Repository navigation
feat(trace): add TRACE v0.2 trust record data model and session mapping (#3086) - #3098
Conversation
🤖 AI Agent: code-reviewer — View details
TL;DR: 0 blockers, 1 warning. The implementation is solid, but a minor improvement is suggested for test coverage.
Action items:
Warnings:
No issues found. Clean change. |
🤖 AI Agent: breaking-change-detector — API Compatibility
API Compatibility
|
Dependency Review✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.Scanned FilesNone |
🤖 AI Agent: test-generator — `agentmesh/governance/trace_model.py`
|
🤖 AI Agent: security-scanner — View details
No security issues found. |
🤖 AI Agent: docs-sync-checker — Docs Sync
Docs Sync
|
PR Review Summary
Verdict: AI review comments are untrusted advisory output. The summary reports workflow-generated completion status only, not model-authored pass/fail claims. |
3313d51 to
e9f68e3
Compare
…ADR-0032, step 1/5)
Implements the data model layer for TRACE v0.2 Trust Records without signing,
sinks, or wire transport (those land in steps 2-5). Adds session-to-record
mapping so a closed AGT session can be projected into the 11-field TRACE payload
described in ADR-0032.
Changes:
- New trace_model.py: TraceModelConfig, TraceSession, TrustRecord dataclasses
and session_to_trust_record() mapping function with _jcs_hash() helper
- appraisal.status set to "contraindicated" when any audit entry has
outcome=="denied" or event_type in {"policy_violation", "tool_blocked"}
- tool_transcript.hash uses RFC 8785 JCS-canonical JSON (UTF-8, sorted keys,
no whitespace) per the TRACE spec
- PolicyInterceptor gains optional policy_bundle_hash param captured at load time
so the sink can include it in the Trust Record at session close
- GovernedCallable computes _policy_bundle_hash from raw bundle bytes at
policy load time (sha256: prefix, empty string when bytes unavailable)
- governance/__init__.py exports the four new public symbols
Closes #3086
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Signed-off-by: Imran Siddique <imran.siddique@opaque.co>
e9f68e3 to
46c4439
Compare
4770a32
into
main
Summary
Implements the data model layer for TRACE v0.2 Trust Records (ADR-0032, step 1 of 5). No signing, sinks, or wire transport yet -- those land in steps 2-5.
trace_model.py--TraceModelConfig,TraceSession,TrustRecorddataclasses +session_to_trust_record()mapping functionappraisal.status-- set to"contraindicated"when any entry hasoutcome=="denied"orevent_type in {"policy_violation", "tool_blocked"};"affirming"otherwisetool_transcript.hash-- RFC 8785 JCS-canonical JSON hash per TRACE spec (sha256:prefix)PolicyInterceptor-- optionalpolicy_bundle_hashparam stored at load time; sink reads it at session closeGovernedCallable-- computes_policy_bundle_hashfrom raw bundle bytes at policy load timegovernance/__init__.py-- exports the four new public symbolsAcceptance criteria
TrustRecorddataclass with all 11 required TRACE v0.2 fieldssession_to_trust_record(session, config) -> dictmapping functionPolicyInterceptorstorespolicy_bundle_hashat load timesubjectderived fromsession.agent_did(e.g.did:mesh:spiffe://...) -- no SPIFFE config needed (ADR-0032 v0.2)appraisal.status = "contraindicated", call_count counts onlytool_invocationentries, transcript hash is deterministicTest plan
pytest agent-governance-python/agent-mesh/tests/governance/test_trace_model.py -vpasses (10 test cases)References
🤖 Generated with Claude Code