Skip to content

[TRACE] TRACE model and field mapping (ADR-0032, step 1/5) #3086

Description

Summary

Implement the TrustRecord dataclass and the mapping function from a closed AGT session to a TRACE v0.2 Trust Record payload. This is the data model layer -- no signing, no sink, no config yet.

Scope

New file: agent-governance-python/agent-mesh/src/agentmesh/governance/trace_model.py

Fields to map:

TRACE field Source
eat_profile Constant "tag:agentrust.io,2026:trace-v0.1"
iat AuditEntry.timestamp (latest entry) converted to Unix epoch seconds
subject session.agent_did directly (TRACE v0.2 accepts did: natively -- no SPIFFE config needed)
model Config-injected dict (provider, model_id, version, weights_digest)
runtime Config-injected; platform: "software-only", measurement: "sha256:" + "0"*64
policy.bundle_hash SHA-256 of Cedar policy bundle bytes, captured at PolicyInterceptor load time
policy.enforcement_mode Config: "enforce" or "advisory"
data_class SessionState.monotonic_data_class
build_provenance Config-injected (slsa_level, builder, digest)
appraisal.status "affirming" if zero deny decisions in session, else "contraindicated"
appraisal.verifier Config-injected URI
transparency Empty string for Phase 1
tool_transcript.hash sha256: + SHA-256 of RFC 8785 JCS-canonical JSON of the AuditEntry list
tool_transcript.call_count Count of tool_invocation entries in the chain

Change to PolicyInterceptor: capture policy_bundle_hash at load time (hashlib.sha256(bundle_bytes).hexdigest()) and store on the interceptor instance so the sink can read it at session close.

No changes to AuditEntry, MerkleAuditChain, or SessionState structure.

Acceptance criteria

  • TrustRecord dataclass with all 11 required TRACE fields
  • session_to_trust_record(session, config) -> dict mapping function
  • PolicyInterceptor stores policy_bundle_hash at load time
  • subject is derived from session.agent_did (e.g. did:mesh:spiffe://...)
  • Unit tests: golden-path mapping, deny decision sets appraisal.status = "contraindicated"

References

Activity

  1. added a commit that references this issue on Jun 17, 2026
    e9f68e3
  2. imran-siddique commented on Jun 17, 2026

    @imran-siddique
    CollaboratorAuthor

    Addressed by #3099. session_to_trust_record() in race_sink.py handles the field mapping; TrustRecord model comes from �gentrust-trace>=0.2.0 -- no local reimplementation.

  3. added a commit that references this issue on Jun 17, 2026
    46c4439
  4. added a commit that references this issue on Jun 17, 2026
    4770a32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

enhancementNew feature or requestpythonPull requests that update python codestandardsStandards body submissions and compliance

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions