Repository navigation
feat(trace): emit TRACE v0.2 Trust Records at session close (ADR-0032) - #3099
Conversation
🤖 AI Agent: code-reviewer — Action items:
TL;DR: 0 blockers, 1 warning. The change introduces TRACE v0.2 Trust Record emission at session close, with no critical security or correctness issues identified.
Action items:
Warnings:
|
🤖 AI Agent: breaking-change-detector — API Compatibility
API Compatibility
|
🤖 AI Agent: security-scanner — View details
No security issues found. |
🤖 AI Agent: docs-sync-checker — Docs Sync
Docs Sync
|
🤖 AI Agent: test-generator — `agentmesh/governance/trace_sink.py`
|
Dependency ReviewThe following issues were found:
License Issuesagent-governance-python/agent-governance-toolkit-core/pyproject.toml
OpenSSF Scorecard
Scanned Files
|
PR Review Summary
Verdict: AI review comments are untrusted advisory output. The summary reports workflow-generated completion status only, not model-authored pass/fail claims. |
📦 Dependency diff (SBOM)Comparing main → feat/agt-3086-3090-trace-emission. ✅ No dependency changes detected. |
b16449b to
676db01
Compare
676db01 to
da3cf9f
Compare
dd91cfd to
1b5293b
Compare
Implements issues #3086-#3090. Uses agentrust-trace>=0.2.0 for TrustRecord model, Ed25519 signing, and validation -- no local reimplementation. - trace_sink.py: TraceConfig dataclass, session_to_trust_record() mapping function, TRACEAuditSink session-close emitter - govern.py: TraceConfig field on GovernanceConfig, policy bundle hash computation at init, TRACEAuditSink wired up, close_session() method on GovernedCallable - governance/__init__.py: export TraceConfig, TRACEAuditSink - agent-governance-toolkit-core/pyproject.toml: agentrust-trace>=0.2.0 runtime dependency - agent-mesh/pyproject.toml: agentrust-trace>=0.2.0 in dev extras - tests/governance/test_trace_sink.py: 20 tests covering mapping, emission, file output, validation, and GovernedCallable.close_session() - check_dependency_confusion.py: register agentrust-trace in allowlist - .cspell-repo-terms.txt: add agentrust, isfile, reimplementation Signed-off-by: Imran Siddique <imran.siddique@opaque.co> Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Marks status accepted. Corrects wire format (signed JSON, not compact JWT), documents TraceConfig/close_session() API, notes key management delegation to agentrust-trace, and adds agentrust-trace v0.2.0 to references. Signed-off-by: Imran Siddique <imran.siddique@opaque.co> Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
8815fd3 to
560fd2b
Compare
Both terms appear in ADR-0032 (CBOR-COSE wire format deferral note). Signed-off-by: Imran Siddique <imran.siddique@opaque.co> Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
condition: "true" is treated as a path lookup by the policy engine, returning False for any context. Use action.type != 'deny' instead, which evaluates to True for all normal action calls. Signed-off-by: Imran Siddique <imran.siddique@opaque.co> Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Signed-off-by: Imran Siddique <imran.siddique@opaque.co> Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
45d89de
into
main
Summary
trace_sink.pywithTraceConfig,session_to_trust_record(), andTRACEAuditSink-- the session-close TRACE emitterTraceConfigfield toGovernanceConfig; addsclose_session()toGovernedCallableas the explicit session-end hookagentrust-trace>=0.2.0as a runtime dependency ofagent-governance-toolkit-coretests/governance/test_trace_sink.pycovering field mapping, file output, signed record validation, and end-to-endgovern()+close_session()Design decisions
No local reimplementation.
TrustRecord,sign_record, andload_signing_keycome fromagentrust-trace>=0.2.0. The only AGT-specific code is the mapping fromAuditLogto the TRACE dict.Session-close pattern, not entry-level sink.
TRACEAuditSinkis NOT anAuditSink. It is called explicitly viaclose_session()once per agent session after all governed calls complete. Entry-level sinks write one line per call; TRACE writes one record per session.Phase 1 only.
platform: software-only,slsa_level: 0. Phase 2 (hardware TEE attestation binding) is cMCP responsibility per ADR-0032.DID required.
close_session()emits a warning and returnsNoneifagent_idis not a DID or SPIFFE URI.Usage
Test plan
pytest tests/governance/test_trace_sink.pypassestrace-tests verify --record <output>.json --level 0passes on emitted recordsagentrust-trace>=0.2.0resolves inpip install agent-governance-toolkit-coreCloses #3086, #3087, #3088, #3089, #3090
🤖 Generated with Claude Code