Skip to content

Keep session evidence and record cost for every backend - #457

Merged
renmengye merged 4 commits into
mainfrom
feat/session-capture
Oct 3, 2026
Merged

renmengye merged 4 commits into
mainfrom
feat/session-capture

Conversation

@renmengye

Copy link
Copy Markdown
Member

Keeps the evidence of every author and judge session, and records token usage and cost for every backend.

Why

A session's real record was lost: the kernel kept only the harness's stdout (Claude Code's final JSON, Codex exec events, Hermes stdout), the delivered prompt was rendered in memory and never saved, and the harness's native session log lived in the run's HOME, deleted about a day after the run ended. Codex and Hermes sessions also reported a cost of $0, so resource use was wrong for two of three backends. Analysing runs after the fact (what an agent was told, what it did, what it cost) needs all three.

What changes

  • Delivered prompt: the exact prompt for each fresh and resumed session is saved next to its capture, with the capture's known-secret redaction.
  • Native log: at session end the harness's own log (Claude Code session JSONL, Codex rollout file, Hermes trajectory export) is copied out of the session HOME into the run's state directory, outside the author's writable space. Resolved by session id, never by "newest file"; redacted; size-capped with truncation recorded; a missing log is recorded, never an error. Copies hold back an unresolved tail so a secret straddling the cap cannot leave a prefix behind. Directory walks are bounded in depth, entries and time.
  • Usage and cost: tokens (input, cached input, output, as each backend reports them) for every backend. Dollars: Claude Code's reported figure, otherwise an operator price table per model; with no price, cost is recorded as unknown, distinct from an explicit zero (a self-hosted model). Partial usage leaves the cost unknown.
  • Session record: a small JSON per session with backend, model, session id, times, turns, tokens, cost, and paths plus SHA-256 of the capture, prompt and native log, and the brief hash.
  • Pre-existing fix: Codex's last-message file is read with the bounded no-follow reader, so a planted symlink cannot pull a host file into the report.

Capture failures never fail or delay the session. Evidence is never committed or published (SECURITY.md).

Compatibility

Run records gain fields; readers tolerate their absence. Legacy fixture tests/fixtures/session_cost_legacy.json (a record with numeric zero cost) reads unchanged. Upgrading: line in CHANGELOG: no action; old runs show cost as recorded.

Verification

Gate: ruff check, ruff format --check, mypy, pytest (2954 passed, 10 skipped). Per-backend usage parsers tested on synthetic fixtures; redaction across the cap boundary mutation-checked. Live check on a real deployment (fresh, resumed and timed-out sessions per backend) still to do.

Built by Codex (gpt-5.6); reviewed by Codex (read-only pass) and Claude.

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Round 1 — reviewed head 895f7d25 — reviewer summarizer:hermes/gpt-5.6-terra over coverage+credentials+deployment+general+lifecycle+prose.

terra
Advisory findings from outerloop — the code owner decides. Reply to disagree; the outerloop:no-review label opts this PR out.

Verdict: 3 blocking, 1 advisory.

4 findings attached to the lines below.

Three blocking findings: native evidence can retain Vertex ADC credentials, failed Codex invocations can be reported with partial cost, and author-controlled sidecars can forge session-cost totals. One advisory correctness finding: resumed Hermes session records hash the original brief rather than the rehydrated delivered prompt. Rejected: none; the coverage and lifecycle scans reported no findings.

Comment thread src/outerloop/session_evidence.py Outdated
Comment thread src/outerloop/session_evidence.py Outdated
Comment thread src/outerloop/session_evidence.py Outdated
Comment thread src/outerloop/session_evidence.py Outdated
…riced, persisted kernel-owned totals, Hermes delivered-prompt hash

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Round 1 — reviewed head 5e4f1896 — reviewer hermes/gpt-5.6-terra.

terra
Advisory findings from outerloop — the code owner decides. Reply to disagree; the outerloop:no-review label opts this PR out.

Verdict: no defects found.

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Round 2 — reviewed head 1b560fb1 — reviewer hermes/gpt-5.6-terra.

terra
Advisory findings from outerloop — the code owner decides. Reply to disagree; the outerloop:no-review label opts this PR out.

Verdict: 1 blocking, 1 advisory.

2 findings attached to the lines below.

Failed Hermes sessions can be recorded with a priced cost, and credential capture errors can abort a harness run.

Comment thread src/outerloop/session_evidence.py Outdated
Comment thread src/outerloop/session_evidence.py

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Round 3 (re-run on the same head) — reviewed head 1b560fb1 — reviewer hermes/gpt-5.6-terra.

terra
Advisory findings from outerloop — the code owner decides. Reply to disagree; the outerloop:no-review label opts this PR out.

Verdict: 1 blocking, 0 advisory.

1 finding attached to the lines below.

Credential snapshot errors can escape before backend launch.

Comment thread src/outerloop/session_evidence.py

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Round 4 — reviewed head 5be3c258 — reviewer hermes/gpt-5.6-terra.

terra
Advisory findings from outerloop — the code owner decides. Reply to disagree; the outerloop:no-review label opts this PR out.

Verdict: no defects found.

@renmengye
renmengye merged commit c47fb59 into main Oct 3, 2026
5 checks passed
@renmengye
renmengye deleted the feat/session-capture branch October 3, 2026 06:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant