Skip to content

fix(pylon): judge canary runaway by exact usage, not character estimates - #2315

Merged
FamousDirector merged 1 commit into
mainfrom
FamousDirector/https-nvbugspro.nvidia.com-bug-6866892
Oct 7, 2026
Merged

FamousDirector merged 1 commit into
mainfrom
FamousDirector/https-nvbugspro.nvidia.com-bug-6866892

Conversation

@FamousDirector

@FamousDirector FamousDirector commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

TL;DR

Pylon canaries no longer fail as runaway generation when a reasoning model stops exactly at the canary max_tokens cap. Exact usage decides the verdict. A character estimate is judged only when a completed stream reports no usage.

Additional Details (optional for docs, build, test, refactor, ci, chore, style, and revert PRs)

Why: send_canary_request sends max_tokens = --canary-max-generation-threshold (default 237) and checked observed_tokens > threshold after every SSE message. Before the final usage chunk, observed_tokens is the OutputTokenParser character estimate (ASCII / 4 plus one per non-ASCII character). Reasoning models with thinking enabled by default run to the cap on the 1+1= prompt, so small estimate errors push the estimate to 238-240. The canary failed before reading the exact usage chunk (which reported exactly 237), demoting the model and causing 503s for callers while the backend was healthy.

What changed in crates/pylon-lib/src/bringup/upstream.rs:

  • Track the latest accepted exact usage separately from the character estimate.
  • Require the [DONE] sentinel to complete the canary. sse_message_stream.rs gains a done_sentinel fact because the shared parser also reports response.completed as complete.
  • Stream completes with usage: RunawayGeneration if the accepted exact usage is above the cap, even if estimated output follows it.
  • Stream completes without usage: RunawayGeneration if the estimate is above the cap.
  • Stream times out, errors, carries a failure event, or ends without [DONE]: the normal timeout or invalid-response error, never runaway. The one exception is exact usage above the cap on a non-terminal event, which fails immediately because the count is already exact. An estimate never fails the canary mid-stream.

Also: the --canary-max-generation-threshold help text now says it is the canary max_tokens and that exact usage overrides the estimate.

Observability: no new logs, spans, or metrics. Fewer false failure results in the existing canary result metric.

For the Reviewer

Focus on the verdict logic in crates/pylon-lib/src/bringup/upstream.rs and the event-sequence tests in crates/pylon-lib/src/bringup.rs. The three-case verdict follows review feedback. Two Codex critical reviews were run and their findings addressed.

For QA (optional for docs, build, test, refactor, ci, chore, style, and revert PRs)

From src/libraries/rust/stargate:

  • cargo test --locked -p pylon-lib --lib: 548 passed. New event-sequence tests cover split and same-event overshoot settled by exact usage, estimated output after exact usage, regressed usage being ignored, exact usage above the cap (at completion and before the stream ends), a failure event carrying usage above the cap, no-usage streams at and above the cap, stall, EOF, or a read error after an overshoot staying a timeout or invalid response, and a completion event without [DONE] being invalid. The split-overshoot case failed before the fix with RunawayGeneration.
  • cargo test --locked -p pylon: passed.
  • cargo clippy --locked -p pylon-lib -p pylon --all-targets -- -D warnings: clean.
  • cargo fmt -p pylon-lib -p pylon -- --check: clean.

QA: not needed beyond CI. A live check against a reasoning model with default thinking enabled would confirm canaries stay healthy.

Issues

Closes #2314

Checklist

  • I am familiar with the Contributing Guidelines.
  • I have signed off my commits for Developer Certificate of Origin (DCO) compliance.
  • New or existing tests cover these changes.
  • The documentation is up to date with these changes.

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Bug Fixes

    • Canary generation now distinguishes estimated token counts from exact usage. Exact usage above the configured limit is classified as runaway generation, while estimates above the limit are checked when the stream completes.
    • Exact usage at or below the limit can settle an estimated overshoot, including when usage arrives across multiple events. A stalled stream after an estimated overshoot remains a timeout.
    • Streams missing the completion marker are treated as invalid responses rather than successful completions.
  • Documentation

    • Clarified that the generation limit applies to tokens and that exact usage takes precedence over estimates.

@coderabbitai

coderabbitai Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Repository: NVIDIA/nvcf/.coderabbit.yaml
  • Review profile: CHILL
  • Plan: Enterprise
  • Run ID: 5f5dfe22-b3c8-4a39-863c-6cf57dabffb8
📥 Commits

Reviewing files that changed from the base of the PR and between ac650e3 and e68beee.

📒 Files selected for processing (3)
  • src/libraries/rust/stargate/crates/pylon-lib/src/bringup.rs
  • src/libraries/rust/stargate/crates/pylon-lib/src/bringup/upstream.rs
  • src/libraries/rust/stargate/crates/pylon-lib/src/sse_message_stream.rs

Included review availability: This review used your included allowance. Your plan provides up to 12 included reviews per hour; 9 remain after this review.


📝 Walkthrough

Walkthrough

The canary now separates estimated token counts from exact usage. Exact usage above the threshold produces RunawayGeneration. Estimated overshoots are checked only after successful stream completion. Successful completion also requires the [DONE] sentinel.

Changes

Canary threshold behavior

Layer / File(s) Summary
SSE completion signal
src/libraries/rust/stargate/crates/pylon-lib/src/sse_message_stream.rs, src/libraries/rust/stargate/crates/pylon-lib/src/bringup/upstream.rs
SseEventFacts records whether an event contains the [DONE] sentinel. Canary completion requires the sentinel and a complete terminal outcome.
Token count and runaway verdict
src/libraries/rust/stargate/crates/pylon-lib/src/bringup/upstream.rs, src/libraries/rust/stargate/crates/pylon/src/main.rs
The canary tracks estimates separately from exact usage. Exact usage above the threshold produces RunawayGeneration; estimated overshoots are checked after successful stream completion. The CLI help describes the threshold and exact-usage behavior.
Threshold and stream-ending tests
src/libraries/rust/stargate/crates/pylon-lib/src/bringup.rs
Tests cover exact usage settling estimates, regressed usage, threshold boundaries, failed streams, and completion, EOF, and stall endings.

Priority: ➖ Normal

Estimated code review effort: 3 (Moderate) | ~20 minutes

Change: Bug fix · Severity of issue fixed: Medium

Merge Risk: ⚪ Minimal · up to e68be

No actionable issue remains from this review; the change is mergeable after normal checks.

🚥 Pre-merge checks | ✅ 3 | ❌ 2

❌ Failed checks (2 warnings)

Check name Status Explanation Resolution
Linked Issues check ⚠️ Warning Issue #2314 requires estimates to flag only generation clearly beyond the cap. send_canary_request returns RunawayGeneration whenever a completed stream has no exact usage and `estimated_tokens > … Add a confidence margin or equivalent rule for estimates when exact usage is absent. Allow a small estimate overshoot, while retaining runaway detection for estimates clearly beyond the cap. Update the event-sequence tests to cover both cas…
Docstring Coverage ⚠️ Warning Docstring coverage is 77.27% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 22 functions across 4 files. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (3 passed)
Check name Status Explanation
Out of Scope Changes check ✅ Passed The canary verdict changes, SSE completion fact, event-sequence tests, and CLI help text support issue #2314. The reviewed changes show no unrelated work.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title follows Conventional Commits syntax with the required scope for fix and accurately describes the canary runaway-verdict change.
Full details: Linked Issues check

Explanation

Issue #2314 requires estimates to flag only generation clearly beyond the cap. send_canary_request returns RunawayGeneration whenever a completed stream has no exact usage and estimated_tokens > threshold. The test summary confirms an estimate of 8 at a threshold of 7 fails, so a one-token estimate overshoot still fails. Exact-usage handling and incomplete-stream errors meet the stated requirements.

Resolution

Add a confidence margin or equivalent rule for estimates when exact usage is absent. Allow a small estimate overshoot, while retaining runaway detection for estimates clearly beyond the cap. Update the event-sequence tests to cover both cases.

✨ Finishing Touches 💡 1
📝 Generate docstrings 💡
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Comment @coderabbitai help to get the list of available commands.

@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

🛡️ CodeQL Analysis

🚨 Found 5 issue(s)

Severity Breakdown:

  • 🔴 Errors: 0
  • 🟡 Warnings: 0
  • 🔵 Notes: 0
📋 Top Issues

🔗 View full details in Security tab

🕐 Last updated: 2026-10-06 13:59:01 UTC | Commit: b106ac0

@FamousDirector
FamousDirector marked this pull request as ready for review October 6, 2026 14:44
@FamousDirector
FamousDirector requested a review from a team as a code owner October 6, 2026 14:44
@FamousDirector
FamousDirector requested review from along-2017, barrygreengus and dmikhaylovnv and removed request for dmikhaylovnv October 6, 2026 14:44
@barrygreengus

Copy link
Copy Markdown
Contributor

We should have 3 cases:

  1. stream finishes with usage -> fail w runaway error if over limit
  2. stream finishes without usage -> fail w runaway error if over limit
  3. stream times out or has an error -> fail with a normal error

we shouldnt have the possible conflation on the timeout case

@FamousDirector

Copy link
Copy Markdown
Contributor Author

Done in c1a9c7e. Completed with usage: runaway if exact usage is over the cap. Completed without usage: runaway if the estimate is over the cap. Timeout, stream error, or no [DONE]: the normal error, never runaway. Exact usage over the cap mid-stream still fails immediately, since it is already exact.

The canary sets max_tokens to the runaway threshold and compared the
character-based output estimate to that threshold on every SSE message.
Reasoning models that run to the cap produced estimates slightly above
it before the exact usage chunk arrived, so bounded responses failed the
canary and demoted the model.

The canary verdict now has three cases:

- A stream that completes with usage fails as runaway only if the
  accepted exact usage is above the cap. Exact usage above the cap on a
  non-terminal event still fails immediately.
- A stream that completes without usage fails as runaway only if the
  estimate is above the cap.
- A timeout, read error, failure event, or stream without [DONE] fails
  with its normal error, never runaway.

The SSE facts gain a done_sentinel flag because the shared parser also
reports response.completed as complete, and the canary requires [DONE].

Closes #2314

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Signed-off-by: jcameron <jcameron@nvidia.com>
@FamousDirector
FamousDirector force-pushed the FamousDirector/https-nvbugspro.nvidia.com-bug-6866892 branch from e68beee to a90b068 Compare October 6, 2026 17:36
@FamousDirector
FamousDirector added this pull request to the merge queue Oct 7, 2026
Merged via the queue into main with commit f9e251e Oct 7, 2026
25 checks passed
@FamousDirector
FamousDirector deleted the FamousDirector/https-nvbugspro.nvidia.com-bug-6866892 branch October 7, 2026 18:25
@balajinvda

Copy link
Copy Markdown
Contributor

🎉 This PR is included in src/libraries/rust/stargate/v0.23.0 🎉

The release is available on GitHub release

Your semantic-release bot 📦🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

fix(pylon): canary flags capped reasoning responses as runaway generation

4 participants