Repository navigation
feat(agent-mesh): action-bound approval protocol foundation (ADR-0030 step 1) - #3015
Conversation
…0030) Implements step 1 of the ADR-0030 migration: the versioned protocol models, RFC 8785 JCS digest helper, durable approval-store contract, and the approval coordinator. Purely additive — nothing is wired into the policy evaluator or the legacy approval handlers yet. The coordinator binds each approval to one action digest, records hash-linked, append-only approval-chain entries, resolves require_approval to a terminal allow/deny/expired, and performs fail-closed execution-time revalidation: action digest, policy version, chain version, expiry, chain integrity, and one-time consumption. LLM advisory votes are recorded but never satisfy a stage (ADR-0030 section 8). Refs microsoft#2478 Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
PR Review Summary
Verdict: AI review comments are untrusted advisory output. The summary reports workflow-generated completion status only, not model-authored pass/fail claims. |
|
ADR-0030 has merged and #2478 is now unblocked. This is step 1 of the ADR section-9 migration (the action-bound approval-protocol foundation) — marking ready for review. Steps 2-6 will follow as separate PRs. |
Imran Siddique (imran-siddique)
left a comment
There was a problem hiding this comment.
Clean step-1 foundation. JCS canonicalization vendored correctly (no new dep), action digest is deterministic over all execution-relevant fields, validate_for_execution is fail-closed with machine-readable reason codes, and the hash-linked chain entry structure matches ADR-0030 section 4. Purely additive — nothing wired into the evaluator yet, which is exactly right for step 1. Unblocks #2478.
4bc2b1b
into
microsoft:main
…0030) (microsoft#3015) Implements step 1 of the ADR-0030 migration: the versioned protocol models, RFC 8785 JCS digest helper, durable approval-store contract, and the approval coordinator. Purely additive — nothing is wired into the policy evaluator or the legacy approval handlers yet. The coordinator binds each approval to one action digest, records hash-linked, append-only approval-chain entries, resolves require_approval to a terminal allow/deny/expired, and performs fail-closed execution-time revalidation: action digest, policy version, chain version, expiry, chain integrity, and one-time consumption. LLM advisory votes are recorded but never satisfy a stage (ADR-0030 section 8). Refs microsoft#2478 Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com> Signed-off-by: jlaportebot <jlaportebot@gmail.com>
Summary
Step 1 of the ADR-0030 migration (section 9): the action-bound, fail-closed approval protocol foundation in
agentmesh.governance.approval_protocol.Purely additive — nothing is wired into the policy evaluator or the legacy
agentmesh.governance.approvalhandlers yet, so no existing import path or behavior changes.Unblocks implementation of #2478 (
require_approvalverdict / human + LLM approval chains).What's included
digest.py— vendored RFC 8785 JCS canonicalization +sha256_jcs()(no new dependency).binding.py—ActionBinding/ActionTargetand theaction_digest(ADR section 2): an approval is bound to one exact action; changing any parameter, target, tool schema version, agent, or subject changes the digest.models.py— the four protocol objects (PolicyDecisionRecord,ApprovalRequest,ApprovalChainEntry,ApprovalResolution) with hash-linked, self-sealing chain entries (ADR section 3).store.py—ApprovalStoredurable-store protocol + thread-safeInMemoryApprovalStorewith atomic one-timeconsume()(ADR section 5).coordinator.py—ApprovalCoordinator: open → submit (authority-checked, hash-linked) → resolve → 7-point fail-closed execution-time revalidation (ADR section 6).Fail-closed properties (all test-covered)
chain_tampered).Tests
tests/test_approval_protocol.py— 25 tests, all passing.Deferred to follow-up PRs (per ADR section 9)
require_approvalthrough PolicyEvaluator /governApprovalHandlercompatibility adaptersRefs #2478. Implements ADR-0030 step 1.
🤖 Generated with Claude Code