feat: experimental relevance compaction, off by default - #142
Closed
DevMortimer wants to merge 4 commits into
Closed
DevMortimer wants to merge 4 commits into
DevMortimer wants to merge 4 commits into
Conversation
A new `compaction` config section (off by default) lets pi-warden write the compaction summary. User messages and assistant text stay word for word and thinking is left out. Jev scores each tool call with its result, each extension message, and each part of the previous summary against the current task. Kept units go in verbatim, with tool output fenced as untrusted data; the rest become one line each. Results flagged as a possible prompt injection are never kept verbatim, and results the context saver compressed keep their excerpt. Any failure, timeout, abort, missing consent, a provider in `compaction.skipProviders`, or a summary over `compaction.maxSummaryTokens` returns nothing, so Pi's own summary runs; the hook never cancels a compaction. Each compaction leaves one trace entry, and /warden status has one line for it. scripts/relevance-replay.mjs replays recorded compactions with real requests. First measurement (docs/guards.md, Calibration): the summary is 4.7 times larger than Pi's at the median and holds 1 of 34 re-fetched reads whole and 11 as head and tail, so the feature stays off by default.
- Kept text can no longer open or close Pi's <summary> wrapper: a `<` that starts a summary tag is written `<`, and the header says so. - Extension message types and earlier-summary headings are redacted before they reach Jev, in the candidates and in the outline. - Every rendered section is fenced with a fence longer than any backtick run in it, so the next compaction parses back the same units. - compaction.timeoutMs bounds the whole compaction; each request is also bounded by the global timeoutMs, and the docs say exactly that. - New compaction.maxRequests (default 12). A compaction sends nothing when its requests would leave fewer than 50 of the session budget, and stops before any request when fewer than 50 remain, read from the shared client. A budget stop no longer turns judgments off. - compaction.enabled is user file only; a project tunes the other keys. - Docs and changelog call the feature experimental, off by default, not recommended, with the replay result, and say that flagged results are recognised only when the security check is on.
Owner
Author
|
Superseded by 143: the same change plus the README update, ordered so the version bump stays the last commit. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Experimental, off by default, and not recommended. It ships so anyone can try it or improve it.
What it does
When
compaction.enabledis on (user config only), pi-warden replaces the summary Pi's model writes at compaction. User messages and assistant text are kept word for word, thinking is left out, and each tool call with its result is scored by the judge against the current task: kept word for word (long results as head and tail) or reduced to one line. Kept tool output is fenced as untrusted data, results flagged as possible prompt injection (when the security check is on) are never kept word for word, and any<summarytag in kept text is escaped so it cannot close Pi's wrapper. On any error, timeout, abort, oversize, or budget stop it returns nothing and Pi's own summary runs; it never cancels a compaction. It steps aside for providers that compact their own models (skipProviders, default["claude-bridge"]).It spends from the session request budget with limits: at most
compaction.maxRequests(12) per compaction, and it sends nothing when fewer than 50 requests would remain for the guards.Why not recommended
A replay of 48 recorded compactions against Pi's own summaries:
Details and the replay script (
scripts/relevance-replay.mjs) are indocs/guards.md.Verification
npm run check: 1249 pass / 0 fail; typecheck and build clean.