Skip to content

hermes-plugin: fence recalled content, seal session on compress/switch, bound recall timeout - #897

Open
francialisomlimoeiro wants to merge 2 commits into
TencentCloud:feat/serverfrom
francialisomlimoeiro:pr/hermes-plugin-fencing-seal
Open

francialisomlimoeiro wants to merge 2 commits into
TencentCloud:feat/serverfrom
francialisomlimoeiro:pr/hermes-plugin-fencing-seal

Conversation

@francialisomlimoeiro

Copy link
Copy Markdown

What it does

  1. prefetch() wraps recalled context in a <recalled-memory trust=untrusted-historical-data> envelope with a data-not-instructions note; fence tokens inside the payload are neutralised (prompt-injection defence for historical data).
  2. New on_pre_compress() / on_session_switch() seal hooks: drain in-flight sync threads, then end_session so compaction/session rotation never loses uncaptured context; plugin.yaml hook list updated.
  3. client.recall bounded by RECALL_TIMEOUT=5s; seal end_session also bounded (same budget). Prefetch stays fail-open.

Motivation

Recalled memory is historical data that may contain attacker-controlled text; unfenced injection lets it impersonate instructions. Separately, compression/session rotation bypass on_session_end, leaving async captures in flight and the Gateway session unsealed.

Hook contract verification

on_pre_compress(messages) -> str and on_session_switch(new_session_id, *, parent_session_id, reset, rewound, **kwargs) match the upstream hermes-agent agent/memory_provider.py optional-hook signatures exactly (checked against hermes-agent main). Manager-side dispatch exists in agent/memory_manager.py (per-provider exception guards).

Tests

hermes-plugin/memory/memory_tencentdb/tests/test_prefetch_fencing.py — 16 tests (hostile-payload fencing, fail-open, timeout, seal hooks + log line, plugin loadability):

PYTHONPATH=<hermes-agent checkout> python3 -m pytest tests/test_prefetch_fencing.py
# 16 passed

aameobius added 2 commits August 9, 2026 21:20
…h, bound recall timeout

- prefetch() now wraps recalled context in a
  <recalled-memory trust=untrusted-historical-data> envelope with a
  data-not-instructions note; fence tokens inside the payload are
  neutralised (prompt-injection defence for historical data)
- add on_pre_compress() and on_session_switch() seal hooks: drain
  in-flight sync threads, then end_session so compaction/session
  rotation never loses uncaptured context; plugin.yaml hook
  declarations updated
- client.recall bounded by RECALL_TIMEOUT=5s, prefetch stays fail-open
- tests/test_prefetch_fencing.py: hostile-payload fencing, fail-open,
  timeout, seal hooks + log line, plugin loadability (16 tests)
@Maxwell-Code07

Copy link
Copy Markdown
Collaborator

Thanks for your contribution and attention! We will review this PR and get back to you as soon as possible.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants