v0.11.0 - End-to-end execution traceability
End-to-end execution traceability: one trace_id now reconstructs
routing, broadcasts, agents, experts, native pipeline stages,
universal-memory publication, ethical decisions, action proposals,
handlers, results, rejections, and errors. An independent adversarial
review was run against the release candidate before publishing - every
finding reproduced against source and fixed (see AUDIT_v0.11.0.md).
✨ Added
- Immutable
ExecutionContext: generated or caller-supplied
trace_id/run_id, causalparent_id, UTC creation time, opaque
application/instance/subject/session/turn identifiers, recursively
frozen size-bounded metadata, andderive()for child operations. - Run-local propagation via
contextvars- bound only while a component
executes, always reset (including after rejection and exceptions). TraceEventand per-orchestratorTraceRecorder: thread-safe
structured events, monotonic sequence, SHA-256 hash chain, immediate
cause_idreferences, parent-run verification, sanitized export, and
exporter hooks.- End-to-end instrumentation across routing, broadcast, agents, experts,
pipeline stages, universal-memory publication, ethical decisions,
action proposals, handlers, results, rejections, and errors. SETTOrchestrator.process_traced()/TracedResult,get_trace(),
export_trace(),register_trace_exporter(),verify_traces(),
last_trace_id.- Stable generated
Action.action_idfor causal effect correlation. docs/execution_context_v0.11_design.mdandMIGRATION_v0.11.md.
🔒 Security
- Traces record operational metadata only - input/action payloads,
handler return values, exception messages/locals, biometric values,
risk profiles, prompts, model responses, and private-memory values are
excluded by default. - Metadata is bounded (32 top-level keys, depth 8, 16 KiB serialized) and
rejects sensitive key fragments and non-JSON objects. handler.authorizedis the committed pre-effect boundary: an exporter
failure there recordshandler.blocked, raises
SETTConfigurationError, and neitherhandler.startednor the real
handler ever runs.- Trace exports are defensive copies; hash and causal verification
detects mutation, removal, reordering, duplicate IDs, cross-trace/
forward causes, invalid parent runs, and incomplete instrumented
operations.
🐛 Fixed
tests/test_elevenlabs_adapter.pynow guards with
pytest.importorskip("requests")- already fixed as of v0.9.0 (see
that release), carried forward unchanged.
✅ Compatibility
SETTAgent.process(),SETTExpert.resolve(), executor handlers,
SETTOrchestrator.process(), broadcasts, and pipelines remain
source-compatible.execution_contextis additive and keyword-only.- The complete v0.10.1 suite passes unchanged.
- The private companion-assistant reference application's complete
baseline suite (842 tests) passes against this source release without
any application code changes.
Status
- 340 tests passing (290 before), 50 new (
tests/test_execution_context_v011.py). - Independent adversarial review: 8/8 findings reproduced and fixed - see
AUDIT_v0.11.0.md.