Skip to main content

switchyard_libsy/algorithms/vgr/
config.rs

1// SPDX-FileCopyrightText: Copyright (c) 2026 NVIDIA CORPORATION & AFFILIATES. All rights reserved.
2// SPDX-License-Identifier: Apache-2.0
3
4use std::time::Duration;
5
6use switchyard_protocol::ModelId;
7
8use super::safety::{BreakerConfig, KillSwitch};
9use crate::{LibsyError, Result};
10
11/// Required attestation for live local commits.
12pub const ACTIVE_APPROVAL: &str = "prospective-validation-and-canary-approved";
13
14/// Authority granted to VGR decisions.
15#[derive(Clone, Debug, Default, Eq, PartialEq)]
16pub enum ServingMode {
17    /// Always serves cloud without producing an attempt.
18    #[default]
19    Off,
20    /// Serves decisions, for isolated measurement.
21    Evaluate,
22    /// Decides but always serves cloud.
23    Shadow,
24    /// Serves decisions after operator approval.
25    Active {
26        /// Operator approval attestation.
27        approval: String,
28    },
29}
30
31/// Targets used by a VGR route.
32#[derive(Clone, Debug)]
33pub struct Targets {
34    /// Tier that produces the candidate attempt.
35    pub local: ModelId,
36    /// Tier used when the candidate is not licensed.
37    pub cloud: ModelId,
38    /// Local verifier, defaulting to `local`.
39    pub judge: Option<ModelId>,
40    /// Capable-tier verifier; unset removes the cloud confirmation rungs.
41    pub cloud_judge: Option<ModelId>,
42}
43
44/// VGR runtime configuration.
45#[derive(Clone, Debug)]
46pub struct VgrConfig {
47    /// Completion and verifier targets.
48    pub targets: Targets,
49    /// Authority granted to routing decisions.
50    pub mode: ServingMode,
51    /// Budget for one turn's attempt and verification.
52    pub deadline: Duration,
53    /// Optional live stop controlled by the operator.
54    pub kill_switch: Option<KillSwitch>,
55    /// Local endpoint breaker tuning.
56    pub breaker: BreakerConfig,
57    /// Whether a cheap typing call selects a verification regime.
58    pub task_typing: bool,
59    /// Whether the local tier accepts image content.
60    pub local_supports_images: bool,
61    /// Lets a long agentic run with earlier tool errors commit on a capable-tier
62    /// confirmation once it ends in this many consecutive clean tool results.
63    pub confirmed_recovery_min_clean_tail: Option<u32>,
64    /// Tells the capable tier, once per user turn, that it inherits unverified
65    /// tool-using work.
66    pub agentic_handoff: bool,
67    /// Condenses the local tier's work into a digest at handoff. Requires
68    /// `agentic_handoff`.
69    pub compact_handoff: bool,
70    /// Wall-clock budget for the local tier within one user turn, including the
71    /// client's tool execution.
72    pub local_turn_budget: Option<Duration>,
73}
74
75impl VgrConfig {
76    /// Creates an off-by-default route between local and capable tiers.
77    pub fn new(local: ModelId, cloud: ModelId) -> Self {
78        Self {
79            targets: Targets {
80                local,
81                cloud,
82                judge: None,
83                cloud_judge: None,
84            },
85            mode: ServingMode::Off,
86            deadline: Duration::from_secs(30),
87            kill_switch: None,
88            breaker: BreakerConfig::default(),
89            task_typing: true,
90            local_supports_images: false,
91            confirmed_recovery_min_clean_tail: None,
92            agentic_handoff: false,
93            compact_handoff: false,
94            local_turn_budget: None,
95        }
96    }
97
98    pub(super) fn validate(&self) -> Result<()> {
99        if self.deadline.is_zero() || self.breaker.threshold == 0 {
100            return Err(LibsyError::AlgorithmError {
101                message: "vgr deadline and breaker threshold must be non-zero".into(),
102            });
103        }
104        if let ServingMode::Active { approval } = &self.mode
105            && approval != ACTIVE_APPROVAL
106        {
107            return Err(LibsyError::AlgorithmError {
108                message: format!(
109                    "vgr active mode requires approval attestation {ACTIVE_APPROVAL:?}"
110                ),
111            });
112        }
113        Ok(())
114    }
115
116    pub(super) fn judge(&self) -> &ModelId {
117        self.targets.judge.as_ref().unwrap_or(&self.targets.local)
118    }
119
120    pub(super) fn confirmed_min_clean_tail(&self) -> Option<i32> {
121        self.confirmed_recovery_min_clean_tail
122            .map(|tail| i32::try_from(tail.max(1)).unwrap_or(i32::MAX))
123    }
124}