Skip to content

feat(agent-mesh): wire GovernedCallable into ring enforcement (rebased #2731 + hardening) - #2761

Merged
Imran Siddique (imran-siddique) merged 11 commits into
microsoft:mainfrom
imran-siddique:feat/ring-enforcement-v2
Jun 2, 2026
Merged

Imran Siddique (imran-siddique) merged 11 commits into
microsoft:mainfrom
imran-siddique:feat/ring-enforcement-v2

Conversation

@imran-siddique

Copy link
Copy Markdown
Collaborator

Summary

Rebases #2731 (rsd-darshan) onto current main and applies two security hardenings that came out of code review.

Wires GovernedCallable into hypervisor ring enforcement so a denied ring never reaches the policy engine.

Hardenings on top of #2731

  1. Shared circuit breaker per (agent_id, session_id). Each GovernedCallable previously held its own RingBreachDetector. An agent with N governed tools could spend the full per-detector violation budget N times before the breaker tripped. Now detectors are held in a module-level registry keyed by (agent_id, session_id) so all of an agent's callables share one breaker.

  2. Exact-token resource inference. The original substring match flagged false positives like set_httponly_flag -> NETWORK and overwrite_protection_check -> FILESYSTEM. Inference now splits the action string on non-alphanumeric chars and requires an exact token match against the subprocess/network/filesystem token sets.

Changes

File Change
�gent-governance-python/agent-mesh/src/agentmesh/governance/govern.py Add shared detector registry + _infer_resource_type helper
�gent-governance-python/agent-mesh/tests/test_govern.py 6 new tests for shared-detector + token-boundary inference

Testing

  • 6 new tests covering shared vs. isolated detectors and resource-type inference edge cases.
  • Existing TestRingEnforcement suite still passes (no behavior change for
    ing=None).

Supersedes #2731. Original author credit preserved via co-author trailer.

Co-authored-by: rsd-darshan

Add an autouse fixture in TestRingEnforcement that calls
_reset_shared_breach_detectors before and after each test. The shared
detector now persists across tests by design (singleton per
agent/session), which would otherwise let an earlier test's circuit
breaker bleed into a later one's assertions.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Signed-off-by: Imran Siddique <imran.siddique@microsoft.com>
@imran-siddique
Imran Siddique (imran-siddique) merged commit 8f1d438 into microsoft:main Jun 2, 2026
31 checks passed
@imran-siddique
Imran Siddique (imran-siddique) deleted the feat/ring-enforcement-v2 branch June 2, 2026 00:43
Imran Siddique (imran-siddique) added a commit that referenced this pull request Jun 2, 2026
Resolves ruff F401 lint failure on main introduced by ring-enforcement
landing (#2761). The ResourceType symbol is only referenced via string
comparisons in the rule grammar, not imported at runtime.

Signed-off-by: Imran Siddique <imran.siddique@microsoft.com>
Darshan Poudel (rsd-darshan) added a commit to rsd-darshan/agent-governance-toolkit that referenced this pull request Jun 2, 2026
…mports

agent_hypervisor 4.0.0 does not exist on PyPI (latest: 3.7.0), so the
hard dependency broke the CI install step for agent-sandbox.

- Move agent_hypervisor to optional extras as >=3.7.0,<5.0 (mirrors the
  pattern used in agent-mesh after microsoft#2761)
- Guard every hypervisor import behind `if ring is not None:` so the
  package is never imported when ring enforcement is not configured
- SandboxConfig.ring defaults to None; providers skip ring enforcement
  when None, preserving all existing behaviour unchanged
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

agent-mesh agent-mesh package dependencies Pull requests that update a dependency file size/L Large PR (< 500 lines) tests

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants