Skip to content

fix(agent-os): fill four empty if-body syntax errors in crewai_adapter - #2911

Merged
Imran Siddique (imran-siddique) merged 5 commits into
mainfrom
hotfix/crewai-adapter-syntax-errors
Jun 9, 2026
Merged

Imran Siddique (imran-siddique) merged 5 commits into
mainfrom
hotfix/crewai-adapter-syntax-errors

Conversation

@imran-siddique

Copy link
Copy Markdown
Collaborator

Summary

  • Commit 16e392c (#2572) introduced four if statements with no body in crewai_adapter.py, causing IndentationError on import
  • This breaks lint (agent-os), test (agent-os, *), test (agt-policies, *), and docker-compose-test on main

Four fixes:

  • if tool_name not in kernel.policy.allowed_tools: — add return False with log
  • if matched: in after_tool_call — raise PolicyViolationError (consistent with other output denials)
  • if not allowed: after pre_execute in before_llm_call — add return False with log
  • if matched: in after_llm_call — raise PolicyViolationError

Test plan

  • lint (agent-os) passes
  • test (agent-os, 3.11/3.12/3.13) passes
  • test (agt-policies, 3.11/3.12/3.13) passes
  • docker-compose-test passes

🤖 Generated with Claude Code

…adapter

Commit 16e392c added four if statements with no body, causing
IndentationError at import time and failing lint, test, and
docker-compose-test jobs on main.

- allowed_tools check: return False when tool not in allowlist
- after_tool_call pattern match: raise PolicyViolationError
- before_llm_call pre_execute check: return False with log
- after_llm_call pattern match: raise PolicyViolationError

Signed-off-by: Imran Siddique <imran.siddique@opaque.co>
@github-actions

github-actions Bot commented Jun 9, 2026 •

Copy link
Copy Markdown

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

Scanned Files

None

@github-actions github-actions Bot added the size/S Small PR (< 50 lines) label Jun 9, 2026
@github-actions

github-actions Bot commented Jun 9, 2026 •

Copy link
Copy Markdown

PR Review Summary

Check Status Details
🔍 Code Review ⚠️ Missing No current-run comment
🛡️ Security Scan ⚠️ Missing No current-run comment
🔄 Breaking Changes ⚠️ Missing No current-run comment
📝 Docs Sync ⚠️ Missing No current-run comment
🧪 Test Coverage ⚠️ Missing No current-run comment

Verdict: ⚠️ AI review incomplete; ready for human review

AI review comments are untrusted advisory output. The summary reports workflow-generated completion status only, not model-authored pass/fail claims.

…n, sk adapters

Same commit (16e392c) left duplicate import blocks in three adapters,
causing F811 ruff errors masked by the SyntaxError in crewai_adapter.

- google_adk_adapter: remove redundant second 'from .base import' line
- langchain_adapter: merge Callable, remove duplicate datetime/typing/.base imports
- semantic_kernel_adapter: same as langchain_adapter

Signed-off-by: Imran Siddique <imran.siddique@opaque.co>
PR #2782 made private_key_bytes required when local_mode=True registers
an agent (registry now verifies the manifest signature). Tests were not
updated and failed with ValueError on every register() call.

Use generate_keypair() to create a real keypair per test client and
set the manifest verification_key to the matching public key.

Signed-off-by: Imran Siddique <imran.siddique@opaque.co>
@github-actions github-actions Bot added tests size/M Medium PR (< 200 lines) and removed size/S Small PR (< 50 lines) labels Jun 9, 2026
@imran-siddique

Copy link
Copy Markdown
Collaborator Author
@microsoft-github-policy-service agree

@microsoft-github-policy-service agree

…ning

Registry verifies signatures on register/deregister. Tests using fake
keys ("ed25519:test_key_123") and fake sigs ("sig") caused
InvalidSignatureError. Replace create_test_manifest with
create_signed_manifest returning a real keypair, and recompute the
deregister signature as sign(private_key_bytes, agent_did.encode()).

Signed-off-by: Imran Siddique <imran.siddique@opaque.co>
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@github-actions github-actions Bot added size/L Large PR (< 500 lines) and removed size/M Medium PR (< 200 lines) labels Jun 9, 2026
…tcome tests

client.create_escrow now passes requester_signature via _sign_escrow().
sign_dmz_policy replaced nonexistent _generate_signature with an inline
sign(private_key_bytes, transfer_id.encode()) call.
TestProofOfOutcome tests generate a real keypair and pass requester_signature
to poo.create_escrow(), satisfying the ValueError guard added in 16e392c.

Signed-off-by: Imran Siddique <imran.siddique@opaque.co>
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@imran-siddique
Imran Siddique (imran-siddique) merged commit 245c9d6 into main Jun 9, 2026
125 of 126 checks passed
@imran-siddique
Imran Siddique (imran-siddique) deleted the hotfix/crewai-adapter-syntax-errors branch June 9, 2026 21:35
Imran Siddique (imran-siddique) added a commit that referenced this pull request Jun 9, 2026
Promote all 4.0.x packages to 4.1.0 to reflect the changes since
the v4.0.0 release on 2026-06-01:
- skill-aware audit trail hardening (#2572)
- Ed25519 signature verification in Nexus registry/escrow (#2782)
- ring enforcement wiring in sandbox providers (#2868)
- dynamic policy conditions: time-based, cost-aware, quota-aware (#2870)
- policy regression testing framework (agt test) (#2869)
- crewai adapter if-body syntax fix (#2911)
- various security fixes, dependabot updates

Also promote agt-policies from 5.0.0a1 to 5.0.0 (alpha has been
live on PyPI since the June 9 dry-run confirmed the build was clean).

Signed-off-by: Imran Siddique <imran.siddique@opaque.co>
Imran Siddique (imran-siddique) added a commit that referenced this pull request Jun 9, 2026
Promote all 4.0.x packages to 4.1.0 to reflect the changes since
the v4.0.0 release on 2026-06-01:
- skill-aware audit trail hardening (#2572)
- Ed25519 signature verification in Nexus registry/escrow (#2782)
- ring enforcement wiring in sandbox providers (#2868)
- dynamic policy conditions: time-based, cost-aware, quota-aware (#2870)
- policy regression testing framework (agt test) (#2869)
- crewai adapter if-body syntax fix (#2911)
- various security fixes, dependabot updates

Also promote agt-policies from 5.0.0a1 to 5.0.0 (alpha has been
live on PyPI since the June 9 dry-run confirmed the build was clean).

Signed-off-by: Imran Siddique <imran.siddique@opaque.co>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/L Large PR (< 500 lines) tests

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant