Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
29 commits
Select commit Hold shift + click to select a range
07d9d1d
refactor(policy-engine)!: replace the embedded engine with agent-cont…
liamcrumm Aug 1, 2026
3647672
feat(sdk): take on the agent-hooks host obligations
liamcrumm Aug 1, 2026
91614fa
refactor(sdk): retarget the Python and Node bindings
liamcrumm Aug 1, 2026
cf44d49
feat(dotnet): retarget the .NET SDK and its C ABI
liamcrumm Aug 1, 2026
2fe214d
refactor: migrate the callers, manifests and policies to the new grammar
liamcrumm Aug 1, 2026
8ed349f
refactor(generator): emit the new grammar and correct the wire schemas
liamcrumm Aug 1, 2026
aa42b74
test(conformance): restore the corpus runner and retarget the cases
liamcrumm Aug 1, 2026
c8f88ca
docs: record the retarget, the reason split and the open gaps
liamcrumm Aug 1, 2026
136b627
chore(ci): register the upstream crates and the new vocabulary
liamcrumm Aug 1, 2026
4cdf577
fix: close the gaps this change could close itself
liamcrumm Aug 1, 2026
3bf5acd
fix: hold the npm version until the platform packages are published
liamcrumm Aug 1, 2026
a3c755e
fix: drop the version requirement from unpublished path dependencies
liamcrumm Aug 1, 2026
ab76014
fix(supply-chain): age-check `=`-pinned cargo dependencies
MohammadHaroonAbuomar Aug 1, 2026
fddba74
fix(supply-chain): satisfy the cooling-off rule the scanner fix now e…
liamcrumm Aug 1, 2026
ffa329d
test: use a spellable placeholder crate name
liamcrumm Aug 1, 2026
3ae7341
revert: move the scanner fix to its own PR
liamcrumm Aug 1, 2026
d91037f
docs: record the breaking change, the guard's real scope and the publ…
liamcrumm Aug 1, 2026
6ddbd99
Merge remote-tracking branch 'origin/main' into liamcrumm/retarget-ac…
liamcrumm Aug 3, 2026
4a12d0e
test(core): guard every committed manifest against grammar drift
liamcrumm Aug 3, 2026
673e2f7
Merge current main into ACS retarget
liamcrumm Sep 8, 2026
5ba84cf
fix(acs): preserve host limits and release contracts
liamcrumm Sep 8, 2026
61d2746
fix(ci): complete retarget dependency and publication ordering
liamcrumm Sep 8, 2026
21c59cc
fix(ci): support pinned fuzz builder curl
liamcrumm Sep 8, 2026
a4857f8
fix(fuzz): preserve native sanitizer instrumentation
liamcrumm Sep 8, 2026
be00c44
chore: register fuzzing tool identifiers
liamcrumm Sep 8, 2026
7e8de67
fix(acs): align with current published engine contracts
liamcrumm Sep 8, 2026
aa25d0a
fix(acs): preserve isolated builds and compatibility constants
liamcrumm Sep 8, 2026
f6b6928
fix(ci): align shared typing extensions with AnyIO
liamcrumm Sep 8, 2026
ed0f9bb
test(ci): keep runtime dependency checks in the runtime suite
liamcrumm Sep 8, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
7 changes: 7 additions & 0 deletions .clusterfuzzlite/Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -3,4 +3,11 @@ FROM gcr.io/oss-fuzz-base/base-builder-python@sha256:9e7e09e8e63d9cc9646306d8642
COPY . $SRC/agent-governance-toolkit
WORKDIR $SRC/agent-governance-toolkit

# Keep the image's Cargo coverage wrapper and provide its missing compiler.
# Nightly is required by OSS-Fuzz's -Zsanitizer flags.
RUN bash scripts/ci/install_pinned_rust.sh "" nightly-2025-08-07 \
&& mkdir -p /rust/bin \
&& ln -s /root/.cargo/bin/cargo /rust/bin/cargo
ENV PATH="${PATH}:/root/.cargo/bin"

COPY .clusterfuzzlite/build.sh $SRC/build.sh
7 changes: 7 additions & 0 deletions .clusterfuzzlite/build.sh
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,13 @@

cd $SRC/agent-governance-toolkit

pip3 install maturin==1.8.7 # Scorecard: version-pinned
# Python fuzzing uses x86_64. An explicit target keeps sanitizer flags off
# host procedural macros while instrumenting the native SDK.
CARGO_BUILD_TARGET=x86_64-unknown-linux-gnu \
pip3 install --no-build-isolation ./policy-engine/sdk/python
pip3 install ./agent-governance-python/agt-policies

# Install the governance packages (paths updated after mono-repo reorg).
# Fail loudly if any install fails — silently building fuzzers without
# their target packages produces fuzzers that exercise none of the code
Expand Down
20 changes: 20 additions & 0 deletions .cspell-repo-terms.txt
Original file line number Diff line number Diff line change
Expand Up @@ -44,6 +44,7 @@ Bradner
CBN
CBOR
CCPA
CDLL
CISA
CMVK
CODEOWNERS
Expand Down Expand Up @@ -158,10 +159,12 @@ Println
Pydantic
REALPKG
RUBYOPT
RUSTFLAGS
RUSTUP
Ravande
Redocly
Rego
Regorus
Rekor
Repoint
Rootfs
Expand Down Expand Up @@ -241,7 +244,9 @@ allowlisted
alnum
amannn
anchore
anes
anomalyco
anstyle
antigravity
apikey
apiserver
Expand All @@ -250,6 +255,7 @@ approvable
approvеd
appsettings
argparse
argtypes
arraycomprehension
arrowsize
artefacts
Expand Down Expand Up @@ -289,6 +295,7 @@ buildkit
buildx
bursty
bypassable
byref
bytearray
bytecodes
bytecount
Expand All @@ -301,6 +308,7 @@ carloshvp
carryforward
carveout
casefold
cdylib
cedarling
cedarpy
cedarschema
Expand All @@ -327,6 +335,7 @@ clientid
clippy
cloudevent
cloudevents
clusterfuzzlite
cmdshell
cmpl
codepoint
Expand Down Expand Up @@ -359,6 +368,7 @@ crossstate
crun
cstr
cstring
ctypes
custodied
cutover
dalek
Expand Down Expand Up @@ -390,6 +400,7 @@ digestmod
displaydoc
dists
dkwargs
dlopen
dnssec
doesnotexist
domaintenantid
Expand All @@ -403,6 +414,7 @@ eastus
egresspolicy
elif
elts
embedder
embedders
emnapi
endswith
Expand Down Expand Up @@ -667,6 +679,7 @@ offence
omitempty
oncall
oneshot
oorandom
opencode
openpolicyagent
openshell
Expand Down Expand Up @@ -756,6 +769,7 @@ recompiles
redactions
redef
rederive
rederived
rederives
redteam
reemits
Expand All @@ -776,7 +790,10 @@ resear
reserialize
reshapeable
responsibleai
restype
retarget
retargeted
retargets
returncode
rfile
rfind
Expand All @@ -795,6 +812,7 @@ runbooks
runsc
rustc
rustdecimal
rustix
rustls
rustup
sagaorchestrator
Expand Down Expand Up @@ -888,6 +906,7 @@ thiserror
timedelta
tinyrainbow
tinystr
tinytemplate
tlsv
tmpfs
toolkits
Expand Down Expand Up @@ -1021,6 +1040,7 @@ yamls
zerofrom
zerotrie
zerovec
zmij
zoneinfo

