Skip to main content

deepstrike_core/context/
token_engine.rs

1use std::sync::Arc;
2
3use crate::types::message::{Content, ContentPart, Message};
4
5/// Token counting and truncation interface. Implementations must be
6/// deterministic and must never panic on any valid UTF-8 input.
7pub trait TokenCounter: Send + Sync {
8    /// Count tokens in a UTF-8 string.
9    fn count(&self, text: &str) -> u32;
10
11    /// Return the longest prefix of `text` that fits within `max_tokens`.
12    /// The returned slice is always a valid UTF-8 prefix of `text`.
13    fn truncate<'a>(&self, text: &'a str, max_tokens: u32) -> &'a str;
14}
15
16/// Char-count approximation: 4 chars ≈ 1 token.
17/// Used when no real tokeniser is available. More accurate than byte-count
18/// for CJK text (3 bytes/char but ~0.5 tokens/char).
19pub struct CharApproxCounter;
20
21impl TokenCounter for CharApproxCounter {
22    fn count(&self, text: &str) -> u32 {
23        (text.chars().count() as u32 / 4).max(1)
24    }
25
26    fn truncate<'a>(&self, text: &'a str, max_tokens: u32) -> &'a str {
27        let max_chars = (max_tokens as usize).saturating_mul(4);
28        let mut byte_end = text.len(); // default: keep all
29        let mut seen = 0usize;
30        for (byte_idx, _) in text.char_indices() {
31            if seen >= max_chars {
32                byte_end = byte_idx;
33                break;
34            }
35            seen += 1;
36        }
37        &text[..byte_end]
38    }
39}
40
41/// spc_011-C-01: real-BPE-backed counter, the production default. `CharApproxCounter`'s
42/// char/4 divisor only holds for English text — on CJK-heavy text it underestimates real BPE
43/// counts by 40-70% (its own doc comment claims "~0.5 tokens/char" for CJK, but the
44/// implementation applies the same 0.25 tokens/char divisor to every script). This wraps
45/// `deepstrike-tokenizer`'s real cl100k BPE tokenizer (previously an orphaned crate — not a
46/// workspace member, zero call sites anywhere) and adds a fixed margin on top. That only
47/// guarantees a value above the selected `cl100k_base` estimate; it does not prove that the
48/// result is conservative for every provider model. Native Anthropic/Gemini token counts take
49/// precedence where callers explicitly request them.
50pub struct FallbackEstimator {
51    tokenizer: deepstrike_tokenizer::Tokenizer,
52    /// Multiplier applied on top of the raw BPE count. `1.1` is a starting margin over
53    /// `cl100k_base`, not an empirical claim about any provider tokenizer.
54    safety_margin: f64,
55}
56
57impl FallbackEstimator {
58    pub fn new(backend: deepstrike_tokenizer::TokenizerBackend, safety_margin: f64) -> Self {
59        Self {
60            tokenizer: deepstrike_tokenizer::Tokenizer::new(backend),
61            safety_margin,
62        }
63    }
64}
65
66impl Default for FallbackEstimator {
67    fn default() -> Self {
68        Self::new(deepstrike_tokenizer::TokenizerBackend::Cl100k, 1.1)
69    }
70}
71
72impl TokenCounter for FallbackEstimator {
73    fn count(&self, text: &str) -> u32 {
74        let raw = self.tokenizer.count(text) as f64;
75        ((raw * self.safety_margin).ceil() as u32).max(1)
76    }
77
78    fn truncate<'a>(&self, text: &'a str, max_tokens: u32) -> &'a str {
79        // Budget in *raw* BPE tokens so that, after the margin is applied by `count`, the
80        // truncated text's reported count still fits within `max_tokens`.
81        let raw_budget = ((max_tokens as f64) / self.safety_margin).floor() as u32;
82        self.tokenizer.truncate(text, raw_budget)
83    }
84}
85
86/// Cheaply cloneable token engine shared across the context subsystem.
87/// All token counting and truncation goes through this single object —
88/// pressure, compression, and render use the same backend.
89#[derive(Clone)]
90pub struct ContextTokenEngine(Arc<dyn TokenCounter>);
91
92impl ContextTokenEngine {
93    /// Deterministic char/4 approximation. Kept as an explicit, opt-in constructor for tests
94    /// that pin exact token counts (many do, calibrated to this specific math) — **not** used
95    /// by any production call site as of spc_011-C-01; see [`Self::fallback_estimator`].
96    pub fn char_approx() -> Self {
97        Self(Arc::new(CharApproxCounter))
98    }
99
100    /// spc_011-C-01: the production default token engine. Real-BPE-backed (see
101    /// [`FallbackEstimator`]), replacing the previous `char_approx()` default that
102    /// underestimated CJK-heavy text by 40-70%.
103    pub fn fallback_estimator() -> Self {
104        Self(Arc::new(FallbackEstimator::default()))
105    }
106
107    pub fn count(&self, text: &str) -> u32 {
108        self.0.count(text)
109    }
110
111    pub fn truncate<'a>(&self, text: &'a str, max_tokens: u32) -> &'a str {
112        self.0.truncate(text, max_tokens)
113    }
114
115    pub fn token_budget_to_bytes(&self, tokens: u32) -> usize {
116        (tokens as usize).saturating_mul(4)
117    }
118
119    pub fn count_message(&self, msg: &Message) -> u32 {
120        match &msg.content {
121            Content::Text(t) => self.count(t),
122            Content::Parts(parts) => parts.iter().map(|p| self.count_part(p)).sum(),
123        }
124    }
125
126    fn count_part(&self, part: &ContentPart) -> u32 {
127        match part {
128            ContentPart::Text { text } => self.count(text),
129            ContentPart::ToolResult { output, .. } => self.count(output),
130            // Image/Audio: modality heuristic (0.2.66 DEL-2 — the heuristic lives here,
131            // in the engine, not on ContentPart) — never treat base64/url payloads as
132            // UTF-8 text (that blind-spots compression ρ).
133            ContentPart::Image { .. } | ContentPart::Audio { .. } => {
134                modality_estimate_tokens(part).unwrap_or(1)
135            }
136        }
137    }
138
139    /// Truncate a text message to `max_tokens`. Returns the message unchanged
140    /// if it fits. Parts messages are never truncated — mangling structured
141    /// content produces worse outcomes than a minor token overrun.
142    pub fn truncate_message(&self, msg: &Message, max_tokens: u32) -> Message {
143        match &msg.content {
144            Content::Text(t) => {
145                let kept = self.0.truncate(t, max_tokens);
146                if kept.len() < t.len() {
147                    let mut m = msg.clone();
148                    m.content = Content::Text(format!("{}… [truncated]", kept));
149                    m.token_count = Some(max_tokens);
150                    m
151                } else {
152                    msg.clone()
153                }
154            }
155            Content::Parts(_) => msg.clone(),
156        }
157    }
158}
159
160/// Modality-aware token estimate for Image/Audio parts (0.2.66 DEL-2: moved here from
161/// `ContentPart::estimate_tokens`, which is deleted — the engine holds the heuristic,
162/// `ContentPart` stays pure semantics). Returns `None` for text-bearing parts that must
163/// go through a real [`TokenCounter`].
164///
165/// Image: OpenAI-vision-style tile heuristic (`low=85`, `auto/default=255`, `high=680`).
166/// Audio: `max(1, floor(decoded_bytes / 1600))` where `decoded_bytes ≈ base64_len * 3/4`.
167/// Never treat base64 payloads as UTF-8 text for counting.
168fn modality_estimate_tokens(part: &ContentPart) -> Option<u32> {
169    match part {
170        ContentPart::Image { detail, .. } => Some(match detail.as_deref() {
171            Some("low") => 85,
172            Some("high") => 680,
173            _ => 255,
174        }),
175        ContentPart::Audio { data, .. } => {
176            let decoded_bytes = (data.len() as u64).saturating_mul(3) / 4;
177            Some((decoded_bytes / 1600).max(1) as u32)
178        }
179        ContentPart::Text { .. } | ContentPart::ToolResult { .. } => None,
180    }
181}
182
183#[cfg(test)]
184mod tests {
185    use super::*;
186    use crate::types::message::{ContentPart, Message};
187
188    fn engine() -> ContextTokenEngine {
189        ContextTokenEngine::char_approx()
190    }
191
192    #[test]
193    fn count_nonzero_for_nonempty_text() {
194        assert!(engine().count("hello") > 0);
195    }
196
197    #[test]
198    fn count_is_char_based_not_byte_based() {
199        let e = engine();
200        // "你好" = 6 bytes, 2 chars → count = max(2/4, 1) = 1
201        // "hello" = 5 bytes, 5 chars → count = max(5/4, 1) = 1
202        // The key property: count doesn't grow 3× for CJK vs ASCII
203        let cjk_count = e.count("你好世界"); // 4 chars
204        let ascii_count = e.count("abcd"); // 4 chars (same char count)
205        assert_eq!(cjk_count, ascii_count);
206    }
207
208    #[test]
209    fn truncate_stays_within_budget() {
210        let e = engine();
211        let text = "a".repeat(1000);
212        let kept = e.0.truncate(&text, 10);
213        assert!(e.count(kept) <= 10);
214    }
215
216    #[test]
217    fn truncate_cjk_valid_utf8() {
218        let e = engine();
219        let text = "你好世界".repeat(100);
220        let kept = e.0.truncate(&text, 5);
221        assert!(std::str::from_utf8(kept.as_bytes()).is_ok());
222    }
223
224    #[test]
225    fn truncate_count_le_budget() {
226        let e = engine();
227        for max in [1u32, 5, 20, 100] {
228            let kept =
229                e.0.truncate("The quick brown fox jumps over the lazy dog.", max);
230            assert!(
231                e.count(kept) <= max,
232                "max={max} kept_count={}",
233                e.count(kept)
234            );
235        }
236    }
237
238    #[test]
239    fn truncate_message_appends_suffix_on_cut() {
240        let e = engine();
241        let msg = Message::user("a".repeat(200));
242        let truncated = e.truncate_message(&msg, 5);
243        let text = truncated.content.as_text().unwrap();
244        assert!(text.ends_with("… [truncated]"), "got: {text}");
245    }
246
247    #[test]
248    fn truncate_message_unchanged_when_fits() {
249        let e = engine();
250        let msg = Message::user("hi");
251        let out = e.truncate_message(&msg, 1000);
252        assert_eq!(out.content.as_text().unwrap(), "hi");
253    }
254
255    #[test]
256    fn count_image_uses_detail_heuristic_not_one() {
257        let e = engine();
258        let low = Message::user_multimodal(vec![ContentPart::image_base64_with_detail(
259            "abc",
260            "image/png",
261            "low",
262        )]);
263        let auto = Message::user_multimodal(vec![ContentPart::image_base64("abc", "image/png")]);
264        let high = Message::user_multimodal(vec![ContentPart::image_base64_with_detail(
265            "abc",
266            "image/png",
267            "high",
268        )]);
269        assert_eq!(e.count_message(&low), 85);
270        assert_eq!(e.count_message(&auto), 255);
271        assert_eq!(e.count_message(&high), 680);
272    }
273
274    /// spc_011-C-01 Red: `CharApproxCounter` (char/4) badly underestimates real BPE token
275    /// counts on CJK-heavy text — its own doc comment claims "~0.5 tokens/char" for CJK, but
276    /// the implementation divides by 4 (0.25 tokens/char) regardless of script, which is only
277    /// correct for English. This reproduces the underestimate against a sample matching this
278    /// repo's own actual workload (Chinese spec/status prose), not a synthetic worst case.
279    #[test]
280    fn char_approx_severely_underestimates_cjk_heavy_text_vs_real_bpe() {
281        let sample = "核实 `ContextTokenEngine` 默认使用 `CharApproxCounter`(4 字符≈1 token),\
282而 `ContextManager::new()` 明确默认初始化 `ContextTokenEngine::char_approx()`。这就能解释实际观察到的 \
28320%~30% 少算问题。这个值直接进入 Context ρ → Snip → Micro → Collapse → Auto → Renewal 决策链路,\
284低估会导致压缩没有按时触发,继续 append 下去最终造成 Provider context overflow。";
285
286        let approx = CharApproxCounter.count(sample);
287        let real =
288            deepstrike_tokenizer::Tokenizer::new(deepstrike_tokenizer::TokenizerBackend::Cl100k)
289                .count(sample);
290
291        let underestimate_pct = 1.0 - (approx as f64 / real as f64);
292        assert!(
293            underestimate_pct > 0.30,
294            "expected char_approx to underestimate real BPE count by >30% on CJK-heavy text, \
295             got approx={approx} real={real} ({:.1}%)",
296            underestimate_pct * 100.0
297        );
298    }
299
300    /// The production default (`fallback_estimator`) must not reproduce the CJK underestimate
301    /// above: its fixed margin keeps it at or above the selected `cl100k_base` count.
302    #[test]
303    fn fallback_estimator_does_not_underestimate_cjk_heavy_text() {
304        let sample = "核实 `ContextTokenEngine` 默认使用 `CharApproxCounter`(4 字符≈1 token),\
305而 `ContextManager::new()` 明确默认初始化 `ContextTokenEngine::char_approx()`。这就能解释实际观察到的 \
30620%~30% 少算问题。";
307
308        let e = ContextTokenEngine::fallback_estimator();
309        let estimated = e.count(sample);
310        let real =
311            deepstrike_tokenizer::Tokenizer::new(deepstrike_tokenizer::TokenizerBackend::Cl100k)
312                .count(sample);
313
314        assert!(
315            estimated >= real,
316            "fallback_estimator margin must stay above its cl100k base \
317             (estimated={estimated} real={real})"
318        );
319    }
320
321    /// The default production engine (`ContextManager::new`) must be the fallback estimator,
322    /// not `char_approx` — this is the actual bug: the constructor call site, not the counter
323    /// implementation itself (which stays correct as an explicit, deterministic test helper).
324    #[test]
325    fn context_manager_new_does_not_default_to_char_approx() {
326        let cjk = "这是一段包含中文的示例文本,用来验证生产路径默认引擎不再是字符近似计数器。";
327        let mgr = crate::context::manager::ContextManager::new(100_000);
328        let default_engine_count = mgr.engine.count(cjk);
329        let char_approx_count = ContextTokenEngine::char_approx().count(cjk);
330        assert_ne!(
331            default_engine_count, char_approx_count,
332            "ContextManager::new() must not use char_approx as its token engine"
333        );
334    }
335
336    #[test]
337    fn count_audio_uses_decoded_byte_heuristic_not_base64_text() {
338        let e = engine();
339        // 6400 base64 chars → ~4800 decoded bytes → 4800/1600 = 3 tokens
340        let audio =
341            Message::user_multimodal(vec![ContentPart::audio("A".repeat(6400), "audio/wav")]);
342        assert_eq!(e.count_message(&audio), 3);
343        // Must not explode to thousands the way counting base64 as text would.
344        assert!(e.count_message(&audio) < 100);
345    }
346}