Repository navigation
fix(cron): bind authoritative delivery target into cron worker turns (origin misroute) - #278
Merged
Merged
Conversation
Expose the resolved cron delivery target to worker prompts so nested ACK and heartbeat helpers do not infer a foreign chat from task context.\n\nVerified: scripts/run_tests.sh tests/cron/test_scheduler.py -q (227 passed); related gateway/send suites (172 passed); ruff check passed; mutation removal fails the new worker regression.
Kyzcreig
enabled auto-merge (squash)
July 10, 2026 23:12
Kyzcreig
added a commit
that referenced
this pull request
Jul 26, 2026
…00 summary-role pin) (#431) * vendor(lcm): cherry-pick 9 upstream fixes from hermes-lcm (03b74f8 -> selected from 49e99a2) Upstream hermes-lcm went MIT (LICENSE added 2026-06-26, f7ae61f) — vendoring and cherry-picking now permitted with attribution. Tier-1 picks per /tmp/lcm-refresh-out/CHERRY-PICK-LIST.md, code-only (their tests/docs/changelog excluded; our vendored copy carries no tests dir — coverage rides tests/context_engine/): #263 preserve source lineage after long sessions #264 perf: aggregate DAG status stats #265 harden externalized payload durability #269 preserve raw session ownership across compression rollover #278 avoid payload integrity false positives from log examples #280 pin summary role to user after system anchor (Anthropic HTTP 400) <- highest value #285 make context engine deepcopy clone-safe (subagent spawn safety) #282 strip injected context before compaction (+) discard reasoning-only summaries (unclosed <think> = quality bug + prompt leak) All 9 verified clean-apply by the refresh-analysis worker on a simulated copy of our tree; re-applied here onto fork/main. * test(compaction): regenerate in-turn reconcile fixture for the vendored sanitizer The 9 LCM cherry-picks (3c1d61c) add one line to _sanitize_active_context_messages (upstream pick #282, strip injected context before compaction), which moves the fixture's sanitizer_source_sha1 provenance hash and reds test_fixture_sanitizer_provenance_current. Regenerated via the committed generator: python tests/agent/fixtures/gen_inturn_reconcile_fixture.py Diff is the provenance hash ONLY -- messages, compressed, true_kept_count and fresh_tail_count are byte-identical. The new line routes through _preserved_objective_context_content, which returns "" unless a row starts with the preserved-objective prefix, so it is a strict no-op on all 632 fixture rows (verified: 0 rows mutated) and the real sanitizer output is unchanged. Only one of the four hashed functions changed; the other three are byte-identical. Follow-up candidate (not this PR): this provenance test is a change-detector, which AGENTS.md discourages -- it should assert the sanitizer's behaviour (live sanitize(raw_tail) == committed comp tail) rather than pinning its source SHA. --------- Co-authored-by: Kyzcreig <9063726+Kyzcreig@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Sibling of #271, cron path. A cron job with a CORRECT stored origin (deliver=origin, chat_id X) had its agent turn post a status message to a DIFFERENT Discord thread (live incident 2026-07-10 15:32, evidence in task t_37659d3c).
Root cause
Cron execution deliberately carries no HERMES_SESSION_* sender identity (delivery metadata lives in HERMES_CRON_AUTO_DELIVER_* ContextVars). But nothing surfaced the authoritative target to the WORKER TURN itself — so a cron turn that spawns helpers emitting ACKs/status inferred a delivery chat from task text / referenced work, and misrouted.
Fix
_bind_cron_delivery_target_hint(): the scheduler injects the job's stored delivery target (platform/chat_id/thread_id JSON, authoritative) into the cron worker prompt, with explicit instruction that nested status emitters route ONLY there and read the same target from the HERMES_CRON_AUTO_DELIVER_* env in shell commands — never inferring a target from task content.Tests
Cache safety
Prompt-prefix injection happens at job-prompt ASSEMBLY (before the turn starts), not mid-conversation — no cache invalidation of live sessions.