Skip to content

chore: Phase 0 pre-launch audit — license headers + email cleanup - #24

Merged
Imran Siddique (imran-siddique) merged 4 commits into
mainfrom
fix/phase0-audit
Mar 5, 2026
Merged

Imran Siddique (imran-siddique) merged 4 commits into
mainfrom
fix/phase0-audit

Conversation

@imran-siddique

Copy link
Copy Markdown
Collaborator

Phase 0: Pre-Launch Audit

Changes

  • License headers: Added MIT license headers to 1,159 source files (Python, TypeScript, JavaScript)
  • Email cleanup: Replaced personal email with team alias (\�gt@microsoft.com) in 5 package metadata files
  • URL update: Chart.yaml URLs updated to microsoft/ org
  • Internal reference removed: Removed internal feed reference from providers.py

Audit Results (all clean ✅)

Check Result
Secret scan (API keys, tokens, PATs) ✅ Clean
pip-audit (known vulnerabilities) ✅ 0 vulns
Azure IDs (subscription/tenant) ✅ Only test values
Private registries ✅ None referenced
Git history (.env, .pem, .key) ✅ Never committed

Files Changed

  • 1,134 files (mostly +2 lines per file for license header)
  • 5 files with email replacement
  • 1 file with internal reference removal

Part of the Migration Checklist Phase 0.

Imran Siddique and others added 4 commits March 4, 2026 14:00
…otes

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
- Add MIT license headers to 1,159 source files (Python, TypeScript, JavaScript)
- Replace personal email (imran.siddique@microsoft.com) with team alias (agt@microsoft.com) in 5 files:
  - docs/AAIF-PROPOSAL.md
  - packages/agent-mesh/charts/agentmesh/Chart.yaml
  - packages/agent-mesh/packages/mcp-proxy/package.json
  - packages/agent-os/modules/caas/src/caas/__init__.py
  - packages/agent-os/modules/control-plane/setup.py
- Update Chart.yaml URLs from imran-siddique/ to microsoft/ org
- Remove internal feed reference from providers.py docstring

Audit results:
- Secret scan: CLEAN (no leaked keys, tokens, or credentials)
- pip-audit: CLEAN (0 known vulnerabilities across 8 critical packages)
- Azure IDs: CLEAN (only test/placeholder values like contoso-tenant-001)
- Private registries: CLEAN (no internal feeds referenced)
- Git history: CLEAN (no .env, .pem, .key files ever committed)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@imran-siddique
Imran Siddique (imran-siddique) merged commit 8eea75f into main Mar 5, 2026
19 of 20 checks passed
@imran-siddique
Imran Siddique (imran-siddique) deleted the fix/phase0-audit branch March 12, 2026 19:53
MohammadHaroonAbuomar pushed a commit to MohammadHaroonAbuomar/agt-acs that referenced this pull request Jun 1, 2026
…crosoft#24)

* docs: add OpenSSF badges, update OWASP to 10/10, add v1.0.0 release notes

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* chore: Phase 0 pre-launch audit fixes

- Add MIT license headers to 1,159 source files (Python, TypeScript, JavaScript)
- Replace personal email (imran.siddique@microsoft.com) with team alias (agt@microsoft.com) in 5 files:
  - docs/AAIF-PROPOSAL.md
  - packages/agent-mesh/charts/agentmesh/Chart.yaml
  - packages/agent-mesh/packages/mcp-proxy/package.json
  - packages/agent-os/modules/caas/src/caas/__init__.py
  - packages/agent-os/modules/control-plane/setup.py
- Update Chart.yaml URLs from imran-siddique/ to microsoft/ org
- Remove internal feed reference from providers.py docstring

Audit results:
- Secret scan: CLEAN (no leaked keys, tokens, or credentials)
- pip-audit: CLEAN (0 known vulnerabilities across 8 critical packages)
- Azure IDs: CLEAN (only test/placeholder values like contoso-tenant-001)
- Private registries: CLEAN (no internal feeds referenced)
- Git history: CLEAN (no .env, .pem, .key files ever committed)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
MohammadHaroonAbuomar added a commit that referenced this pull request Sep 13, 2026
The retarget note stated an organization or team co-owner on the
agent-control-spec crate as a merge precondition. The maintainer waived
that in August 2026: the sole owner maintains this integration,
publication is bound to a public commit through trusted publishing, and
adding a team owner is a registry-side change tracked in upstream #24.
Say so instead of presenting it as a blocker, and refresh the
verification date and evidence.

Signed-off-by: MohammadHaroonAbuomar <40180927+MohammadHaroonAbuomar@users.noreply.github.com>
(cherry picked from commit bc6dfd8)
MohammadHaroonAbuomar added a commit that referenced this pull request Sep 13, 2026
…ved manifest fields after the ACS retarget (#3940)

* fix(policy-engine): evaluate the SSRF guard on the canonical URL host

`reject_blocked_fetch_host` hand-split the authority and called
`str::parse::<IpAddr>`, which accepts only dotted-quad literals. The
upstream loader canonicalizes the fetch target with the `url` crate, so
`127.1`, `2130706433`, `0x7f000001`, `0177.0.0.1`, `0251.0376.0251.0376`
and `127.0.0<TAB>.1` walked past the guard and the fetcher connected to
loopback or the metadata address. A loopback listener probe confirmed the
TCP connect.

Parse with the same `url` crate and evaluate `Url::host()`, so the guard
sees the address the fetcher will connect to. Widen the blocked set to
private (RFC 1918), shared address space (100.64.0.0/10), IPv6
unique-local and site-local, 0.0.0.0/8, and the names `localhost`,
`*.localhost` and `*.local`. Check IPv4-mapped, IPv4-compatible and NAT64
literals on the embedded IPv4 address. A malformed URL now fails closed
at the guard.

`agent-control-spec` 0.4.0-alpha.3 follows redirects inside its HTTP
client and exposes no hook, so hops are still not re-checked. Document
that and the `max_manifest_url_redirects: 0` mitigation in the retarget
note, the spec and BREAKING_CHANGES.md, and give `manifest_from_url` its
own doc comment again.

Tests: `manifest_from_url_blocks_ssrf_targets` carries every probe form
plus the new ranges and names; `manifest_from_url_never_connects_to_a_
blocked_literal` binds a loopback listener and asserts nothing connects.

Signed-off-by: MohammadHaroonAbuomar <40180927+MohammadHaroonAbuomar@users.noreply.github.com>
(cherry picked from commit f23315b)

* fix(policy-engine): fail closed on manifest fields the pinned engine dropped

`bundle_url`, `system_prompt_file` and `system_prompt_url` were normative
in spec/SPECIFICATION.md and both manifest.schema.json copies, but
agent-control-spec 0.4.0-alpha.3 has no implementation of them and its
policy and annotator configuration maps are open. A manifest declaring
one of them parsed and validated cleanly while the feature was silently
absent: an `llm` annotator ran with the default prompt, and a
`bundle_url` rego policy denied every request with
`runtime_error:policy_invocation_failed` and no diagnostic. Every
fail-closed check the old engine had for them had become a silent
accept.

Add `reject_removed_manifest_fields` to the core shim. It walks each
policy definition, annotator declaration, policy binding and annotation
binding and returns `runtime_error:manifest_invalid` naming the location
and the field, pointing at the migration note. Run it from
`validate_manifest_yaml`, `validate_manifest_overlay_yaml`, every
`AgentControl` constructor, `manifest_from_url`, every C ABI
`acs_builder_from_*` loader, and the Python and Node constructors.

Keep the three keys in both schemas as `not: {}` properties (rego
policy, policy binding, annotator, annotation binding); the enclosing
objects allow additional properties, so dropping the keys would accept
them silently. Update SPECIFICATION.md sections 2.3, 10 and 12.1, the
Foundry example doc, and the stale dispatch-time fetch comments in
host/mod.rs and ffi.rs. Record the change in BREAKING_CHANGES.md and add
a "Removed manifest fields" section and a gap row to acs-retarget.md.

Tests: the six manifests from the review probe are rejection tests in
core (every entry point, plus binding-level and custom-policy forms),
a canary asserts upstream still accepts them so the check can be
retired when it stops, a host constructor test in sdk/rust, a Python
test across validate/from_native/from_manifest_chain, a schema test in
artifact_validation, and two cases in the shared artifact validation
parity corpus that the Rust, Python, Node and .NET runners consume.

Signed-off-by: MohammadHaroonAbuomar <40180927+MohammadHaroonAbuomar@users.noreply.github.com>
(cherry picked from commit 03c11e4)

* docs(policy-engine): record the crates.io ownership decision

The retarget note stated an organization or team co-owner on the
agent-control-spec crate as a merge precondition. The maintainer waived
that in August 2026: the sole owner maintains this integration,
publication is bound to a public commit through trusted publishing, and
adding a team owner is a registry-side change tracked in upstream #24.
Say so instead of presenting it as a blocker, and refresh the
verification date and evidence.

Signed-off-by: MohammadHaroonAbuomar <40180927+MohammadHaroonAbuomar@users.noreply.github.com>
(cherry picked from commit bc6dfd8)

* test(policy-engine): gate the OPA artifact test on the opa feature

`cargo test --locked -p agent_control_specification` failed to compile
under the crate's default features: tests/artifact_validation.rs imports
`agent_control_specification_core::validate_acs_artifacts`, which core
gates behind `opa`, and the SDK no longer enables that by default. The
workspace build only passed because the Python and Node members unify
`core/opa` in.

Declare the test target with `required-features = ["opa"]` so a
per-crate run skips it. The bindings enabled `opa` on core directly, not
on the SDK, so with that entry alone the workspace run skipped the test
too; enable the SDK's `opa` feature (which forwards to core) from
sdk/python and sdk/node so the workspace run keeps it.

Signed-off-by: MohammadHaroonAbuomar <40180927+MohammadHaroonAbuomar@users.noreply.github.com>
(cherry picked from commit 3ca7f91)

* fix(agent-os): report approval-gated denials through the approval block

`NativeAdapterResult.public_message` still branched on
`verdict == "escalate"`, a decision the engine no longer emits. An
approval-gated action now arrives as a `deny` carrying an `approval`
block, so it fell through to "Request blocked by policy." and the audit
record showed a plain deny.

Add `approval_required`, read from the verdict's `approval` block, use it
for the public message, and include it in the `agt.policy_evaluation.v1`
audit record. Tests cover a liftable deny that the host left unresolved
and a plain deny.

Signed-off-by: MohammadHaroonAbuomar <40180927+MohammadHaroonAbuomar@users.noreply.github.com>
(cherry picked from commit 4b904c3)

* docs(policy-engine): clear stale retarget references

- scripts/check_dependency_confusion.py and sdk/rust/Cargo.toml: cite the
  pinned agent-control-spec 0.4.0-alpha.3 and agent-hooks-sdk
  0.1.0-alpha.5 rather than alpha.1 and alpha.4.
- policy-engine/README.md: LICENSE.acs now covers the spec, schema and
  conformance files; the engine is a registry dependency, not vendored.
- Add the Microsoft license header to generator/tests/test_spec_artefacts.py
  and tests/artifact_enforcement_probe.py.
- BREAKING_CHANGES.md: list the host reason-code moves
  (runtime_error:approval_* to host_error:approval_*, action_mismatch to
  identity_mismatch, the new approval_unresolved, adapter and streaming
  codes, the effects codes that went away) and the core module-path moves
  (manifest_yaml, telemetry_sinks, identity, removed modules, crate-type).
  Fix the five docs that still cited the old approval codes.
- docs/rust-capability-manifest.md: main now depends on the published
  engine; drop "blocked" and the embedded 0.3.1-beta wording.
- scripts/ci/smoke_acs_python_wheel.py: feed the 0.4.0-alpha.1 grammar
  and validate it, so the release smoke checks the shipped grammar rather
  than a version the parser does not inspect.

Signed-off-by: MohammadHaroonAbuomar <40180927+MohammadHaroonAbuomar@users.noreply.github.com>
(cherry picked from commit 7417a1f)

* chore: satisfy the spell-check gate on the retarget follow-up

Replace the personal name in the ownership note with the role, use a
cspell-safe embedded-space host in the SSRF test vector, and add
nonblocking to the repo dictionary.

Signed-off-by: MohammadHaroonAbuomar <40180927+MohammadHaroonAbuomar@users.noreply.github.com>
(cherry picked from commit b3399f0)

* docs(deps): audit record for the url crate as a direct SDK dependency

The Dependency Audit Trail gate requires an audit doc in any PR that
changes a lockfile. The follow-up adds url 2.5.8 (already resolved
transitively) as a direct dependency of the ACS Rust SDK so the SSRF
guard parses hosts with the same crate the fetcher uses.

Signed-off-by: MohammadHaroonAbuomar <40180927+MohammadHaroonAbuomar@users.noreply.github.com>

---------

Signed-off-by: MohammadHaroonAbuomar <40180927+MohammadHaroonAbuomar@users.noreply.github.com>
Karim Mehalebi (karimad) pushed a commit to karimad/agent-governance-toolkit that referenced this pull request Sep 14, 2026
…ved manifest fields after the ACS retarget (microsoft#3940)

* fix(policy-engine): evaluate the SSRF guard on the canonical URL host

`reject_blocked_fetch_host` hand-split the authority and called
`str::parse::<IpAddr>`, which accepts only dotted-quad literals. The
upstream loader canonicalizes the fetch target with the `url` crate, so
`127.1`, `2130706433`, `0x7f000001`, `0177.0.0.1`, `0251.0376.0251.0376`
and `127.0.0<TAB>.1` walked past the guard and the fetcher connected to
loopback or the metadata address. A loopback listener probe confirmed the
TCP connect.

Parse with the same `url` crate and evaluate `Url::host()`, so the guard
sees the address the fetcher will connect to. Widen the blocked set to
private (RFC 1918), shared address space (100.64.0.0/10), IPv6
unique-local and site-local, 0.0.0.0/8, and the names `localhost`,
`*.localhost` and `*.local`. Check IPv4-mapped, IPv4-compatible and NAT64
literals on the embedded IPv4 address. A malformed URL now fails closed
at the guard.

`agent-control-spec` 0.4.0-alpha.3 follows redirects inside its HTTP
client and exposes no hook, so hops are still not re-checked. Document
that and the `max_manifest_url_redirects: 0` mitigation in the retarget
note, the spec and BREAKING_CHANGES.md, and give `manifest_from_url` its
own doc comment again.

Tests: `manifest_from_url_blocks_ssrf_targets` carries every probe form
plus the new ranges and names; `manifest_from_url_never_connects_to_a_
blocked_literal` binds a loopback listener and asserts nothing connects.

Signed-off-by: MohammadHaroonAbuomar <40180927+MohammadHaroonAbuomar@users.noreply.github.com>
(cherry picked from commit f23315b)

* fix(policy-engine): fail closed on manifest fields the pinned engine dropped

`bundle_url`, `system_prompt_file` and `system_prompt_url` were normative
in spec/SPECIFICATION.md and both manifest.schema.json copies, but
agent-control-spec 0.4.0-alpha.3 has no implementation of them and its
policy and annotator configuration maps are open. A manifest declaring
one of them parsed and validated cleanly while the feature was silently
absent: an `llm` annotator ran with the default prompt, and a
`bundle_url` rego policy denied every request with
`runtime_error:policy_invocation_failed` and no diagnostic. Every
fail-closed check the old engine had for them had become a silent
accept.

Add `reject_removed_manifest_fields` to the core shim. It walks each
policy definition, annotator declaration, policy binding and annotation
binding and returns `runtime_error:manifest_invalid` naming the location
and the field, pointing at the migration note. Run it from
`validate_manifest_yaml`, `validate_manifest_overlay_yaml`, every
`AgentControl` constructor, `manifest_from_url`, every C ABI
`acs_builder_from_*` loader, and the Python and Node constructors.

Keep the three keys in both schemas as `not: {}` properties (rego
policy, policy binding, annotator, annotation binding); the enclosing
objects allow additional properties, so dropping the keys would accept
them silently. Update SPECIFICATION.md sections 2.3, 10 and 12.1, the
Foundry example doc, and the stale dispatch-time fetch comments in
host/mod.rs and ffi.rs. Record the change in BREAKING_CHANGES.md and add
a "Removed manifest fields" section and a gap row to acs-retarget.md.

Tests: the six manifests from the review probe are rejection tests in
core (every entry point, plus binding-level and custom-policy forms),
a canary asserts upstream still accepts them so the check can be
retired when it stops, a host constructor test in sdk/rust, a Python
test across validate/from_native/from_manifest_chain, a schema test in
artifact_validation, and two cases in the shared artifact validation
parity corpus that the Rust, Python, Node and .NET runners consume.

Signed-off-by: MohammadHaroonAbuomar <40180927+MohammadHaroonAbuomar@users.noreply.github.com>
(cherry picked from commit 03c11e4)

* docs(policy-engine): record the crates.io ownership decision

The retarget note stated an organization or team co-owner on the
agent-control-spec crate as a merge precondition. The maintainer waived
that in August 2026: the sole owner maintains this integration,
publication is bound to a public commit through trusted publishing, and
adding a team owner is a registry-side change tracked in upstream microsoft#24.
Say so instead of presenting it as a blocker, and refresh the
verification date and evidence.

