<!-- llms-explorer concept facts · https://llms-explorer.com/tree/agent-owned-kv-cache-export-import-artifacts/ · pack 2026-10-05 · ~1004 tokens -->

# Agent-owned KV cache export import artifacts

> ds4 stores a bounded tool-call replay map (exact sampled DSML text keyed by unguessable tool IDs) inside the cache files, so a restored session keeps byte-identical tool history.

Parent: [Mac local LLMs: Prompt cache and persistent KV](https://llms-explorer.com/tree/mac-local-llms-prompt-cache-and-persistent-kv/) · 1 facets · 16 facts · page: https://llms-explorer.com/tree/agent-owned-kv-cache-export-import-artifacts/

## Facts

- ds4 stores a bounded tool-call replay map (exact sampled DSML text keyed by unguessable tool IDs) inside the cache files, so a restored session keeps byte-identical tool history. — source: `asserted`
- On ds4 tensor-parallel setups a disk cache load rebuilds the saved token prefix on both ranks, so it is not instant; pipeline loading redistributes saved layer state across its route. — source: `asserted`
- If exact tool replay is unavailable, canonical rendering may force part of the prefix to be rebuilt. — source: `asserted`
- ds4 states cache formats are implementation details (not a stable interchange format); the oMLX 3612 proposal asks for a versioned manifest. These are opposite stances on portability; no source reconciles them. — source: `asserted`
- No source documents the ds4 on-disk header layout beyond naming ds4_kvstore.h and ds4_kvstore.c. — source: `asserted`
- No source found of a local-Mac harness (Claude Code or similar) that owns the export/import lifecycle itself. — source: `asserted`
- ds4 stores a bounded tool-call replay map in its cache files; `--tool-memory-max-ids` bounds it and `--disable-exact-dsml-tool-replay` turns exact replay off for diagnostics. — [source](https://raw.githubusercontent.com/antirez/ds4/main/docs/SERVER.md)
- ds4 `--trace FILE` records prompt rendering, cache decisions, generated text and tool-parser events, and the docs warn traces can contain sensitive content. — [source](https://raw.githubusercontent.com/antirez/ds4/main/docs/SERVER.md)
- ds4 documents its cache formats as implementation details; the header and extension definitions live only in ds4_kvstore.h and ds4_kvstore.c, with model-specific payload handling in ds4.c. — [source](https://raw.githubusercontent.com/antirez/ds4/main/docs/SERVER.md)
- With multiple ds4 slots each slot keeps its own live state and disk is an extra persistence layer, not the only way sessions are retained. — [source](https://raw.githubusercontent.com/antirez/ds4/main/docs/SERVER.md)
- ds4 tensor-parallel cache loading rebuilds the saved token prefix on both ranks and is not an instantaneous restore; pipeline loading redistributes saved layer state over its route. — [source](https://raw.githubusercontent.com/antirez/ds4/main/docs/SERVER.md)
- Shared KV caches expose an API-visible timing side channel that lets one tenant infer another tenant's prompts (SGLang longest-prefix-match scheduling was the NDSS 2025 target). — [source](https://www.ndss-symposium.org/wp-content/uploads/2025-1772-paper.pdf)
- Timing obfuscation (TTFT padding, jitter) is argued to be a poor defense because repeated probing only needs a statistical separation; per-user cache isolation works but forces recompute and duplicate storage across HBM, DRAM and SSD tiers. — [source](https://arxiv.org/html/2508.08438v2)
- SafeKV proposes sharing only entries classified non-private and keeping sensitive ones per user, reporting up to 2.66x throughput over full isolation. — [source](https://arxiv.org/html/2508.08438v2)
- For a single-user local box the cross-tenant timing channel does not apply, but any process able to read the cache directory reads prompt text, so directory permissions are the control (inferred from ds4's "treat the directory as private"). — source: `asserted`
- An agent harness that owns per-session artifacts should key each file by session id plus model file hash, quant, template hash and engine version, and treat a mismatch as a cold start (synthesis of existing-dossier invalidators). — source: `asserted`
