Skip to content

fix(llm): TTL split only counts as evidence when consistent with its own aggregate - #5

Merged
danielzarioiu merged 1 commit into
synapse/v1.6.0-compat1from
feat/ttl-split-consistency-guard
Oct 10, 2026
Merged

danielzarioiu merged 1 commit into
synapse/v1.6.0-compat1from
feat/ttl-split-consistency-guard

Conversation

@danielzarioiu

Copy link
Copy Markdown
Member

P0-C of the cache-write double-metering correction (accounting-side PR is separate and already rejects split-vs-aggregate contradictions at settlement). Anthropic documents cache_creation_input_tokens == 5m + 1h for a final snapshot; captured production snapshots violate it (aggregate 13 / 1 with {5m:0,1h:0} — sub-minimum cache markers). This guard refuses to certify contradictory splits as evidence (degrades to unknown, fail-closed preserved), on the streaming paths (message_start + delta, delta-wins-when-consistent, contradictory-delta-never-clobbers) and the buffered pass-through parse. Client wire untouched. Goldens drop exactly the two forwarded 0/0 fields each. NOT built or released — pending approval. agent-llm 429/429, agentgateway 2229/2229, fmt+clippy clean.

…own aggregate

Anthropic documents cache_creation_input_tokens == ephemeral_5m +
ephemeral_1h for a final usage snapshot. Captured production snapshots
violate that invariant (stream_basic: aggregate 13 with {5m:0,1h:0};
thinking: aggregate 1 with {5m:0,1h:0} — sub-minimum cache markers), and
reading those zeros as authoritative would silently unprice the residual
aggregate downstream (the accounting settlement now rejects the same
contradiction, so the producer must not certify it as evidence either).

- CacheCreationSplit::evidence_against: per-TTL buckets become evidence
  only when they sum to the SAME usage object's aggregate; contradictory
  splits degrade to unknown — settlement keeps failing closed on the
  collapsed meter instead.
- Streaming converters (passthrough + translation): message_start and
  message_delta both route through the guard; a consistent delta
  (including an explicit consistent zero) still wins over message_start,
  and a contradictory delta leaves earlier evidence untouched.
- Buffered Usage::cache_ttl_split: same invariant on the pass-through
  parse. Client-facing wire untouched (parse-only; json_passthrough).
- Goldens: the four anthropic snapshots drop exactly the two forwarded
  0/0 evidence fields (per-diff verified) — contradictory splits are no
  longer certified.

agent-llm 429/429 (427 + 2), agentgateway 2229/2229, fmt + clippy clean.
@danielzarioiu
danielzarioiu merged commit b584a9e into synapse/v1.6.0-compat1 Oct 10, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant