fix(evals): never judge faithfulness on silently truncated evidence
Browse filesrun_battery captures tool outputs at 40k chars and evidence_is_complete
gates faithfulness rows on nothing being truncated at capture time, but
faithfulness_evidence then sliced the joined evidence to 12k (behind a
stale "~6000 chars per output" comment predating the 40k raise): the
judge could see under a third of the grounding it was grading, yielding
false fabrication verdicts, the exact blind-judge failure class the
completeness gate exists to prevent.
Evidence now reaches the judge untruncated or the row is not emitted:
a new evidence_fits gate (cap raised 12k -> 200k, covering what capture
guarantees) excludes over-cap turns instead of slicing them, matching
the harness's exclude-don't-judge-blind philosophy. Stale comments
fixed. (The test file also carries the CLI tests for the check_triggers
fix in the next commit.)
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
- evals/grade.py +40 -18
- tests/test_evals_grade.py +104 -3
|
@@ -50,10 +50,16 @@ RETRIEVAL_TOOLS = {"retrieve_tutor_context", "run_kb_command"}
|
|
| 50 |
# in the command or its output reveal which corpus source the agent touched.
|
| 51 |
KB_RAW_SOURCE_RE = re.compile(r"raw/(?:docs|courses)/([A-Za-z0-9_.\-]+)/")
|
| 52 |
|
| 53 |
-
#
|
| 54 |
-
#
|
| 55 |
-
# call
|
| 56 |
-
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 57 |
|
| 58 |
# Holistic = the "would staff approve sending this?" gate (evals/background.md
|
| 59 |
# Layer 4). Emitted for every single-turn answer; the full rubric lives in
|
|
@@ -74,16 +80,17 @@ FAITHFULNESS_CRITERION = (
|
|
| 74 |
)
|
| 75 |
|
| 76 |
|
| 77 |
-
def faithfulness_evidence(
|
| 78 |
-
bundle: dict[str, Any], max_chars: int = FAITHFULNESS_EVIDENCE_MAX
|
| 79 |
-
) -> str:
|
| 80 |
"""Concatenate the retrieval/KB evidence the tutor saw, for grounding grades.
|
| 81 |
|
| 82 |
Joins each retrieval/KB tool call's command + output (and, for
|
| 83 |
`retrieve_tutor_context`, the ranked source titles/URLs) so the judge can
|
| 84 |
-
check the answer's claims against exactly what the tools returned.
|
| 85 |
-
the
|
| 86 |
-
|
|
|
|
|
|
|
|
|
|
| 87 |
"""
|
| 88 |
parts: list[str] = []
|
| 89 |
for call in bundle.get("tool_calls") or []:
|
|
@@ -100,7 +107,7 @@ def faithfulness_evidence(
|
|
| 100 |
body = f"{body}\nSOURCES: {cites}".strip()
|
| 101 |
if header or body:
|
| 102 |
parts.append(f"{header}\n{body}".strip())
|
| 103 |
-
return "\n\n".join(parts)
|
| 104 |
|
| 105 |
|
| 106 |
def evidence_is_complete(bundle: dict[str, Any]) -> bool:
|
|
@@ -125,6 +132,17 @@ def evidence_is_complete(bundle: dict[str, Any]) -> bool:
|
|
| 125 |
return True
|
| 126 |
|
| 127 |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 128 |
def index_battery(battery: list[dict[str, Any]]) -> dict[str, dict[str, Any]]:
|
| 129 |
index: dict[str, dict[str, Any]] = {}
|
| 130 |
for record in battery:
|
|
@@ -143,8 +161,9 @@ def kb_browsed_sources(bundle: dict[str, Any]) -> set[str]:
|
|
| 143 |
|
| 144 |
Lets recall credit KB grounding, which recall@shown cannot see (KB output is
|
| 145 |
raw text, not structured matches). Caveats: bundle output is capped at
|
| 146 |
-
|
| 147 |
-
sources at once (an over-count
|
|
|
|
| 148 |
"""
|
| 149 |
seen: set[str] = set()
|
| 150 |
for call in bundle.get("tool_calls") or []:
|
|
@@ -321,12 +340,15 @@ def quality_sheet_rows(
|
|
| 321 |
reference=reference,
|
| 322 |
)
|
| 323 |
]
|
| 324 |
-
# Faithfulness only when the
|
| 325 |
-
#
|
| 326 |
-
#
|
| 327 |
-
#
|
|
|
|
|
|
|
|
|
|
| 328 |
evidence = faithfulness_evidence(bundle)
|
| 329 |
-
if evidence and evidence_is_complete(bundle):
|
| 330 |
rows.append(
|
| 331 |
sheet_row(
|
| 332 |
bundle=bundle,
|
|
|
|
| 50 |
# in the command or its output reveal which corpus source the agent touched.
|
| 51 |
KB_RAW_SOURCE_RE = re.compile(r"raw/(?:docs|courses)/([A-Za-z0-9_.\-]+)/")
|
| 52 |
|
| 53 |
+
# Judge-prompt budget for a faithfulness row's evidence. Bundles capture each
|
| 54 |
+
# tool output at run_battery.TOOL_OUTPUT_MAX_CHARS = 40_000 chars (the KB
|
| 55 |
+
# shell's own per-call output cap), so one turn's complete evidence can span
|
| 56 |
+
# several 40k outputs; 200k covers ~5 max-size calls. This is a GATE, not a
|
| 57 |
+
# slice: quality_sheet_rows emits a faithfulness row only when the FULL
|
| 58 |
+
# assembled evidence fits (see evidence_fits), so the judge never grades
|
| 59 |
+
# silently truncated grounding (the evals.md F23/F24 blind-signal class).
|
| 60 |
+
# Worst case per row is ~200k chars (~50k tokens) of judge prompt; typical
|
| 61 |
+
# turns are far smaller, and anything larger is excluded, not sliced.
|
| 62 |
+
FAITHFULNESS_EVIDENCE_MAX = 200_000
|
| 63 |
|
| 64 |
# Holistic = the "would staff approve sending this?" gate (evals/background.md
|
| 65 |
# Layer 4). Emitted for every single-turn answer; the full rubric lives in
|
|
|
|
| 80 |
)
|
| 81 |
|
| 82 |
|
| 83 |
+
def faithfulness_evidence(bundle: dict[str, Any]) -> str:
|
|
|
|
|
|
|
| 84 |
"""Concatenate the retrieval/KB evidence the tutor saw, for grounding grades.
|
| 85 |
|
| 86 |
Joins each retrieval/KB tool call's command + output (and, for
|
| 87 |
`retrieve_tutor_context`, the ranked source titles/URLs) so the judge can
|
| 88 |
+
check the answer's claims against exactly what the tools returned. Returns
|
| 89 |
+
the evidence UNTRUNCATED: whether it fits the judge prompt is a separate
|
| 90 |
+
gate (evidence_fits), so an oversized turn is excluded from faithfulness
|
| 91 |
+
grading rather than judged against a silent slice. Empty when the turn used
|
| 92 |
+
no retrieval/KB tool (e.g. answer_general), which is the signal to skip the
|
| 93 |
+
faithfulness row for that case.
|
| 94 |
"""
|
| 95 |
parts: list[str] = []
|
| 96 |
for call in bundle.get("tool_calls") or []:
|
|
|
|
| 107 |
body = f"{body}\nSOURCES: {cites}".strip()
|
| 108 |
if header or body:
|
| 109 |
parts.append(f"{header}\n{body}".strip())
|
| 110 |
+
return "\n\n".join(parts)
|
| 111 |
|
| 112 |
|
| 113 |
def evidence_is_complete(bundle: dict[str, Any]) -> bool:
|
|
|
|
| 132 |
return True
|
| 133 |
|
| 134 |
|
| 135 |
+
def evidence_fits(evidence: str, max_chars: int = FAITHFULNESS_EVIDENCE_MAX) -> bool:
|
| 136 |
+
"""True if the assembled evidence fits the faithfulness judge-prompt budget.
|
| 137 |
+
|
| 138 |
+
Companion gate to ``evidence_is_complete``: that one guarantees nothing was
|
| 139 |
+
lost at CAPTURE time, this one guarantees nothing would be lost at JUDGE
|
| 140 |
+
time. A turn whose complete evidence still exceeds the cap is excluded from
|
| 141 |
+
faithfulness grading instead of being judged on truncated grounding.
|
| 142 |
+
"""
|
| 143 |
+
return len(evidence) <= max_chars
|
| 144 |
+
|
| 145 |
+
|
| 146 |
def index_battery(battery: list[dict[str, Any]]) -> dict[str, dict[str, Any]]:
|
| 147 |
index: dict[str, dict[str, Any]] = {}
|
| 148 |
for record in battery:
|
|
|
|
| 161 |
|
| 162 |
Lets recall credit KB grounding, which recall@shown cannot see (KB output is
|
| 163 |
raw text, not structured matches). Caveats: bundle output is capped at
|
| 164 |
+
``run_battery.TOOL_OUTPUT_MAX_CHARS`` (40k) per call, so a path past the cap
|
| 165 |
+
is missed; a broad ``rg`` can surface many sources at once (an over-count
|
| 166 |
+
toward "shown", not "used").
|
| 167 |
"""
|
| 168 |
seen: set[str] = set()
|
| 169 |
for call in bundle.get("tool_calls") or []:
|
|
|
|
| 340 |
reference=reference,
|
| 341 |
)
|
| 342 |
]
|
| 343 |
+
# Faithfulness only when the judge can see 100% of what the agent grounded
|
| 344 |
+
# on: (1) every retrieval/KB output was captured in full at record time
|
| 345 |
+
# (bundles recorded under the old 6k tool-output cap fail this; re-record
|
| 346 |
+
# at the 40k cap to re-enable), and (2) the full assembled evidence fits
|
| 347 |
+
# the judge-prompt budget. A turn failing either is excluded rather than
|
| 348 |
+
# judged on silently truncated evidence, which would score
|
| 349 |
+
# capture-completeness, not grounding (evals.md F23/F24 class).
|
| 350 |
evidence = faithfulness_evidence(bundle)
|
| 351 |
+
if evidence and evidence_is_complete(bundle) and evidence_fits(evidence):
|
| 352 |
rows.append(
|
| 353 |
sheet_row(
|
| 354 |
bundle=bundle,
|
|
@@ -1,13 +1,18 @@
|
|
| 1 |
from __future__ import annotations
|
| 2 |
|
| 3 |
import csv
|
|
|
|
| 4 |
import tempfile
|
| 5 |
import unittest
|
| 6 |
from pathlib import Path
|
|
|
|
| 7 |
|
|
|
|
| 8 |
from evals.common import detect_battery_type, normalize_url, percentile
|
| 9 |
from evals.grade import (
|
|
|
|
| 10 |
behavior_heuristic,
|
|
|
|
| 11 |
evidence_is_complete,
|
| 12 |
faithfulness_evidence,
|
| 13 |
grade_persona_question,
|
|
@@ -182,11 +187,16 @@ class FaithfulnessEvidenceTests(unittest.TestCase):
|
|
| 182 |
self.assertEqual(faithfulness_evidence(bundle), "")
|
| 183 |
self.assertEqual(faithfulness_evidence({}), "")
|
| 184 |
|
| 185 |
-
def
|
|
|
|
|
|
|
|
|
|
|
|
|
| 186 |
bundle = {
|
| 187 |
-
"tool_calls": [{"tool_name": "run_kb_command", "output_text": "z" *
|
| 188 |
}
|
| 189 |
-
|
|
|
|
| 190 |
|
| 191 |
|
| 192 |
class EvidenceCompletenessTests(unittest.TestCase):
|
|
@@ -252,6 +262,97 @@ class EvidenceCompletenessTests(unittest.TestCase):
|
|
| 252 |
self.assertIn("faithfulness", types_full) # full evidence -> emitted
|
| 253 |
|
| 254 |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 255 |
class JudgeRubricTests(unittest.TestCase):
|
| 256 |
def test_holistic_and_faithfulness_rubrics_exist(self) -> None:
|
| 257 |
self.assertIs(rubric_for("holistic"), RUBRICS["holistic"])
|
|
|
|
| 1 |
from __future__ import annotations
|
| 2 |
|
| 3 |
import csv
|
| 4 |
+
import sys
|
| 5 |
import tempfile
|
| 6 |
import unittest
|
| 7 |
from pathlib import Path
|
| 8 |
+
from unittest import mock
|
| 9 |
|
| 10 |
+
from evals import check_triggers
|
| 11 |
from evals.common import detect_battery_type, normalize_url, percentile
|
| 12 |
from evals.grade import (
|
| 13 |
+
FAITHFULNESS_EVIDENCE_MAX,
|
| 14 |
behavior_heuristic,
|
| 15 |
+
evidence_fits,
|
| 16 |
evidence_is_complete,
|
| 17 |
faithfulness_evidence,
|
| 18 |
grade_persona_question,
|
|
|
|
| 187 |
self.assertEqual(faithfulness_evidence(bundle), "")
|
| 188 |
self.assertEqual(faithfulness_evidence({}), "")
|
| 189 |
|
| 190 |
+
def test_returns_full_evidence_untruncated(self) -> None:
|
| 191 |
+
# One full-size KB capture (run_battery caps each output at 40k). The
|
| 192 |
+
# old 12k slice here silently cut the judge's evidence to <1/3 of the
|
| 193 |
+
# grounding; evidence must now come back whole -- fitting the judge
|
| 194 |
+
# prompt is a separate gate (evidence_fits), not a slice.
|
| 195 |
bundle = {
|
| 196 |
+
"tool_calls": [{"tool_name": "run_kb_command", "output_text": "z" * 40_000}]
|
| 197 |
}
|
| 198 |
+
evidence = faithfulness_evidence(bundle)
|
| 199 |
+
self.assertGreaterEqual(len(evidence), 40_000)
|
| 200 |
|
| 201 |
|
| 202 |
class EvidenceCompletenessTests(unittest.TestCase):
|
|
|
|
| 262 |
self.assertIn("faithfulness", types_full) # full evidence -> emitted
|
| 263 |
|
| 264 |
|
| 265 |
+
class EvidenceFitsTests(unittest.TestCase):
|
| 266 |
+
"""The judge-prompt side of the completeness guarantee: a faithfulness row
|
| 267 |
+
carries the FULL evidence or is not emitted at all -- never a silent slice
|
| 268 |
+
(the F23/F24 blind-judge class the capture gate exists to prevent)."""
|
| 269 |
+
|
| 270 |
+
@staticmethod
|
| 271 |
+
def _bundle(output_text: str) -> dict:
|
| 272 |
+
return {
|
| 273 |
+
"run_id": "r",
|
| 274 |
+
"battery_type": "singleturn",
|
| 275 |
+
"preset": "prod",
|
| 276 |
+
"query": "q",
|
| 277 |
+
"answer": "a",
|
| 278 |
+
"tool_calls": [
|
| 279 |
+
{
|
| 280 |
+
"tool_name": "run_kb_command",
|
| 281 |
+
"args_text": "cat raw/docs/x/big.md",
|
| 282 |
+
# Fully captured: output_chars == len(output_text), so the
|
| 283 |
+
# capture-completeness gate passes.
|
| 284 |
+
"output_text": output_text,
|
| 285 |
+
"output_chars": len(output_text),
|
| 286 |
+
}
|
| 287 |
+
],
|
| 288 |
+
}
|
| 289 |
+
|
| 290 |
+
def test_evidence_fits_predicate(self) -> None:
|
| 291 |
+
self.assertTrue(evidence_fits("x" * FAITHFULNESS_EVIDENCE_MAX))
|
| 292 |
+
self.assertFalse(evidence_fits("x" * (FAITHFULNESS_EVIDENCE_MAX + 1)))
|
| 293 |
+
self.assertTrue(evidence_fits("abc", max_chars=3))
|
| 294 |
+
self.assertFalse(evidence_fits("abcd", max_chars=3))
|
| 295 |
+
|
| 296 |
+
def test_cap_covers_a_realistic_multi_call_kb_turn(self) -> None:
|
| 297 |
+
# The gate must not exclude what capture guarantees: a few full 40k
|
| 298 |
+
# KB outputs (run_battery.TOOL_OUTPUT_MAX_CHARS) per turn must fit.
|
| 299 |
+
self.assertGreaterEqual(FAITHFULNESS_EVIDENCE_MAX, 4 * 40_000)
|
| 300 |
+
|
| 301 |
+
def test_faithfulness_row_carries_full_evidence(self) -> None:
|
| 302 |
+
# One complete 40k KB output: under the old 12k slice the judge saw
|
| 303 |
+
# ~30% of the grounding. The row must now carry all of it.
|
| 304 |
+
text = ("y" * 39_990) + "END-MARKER"
|
| 305 |
+
rows = [
|
| 306 |
+
r
|
| 307 |
+
for r in quality_sheet_rows(self._bundle(text))
|
| 308 |
+
if r["item_type"] == "faithfulness"
|
| 309 |
+
]
|
| 310 |
+
self.assertEqual(len(rows), 1)
|
| 311 |
+
self.assertGreater(len(rows[0]["reference"]), 12_000) # old cap is gone
|
| 312 |
+
self.assertTrue(rows[0]["reference"].endswith("END-MARKER"))
|
| 313 |
+
|
| 314 |
+
def test_faithfulness_row_excluded_when_evidence_exceeds_cap(self) -> None:
|
| 315 |
+
# Fully captured but too big for the judge prompt: excluded, not
|
| 316 |
+
# silently truncated. Holistic (which never uses evidence) still emits.
|
| 317 |
+
bundle = self._bundle("z" * (FAITHFULNESS_EVIDENCE_MAX + 1))
|
| 318 |
+
types = {r["item_type"] for r in quality_sheet_rows(bundle)}
|
| 319 |
+
self.assertIn("holistic", types)
|
| 320 |
+
self.assertNotIn("faithfulness", types)
|
| 321 |
+
|
| 322 |
+
|
| 323 |
+
class CheckTriggersMainTests(unittest.TestCase):
|
| 324 |
+
"""check_triggers must evaluate EVERY run: all() over a bare generator
|
| 325 |
+
short-circuited on the first failing run, hiding later runs' diagnostics."""
|
| 326 |
+
|
| 327 |
+
def _run_main(self, runs: list[str], results: list[bool]) -> tuple[list[Path], int]:
|
| 328 |
+
calls: list[Path] = []
|
| 329 |
+
|
| 330 |
+
def fake_check_run(run_dir: Path, expect_none: bool) -> bool:
|
| 331 |
+
calls.append(run_dir)
|
| 332 |
+
return results[len(calls) - 1]
|
| 333 |
+
|
| 334 |
+
argv = ["check_triggers", "--runs", *runs]
|
| 335 |
+
with (
|
| 336 |
+
mock.patch.object(check_triggers, "check_run", fake_check_run),
|
| 337 |
+
mock.patch.object(sys, "argv", argv),
|
| 338 |
+
self.assertRaises(SystemExit) as ctx,
|
| 339 |
+
):
|
| 340 |
+
check_triggers.main()
|
| 341 |
+
return calls, ctx.exception.code
|
| 342 |
+
|
| 343 |
+
def test_later_runs_still_checked_after_a_failure(self) -> None:
|
| 344 |
+
calls, code = self._run_main(
|
| 345 |
+
["runs/a", "runs/b", "runs/c"], [False, True, True]
|
| 346 |
+
)
|
| 347 |
+
self.assertEqual(calls, [Path("runs/a"), Path("runs/b"), Path("runs/c")])
|
| 348 |
+
self.assertEqual(code, 1) # exit semantics preserved
|
| 349 |
+
|
| 350 |
+
def test_exit_zero_when_all_runs_pass(self) -> None:
|
| 351 |
+
calls, code = self._run_main(["runs/a", "runs/b"], [True, True])
|
| 352 |
+
self.assertEqual(len(calls), 2)
|
| 353 |
+
self.assertEqual(code, 0)
|
| 354 |
+
|
| 355 |
+
|
| 356 |
class JudgeRubricTests(unittest.TestCase):
|
| 357 |
def test_holistic_and_faithfulness_rubrics_exist(self) -> None:
|
| 358 |
self.assertIs(rubric_for("holistic"), RUBRICS["holistic"])
|