fix(tools): always redact durable process receipts

This commit is contained in:
Teknium
2026-09-07 02:34:52 -07:00
parent 0522ae934e
commit 1735ccde44
5 changed files with 14 additions and 5 deletions
@@ -152,6 +152,8 @@ def test_receipts_are_bounded_redacted_and_session_scoped(tmp_path, monkeypatch)
from tools import process_registry_results as receipts
from tools.process_registry import MAX_OUTPUT_CHARS, ProcessRegistry, ProcessSession
from agent import redact
monkeypatch.setattr(redact, "_REDACT_ENABLED", False)
monkeypatch.setattr(receipts, "MAX_RETAINED_RESULTS", 2)
secret = "sk-" + "aB2cD3eF4gH5iJ6kL7mN8pQ9rS0tU1vW2xY3zA4bC5dE6fG7"
from gateway.session_context import scoped_current_session_id
+5 -2
View File
@@ -46,12 +46,15 @@ def _result_paths():
def save_completed_result(session) -> None:
from tools.process_registry import MAX_OUTPUT_CHARS, _redact_process_result
from agent.redact import redact_sensitive_text, redact_terminal_output
from tools.process_registry import MAX_OUTPUT_CHARS
with session._lock:
record = {key: getattr(session, key) for key in _RESULT_FIELDS}
record["output"] = session.output_buffer[-MAX_OUTPUT_CHARS:]
_redact_process_result(record)
# Live-output opt-out must not persist raw credentials in durable receipts.
record["output"] = redact_terminal_output(record["output"], record["command"], force=True)
record["command"] = redact_sensitive_text(record["command"], code_file=True, force=True)
directory = get_hermes_home() / "logs" / "process-results"
try:
directory.mkdir(mode=0o700, parents=True, exist_ok=True)
@@ -234,7 +234,9 @@ process query methods load retained snapshots without adopting PIDs or enqueuing
notifications. Reads require the commissioning durable session or its compression
continuation; knowing a handle alone does not authorize a retained result read.
The registry captures that owner before starting any output reader, including on
CLI and non-notifying processes. Receipt retention is bounded by age and count.
CLI and non-notifying processes, and preserves the producer's profile context in
reader threads. Receipt redaction is forced independently of live-output opt-out;
retention is bounded by age and count.
## Concurrency
+2 -1
View File
@@ -242,7 +242,8 @@ also includes retained results for the current task or conversation.
Hermes keeps the newest **64 completed results**, for up to **7 days after
completion**, under `logs/process-results/` in the profile's Hermes home. Each
receipt contains at most the existing rolling **200,000-character output tail**,
with the same secret redaction as terminal output. Receipts expire on subsequent
with terminal secret-redaction rules always applied, even when live-output
redaction is disabled. Receipts expire on subsequent
result reads or writes. Recovery does not rerun commands or replay completion
notifications. This preserves work that finished while the parent was alive;
it does not keep unfinished children alive after a timeout or crash.
@@ -209,7 +209,8 @@ PTY 模式(`pty=true`)可启用 Codex 和 Claude Code 等交互式 CLI 工
每个配置档案在 `logs/process-results/` 下最多保留最近 **64 个已完成结果**,
自完成起保存不超过 **7 天**。每份记录最多包含滚动输出末尾的 **200,000 个字符**,
使用与终端输出相同的敏感信息脱敏规则。后续读取或写入结果时会清理过期记录。
始终使用终端的敏感信息脱敏规则,即使实时输出的脱敏功能已关闭。
后续读取或写入结果时会清理过期记录。
恢复结果不会重新运行命令,也不会重放完成通知。这仅保护父进程存活期间已经
完成的工作,不保证未完成的子进程在超时或崩溃后继续运行。