Skip to content

fix(context): strip invalidated signed thinking from replay - #47

Open
Brian Krabach (bkrabach) wants to merge 2 commits into
mainfrom
fix/strip-invalidated-signed-thinking-replay
Open

Brian Krabach (bkrabach) wants to merge 2 commits into
mainfrom
fix/strip-invalidated-signed-thinking-replay

Conversation

@bkrabach

@bkrabach Brian Krabach (bkrabach) commented Sep 29, 2026 •

Copy link
Copy Markdown
Collaborator

What does this change?

Fix signed-thinking replay across context compaction while preserving canonical history and transaction boundaries.

  • Preserve provider-signed thinking for a partially completed tool turn: the outbound view keeps the sticky thinking prefix and whole thinking block, and does not perform further compaction when the raw budget fits.
  • For a hard-budget / measured-limit request that cannot fit, fail closed with the existing ContextLengthError; canonical history and compaction transactions remain unchanged.
  • When a completed tool turn is stripped after an invalidated prefix, resume the existing stripping behavior: invalidated signed-thinking blocks are omitted from the compacted provider-facing view, while canonical history remains intact.

Type of change

  • Bug fix
  • New feature
  • Documentation
  • Refactor / internal change (no behavior change)
  • Other:

Testing

  • Local/Mac test suites: 236 passed, 1 xfailed.
  • Latest Linux DTU joint qualification against the released Core 2.0.1 wheel: PASS; source provenance matched the exact 38cf5f9e819cc1f9f4a6da0d182b10edd8976d05 commit.
  • uvx ruff format --check . and uvx ruff check . pass locally
  • If this touches the coexistence guard, presence detector, or an input backend: not applicable.

Evidence checklist

  • This PR makes a claim about platform behavior (timing, permission dialogs, input delivery, screenshot capture, etc.).
  • This PR flips a GUARD_MEASURED flag to True.
  • Neither of the above applies to this PR.

Live signed-history evidence

A genuine Sonnet 5.5 signed-thinking response was obtained with explicit binding-error enforcement enabled:

  • Unchanged append-only replay returned HTTP 200.
  • An edited prefix returned the expected HTTP 400 signature-binding error.
  • After an actual completed-turn compaction, the invalidated signature was dropped from the outbound view and continuation returned HTTP 200.
  • A CLI persisted-resume path containing two historical signatures with enforcement enabled also continued with HTTP 200.

Partially completed tool-turn guard

The newly qualified boundary keeps the sticky outbound view and whole thinking block while a tool turn is incomplete. If the raw budget fits, it does not compact again; if the hard budget cannot fit, it fails closed with the existing ContextLengthError without changing canonical history or compaction transactions. Completed-tool-turn stripping still resumes normally.

Anything reviewers should focus on

  • Verify the unfinished-tool-turn guard does not broaden retention beyond the provider-signed thinking required for the pending turn.
  • Confirm the hard-budget failure path remains fail-closed and transactionally reversible.
  • The exact Sonnet 5.5 / routing and default changes remain held locally and are not active; this PR contains only the qualified context follow-up.
  • Please keep this PR draft pending the latest CI snapshot, human review, and merge. No release or merge is requested by this update.

Breaking changes

None. Canonical admitted history, public configuration, and completed-turn behavior remain unchanged except that invalidated signed-thinking blocks are omitted from compacted provider-facing replay.

Strip provider-signed thinking from compacted outbound views after their prefix changes, while preserving canonical history and structured tool pairing.

Generated with Amplifier

Co-Authored-By: Amplifier <240397093+microsoft-amplifier@users.noreply.github.com>
Generated with Amplifier

Co-Authored-By: Amplifier <240397093+microsoft-amplifier@users.noreply.github.com>
@bkrabach

Copy link
Copy Markdown
Collaborator Author

Review-readiness evidence (not a GitHub formal approval):

  • Source audit: PASS at 38cf5f9.
  • CI: all reported checks green on this exact head: ruff, pytest on Python 3.11 and 3.12, and CLA.
  • Scoped release qualification: 3,427 passed, 21 skipped, 0 failures/errors against Core 2.0.1. Signed-history replay was exercised, including unchanged replay, edited-prefix binding failure, compaction recovery, and persisted CLI resume.
  • Limitation: this is evidence for normal review; it is not a maintainer approval and makes no production-merged claim.

No CODEOWNERS or clear public prior reviewer assignment was found, and no reviewer is currently requested. Please use the repository's normal human approval gate.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants