fix: separate lineage hash domains and preserve result semantics - #941
Merged
Conversation
rynfar
marked this pull request as ready for review
September 4, 2026 20:56
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
A changed tool result could retain the same lineage hash as the cached history: changing
is_errorfrom false to true resumed the old SDK session and still answered SUCCEEDED. Text could also impersonate tool blocks or inject message boundaries, and per-block proofs did not include the message role.Use structured, domain-separated encodings for aggregate, message and block hashes. Preserve roles, boundaries, tool identities/arguments and result error status. Canonicalize JSON keys while retaining plain-string/text-block equivalence and ignoring opaque thinking/cache hints. The existing adapter/diagnostic renderer remains unchanged and no longer acts as a lineage proof.
Legacy hashes trigger complete replay through the validated #940 path, then subsequent turns on upgraded proxies resume normally. Alternating between old/new proxy versions can repeat this cost until all participating proxies are upgraded. SDK transcript files are never rewritten for migration.
Validation:
npm test: 3,350 pass, one existing skip, zero failures. Typecheck/build pass.Fixes #887. Related to #872; this does not adopt its proposed arbitrary block-drop continuation.