# --- Documentation site and ACS integration terms ---
Expand Down
9 changes: 9 additions & 0 deletions .github/ci/workflows.toml
Original file line number Diff line number Diff line change
Expand Up @@ -56,9 +56,18 @@ run = "cargo fmt --all -- --check"
name = "Clippy"
run = "cargo clippy --workspace --all-targets -- -D warnings"
[[workflow.job.step]]
name = "Isolated compatibility crates"
run = """
cargo check --locked -p agent_control_specification_core --no-default-features --lib
cargo check --locked -p agent_control_specification_otel --lib
"""
[[workflow.job.step]]
name = "Test"
run = "cargo test --workspace"
[[workflow.job.step]]
name = "OPA compatibility with upstream Rego enabled"
run = "AGT_EXPECT_UPSTREAM_REGO=1 cargo test --locked -p agent_control_specification --features bundled-dispatchers,opa,agent-control-spec/rego --test upstream_compatibility"
[[workflow.job.step]]
name = "Package publishable ACS crates"
run = """
cargo package -p agent_control_specification_core --allow-dirty
Expand Down
26 changes: 18 additions & 8 deletions .github/pipelines/esrp-publish.yml
Original file line number Diff line number Diff line change
Expand Up @@ -198,26 +198,26 @@ parameters:
displayName: 'ACS .NET native runtime assets'
default:
- rid: linux-x64
nativeLib: libagent_control_specification_core.so
nativeLib: libagent_control_specification.so
rustTarget: x86_64-unknown-linux-gnu
vmImage: ubuntu-latest
- rid: linux-arm64
nativeLib: libagent_control_specification_core.so
nativeLib: libagent_control_specification.so
rustTarget: aarch64-unknown-linux-gnu
vmImage: ubuntu-latest
aptPackages: gcc-aarch64-linux-gnu
linkerEnv: CARGO_TARGET_AARCH64_UNKNOWN_LINUX_GNU_LINKER
linker: aarch64-linux-gnu-gcc
- rid: osx-x64
nativeLib: libagent_control_specification_core.dylib
nativeLib: libagent_control_specification.dylib
rustTarget: x86_64-apple-darwin
vmImage: macOS-latest
- rid: osx-arm64
nativeLib: libagent_control_specification_core.dylib
nativeLib: libagent_control_specification.dylib
rustTarget: aarch64-apple-darwin
vmImage: macOS-latest
- rid: win-x64
nativeLib: agent_control_specification_core.dll
nativeLib: agent_control_specification.dll
rustTarget: x86_64-pc-windows-msvc
vmImage: windows-latest

Expand Down Expand Up @@ -651,7 +651,7 @@ stages:
publishLocation: 'pipeline'
displayName: 'Publish complete ACS Python distribution'

# All PyPI packages publish in parallel after build completes.
# Publish prerequisites before consumers; unrelated packages stay parallel.
- stage: Publish_PyPI
displayName: 'Publish All Packages to PyPI'
dependsOn: Build_PyPI
Expand All @@ -660,6 +660,16 @@ stages:
- ${{ each pkg in parameters.pypiPackages }}:
- job: Publish_PyPI_${{ replace(pkg.name, '-', '_') }}
displayName: 'Publish ${{ pkg.name }} to PyPI'
dependsOn:
- ${{ each prerequisite in parameters.pypiPackages }}:
- ${{ if and(eq(prerequisite.name, 'agent-control-specification'), or(eq(pkg.name, 'agt-policies'), eq(pkg.name, 'acs-generator'))) }}:
- Publish_PyPI_${{ replace(prerequisite.name, '-', '_') }}
- ${{ if and(eq(prerequisite.name, 'agt-policies'), eq(pkg.name, 'agent-governance-toolkit-core')) }}:
- Publish_PyPI_${{ replace(prerequisite.name, '-', '_') }}
- ${{ if and(eq(prerequisite.name, 'agent-governance-toolkit-core'), or(eq(pkg.name, 'agent-governance-toolkit-cli'), eq(pkg.name, 'agent-governance-toolkit-integrations'), eq(pkg.name, 'agent-governance-toolkit-protocols'))) }}:
- Publish_PyPI_${{ replace(prerequisite.name, '-', '_') }}
- ${{ if and(eq(prerequisite.name, 'agent-governance-toolkit-cli'), eq(pkg.name, 'agt-sandbox')) }}:
- Publish_PyPI_${{ replace(prerequisite.name, '-', '_') }}
steps:
- task: DownloadPipelineArtifact@2
inputs:
Expand Down Expand Up @@ -1004,8 +1014,8 @@ stages:
export ${{ native.linkerEnv }}="${{ native.linker }}"
fi
cargo build --release \
-p agent_control_specification_core \
--features default-dispatchers,aacs,openai_moderation,perspective,llama_guard,lakera_guard,auto \
-p agent_control_specification \
--features opa,bundled-dispatchers \
--target ${{ native.rustTarget }} \
--manifest-path policy-engine/Cargo.toml
mkdir -p "$(Pipeline.Workspace)/acs-dotnet-native/${{ native.rid }}/native"
Expand Down
26 changes: 15 additions & 11 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -384,13 +384,12 @@ jobs:
echo "$RUNNER_TEMP" >> "$GITHUB_PATH"
"$RUNNER_TEMP/opa" version
- name: Build native ACS SDK (ACS-backed Python policy runtime)
# agent-os, agt-policies, agent-compliance, agent-marketplace and
# agent-sandbox route evaluations through the native
# `agent_control_specification` Rust SDK (pyo3/maturin). Build & install
# it from the vendored policy-engine so native-runtime tests run.
# Every selected package resolves the local agt-policies dependency.
# Its retargeted SDK is not on PyPI yet, so build it from this checkout
# rather than letting pip resolve an incompatible registry version.
# The wheel is abi3-py311, so one build serves all agent-os matrix
# Python versions (3.11-3.13). ubuntu-latest ships Rust + a C toolchain.
if: steps.gate.outputs.run == 'true' && (matrix.package == 'agent-os' || matrix.package == 'agt-policies' || matrix.package == 'agent-compliance' || matrix.package == 'agent-marketplace' || matrix.package == 'agent-sandbox')
if: steps.gate.outputs.run == 'true'
run: |
set -euo pipefail
pip install --no-cache-dir maturin==1.8.7 # Scorecard: version-pinned
Expand Down Expand Up @@ -542,13 +541,16 @@ jobs:
run: |
set -euo pipefail
rm -rf dist-coherence && mkdir -p dist-coherence
pip install --no-cache-dir maturin==1.8.7 # Scorecard: version-pinned
python -m pip wheel --no-deps --no-build-isolation \
./policy-engine/sdk/python --wheel-dir dist-coherence
# The umbrellas own the source; the sibling stubs are dep-only. Build
# them all with --wheel because the umbrellas force-include sibling
# source, which only resolves when building directly from the source
# tree. -core's set is the five renamed stubs; -cli's set adds
# agent-sre; -protocols' set adds agent-mcp-governance.
for pkg in \
agent-governance-toolkit-core \
agt-policies agent-governance-toolkit-core \
agent-hypervisor agent-mesh agent-os agent-runtime agent-primitives \
agent-governance-toolkit-cli agent-sre \
agent-governance-toolkit-protocols agent-mcp-governance; do
Expand All @@ -561,7 +563,7 @@ jobs:
run: |
set -euo pipefail
python -m venv /tmp/venv-core
/tmp/venv-core/bin/pip install --no-cache-dir \
/tmp/venv-core/bin/pip install --no-cache-dir --find-links dist-coherence \
dist-coherence/agent_governance_toolkit_core-*.whl
/tmp/venv-core/bin/python -W ignore \
-c "import hypervisor, agentmesh, agent_os, agent_runtime, agent_primitives; print('meta import OK')"
Expand Down Expand Up @@ -606,6 +608,11 @@ jobs:
pip install --no-cache-dir --require-hashes --no-deps -r "$GITHUB_WORKSPACE/agent-governance-python/requirements/ci-safety.txt"
pip install --no-cache-dir typer==0.14.0 marshmallow==3.21.3 # Scorecard: version-pinned (safety transitive deps)
pip install --no-cache-dir safety==3.2.1 # Scorecard: version-pinned, hash-verified via ci-safety.txt
- name: Install local policy dependencies
run: |
pip install --no-cache-dir maturin==1.8.7 # Scorecard: version-pinned
pip install --no-cache-dir --no-build-isolation ./policy-engine/sdk/python
pip install --no-cache-dir ./agent-governance-python/agt-policies
- name: Check dependencies
env:
GIT_TERMINAL_PROMPT: "0"
Expand Down Expand Up @@ -804,13 +811,10 @@ jobs:
# the latest published wheels.
pip install --no-cache-dir --no-deps -e "$GITHUB_WORKSPACE/agent-governance-python/agent-governance-toolkit-core"
pip install --no-cache-dir --no-deps -e "$GITHUB_WORKSPACE/agent-governance-python/agent-governance-toolkit-integrations"
pip install --no-cache-dir -e "$GITHUB_WORKSPACE/agent-governance-python/agt-policies"
# All agentmesh-integrations packages declare a [dev] extra (audited
# 2026-05). Deterministic install — no error-swallowing fallback.
pip install --no-cache-dir -e ".[dev]"
# `.[dev]` resolves agt-policies from PyPI. Reinstall the local
# checkout afterwards so the integrations test against this commit's
# ACS policy API rather than the last published wheel.
pip install --no-cache-dir --no-deps --force-reinstall -e "$GITHUB_WORKSPACE/agent-governance-python/agt-policies"
CI_TEST_REQS="$GITHUB_WORKSPACE/agent-governance-python/requirements/ci-test.txt"
if [ -f "$CI_TEST_REQS" ]; then
# Hash-pinned shared test deps. Previously swallowed errors with
Expand Down
1 change: 1 addition & 0 deletions .github/workflows/e2e-python.yml
Original file line number Diff line number Diff line change
Expand Up @@ -81,6 +81,7 @@ jobs:
python -m pip install --upgrade pip==24.3.1
python -m pip install \
-e agent-governance-python/agent-governance-toolkit-core \
-e agent-governance-python/agt-policies \
./policy-engine/sdk/python \
pytest==9.0.3 \
pytest-timeout==2.4.0
Expand Down
7 changes: 7 additions & 0 deletions .github/workflows/policy-engine-ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -50,9 +50,16 @@ jobs:
- name: Clippy
run: |
cargo clippy --workspace --all-targets -- -D warnings
- name: Isolated compatibility crates
run: |
cargo check --locked -p agent_control_specification_core --no-default-features --lib
cargo check --locked -p agent_control_specification_otel --lib
- name: Test
run: |
cargo test --workspace
- name: OPA compatibility with upstream Rego enabled
run: |
AGT_EXPECT_UPSTREAM_REGO=1 cargo test --locked -p agent_control_specification --features bundled-dispatchers,opa,agent-control-spec/rego --test upstream_compatibility
- name: Package publishable ACS crates
run: |
cargo package -p agent_control_specification_core --allow-dirty
Expand Down
5 changes: 5 additions & 0 deletions .github/workflows/publish.yml
Original file line number Diff line number Diff line change
Expand Up @@ -70,6 +70,7 @@ jobs:
env:
INPUT: ${{ github.event.inputs.package }}
EVENT_NAME: ${{ github.event_name }}
DRY_RUN: ${{ github.event.inputs.dry_run }}
run: |
# Complete list of publishable Python packages.
ALL='[
Expand Down Expand Up @@ -138,6 +139,10 @@ jobs:

GENERIC=$(echo "$SELECTED" | jq -c '[.[] | select(.name != "agent-control-specification")]')
SELECTED_COUNT=$(echo "$SELECTED" | jq 'length')
if [ "$EVENT_NAME" = "workflow_dispatch" ] && [ "$DRY_RUN" = "false" ] && [ "$SELECTED_COUNT" -gt 1 ]; then
echo "::error::Bulk PyPI publication requires the ordered ESRP pipeline. Select one Python package per GitHub publish run, in dependency order; bulk dry-runs remain supported."
exit 1
fi
GENERIC_COUNT=$(echo "$GENERIC" | jq 'length')
ACS_COUNT=$(echo "$SELECTED" | jq '[.[] | select(.name == "agent-control-specification")] | length')
any=$([ "$SELECTED_COUNT" -gt 0 ] && echo true || echo false)
Expand Down
Loading
Loading