Skip to content

fix(turn-handoff): discard saved handoff at conversation boundaries (C4 backfill) - #1347

Merged
ang-fleet-lander[bot] merged 1 commit into
mainfrom
fix/c4-turn-handoff-session-boundary
Sep 27, 2026
Merged

ang-fleet-lander[bot] merged 1 commit into
mainfrom
fix/c4-turn-handoff-session-boundary

Conversation

@ang-fleet-workers

@ang-fleet-workers ang-fleet-workers Bot commented Sep 27, 2026 •

Copy link
Copy Markdown

FleetReview retro-backfill 2026-09-27, class C4 (authz/ownership/guard bypass), slice 1 of hermes-agent.

Instances fixed (re-verified at HEAD 5a9d284):

Fix: SessionStore deletes the key's handoff wherever it mints or switches the session id (reset_session, switch_session, get_or_create new candidate incl. idle/daily auto-reset). Compression advances through advance_compression_session and is untouched, so the same conversation still resumes after a cut turn.

Tests: tests/gateway/test_turn_handoff_session_boundary.py — 3 of 4 FAIL on base (manual reset, /resume switch, auto-reset); keep-case passes on both. With fix 4/4, plus existing turn_handoff wiring + resume-handoff command tests (23 passed, narrow run).


View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

A turn handoff is keyed by the stable gateway chat key and recorded the
session_id but never checked it on consume. /new, /reset, idle/daily
auto-reset and /resume rotate the session id under the same key, so the
first turn of the next conversation injected the discarded conversation's
request, results and tool re-issue instruction.

SessionStore now deletes the key's handoff wherever it mints or switches the
session id (reset_session, switch_session, get_or_create new candidate).
Compression advances via advance_compression_session and is untouched, so
the same conversation still resumes.

FleetReview retro-backfill C4: hermes-agent#813 agent/turn_handoff.py:425,
agent/turn_context.py:1694.

Verified: tests/gateway/test_turn_handoff_session_boundary.py 3/4 FAIL on
base (keep-case passes), 4/4 pass with fix; turn_handoff wiring +
resume-handoff command tests pass (23 passed).
@ang-fleet-lander

Copy link
Copy Markdown

🤖 merged-by: apollo · lane: kanban-merge-pass · gate: ADVISORY (FleetReview not green for 524a708): fleetreview-advisory-20260927-standing.md · why: t_a2bf7813: Backfill C4 [P1] authz / ownership / guard bypass — 92 instances (hermes-agent 4; Argus off card review (Ace 13:08), CI green

@ang-fleet-lander
ang-fleet-lander Bot added this pull request to the merge queue Sep 27, 2026
Merged via the queue into main with commit 7d803a6 Sep 27, 2026
49 checks passed
@ang-fleet-lander
ang-fleet-lander Bot deleted the fix/c4-turn-handoff-session-boundary branch September 27, 2026 21:54
@ang-fleet-ci-actuators ang-fleet-ci-actuators Bot added the fleetreview:post-merge Ask FleetReview to review this MERGED pull (merge commit vs first parent) label Sep 27, 2026
@ang-prism

ang-prism Bot commented Sep 27, 2026

Copy link
Copy Markdown

FleetReview

Review: post-merge · head 7d803a6f252e · duration 10m 19s
Profile: light (merit: default light: lines 166<800, files 3<1000000, hunks 6<1000000, no hot path) · policy: below-size-and-path-gates
Roster: B-assert-ctx → gpt-6-sol (openai), C-assert-xhigh → claude-code-opus-5-5 (anthropic), G → grok-4.6 (xai), L6 → gpt-6-sol (openai)

Post-merge review (fleetreview:post-merge override): this reviewed the merge commit against its first parent — the bytes that already shipped. It is not a pre-merge gate pass.

profile: light (rule: default light: lines 166<800, files 3<1000000, hunks 6<1000000, no hot path) · round 0 · members: B-assert-ctx, L6, C-assert-xhigh, G · families: anthropic,openai,xai

Confidence: 3/5

Findings

  • P1 agent/turn_handoff.py:367 — Failed discard · agreed: B-assert-ctx (openai)
  • P1 gateway/session.py:5105 — Same-session discard · agreed: B-assert-ctx,C-assert-xhigh (openai, anthropic)

FleetReview provenance · models: B=gpt-6-sol, C=claude-code-opus-5-5, D=grok-4.6 · cost: $1.24 · duration: 10m 16s · rounds: 1 · files examined: 3

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

fleetreview:post-merge Ask FleetReview to review this MERGED pull (merge commit vs first parent)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants