Repository navigation
fix(agent-os): deepcopy context in YAML-match audit entry - #3037
Conversation
The flat evaluator's rule-match branch set context_snapshot to the live context reference instead of a copy, leaving audit records sharing state with the caller. Every other branch already used copy.deepcopy; this one was missed in #3023. Fixes TestContextSnapshotIsolation::test_flat_yaml_match_isolated_from_top_level_mutation. Signed-off-by: Imran Siddique <imran.siddique@opaque.co>
🤖 AI Agent: breaking-change-detector — API Compatibility
API CompatibilityNo breaking changes detected. |
🤖 AI Agent: test-generator — `agent-governance-python/agent-os/src/agent_os/policies/evaluator.py`
|
🤖 AI Agent: security-scanner — View details
No security issues found. |
Dependency Review✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.Scanned FilesNone |
🤖 AI Agent: code-reviewer — View details
TL;DR: 0 blockers, 0 warnings. Fix ensures audit record isolation; clean change.
No action items required. Clean change. |
🤖 AI Agent: docs-sync-checker — Docs Sync
Docs SyncDocumentation is in sync. |
PR Review Summary
Verdict: AI review comments are untrusted advisory output. The summary reports workflow-generated completion status only, not model-authored pass/fail claims. |
f401f19
into
main
…3037) The flat evaluator's rule-match branch set context_snapshot to the live context reference instead of a copy, leaving audit records sharing state with the caller. Every other branch already used copy.deepcopy; this one was missed in microsoft#3023. Fixes TestContextSnapshotIsolation::test_flat_yaml_match_isolated_from_top_level_mutation. Signed-off-by: Imran Siddique <imran.siddique@opaque.co> Signed-off-by: jlaportebot <jlaportebot@gmail.com>
Summary
_evaluate_flat()setcontext_snapshotto the livecontextreference rather than a copybackend error,backend success,default action,exception) already calledcopy.deepcopy(context)— this one was missed when fix(agent-os): deep-copy context before storing as context_snapshot #3023 landedcontextwere visible inside the audit record, violating the isolation invariantTest
TestContextSnapshotIsolation::test_flat_yaml_match_isolated_from_top_level_mutationintests/test_folder_governance.pywas failing on all three Python versions. This commit makes it pass.Checklist
--signofffor DCO🤖 Generated with Claude Code