fix(a2a): preserve inbound message in task writeback - #4
Merged
Merged
Conversation
Collaborator
Author
|
CI classification: the fork workflows failed before execution. Each failing detector/OSV job reports an empty runner name, zero steps, and no logs; all code/lint/test jobs were skipped. This is infrastructure red, not a candidate test failure. Executed evidence on exact base
|
RuniThomsen
added a commit
that referenced
this pull request
Aug 23, 2026
…s687 fix(a2a): preserve inbound message in task writeback
RuniThomsen
pushed a commit
that referenced
this pull request
Sep 24, 2026
… fingerprint never authorizes a signal NousResearch#111617 review (andrexibiza P1 #3/#4, kvnloo nit): - worker_started_at persisted only gateway.status.get_process_start_time(): on Linux that is /proc/<pid>/stat field 22, clock ticks since THIS boot. The threat is a row surviving a reboot, and that counter does not, so an unrelated process on a later boot with the same PID and the same tick value passed _start_times_agree(). The fingerprint is now "<gateway.drain_control.current_instantiation_epoch()>|<start>" (boot_id + PID-1 start, the witness the drain marker already uses); both halves must match. Integer values on rows written before this change keep the start-time-only comparison. - A failed capture persisted NULL, which _pid_recycled treats as the legacy pre-fingerprint row and falls back to bare PID existence - a new spawn silently recreated the NousResearch#89614/ NousResearch#99558 kill authority. A failed capture now persists UNVERIFIED_WORKER_FINGERPRINT: the claim is held while the PID is live (never released beside it, never SIGTERM/SIGKILLed by timeout, stale-claim, manual reclaim, archive or the terminal reaper) and reclaimed once it is gone. NULL stays legacy-only. - Every tasks UPDATE that nulls worker_pid nulls worker_started_at too (archive_task and the reclaim/timeout/reopen paths): the fingerprint is part of the kill-authority tuple and must not outlive its pid. Live (real sleeper child): reboot-shaped row (same pid, same tick, other boot id) -> reclaimed to ready, child untouched; matching fingerprint -> SIGTERM delivered, exit -15. tests/hermes_cli/test_kanban_worker_pid_fingerprint.py: +2 hostile tests, both red on base. Not changed: the check-then-act window between _pid_recycled and kill (kvnloo P2) is real but needs pidfd_open/pidfd_send_signal (Linux 5.3+) to close atomically; left as the documented residual of "never kills a DETECTED recycled PID".
RuniThomsen
pushed a commit
that referenced
this pull request
Sep 24, 2026
…as a died link The exit-notify wrap reported every receive-loop exception at ERROR with a traceback, including the ConnectionClosedOK that follows our own CLOSE frame in disconnect(). Gate on the adapter's _running flag (published through the WS thread-local next to on_link_up): a live link's death stays ERROR, an intentional shutdown logs at DEBUG. Live pass side-effect #4 on NousResearch#113662.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Messageas the receiver-ownedTask.historychildreferenceTaskIds, governed metadata, extensions, parts, and correlation IDstaskIdwithout mutating the caller requestSendMessagereceipts and the firstSendStreamingMessageTask frameWhy
NousResearch#727 requires one seat dispatch to produce/attach a visible task row without a second write. The sender-side coupling needs the receiver's first receipt to carry the authoritative Task plus the original Message as its child. Hermes previously minted the Task but discarded that Message from
Task.history.Verification
157 passed, 18 deselectedfortest_a2a_plugin.py+test_a2a_phase23.py1 passedpy_compileandgit diff --checkpassd048b78480because that test still expects holdingcompletedinstead of the new non-holdingworkingreceipt