feat(redact): split OPF into a cached scan and a model-free apply

Commit

peyton-alt1w ago

BatchBytesWithPrivacyFilter ran the model and applied its spans in one call, so whoever needed redacted output had to wait for inference. Split it:

  • ScanBlobsWithPrivacyFilter runs OPF over blobs with no cache entry and stores, per blob, the spans for each prose leaf, keyed by the blob's object hash and the category set. Entries hold leaf hashes and offsets, no text.
  • ApplyCachedPrivacyFilter redacts from the cache alone and returns ErrOPFScanPending unless every blob and every leaf is covered.
  • BatchBytesWithPrivacyFilter keeps its behavior and shares the same leaf collection and scan code.

Model calls are split into chunks of at most 1 MiB of leaf text, each with a deadline scaled to its size (floor 30s, ceiling 3h) instead of a fixed 30s, and the batch input ceiling rises to 256 MiB. The throughput and bug investigation docs these numbers come from are included.

Co-Authored-By: Claude Opus 5.5 (1M context) noreply@anthropic.com Entire-Checkpoint: 01M3SPBMJ9H9KF399NA898R42W

Checkpoints

Fix OPF Byte Cap Scope Per Checkpoint Ref

Claude CodeOpus 5.5
View session
Checkpoint 1