hermes-plugin: fence recalled content, seal session on compress/switch, bound recall timeout - #897
Open
francialisomlimoeiro wants to merge 2 commits into
Conversation
added 2 commits
August 9, 2026 21:20
…h, bound recall timeout - prefetch() now wraps recalled context in a <recalled-memory trust=untrusted-historical-data> envelope with a data-not-instructions note; fence tokens inside the payload are neutralised (prompt-injection defence for historical data) - add on_pre_compress() and on_session_switch() seal hooks: drain in-flight sync threads, then end_session so compaction/session rotation never loses uncaptured context; plugin.yaml hook declarations updated - client.recall bounded by RECALL_TIMEOUT=5s, prefetch stays fail-open - tests/test_prefetch_fencing.py: hostile-payload fencing, fail-open, timeout, seal hooks + log line, plugin loadability (16 tests)
Collaborator
|
Thanks for your contribution and attention! We will review this PR and get back to you as soon as possible. |
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What it does
prefetch()wraps recalled context in a<recalled-memory trust=untrusted-historical-data>envelope with a data-not-instructions note; fence tokens inside the payload are neutralised (prompt-injection defence for historical data).on_pre_compress()/on_session_switch()seal hooks: drain in-flight sync threads, thenend_sessionso compaction/session rotation never loses uncaptured context;plugin.yamlhook list updated.client.recallbounded byRECALL_TIMEOUT=5s; sealend_sessionalso bounded (same budget). Prefetch stays fail-open.Motivation
Recalled memory is historical data that may contain attacker-controlled text; unfenced injection lets it impersonate instructions. Separately, compression/session rotation bypass
on_session_end, leaving async captures in flight and the Gateway session unsealed.Hook contract verification
on_pre_compress(messages) -> strandon_session_switch(new_session_id, *, parent_session_id, reset, rewound, **kwargs)match the upstream hermes-agentagent/memory_provider.pyoptional-hook signatures exactly (checked against hermes-agentmain). Manager-side dispatch exists inagent/memory_manager.py(per-provider exception guards).Tests
hermes-plugin/memory/memory_tencentdb/tests/test_prefetch_fencing.py— 16 tests (hostile-payload fencing, fail-open, timeout, seal hooks + log line, plugin loadability):