hermes-agent/acp_adapter
Teknium 72eda946be fix(security): redact terminal exception results and ACP stderr logs (#77484)
Closes the last two emission gaps from #77484:

- tools/terminal_tool.py: both exception paths (generic except and
  TERMINAL_DEGRADED_MODE=fail) returned raw str(e) + traceback.format_exc()
  to the model — only the logger copy was redacted. Exception text can
  embed the failing command line and any secrets inline in it; both fields
  now pass through redact_sensitive_text.
- acp_adapter/entry.py: _setup_logging cleared root handlers and installed
  a plain logging.Formatter, bypassing redaction entirely on ACP stderr.
  Now uses RedactingFormatter like every other logging surface.

The other three gaps from #77484 (process(list), *_KEY regex variants,
control-char splits) were fixed in #80964/#80965.
2026-08-08 04:19:49 -07:00
..
__init__.py
__main__.py
auth.py
edit_approval.py
entry.py fix(security): redact terminal exception results and ACP stderr logs (#77484) 2026-08-08 04:19:49 -07:00
events.py
permissions.py fix(approval): classify CLI/TUI approval timeouts separately from explicit denials 2026-08-02 20:21:59 -07:00
provenance.py
server.py fix: follow-ups for salvaged PR #80740 2026-08-07 21:02:40 +05:30
session.py fix(state): finish the #80216 bug class — archive-preserving rewrites at the two remaining sibling sites 2026-08-07 14:42:32 +05:30
tools.py