From 7bad91c51d94de86924909ce2b5388074c1ac3dc Mon Sep 17 00:00:00 2001 From: "carnie[bot]" Date: Sun, 9 Aug 2026 05:35:34 +0800 Subject: [PATCH] fix(honcho): skip memory-file migration on non-owner sessions (task #00000801) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit migrate_memory_files() uploads USER.md/MEMORY.md with peer=user_peer — the session's runtime user. In shared channels, a non-owner's new thread uploads the owner's full profile under the NON-OWNER's peer; Honcho's deriver then attributes the owner's psychometrics/medical/biography to that person. This was the root contamination vector (55/70 contaminated sessions carried the payload). Skip migration unless the session user is the configured owner. SOUL.md unaffected (uploads under assistant peer). Co-authored-by: Minh Nguyen --- plugins/memory/honcho/session.py | 14 ++++++++++++++ 1 file changed, 14 insertions(+) diff --git a/plugins/memory/honcho/session.py b/plugins/memory/honcho/session.py index 3a80a9c332..0f14e1bccd 100644 --- a/plugins/memory/honcho/session.py +++ b/plugins/memory/honcho/session.py @@ -1137,6 +1137,20 @@ class HonchoSessionManager: logger.warning("No Honcho session cached for '%s', skipping memory migration", session_key) return False + # Only migrate the owner-describing memory files (MEMORY.md / USER.md) + # when the session's user peer IS the configured owner peer. Otherwise a + # non-owner triggering a new session (e.g. any other human in a shared + # Slack/Discord channel) gets the owner's full profile files uploaded + # under the NON-OWNER's peer, and Honcho's deriver attributes the + # owner's facts to that person. SOUL.md describes the agent, not a + # human, but skipping it here too keeps the migration owner-scoped. + if session.user_peer_id != self._sanitize_id(self._config.peer_name): + logger.info( + "Skipping memory-file migration for non-owner session (user=%s)", + session.user_peer_id, + ) + return False + uploaded = False files = [ (