Conversation
Follows agentrust-io/trace-spec#416. Do not infer policy enforcement from an omitted evidence-constructor mode. Default PolicyEvidence to declared, admit that explicit value, and preserve all supported explicit modes and rejection of unknown values. Document the behavior change and require agentrust-trace>=0.9.0, the release that introduced declared. Runtime enforcement behavior remains unchanged. Signed-off-by: Loek <solloek369@gmail.com>
|
Thanks Loek. Same collision as trace-spec#417: spec section 4.3 says |
|
Yes please Imran, push the same required-argument shape here. |
TRACE spec section 4.3 says declared MUST NOT be a default, and the old enforce default claimed enforcement the constructor cannot know about. Follows the shape of agentrust-io#227: no default, the caller states the mode. The otel-genai adapter gains a required enforcement_mode argument and a required --enforcement-mode flag, as the four framework adapters did. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Signed-off-by: Imran Siddique <imran.siddique@opaque.co>
…d-adapter-defaults
Main added this fixture after the branch point; PolicyEvidence now requires the mode. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Signed-off-by: Imran Siddique <imran.siddique@opaque.co>
|
@solloek369-arch pushed the required-argument shape as you asked. |
|
@carloshvp could you review this one? The last push was mine, so the ruleset needs an approval from someone else. The change makes |
carloshvp
left a comment
There was a problem hiding this comment.
Reviewed head 0bcdec2. No blocking findings. PolicyEvidence and the OTel API/CLI require an explicit enforcement mode; omitted or malformed values are rejected, and all four supported modes are preserved without upgrading software-only/log-import evidence into an attestation or enforcement proof. Runtime enforcement defaults are outside this change.
Local Python 3.12 validation against released TRACE 0.10.0: 127 adapter tests and 22 OTel tests, including released Pydantic AI interoperability, passed. Both suites also passed after a clean merge with current main (2fc8a09). Independent checks covered API omission, ten malformed values at both constructors, CLI omission/invalid modes, and all four API/CLI modes with real TrustRecord validation. The 31 builder tests also passed against TRACE 0.9.0; that floor check was limited to the builder suite. Manifest validation (41 integrations, zero failures), compatibility, generated index/catalog checks, 28 repository validation tests, CI-scoped Ruff, dependency checks and diff checks passed.
Non-blocking documentation cleanup: the PR title/body and the pyproject dependency comment still describe a declared default, and the module's Usage example omits the now-required --enforcement-mode flag. Please align those with the final required-argument behavior.
PolicyEvidence gains the declared mode and loses its enforce default (#223), so a 0.1.1 call that omitted enforcement_mode now raises. That breaks the constructor's API, hence 0.2.0 rather than 0.1.2. Bumps pyproject and __version__, corrects the dependency comment that still described declared as a default, and dates the change in the README. Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
What changes
Implements the
integrationsportion of agentrust-io/trace-spec#416.PolicyEvidence(bundle=...)defaults an omittedenforcement_modetodeclaredinstead ofenforce.enforce,advisory,silent, anddeclaredpass through unchanged; unknown modes remain rejected.agentrust-tracedependency floor changes from>=0.7.0to>=0.9.0.The repository-wide
compatibility.yamlfloor is unchanged; this PR changes only this package's runtime dependency to the first TRACE release that can represent its new default.An omitted evidence-constructor argument must not infer that policy enforcement occurred. Callers with an independently established enforcement context pass the actual mode explicitly. Runtime enforcement defaults and behavior are unchanged.
Compatibility
This changes the emitted evidence for callers that previously omitted the mode. Callers that established enforcement can continue to supply
enforcement_mode="enforce"explicitly.TRACE 0.9.0 introduced
declared; the published wheels were checked: 0.8.0 admits onlyenforce | advisory | silent, while 0.9.0 also admitsdeclared. At 0.9.0, three pre-existing OpenShell tests fail because its JSON Schema requirestransparency; 0.10.0 no longer requires that field. This PR neither causes nor fixes those failures. The hash-locked CI dependency environment uses 0.10.0, against which the local package suite passes. The new dependency floor is therefore not a claim that the complete package suite passes at 0.9.0.Validation
Local validation on macOS with Python 3.12.14, published TRACE packages, and a wheel built from this patch. These results are not a CI run.
requirements/adapters.txt's hash-locked environment:tests/test_builder.py31 passed; packagetests110 passed.tests/test_builder.py31 passed. In the earlier unchanged-base reproduction atf6e8c8b, the package suite was 102 passed, 3 failed. The candidate run produced 107 passed, 3 failed; the same three OpenShell test identities and primary'transparency' is a required propertymessages were reproduced. The baseline was not rerun in this GO 2A validation.pip check.enforcedefault fails the omission regression, and removingdeclaredfromMODESfails the explicit-declaredregression. Each pytest process exits 1 for the intended failure while the invalid-mode control still passes. The unmodified builder suite passes again in both environments.requirements/release.txt(build 1.6.1,twine 7.0.0): sdist and wheel built successfully, andtwine checkpassed for both. The wheel built from the sdist is byte-identical to the wheel used for the package tests above. This is not a run of the complete release workflow.Corresponding trace-spec PR: agentrust-io/trace-spec#417.
Follows agentrust-io/trace-spec#416.