric idle_seconds is ignored (override stays None), so the
# gate keeps the constant behaviour rather than crashing the request.
monkeypatch.setenv("HEADROOM_NET_COST_POLICY", "1")
messages = _messages(_tool_json(300), suffix_filler_words=40000)
result = router.apply([dict(m) for m in messages], tokenizer, idle_seconds="soon")
assert not _tool_slot_compressed(result, messages)
assert "router:netcost_idle_compaction" not in result.transforms_applied
def test_custom_ttl_env_controls_decay(self, router, tokenizer, monkeypatch):
# A shorter TTL makes the same idle fully decay P_alive -> unlock.
monkeypatch.setenv("HEADROOM_NET_COST_POLICY", "1")
monkeypatch.setenv("HEADROOM_NET_COST_CACHE_TTL_SECONDS", "60")
messages = _messages(_tool_json(300), suffix_filler_words=40000)
result = router.apply([dict(m) for m in messages], tokenizer, idle_seconds=59.0)
assert _tool_slot_compressed(result, messages)
assert "router:netcost_idle_compaction" in result.transforms_applied