91f4cf22e1
Operator reported the new Heretic-300 gen seat "sends CoT but never completes
the turn" through Lobe. Diagnosed; not yet fixed (the fix changes gen's
semantics, so it is the operator's call).
The Qwen3.8 chat template appends a pre-closed <think>\n\n</think>\n\n when
enable_thinking is false. The h300 model opens a fresh <think> anyway and never
closes it. Because the prompt already closed the block, vLLM's qwen3 reasoning
parser is not in reasoning state, so the tag passes through as ordinary text --
reasoning_content empty, reasoning_tokens 0, and the whole reasoning-plus-answer
blob lands in content. Lobe then correctly treats the unterminated tag as
still-thinking and renders no answer. The client and the serving stack are both
behaving correctly; the model is not.
The trigger is TEMPERATURE, not presence_penalty (n=12 per arm):
temp 0.7, pp 1.5 (current gen) 4/12
temp 0.7, pp 0.0 4/12
temp 0.7, pp 0.5 3/12
temp 0, pp 1.5 0/12
That falsifies the standing hypothesis, recorded in the litellm config comment
and in the operator's own 2026-08-16 note, that presence_penalty 1.5 is the
first dial to move. It is not this bug's cause.
It also explains the blast radius: only the two temp-0.7 aliases leak, `gen`
and `summarizer-large`. summarizer, classifier, image-judge and qwen-image-bench
all run at temp 0 and are clean, so nevermore's summarizer path is unaffected.
Candidate fix, validated n=30 over 4 prompt types plus a 3-turn conversation:
chat_template_kwargs {enable_thinking: true, reasoning_effort: low} takes 8/30
leaks to 0/30, at ~+27% completion tokens and a ~3% empty-content residual.
The tell appears in eval_coldfusion_h300.json and in none of the aeon, heresy,
mixed or w4a16 evals, so it is new with this build -- but L35 was never evaled,
so this does not separate a Cold-Fusion base trait from a Heretic-300
abliteration artifact.
Reproducers and the full method land in bench/think-leak/. Note in particular
that the 7/7 alias smoke test run at cutover structurally could not catch this:
trivial prompts never invite reasoning, so they never sample the leaking token.
24 lines
1.6 KiB
Python
24 lines
1.6 KiB
Python
import json, urllib.request, collections
|
|
P="A farmer has 17 sheep. All but 9 run away. He buys twice as many as he has left, then sells 4. How many now? Explain."
|
|
BASE={"temperature":0.7,"top_p":0.8,"presence_penalty":1.5,"top_k":20,"min_p":0.0,"repetition_penalty":1.0}
|
|
def run(label, ctk, n=12):
|
|
t=collections.Counter()
|
|
for i in range(n):
|
|
body={"model":"qwen3.8-27b-uncensored","messages":[{"role":"user","content":P}],
|
|
"max_tokens":2048,"chat_template_kwargs":ctk}; body.update(BASE)
|
|
req=urllib.request.Request("http://10.250.50.54:8015/v1/chat/completions",
|
|
data=json.dumps(body).encode(),headers={"Content-Type":"application/json"})
|
|
d=json.loads(urllib.request.urlopen(req,timeout=300).read().decode(),strict=False)
|
|
c=d["choices"][0]; cont=c["message"].get("content") or ""; reas=c["message"].get("reasoning_content") or ""
|
|
t["n"]+=1
|
|
if "<think>" in cont: t["LEAK"]+=1
|
|
if not cont.strip(): t["EMPTY"]+=1
|
|
if reas: t["reasoning_captured"]+=1
|
|
t["ctok_total"]+=d.get("usage",{}).get("completion_tokens") or 0
|
|
if c.get("finish_reason")!="stop": t["finish_"+str(c.get("finish_reason"))]+=1
|
|
n_=t["n"]
|
|
print(f" {label:<44} n={n_} LEAK={t.get('LEAK',0)} EMPTY={t.get('EMPTY',0)} reas_captured={t.get('reasoning_captured',0)} avg_ctok={t['ctok_total']//n_}")
|
|
run("A: enable_thinking=false (CURRENT gen)", {"enable_thinking":False})
|
|
run("B: enable_thinking=true + effort=low", {"enable_thinking":True,"reasoning_effort":"low"})
|
|
run("C: enable_thinking=true + effort=medium", {"enable_thinking":True,"reasoning_effort":"medium"})
|