Skip to content

fix: use evaluated aggregation restrictions in context decision obligations - #3523

Merged
MohammadHaroonAbuomar merged 6 commits into
microsoft:mainfrom
Mr-Neutr0n:agent/issue-3084-feat-language-parity-fo
Sep 13, 2026
Merged

MohammadHaroonAbuomar merged 6 commits into
microsoft:mainfrom
Mr-Neutr0n:agent/issue-3084-feat-language-parity-fo

Conversation

@Mr-Neutr0n

@Mr-Neutr0n hari (Mr-Neutr0n) commented Jul 30, 2026 •

Copy link
Copy Markdown
Contributor

A one-line correctness fix in the Python accumulated-context policy, plus the regression tests it was missing.

Note on issue linkage: this PR previously said Fixes #3084. That was wrong — #3084 is the multi-SDK parity epic (TypeScript, .NET, Rust, Go) and this is a Python bug fix that closes none of it. The keyword is removed so merging this doesn't auto-close that epic. Relates to the Python surface from #2797.

The bug

decide_next() built its obligations from env.restrictions — the restrictions already folded onto the envelope — rather than agg.restrictions, the freshly evaluated set. A rule that fires during this very call has its restriction in agg but not yet in env, so the caller was told to CONSTRAIN while being handed an empty obligation set: gated, with nothing to satisfy.

A second, related hole came out of review (thanks Copilot — this was a good catch). The gate itself still read env.restrictions:

restriction_present = gating is not None and gating in env.restrictions

So a rule that adds a gating token without lifting sensitivity to the RESTRICTED floor triggered neither condition — token present in agg, absent from env, sensitivity below the floor — and the action was allowed. Both the gate and the obligations now read the evaluated set.

This is safe in the fail-closed direction: evaluate_aggregation seeds restrictions from env.restrictions before unioning matching rules (context_aggregation.py:72), so agg.restrictions is always a superset. It can gate more, never less, and an existing envelope restriction can never be dropped.

Third: a floor-triggered CONSTRAIN on an envelope with no recorded restrictions still returned an empty obligation set, which is a no-op for any host that enforces through obligations. The action's own gating token is the constraint being applied there, so it is now named.

Why the existing tests missed it

test_floor_triggers_flow_action_without_explicit_restriction uses {"pii"} alone, so pii_financial_restricted never fires, agg.restrictions stays empty, and env.restrictions vs agg.restrictions is indistinguishable. It passes either way.

Tests

Five added, each verified to fail with its own fix reverted and pass with it applied:

Test Without the fix
test_floor_gated_decision_reports_newly_triggered_restrictions assert set() == {'no_external_export'}
test_obligations_keep_envelope_restrictions_and_add_new_ones assert {'no_print'} == {'no_external_export', 'no_print'}
test_rule_added_restriction_gates_below_the_floor ALLOW where CONSTRAIN is required
test_floor_gated_decision_always_names_an_obligation assert set() == {'no_external_export'}
test_unrelated_action_is_not_gated_by_someone_elses_restriction guard: the gate stays per-action

10 passed. ruff format --check clean on both files.

Not touched

ruff reports UP035 (typing.Iterable) and UP042 (str, Enum) in context_accumulation.py under this package's own config. Both predate this branch. Left alone rather than widening a bug fix; happy to send separately.


This change was prepared with AI assistance under human direction.

…obligations

Signed-off-by: Mr-Neutr0n <64578610+Mr-Neutr0n@users.noreply.github.com>
Copilot AI lite review requested due to automatic review settings July 30, 2026 07:32
@github-actions

Copy link
Copy Markdown

Welcome to the Agent Governance Toolkit! Thanks for your first pull request.
Please ensure tests pass, code follows style (ruff check), and you have signed the CLA.
See our Contributing Guide.

@github-actions

github-actions Bot commented Jul 30, 2026 •

Copy link
Copy Markdown
🤖 AI Agent: test-generator — `agent-governance-python/agent-os/src/agent_os/policies/context_accumulation.py`

AI-generated review output. Treat it as untrusted analysis and verify before acting.

agent-governance-python/agent-os/src/agent_os/policies/context_accumulation.py

  • test_decide_next_handles_empty_agg_restrictions -- Verify behavior when agg.restrictions is empty but env.restrictions is not.
  • test_decide_next_handles_missing_gating_token -- Ensure proper handling when gating is None or missing.
  • test_decide_next_handles_invalid_restriction_types -- Validate behavior when agg.restrictions contains unexpected data types.

agent-governance-python/agent-os/tests/policies/test_context_accumulation.py

  • test_decide_next_handles_invalid_sensitivity_levels -- Test behavior when agg.aggregate_sensitivity is outside expected bounds.
  • test_decide_next_handles_conflicting_restrictions -- Ensure correct behavior when agg.restrictions and env.restrictions conflict.

@github-actions github-actions Bot added the size/XS Extra small PR (< 10 lines) label Jul 30, 2026
@github-actions

Copy link
Copy Markdown
🤖 AI Agent: contributor-guide — View details

AI-generated review output. Treat it as untrusted analysis and verify before acting.

Welcome, and thank you for your contribution! 🎉

Great job updating the code to improve context aggregation logic—your changes are clear and focused.

Before merging, please ensure:

  1. Unit tests are added or updated to validate the new behavior in context_accumulation.py.
  2. Confirm compatibility with existing workflows by running tests locally if possible.

Refer to CONTRIBUTING.md for guidance.

@github-actions

github-actions Bot commented Jul 30, 2026 •

Copy link
Copy Markdown
🤖 AI Agent: code-reviewer — View details

AI-generated review output. Treat it as untrusted analysis and verify before acting.

TL;DR: 0 blockers, 0 warnings. Clean change; fixes aggregation logic and adds comprehensive tests.

# Sev Issue Where

No action items. Clean change.

@github-actions

github-actions Bot commented Jul 30, 2026 •

Copy link
Copy Markdown
🤖 AI Agent: docs-sync-checker — Docs Sync

AI-generated review output. Treat it as untrusted analysis and verify before acting.

Docs Sync

  • decide_next() in context_accumulation.py -- missing docstring
  • README.md -- no update detected, but ensure it reflects the behavioral changes if applicable
  • CHANGELOG -- missing entry for the behavioral changes introduced

@github-actions

Copy link
Copy Markdown

PR Review Summary

Check Status Details
🔍 Code Review ⚠️ Missing No current-run comment
🛡️ Security Scan ⚠️ Missing No current-run comment
🔄 Breaking Changes ⚠️ Missing No current-run comment
📝 Docs Sync ⚠️ Missing No current-run comment
🧪 Test Coverage ⚠️ Missing No current-run comment

Verdict: ⚠️ AI review incomplete; ready for human review

AI review comments are untrusted advisory output. The summary reports workflow-generated completion status only, not model-authored pass/fail claims.

@github-actions

Copy link
Copy Markdown

🟡 Contributor Check: MEDIUM

Check Result
Profile MEDIUM
Credential LOW
Overall MEDIUM

Automated check by AGT Contributor Check.

@github-actions github-actions Bot added the needs-review:MEDIUM Contributor check flagged MEDIUM risk label Jul 30, 2026

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates the Python CAG next-action decision path so host obligations reflect aggregation-evaluated restrictions (including rule-derived restrictions), aligning with the accumulated-context governance model in agent_os.policies.

TL;DR: 1 blockers, 0 warnings. Fix #1 and this ships.

# Sev Issue Where
1 Block Gating still checks env.restrictions, so rule-added restrictions can be missed; floor gating can emit empty obligations decide_next() / context_accumulation.py

Changes:

  • Use evaluated aggregation restrictions (agg.restrictions) when emitting constrain obligations.

Comment thread agent-governance-python/agent-os/src/agent_os/policies/context_accumulation.py Outdated
The one-line fix had no regression test. The existing floor test uses a
single label, so the rule never fires and agg.restrictions stays empty --
which is why it passed either way and the bug went unnoticed.

Adds the case that actually discriminates: labels satisfying the rule with
nothing yet accumulated onto the envelope, where the old code returned
CONSTRAIN with an empty obligation set. Plus a case pinning that reading
obligations off the aggregation result never drops an existing envelope
restriction.

Signed-off-by: Mr-Neutr0n <harikp2002@gmail.com>
Copilot AI review requested due to automatic review settings July 30, 2026 13:39
@github-actions github-actions Bot added tests size/S Small PR (< 50 lines) and removed tests size/XS Extra small PR (< 10 lines) labels Jul 30, 2026
@github-actions

github-actions Bot commented Jul 30, 2026 •

Copy link
Copy Markdown
🤖 AI Agent: security-scanner — View details

AI-generated review output. Treat it as untrusted analysis and verify before acting.

No security issues found.

@Mr-Neutr0n hari (Mr-Neutr0n) changed the title Fix #3084: feat: language parity for accumulated context governance (TypeScript, fix: use evaluated aggregation restrictions in context decision obligations Jul 30, 2026
@Mr-Neutr0n

Copy link
Copy Markdown
Contributor Author

Two corrections to this PR and a test it was missing.

Retitled

The old title was Fix #3084: feat: language parity for accumulated context governance (TypeScript, — which failed Validate PR title (the Fix #3084: prefix hides the conventional-commit type), was truncated mid-word, and described the wrong change. There is no TypeScript implementation of context accumulation in this repo; decide_next exists only in agent-governance-python. The diff is one line of Python and it is a fix, not a feat.

Now fix: use evaluated aggregation restrictions in context decision obligations, and that check passes. Fixes #3084 is in the body.

The test that was missing

The body previously said local test infra was unavailable, which was true — uv sync here fails on agent-governance-toolkit-core vs agent-os-kernel[dev] pinning cryptography. Running the module against PYTHONPATH=src with just pytest, pyyaml and pydantic works fine, so there was no real excuse. Two cases added to tests/policies/test_context_accumulation.py.

The reason the bug survived is worth stating: test_floor_triggers_flow_action_without_explicit_restriction uses {"pii"} only, so pii_financial_restricted never fires, agg.restrictions stays empty, and env.restrictions vs agg.restrictions is indistinguishable. It passes either way.

The discriminating case is an envelope whose labels do satisfy the rule but where no accumulate() has run, so the restriction was never folded in. On the old code:

E   AssertionError: assert set() == {'no_external_export'}
E   AssertionError: assert {'no_print'} == {'no_external_export', 'no_print'}

The first is the real defect: the caller is told CONSTRAIN and handed an empty obligation set — gated, with nothing to satisfy.

On safety of the change

I wanted to be sure swapping env.restrictions for agg.restrictions couldn't drop a restriction. It can't: evaluate_aggregation starts from restrictions: set[str] = set(env.restrictions) (context_aggregation.py:72) before unioning matching rules' adds_restrictions, so the result is always a superset. The second test pins that property, since it is the kind of invariant that would break silently if that seeding were ever removed.

Not touched

ruff reports UP035 (typing.Iterable) and UP042 (str, Enum) in context_accumulation.py under this package's own config. Both predate this branch — my diff is a single token — so I've left them rather than widen a one-line bug fix. Happy to send them separately if wanted.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 2 out of 2 changed files in this pull request and generated no new comments.

hari (Mr-Neutr0n) added a commit to Mr-Neutr0n/agent-governance-toolkit that referenced this pull request Jul 30, 2026
…ion set

Addresses the review on microsoft#3523.

The first commit changed only the obligations to read agg.restrictions and
left the gate reading env.restrictions, which was inconsistent and left a
hole: a rule that adds a gating token without lifting sensitivity to the
floor put the token in agg but not yet in env, so neither trigger fired and
the action was allowed. Both now read the evaluated set. Because
evaluate_aggregation seeds from env.restrictions the result is a superset,
so this can only gate more, never less.

Separately, a floor-triggered CONSTRAIN on an envelope with no recorded
restrictions returned an empty obligation set -- a no-op for any host that
enforces through obligations. The action's gating token is the constraint
being applied in that case, so it is now named.

Signed-off-by: Mr-Neutr0n <harikp2002@gmail.com>
Copilot AI review requested due to automatic review settings July 30, 2026 16:17
@github-actions github-actions Bot added tests and removed size/S Small PR (< 50 lines) labels Jul 30, 2026
@Mr-Neutr0n

Copy link
Copy Markdown
Contributor Author

Thanks — that's exactly the pointer I needed. Added in 0c1e66b:
docs/security/audits/2026-07-31-context-accumulation-restriction-gating.md.

I followed the 2026-06-25-falsy-default-thresholds.md shape you pointed at, and kept the self-review disclaimer the 2026-06-03 context-accumulation audit carries, since these are my own notes rather than an independent review. It links back to that one, since decide_next came from it and this corrects two fail-open paths in the same gate.

