c35a63ed8d
* Python: feat: cross-session origin attribution on context messages Add an optional origin_session_id parameter to SessionContext.extend_messages that propagates into the existing _attribution payload on Message.additional_properties. Downstream context observers can use it to detect when a provider injects content stored under a different session than the requesting one. Populate the field from the harness memory consolidation pipeline (_harness/_memory.py) when injected topics include contributions from sessions other than the current one. Add a self-contained sample observer under samples/02-agents/context_providers/cross_session_observer.py demonstrating how to subscribe to the signal. Backward-compatible: omitting the parameter preserves the existing attribution shape exactly. Tests added in test_sessions.py and test_harness_memory.py cover the new parameter, the harness cross-session case, and the same-session case. Motivated by Dai et al., Stateful Agent Backdoor (arXiv:2605.06158, May 2026), which specifically surveys MAF in section 6.1 / Table 10. See #5914 for design discussion. Surfaced during independent audit conducted by @finnoybu (Ken Tannenbaum, AEGIS Initiative); [MEDIUM, python/packages/core]. * Address cross-session attribution review feedback * Address follow-up review feedback * Address follow-up review comments * Address origin attribution review feedback --------- Co-authored-by: finnoybu <21694570+finnoybu@users.noreply.github.com>