Skip to content

fix(mattermost): resolve thread follow-ups and tool output leaks (#4221) - #4230

Open
devorun wants to merge 1 commit into
NousResearch:mainfrom
devorun:patch-19
Open

fix(mattermost): resolve thread follow-ups and tool output leaks (#4221)#4230
devorun wants to merge 1 commit into
NousResearch:mainfrom
devorun:patch-19

Conversation

@devorun

@devorun devorun commented Mar 31, 2026

Copy link
Copy Markdown
Contributor

What does this PR do?

Fixes #4221 — Mattermost threaded conversations broken in two ways.

1. Tool/reasoning output leaking to main channel
The send method now falls back to metadata.get("thread_id") when reply_to is not set, using it as root_id in the payload. All tool and processing output now stays inside the thread.

2. Follow-up messages ignored inside threads
Added _known_threads set to the adapter. When the bot posts into a thread, it registers that thread's ID. In _handle_ws_event, incoming messages from known threads bypass the @mention gate and continue the conversation naturally.

Related Issue

Fixes #

Type of Change

  • 🐛 Bug fix (non-breaking change that fixes an issue)
  • ✨ New feature (non-breaking change that adds functionality)
  • 🔒 Security fix
  • 📝 Documentation update
  • ✅ Tests (adding or improving test coverage)
  • ♻️ Refactor (no behavior change)
  • 🎯 New skill (bundled or hub)

Changes Made

How to Test

Checklist

Code

  • I've read the Contributing Guide
  • My commit messages follow Conventional Commits (fix(scope):, feat(scope):, etc.)
  • I searched for existing PRs to make sure this isn't a duplicate
  • My PR contains only changes related to this fix/feature (no unrelated commits)
  • I've run pytest tests/ -q and all tests pass
  • I've added tests for my changes (required for bug fixes, strongly encouraged for features)
  • I've tested on my platform:

Documentation & Housekeeping

  • I've updated relevant documentation (README, docs/, docstrings) — or N/A
  • I've updated cli-config.yaml.example if I added/changed config keys — or N/A
  • I've updated CONTRIBUTING.md or AGENTS.md if I changed architecture or workflows — or N/A
  • I've considered cross-platform impact (Windows, macOS) per the compatibility guide — or N/A
  • I've updated tool descriptions/schemas if I changed tool behavior — or N/A

For New Skills

  • This skill is broadly useful to most users (if bundled) — see Contributing Guide
  • SKILL.md follows the standard format (frontmatter, trigger conditions, steps, pitfalls)
  • No external dependencies that aren't already available (prefer stdlib, curl, existing Hermes tools)
  • I've tested the skill end-to-end: hermes --toolsets skills -q "Use the X skill to do Y"

Screenshots / Logs

@alt-glitch alt-glitch added type/bug Something isn't working P2 Medium — degraded but workaround exists comp/gateway Gateway runner, session dispatch, delivery labels May 2, 2026

@teknium1 teknium1 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for addressing both aspects of Mattermost thread usability. The thread-local delivery half has since landed on current main, but the unmentioned-follow-up behavior remains a distinct salvage target.

Problems

  • gateway/platforms/mattermost.py:104 adds an unbounded, never-expiring _known_threads set. Every remembered root permanently bypasses the channel mention gate.
  • gateway/platforms/mattermost.py:270 forwards reply_to directly as root_id; current main resolves a reply to its actual Mattermost root in plugins/platforms/mattermost/adapter.py:326-340.
  • The branch silently changes the documented MATTERMOST_REQUIRE_MENTION=true behavior (website/docs/reference/environment-variables.md:433) and supplies no regression tests.

Suggested changes

  • Port the remaining sticky-follow-up behavior to plugins/platforms/mattermost/adapter.py; the legacy target path was removed by af973e407.
  • Use bounded/explicit sticky ownership and the current root-resolution helper, with tests for expiry and nested replies.

Automated hermes-sweeper review.

self._SEEN_MAX = 2000
self._SEEN_TTL = 300 # 5 minutes

self._known_threads: set[str] = set()

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This set is never bounded or expired, so a long-lived gateway retains every thread root and permanently bypasses mention gating for it. Please use bounded ownership/expiry semantics rather than process-lifetime membership.

formatted = self.format_message(content)
chunks = self.truncate_message(formatted, MAX_POST_LENGTH)

thread_root = reply_to

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

reply_to may be a reply post rather than the Mattermost thread root. Resolve it before assigning root_id; current main does this through _resolve_root_id() to avoid invalid-root errors.

@teknium1 teknium1 added sweeper:risk-message-delivery Sweeper risk: may drop, duplicate, misroute, or suppress messages sweeper:risk-compatibility Sweeper risk: may break existing users, config, migrations, defaults, or upgrades sweeper:blast-moderate Sweeper blast radius: moderate — a subsystem or single platform labels Jul 12, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

comp/gateway Gateway runner, session dispatch, delivery P2 Medium — degraded but workaround exists sweeper:blast-moderate Sweeper blast radius: moderate — a subsystem or single platform sweeper:risk-compatibility Sweeper risk: may break existing users, config, migrations, defaults, or upgrades sweeper:risk-message-delivery Sweeper risk: may drop, duplicate, misroute, or suppress messages type/bug Something isn't working

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Bug]: Mattermost threaded conversations ignore follow-ups and leak tool output to the main channel

3 participants