Signed-off-by: MohammadHaroonAbuomar <40180927+MohammadHaroonAbuomar@users.noreply.github.com>
(cherry picked from commit bc6dfd8)

* test(policy-engine): gate the OPA artifact test on the opa feature

`cargo test --locked -p agent_control_specification` failed to compile
under the crate's default features: tests/artifact_validation.rs imports
`agent_control_specification_core::validate_acs_artifacts`, which core
gates behind `opa`, and the SDK no longer enables that by default. The
workspace build only passed because the Python and Node members unify
`core/opa` in.

Declare the test target with `required-features = ["opa"]` so a
per-crate run skips it. The bindings enabled `opa` on core directly, not
on the SDK, so with that entry alone the workspace run skipped the test
too; enable the SDK's `opa` feature (which forwards to core) from
sdk/python and sdk/node so the workspace run keeps it.

Signed-off-by: MohammadHaroonAbuomar <40180927+MohammadHaroonAbuomar@users.noreply.github.com>
(cherry picked from commit 3ca7f91)

* fix(agent-os): report approval-gated denials through the approval block

`NativeAdapterResult.public_message` still branched on
`verdict == "escalate"`, a decision the engine no longer emits. An
approval-gated action now arrives as a `deny` carrying an `approval`
block, so it fell through to "Request blocked by policy." and the audit
record showed a plain deny.

Add `approval_required`, read from the verdict's `approval` block, use it
for the public message, and include it in the `agt.policy_evaluation.v1`
audit record. Tests cover a liftable deny that the host left unresolved
and a plain deny.

Signed-off-by: MohammadHaroonAbuomar <40180927+MohammadHaroonAbuomar@users.noreply.github.com>
(cherry picked from commit 4b904c3)

* docs(policy-engine): clear stale retarget references

- scripts/check_dependency_confusion.py and sdk/rust/Cargo.toml: cite the
  pinned agent-control-spec 0.4.0-alpha.3 and agent-hooks-sdk
  0.1.0-alpha.5 rather than alpha.1 and alpha.4.
- policy-engine/README.md: LICENSE.acs now covers the spec, schema and
  conformance files; the engine is a registry dependency, not vendored.
- Add the Microsoft license header to generator/tests/test_spec_artefacts.py
  and tests/artifact_enforcement_probe.py.
- BREAKING_CHANGES.md: list the host reason-code moves
  (runtime_error:approval_* to host_error:approval_*, action_mismatch to
  identity_mismatch, the new approval_unresolved, adapter and streaming
  codes, the effects codes that went away) and the core module-path moves
  (manifest_yaml, telemetry_sinks, identity, removed modules, crate-type).
  Fix the five docs that still cited the old approval codes.
- docs/rust-capability-manifest.md: main now depends on the published
  engine; drop "blocked" and the embedded 0.3.1-beta wording.
- scripts/ci/smoke_acs_python_wheel.py: feed the 0.4.0-alpha.1 grammar
  and validate it, so the release smoke checks the shipped grammar rather
  than a version the parser does not inspect.

Signed-off-by: MohammadHaroonAbuomar <40180927+MohammadHaroonAbuomar@users.noreply.github.com>
(cherry picked from commit 7417a1f)

* chore: satisfy the spell-check gate on the retarget follow-up

Replace the personal name in the ownership note with the role, use a
cspell-safe embedded-space host in the SSRF test vector, and add
nonblocking to the repo dictionary.

Signed-off-by: MohammadHaroonAbuomar <40180927+MohammadHaroonAbuomar@users.noreply.github.com>
(cherry picked from commit b3399f0)

* docs(deps): audit record for the url crate as a direct SDK dependency

The Dependency Audit Trail gate requires an audit doc in any PR that
changes a lockfile. The follow-up adds url 2.5.8 (already resolved
transitively) as a direct dependency of the ACS Rust SDK so the SSRF
guard parses hosts with the same crate the fetcher uses.

Signed-off-by: MohammadHaroonAbuomar <40180927+MohammadHaroonAbuomar@users.noreply.github.com>

---------

Signed-off-by: MohammadHaroonAbuomar <40180927+MohammadHaroonAbuomar@users.noreply.github.com>
Yuvraj Singh (yuvrajsingh2428) pushed a commit to yuvrajsingh2428/agent-governance-toolkit that referenced this pull request Oct 1, 2026
…ved manifest fields after the ACS retarget (microsoft#3940)

* fix(policy-engine): evaluate the SSRF guard on the canonical URL host

`reject_blocked_fetch_host` hand-split the authority and called
`str::parse::<IpAddr>`, which accepts only dotted-quad literals. The
upstream loader canonicalizes the fetch target with the `url` crate, so
`127.1`, `2130706433`, `0x7f000001`, `0177.0.0.1`, `0251.0376.0251.0376`
and `127.0.0<TAB>.1` walked past the guard and the fetcher connected to
loopback or the metadata address. A loopback listener probe confirmed the
TCP connect.

Parse with the same `url` crate and evaluate `Url::host()`, so the guard
sees the address the fetcher will connect to. Widen the blocked set to
private (RFC 1918), shared address space (100.64.0.0/10), IPv6
unique-local and site-local, 0.0.0.0/8, and the names `localhost`,
`*.localhost` and `*.local`. Check IPv4-mapped, IPv4-compatible and NAT64
literals on the embedded IPv4 address. A malformed URL now fails closed
at the guard.

`agent-control-spec` 0.4.0-alpha.3 follows redirects inside its HTTP
client and exposes no hook, so hops are still not re-checked. Document
that and the `max_manifest_url_redirects: 0` mitigation in the retarget
note, the spec and BREAKING_CHANGES.md, and give `manifest_from_url` its
own doc comment again.

Tests: `manifest_from_url_blocks_ssrf_targets` carries every probe form
plus the new ranges and names; `manifest_from_url_never_connects_to_a_
blocked_literal` binds a loopback listener and asserts nothing connects.

Signed-off-by: MohammadHaroonAbuomar <40180927+MohammadHaroonAbuomar@users.noreply.github.com>
(cherry picked from commit f23315b)

* fix(policy-engine): fail closed on manifest fields the pinned engine dropped

`bundle_url`, `system_prompt_file` and `system_prompt_url` were normative
in spec/SPECIFICATION.md and both manifest.schema.json copies, but
agent-control-spec 0.4.0-alpha.3 has no implementation of them and its
policy and annotator configuration maps are open. A manifest declaring
one of them parsed and validated cleanly while the feature was silently
absent: an `llm` annotator ran with the default prompt, and a
`bundle_url` rego policy denied every request with
`runtime_error:policy_invocation_failed` and no diagnostic. Every
fail-closed check the old engine had for them had become a silent
accept.

Add `reject_removed_manifest_fields` to the core shim. It walks each
policy definition, annotator declaration, policy binding and annotation
binding and returns `runtime_error:manifest_invalid` naming the location
and the field, pointing at the migration note. Run it from
`validate_manifest_yaml`, `validate_manifest_overlay_yaml`, every
`AgentControl` constructor, `manifest_from_url`, every C ABI
`acs_builder_from_*` loader, and the Python and Node constructors.

Keep the three keys in both schemas as `not: {}` properties (rego
policy, policy binding, annotator, annotation binding); the enclosing
objects allow additional properties, so dropping the keys would accept
them silently. Update SPECIFICATION.md sections 2.3, 10 and 12.1, the
Foundry example doc, and the stale dispatch-time fetch comments in
host/mod.rs and ffi.rs. Record the change in BREAKING_CHANGES.md and add
a "Removed manifest fields" section and a gap row to acs-retarget.md.

Tests: the six manifests from the review probe are rejection tests in
core (every entry point, plus binding-level and custom-policy forms),
a canary asserts upstream still accepts them so the check can be
retired when it stops, a host constructor test in sdk/rust, a Python
test across validate/from_native/from_manifest_chain, a schema test in
artifact_validation, and two cases in the shared artifact validation
parity corpus that the Rust, Python, Node and .NET runners consume.

Signed-off-by: MohammadHaroonAbuomar <40180927+MohammadHaroonAbuomar@users.noreply.github.com>
(cherry picked from commit 03c11e4)

* docs(policy-engine): record the crates.io ownership decision

The retarget note stated an organization or team co-owner on the
agent-control-spec crate as a merge precondition. The maintainer waived
that in August 2026: the sole owner maintains this integration,
publication is bound to a public commit through trusted publishing, and
adding a team owner is a registry-side change tracked in upstream microsoft#24.
Say so instead of presenting it as a blocker, and refresh the
verification date and evidence.

Signed-off-by: MohammadHaroonAbuomar <40180927+MohammadHaroonAbuomar@users.noreply.github.com>
(cherry picked from commit bc6dfd8)

* test(policy-engine): gate the OPA artifact test on the opa feature

`cargo test --locked -p agent_control_specification` failed to compile
under the crate's default features: tests/artifact_validation.rs imports
`agent_control_specification_core::validate_acs_artifacts`, which core
gates behind `opa`, and the SDK no longer enables that by default. The
workspace build only passed because the Python and Node members unify
`core/opa` in.

Declare the test target with `required-features = ["opa"]` so a
per-crate run skips it. The bindings enabled `opa` on core directly, not
on the SDK, so with that entry alone the workspace run skipped the test
too; enable the SDK's `opa` feature (which forwards to core) from
sdk/python and sdk/node so the workspace run keeps it.

Signed-off-by: MohammadHaroonAbuomar <40180927+MohammadHaroonAbuomar@users.noreply.github.com>
(cherry picked from commit 3ca7f91)

* fix(agent-os): report approval-gated denials through the approval block

`NativeAdapterResult.public_message` still branched on
`verdict == "escalate"`, a decision the engine no longer emits. An
approval-gated action now arrives as a `deny` carrying an `approval`
block, so it fell through to "Request blocked by policy." and the audit
record showed a plain deny.

Add `approval_required`, read from the verdict's `approval` block, use it
for the public message, and include it in the `agt.policy_evaluation.v1`
audit record. Tests cover a liftable deny that the host left unresolved
and a plain deny.

Signed-off-by: MohammadHaroonAbuomar <40180927+MohammadHaroonAbuomar@users.noreply.github.com>
(cherry picked from commit 4b904c3)

* docs(policy-engine): clear stale retarget references

- scripts/check_dependency_confusion.py and sdk/rust/Cargo.toml: cite the
  pinned agent-control-spec 0.4.0-alpha.3 and agent-hooks-sdk
  0.1.0-alpha.5 rather than alpha.1 and alpha.4.
- policy-engine/README.md: LICENSE.acs now covers the spec, schema and
  conformance files; the engine is a registry dependency, not vendored.
- Add the Microsoft license header to generator/tests/test_spec_artefacts.py
  and tests/artifact_enforcement_probe.py.
- BREAKING_CHANGES.md: list the host reason-code moves
  (runtime_error:approval_* to host_error:approval_*, action_mismatch to
  identity_mismatch, the new approval_unresolved, adapter and streaming
  codes, the effects codes that went away) and the core module-path moves
  (manifest_yaml, telemetry_sinks, identity, removed modules, crate-type).
  Fix the five docs that still cited the old approval codes.
- docs/rust-capability-manifest.md: main now depends on the published
  engine; drop "blocked" and the embedded 0.3.1-beta wording.
- scripts/ci/smoke_acs_python_wheel.py: feed the 0.4.0-alpha.1 grammar
  and validate it, so the release smoke checks the shipped grammar rather
  than a version the parser does not inspect.

Signed-off-by: MohammadHaroonAbuomar <40180927+MohammadHaroonAbuomar@users.noreply.github.com>
(cherry picked from commit 7417a1f)

* chore: satisfy the spell-check gate on the retarget follow-up

Replace the personal name in the ownership note with the role, use a
cspell-safe embedded-space host in the SSRF test vector, and add
nonblocking to the repo dictionary.

Signed-off-by: MohammadHaroonAbuomar <40180927+MohammadHaroonAbuomar@users.noreply.github.com>
(cherry picked from commit b3399f0)

* docs(deps): audit record for the url crate as a direct SDK dependency

The Dependency Audit Trail gate requires an audit doc in any PR that
changes a lockfile. The follow-up adds url 2.5.8 (already resolved
transitively) as a direct dependency of the ACS Rust SDK so the SSRF
guard parses hosts with the same crate the fetcher uses.

Signed-off-by: MohammadHaroonAbuomar <40180927+MohammadHaroonAbuomar@users.noreply.github.com>

---------

Signed-off-by: MohammadHaroonAbuomar <40180927+MohammadHaroonAbuomar@users.noreply.github.com>
Signed-off-by: yuvrajsingh2428 <offcyuvi2428@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants