Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
25 commits
Select commit Hold shift + click to select a range
609e5f2
refactor(v4-removal)!: replace the v4 policy language with ACS v5 acr…
liamcrumm Jul 28, 2026
5347f08
fix(agent-os): remove dead branches and duplicate assignments in the …
liamcrumm Jul 28, 2026
414ab13
ci: fail policy validation on a manifest that omits its ACS version
liamcrumm Jul 28, 2026
65ba0ce
ci: let BREAKING_CHANGES.md name the v4 symbols it removes
liamcrumm Jul 28, 2026
1ebfb8a
fix: stop treating a transform verdict as plain permission
liamcrumm Jul 28, 2026
b0e14ae
docs: record this PR's removed exports where the removal happens
liamcrumm Jul 29, 2026
b128509
fix: an unbound output point is not a denial
liamcrumm Jul 29, 2026
8997195
fix: apply the unbound-point permit at the runtime, not the base class
liamcrumm Jul 29, 2026
ca13703
fix: permit every unconfigured post-hoc point, not just output
liamcrumm Jul 29, 2026
67be2b0
fix: refuse an unapplied transform everywhere, and stop permitting un…
liamcrumm Jul 29, 2026
4a71144
fix: refuse a transform in the MCP gateway and the trust root
liamcrumm Jul 29, 2026
23edd95
test: make the transform census see through delegation and past docst…
liamcrumm Jul 29, 2026
3ba6ee1
fix: remove the pydantic-ai tool wrapper this PR orphaned
liamcrumm Jul 29, 2026
da8e989
fix: a replacement of the wrong shape no longer falls through
liamcrumm Jul 29, 2026
c71f5ee
test: fold the unconfigured-point tests into the transform census file
liamcrumm Jul 29, 2026
5f85452
test: move the framework SDK stubs into conftest
liamcrumm Jul 29, 2026
66a0e1e
fix: catch the transform drops hiding behind a third condition
liamcrumm Jul 29, 2026
124adb2
fix: audit and surface a refused transform the way a denial is
liamcrumm Jul 29, 2026
f88153b
fix: a rewrite that fails to land is refused, not swallowed
liamcrumm Jul 29, 2026
39c7ca2
fix: a write target that takes nothing is refused, not passed over
liamcrumm Jul 29, 2026
293d478
fix: redact and continue where the value is the return, not an attribute
liamcrumm Jul 29, 2026
a8ba642
test: make the verdict stubs read the same at every layer of the stack
liamcrumm Jul 29, 2026
8345bb8
fix: spell-check on the words this PR introduces
liamcrumm Jul 29, 2026
59d46a5
fix: refuse a transform langchain cannot write, instead of returning …
liamcrumm Jul 29, 2026
fd01a1c
test: close two holes in the target-guard census
liamcrumm Jul 29, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
8 changes: 0 additions & 8 deletions .github/workflows/benchmarks.yml
Original file line number Diff line number Diff line change
Expand Up @@ -25,10 +25,6 @@ jobs:
working-directory: agent-governance-python/agent-sre
run: pip install --no-cache-dir -e ".[dev]" --quiet # Install local package (Scorecard: pinned via pyproject.toml)

- name: Run policy benchmarks
working-directory: agent-governance-python/agent-os
run: python benchmarks/bench_policy.py | tee /tmp/bench_policy.json

- name: Run kernel benchmarks
working-directory: agent-governance-python/agent-os
run: python benchmarks/bench_kernel.py | tee /tmp/bench_kernel.json
Expand All @@ -37,10 +33,6 @@ jobs:
working-directory: agent-governance-python/agent-os
run: python benchmarks/bench_audit.py | tee /tmp/bench_audit.json

- name: Run adapter benchmarks
working-directory: agent-governance-python/agent-os
run: python benchmarks/bench_adapters.py | tee /tmp/bench_adapters.json

- name: Run SRE benchmarks
working-directory: agent-governance-python/agent-sre
run: |
Expand Down
2 changes: 2 additions & 0 deletions .github/workflows/ci-generation-check.yml
Original file line number Diff line number Diff line change
Expand Up @@ -14,6 +14,8 @@ on:
paths:
- '.github/ci/**'
- '.github/workflows/**'
- 'agent-governance-python/agt-policies/**'
- 'agent-governance-python/agent-governance-toolkit-core/pyproject.toml'
- 'scripts/ci/generate_workflows.py'
- 'tests/ci/**'

Expand Down
10 changes: 7 additions & 3 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -353,7 +353,7 @@ jobs:
pip install --no-cache-dir --no-deps -e agent-governance-python/agent-governance-toolkit-integrations
pip install --no-cache-dir --no-deps -e agent-governance-python/agent-governance-toolkit-cli
pip install --no-cache-dir --no-deps -e agent-governance-python/agent-governance-toolkit-protocols
# agt-policies backs the agent-os v5 runtime bridge. Install this
# agt-policies backs the native ACS runtime. Install this
# local sibling without resolving agent-control-specification from
# PyPI; the vendored native SDK is built below for the packages that
# exercise the ACS-backed runtime. Keep its pure-Python runtime deps
Expand All @@ -379,7 +379,7 @@ jobs:
- name: Build native ACS SDK (ACS-backed Python policy runtime)
# agent-os and agt-policies route evaluations through the native
# `agent_control_specification` Rust SDK (pyo3/maturin). Build & install
# it from the vendored policy-engine so bridge-backed tests run.
# it from the vendored policy-engine so native-runtime tests run.
# The wheel is abi3-py311, so one build serves all agent-os matrix
# Python versions (3.11-3.13). ubuntu-latest ships Rust + a C toolchain.
if: steps.gate.outputs.run == 'true' && (matrix.package == 'agent-os' || matrix.package == 'agt-policies')
Expand Down Expand Up @@ -425,7 +425,7 @@ jobs:
working-directory: agent-governance-python/agent-os
run: |
pytest tests/test_governance_parity.py \
tests/test_spec_adapter_contract_conformance.py \
tests/test_adapter_mediation_contract.py \
-v --tb=short
- name: Test ${{ matrix.package }}
if: steps.gate.outputs.run == 'true'
Expand Down Expand Up @@ -719,6 +719,10 @@ jobs:
# All agentmesh-integrations packages declare a [dev] extra (audited
# 2026-05). Deterministic install — no error-swallowing fallback.
pip install --no-cache-dir -e ".[dev]"
# `.[dev]` resolves agt-policies from PyPI. Reinstall the local
# checkout afterwards so the integrations test against this commit's
# ACS policy API rather than the last published wheel.
pip install --no-cache-dir --no-deps --force-reinstall -e "$GITHUB_WORKSPACE/agent-governance-python/agt-policies"
CI_TEST_REQS="$GITHUB_WORKSPACE/agent-governance-python/requirements/ci-test.txt"
if [ -f "$CI_TEST_REQS" ]; then
# Hash-pinned shared test deps. Previously swallowed errors with
Expand Down
155 changes: 0 additions & 155 deletions .github/workflows/demos.yml

This file was deleted.

107 changes: 49 additions & 58 deletions .github/workflows/policy-validation.yml
Original file line number Diff line number Diff line change
Expand Up @@ -23,7 +23,8 @@ jobs:
policies:
- '**/*.yaml'
- '**/*.yml'
- 'agent-governance-python/agent-os/src/agent_os/policies/**'
- 'agent-governance-python/agt-policies/**'
- 'agent-governance-python/agent-compliance/src/agent_compliance/lint_policy.py'

validate-policies:
runs-on: ubuntu-latest
Expand All @@ -36,42 +37,50 @@ jobs:
with:
python-version: "3.11"

- name: Install consolidated v4 packages (local, --no-deps)
# The deprecated shim packages (agent-primitives, agent-os, ...) all
# declare a hard dep on agent-governance-toolkit-core>=4.0, which is
# not yet on PyPI. Pre-install the local consolidated packages with
# --no-deps so the subsequent shim installs resolve without pip
# reaching out to PyPI for the unpublished names.
- name: Install native manifest linter
run: |
pip install --no-cache-dir --no-deps \
-e agent-governance-python/agent-governance-toolkit-core \
-e agent-governance-python/agent-governance-toolkit-cli \
-e agent-governance-python/agent-governance-toolkit-integrations \
-e agent-governance-python/agent-governance-toolkit-protocols
pip install --no-cache-dir -e agent-governance-python/agent-compliance
pip install --no-cache-dir --no-deps -e agent-governance-python/agt-policies

- name: Install agent-primitives (local sibling)
run: pip install --no-cache-dir -e agent-governance-python/agent-primitives

- name: Install agent-os-kernel
working-directory: agent-governance-python/agent-os
run: |
pip install --no-cache-dir -e ".[dev]"
pip install --no-cache-dir --require-hashes -r "$GITHUB_WORKSPACE/agent-governance-python/requirements/ci-yaml.txt"

- name: Find and validate policy files
- name: Find and validate native ACS manifests
run: |
EXIT_CODE=0
echo "::group::Validating policy files"
for f in $(find . -name '*.yaml' -o -name '*.yml' \
| grep -i policy \
| grep -v 'charts/.*/templates/' \
| grep -v 'node_modules/' \
| sort); do
echo "--- Validating: $f ---"
python -m agent_os.policies.cli validate "$f" || EXIT_CODE=1
done
echo "::endgroup::"
exit "$EXIT_CODE"
python - <<'PY'
from pathlib import Path
from agent_compliance.lint_policy import lint_file

# A manifest that omits agent_control_specification_version would skip
# validation silently, which is the wrong direction for a policy gate.
# intervention_points is the ACS-specific tell: policies and agents
# are also used by unrelated config formats in this repo.
def declares_hooks(text):
return text.startswith("intervention_points:") or "\nintervention_points:" in text

manifests = []
missing_version = []
for root in (Path("examples"), Path("agent-governance-python")):
for pattern in ("*.yaml", "*.yml"):
for path in root.rglob(pattern):
text = path.read_text(encoding="utf-8", errors="ignore")
if "agent_control_specification_version:" in text:
manifests.append(path)
elif declares_hooks(text):
missing_version.append(path)

failed = [
f"{path}: declares intervention_points but no "
"agent_control_specification_version, so it skips validation"
for path in sorted(missing_version)
]
for path in sorted(manifests):
result = lint_file(path)
if not result.passed:
failed.extend(result.errors)

print(f"Validated {len(manifests)} native ACS manifests.")
for finding in failed:
print(finding)
raise SystemExit(bool(failed))
PY

test-policies:
runs-on: ubuntu-latest
Expand All @@ -86,35 +95,17 @@ jobs:
with:
python-version: "3.11"

- name: Install consolidated v4 packages (local, --no-deps)
if: needs.changes.outputs.policies == 'true'
# The deprecated shim packages (agent-primitives, agent-os, ...) all
# declare a hard dep on agent-governance-toolkit-core>=4.0, which is
# not yet on PyPI. Pre-install the local consolidated packages with
# --no-deps so the subsequent shim installs resolve without pip
# reaching out to PyPI for the unpublished names.
run: |
pip install --no-cache-dir --no-deps \
-e agent-governance-python/agent-governance-toolkit-core \
-e agent-governance-python/agent-governance-toolkit-cli \
-e agent-governance-python/agent-governance-toolkit-integrations \
-e agent-governance-python/agent-governance-toolkit-protocols

- name: Install agent-primitives (local sibling)
if: needs.changes.outputs.policies == 'true'
run: pip install --no-cache-dir -e agent-governance-python/agent-primitives

- name: Install agent-os-kernel
- name: Install native manifest test dependencies
if: needs.changes.outputs.policies == 'true'
working-directory: agent-governance-python/agent-os
run: |
pip install --no-cache-dir -e ".[dev]"
pip install --no-cache-dir -e agent-governance-python/agent-compliance
pip install --no-cache-dir --no-deps -e agent-governance-python/agt-policies
pip install --no-cache-dir --require-hashes -r "$GITHUB_WORKSPACE/agent-governance-python/requirements/ci-policy-test.txt"

- name: Run policy CLI tests
- name: Run native manifest lint tests
if: needs.changes.outputs.policies == 'true'
working-directory: agent-governance-python/agent-os
run: pytest tests/test_policy_cli.py -v --tb=short
working-directory: agent-governance-python/agent-compliance
run: pytest tests/test_lint_policy.py tests/test_agt_cli.py -k lint -v --tb=short

- name: Skip (no policy changes)
if: needs.changes.outputs.policies != 'true'
Expand Down
Loading
Loading