Three things it records that aren't obvious from the diff:

The containment argument, stated once. evaluate_aggregation seeds restrictions from env.restrictions (context_aggregation.py:72) before unioning matching rules, so agg.restrictions ⊇ env.restrictions unconditionally. Everything else follows from that: the gate can only tighten, obligations can only grow, and no key already emitted is ever dropped or substituted.

Defect 1 needs one ordinary rule, not a contrived one. A rule that adds a gating token without lifting sensitivity to the floor satisfies neither trigger — the token is in agg but not yet in env, and sensitivity is below the floor. It needs no prior accumulate(), which is the normal state for the first gated action in a workflow and for any host that assembles an envelope rather than accumulating one.

Which tests fail on base. I reverted only context_accumulation.py to origin/main and reran: 4 of the 5 new tests fail there and pass on the fix. The fifth (test_unrelated_action_is_not_gated_by_someone_elses_restriction) passes on base by design — it's the guard against this change over-gating, so it's meant to hold in both directions. The audit table marks each one.

tests/policies: 29 passed. The offer from my earlier comment stands — the gate fix and the never-empty-obligations change touch adjacent but independent lines, so they split cleanly if you'd rather they land on different timelines.

@github-actions github-actions Bot added size/L Large PR (< 500 lines) and removed size/M Medium PR (< 200 lines) labels Jul 31, 2026

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 3 out of 3 changed files in this pull request and generated no new comments.

@Mr-Neutr0n

Copy link
Copy Markdown
Contributor Author

One note on verifying it: the quality-gates run for 0c1e66b is sitting at action_required, so the gate itself hasn't re-run — fork PRs need a maintainer to approve the workflow. Ran the script directly against the branch in the meantime:

$ bash scripts/ci/security-audit-required.sh origin/main
⚡ Capability path touched: agent-governance-python/agent-os/src/agent_os/policies/
✅ security-audit-required: audit doc found: docs/security/audits/2026-07-31-context-accumulation-restriction-gating.md

The other 10 checks are green on the new head.

Jainil Gosalia (Jainil-Gosalia) added a commit to Jainil-Gosalia/agent-governance-toolkit that referenced this pull request Jul 31, 2026
- Geography default fail-open: require explicit geography match when
  policy.required_geography is set; absent geography no longer bypasses.
- Empty all_labels rejected: AggregationRule.__post_init__ raises
  ValueError when all_labels is empty, preventing silent backstop defeat.

The restriction-gating gap (decide_next reading env.restrictions) is
covered by microsoft#3523 and intentionally left out of this PR.

Each fix ships with a regression test that would fail without the change,
plus a security audit doc under docs/security/audits/.

Signed-off-by: Jainil Gosalia <jainil.gosalia@gmail.com>
MohammadHaroonAbuomar pushed a commit that referenced this pull request Aug 4, 2026
- Geography default fail-open: require explicit geography match when
  policy.required_geography is set; absent geography no longer bypasses.
- Empty all_labels rejected: AggregationRule.__post_init__ raises
  ValueError when all_labels is empty, preventing silent backstop defeat.

The restriction-gating gap (decide_next reading env.restrictions) is
covered by #3523 and intentionally left out of this PR.

Each fix ships with a regression test that would fail without the change,
plus a security audit doc under docs/security/audits/.

Signed-off-by: Jainil Gosalia <jainil.gosalia@gmail.com>
Signed-off-by: Mr-Neutr0n <harikp2002@gmail.com>
Copilot AI review requested due to automatic review settings August 6, 2026 13:49

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 4 out of 4 changed files in this pull request and generated no new comments.

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Ran this one both ways, because the value of a fail-closed fix is entirely in whether its tests fail
without it.

PR source + PR tests   -> 10 passed
main source + PR tests ->  4 failed, 6 passed

The four that fail against main are test_obligations_keep_envelope_restrictions_and_add_new_ones,
test_rule_added_restriction_gates_below_the_floor,
test_floor_gated_decision_always_names_an_obligation, and one more. So these are genuine regression
tests, not tests written to describe the new code.

The superset argument holds and it is the load-bearing claim. I checked evaluate_aggregation in
context_aggregation.py:

restrictions: set[str] = set(env.restrictions)
for rule in ruleset.rules:
    if rule.all_labels <= env.labels:
        restrictions |= set(rule.adds_restrictions)

It seeds from env.restrictions and only ever unions, so agg.restrictions ⊇ env.restrictions
unconditionally. Your comment's "it can only ever gate more, never less" is exactly right, and that
is what makes reading the evaluated set safe rather than merely different. Without that property this
change could silently drop an obligation, which is why it is worth having stated in the code.

The bug is real and it is the nastier of the two shapes. A rule that adds a gating restriction
without lifting sensitivity to the floor produced neither trigger: the token was in agg but not yet
in env, and the floor never fired. That is a rule that does exactly what a policy author wrote and
has no effect, which is worse than a rule that errors.

The second fix is the one I would highlight. When the floor fires on an envelope with no recorded
restrictions, the old code emitted CONSTRAIN with an empty ObligationSet. For any host that
enforces through obligations that is a constrain instruction with nothing to satisfy, which either
no-ops or blocks with no remedy depending on how the host reads it. Adding the gating token so the
decision always names at least one obligation closes an ambiguity that a caller could not have
resolved. Your test comment says it well: "the caller is told to constrain the action without being
told what to satisfy".

Two mechanical things before this can merge.

It is CONFLICTING and 55 commits behind main.

Spell-check changed files is genuine, one word, in your own added line:

:34:63 - Unknown word (unioning)

That is from the test comment "before unioning rule restrictions". A # cspell:ignore unioning, or
rewording to "before merging in rule restrictions", clears it. Worth knowing it is real, because
several other PRs in this queue show the same check red purely from a stale-base over-scan and this
is not one of them.

Nothing blocking on the fix.

@imran-siddique

Copy link
Copy Markdown
Collaborator

MohammadHaroonAbuomar liamcrumm flagging this one. It closes two fail-opens in context-accumulation
gating, including a CONSTRAIN decision emitted with an empty ObligationSet, which tells a caller
to constrain an action without naming anything to satisfy.

I ran the tests both ways: 10 pass with the fix, 4 fail against main's source, so these are genuine
regression tests. It needs a rebase (55 behind, CONFLICTING) and one cspell:ignore. Review stands.

Resolve conflict in the sibling fail-open-closure audit frontmatter by
taking upstream main. Rephrase "unioning" in the context-accumulation
test comment so spell-check passes.

Signed-off-by: Mr-Neutr0n <harikp2002@gmail.com>

Co-authored-by: hari <harikp2002@gmail.com>
cursor Bot referenced this pull request in Mr-Neutr0n/agent-governance-toolkit Sep 8, 2026
Resolve conflict in the sibling fail-open-closure audit frontmatter by
taking upstream main. Rephrase "unioning" in the context-accumulation
test comment so spell-check passes.

Signed-off-by: Mr-Neutr0n <harikp2002@gmail.com>

Co-authored-by: hari <harikp2002@gmail.com>
@cursor
cursor Bot force-pushed the agent/issue-3084-feat-language-parity-fo branch from 01cf5bc to 5a10d30 Compare September 8, 2026 15:09
@Mr-Neutr0n

Copy link
Copy Markdown
Contributor Author

Merged upstream main into this branch and fixed cspell on the PR head (5a10d306). Conflicts are cleared (MERGEABLE).

Please re-review when you have a chance.

@MohammadHaroonAbuomar

Copy link
Copy Markdown
Collaborator

Re-triggering CI against current main (the earlier run predates the typing-extensions pin fix in #3928). Reopening now.

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
There may be pipelines that require an authorized user to comment /azp run to run.

@MohammadHaroonAbuomar MohammadHaroonAbuomar left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved after group integration review (tests, gates and adversarial pass on the combined change).

@MohammadHaroonAbuomar
MohammadHaroonAbuomar merged commit c4103c0 into microsoft:main Sep 13, 2026
250 of 254 checks passed
Karim Mehalebi (karimad) pushed a commit to karimad/agent-governance-toolkit that referenced this pull request Sep 14, 2026
…ations (microsoft#3523)

* fix: use evaluated aggregation restrictions in constraining decision obligations

Signed-off-by: Mr-Neutr0n <64578610+Mr-Neutr0n@users.noreply.github.com>

* test: cover obligations for restrictions triggered during decide_next

The one-line fix had no regression test. The existing floor test uses a
single label, so the rule never fires and agg.restrictions stays empty --
which is why it passed either way and the bug went unnoticed.

Adds the case that actually discriminates: labels satisfying the rule with
nothing yet accumulated onto the envelope, where the old code returned
CONSTRAIN with an empty obligation set. Plus a case pinning that reading
obligations off the aggregation result never drops an existing envelope
restriction.

Signed-off-by: Mr-Neutr0n <harikp2002@gmail.com>

* fix: gate on evaluated restrictions and never return an empty obligation set

Addresses the review on microsoft#3523.

The first commit changed only the obligations to read agg.restrictions and
left the gate reading env.restrictions, which was inconsistent and left a
hole: a rule that adds a gating token without lifting sensitivity to the
floor put the token in agg but not yet in env, so neither trigger fired and
the action was allowed. Both now read the evaluated set. Because
evaluate_aggregation seeds from env.restrictions the result is a superset,
so this can only gate more, never less.

Separately, a floor-triggered CONSTRAIN on an envelope with no recorded
restrictions returned an empty obligation set -- a no-op for any host that
enforces through obligations. The action's gating token is the constraint
being applied in that case, so it is now named.

Signed-off-by: Mr-Neutr0n <harikp2002@gmail.com>

* docs(security): add the audit record for the context-accumulation gate fix

The security-audit-required gate flags any change under
agent_os/policies/. Records the two fail-open defects, the monotone
direction of both fixes, and which regression tests fail on base.

Signed-off-by: Mr-Neutr0n <harikp2002@gmail.com>

---------

Signed-off-by: Mr-Neutr0n <64578610+Mr-Neutr0n@users.noreply.github.com>
Signed-off-by: Mr-Neutr0n <harikp2002@gmail.com>
Yuvraj Singh (yuvrajsingh2428) pushed a commit to yuvrajsingh2428/agent-governance-toolkit that referenced this pull request Oct 1, 2026
…ations (microsoft#3523)

* fix: use evaluated aggregation restrictions in constraining decision obligations

Signed-off-by: Mr-Neutr0n <64578610+Mr-Neutr0n@users.noreply.github.com>

* test: cover obligations for restrictions triggered during decide_next

The one-line fix had no regression test. The existing floor test uses a
single label, so the rule never fires and agg.restrictions stays empty --
which is why it passed either way and the bug went unnoticed.

Adds the case that actually discriminates: labels satisfying the rule with
nothing yet accumulated onto the envelope, where the old code returned
CONSTRAIN with an empty obligation set. Plus a case pinning that reading
obligations off the aggregation result never drops an existing envelope
restriction.

Signed-off-by: Mr-Neutr0n <harikp2002@gmail.com>

* fix: gate on evaluated restrictions and never return an empty obligation set

Addresses the review on microsoft#3523.

The first commit changed only the obligations to read agg.restrictions and
left the gate reading env.restrictions, which was inconsistent and left a
hole: a rule that adds a gating token without lifting sensitivity to the
floor put the token in agg but not yet in env, so neither trigger fired and
the action was allowed. Both now read the evaluated set. Because
evaluate_aggregation seeds from env.restrictions the result is a superset,
so this can only gate more, never less.

Separately, a floor-triggered CONSTRAIN on an envelope with no recorded
restrictions returned an empty obligation set -- a no-op for any host that
enforces through obligations. The action's gating token is the constraint
being applied in that case, so it is now named.

Signed-off-by: Mr-Neutr0n <harikp2002@gmail.com>

* docs(security): add the audit record for the context-accumulation gate fix

The security-audit-required gate flags any change under
agent_os/policies/. Records the two fail-open defects, the monotone
direction of both fixes, and which regression tests fail on base.

Signed-off-by: Mr-Neutr0n <harikp2002@gmail.com>

---------

Signed-off-by: Mr-Neutr0n <64578610+Mr-Neutr0n@users.noreply.github.com>
Signed-off-by: Mr-Neutr0n <harikp2002@gmail.com>
Signed-off-by: yuvrajsingh2428 <offcyuvi2428@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentation Improvements or additions to documentation needs-review:MEDIUM Contributor check flagged MEDIUM risk security Security-related issues size/L Large PR (< 500 lines) tests

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants