Repository navigation
fix(schema): accept serialized runtime audit entries and guard drift - #735
imran-siddique merged 2 commits into
Conversation
Signed-off-by: Srinivasa Dinakar <dinakarjs@gmail.com>
|
@imran-siddique The schema/test-only implementation of your #734 ruling is ready at 689c568. Please review the current head. The requested EntryType drift guard is in tests/unit so the normal CI selection executes it; actual persisted unadmitted observations and malformed-record mutants are covered. Fresh broad suite: 2508 passed, 37 skipped, 90.02% coverage. No audit/chain.py or runtime code changed. |
|
🟡 Contributor Check: MEDIUM
Automated check by AgenTrust Contributor Check. |
|
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
imran-siddique
left a comment
There was a problem hiding this comment.
@dinakarjs this covers #734 as scoped, and the EntryType drift guard is the one I asked for. One change before merge: making call_id nullable for every entry also accepts a tool_call record with no call identity, which the old schema refused and the runtime never writes. Keep null for non-call events and require a UUID string when entry_type is tool_call, for example an if/then on entry_type. test_call_id_remains_required_even_when_null_is_allowed currently validates exactly that case on the tool_call fixture, so it should flip to a rejection there, with a non-call event as the accepting twin.
Allow null call_id only outside tool_call events and cover the accepting and rejecting event cases. Signed-off-by: Srinivasa Dinakar <dinakarjs@gmail.com>
The published audit-entry schema rejects serialized runtime records because six EntryType values and five emitted fields are undeclared, and non-call call_id:null is forbidden. Reconcile the schema with AuditEntry serialization while retaining required existing fields, explicit value types, and rejection of unknown top-level properties. Newly declared fields remain optional so legacy records validate.
For tool_call entries, an if/then condition requires call_id to be a UUID string; null is accepted for non-call events. Both call and non-call entries must still include the call_id field. Tests cover valid tool calls, all 14 runtime event types, null IDs for all 13 non-call events, rejection of null tool-call IDs and missing IDs, actual SQLite-persisted unadmitted observations including a 65-name summary, legacy records, malformed variants, and enum/dataclass-field drift.
Closes #734 under the confirmed scope: #734 (comment). Schema/tests only. Schema validation does not establish hash-chain integrity or evidence authenticity. Validators pinned to the old schema must update to accept these existing runtime records.
Validation, Linux/Python 3.12: 2,523 passed, 37 skipped, 90.02% coverage across the normal CI test directories plus tests/test_aarm_conformance.py. The focused schema/persistence tests passed all 71 cases, including 48 schema tests. The null tool-call regression failed on the prior schema and passed with the condition. Ruff across src/tests and whitespace checks passed. No runtime, dependency or lockfile changes. Remote CI and maintainer approval remain pending.