UNPKG

kestrel.markets

Version:

A typed, token-efficient language + runtime for agentic trading: agents author bounded plans, the runtime fires them at the tick. CLI + typed library + MCP server.

181 lines (155 loc) 11.5 kB
# OSS-ADR-0056 — Delta-kernel is the default WAKE render (keyframe on structural change) Status: **Accepted** (loop-accepted on EXP-70.15 evidence, 2026-07-19; owner ratification window open — bead `kestrel-uhef`). Composes with and does not re-litigate OSS-ADR-0019 (the delta-encoded kernel mechanism), OSS-ADR-0041 (the render-channel doctrine: safety facts render exactly twice), OSS-ADR-0044 (comprehension is a first-class measured gate), and OSS-ADR-0052 (the Rendering seam). Evidence: `docs/percept-lab/exp-70-15-results.md` (+ its pre-registration), CLIMB-LEDGER row F3. ## Context OSS-ADR-0019 reinterpreted the kernel-leads invariant for cache-monotone streams and shipped the machinery: `renderWakeDeltaKernel` (`src/frame/render.ts`) emits a WAKE kernel as ONLY the fields that MOVED since the reader's cached prior kernel, falling back to a full keyframe whenever the kernel's SKELETON changed. That ADR settled the *mechanism* and its correctness gate ("delta-encoding is used only under the streaming policies, where the reader provably holds the prior full kernel; `stateless-redraw` always gets a full kernel"). It did **not** decide whether the delta form should be the *sanctioned default WAKE render*, because at the time the binding risk — does eliding an unchanged-but-safety-relevant fact cost the reader *comprehension* of it k wakes later? — had not been measured. Two facts have since changed: 1. **The delta form is already, de facto, the default.** The default cache policy is `conversation-cached` (`DEFAULT_CACHE_POLICY`, `src/session/harness/live-agent.ts`). Under any streaming policy the live harness threads the prior frame's kernel (`streamPrev = reuse ? priorKernel : undefined`) into `renderWakePrompt`, whose streaming gate (`policy !== "stateless-redraw" && prevKernel !== undefined`) routes the WAKE render through `renderWakeDeltaStreamed`. So every non-first, same-skeleton WAKE of a default-config session already renders as a delta. This was an emergent consequence of ADR-0019 + the cost-driven default policy (kestrel-rul / m9i.5), never a ratified, evidence-backed decision — and nothing locked the wire, so a future refactor could silently regress it to full re-statement while every unit test stayed green. 2. **The comprehension risk has been priced and cleared.** OSS-ADR-0044 makes percept-reading comprehension a first-class measured property and a gate: a render change that plausibly affects what the model can *read* may not be blessed on token savings alone. EXP-70.15 is the pre-registered experiment that supplies the missing measurement. ## The evidence (EXP-70.15 — WIN, all three limbs) Over a frozen, invented, date-blind 9-vantage session (generic SPX/SPXW; one deliberate skeleton-change wake at w2), model-free where possible and model-graded where not (readers `claude-haiku-4-5` + `claude-sonnet-4-5`; grading mechanical; 240/240 quiz cells within the ≤400 budget): - **SAVINGS — PASS.** Mean **87.6%** kernel-token savings across the 7 delta-rendered wakes (cl100k; the kernel drops from ~258–273 tokens to ~25–44), ≈2.5× over the 35% bar; session-total 68.4%. - **SAFETY — PASS.** At every one of the 9 vantages the reconstructed kernel's `numericFacts` multiset is **byte-identical** to the full-kernel arm — verified *independently* of the encoder's own composed-completeness guard. The skeleton-change wake (w2: a resting order appears) returned `null` and re-keyframed, proving the honest structural-change escape hatch fires on the real path. - **RECALL — PASS.** The falsifier ("delta-arm effective recall below full-kernel at any k ≤ 3 beyond the foil band") does **not** fire at any k. The k-sweep decay curve is **flat through k = 5**: recall of an elided-but-unchanged fact does not decay out to five wakes of elision under the explicit "unlisted fields unchanged" contract. At k = 1 the delta arm *outperforms* full re-statement on effective recall. - **Foil side-finding (an affirmative argument, not merely a cost).** Every one of the 7 P&L-attribution foil guesses is cross-attribution of a *present* number (the real position's `unreal` mapped onto a never-present one), and the FULL arm guessed **more** (5) than the delta arm (2). Re-stating everything every wake mildly *increases* misattribution pressure — so full re-statement is not a free safety margin; on this evidence it is slightly worse for cross-attribution. ## Decision **The delta-kernel is the sanctioned default WAKE render under cache-monotone delivery.** A WAKE frame whose reader provably holds the prior full kernel (the `conversation` / `conversation-cached` policies) renders its SAFETY/CONTROL kernel as a `KERNEL DELTA` block carrying only the fields that MOVED; the byte-stable skeleton and every unchanged field ride the cached prefix. This ratifies the already-wired behaviour with the EXP-70.15 evidence; it changes **no bytes** and introduces **no new configuration**. **Keyframe (the complete kernel) is rendered — fail-closed — whenever the reader may not hold the prior kernel or the delta cannot be proven complete:** - the OPEN briefing (wake 0 has no prior), - every `stateless-redraw` frame (the reader holds no prior context — this is also the explicit full-kernel **opt-out**: pin `cachePolicy: "stateless-redraw"`), - any wake where no `prevKernel` is available (a non-harness caller, the first wake after OPEN when the OPEN→WAKE skeleton differs), - any **structural change** — a section/list changed shape ⇒ `renderWakeDeltaKernel` returns `null` ⇒ the caller emits a full keyframe (the honest re-keyframe), - any **wire-unsafe** field (an anchor or value that would break the ` <anchor> <value>` line framing) ⇒ fail safe to a keyframe, - any **composed-completeness** doubt — before returning, the encoder composes the delta against the cached prior and asserts the result is byte-identical to the full current kernel; a mismatch throws `KernelHonestyError` rather than emit a partial kernel. There is no silent partial render: the delta path either produces a block that provably reconstructs the complete current kernel, or it falls back to a full keyframe. The full-kernel **opt-out already exists** (`stateless-redraw`); this ADR invents no new render config (per the no-new-config-system rule). ## Composition with the standing doctrine - **OSS-ADR-0019 (mechanism).** Unchanged and not re-litigated. This ADR only elevates the delta form from "the mechanism used under streaming policies" to "the evidence-backed default WAKE render," and locks the wire with a through-the-driver fixture. The correctness gate (streaming-only; keyframe on null / stateless-redraw / OPEN) is exactly ADR-0019's and is preserved verbatim. - **OSS-ADR-0041 (safety facts render exactly twice).** Preserved. A safety-critical fact is repetition-coded at two positions — the kernel (primacy) and the pane nearest the decision it governs (recency), asserted byte-identical. The **body panes are never delta-encoded** (only the kernel block is), so the recency occurrence is physically present on every wake. The kernel (primacy) occurrence, when unchanged, is not re-emitted on the wire but is reconstructed **byte-identically** from the cached prefix by the composed-completeness guard — so both occurrences remain available and byte-identical to the reader. The delta elides an unchanged row only where the reader provably still holds it; absent-not-hidden is preserved (a field that MOVED to UNKNOWN is present-and-marked in the delta; a field merely unchanged is absent-because-cached, never confused with absent-because-unknown). EXP-70.15's safety limb re-verifies the full numeric multiset per wake, independently of the encoder's guard. - **OSS-ADR-0044 (comprehension is a measured gate).** This ADR is the gate being cleared: EXP-70.15's model-graded recall limb is the comprehension evidence the render change is admitted on, not token savings alone. The flat k ≤ 5 decay curve is the general elision-decay price-card the experiment produced. - **OSS-ADR-0052 (the Rendering seam).** The delta is a property of the one kernel/tape walk's WAKE rendering, not a new renderer. Canonical bytes are the frozen leaderboard control and are **unchanged** by this ADR (it ratifies, it does not re-render). The delta path is orthogonal to the format adapters — it selects *which kernel block* leads a cache-monotone WAKE, not *which format* materializes it. ## Determinism and the fail-closed contract The delta is a **pure function of `(prevKernel, curKernel)`** — no wall clock, no RNG, no I/O. Same bus + same armed documents ⇒ byte-identical event stream and report; caching is a transport-side concern that lives above the determinism line (the graded Bus is unchanged, and `recordedAgent` replays byte-identically regardless of how a wake was framed). The lead guard (`assertKernelLeads`) accepts either the full-kernel lead sentinel or the `KERNEL DELTA` sentinel and throws on any other first line; the composed-completeness guard throws rather than emit an incomplete kernel. Fail-closed at every branch: any doubt re-keyframes. ## Why a through-the-real-driver fixture (the #365 reviewer observation) `renderWakeDeltaKernel`'s **internal** byte-identity guard (compose-and-compare before returning) is the *safety* mechanism — it makes it impossible for a delta to escape that does not reconstruct the complete kernel. It is **not** evidence that the delta path is *wired* into the production WAKE render: a green unit test of the guard proves the function is correct, never that any wake reaches it. The harness-level `numericFacts` re-check is likewise dominated by that internal guard. So the deployment gate for this ADR is a **through-the-real-driver red-on-inert fixture** (`tests/bench.delta-kernel-default-e2e.test.ts`): a stand-pat multi-wake session driven through `runSimulateSession` + `liveAgent` (default config) with a capturing client, asserting that wake N ≥ 1 (same-skeleton) renders the `KERNEL DELTA` form, that the full-kernel lead sentinel does **not** reappear on an unchanged wake, and that the kernel numeric multiset is preserved every wake. The decisive property: **delete the delta call site** (restore `renderWakeDelta` in `renderWakePrompt`) and the fixture goes RED — an unwired default cannot pass it. ## Consequences - The already-default delta WAKE render is now ratified and **locked** by the red-on-inert fixture; a refactor that un-wires it (regressing to full re-statement, which the foil finding shows is mildly *worse* for cross-attribution) is caught through the real driver, not just in a unit test. - No bytes change: canonical goldens, the renderer epoch (`RENDERER_REVISION` / `n_HASH`), and every pinned render-corpus/summary hash are untouched. This ADR ratifies existing behaviour and adds a wiring lock; it is not a render change. - `stateless-redraw` remains the self-complete full-kernel arm (the m9i.5 A/B control and the explicit full-kernel opt-out). No new render configuration is introduced. - The flat k ≤ 5 elision-decay curve is now the price-card for downstream cross-wake elision ideas (e.g. multiday-fold): on this evidence they pay no measured recall tax through k = 5 under an explicit unlisted-fields-unchanged contract.