Skip to content

fix(adapters): default PolicyEvidence mode to declared - #223

Merged
carloshvp merged 4 commits into
agentrust-io:mainfrom
solloek369-arch:fix/issue-416-declared-adapter-defaults
Sep 30, 2026
Merged

carloshvp merged 4 commits into
agentrust-io:mainfrom
solloek369-arch:fix/issue-416-declared-adapter-defaults

Conversation

@solloek369-arch

Copy link
Copy Markdown
Contributor

What changes

Implements the integrations portion of agentrust-io/trace-spec#416.

  • PolicyEvidence(bundle=...) defaults an omitted enforcement_mode to declared instead of enforce.
  • Explicit enforce, advisory, silent, and declared pass through unchanged; unknown modes remain rejected.
  • The README makes the emitted default and migration for existing callers explicit.
  • This package's agentrust-trace dependency floor changes from >=0.7.0 to >=0.9.0.

The repository-wide compatibility.yaml floor is unchanged; this PR changes only this package's runtime dependency to the first TRACE release that can represent its new default.

An omitted evidence-constructor argument must not infer that policy enforcement occurred. Callers with an independently established enforcement context pass the actual mode explicitly. Runtime enforcement defaults and behavior are unchanged.

Compatibility

This changes the emitted evidence for callers that previously omitted the mode. Callers that established enforcement can continue to supply enforcement_mode="enforce" explicitly.

TRACE 0.9.0 introduced declared; the published wheels were checked: 0.8.0 admits only enforce | advisory | silent, while 0.9.0 also admits declared. At 0.9.0, three pre-existing OpenShell tests fail because its JSON Schema requires transparency; 0.10.0 no longer requires that field. This PR neither causes nor fixes those failures. The hash-locked CI dependency environment uses 0.10.0, against which the local package suite passes. The new dependency floor is therefore not a claim that the complete package suite passes at 0.9.0.

Validation

Local validation on macOS with Python 3.12.14, published TRACE packages, and a wheel built from this patch. These results are not a CI run.

  • TRACE 0.10.0 from requirements/adapters.txt's hash-locked environment: tests/test_builder.py 31 passed; package tests 110 passed.
  • TRACE 0.9.0: tests/test_builder.py 31 passed. In the earlier unchanged-base reproduction at f6e8c8b, the package suite was 102 passed, 3 failed. The candidate run produced 107 passed, 3 failed; the same three OpenShell test identities and primary 'transparency' is a required property messages were reproduced. The baseline was not rerun in this GO 2A validation.
  • Both environments have zero skipped tests and pass pip check.
  • Two targeted mutation controls were run in separate local source copies: restoring the enforce default fails the omission regression, and removing declared from MODES fails the explicit-declared regression. Each pytest process exits 1 for the intended failure while the invalid-mode control still passes. The unmodified builder suite passes again in both environments.
  • Local distribution inspection using requirements/release.txt (build 1.6.1, twine 7.0.0): sdist and wheel built successfully, and twine check passed for both. The wheel built from the sdist is byte-identical to the wheel used for the package tests above. This is not a run of the complete release workflow.

Corresponding trace-spec PR: agentrust-io/trace-spec#417.

Follows agentrust-io/trace-spec#416.

Follows agentrust-io/trace-spec#416.

Do not infer policy enforcement from an omitted evidence-constructor mode.
Default PolicyEvidence to declared, admit that explicit value, and preserve
all supported explicit modes and rejection of unknown values.

Document the behavior change and require agentrust-trace>=0.9.0, the release
that introduced declared. Runtime enforcement behavior remains unchanged.

Signed-off-by: Loek <solloek369@gmail.com>
@imran-siddique

Copy link
Copy Markdown
Member

Thanks Loek. Same collision as trace-spec#417: spec section 4.3 says declared "MUST NOT be a default", so PolicyEvidence cannot pick it for the caller either. trace-spec#419 settled the adapters by requiring enforcement_mode with no default, and #227 does the same for the four framework adapters here. Could this PR follow that shape, a required argument instead of a new default? Edits by maintainers are on here, so I can push it if you prefer.

@solloek369-arch

Copy link
Copy Markdown
Contributor Author

Yes please Imran, push the same required-argument shape here.
Sorry for the extra work!

imran-siddique and others added 3 commits September 27, 2026 21:41
TRACE spec section 4.3 says declared MUST NOT be a default, and the old
enforce default claimed enforcement the constructor cannot know about.
Follows the shape of agentrust-io#227: no default, the caller states the mode. The
otel-genai adapter gains a required enforcement_mode argument and a
required --enforcement-mode flag, as the four framework adapters did.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Signed-off-by: Imran Siddique <imran.siddique@opaque.co>
Main added this fixture after the branch point; PolicyEvidence now requires
the mode.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Signed-off-by: Imran Siddique <imran.siddique@opaque.co>
@imran-siddique

Copy link
Copy Markdown
Member

@solloek369-arch pushed the required-argument shape as you asked. PolicyEvidence.enforcement_mode has no default now, following #227, and otel-genai's build_from_spans and CLI gain a required mode. I also merged main and passed the mode in the test_untrusted_input.py fixture main added since. Adapter suite 127 passed, otel-genai 14 passed.

@imran-siddique

Copy link
Copy Markdown
Member

@carloshvp could you review this one? The last push was mine, so the ruleset needs an approval from someone else. The change makes PolicyEvidence.enforcement_mode required with no default (spec section 4.3, same shape as #227), and threads a required mode through otel-genai. All 17 technical checks pass on 0bcdec2.

@carloshvp carloshvp left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed head 0bcdec2. No blocking findings. PolicyEvidence and the OTel API/CLI require an explicit enforcement mode; omitted or malformed values are rejected, and all four supported modes are preserved without upgrading software-only/log-import evidence into an attestation or enforcement proof. Runtime enforcement defaults are outside this change.

Local Python 3.12 validation against released TRACE 0.10.0: 127 adapter tests and 22 OTel tests, including released Pydantic AI interoperability, passed. Both suites also passed after a clean merge with current main (2fc8a09). Independent checks covered API omission, ten malformed values at both constructors, CLI omission/invalid modes, and all four API/CLI modes with real TrustRecord validation. The 31 builder tests also passed against TRACE 0.9.0; that floor check was limited to the builder suite. Manifest validation (41 integrations, zero failures), compatibility, generated index/catalog checks, 28 repository validation tests, CI-scoped Ruff, dependency checks and diff checks passed.

Non-blocking documentation cleanup: the PR title/body and the pyproject dependency comment still describe a declared default, and the module's Usage example omits the now-required --enforcement-mode flag. Please align those with the final required-argument behavior.

@carloshvp
carloshvp merged commit 5920c72 into agentrust-io:main Sep 30, 2026
21 of 22 checks passed
imran-siddique added a commit that referenced this pull request Oct 1, 2026
PolicyEvidence gains the declared mode and loses its enforce default (#223),
so a 0.1.1 call that omitted enforcement_mode now raises. That breaks the
constructor's API, hence 0.2.0 rather than 0.1.2.

Bumps pyproject and __version__, corrects the dependency comment that still
described declared as a default, and dates the change in the README.

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants