Skip to content

fix(planning): #148 follow-ups — encoded credential redaction, retry-log flattening, Go scope, distinct headers - #152

Open
ddbaron wants to merge 5 commits into
Agent-Field:mainfrom
ddbaron:fm/sweaf-148-followups-r1
Open

ddbaron wants to merge 5 commits into
Agent-Field:mainfrom
ddbaron:fm/sweaf-148-followups-r1

Conversation

@ddbaron

@ddbaron ddbaron commented Sep 24, 2026

Copy link
Copy Markdown
Contributor

Summary

Follow-up to the four changes requested in the maintainer review of #148. The branch contains only these follow-ups on top of main:

  • Redact encoded credential spellings in planning retry logs. Exact matching missed values escaped as JSON (quotes/backslashes), standard ASCII-escaped JSON for non-ASCII values, HTML-escaped JSON, and URL-encoded forms (%xx, +), including mixed-case percent escapes. Redaction is bounded and longest-first; a value that cannot be encoded still falls back to exact matching so diagnostics never fail the stage.
  • Flatten multiline fatal reasons. The terminal ===== outcome: ... ===== retry-log entry now stays on one physical line.
  • Align Go credential lookup with scout storage. Go resolves planning credentials by RootWorkflowID when RunID is empty, matching Python.
  • Distinguish same-second run headers. A process-local section counter distinguishes repeated same-run-id invocations made within the same second.

Testing

Targeted regression tests pass for encoded redaction, multiline outcomes, credential-scope fallback, and distinct headers in both ports: tests/test_planning_roles_schema_retry.py under Python 3.12, and Go -race tests for internal/roles/planning, internal/harnessx, and internal/hitl. Synthetic harness responses exercise planning through the persisted retry logs, and a pre-fix comparison reproduced the ASCII-JSON leak in the Go path. The full suite was not run.

Limitations

  • CI did not run on the fork branch (fork Actions created no workflow run or check), and upstream CI on this PR is pending. No CI result should be treated as green.
  • Repository-wide Ruff debt is pre-existing and was left untouched.

…try-log reasons

Address the four non-blocking follow-ups from the Agent-Field#148 maintainer review:

- Redaction now also replaces the JSON-escaped body of each scoped
  credential (values containing " or \) and its percent-/form-encoded URL
  spellings, in both ports. Exact matching missed those forms, so an
  echoed credential could still land in the archived retry log.
- The terminal retry outcome and each attempt header flatten multi-line
  failure reasons, so the last physical line stays the greppable
  ===== outcome: ... ===== line.
- Go resolves the credential scope through hitl.ScopeID (RunID, falling
  back to RootWorkflowID), matching where the scout stores when RunID is
  empty, for both harness env injection and retry-log redaction.
- Retry-log run headers carry a monotonic section number so two
  invocations with the same run id in the same second stay distinct.

Regression tests cover encoded spellings, multi-line flattening, the Go
root-scope lookup, and same-second header uniqueness in both ports.
@ddbaron
ddbaron requested a review from AbirAbbas as a code owner September 24, 2026 20:13

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant