Skip to content

fix(agent-os): deepcopy context in YAML-match audit entry - #3037

Merged
Imran Siddique (imran-siddique) merged 1 commit into
mainfrom
fix/context-snapshot-yaml-match
Jun 15, 2026
Merged

Imran Siddique (imran-siddique) merged 1 commit into
mainfrom
fix/context-snapshot-yaml-match

Conversation

@imran-siddique

Copy link
Copy Markdown
Collaborator

Summary

  • YAML-match branch of _evaluate_flat() set context_snapshot to the live context reference rather than a copy
  • Every other branch (backend error, backend success, default action, exception) already called copy.deepcopy(context) — this one was missed when fix(agent-os): deep-copy context before storing as context_snapshot #3023 landed
  • Post-evaluation mutations to context were visible inside the audit record, violating the isolation invariant

Test

TestContextSnapshotIsolation::test_flat_yaml_match_isolated_from_top_level_mutation in tests/test_folder_governance.py was failing on all three Python versions. This commit makes it pass.

Checklist

  • One-line change, no behavior impact beyond isolation correctness
  • Existing test coverage
  • --signoff for DCO

🤖 Generated with Claude Code

The flat evaluator's rule-match branch set context_snapshot to the
live context reference instead of a copy, leaving audit records
sharing state with the caller. Every other branch already used
copy.deepcopy; this one was missed in #3023.

Fixes TestContextSnapshotIsolation::test_flat_yaml_match_isolated_from_top_level_mutation.

Signed-off-by: Imran Siddique <imran.siddique@opaque.co>
@github-actions

Copy link
Copy Markdown
🤖 AI Agent: breaking-change-detector — API Compatibility

AI-generated review output. Treat it as untrusted analysis and verify before acting.

API Compatibility

No breaking changes detected.

@github-actions

Copy link
Copy Markdown
🤖 AI Agent: test-generator — `agent-governance-python/agent-os/src/agent_os/policies/evaluator.py`

AI-generated review output. Treat it as untrusted analysis and verify before acting.

agent-governance-python/agent-os/src/agent_os/policies/evaluator.py

  • test_flat_yaml_match_isolated_from_top_level_mutation -- Validate that context_snapshot in the YAML-match branch is isolated from mutations to the context object after evaluation.

@github-actions

Copy link
Copy Markdown
🤖 AI Agent: security-scanner — View details

AI-generated review output. Treat it as untrusted analysis and verify before acting.

No security issues found.

@github-actions github-actions Bot added the size/XS Extra small PR (< 10 lines) label Jun 15, 2026
@github-actions

Copy link
Copy Markdown

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

Scanned Files

None

@github-actions

Copy link
Copy Markdown
🤖 AI Agent: code-reviewer — View details

AI-generated review output. Treat it as untrusted analysis and verify before acting.

TL;DR: 0 blockers, 0 warnings. Fix ensures audit record isolation; clean change.

# Sev Issue Where

No action items required. Clean change.

@github-actions

Copy link
Copy Markdown
🤖 AI Agent: docs-sync-checker — Docs Sync

AI-generated review output. Treat it as untrusted analysis and verify before acting.

Docs Sync

Documentation is in sync.

@github-actions

Copy link
Copy Markdown

PR Review Summary

Check Status Details
🔍 Code Review ⚠️ Missing No current-run comment
🛡️ Security Scan ⚠️ Missing No current-run comment
🔄 Breaking Changes ⚠️ Missing No current-run comment
📝 Docs Sync ⚠️ Missing No current-run comment
🧪 Test Coverage ⚠️ Missing No current-run comment

Verdict: ⚠️ AI review incomplete; ready for human review

AI review comments are untrusted advisory output. The summary reports workflow-generated completion status only, not model-authored pass/fail claims.

@imran-siddique
Imran Siddique (imran-siddique) merged commit f401f19 into main Jun 15, 2026
127 of 131 checks passed
@imran-siddique
Imran Siddique (imran-siddique) deleted the fix/context-snapshot-yaml-match branch June 15, 2026 20:52
jlaportebot (jlaportebot) pushed a commit to jlaportebot/agent-governance-toolkit that referenced this pull request Jun 17, 2026
…3037)

The flat evaluator's rule-match branch set context_snapshot to the
live context reference instead of a copy, leaving audit records
sharing state with the caller. Every other branch already used
copy.deepcopy; this one was missed in microsoft#3023.

Fixes TestContextSnapshotIsolation::test_flat_yaml_match_isolated_from_top_level_mutation.

Signed-off-by: Imran Siddique <imran.siddique@opaque.co>
Signed-off-by: jlaportebot <jlaportebot@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/XS Extra small PR (< 10 lines)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant