provenance

package
v0.174.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 1, 2026 License: Apache-2.0 Imports: 4 Imported by: 0

Documentation

Overview

Package provenance reads the harness identity a WB record can safely carry, at zero cost: environment variables and the already-resolved wb build version, nothing else. No network, no process spawn, no file I/O.

This exists because a WB record today says which worktree and which repository, but not which agent session did the work — the SDLC logging-gap analysis (2026-09-18, wb#631) found claims carry `wb_session_id` derived from a PID that every subagent shares with its orchestrator, and `wb session register` ran in only 7 of 188 transcripts. Every field here is an opaque ID. Never a prompt, a response body, or an email: internal/worktrees' `model_declared_by` has carried an email once (see its own doc), and this package exists so that mistake is structurally harder to repeat — there is nowhere in Fields free text can go.

Index

Constants

View Source
const (
	EnvHarnessSessionID = "CLAUDE_CODE_SESSION_ID"
	EnvHarness          = "AI_AGENT"
	EnvEffortLevel      = "CLAUDE_EFFORT"
	EnvAgentID          = "WB_SUBAGENT_ID"
	EnvToolUseID        = "WB_SUBAGENT_TOOL_USE_ID"
)

Environment variables this package reads. WB_SUBAGENT_ID and WB_SUBAGENT_TOOL_USE_ID are the same variables the agent guard's rewrite stamps onto a Bash call that invokes wb (internal/agentguard, wb#637) — this package is the other half of that loop: the guard writes them into the child process's environment, and every WB record writer reads them back.

These are deliberately named outside the WB_AGENT_* family: WB_AGENT_ID already exists as the owner-identity variable a session declares to claim a worktree (internal/worktrees.EnvAgentID, see ownership.md). Wb#645's review (Blocker 3) found that reusing that name made a declared subagent identity look like a live owner declaration, which flips `--mode auto` to agent mode and then fails admission for any subagent that never separately registered a session. A distinct name keeps "which subagent called wb" (this package) and "who owns this worktree" (internal/worktrees) from ever colliding.

Variables

This section is empty.

Functions

func SafeID

func SafeID(value string) bool

SafeID reports whether value is a compact token safe to record verbatim and, where applicable, to interpolate unescaped into a shell command: no whitespace, quotes, or shell metacharacters.

Types

type Fields

type Fields struct {
	// HarnessSessionID is the harness's own session identity
	// (CLAUDE_CODE_SESSION_ID). Unlike WB's PID-derived wb_session_id, this
	// is stable across every subagent a Claude Code session dispatches.
	HarnessSessionID string `json:"harness_session_id,omitempty"`
	// Harness names the driving harness (AI_AGENT), e.g. "claude-code".
	Harness string `json:"harness,omitempty"`
	// EffortLevel is the declared reasoning/effort tier (CLAUDE_EFFORT).
	EffortLevel string `json:"effort_level,omitempty"`
	// AgentID identifies a subagent (WB_AGENT_ID), set by the agent guard's
	// export prefix when a subagent's Bash call invokes wb.
	AgentID string `json:"agent_id,omitempty"`
	// ToolUseID identifies the exact tool call that ran this command
	// (WB_TOOL_USE_ID), set the same way as AgentID.
	ToolUseID string `json:"tool_use_id,omitempty"`
	// WBVersion is the running wb binary's own version. It is never empty:
	// buildinfo.Version() reports "unknown" rather than "".
	WBVersion string `json:"wb_version,omitempty"`
}

Fields is machine identity, cheap enough to attach to every WB record: worktree claims, fleet events, `wb run` events, and wait records.

func FromEnv

func FromEnv() Fields

FromEnv reads every field above from the process environment and the already-resolved build info. It performs no I/O beyond that, so every record writer can call it on every write without a latency or reliability cost.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL