fix(yuanbao): preserve archived history on recall redaction

Sibling-site fix for #80216: yuanbao recall redaction also calls
rewrite_transcript() and was subject to the same archived-history
data loss when active_only defaulted to False. Pass active_only=True
at both yuanbao call sites — load_transcript only returns active
rows, so the redacted content is in the active set and the archived
pre-compaction history should survive the rewrite.

Also drops the stale 'callers that mean to purge (e.g. yuanbao
recall redaction) keep the default' note from the rewrite_transcript
docstring — no caller intentionally purges archived rows.
This commit is contained in:
kshitij
2026-08-07 13:46:11 +05:30
committed by kshitij
parent 30c1421acf
commit 2d9b809ff0
2 changed files with 3 additions and 4 deletions
+2 -2
View File
@@ -1150,7 +1150,7 @@ class RecallGuardMiddleware(InboundMiddleware):
if entry.get("role") == "user" and entry.get("content") == recalled_text:
entry["content"] = cls._REDACTED
try:
store.rewrite_transcript(sid, transcript)
store.rewrite_transcript(sid, transcript, active_only=True)
logger.info("[%s] Recall redact: session %s", adapter.name, session_key[:30])
except Exception as exc:
logger.warning("[%s] Recall redact failed: %s", adapter.name, exc)
@@ -1210,7 +1210,7 @@ class RecallGuardMiddleware(InboundMiddleware):
if target is not None:
target["content"] = cls._REDACTED
try:
store.rewrite_transcript(sid, transcript)
store.rewrite_transcript(sid, transcript, active_only=True)
logger.info("[%s] Recall: redacted msg_id=%s (%s)", adapter.name, recalled_id, branch_label)
except Exception as exc:
logger.warning("[%s] Recall: rewrite_transcript failed: %s", adapter.name, exc)
+1 -2
View File
@@ -3379,8 +3379,7 @@ class SessionStore:
compaction history that archive_and_compact() keeps on disk
(#38763). Callers rewriting the live transcript of a session that
may carry archived rows must pass ``active_only=True`` so only the
live rows are replaced; callers that mean to purge (e.g. yuanbao
recall redaction) keep the default.
live rows are replaced.
Returns ``True`` when the write lands (or there is no DB to write to)
and ``False`` when the canonical write fails. Most callers can ignore