Conversation
0c4a482 to
6af89e8
Compare
|
Re-review requested. Closed the remaining per-platform isolation gaps in authorization, persisted Validation: 152 focused gateway tests passed; focused Ruff, diff checks, and SSH signature verification passed. |
6af89e8 to
d8b6490
Compare
|
Rebased the completed isolation fix onto current Validation: 164 focused gateway tests passed; focused Ruff, GitHub Actions for exact head @coderabbitai review Maintainers: please re-review the current head. |
|
@teknium1 @alt-glitch please re-review the current head. |
fix(gateway): honor per-platform session isolation overrides Centralizing resolution in
|
|
Addressed all three points on current head
Validation: 165 existing and new session/resume/config/WhatsApp isolation tests passed; focused Ruff, attribution audit, both diff checks, and all six upstream-range SSH signature checks passed. @teknium1 @alt-glitch please re-review the materially changed current head. |
|
Fixed profile-safe recovery when a per-user session key becomes shared: durable session ownership now wins over the legacy key namespace, while rows owned by another profile remain rejected. Added continuity and cross-profile rejection regressions. Current head e9dde73b6f883100dff930538e5c5e01d26f7c8a preserves the validated patch exactly. Validation: 165 focused tests passed; focused Ruff, diff checks, attribution audit, and all upstream-range commit signatures passed. @teknium1 @alt-glitch please re-review the current head. Actions on this exact SHA are awaiting write-access approval; please approve the workflow runs. |
9e363b6 to
e9dde73
Compare
|
Final disposition on #81207: #84925 is the preferred replacement. It carries #81207’s two session-isolation commits with original authorship preserved, then applies the same effective per-platform policy consistently to authorization, durable |
|
Significant-overlap disposition: #62370 fixes one remaining global group/thread-precedence case inside |
|
Further relationship disposition: #13939 deliberately decouples sender attribution from session isolation by adding a default-on stable |
e9dde73 to
fec7e34
Compare
|
Resolved the contributor-identity exposure at its source. The carried contributor commits now use the verified public GitHub noreply identity, the mapping-only commit and both added mapping files are gone, and the code/test patch is unchanged by range-diff. The stale dirty-worktree blocker came from two upstream mapping filenames that differed only by case; current main deletes both, and this branch now includes that upstream fix. Current head |
fec7e34 to
9cdb7a7
Compare
|
Updated at |
9cdb7a7 to
e736dae
Compare
|
+1 on this shape over #81207: routing every consumer (store, run.py fallback key, sender attribution, session context, Two suggestions from having hit this bug class in production (an iMessage-plugin deployment where
Happy to test a build of this against our deployment. EDIT: Opened the complementary PR for the plugin/out-of-tree gap described above: #99950 — adapters register their declared scope with the session store at acceptance; the registry consult sits above the config fallback, so it composes with this PR whichever merges first. |
|
Final disposition on both suggestions:
No patch change is required on #84925. |
e736dae to
018c8e4
Compare
|
Resolved the current-main conflict in durable profile recovery: single-profile rows remain fenced by the active durable owner, while multiplexed rows now use the requested profile namespace rather than the process-active profile. Added matching/mismatching durable-owner regression coverage. Validation on head @teknium1 @alt-glitch please review this exact head. A write-access maintainer: please approve its pending Actions workflows. |
018c8e4 to
b7bff37
Compare
|
@teknium1 Rebased this PR onto current Every current consumer now resolves the same per-platform policy: store and bare-runner keys, sender attribution, prompt context, live/persisted resume authorization, Discord prospective-thread persistence, and durable recovery. The port also preserves current-main's DM rule by ignoring prospective thread metadata in Discord DMs. All prior feedback remains resolved. #84926 stays dependent and will be restacked instead of duplicating this base. #99950 remains complementary for adapter-declared/plugin scope; runner consumers now consult the real store before the per-platform-config fallback, preserving the intended composition. Durable profile ownership remains here because it is required to recover an isolated row into a shared key without crossing profile boundaries. #62370, #47794, #13939, and #75770 remain separately owned as documented in the body. Validation: 192 focused config/session/resume/Discord-topic tests passed; focused Ruff, compatibility-pointer, attribution, and diff checks pass. Five focused invariants fail on current This head is mergeable. CI, Nix, and Docker are |
b7bff37 to
3219c9f
Compare
|
Rebased onto current upstream main at head 3219c9f. The shared isolation resolver still governs session keys, sender attribution, context, recovery, and resume authorization; the current platform-event extraction is integrated without widening the patch. Validation: 185 focused tests passed; focused Ruff, Windows-footgun, plugin-compat, attribution, and diff checks passed. The preserved co-author remains attributed. @teknium1 @alt-glitch please review this exact head. A write-access maintainer: please approve its Actions workflows. |
SessionStore derived group_sessions_per_user / thread_sessions_per_user from the global gateway config only, so a plugin / out-of-tree platform adapter that declares its own isolation in config.extra was silently ignored — it has no entry in config.platforms for the per-platform fixes (NousResearch#81207 / NousResearch#84925) to read. Production incident: an iMessage-plugin family group chat with group_sessions_per_user=false split into per-user sessions and the agent answered one member with another's task thread. Add the missing seam: adapters register their resolved scope with the store when their handlers are wired (before connect(), where Telegram polling / webhooks go inbound-reachable), and every key derivation and every guard that must agree with key shape resolves through it before the config defaults. - SessionStore.register_platform_session_scope / resolve_session_scope, keyed (profile, platform) so multiplexed profiles can't leak overrides; _generate_session_key resolves through it. Registry lives behind the store's _lazy() helper like its other optional maps. - GatewayAdapterLifecycleMixin._register_adapter_session_scope runs from _wire_adapter_handlers (primary + secondary via _configure_profile_ adapter). A missing / explicit-None flag is seeded from the OWNING gateway config (a secondary profile's, not the primary's) and written back to config.extra so adapter-side key derivation agrees; the instantiate-time primary-config seed is deleted. - GatewayRunner._resolve_session_scope_for is the one runner-side read of isolation flags: _session_key_for_source's no-store fallback, the inbound sender-attribution gate, and the /resume IDOR guards use it; build_session_context takes session_store so the agent-facing shared_multi_user_session flag agrees with the key. - One key owner everywhere: /undo evicts under _session_key_for_source, the voice-handoff destination uses it too (_handoff_session_key deleted; dest.source already carries the queuing profile), and Slack's thread / rehydration keys resolve through the store under the adapter's owning profile. - config_session_scope(config) owns the config-default pair. Tests: registered override beats the global default, profile keying (multiplexed), context flag follows scope, owning-profile seeding, the IDOR guard flipping with the registered scope + runner key byte-identical to the store key (real store), and a secondary Slack bot's thread keys following its own profile's registration. Composes with NousResearch#84925 (registry -> platform-config -> defaults). Adjacent: NousResearch#81860's handoff destination-shape ownership is unchanged. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Lqr7yMugdYt53YxrszjnSG
9c50a47 to
24325b1
Compare
7760e0a to
c10a6df
Compare
|
Current-main compatibility is resolved on head |
c10a6df to
ed7922f
Compare
Co-authored-by: dhruv kejriwal <96516827+dhruvkej9@users.noreply.github.com>
ed7922f to
c3f3351
Compare
What does this PR do?
Makes every current gateway consumer honor the same effective per-platform
group_sessions_per_userandthread_sessions_per_userpolicy.Per-platform overrides now survive config loading and flow through session keying, bare-runner fallback keying, shared-session sender attribution, prompt context, live and persisted
/resumeauthorization, Discord prospective-thread persistence, and durable profile-safe recovery. Routing still falls back to the global gateway defaults when no platform override exists.Lineage and related work
Supersedes #81207 while preserving the original isolation contribution from #81208 with public co-author attribution. #84926 remains stacked on this contract for its separate authorized WhatsApp group-observation behavior and will be restacked after this base PR.
is_shared_multi_user_session.slash_commands_session.pyownership.Type of Change
Changes Made
extramap, including extra-only blocks, while retaining top-level bridged-key precedence.SessionStore, runner fallback, sender attribution, context construction, and resume authorization through that policy.profile_nameownership during recovery; use the requested namespace in multiplex mode and the active owner in single-profile mode.config_loader.py,run_inbound.py,session_recovery.py, andslash_commands_session.py.Review feedback disposition
All prior findings and suggestions remain explicitly resolved:
build_session_context()calls the same per-platform resolver used by keying and authorization; no inline isolation lookup remains.No maintainer review or inline finding is pending.
How to Test
./scripts/run_tests.sh tests/gateway/test_config.py tests/gateway/test_session.py tests/gateway/test_resume_command.py tests/gateway/test_run_progress_topics.py tests/gateway/test_session_identity_restore.pyThe five focused config/session invariants fail against current upstream
mainwith dropped nested config, divergent per-user keys, mismatched prospective-thread persistence, and profile-unsafe recovery; they pass on this head.Verification
git diff --checkpassed.Checklist
Code
Documentation & Housekeeping