Repository navigation
Keep session evidence and record cost for every backend - #457
Conversation
…d record cost for every backend
There was a problem hiding this comment.
Round 1 — reviewed head 895f7d25 — reviewer summarizer:hermes/gpt-5.6-terra over coverage+credentials+deployment+general+lifecycle+prose.
terra
Advisory findings from outerloop — the code owner decides. Reply to disagree; the outerloop:no-review label opts this PR out.
Verdict: 3 blocking, 1 advisory.
4 findings attached to the lines below.
Three blocking findings: native evidence can retain Vertex ADC credentials, failed Codex invocations can be reported with partial cost, and author-controlled sidecars can forge session-cost totals. One advisory correctness finding: resumed Hermes session records hash the original brief rather than the rehydrated delivered prompt. Rejected: none; the coverage and lifecycle scans reported no findings.
…riced, persisted kernel-owned totals, Hermes delivered-prompt hash
There was a problem hiding this comment.
Round 2 — reviewed head 1b560fb1 — reviewer hermes/gpt-5.6-terra.
terra
Advisory findings from outerloop — the code owner decides. Reply to disagree; the outerloop:no-review label opts this PR out.
Verdict: 1 blocking, 1 advisory.
2 findings attached to the lines below.
Failed Hermes sessions can be recorded with a priced cost, and credential capture errors can abort a harness run.
There was a problem hiding this comment.
Round 3 (re-run on the same head) — reviewed head 1b560fb1 — reviewer hermes/gpt-5.6-terra.
terra
Advisory findings from outerloop — the code owner decides. Reply to disagree; the outerloop:no-review label opts this PR out.
Verdict: 1 blocking, 0 advisory.
1 finding attached to the lines below.
Credential snapshot errors can escape before backend launch.
Keeps the evidence of every author and judge session, and records token usage and cost for every backend.
Why
A session's real record was lost: the kernel kept only the harness's stdout (Claude Code's final JSON, Codex exec events, Hermes stdout), the delivered prompt was rendered in memory and never saved, and the harness's native session log lived in the run's HOME, deleted about a day after the run ended. Codex and Hermes sessions also reported a cost of $0, so resource use was wrong for two of three backends. Analysing runs after the fact (what an agent was told, what it did, what it cost) needs all three.
What changes
Capture failures never fail or delay the session. Evidence is never committed or published (SECURITY.md).
Compatibility
Run records gain fields; readers tolerate their absence. Legacy fixture
tests/fixtures/session_cost_legacy.json(a record with numeric zero cost) reads unchanged.Upgrading:line in CHANGELOG: no action; old runs show cost as recorded.Verification
Gate: ruff check, ruff format --check, mypy, pytest (2954 passed, 10 skipped). Per-backend usage parsers tested on synthetic fixtures; redaction across the cap boundary mutation-checked. Live check on a real deployment (fresh, resumed and timed-out sessions per backend) still to do.
Built by Codex (gpt-5.6); reviewed by Codex (read-only pass) and Claude.