Repository navigation
feat(engine-api): add capability-metadata library for AGT Studio - #3027
Conversation
Implements the capability-flag substrate from the Engine API contract (docs/studio/engine-api-contract.md sections 5 and 6): a CapabilityFlags model enforcing the read-only invariant at construction, a capability_flags decorator, an OpenAPI x-capability-flags injection hook, and the read-only client allowlist derivation. Library-only and purely additive; no routes. Closes #3026 Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Signed-off-by: Ricky Gummadi <ricky.gummadi@outlook.com>
🤖 AI Agent: code-reviewer — Action Items:
TL;DR: 0 blockers, 1 warning. The PR introduces a well-structured and tested capability-metadata library for the Engine API, but the lack of explicit tests for edge cases in
Action Items:
Warnings:
|
🤖 AI Agent: docs-sync-checker — Docs Sync
Docs Sync
|
🤖 AI Agent: test-generator — `src/agentmesh/engine_api/capabilities.py`
|
Dependency Review✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.Scanned FilesNone |
🤖 AI Agent: security-scanner — View details
No security issues found. |
🤖 AI Agent: breaking-change-detector — API Compatibility
API CompatibilityNo breaking changes detected. |
PR Review Summary
Verdict: AI review comments are untrusted advisory output. The summary reports workflow-generated completion status only, not model-authored pass/fail claims. |
|
🟡 Contributor Check: MEDIUM
Automated check by AGT Contributor Check. |
- derive_studio_client_allowlist: guard against non-bool flag values and drop the prohibited is False comparison (AGENTS.md CodeQL guidance) in favour of isinstance + truthy check. - Replace is True/is False boolean-identity assertions in the capability tests with truthy/falsy asserts to match the project standard. - Add dunder to the cspell dictionary so the spell-check gate passes. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Signed-off-by: Ricky Gummadi <ricky.gummadi@outlook.com>
Imran Siddique (imran-siddique)
left a comment
There was a problem hiding this comment.
Reviewed. Clean implementation: frozen Pydantic model with the read-only invariant enforced at construction time, extra='forbid' prevents accidental extension, and the OpenAPI hook reads directly from __capability_flags__. No breaking changes — purely additive library. Merging; pre-existing dep-confusion-scan and docker-compose-test failures are not introduced here.
60579ca
into
main
…rosoft#3027) * feat(engine-api): add capability-metadata library for AGT Studio Implements the capability-flag substrate from the Engine API contract (docs/studio/engine-api-contract.md sections 5 and 6): a CapabilityFlags model enforcing the read-only invariant at construction, a capability_flags decorator, an OpenAPI x-capability-flags injection hook, and the read-only client allowlist derivation. Library-only and purely additive; no routes. Closes microsoft#3026 Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Signed-off-by: Ricky Gummadi <ricky.gummadi@outlook.com> * fix(engine-api): address review and spell-check - derive_studio_client_allowlist: guard against non-bool flag values and drop the prohibited is False comparison (AGENTS.md CodeQL guidance) in favour of isinstance + truthy check. - Replace is True/is False boolean-identity assertions in the capability tests with truthy/falsy asserts to match the project standard. - Add dunder to the cspell dictionary so the spell-check gate passes. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Signed-off-by: Ricky Gummadi <ricky.gummadi@outlook.com> --------- Signed-off-by: Ricky Gummadi <ricky.gummadi@outlook.com> Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Signed-off-by: jlaportebot <jlaportebot@gmail.com>
Summary
Adds a small, reusable
agentmesh.engine_apilibrary that implements the capability-metadata substrate from the Engine API contract, so the future FastAPI reference adapter (issue #3) can declare each endpoint's three flags inline and emit them as thex-capability-flagsOpenAPI extension. Library-only and purely additive: no HTTP routes are exposed and no existing source is modified.Problem
The Studio contract (
docs/studio/engine-api-contract.mdsections 5 and 6) defines three per-endpoint capability flags and a read-only invariant, but there was no Python mechanism to declare them, emit them into the generated OpenAPI document, or machine-derive the read-only Studio client allowlist. Without this, the allowlist would be hand-maintained and the read-only rule would be unenforceable by CI (Epic 1d).Changes
src/agentmesh/engine_api/capabilities.pyCapabilityFlagsPydantic v2 model (frozen, three booleans) that enforces the read-only invariantread_only_surface == (not runtime_mutating)at construction, raising a clearValueError; plus thecapability_flags(...)decorator that validates and attaches flags under__capability_flags__.src/agentmesh/engine_api/openapi.pyinject_capability_extension(app)overridesapp.openapito writex-capability-flagsonto each operation and raises if a schema operation has no attached flags (fail loudly);derive_studio_client_allowlist(openapi_doc)returns sortedoperationIds whereruntime_mutating == false. FastAPI is lazy-imported.src/agentmesh/engine_api/__init__.pytests/engine_api/test_capabilities.pypolicy_saveexclusion, 12-of-13 fixture).tests/engine_api/test_openapi.pyopenapi.yaml, idempotency, the missing-flags raise, and end-to-end allowlist derivation.tests/engine_api/__init__.pyDesign decisions
__capability_flags__(dunder, exported asCAPABILITY_FLAGS_ATTR).pyproject.tomlis a deprecation stub whose runtime deps only carry the-coreredirect, andfastapiis already in the[dev]extra used by CI. The OpenAPI hook lazy-imports FastAPI instead.Testing
python -m ruff check --select E,F,W --ignore E501 .../engine_api .../tests/engine_apipasses.python -m pytest tests/engine_apipasses (22 passed).Closes #3026