Skip to content

fix(review): bind background_review origin for same-session injection turns - #107853

Open
kokhlo wants to merge 2 commits into
NousResearch:mainfrom
kokhlo:fix/background-review-same-session-write-origin
Open

kokhlo wants to merge 2 commits into
NousResearch:mainfrom
kokhlo:fix/background-review-same-session-write-origin

Conversation

@kokhlo

@kokhlo kokhlo commented Sep 11, 2026 •

Copy link
Copy Markdown

Fixes #107850

Root cause

When a review prompt ("Review the conversation above...") is injected into the foreground agent's loop without forking (v0.21 same-session injection path), the foreground agent._memory_write_origin stayed at the default "assistant_tool", causing is_background_review() to return False and bypassing the curator / skill-authoring gates that rely on it (user-owned-skills guard, read-before-write, skill ledger [auto] tag, approval staging).

Fix

turn_context.py:891 already binds agent._memory_write_origin onto the write-origin ContextVar at turn start. This PR adds detection for review-prompt injection: when the foreground agent receives a user message starting with "Review the conversation above", override the origin to "background_review" for the duration of that turn.

Both the fork path (build_cache_parity_fork already sets review_agent._memory_write_origin = "background_review") and the same-session injection path now share the same origin, so all guards fire correctly.

Evidence

Before: same-session review writes landed in ~/.hermes/skills/ without curator/gate review (issue evidence: 2026-09-10 18:08–18:12, platform=cli, skill_manage create passed the gate).

After: is_background_review() returns True for both paths; skill guards apply.

Test coverage

✓ 23 tests in test_turn_context.py (turn prologue, existing paths)
✓ 4 tests in test_skill_provenance.py (origin ContextVar)
✓ 10 tests in test_background_review_memory_scope.py (fork path, attended/unattended)
✓ 2 NEW tests in test_same_session_review_origin.py (injection detection logic)

39 tests passed — fork path, normal path, and injection path all verified.

… turns (NousResearch#107850)

When a review prompt ("Review the conversation above...") is injected
into the foreground agent's loop without forking (v0.21 same-session
injection path), the foreground agent's _memory_write_origin stayed at
the default "assistant_tool", causing is_background_review() to return
False and bypassing the curator/skill guards.

Detect the review prompt prefix at turn start and override the origin
ContextVar to "background_review" for the duration of that turn, so
skill_manage and memory guards apply correctly on both fork and inline
paths.
…earch#107850)

Unit test for the review-prompt detection logic added in turn_context.py.
Confirms that messages starting with 'Review the conversation above'
trigger the background_review origin override when the agent is in
foreground assistant_tool mode, while preserving fork origins and leaving
normal user messages unchanged.
@alt-glitch alt-glitch added type/bug Something isn't working P3 Low — cosmetic, nice to have comp/agent Core agent runtime: loop, agent_init, prompt builder, context-compression, responses endpoint tool/skills Skills system (list, view, manage) labels Sep 11, 2026
@alt-glitch

Copy link
Copy Markdown

This was generated by AI during triage.

Related: #107850 (the issue), #52849 (merged: sets _memory_write_origin='background_review' on the curator fork), #61088 (pre-seeds the origin before AIAgent.__init__).

Note for reviewers: on current main every review path (_run_review_in_thread -> _run_review_fork -> build_cache_parity_fork, and agent/curator.py) runs in a fork that already carries _memory_write_origin='background_review'; the fork inherits agent.platform and shares the parent session_id, which matches the platform=cli / same-session-id log lines cited in the issue. A same-session non-fork review path was not found. Sniffing the Review the conversation above prefix in build_turn_context would also tag a real user's turn as a background review if they type that phrase.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

comp/agent Core agent runtime: loop, agent_init, prompt builder, context-compression, responses endpoint P3 Low — cosmetic, nice to have tool/skills Skills system (list, view, manage) type/bug Something isn't working

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Background Review same-session injection turn doesn't set write_origin — is_background_review() returns False, breaking user-owned skills guards

2 participants