Skip to content

v0.11.0 - End-to-end execution traceability

Choose a tag to compare

@EduDanielV EduDanielV released this 03 Aug 01:00
· 8 commits to main since this release
c823e09

End-to-end execution traceability: one trace_id now reconstructs
routing, broadcasts, agents, experts, native pipeline stages,
universal-memory publication, ethical decisions, action proposals,
handlers, results, rejections, and errors. An independent adversarial
review was run against the release candidate before publishing - every
finding reproduced against source and fixed (see AUDIT_v0.11.0.md).

✨ Added

  • Immutable ExecutionContext: generated or caller-supplied
    trace_id/run_id, causal parent_id, UTC creation time, opaque
    application/instance/subject/session/turn identifiers, recursively
    frozen size-bounded metadata, and derive() for child operations.
  • Run-local propagation via contextvars - bound only while a component
    executes, always reset (including after rejection and exceptions).
  • TraceEvent and per-orchestrator TraceRecorder: thread-safe
    structured events, monotonic sequence, SHA-256 hash chain, immediate
    cause_id references, parent-run verification, sanitized export, and
    exporter hooks.
  • End-to-end instrumentation across routing, broadcast, agents, experts,
    pipeline stages, universal-memory publication, ethical decisions,
    action proposals, handlers, results, rejections, and errors.
  • SETTOrchestrator.process_traced() / TracedResult, get_trace(),
    export_trace(), register_trace_exporter(), verify_traces(),
    last_trace_id.
  • Stable generated Action.action_id for causal effect correlation.
  • docs/execution_context_v0.11_design.md and MIGRATION_v0.11.md.

🔒 Security

  • Traces record operational metadata only - input/action payloads,
    handler return values, exception messages/locals, biometric values,
    risk profiles, prompts, model responses, and private-memory values are
    excluded by default.
  • Metadata is bounded (32 top-level keys, depth 8, 16 KiB serialized) and
    rejects sensitive key fragments and non-JSON objects.
  • handler.authorized is the committed pre-effect boundary: an exporter
    failure there records handler.blocked, raises
    SETTConfigurationError, and neither handler.started nor the real
    handler ever runs.
  • Trace exports are defensive copies; hash and causal verification
    detects mutation, removal, reordering, duplicate IDs, cross-trace/
    forward causes, invalid parent runs, and incomplete instrumented
    operations.

🐛 Fixed

  • tests/test_elevenlabs_adapter.py now guards with
    pytest.importorskip("requests") - already fixed as of v0.9.0 (see
    that release), carried forward unchanged.

✅ Compatibility

  • SETTAgent.process(), SETTExpert.resolve(), executor handlers,
    SETTOrchestrator.process(), broadcasts, and pipelines remain
    source-compatible. execution_context is additive and keyword-only.
  • The complete v0.10.1 suite passes unchanged.
  • The private companion-assistant reference application's complete
    baseline suite (842 tests) passes against this source release without
    any application code changes.

Status

  • 340 tests passing (290 before), 50 new (tests/test_execution_context_v011.py).
  • Independent adversarial review: 8/8 findings reproduced and fixed - see AUDIT_v0.11.0.md.